Re: Putting together a computer from old components
Paul <[email protected]>
| Newsgroups | alt.comp.hardware,uk.comp.homebuilt |
|---|---|
| Organization | A noiseless patient Spider |
| Message-ID | <[email protected]> |
On 12/5/2021 10:39 AM, Spiros Bousbouras wrote: > On Mon, 29 Nov 2021 20:05:24 +0000 > Richard Kettlewell <[email protected]> wrote: >> Spiros Bousbouras <[email protected]> writes: >>> Richard Kettlewell <[email protected]> wrote: >>>> Spiros Bousbouras <[email protected]> writes: >> >>>>> The Intel management engine and the analogous from AMD creep me out >>>>> so I want to put a computer together using old processors from >>>>> before these facilities came into the picture. >>>> >>>> Is there a reason why you don’t want to buy a current platform and >>>> disable the feature in the firmware? You might need to do a bit of >>>> research to ensure you get something where disabling it is possible >>>> but it seems a lot easier than building a computer from old parts. >>> >>> Is it possible to disable them ? >>> https://en.wikipedia.org/wiki/AMD_Secure_Technology does not say >>> anything. >> >> https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm?turl=WordDocuments%2Fdisablingintelamt.htm > > This page is about disabling AMT : > https://en.wikipedia.org/wiki/Intel_Management_Engine : > The Management Engine is often confused with Intel AMT (Intel Active > Management Technology). AMT runs on the ME, but is only available on > processors with vPro. AMT gives device owners remote administration of > their computer,^[6] such as powering it on or off, and reinstalling the > operating system. > > However, the ME itself is built into all Intel chipsets since 2008, not > only those with AMT. While AMT can be unprovisioned by the owner, there > is no official, documented way to disable the ME.^[citation needed] > > Although it says "citation needed" , I find it unlikely that , if there was a > way to disable the ME , someone would not have added it to the article by now. In > any case see also > > https://www.techrepublic.com/article/is-the-intel-management-engine-a-backdoor/ : > Various sources report that Intel's latest x86 chips contain a secret > backdoor. SoftPedia cites security expert Damien Zammit as revealing that > these Intel chips come with an embedded subsystem called the Management > Engine (ME) that functions as a separate CPU and cannot be disabled, and > the code is proprietary. > [...] > > However, the ME contains the AMT instructions, which can function > similarly to wake-on-LAN. That means if the right person used the ME to > gain access to a machine, they could then take advantage of AMT and boot > the machine. Viola! Your PC is now readily available for someone with the > requisite skills to pick and choose what they want--this could include > company data. > [...] > > The good news is that you can disable the AMT feature. Here's how. > > * In the PC BIOS, go to Advance Chipset Feature | Intel AMT > (Enabled,Disabled) > * During boot, CTRL+P to go to AMT Menu | Intel ME Control State > (Enabled,Disabled) > > There is no way to know if the ME has the ability to re-enable AMT on its > own. Why? Because no one except Intel knows what exactly it contains. So, > you could disable ATM on the machine and not know if the ME can > circumvent that BIOS setting. It's not a "secret" enclave, as there was at least one slide deck about the feature set. I've not seen a slide deck since the Wifi was added to the more modern setups. The Intel NIC is dual-headed (so certain NICs are needed to make it work). And it is possible the Intel Wifi modules have dual head as well. http://pds4.egloos.com/pds/200706/04/57/ps_adts003.pdf Since it potentially can be used for anti-theft purposes, that's why there can't be a hardware jumper plug to guarantee it is off. A thief would just use that. Paul