Re: Putting together a computer from old components
Spiros Bousbouras <[email protected]>
| Newsgroups | alt.comp.hardware,uk.comp.homebuilt |
|---|---|
| Organization | A noiseless patient Spider |
| Message-ID | <[email protected]> |
On Mon, 6 Dec 2021 03:10:00 -0500 Paul <[email protected]> wrote: > On 12/5/2021 10:39 AM, Spiros Bousbouras wrote: > > On Mon, 29 Nov 2021 20:05:24 +0000 > > Richard Kettlewell <[email protected]> wrote: > >> Spiros Bousbouras <[email protected]> writes: > >> https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm?turl=WordDocuments%2Fdisablingintelamt.htm > > > > This page is about disabling AMT : > > https://en.wikipedia.org/wiki/Intel_Management_Engine : > > The Management Engine is often confused with Intel AMT (Intel Active > > Management Technology). AMT runs on the ME, but is only available on > > processors with vPro. AMT gives device owners remote administration of > > their computer,^[6] such as powering it on or off, and reinstalling the > > operating system. > > > > However, the ME itself is built into all Intel chipsets since 2008, not > > only those with AMT. While AMT can be unprovisioned by the owner, there > > is no official, documented way to disable the ME.^[citation needed] > > > > Although it says "citation needed" , I find it unlikely that , if there was a > > way to disable the ME , someone would not have added it to the article by now. In > > any case see also > > > > https://www.techrepublic.com/article/is-the-intel-management-engine-a-backdoor/ : > > Various sources report that Intel's latest x86 chips contain a secret > > backdoor. SoftPedia cites security expert Damien Zammit as revealing that > > these Intel chips come with an embedded subsystem called the Management > > Engine (ME) that functions as a separate CPU and cannot be disabled, and > > the code is proprietary. > > [...] > > > > However, the ME contains the AMT instructions, which can function > > similarly to wake-on-LAN. That means if the right person used the ME to > > gain access to a machine, they could then take advantage of AMT and boot > > the machine. Viola! Your PC is now readily available for someone with the > > requisite skills to pick and choose what they want--this could include > > company data. > > [...] > > > > The good news is that you can disable the AMT feature. Here's how. > > > > * In the PC BIOS, go to Advance Chipset Feature | Intel AMT > > (Enabled,Disabled) > > * During boot, CTRL+P to go to AMT Menu | Intel ME Control State > > (Enabled,Disabled) > > > > There is no way to know if the ME has the ability to re-enable AMT on its > > own. Why? Because no one except Intel knows what exactly it contains. So, > > you could disable ATM on the machine and not know if the ME can > > circumvent that BIOS setting. > > It's not a "secret" enclave, as there was at least one slide > deck about the feature set. > > I've not seen a slide deck since the Wifi was added to > the more modern setups. The Intel NIC is dual-headed > (so certain NICs are needed to make it work). And it is > possible the Intel Wifi modules have dual head as well. > > http://pds4.egloos.com/pds/200706/04/57/ps_adts003.pdf If you mean the slides on the link , it's not clear to me which particular slide you have in mind. In any case , there is no precise definition of what counts as secret. One might say that , since we know that the management engine exists , it's not secret. > Since it potentially can be used for anti-theft purposes, > that's why there can't be a hardware jumper plug to > guarantee it is off. A thief would just use that. Are you saying that the management engine serves anti-theft purposes ? How ?