Re: Putting together a computer from old components
Spiros Bousbouras <[email protected]>
| Newsgroups | alt.comp.hardware,uk.comp.homebuilt |
|---|---|
| Organization | Aioe.org NNTP Server |
| Message-ID | <[email protected]> |
On Mon, 29 Nov 2021 20:23:46 +0000 Richard Kettlewell <[email protected]> wrote: > Spiros Bousbouras <[email protected]> writes: > > SH <[email protected]> wrote: > >> what is it about the intel management engine that creeps you out? > > > > That there is a part of the processor running secret code which has > > access to everything on the computer (memory , storage media , > > internet communications) and nothing in the software that you choose > > to run on your computer can affect this. > > You could say much the same about the CPU microcode or the platform > firmware (e.g. UEFI, or BIOS if you can find something old enough). > > > Note also that these management engines are an additional large and > > complicated attack surface which doesn't buy *me* anything. I'm not > > even sure why they're there , I mean what is the official > > justification ? > > Platform-level remote management. This applies to Intel Active Management Technology , not the management engine. > > I'd rather avoid Intel since their processors have had too many > > vulnerabilities over the years even unrelated to the management > > engine. > > How many is too many? AMD and ARM CPUs have had vulnerabilities too, and > almost certainly will have more in the future. I don't have a precise criterion. I don't keep precise statistics either but I see in the news announcements about vulnerabilities on Intel processors a lot more often that I do for AMD (not just related to the management engines). Also , en.wikipedia.org/wiki/Intel_Management_Engine mentions many more vulnerabilities than en.wikipedia.org/wiki/AMD_Secure_Technology . > In all cases I suspect > you’re more at risk from vulnerabilities in the software you run on > them. Possibly. But I don't run software I don't need and I try to use the simplest software which achieves what I need although there are other criteria than simplicity. The problem with the management engines is that they offer a large attack surface and they don't offer any functionality of use to me , at least to the extent that we know what functionality they offer. > Disabling this stuff may reduce your total risk, but not necessarily by > as much as you hope. -- vlaho.ninja/prog