Re: Putting together a computer from old components

Spiros Bousbouras <[email protected]>
Newsgroups alt.comp.hardware,uk.comp.homebuilt
Organization Aioe.org NNTP Server
Message-ID <[email protected]>
On Mon, 29 Nov 2021 20:23:46 +0000
Richard Kettlewell <[email protected]> wrote:
> Spiros Bousbouras <[email protected]> writes:
> > SH <[email protected]> wrote:
> >> what is it about the intel management engine that creeps you out?
> >
> > That there is a part of the processor running secret code which has
> > access to everything on the computer (memory , storage media ,
> > internet communications) and nothing in the software that you choose
> > to run on your computer can affect this.
> 
> You could say much the same about the CPU microcode or the platform
> firmware (e.g. UEFI, or BIOS if you can find something old enough).
> 
> > Note also that these management engines are an additional large and
> > complicated attack surface which doesn't buy *me* anything. I'm not
> > even sure why they're there , I mean what is the official
> > justification ?
> 
> Platform-level remote management.

This applies to Intel Active Management Technology , not the management
engine.

> > I'd rather avoid Intel since their processors have had too many
> > vulnerabilities over the years even unrelated to the management
> > engine.
> 
> How many is too many? AMD and ARM CPUs have had vulnerabilities too, and
> almost certainly will have more in the future.

I don't have a precise criterion. I don't keep precise statistics either but
I see in the news announcements about vulnerabilities on Intel processors a
lot more often that I do for AMD (not just related to the management engines).
Also , en.wikipedia.org/wiki/Intel_Management_Engine  mentions many more
vulnerabilities than  en.wikipedia.org/wiki/AMD_Secure_Technology .

> In all cases I suspect
> you’re more at risk from vulnerabilities in the software you run on
> them.

Possibly. But I don't run software I don't need and I try to use the simplest
software which achieves what I need although there are other criteria than
simplicity. The problem with the management engines is that they offer a large
attack surface and they don't offer any functionality of use to me , at least
to the extent that we know what functionality they offer. 

> Disabling this stuff may reduce your total risk, but not necessarily by
> as much as you hope.

-- 
vlaho.ninja/prog
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.