ASRock.com Homepage
Forum Home Forum Home > Technical Support > Intel Motherboards
  New Posts New Posts RSS Feed - Feature Request: Allow Disabling of Intel ME
  FAQ FAQ  Forum Search Search  Events   Register Register  Login Login

Feature Request: Allow Disabling of Intel ME

 Post Reply Post Reply
Author
Message
Beowulf View Drop Down
Newbie
Newbie


Joined: 08 Mar 2018
Status: Offline
Points: 4
Post Options Post Options   Thanks (0) Thanks(0)   Quote Beowulf Quote  Post ReplyReply Direct Link To This Post Topic: Feature Request: Allow Disabling of Intel ME
    Posted: 08 Mar 2018 at 3:48am
To summarize the issue (from this website):

"Intel's Management Engine (ME) is a completely separate computing environment running on Intel chipsets that has access to everything. The ME has network access, access to the host operating system, memory, and cryptography engine. The ME can be used remotely even if the PC is powered off. If that sounds scary, it gets even worse: no one knows what the ME is doing, and we can't even look at the code. When -- not `if' -- the ME is finally cracked open, every computer running on a recent Intel chip will have a huge security and privacy issue. Intel's Management Engine is the single most dangerous piece of computer hardware ever created."

We are all aware of the public vulnerabilities which Intel has admitted, but it's likely NSA or others have toolkits for accessing it which have not been publicized nor patched.  In the interests of privacy, it would be desirable for this spyware to be disabled. 

The ME is actually used to boot the main CPU, but all the rest of its functionality can be removed by BIOS mods, such as are described here.

However, this would likely void Asrock's warranty.  Much better would be for Asrock to step up and implement this feature themselves, via either a BIOS configuration option, or an alternative BIOS.  It would be a selling point for Asrock over its competitors to provide a secure, non-pwnable platform.

Back to Top
wardog View Drop Down
Moderator Group
Moderator Group


Joined: 15 Jul 2015
Status: Offline
Points: 6447
Post Options Post Options   Thanks (0) Thanks(0)   Quote wardog Quote  Post ReplyReply Direct Link To This Post Posted: 08 Mar 2018 at 7:48am
I can all but guarantee you ASRock nor any other motherboard manufacturer will offer a Toggle for this as a BIOS Option. Period. No arguments. Intel would NOT allow it.


Having said that, it will be up to the end user to fudge this to occur.

The link you listed has to do with connecting a Rasberry-PI ??? Really?....WTF?

See here:
http://blog.ptsecurity.com/2017/08/disabling-intel-me.html

Mind you, you proceed at your own risk and accept FULL responsibilities should things hose up.




Edited by wardog - 08 Mar 2018 at 7:49am
Back to Top
Beowulf View Drop Down
Newbie
Newbie


Joined: 08 Mar 2018
Status: Offline
Points: 4
Post Options Post Options   Thanks (0) Thanks(0)   Quote Beowulf Quote  Post ReplyReply Direct Link To This Post Posted: 08 Mar 2018 at 12:16pm
Originally posted by wardog wardog wrote:

I can all but guarantee you ASRock nor any other motherboard manufacturer will offer a Toggle for this as a BIOS Option. Period. No arguments. Intel would NOT allow it.


Intel has that much control over what BIOS options various motherboard manufacturers provide?  Sounds like a class action lawsuit needs to be filed to order the SEC to reign in Intel and stop them from restraining the free market with over-controlling licensing agreements.  Too powerful.

As evidence that resistance isn't futile, System 76 is already selling laptops with it disabled right now, and there's this from liliputing.com:

Quote
But independent researchers have recently discovered a way to disable the Intel Management Engine and companies including Google and Purism have already announced plans to do so.



Edited by Beowulf - 08 Mar 2018 at 12:22pm
Back to Top
wardog View Drop Down
Moderator Group
Moderator Group


Joined: 15 Jul 2015
Status: Offline
Points: 6447
Post Options Post Options   Thanks (0) Thanks(0)   Quote wardog Quote  Post ReplyReply Direct Link To This Post Posted: 08 Mar 2018 at 1:19pm
I'll bet my left gonad Intel tries their damnest is ceasing their practice.

Yes. Intel is notorious for stiff arming Co's that don't abide by their demands.

What's a manufacturer to do when Intel stops selling you the req'd chipsets but cease production?

They have their "ways'.
Back to Top
wardog View Drop Down
Moderator Group
Moderator Group


Joined: 15 Jul 2015
Status: Offline
Points: 6447
Post Options Post Options   Thanks (0) Thanks(0)   Quote wardog Quote  Post ReplyReply Direct Link To This Post Posted: 08 Mar 2018 at 1:30pm
Interesting System76's Lemur still has ME disabled

https://system76.com/laptops/lemur

<me> clutching my left gonad !
Back to Top
 Post Reply Post Reply
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.04
Copyright ©2001-2021 Web Wiz Ltd.

This page was generated in 0.109 seconds.