Intel Management Engine

Daily fucking reminder:

List of Intel CPUs that have intel M.E:
>the entirety of core i5 and i7
>Haswell-WS and Kaby-lake-DT Xeons
>Celeron Nxxxx and Jxxxx series
If your CPU falls in this criteria you should be worried, you have an Intel backdoor with shit security that has ALREADY been exploited and many machines were affected
All your debotneting efforts are pointless if you are using the CPUs above
So either use ME neutralizer or change your CPU.

All Pentiums, all Xeons except above, all Celerons except above, core i3 and i9 have no Vpro, AMT or ME in them.

Other urls found in this thread:

libreboot.org/docs/hardware/#desktops-amd-intel-x86
libreboot.org/docs/hardware/#serversworkstations-amd-x86
libreboot.org/docs/hardware/#laptops-intel-x86
puri.sm/learn/freedom-roadmap/
coreboot.org/Chromebooks
docs.google.com/presentation/d/1eGPMu03vCxIO0a3oNX8Hmij_Qwwz6R6ViFC_1HlHOYQ/edit#slide=id.p
inforcecomputing.com/products/single-board-computers-sbc/qualcomm-snapdragon-820-inforce-6640-sbc
cavium.com/Table.html
en.wikipedia.org/wiki/Free_and_open-source_graphics_device_driver#ARM
github.com/altreact/archbk/issues/3
raptorcs.com/TALOSII/
nxp.com/products/microcontrollers-and-processors/power-architecture-processors
powerpc-notebook.org/faq/
embeddedplanet.com/product/single-board-computers/
lemote.com/html/product/
embeddedplanet.com/single-board-computers/processor/cavium-oceteon-ii/
sifive.com/products/freedom/
lowrisc.org/
intel.com/content/www/us/en/support/articles/000025619/software.html
downloadcenter.intel.com/download/27150
security-center.intel.com/advisory.aspx?intelid=intel-sa-00075&languageid=en-fr
security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr
mozilla.github.io/arewefastyet-speedometer/2.0//
passmark.com/products/pt.htm
twitter.com/SFWRedditVideos

Wait... the i9 doesnt? Whats the logic behind that?

That's why I ARM Chromebook :)

I thought my Xeon X5675s had IME?

Don't really know, i'm pretty surprised too, wikipedia specifies that there's no vpro or amt in i9

Nope, no vpro

I want a Samsung Chromebook pro, that's what that is right?

>ME neutralizer
What is that?

So do I just deblob my BIOS firmware with me_cleaner and then flash it back to the motherboard to burn the sucker or what?

>using amd Llano
feels comfy when it's not burning down my house

Also thinking of getting an asus c201 and librebooting it

Libreboot is good

Amd has the equivalent of intel ME, it's called AMD PSP
I'm going to check which amd CPU has it, later.

Yes but i believe me cleaner is only compatible with a small group of CPUs (i think the list is on github) so you should probably ask the devs before you flash

It's supposed to completely shut down intel ME on your CPU, not sure how good it'll work

Almost. Samsung Chromebook Plus (silver) is the ARM version. Pro (black) is the backdoored Intel model. Avoid that one.

works only with an extremely small number of computer models

Most motherboards don't support ME and the ones that do it has to be enabled.

Non-issue for 99.9% of consumers.

>Most motherboards don't support ME and the ones that do it has to be enabled.
source.

Yes, but they're all great computers

>no backdoor in i3 or i9


FUKEN KEK

u guys believe this??

>Non-issue for 99.9% of consumers.
Prove it.

I do not believe this, they definitely have ME

>using hardware with backdoors in 2017

I have a laptop with a i3-4005U and this shows up in my programs list (Translates to: Parts of Intel Management Engine)
Can I safely remove it?

Well wikipedia nor intel say i3/i9 have ME so...

>Non-issue for 99.9% of consumers.
yeah except for all the people that got their machines raped by the recent intel ME exploit
retarded tripfag

>backdoors
of course they have
>ME
not officially

This post should be enough proof that this piece of shit polish tripfag is a paid shill.

>core i5 and i7
>Listing something else than arch's

ME is in silicon you fucking moron
The point is it can be accessed while the PC is OFF
it doesn't matter what you do to ANYTHING which is affected by the computer being ON - eg drivers, software, utils, config, OS blah blah
all irrelevant.

What if Intel decided to flip FBI and ditched IME completely?
They could still charge enormous amounts of money for soon-to-be worse performance than AMD, because there's always gonna be a market for privacy.
This might be the edge they need while they get back on track with performance.

Something I'm missing?

Leaving this here again

(1/2)
Findings so far
x86:
For desktops, there's lots of C2Ds and atoms listed, but also some very nice opterons and apparently an iMac
libreboot.org/docs/hardware/#desktops-amd-intel-x86
libreboot.org/docs/hardware/#serversworkstations-amd-x86
For Laptops, you have the CD and C2D memepads
libreboot.org/docs/hardware/#laptops-intel-x86
Purism doesn't do libreboot, but their roadmap includes this as a future goal.
puri.sm/learn/freedom-roadmap/
The last AMD chip that came without the PSP is Piledriver.
VIA and Zhaoxin Semiconductor apparently also make x86 processors.

ARM:
Obviously there's a shit ton of SBCs (Olimex, Beagle, etc).
For a laptop option with an open firmware, try ARM Chromebooks.
I'm dead serious. Open it up, remove the write protection, reflash coreboot with different payload (Not seaBIOS or Depthcharge), install loonix of choice.
coreboot.org/Chromebooks
docs.google.com/presentation/d/1eGPMu03vCxIO0a3oNX8Hmij_Qwwz6R6ViFC_1HlHOYQ/edit#slide=id.p
Inforce has an SBC with high-specs and an open GPU
inforcecomputing.com/products/single-board-computers-sbc/qualcomm-snapdragon-820-inforce-6640-sbc
Cavium makes some god-tier processors. Be on the lookout for that.
cavium.com/Table.html
In general, your biggest concern with ARM is the GPU drivers.
Mali is fucked. PowerVR too. Vivante GC and Qualcomm Ardreno are fine. Broadcom VideoCore is partial.
en.wikipedia.org/wiki/Free_and_open-source_graphics_device_driver#ARM
Some anons have reported that lighter environments like XFCE are usable on stuff like Mali without the driver, but it's not ideal.
One user said he couldn't remove the ChromeOS on his libreboot C201. This github issue talks about a solution.
github.com/altreact/archbk/issues/3

people neither know nor care about this shit

(2/2)
OpenPOWER:
Raptor Engineering sells POWER9 workstations, that may soon be getting RYF certification.
They're expensive as fuck, but probably the most powerful non-botnet computers that exist. Comparable to Xeons/Epyc.
raptorcs.com/TALOSII/

PowerPC:
The company that still makes this is NXP
nxp.com/products/microcontrollers-and-processors/power-architecture-processors
Here is a project for a Libre PowerPC laptop using NXP, shooting for RYF certification.
powerpc-notebook.org/faq/
EmbeddedPlanet has several PowerPC SBCs, most using NXP.
embeddedplanet.com/product/single-board-computers/

MIPS:
The /csg/ of desktops. Lemote is a chink company that sells libre MIPS boards, using PMON firmware.
lemote.com/html/product/
A German user on this board says he is going to work with Lemote to resell their stuff.
EmbeddedPlanet also has MIPS boards with processors from Cavium with U-boot firmware.
embeddedplanet.com/single-board-computers/processor/cavium-oceteon-ii/

RISC-V:
Only SBCs here. SiFive has some.
sifive.com/products/freedom/
There's also LowRISC
lowrisc.org/

Intel are masters of slideshows.
Now that AMD joined the ME-meme it's only fitting for them to do a 180° turn, declare ME the devil and bring public attention to the issue.
You know - make people care *and* win on marketing.
It's also something fresh and topical with all the net neutrality buzz. "Protect your privacy with premium Intel Backdoorless™ experience!".

They could pull it off, we both know they could.

Yeah but knowing Intel, the processors will probably still ship with IME kek

I appreciate your efforts user :)

I have nothing to hide.

You do

your credit card details
your pictures
your browsing history
your passwords

it's gonna be painful if somebody ever happened to blackmail you with those

Lies, use the intel detection tool to detect vulnerabilities, the consumer grade cpu are fucked up too.
intel.com/content/www/us/en/support/articles/000025619/software.html

Thanks! I might start posting more threads soon for it

Apparently HEDT doesn't

Haxxor man just broght drugs and cp using your computer as a proxy, steal all your passwords and using them to do fraud with, hide cp in your computer just for the laugh, now white boy still have nothing to hide?

>Affected products:
6th, 7th & 8th Generation Intel® Core™ Processor Family
Intel® Xeon® Processor E3-1200 v5 & v6 Product Family
Intel® Xeon® Processor Scalable Family
Intel® Xeon® Processor W Family
Intel® Atom® C3000 Processor Family
Apollo Lake Intel® Atom Processor E3900 series
Apollo Lake Intel® Pentium™
Celeron™ N and J series

So, a 4810MQ is in danger? It's got all the business vPro shit as well.

Are you loyal? Can you be trusted? Can you be trusted a secret? Not being able to be trusted a secret is a sign of disloyalty.

You jest, of course. But for the others there is something to ponder: Having anything to hide is different to having anything illegal. I have nothing illegal here, so there is nothing for the authorities, so nothing to see here, go away.

use this to know:
downloadcenter.intel.com/download/27150
Go to the folder DiscoveryTool.GUI
And open Intel-SA-00086-GUI.exe

are there any oficial fixes yet?

Bump.

Id rather have an unoffical fix..

Yeah true, but I fear fucking up my cpu by doing something related to the microcode.

I did it.

show me an RCE exploit for it. show me that you can send data packets to it via ethernet or bluetooth and since all code flows through the cpu it triggers the vuln.

show me exploits that do not require me to be running the actual IME software on the machine

i'll wait

Feels good man

>show me an RCE exploit
>show me exploits
Like someone would give it to you for free.

>paranoid schizophrenic trashes $2,819.87 because of a mentall illness
I don't find this funny, you should seek help.

lol IC spends MILLIONS/BILLIONS developing these exploits and bribing people n u want Sup Forums to tell you lol

If he have the money why not?

kek

Because if he got therapy he could realize that it was a waste of money and he could put that money into a hobby that doesn't involve heavy anxiety and paranoia

You dumb fuck, it's not even about ABC agencies anymore. Theses backdoors aren't secure, as the rescent event shown us. Theses things will be used by criminals (like most of others backdoors btw, take a look at wanacry).

t. butthurted numale poorfag

t. Intel shilling NSA employee

>Whats the logic behind that?
Maybe intel is going to compete against itself so to speak, letting those who want extra security pay more.

...

There is a unofficial one, but the devs have explicitly stated that the fix might brick your computer if you dont know what youre doing.
Intel has also stated they will never make an official way to disable the ME for consumers. They have admitted that a method exists, but its for NSA eyes only.
Regarding the exploit, it has already been patched.
security-center.intel.com/advisory.aspx?intelid=intel-sa-00075&languageid=en-fr

>INTEL-SA-00075
>Original release: May 01, 2017
Thats one is old, we talking about the new one:
>INTEL-SA-00086
>Original release: Nov 20, 2017
security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr

fuck. sorry about that.

...

Well the thread seem dead, seeya later.
love you Sup Forums. Traps are gay.

>tripfag shill comes onto the board and just fucking lies
you'd blend in better without that tripcode you dumb glow in the dark

Literally everybody who uses a tripcode is a shill, they have to use them to get paid though.

bullshit, on both counts you're wrong

...

Post pics when you've received it.

>core i-anything

Guess my next upgrade will be a core 2 quad or something AMD-ish. Maybe a quad core Phenom.

Botnet-free and loving it here.

and what about AMD?
How do you know they don't hide backdoors in their hardware?

They do, and the major ARM vendors do too.
Power and SPARC are the ways to go for modern botnet-free computing.

what do you mean with Power?
And are these really the only ways to be botnet-free?

Bullshit. Run vrms

...

Sheeit, I () have Steam, Nvidia binary drivers, and EnergyXT installed. I know my shit ain't 100% free.

Just build your own cpu, motherboard, ram and gpu from 0 :DDDD

Create a thread and post all about it please!

...

Why should I care?

I'll be shitposting in guts threads as soon as it arrives

ARM™ TrustZone™ is the same kind of big brother backdoor.

Nah, Create your own thread. I saw some other guy with a POWER9 cpu get a super high score in a firefox browser benchmark test, so I think a lot of people will be interested in asking you to do bechmarks.

AMD™ has something called PSP. It's the same as Intel™ mangement engine.

Sure, I'll do that too.

>I saw some other guy with a POWER9 cpu get a super high score in a firefox browser benchmark test

I remember this, didn't the poster disappear without proof?

At least there's no (known) remote access IIRC

Yes***

Basically the 3 letter agencies secretly forced it this way. Gotta love all this free enterprise with a side of fucking freedom fries.

Fuck USA. We are the mist 2-faced nation it's really sad.

Besides that it has a sole purpose of providing remote access to unknown parties.

New AMD cpus are no good either from what I can gather...

Yeah you're right. I found his post in the archives.

Can't remeber what his score was, but it was 600 or something insane.
mozilla.github.io/arewefastyet-speedometer/2.0//

>tripfags being fags, as per usual

Has anyone noticed lower latency or microstuttering in games after disabling the ME?I know the integrated graphics cause a lot of stuttering.

Do a benchmark with PassMark and post results.
passmark.com/products/pt.htm

...

That has ARM TrustZone you stupid fuck.
It has all the same problems.

>Intel tool to detect if Intel Management Engine is a vulnerability
Am I missing something here?
Obviously it won't flag ME