System76 announces plan to disable Intel Management Engine on all of their laptops

blog.system76.com/post/168050597573/system76-me-firmware-updates-plan
blog.system76.com/post/168050597573/system76-me-firmware-updates-plan

>Proprietary code always makes life harder and Intel’s Management Engine (ME) firmware is a particularly challenging chunk of secretive software. Thanks to issues identified by external security researchers, Intel initiated an audit of its ME firmware and discovered multiple critical vulnerabilities as described in SA-00086.

>Separately, researchers at Positive Technologies discovered an undocumented High Assurance Platform (HAP) settings in Intel ME firmware. HAP was developed by the NSA for secure computing. Setting the “reserve_hap” bit to 1 disables the ME.

>In July of this year we began a project to automatically deliver firmware to System76 laptops similar to the way software is currently delivered through the operating system. We began testing the system in production on August 4th. Now it’s very near ready for laptop customers. For desktops, System76 will work on automated firmware delivery as part of our internal desktop design and manufacturing project.

>All of this has culminated in the System76 plan to address Intel’s November 20th vulnerability announcement and our ability to respond to future firmware update needs.

Other urls found in this thread:

system76.com/shipping
system76.com/cart/configure/gaze12
twitter.com/SFWRedditImages

Sounds pretty good. I'll look forward to the update.

Good luck with that, giants like Google have been trying for years without any success.

i dont care about these laptops but if it means that me can be disabled on al. computers with that flag then this is a good thing

>look up system76 laptops
>all relatively pricey and extremely ugly
Is there any proof this bit switch actually works and isn't just barrier-type bait? Then again lately the NSA and Intel both make even Sony look like masters of cybersecurity.

Yeah i'm a bit skeptical of the whole bit switch thing myself.

Okay, do they ship overseas?

If you would read their fucking FAQ you wouldn't have to ask.

Different user here who wants to know the same thing, don't be so fucking rude. Even with this news, people are not going to start giving a shit about system76 unless they do significantly better than what we already have.
Being a rude cunt doesn't incentivize us to give a shit.

They need to add more countries.

Here buddy system76.com/shipping

>Desktops
>Update all affected models with new ME firmware
>Create the “firmware” github repo structure for storing desktop firmware
>If the ME also requires a BIOS update, create customized BIOS for each model.
Anyone know what mobos they use?

I guess Clevo mobos?

Oh wait you said desktops. nevermind then.

So this and Purism and Google(albeit just for Chromebooks)

Who's next?

purism already did this

>Open website
>Tumblr, "open in app", HackerNews, Reddit
>Meme blog layout and design
This company isn't giving me a professional vibe.

i have a system76 laptop and it's great. it's a bit pricey but totally reasonable considering the specs

What are the specs?

They are a real company but yeah wtf. Why are they using tumblr?

just look at the website
system76.com/cart/configure/gaze12

That's not bad at all. I'm not interested in the idea, but yeah, that's one way of doing it I guess.

lol remember when Intel said you needed ME for their stuff to work.

Crooks, all of them.