[1] https://archive.org/details/bitsavers_ibmpcat150ferenceMar84...
[1] https://archive.org/details/bitsavers_ibmpcat150ferenceMar84...
Occam's razor says they really just sell a ton of CPUs to huge datacenters and wanted to solve the problem of having to have some tech go out and physically reset a machine when it misbehaves. If you've ever accidentally powered down a machine that's sitting in some lights-out facility in Northern Alabraska, this kind of technology is a godsend. Now I'm not saying I'd bet my hat that it's 100% secure, or that Intel couldn't be thumb-screwed by the feds to use it as a backdoor in some scenario, but it wasn't built from the ground up to be one.
http://recon.cx/2014/slides/Recon%202014%20Skochinsky.pdf
SPARC and Java(!) are present in this system. It gives a whole new meaning to the "3 billion devices run Java" advert...
They even changed the CPU at some point. It used to be ARC, now it's SPARC. The LOM aspect of it didn't change. It worked just fine with ARC before. So why did it change?
There is no technical reason why implementing the LOM function is easier or better with one CPU compared with another. In fact, there's no technical reason why implementing anything is easier with one CPU or some other CPU. The new CPU seems even less power-efficient than their old one. The only reason why you'd want a particular CPU architecture is if you want to run some particular code for that particular CPU. And apparently running this secret code is so important, that it was worth the huge expense of porting all the other already-existing, already-working firmware they had before.
[1] http://en.wikipedia.org/wiki/ARC_%28processor%29
[2] http://www.eetimes.com/document.asp?doc_id=1248611
[3] http://blog.invisiblethings.org/2015/10/27/x86_harmful.html
Yes, they use Linux, but, as you say, they run a bunch of other crap that's old and buggy, and the implementation of the protocol itself is not stellar.
How many bugs were found in IPMI implementations vs. ssh over the last 5 years?
We don't need IPMI, we really only need ssh, and a console that allows setting things up (like Open Firmware on RISC machines).
We don't need a new protocol for remotely accessing our machines, when we can remotely export the plain old machine console securely.
Some vendors do work the way I described, at least for their RISC offerings, although, for example, the Oracle ILOM runs some Java web server crap by default. But at least you can turn it off and use pure ssh! No IPMI.
Intel is a large company, with lots of engineers, both hardware and software, managers, marketers and project managers. Some really stupid decisions will come out of simple scope creep and someones pet project suddenly becoming the next product.
Outside of evidence of actual malevolent intention, what you have here is easily a project gone really really weird.
How do I use this technology to, say, boot my turned off but plugged in and network-connected laptop?
I mean in a legitimate way. I'd really love to see how this works (and then be horrified).
I don't get your point. If it's just about OOB management, then there are already plenty of BMC technologies out there (IPMI, ILO, ...). There is no need for AMT/ME here. Or maybe I just misunderstood how this whole thing works.