The problem is not only that this co-processor is running it's own operating system with full unrestricted access to the systems main memory and network interface, but also that the main processor can't actually tell what the co-processor is doing with this data or when does it access it, on top of that both Intel and AMD delivers you the software running on the co-processor as a binary blob so we can't really be sure if it's secure, has backdoors, spying on you, etc..
LibreBoot/Coreboot are projects to write an open-source BIOS for x86 hardware, and since a big part of the BIOS is running on this co-processor you only have a choice of either using the binary blob provided by Intel/AMD or lose the functionality provided.
The Intel Management Engine will make a lot of tinfoil hats tingle: http://hackaday.com/2016/11/28/neutralizing-intels-managemen...
Libre-boot and coreboot promote a kind of transparency where you know what your system is booting and why.
It's much better than having this proprietary walled garden with astounding amounts of power/control inaccessible to anyone but Intel in your machine.
Intel would of course argue that this is necessary for good crypto and it's for the users, not against them. Which may hold true a little bit....until it's compromised by someone.
The first would probably require replacing lots of purchased code with code that can be disclosed, and doing a full security audit of the remaining code.
The second would require separate SKU's and validation for consumer vs business use.
The first would benefit enterprises too by replacing the current "security by obscurity" scheme with auditable security, so that's where we should probably focus our lobbying.
Providing hardware documentation and a way to flash the firmware is enough. This shouldn't put AMD in front of significant problems.
This is (as far as I know) only one use-case. Another one (that makes Hollywood drool) is implementing DRM.
Hardened? Have you tested it? This feature relies on obscurity for it's "security".
> all attacks
Also, stating that anything could be secure against "all" attacks is the kind of hubris that encourages complacency.
> independent operating system
That OS is monoculture[1], greatly increasing the utility of an exploit.
> even if those machines have been compromised
Only if you assume the builtin OS is magically secure. Intel/AMD have had many bugs in their products in the past.
[1] really a small set of monocultures