Disabling Intel AMT on Windows
mattermedia.com
mattermedia.com
As others have said, it doesn't disable the ME. It merely removes OS-side support for it and resets configuration to non-exploitable state.
The ME itself remains up and running.
[1] https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20...
* To clarify - the original title of this post was something like "Completely Disable Intel Management Engine (finally!)".
How do we know that the vulnerability is in the OS-side? Has this been established yet?
Unprovisioning AMT seems to be the essential part and I am curious if the other steps serve any real purpose.
The Mitigation Guide goes on to say: "Systems that are vulnerable [...] should be unprovisioned using the tools used to initially configure them [...] As an example, the Intel AMT Configuration Utility [...]"
So ACUConfig is just an example and specifically not the Intel recommended way. OP doesn't say that.
"Systems that are vulnerable [...] should be unprovisioned using the tools used to initially configure them [...]"
Given the sheer brazenness and scope I wonder why the security folks have been so muted, what can be more important this this?
What ever the benefits of this backdoor for enterprises or any single group imposing it on all users makes it look like a fig leaf. The fact that it is done in consort with AMD and ARM can only lead to the conclusion it is some kind of a mandated NSA backdoor.
There is a huge unresolved dichotomy now of 'democracies' with governments completely and singularly obsessed with their citizens' speech. Having hundreds of thousands of government employees working on monitoring citizens and doing things like backdooring CPUs is the furthest you can get from free societies. Infact it's the opposite.
The actual ME co-processor is still running.
It would disappear from the PCI bus.
Your commands un-provision AMT (Active Management Technology), the ME feature that apparently has a security issue. Unless you've explicitly enabled AMT, it's not provisioned anyway so this doesn't do anything.
It disables the optional OS-side of AMT. How do we know that the vulnerability is in the OS-side? Has this been established yet?
Still coreboot guys are quite experts on the matter.
Edit: The title has been changed again and now reads "Disabling Intel AMT on Windows". That's better and less confusing.
Now, if that's not in your threat model, then you'll probably be fine using it unless foreign adversaries are in your threat model. And the rabbit hole of how threatening are live backdoors on your network just goes on from there.
There's at least calls to remove SIGINT agency from TCG:
https://www.securitycurrent.com/en/writers/richard-stiennon/...
Why do you think Intel doesn't let users turn it off?
For example: there's an embedded-profile JVM for running Java Card smart-card software, allowing enterprises to deploy crypto auth firmware written for smart-cards directly to the device. This avoids the need to flash, deploy, and manage hardware smart cards, while also preventing the OS from being able to introspect said software's operation. (This particular feature almost sounds like a good thing, doesn't it? It's a programmable TPM!)
What OP removed is probably some sort of OS-level agent that collects information about the system (installed software, patches, ...).
(Qualcomm's TrustZone kernel runs on a similarly limited but much better documented platform, does not run a web server, and has had a good share of vulnerabilities over the years. I see no reason to expect Intel's ME software stack to be any better.)
It has its own network stack and entirely bypasses the operating system - you cannot see it listening using netstat, you wouldn't even see the actual communication using Wireshark. It works even when the computer is off (which makes sense for an out-of-band management solution).
In the case of my Thinkpad, I had to open it up and flash the chip using the Raspberry Pi hardware over SPI bus.
Then I found out that removing the Intel Management Engine breaks Hackintosh so I ended up having to put it back.
Another alternative is flashing Coreboot/Libreboot, but this also breaks Hackintosh.
Any idea what this buys me?
Their last BIOS update was March 14. I'm hoping their next one has the new firmware.
Then again, maybe it's not actually enabled, since I didn't use the software to do so.
Intel advised me that a Linux version of the Mitigation Guide is coming - https://twitter.com/IntelSupport/status/859437569368567811
https://github.com/corna/me_cleaner
https://hardenedlinux.github.io/firmware/2016/11/17/neutrali...
To be 100% clear, I haven't tried either.
Simply no one care; not even enterprises and governments.
And even if you can mitigate hardware issues your "secure" system will be practically useless because on software layer best you can get it's PoC like CubesOS since desktop Linux is just damn insecure.
So if you want solution that actually let you have work done then you have to sacrifice something: keep important data on isolated always offline PC, get older hardware without PSP / ME (or deactivated one) for online and pray. Then always put newer untrusted hardware behind hardware firewall / VPN / etc.
In the end several completely isolated devices for different use cases give you much better practical security than one backdoor-free PC / server.
This probably won't happen for a while, though...
And it's much worse in case of PSP because first of all it's ARM IP and they wouldn't be able to change anything without agreement with them. Also after a little of Google-fu I find interesting document:
http://fileshare.arseniyshestakov.com/mirror/AMD_PSP_Briefin...
That's mirror, but you can easily find source. So AMD actually pitch it not just to governments, but also defence institutions and this is just much much worse than story with DRM.
http://www.pcworld.com/article/3111693/hardware/open-source-...
Also, I keep suggesting appealing to Intel or AMD's "Semi-Custom" business that modifies their processors or I.P. in customized ways. This undoubtedly cost millions of dollars. However, just taking out the ME or other bloat with only custom work being re-integrating proven components should be an easy job for their engineers. It's also way, way cheaper than designing an Intel- or AMD-class, x86 CPU. Maybe no patent suits either.
A company like Amazon or Google could easily pay for this to be done with their servers using enough CPU's to create the necessary volume to bootstrap sales of it. If it gets popular, Intel and AMD will likely release it as a product themselves.
It'd be nice to have something that actually disables these additional Intel "management" chipsets, across all platforms.