The actual ME co-processor is still running.
The actual ME co-processor is still running.
Edit: The title has been changed again and now reads "Disabling Intel AMT on Windows". That's better and less confusing.
Now, if that's not in your threat model, then you'll probably be fine using it unless foreign adversaries are in your threat model. And the rabbit hole of how threatening are live backdoors on your network just goes on from there.
There's at least calls to remove SIGINT agency from TCG:
https://www.securitycurrent.com/en/writers/richard-stiennon/...
Why do you think Intel doesn't let users turn it off?
It would disappear from the PCI bus.
Your commands un-provision AMT (Active Management Technology), the ME feature that apparently has a security issue. Unless you've explicitly enabled AMT, it's not provisioned anyway so this doesn't do anything.
It disables the optional OS-side of AMT. How do we know that the vulnerability is in the OS-side? Has this been established yet?
Still coreboot guys are quite experts on the matter.