http://www.pvsm.ru/informatsionnaya-bezopasnost/262876
(you can use Google translator from the top of the page, to translate content from Russian to English)
http://www.pvsm.ru/informatsionnaya-bezopasnost/262876
(you can use Google translator from the top of the page, to translate content from Russian to English)
On Monday, Positive Technologies researchers Dmitry Sklyarov, Mark Ermolov, and Maxim Goryachy said they had found a way to turn off the Intel ME by setting the undocumented HAP bit to 1 in a configuration file.
HAP stands for high assurance platform. It's an IT security framework developed by the US National Security Agency, an organization that might want a way to disable a feature on Intel chips that presents a security risk.
The Register asked Intel about this and received the same emailed statement that was provided to Positive Technologies.
"In response to requests from customers with specialized requirements we sometimes explore the modification or disabling of certain features," Intel's spokesperson said. "In this case, the modifications were made at the request of equipment manufacturers in support of their customer's evaluation of the US government's 'High Assurance Platform' program. These modifications underwent a limited validation cycle and are not an officially supported configuration."
We can all rest easy now that Intel has come out and public said this, right?
And this has already been added to me_cleaner [2] as --soft-disable option 2 months ago.
[1] http://blog.ptsecurity.com/2017/08/disabling-intel-me.html
[2] https://github.com/corna/me_cleaner/commit/ced3b46ba2ccd7460...