Need to maintain crypto keys for SGX enclave memory? Do it in the ME. Need to do some extra stuff on suspend/resume? Do it in the ME. Not sure if any other special handling might require updates at a later date? Do it in the ME. ...
There's no need for nefarious purposes to explain why the ME isn't optional anymore - it's just more convenient.
Need to monitor/hack the computer when the users think it is "power off", Do it in ME.
Need to add other "features" to the system in the future, Do it in ME.
Ignoring the security concerns, the remote access, imaging, etc, are actually pretty nice. Better done than most 3rd party IPMI implementations.
If it were open and documented , and able to be turned off, it has value.
>Based on the items identified through the comprehensive security review, an attacker could gain unauthorized access to platform, Intel® ME feature, and 3rd party secrets protected by the Intel® Management Engine (ME), Intel® Server Platform Service (SPS), or Intel® Trusted Execution Engine (TXE).
It seems like there's a reasonable chance of that being the case.
[1] https://security-center.intel.com/advisory.aspx?intelid=INTE...
The things for which you actually want a backdoor in your server to control it from. Maybe even in the face of an attacker who has gained full control of both software and hardware.
A) Trust their employees
B) Respect my privacy
C) Aren't paternalistic
Why are people buying their products?
Anyway, I see some value in the features that ME provides, and so I'm not as anti-ME as a lot of the commenters on here. But obviously, I want the security bugs to be fixed too.