Use non-x86 platforms such as an ARM based Chromebook, or potentially an x86 with the ME partially disabled (coreboot or similar, but it's not a 100% guarantee).
> Plugging out the network cable?
It depends on the vulnerability scope. If it's over HECI (virtual PCI device between host OS and ME) then removing the network cable won't save you from local malware owning the ME via HECI.
> But then again the moment you plug internet back in you're done.
Well considering how few people ever update the firmware of their devices, it's unlikely a majority of computers would ever be patched against an ME vulnerability anyway.
Starting with ME12 Intel is going to start checking the ME firmware version number in the ME's silicon (read-only) boot ROM to prevent firmware downgrade attacks. [1] This version number is stored in single use eFuses which can only be incremented, and are during an ME update.
But it depends on your threat model. As stated in the PDF, there are only 3 known exploits against the ME, and only one results in unsigned code execution. Until someone weaponizes such an exploit, which at the moment it seems physical access is needed, then Intel x86 owners are safe.
If your adversary is a three letter agency or nation state attacker, then you've got bigger concerns than someone hacking your ME (starting with, say, your OS).
[1] https://github.com/corna/me_cleaner/issues/111#issuecomment-...
Or even x86 before it had ME at all, which means anything before ~Core 2 or so. AFAIK the Thinkpad x60 is one of those.
Careful there. Microsoft has been slipping PC bits into their Windows Arm systems because Windows is so hopelessly tied to the PC platform that they had to PCify their Arm with EFI, ACPI and other PC legacy junk. Just be sure your Arm does not have any of this anti-consumer crap and you should be good to go.
I used the following guide (very easy to follow): https://steemit.com/tutorial/@joeyd/run-don-t-walk-from-the-...
EDIT: You can also get a laptop with Intel ME disabled. As far as I know you can get a modern laptop without ME from System76, Purism. For a while Dell offered such machines, but that might no longer be the case.
The initialization stuff (in the BUP module) are necessary and AFAIK, nobody is suggesting that be removed.
I have not done any research recently in the success rate of ME cleaner, but it isn't that low, it usually works to the best of my knowledge, and once we have good documented statistics saying "this works most of the time" it becomes more feasible for those not directly involved in its development to start using it more proactively to get rid of this vulnerability.