If/when someone manage to conpromise those, they can basically take over your computer, and Intel/AMD doesn't provide any sort of killswitch or physical way of disabling it.
It can be used for 'out of band' management of your system, including firmware/bios rollouts and updates. Allows remote hijacking of attached hardware devices. Basically can puppeteer your entire system.
> why can't we do anything about it?
Because there is no ability to update or modify this code. It is only updatable by the hardware vendor as it is encrypted, signed and checked during update.
As someone could in theory cobble together an HDCP compliant rig and good heavens, might be able to intercept and decode HD content!
So much of what makes the tech giants so lucrative is that they act as centralization points for industry level orchestration of what user behavior to support.
You can bet that if an industry working group is stoked, there's likely hidden in there somewhere an implementation detail intended to curb an undesirable user freedom or general capability.
(sure the code could still do nasty stuff like facilitate tempest or other sidechannels, but that's leaps and bounds ahead of the built in assumed-RCEs of ME/PSP).
As if that even matters - pointless standard. can't think of any content that there isn't a torrent up hours after it's available lol
Problem is (temporarily) solved :D
For example, for $4k, you can get this with specs roughly equivalent to a normal developer machine: https://www.raptorcs.com/content/BK1SD1/intro.html
[0] https://www.winehq.org/pipermail/wine-devel/2019-February/14...
I bought two of these last year and they're great, stuff your own memory in there, add some storage and off you go.
Edit: clarified that this would be a mainboard + CPU.