If you consider NSA or similar agencies a problem then you are in a world of pain anyway and using an entry level guiding blog post is certainly not appropriate.
For everyone else, this puts already quite a big defense layer to your arsenal even if not unhackable in absolute terms.
>The post is still somewhat valuable, but should really not use "trustworthy."
The posted article is dealing in absolutes, not me.
The ME has had many security vulnerabilities and probably more to come. For an appliance some old CPU might be good enough, but it does not get security updates. Some claim the ME might contain a NSA backdoor. That the ME can do networking certainly doesn't give confidence. The US government can order CPUs without ME, but nobody else can. Does not raise confidence either.
Trustzone is a secure execution environment, mostly isolated from normal CPU operation. Wasn't it so that it cannot even access main memory???
ME is really more privileged than the CPU?
I have not heard about Trustzone doing networking. But ME can supposedly do even WLAN while the CPU is not running.
Disclaimer: I am not a hands-on expert at that level, more like an armchair pilot...
On top of that, it is well known that governments research or buy 0-day hardware and software vulnerabilities and keep them secret to be used as weapons.
ME is just a fraction of the attack surface. When I read the title of the article I thought "trustworthy" was about mitigating hardware vulnerabilities.
At this stage it's practically impossible. :(
So you need to trust Microsoft for the first keys :)
[1] Every machine I've ever had access to has. If anyone has an x86 machine with a Windows 8 or later sticker that implements secure boot but doesn't let you modify the secure boot key database, I have a standing offer that I'll buy one myself and do what I can to rectify this. I just need a model number and some willingness on your part to chip in if it turns out you were wrong.
https://github.com/Foxboron/sbctl
It should hopefully end up being an improvement on efitools and sbsigntools. Tried posting about this on HN but somehow it's a topic with little to no interest, strange world!
However, they all do have the option to disable Secure Boot entirely (and you get a permanent red boot screen for the privilege).
You can make it difficult but defeating an attacker who can touch the hardware is for all intents and purposes impossible.
edit I found that Microsoft did the smart thing like Sony did with the original PS3 and allowed people to run their own code (but not XBox games) on their consoles, removing a large incentive for people hacking the console.
That doesn’t automatically make the security watertight though.