"unless there are vulnerabilities or backdoors in the Intel Management Engine (ME)".
There, fixed it for you.
"unless there are vulnerabilities or backdoors in the Intel Management Engine (ME)".
There, fixed it for you.
A computer is a to dangerous tool to leave it to the public without state control.
The fist one everyone gets. This one doesn't allow remote management, it is intended for internal housekeeping, plus things like emulated TPM and DRM.
The second one, which builds on top of the first one, allows management in about the same scope as any other BMC would, and it is pretty easy to avoid it - just do not purchase SKUs with vPro. For vPro, you have to pay extra, so doing that is pretty easy.
That said, I also consider vPro generally useful, though somewhat flaky and unreliable. It is also about the only way to get BMC-like functionality for desktops or laptops (hey, Intel, any plans for new NUCs with vPro?).
Wikipedia is missing such a link.
AFAIK vPro doesn't let anything talk to its management interface over the network until you actually do the local setup.
I found this out to my irritation, when I once acquired a used workstation with vPro, freshly wiped, and — thinking I could just set it up by plugging its management-network NIC into my switch and talking to it over the LAN — I found out to my dismay that it wouldn't even bother to acquire an IP address for the management interface until I enabled vPro in the BIOS and then told it to use DHCP.
(Am I wrong about this? Perhaps, do OEMs ship batches of machines with vPro pre-configured in certain ways, for clients that explicitly specify that they're going to use vPro for remote provisioning? Or does every workstation order have an implicit "unload from the pallet, plug into a KVM, enable vPro, then install at location" step?)
"I remember a story a few years past when a full line of CPU's went out with IME having no password set at all"
They describe a pretty serious snag. My experience of iDRAC/iLO/vPRO etc etc etc is that they have all had some pretty major problems.
Keep your monitoring/management interfaces on their own network/VLAN is my advice. While you are at it, get the logging and firewall rules sorted.
The closest analog to the claims that I could find in short order did mention a known AMT exploit[1] in 2017.
[1] https://www.theregister.com/2017/05/05/intel_amt_remote_expl...
You shouldn't just trust Intel that it doesn't respond to network access if you tell it to nicely.
I don't want to rehash it here, but if you look at my reply to your sibling, you'll get a better insight into my reasoning.
Basically the TL;DR version is that there are some absolutely asinine conspiracists who literally think that government agencies can extract all of their data while the computer is powered off using IME/AMT.
Obviously, there's a lot more to it, but I do agree that I don't trust Intel, and IME/AMT are dangerous.
I'd link one of the posts I ran into that made this claim, but I don't really want to give the idiots who peddle this garbage any more exposure than necessary, because they appear to be into the 5G "mind control" conspiracies as well.
No, I'm not kidding.
If by "vestiges" you mean "fringes", I find that a bit disturbing assuming you are sincere.
Whatever thought process led you to think it was an obscure conspiracy theory - did you check Wikipedia?
The third sentence of the Wikipedia page on the IME is:
"The Intel Management Engine always runs as long as the motherboard is receiving power, even when the computer is turned off."
https://en.wikipedia.org/wiki/Intel_Management_Engine
There isn't a specific source for this given, but I looked at some of the references and found this in Intel documentation:
"This interface can retrieve the current power state and change the power state of the hosting machine via commands to Intel AMT."
https://software.intel.com/sites/manageability/AMT_Implement...
There is also a link to "Black Hat 2017" given as a source for the ability to manipulate computers when they are turned off through the Management Engine.
And then, looking at your Register link, I don't see that it says anything about the capability of control when powered off.
I'm guessing you haven't encountered the conspiracists on sites like 4chan and Gab where they literally claim that you can extricate all data from the machines while powered off.
Do not underestimate the idiocy and extremism behind some of these conspiracies. They have widely stupid claims that are outright impossible, but because it's terrifying to users who don't know better otherwise, the truth gets muddied.
Yes, IME/AMT can be accessed as long as the machine has utility power. However, the machine still has to be remotely powered up to access anything else (e.g. if there were an exploit that allowed remote extrication of in-memory data loaded by the OS because, well, the OS has to be booted).
So yes, I'm well aware of this. I think the problem is that you haven't encountered some of the really wild and ridiculously extreme interpretations of this conspiracy on, shall we say, the vestigial fringes of the Internet that harbor some equally stupid notions. It's no accident that the people who think $THREE_LETTER_AGENCY can access all of your personal photos and information with your machine powered off via IME/AMT are almost uniformly also the types who think that 5G is going to instigate mind control or believe the Earth is flat.
I know of these because I regularly find it perversely amusing to debate them because I'm either stupid, crazy, or both.
It may have been disabled by the prior owner of the workstation. The servers we get come with "All management enabled, and will get an IP from DHCP" mode. There's a probability that these workstations left the factory with vPro enabled.
To be clear, are you talking about Intel AMT specifically (which I’m not really aware of being a “thing” with Xeon), or just regular server-OEM BMCs (iLO, DRAC, etc.)?
BMCs are definitely usually pre-configured. That’s part of the point of BMCs: you can rack the servers and run cable from their management NICs to the management-VLAN switches; then populate their drive bays; and then batch-provision everything at once through the BMCs (including, hopefully, setting up actual security on the BMC.)
But Intel AMT isn’t quite the same thing. (For one, vPro-badged computers don’t usually have a separate management NIC — though some do! — but rather Intel AMT usually uses the IOMMU to virtualize another NIC onto the same physical motherboard RJ45 socket. So it’d be a much worse security design to have AMT default-enabled from the factory, since that’d put new machines’ control-plane interfaces out onto your regular-traffic VLAN by default...)
And even if you actually have a backdoor on your PC, for hackers to exploit it, they somehow need to get to your local network first, which is not that easy on a home network unless your computer is the one to initiate the connection. I also probably won't work on anything but the built-in Ethernet port.
I don't know what "field day" hackers had, but I suspect it only helped them compromise corporate networks they could access where IME remote control (vPro?) was actively used. It is indeed a serious concern and warrants a recall, but I've yet to see how it can be a concern to most individuals, at least compared to OS-level attacks. And if it is, firewalls, including the simple ones in home routers should be effective.
Completely coincidentally Chris Domas managed to discover the only Intel CPU backdoor ever discovered and publicized the very same year Intel already patched it
The US government has 60,000 full time shills telling you to take your meds and stop speculating. And studies have shown that they target their chidings.
I don't shop for groceries and canned corn, I shop for groceries.
I don't listen to music and <insert artist>, I listen to music.
in fact, the way you separate them seems to indicate that you believe that backdoors are not vulnerabilities, and they absolutely are vulnerabilities.
vulnerabilities are things that make you vulnerable. undocumented backdoors definitely make you vulnerable.