Intel vPro CPUs have a web server open
mastodon.lilysthings.org
mastodon.lilysthings.org
> Remote Manageability
> Remotely power up, update, and repair PCs outside of the firewall, even if they’re out-of-band1, to help your users from virtually anywhere.
https://www.intel.com/content/www/us/en/now/itheroes.html
> With features like hardware-level remote keyboard, video, and mouse control (KVM)1 3 Intel AMT allows you to discover, repair, and help protect networked computing assets as easily as if working in person.
https://www.intel.com/content/www/us/en/architecture-and-tec...
Morale of the story here seems to be to actually bother to spend 5 seconds figuring out what you bought?
Instead of aimlessly searching the doc if you know it exists you can just search for it and find some documentation which appear way more interesting: https://software.intel.com/sites/manageability/AMT_Implement...
And the author is quite happy with the feature, appeared he just wanted to advertise it:
> yeah... I will say though. I used this laptop as a server for a bit and it was so so useful.
I mean how else does any remote management solution work? This is no different than IPMI?
Seems messy regardless. Just having it be a passive server is much simpler as it never needs to care how the packets got routed to it, it just responds in kind
Are you sure you're not actually talking to some Windows service?
EDIT: From reading further in the Twitter thread, it is indeed a Windows service you're talking to.
[1] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin...
If it's already enabled, the management engine is a separate computer tapping your network connection, no software install needed.
Nowadays I'd probably turn it off and use pikvm instead, though.
The internal web server shown here lets you configure AMT, disable it if you wish, etc.
https://en.wikipedia.org/wiki/Intel_Active_Management_Techno...
It's bad if you don't know it's on because it lets you remotely access pieces of the computer you normally need physical access for like accessing the preboot environment.
The CPU/chipset has an integrated keyboard/video/mouse (via VNC), serial console, power control (on/off) and some settings exposed via this webserver over some kind of XMLRPC.
It is activated either by configuring it locally through the BIOS or some special key combination at boot, or when connecting to a network that has a setup server with a special certificate (not really a security feature, just a money grab) present. Some vendors might also ship it always-on. Network can be either wired or WiFi, not sure about mobile networks.
The threat is extreme, hidden remote access, several known vulnerabilities in the past in e.g. the broken XML parser, activation and takeover via brief physical access at boot (press the magic key, set username and password, boom, it is not your machine anymore) or connecting to a network with a magic setup server and certificate (corporate WiFi might do this accidentially to your machine). No good consistent and easy way to deactivate or prevent, it is different for each generation and vendor unfortunately, if at all possible.
Eh? https://software.intel.com/sites/manageability/AMT_Implement...
Eh! Read what your link says:
> Beginning in Release 12.0, it is possible to globally disable Intel AMT.
It took them 12 versions to put in an off-switch, so only newer hardware even has one. And:
> Intel AMT can be disabled using one of the following methods: Through the MEBX menu: Make sure that Manageability Feature State is disabled, then open the MEBX menu and change the Intel ® AMT option to Disabled. This option can only be reenabled after a reboot.
That only works if your hardware vendor exposes the MEBX menu, which not all vendors do.
> Through an MEI command invoked by OS software: Invoke the CFG_DisableAndClearAMT MEI command.
For that AMT has to be already enabled and configured in the operating system.