Gentoo Archives: gentoo-user

From: "Taiidan@×××.com" <Taiidan@×××.com>
To: gentoo-user@l.g.o, R0b0t1 <r030t1@×××××.com>
Cc: Adam Carter <adamcarter3@×××××.com>
Subject: Re: [gentoo-user] Intel ucode updates for ME issues?
Date: Thu, 23 Nov 2017 04:37:19
Message-Id: 7c071864-4249-9749-99e0-c1efff7d12be@gmx.com
In Reply to: Re: [gentoo-user] Intel ucode updates for ME issues? by R0b0t1
1 On 11/22/2017 11:16 PM, R0b0t1 wrote:
2
3 > Does anyone have more information on this? Has anything been
4 > published? I'm interested in exploiting my own computers so I can
5 > control the ME.
6 It seems that it is the same people who figured out HAP mode but they
7 haven't made a blog update I would ask on the coreboot mailinglist,
8 there are some very smart people there.
9
10 Although I doubt you will find any real information anywhere at all due
11 to the recent "white hat" tendency to restrict the real nuts and bolts
12 info and utilities to wealthy corporations instead of us peons who
13 *gasp* might do something "bad" with it/don't have lots of money to pay
14 for a "premier" support account.
15
16 I am curious as to why you wish to do this, considering you can buy a
17 libre firmware owner controlled motherboard with better functionality
18 (ex: OpenBMC) than any me/psp board for only $250 and $100 for a FX-8310
19 equivalent cpu.
20
21 On 11/22/2017 11:18 PM, R0b0t1 wrote:
22
23 > On Wed, Nov 22, 2017 at 6:03 PM, Taiidan@×××.com <Taiidan@×××.com> wrote:
24 >> Using ME cleaner would also solve the issue and you wouldn't need any more
25 >> firmware updates when the next "bug" comes around.
26 >>
27 > Intel ME has been found to remain active after being disabled, and
28 > some motherboards that do not ship as "vPro enabled" and consequently
29 > haven't had the licensing paid for certain features have been found
30 > with those same features enabled. I own an Asus laptop which is
31 > affected. Some Asus forum post reported that there's a Java-based SOAP
32 > webserver listening on the port associated with Intel ME. Intel ME is
33 > not visible to the BIOS, and so it can't be turned any more "off."
34 I understand the limitations of me_cleaner, although in this case it
35 would in fact solve the problems as all the currently *publicly*
36 discovered "bugs" are all ME feature exploits (and the features are
37 removed by me_cleaner) rather than exploits of the ME kernel although I
38 am certain that one is on the way.
39
40 Believe me I know what I am talking about, I regularly provide support
41 on the coreboot mailinglist and I own a variety of devices that are
42 owner controlled with libre firmware (and of course no ME/PSP).

Replies

Subject Author
Re: [gentoo-user] Intel ucode updates for ME issues? R0b0t1 <r030t1@×××××.com>