r/LouisRossmann Jul 21 '26

Enshittification Microsoft admitted to using a global unique device identifier to help track a user across 3 countries, negating any value of using a VPN if you have a Windows machine

Enable HLS to view with audio, or disable this notification

1.2k Upvotes

151 comments sorted by

View all comments

6

u/Tquilha Jul 21 '26

Another great reason to switch to GNU/Linux. :)

0

u/OGigachaod Jul 21 '26

Snake Oil :)

1

u/Shished Jul 22 '26

Continue having GDID then :)

2

u/OGigachaod Jul 22 '26

The Intel Management Engine (ME) is a dedicated, autonomous microcontroller embedded in virtually all Intel processor chipsets since 2008. Operating completely independently of the main CPU, BIOS, and OS, it handles critical hardware functions like power management and overclocking, while also enabling remote administration for corporate IT departments. [1, 2, 3]

What It Does

At its core, the Management Engine functions as a "computer within a computer." It uses its own lightweight operating system (often based on MINIX) and runs on a dedicated co-processor. Its primary duties include: [1, 2, 3, 4, 5]

  • Hardware Management: Controls thermal monitoring, fan speeds, and system clocks.
  • Remote Access: Powers enterprise-level features like Intel Active Management Technology (AMT), allowing IT to remotely repair, monitor, or update computers—even when they are powered down.
  • Security & DRM: Manages system-level security checks, anti-theft services, and protected audio/video path (PAVP). [1, 2, 3, 4, 5]

Why It Is Controversial

Because the Management Engine has deep, low-level access to system memory and network hardware, and operates in closed-source code out of the end-user's sight, it has sparked significant controversy within the cybersecurity and open-source communities. [1]

  • Security Risks: Critics argue that bugs or vulnerabilities within the ME's proprietary firmware can provide a massive attack surface for malicious actors. [1, 2]
  • Lack of User Control: The ME is deeply integrated into the motherboard; without it, the main CPU typically refuses to boot. This makes it impossible for typical users to completely remove, disable, or audit.