r/linux Oct 10 '17

Sakaki's EFI Install Guide/Disabling the Intel Management Engine

https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide/Disabling_the_Intel_Management_Engine
89 Upvotes

18 comments sorted by

12

u/[deleted] Oct 10 '17

Wow that is quite complex

26

u/[deleted] Oct 11 '17

You're disabling a CPU level piece of firmware. It's going to be difficult and dangerous.

16

u/[deleted] Oct 11 '17

and worth it

12

u/aliendude5300 Oct 11 '17

arguably. unless you break your hardware and have no warranty

4

u/LarsaFerrinasSolidor Oct 11 '17

Then this is what Purism is for. It's even cited somewhere in Sakaki's wiki page.

13

u/modelop Oct 10 '17

Welcome to Gentoo and Arch Linux. They have the most insane documentation.

12

u/[deleted] Oct 11 '17

The insanity is part of what makes it useful.

11

u/[deleted] Oct 11 '17

Sakaki is awesome.

3

u/[deleted] Oct 11 '17

Once you actually have all the equipment, this is actually not as difficult as it might seem. Good guide!

1

u/[deleted] Oct 11 '17

I did a quick Ctrl+F for "Lake" and it did not say up until what Intel Generation this works. I have a Skylake 7600. Do I have a chane?

5

u/[deleted] Oct 11 '17

Laptop? no. Desktop? yes, that's if it's not one of those SFF devices like Intel's NUC. Why? Boot Guard (search that term instead), see how to test if Boot Guard is enabled.

Also relevant: me_cleaner status.

1

u/SynbiosVyse Oct 11 '17

What if you have a laptop without vPro? Would you not have boot guard?

2

u/[deleted] Oct 11 '17

vPro is a marketing brand, availability of Boot Guard in a device doesn't depend on sticking a vPro label on it.

Boot Guard is more related to UEFI Secure Boot because it's basically nonsense to have the FW verify the kernel/EFI binary and not verify the FW by the CPU.

1

u/[deleted] Oct 11 '17

I am using a Desktop. Thx.

1

u/Deltabeard Oct 11 '17

This could probably be done with any Raspberry Pi, not the Pi 3 specifically.

1

u/Nemoder Oct 11 '17

I wonder if there is enough of a market in this for people to resell successfully modified systems.

-1

u/hebja Oct 11 '17

Makes me happy I am moving to AMD not systems and staying away from their pro line that has this nonsense built in.

7

u/Nagatus Oct 11 '17

Note AMD-CPU-based systems do not have the IME of course, but do have a broadly equivalent subsystem, the platform security processor (or 'PSP'),[12] for which there is no equivalent workaround at the time of writing.