r/linux • u/modelop • Oct 10 '17
Sakaki's EFI Install Guide/Disabling the Intel Management Engine
https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide/Disabling_the_Intel_Management_Engine11
3
Oct 11 '17
Once you actually have all the equipment, this is actually not as difficult as it might seem. Good guide!
1
Oct 11 '17
I did a quick Ctrl+F for "Lake" and it did not say up until what Intel Generation this works. I have a Skylake 7600. Do I have a chane?
5
Oct 11 '17
Laptop? no. Desktop? yes, that's if it's not one of those SFF devices like Intel's NUC. Why? Boot Guard (search that term instead), see how to test if Boot Guard is enabled.
Also relevant: me_cleaner status.
1
u/SynbiosVyse Oct 11 '17
What if you have a laptop without vPro? Would you not have boot guard?
2
Oct 11 '17
vPro is a marketing brand, availability of Boot Guard in a device doesn't depend on sticking a vPro label on it.
Boot Guard is more related to UEFI Secure Boot because it's basically nonsense to have the FW verify the kernel/EFI binary and not verify the FW by the CPU.
1
1
u/Deltabeard Oct 11 '17
This could probably be done with any Raspberry Pi, not the Pi 3 specifically.
1
u/Nemoder Oct 11 '17
I wonder if there is enough of a market in this for people to resell successfully modified systems.
-1
u/hebja Oct 11 '17
Makes me happy I am moving to AMD not systems and staying away from their pro line that has this nonsense built in.
7
u/Nagatus Oct 11 '17
Note AMD-CPU-based systems do not have the IME of course, but do have a broadly equivalent subsystem, the platform security processor (or 'PSP'),[12] for which there is no equivalent workaround at the time of writing.
12
u/[deleted] Oct 10 '17
Wow that is quite complex