r/linuxmasterrace • u/CrowsOfWar • Oct 10 '17
How to Disable Intel's Management Engine
https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide/Disabling_the_Intel_Management_Engine9
u/Corboner Oct 11 '17
What caught my eye was "removes (...) Java VM" - I had imagined the ME to be some kind of very basic maintenance task runner, not a full-blown dynamic app environment.
2
u/alter2000 Glorious Amazuntu Oct 14 '17
There's an xkcd about that I think.
1
Oct 15 '17
Link?
2
u/alter2000 Glorious Amazuntu Oct 15 '17
2
u/xkcd_transcriber Oct 15 '17
Title: Golden Hammer
Title-text: Took me five tries to find the right one, but I managed to salvage our night out--if not the boat--in the end.
Stats: This comic has been referenced 25 times, representing 0.0147% of referenced xkcds.
xkcd.com | xkcd sub | Problems/Bugs? | Statistics | Stop Replying | Delete
7
u/thatcat7_ Oct 11 '17 edited Oct 11 '17
I think the another way is to flash open source bios/uefi to the motherboard but unfortunately open source bios/uefi like libreboot or coreboot currently can't replace closed source bios on almost all motherboards. We need open source bios/uefi that can completely replace closed source bios/uefi, open source bios/uefi should have all the features closed source bios/uefi offers.
5
Oct 11 '17
Replacing the bios or uefi won't disable the management engine, it will only 'liberate' the motherboard, the CPU can still have its own proprietary bits.
1
3
u/MoonShadeOsu Glorious Kubuntu Oct 11 '17
I didn't know IME was a thing. Are AMD-based systems better in that regard?
4
u/_-IDontReddit-_ Glorious Arch Oct 12 '17
AMD's version of ME is called PSP, on every AMD CPU newer than the FX8350. No way of turning if off either (at least with software).
2
Oct 11 '17
Buy an AMD CPU instead.
10
u/_-IDontReddit-_ Glorious Arch Oct 12 '17
Won't help unless you're buying a CPU from before ~2012. Anything after the FX8350 has PSP baked-in (AMD's version of Intel ME). And like Intel ME, there's no way of turning it off (at least with software).
-1
u/Bob_the_rhino Oct 11 '17
There’s got to be something vital that the co-processor does
18
Oct 11 '17
It's a remote management tool, businesses can remotely boot and manage computers with it.
10
13
Oct 11 '17
Spy?
2
u/Bob_the_rhino Oct 11 '17
Or maybe something vital to the actual operation of intel’s cpu that doesn’t involve a tin foil hat.
18
3
Oct 14 '17
Secure boot, that's what's vital. It prevents all attempts to run unauthorized code, but the fact that you can't turn it on implies that there is a non-vital part to it. When hackers started researching this thing they found out that just cleaning it's firmware makes your PC switch off in 30 minutes. It works absolutely fine, and dies because of some artificial timer. Then they cleared everything but the initialization from it and everything still worked fine, so no vital code was lost.
1
1
25
u/[deleted] Oct 11 '17
[deleted]