Slashdot Mirror


Purism Now Offers Laptops with Intel's 'Management Engine' Disabled (puri.sm)

"San Francisco company Purism announced that they are now offering their Librem laptops with the Intel Management Engine disabled," writes Slashdot reader boudie2. Purism describes Management Engine as "a separate CPU that can run and control a computer even when powered off."

HardOCP reports that Management Engine "is widely despised by security professionals and privacy advocates because it relies on signed and secret Intel code, isn't easily alterable, isn't fully documented, and has been found to be vulnerable to exploitation... In short, it's a tiny potentially hackable computer in your computer that you cannot totally control, nor opt-out of, but it can totally control your system."

Purism writes: Disabling the Management Engine is no easy task, and it has taken security researchers years to find a way to properly and verifiably disable it. Purism, because it runs coreboot and maintains its own BIOS firmware update process, has been able to release and ship coreboot that disables the Management Engine from running, directly halting the ME CPU without the ability of recovery... "Disabling the Management Engine, long believed to be impossible, is now possible and available in all current Librem laptops. It is also available as a software update for previously shipped recent Librem laptops," says Todd Weaver, Founder & CEO of Purism.

1 of 151 comments (clear)

  1. Re:Sigh. by gamorck · · Score: 3, Interesting

    "Preorder from $1,199"

    For a Core M, Intel HD Graphics, 8GB, 11.6" laptop.

    That's some pricey freedom.

    They don't even have a model with an Ethernet port (which makes me question what disabling the ME actually does anyway, because isn't the ME for things like OOB access?).

    Sorry, but - as always - I have to live in the real world rather than some scene out of Hackers. And if I really valued my freedom and genuinely thought things like this were the threat, I wouldn't be using any of these machines, no matter the cost.

    They don't include an ethernet port on the machines because there is no compatible hardware they can install on their devices which can be operated within Linux without requiring use of a firmware blob. As a Purism Librem 15v3 owner, I'm not quite as hardcore as Purism themselves are, so I am willing to use firmware blobs for specific devices. So instead of PureOS I run Arch. I have also replaced the 100% libre Atheros wifi hardware with an Intel module because the Atheros module had les than great performance (plus doesn't support 802.11ac). As for ethernet, I have a USB3/Ethernet dongle that I use for that purpose. Having said all that, I have used Purism's update to completely disable Intel ME on my laptop and everything is working without a hitch. I don't trust Intel ME. I'm willing to trust tiny firmware blobs for specific devices in specific cases. I'm not willing to trust an entirely seperate and unauditable system that operates independently and secretly. No sir. IME is a cancer (and PSP by extension) on modern day computing.

    To those that claim that you can disable and remove Intel ME on other laptops, so this really isn't a big deal or particularly notable. You are telling half truths. For older hardware that is certainly true. For Skylake level hardware there are no other devices that that had have or currently can have the Intel ME removed/neutralized/disabled. me_cleaner doesn't support Skylake level systems yet. In fact the Purism update process makes use of a forked version of the me_cleaner which contains changes Purism has made to accomodate their Skylake hardware. They plan on switching back to me_cleaner once all of their patches are accepted in the upstream project.

    But hey, don't take my word for it. Cruise the blogs and forums on Purism's website if you want to learn more. Don't take my word for it. Don't take anybody's word for it. Especially not Intels much less AMDs.

    --
    I love idealists not because I am one, but because they make life bearable for pragmatists such as myself.