Slashdot Mirror


Dell Begins Offering Laptops With Intel's 'Management Engine' Disabled (liliputing.com)

An anonymous reader quotes Liliputing.com Linux computer vendor System76 announced this week that it will roll out a firmware update to disable Intel Management Engine on laptops sold in the past few years. Purism will also disable Intel Management Engine on computers it sells moving forward. Those two computer companies are pretty small players in the multi-billion dollar PC industry. But it turns out one of the world's largest PC companies is also offering customers the option of buying a computer with Intel Management Engine disabled.

At least three Dell computers can be configured with an "Intel vPro -- ME Inoperable, Custom Order" option, although you'll have to pay a little extra for those configurations... While Intel doesn't officially provide an option to disable its Management Engine, independent security researchers have discovered methods for doing that and we're starting to see PC makers make use of those methods.

The option appears to be available on most of Dell's Latitude laptops (from the 12- to 15-inch screens), including the 7480, 5480, and 5580 and the Latitude 14 5000 Series (as well as several "Rugged" and "Rugged Extreme" models).

Dell is charging anywhere from $20.92 to $40 to disable Intel's Management Engine.

4 of 140 comments (clear)

  1. DIY by Anonymous Coward · · Score: 3, Interesting

    So in theory, it doesn't matter if you order one of these 'Custom Order' editions? You'll be able to apply the exact same changes yourself?

  2. "Disabled", not disabled. by Anonymous Coward · · Score: 5, Interesting

    Does anyone trust Intel or Dell (or AMD or anyone else) enough at this point to actually believe that the chip is disabled? Or that it won't just be magically re-enabled the first time you log in to the machine? How can anyone independently verify that the chip is actually disabled and stays that way?

    We need to move back towards more open hardware and things like physical switches to turn devices on and off, DIP switches to configure hardware, and on-board fuses that can be permanently blown to disable things you don't want. Oh, and mainboards/CPUs/chipsets that don't have this deep-state backdoor bullshit built-in in the first place.

    None of this shit should have EVER found its way into consumer-grade hardware. EVER. The out of band management hardware should only have been able to be ordered on enterprise grade servers. This is really the only valid use case for this kind of technology. I've worked in a number of large corporate environments, and never once has the ME/vPro shit even been used on desktop PCs. Build it in to the servers that need it, and if a company really NEEDS it for their desktop support method, then it should be a special order.

    Until it's physically gone from the board, you can bet it's never going to be permanently disabled.

  3. From the start this was a problem by TheReaperD · · Score: 4, Interesting

    Well, its a start, at least. With a little luck, maybe vendors will get the message that we don't want this black box privacy invading systems in our computers. I remember when Intel had us over to show off their latest and greatest and they were just gushing with pride over this system. I asked them then about the potential privacy and security problems and all they could answer with is don't worry, it will be the most secure system ever made. Like I haven't heard that a million times with the same result. After that, I was just treated like the party buzzkill.

    --
    "Be particularly skeptical when presented with evidence confirming what you already believe." -
  4. Re:For people with a life... by dissy · · Score: 3, Interesting

    Most of that is simply false, and I have proven it myself with HP Compaq, EliteDesk, and EliteBook hardware.

    You don't need access inside a network or on the physical machine, it has been proven to "call home" and receive orders much as botnets do, over unblocked HTTP requests.

    Etherial shows nothing except ARP traffic while powered off, or powered on in any mode but provisioning mode.
    In provisioning mode Etherial shows two TCP connections to my provisioning server, and neither are HTTP.

    You can't stop it if it is plugged into a network

    Until ME is enabled, it doesn't even perform ARP requests let alone is capable or tries to send packets anywhere.

    and all of the benefits you listed already existed in other forms which didn't require a massive multi-million-dollar engineering effort to stick inside the chip undetected for years.

    It was never hidden in the chip, you just didn't bother reading Intels documentation, which was publicly available on Intels website since before vPro and ME hit the market.

    Yes management cards were available before, but they are equally closed source and not auditable, and cost extra per PC to deploy.

    If it were legitimate it would have been public knowledge from the start,

    Which is has been.

    https://software.intel.com/en-us/articles/intel-active-management-technology-start-here-guide-intel-amt-9
    https://www.intel.com/content/www/us/en/software/setup-configuration-software.html

    Documentation goes back to 2008 when vPro, the software containing ME, was released.

    not a secret projects the alphabet agencies recruited hardware developers for, required top secret clearance to undertake within the Intel team working on it, etc.

    Any evidence for that claim? Other than Intels own website and documentation that disproves it was "secret"?

    The justifications for the existence of it are like the shills

    Oh, damn, wish I saw that sooner before actually providing you with facts you don't care about.
    Yes, I use technology, that makes me a shill by your definition.
    Continue on with your fantasies, I'll stop ruining them.