#intelme — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #intelme, aggregated by home.social.
-
Writen using #FreeBSD on #thinkpad t460
What's good:
* No system load at all! All feels logical and snappy
* Good pkg system, I like the tips after package install
* Solid installer, base image is only 500MB (~150MB compressed)What's bad:
* Screen brightness control does not work out of the box
* Reading SD cards can be pain due poor exfat and SD-slot support
* Takes significantly longer to bootNeutral:
* WiFi seems more stable, but I still accidentally need to restart networking
* MATE style comes very basic, looks good after installing theme
* No(?) SafeEyes package, WorkRave is way more annoying
* unfortunately, @delta chat is not in packages due electron toolchainAlso; I went trough hell updating lenovo #firmware, which is only
supported on wingdows (g intended) so I have experience to compare.Sadly, lenovo does not support firmware updates for my laptop anymore.
Interestingly #IntelME firmware for t460s laptop seems to work.!
This Is probably my 100th post <3
! -
After preparing the modified image with
me_cleaner, the next step was flashing it. Only the ME region should be written back, leaving the rest of the BIOS untouched. WithFPT, this is done using a specific command-line option that limits the operation to that region.Some motherboards have an
FDO(Flash Descriptor Override) jumper that temporarily unlocks ME access. On this board, the jumper had to be shorted during flashing; otherwise,FPTrefused to write. It is unclear how the manufacturer’s own tool was able to flash ME before, possibly through another privileged path.After the modified ME firmware was successfully written, the system rebooted normally. It worked fine as long as the
FDOjumper stayed shorted. Once the jumper was removed, the next boot showed a HECI error on the POST screen, requiring a manual confirmation with F1. Re-enabling the jumper made the error disappear again. -
On most boards, BIOS and ME regions are protected in different ways. The first layer of protection is cryptographic signing, but there are also hardware-level locks. Some chipsets use special BIOS variables called Protected Range Registers that completely disable writes to certain regions.
In other cases, the board must be switched into a special state called manufacturing mode before flashing is allowed. How this is done depends on the board — sometimes through a hidden jumper, sometimes through an internal setting.
Working around these protections safely requires reading the exact documentation for the board and the chipset. The same method rarely works twice.
On my board, the Intel ME firmware is generation 8.x, which is supported by
me_cleaner. The manufacturer provides BIOS and ME together in a single image, some_cleanercan process it directly.The
FPTtool also supports the flash chip used here. That makes it possible to dump and reflash only the ME region, leaving the rest of the BIOS untouched. -
🔋 Disabling the Intel Management Engine (ME) leads to battery draining in suspend mode due to modern standby (S0ix). In this guide, we will workaround this issue by setting up a suspend-then-hibernate policy.
https://novacustom.com/prevent-battery-draining-while-suspending-with-me-disabled-linux/
-
Enabling Intel AMT For BIOS-over-WiFi - Intel ME, AMT, SMT, V-Pro… All of these acronyms are kind of intimidating, all we ... - https://hackaday.com/2024/01/05/enabling-intel-amt-for-bios-over-wifi/ #intelmanagementengine #managementengine #computerhacks #securityhacks #intelamt #intelsmt #spiflash #intelme #intel #bios #uefi #ime #rom #me
-
My colleague's put together a collection of #Linux commands you can use to check the hardware and firmware on your machines, including #SecureBoot, #UEFI, #BIOS, #IntelME, #TPM, and more.
Bookmark for reference!
https://eclypsium.com/blog/linux-commands-to-check-the-state-of-firmware/
-
We try our best to bring back privacy, security and an eco-friendly life by setting up refurbished and secure laptops with Intel ME disabled! You can support us by purchasing a monocles laptop on https://store.monocles.eu/produkt/monocles-book-1/
Or wait for our instructions on how to flash our modified BIOS/UEFI and disable Intel ME yourself (Sidenote: You need technical knowledge and special devices to disable Intel ME).
(Part 4/4) -
Read more about it in the public wikipedia article:
https://en.m.wikipedia.org/wiki/Intel_Management_EngineThere you will also find mentioned monocles for commercial ME disablement: https://en.m.wikipedia.org/wiki/Intel_Management_Engine#Commercial_ME_disablement
(Part 3/4) -
::: System76 developers have managed to DISABLE Intel ME? (A backdoor) :popos:
It is recently claimed that System76's Coreboot open firmware manages now to disable Intel ME for Raptor Lake processor.
Are they on to something bigger towards the realm away from Intel's "Big Brother" practices?
This could be huge in near future! What do YOU think?
=> https://blog.system76.com/post/major-updates-for-system76-open-firmware-june-2023
#System76 #Coreboot #Intel #ME #IntelME #privacy #backdoor #microkernel #microcontroller #Linux #CPU #processor
-
System76 Open Firmware update disables Intel Management Engine on most of the company's Linux laptops. There's also now an option to enable/disable Secure Boot and TPM2 on models with 13th-gen Intel chips and other changes. https://blog.system76.com/post/major-updates-for-system76-open-firmware-june-2023
#System76 #IntelME #IntelManagementEngine #Firmware #Coreboot #firmware
-
Some Backdoors Discovered In Hardware (Some Legitimized)
Watch Video: On Peertube
#News #Asus #Backdoors #Peertube #Infosec #Cybersecurity #IntelME #Video #Gigabyte #Motherboards #Firmware
https://tube.tchncs.de/w/1mNkBdxTQxx1hKcskARPVD -
Intel debug feature enables high severity bug, potential to read encryption files. From 'blacklisted' group 'Positive Technologies', (who brought you the HAP bit solution to disable Intel ME) #Infosec #Intel #Encryption #News #IntelME #PositiveTechnologies https://threatpost.com/intel-processor-bug-encryption-keys/176355/
-
Hat jemand von euch das #onenotebook #onegx1 (pro) ? Wie sind so eure Erfahrungen? Kann man es beim Surfen und co auch ohne dass der Lüfter angeht betreiben? Ist die #intelme abschaltbar?
-
@tuxedocomputers for me one of the most notable features is that i can deactivate the #intelME on your current product line x) i think for all geeks on mastodon this is just awesome
-
@andoluca perdón, debí decir privilegios en el anillo cero, que es por debajo del kernel del OS. Si entendes inglés, podes ver más del Intel ME en esta charla de hace unos años: https://media.ccc.de/v/32c3-7352-towards_reasonably_trustworthy_x86_laptops #intel #rootkit #intelme
-
I paid for the whole cpu let me use the whole cpu #opensourcemicrocodespecs #PSP #IntelME