Reply to post: Re: ME capability should be fused

Apple forgot to lock Intel Management Engine in laptops, so get patching

JohnFen

Re: ME capability should be fused

"The vast majority of their customers did not ask for this or utilize this, and it is astonishing to me that Intel would not provide people with a way to permanently disable it."

I'm actually very familiar with the ME and its history, so I can comment on this a bit.

Intel's largest customers (enterprises) did ask for this functionality. They needed to be able to do low-level maintenance on large fleets of PCs in a more efficient manner, and the ME allows you to do everything remotely that you can do when physically present (including replacing the operating system, etc.) This is actually a legitimate and non-nefarious use for this sort of technology.

Originally, if you wanted the ME you had to buy special versions of the CPU, and you paid a premium for it. It was not included in CPUs that were aimed at the consumer market. At some point, though, they just started putting it in all of their CPUs.

In my opinion, that was the first huge mistake Intel made. The second was ignoring all the security experts who spent years telling Intel that the ME had serious security problems. The third was (and is) refusing to actually engage in effective measures to fix the problem.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon