Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How is Intel ME any different in functionality than the Baseboard Management Controller usually found on servers (eg: Aspeed)? And what of those whom extend these feature sets with boards like the Raspberry Pi?


Here's the real kick in the nuts that IME does compared to BMC or other 'Management ports'.

(1) It is not something that you can (easily) disable

(2) It uses the same Network port that your LAN NIC uses instead of a separate "I won't plug that in if I don't want it" NIC.

(3) Security/Patches? This is outside the control of the BIOS manufacturer, so how do you make sure it's patched and upto date? and

(4) It wasn't an option.


Note that the BMC does not always restrict itself to the BMC port. I've worked with machines that have a dedicated BMC port, but also have a BIOS-configurable option (on by default) to let it use whatever port is connected.


Ouch, atleast it's a BIOS option.


That's a really low bar because (1) BMCs are a security nightmare because their firmware is garbage and (2) many PC owners do not need or want BMCs.

I think the ME hating is kinda strident but it has a bunch of undocumented firmware and your PC still works after you remove it so... what was that firmware doing?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: