From 30683b65251323475f2b3b354cb9c3d320553f87 Mon Sep 17 00:00:00 2001 From: Francis Rowe Date: Tue, 28 Jul 2015 07:49:53 -0400 Subject: FAQ (ME section): links for DRM and tivoization --- (limited to 'site/faq') diff --git a/site/faq/index.php b/site/faq/index.php index a59a390..9d62da1 100644 --- a/site/faq/index.php +++ b/site/faq/index.php @@ -93,7 +93,8 @@ removed (with the ME processor permanently deactivated), but not replaced (due to cryptographic signature checking on the firmware). The management engine provides remote access capabilities, independently from the running operating system. It has full access to your RAM, and it has full networking support. It also handles the TPM module, AMT (Active Management Technology), Boot Guard and - various DRM mechanisms. The ME also performs some basic hardware initialization and power management, on recent systems. + various DRM mechanisms. + The ME also performs some basic hardware initialization and power management, on recent systems.

All modern Intel systems built after around the year 2008 (after ICH9) require this blob, and @@ -111,7 +112,7 @@ if Intel wanted to release the source code for this blob, they could not do so. Even if they did, the ME firmware is cryptographically signed, where the signature is verified at boot time. If you try to use your own modified version of the ME firmware, it will be rejected by the ARC processor and your system will not boot. In other words, - the ME firmware is tivoized. + the ME firmware is tivoized.

The Management Engine is a giant backdoor, allowing full access to your entire system for malicious adversaries. -- cgit v0.9.1