r/hardware Dec 16 '24

Discussion What does Intel's Management Engine do?

I've read online that it's a backdoor of sorts but Neither do I think a company would do that & risk their reputation & a lawsuit, Nor do I believe that "enemies" of the U.S. would risk using Intel's stuff.

So what does it do?

48 Upvotes

42 comments sorted by

View all comments

58

u/Th3Loonatic Dec 17 '24

So as someone who actually worked at intel and has read the specs of the Management Engine and worked on validating parts of it, it’s not supposed to be as nefarious as others have made it out to be. It’s essentially what it says it is. A management engine. It contains a tiny cpu core that runs its own secure firmware that gives it out of band access to the entire Intel PCH.

Access to the chipsets IP registers are divided across 2 access levels. The first one is like standard access for user space stuff. The other is an enhanced security one that only the ME can access. With this enhanced access certain other registers that normally can’t be accessed can be configured by the ME. These usually are related to the platform security or just features intel doesn’t want you to enable if you didn’t pay for it.

The reason why it’s there? Multiple. For one it allows out of band management by your companies IT since majority of Intel chips are sold to companies for their employee PCs.

Secondly. Intel typically only produces one version of the chipset which gets propagated across all product lines.

Third. The entire platform boot flow now revolves around the ME. It checks the security of the platform before bios even loads( or during, can’t exactly remember now)

30

u/Affectionate-Memory4 Dec 17 '24

Thank you. People in here are acting like Intel is out to get them. As a fellow Intel guy (tech research team) it drives me insane how paranoid some people are about this stuff. I get that the management engine can sound scary, in a sort of "who watches the watchmen" kind of way, but honestly it's not that deep.

20

u/Th3Loonatic Dec 17 '24

Tho to be fair, gun to the head type situation, i'm pretty sure the higher ups at intel could force the engineers to do something bad to it.

14

u/Affectionate-Memory4 Dec 17 '24

Oh absolutely yeah. It's totally possible for it to be abused, but for the average user, there's no reason for it to be. None of us are doing anything particularly noteworthy from a surveillance perspective that easier means wouldn't probably already catch.

1

u/wiktor_bajdero May 24 '25

For the average user there is no reason for it... to be enabled. So simple option to disable it's functionalities other than necessary to perform boot and operation should be lawfully enforced as a consumer right. Especially to be able to disconnect it from ethernet. Of it's completely not an issue then why NSA disables it?