Intel ME Neuter vs. HAP Bit Switch vs. RISC-V vs. ARM (Rockchip)

How can someone really verify this? If you can run commands on the Minix based OS, how do you run them? If you do have a way to run them, what commands do you run? If instead you run a binary that talks over the HECI/PECI, have you considered that taking what the Minix based system responds with over the HECI/PECI is rather naive?

Have you ever had a binary you compiled yourself successfully execute and run on the processor the Minix based OS runs on? Have you successfully interacted with this binary? If so, what insight was the binary able to provide for the Minix based kernel it was subject to?

You can flip the HAP bit on an Intel ME firmware image and the Intel ME firmware image may successfully run with no detected ill effects (which seems to be the case you experienced), but how can you verify that the HAP bit was not benign?

Igor Skochinsky’s talk that not only brought attention to the Intel ME but provided useful revelations was presented in 2014, more than a half decade after the Intel ME had been deployed to users to be positioned to victimize them.

Other actionable Blackhat talks came nine years later (about a decade). Intel security advisary 00086 was disclosed in the same year.

Mate Kukri introduced Deguard in 2024.

Take a moment to step back from this pattern of calling others liars. Please take a moment to seriously consider this larger picture, the much larger picture. At sixteen years after the Intel ME had been positioned to victimize high-value targets, were machine owners able to meaningfully reign in control of their own property they lawfully own, on a processor reasonably not too ancient, and only on machines that were closer to one decade old (seven years) than they were one half of a decade.

If you have yourself successfully executed code at all on the processor the Minix based Intel ME system runs on (not the same CPU as the Intel Core i5/i7 CPU) on a 12th gen Intel chipset (one that does not have a publicly available exploit like Deguard) in your possession, let alone code that runs in the equivalent context to root or kernel space, then perhaps you can tell this broader community something new with some confidence that does have some substance behind it. But if you do not do this, then we’ll have to take what you have posted as what your situation looks like at face value: your asshole is thoroughly exposed.

2 Likes