The Intel ME has full read+write access to the memory used by the Core i5/i7 series processor. The reverse is not true.
The Intel ME does not need to be “compromised”, the purpose of the Intel ME’s architecture is to ensure you can always be reliably compromised by the presence of static data loaded into memory.
If this sounds like a “claim” to you that is outlandish, it is because you wrote “even if my computer is fully compromised at kernel level, Intel ME cannot get compromised too”, which is the kind of oblivious that is the complete and total opposite of what what I was referred to in what I wrote earlier: “This is obvious to anyone who knows some basics on how computers work.”
This “even if my computer is fully compromised at kernel level, Intel ME cannot get compromised too” confirms you did not possess the comprehension of basics on how computers work necessary to even enter a discussion about the serious risks of Intel ME.
You were utterly oblivious to: the Intel ME has full read+write access to the memory used by the Core i5/i7 series processor. The reverse is not true.
Given the lucidity of what you have posted I do not doubt that you can comprehend these things but you did not connect the dots. The blind spot is not so much technical but blind spots in human behaviors that you are fortunate enough to have personally remained oblivious to. Maybe some day you will experience something that was not ever expected to happen, although I do not wish this on you.
The Intel ME runs no matter what. The Intel ME does not give a shit what Linux or some other software running on the subordinate CPU does. You can not turn the Intel ME off.
If you comprehended full read+write access to the memory above then you can comprehend why there is NOTHING that Linux/Xen/BSD/illumos/Retardows can do or neglect to do to prevent ANYTHING loaded into memory, any random document or any random web page contents, from talking to the Intel ME.
The Intel ME is the backdoor. From a computer engineer’s perspective it is more like a frontdoor. It’s the same tactic Microshit did embedding a web browser in the file explorer. The Asahi Linux people commented that Apple’s boards looked more like a Talos II board from RaptorCS and that they do not have a critical single point of compromise reaching into every single peripheral on the board like Intel ME does.
The Intel ME is a frontdoor by design.
The big question to be asked is: security, but on terms defined by who?
Bootguard does not protect the interests of the machine owner. Bootguard protects the interests of someone else.
If Bootguard was for the machine owner then the machine owner would have an accessible means to apply a cryptographic key as the machine owner sees fit. But Bootguard never had this, we had to wait for Deguard to “break” the Intel ME for the machine owner to have some control.
This is not a “political” stance this is basic ethical standard.
Every vulnerability disclosed was a backdoor/frontdoor to ring -3, not ring 3, not ring 0, ring -3. Just because you choose to call it something else doesn’t make it magically something else after all the whole time it was a 0day.
Here is what the source code for a piece of the Intel ME software stack looked like before the HAP bit was publicly disclosed:
case $HAP in
0))
scan_for_fuck_up_dumb_cattle_lol ;;
1))
things_are_okay_NSA ;;
esac
now here is what the source code for a piece of the Intel ME software stack released to dumb_cattle (NSA/GHCQ gets a separate release, coordinated by ODM) after the HAP bit was publicly disclosed:
// lol dumb fucks
The world doesn’t revolve around you and the limits of the perceptions you just happen to experience individually on your own.
These vulnerabilities were essential to flipping the Intel ME to work for the machine owner rather than against the machine owner.
I see you @ryrona ignored the questions I presented in this post which tells us that the answers of whether you have run software of your own volition on the higher privileged processor is no which means you have no idea what happens on that other operating system other than blindly trusting word you get from others. You have never been able to get insight to have any idea what the fuck the thing is doing by your own hands.
Many red team actors have run their code on the Intel ME. Fortunately, some blue team actors have too.