Purism Librem laptops disable Intel’s Management Engine

Only a few weeks after the news that security researchers had managed to completely disable the Intel Management Engine, Purism has announced it’s disabling the IME on all of its available Librem laptops.

Purism’s Librem Laptops, running coreboot, are now available with the Intel Management Engine completely and verifiably disabled.

The Management Engine (ME), part of Intel AMT, is a separate CPU that can run and control a computer even when powered off. The ME has been the bane of the security market since 2008 on all Intel based CPUs, with publicly released exploits against it, is now disabled by default on all Purism Librem laptops.

Disabling the Management Engine is no easy task, and it has taken security researchers years to find a way to properly and verifiably disable it. Purism, because it runs coreboot and maintains its own BIOS firmware update process has been able to release and ship coreboot that disables the Management Engine from running, directly halting the ME CPU without the ability of recovery.

Great move.

28 Comments

  1. 2017-10-24 8:12 pm
    • 2017-10-25 6:05 am
    • 2017-10-26 3:29 am
      • 2017-10-26 7:05 pm
        • 2017-10-26 7:59 pm
  2. 2017-10-24 8:20 pm
    • 2017-10-24 10:29 pm
      • 2017-10-25 6:20 am
        • 2017-10-25 9:00 am
          • 2017-10-25 11:24 am
          • 2017-10-25 2:53 pm
          • 2017-10-26 7:55 pm
        • 2017-10-26 3:56 pm
    • 2017-10-24 11:08 pm
      • 2017-10-26 4:00 am
        • 2017-10-27 6:31 pm
    • 2017-10-25 2:50 am
  3. 2017-10-24 11:13 pm
    • 2017-10-24 11:26 pm
      • 2017-10-25 12:06 am
        • 2017-10-25 6:24 am
      • 2017-10-26 3:59 pm
        • 2017-10-27 6:34 pm
          • 2017-10-29 2:17 pm
    • 2017-10-26 4:01 pm
  4. 2017-10-25 10:46 am
  5. 2017-10-25 2:52 pm
  6. 2017-10-25 4:49 pm