Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Linux laptop-flinger (System76) says bye-bye to buggy Intel Management Engine
The Register ^ | Dec 1, 2017 | Andrew Silver

Posted on 12/03/2017 7:56:42 AM PST by dayglored

In a slap to Intel, custom Linux computer seller System76 has said it will be disabling the Intel Management Engine in its laptops.

Last month, Chipzilla admitted the existence of firmware-level bugs in many of its processors that would allow hackers to spy on and meddle with computers.

One of the most important vulnerabilities is in the black box coprocessor – the Management Engine – which has its own CPU and operating system that has complete machine control. It's meant for letting network admins remotely log into servers and workstations to fix any problems (such as not being able to boot).

The bugs – as security researchers discovered – allow for installing rootkits and spyware on machines that could steal or tamper with information. So, perhaps unsurprisingly, several vendors – including Lenovo – have been quick to patch the bugs.

Denver, Colorado-based System76, meanwhile, has just banned the Management Engine outright.

In a blog post Thursday, the firm wrote: "System76 will automatically deliver updated firmware with a disabled ME on Intel 6th, 7th, and 8th Gen laptops. The ME provides no functionality for System76 laptop customers and is safe to disable."

It will apply to customers running Ubuntu 16.04 LTS, Ubuntu 17.04, Ubuntu 17.10, Pop!_OS17.10, or an Ubuntu derivative with the System76 driver installed.

Desktops are not affected by the ban – they'll just receive ME patches "as they are available".

The firm said the rollout would happen over time and customers will be notified by email prior to delivery.

"Disabling the ME will reduce future vulnerabilities and using our new firmware delivery infrastructure means future updates can rollout extremely fast and with a higher percentage of adoption (over listing affected models with links to firmware that most people don't install)."

System76 did, however, note that Intel has the power to change device function and not allow manufacturers and consumers to disable ME, so this may not last forever.

Intel has not responded to a request for comment. ®


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: managementengine; security; system76; windowspinglist
Navigation: use the links below to view more comments.
first previous 1-2021-27 last
To: captain_dave
> My first guess is this is the backdoor the NSA and others use to sneak around.

And my first guess is that your first guess is probably right.

/tinfoilhat

21 posted on 12/03/2017 3:29:49 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 20 | View Replies]

To: deadrock
Is there an Office suite of some kind?

Looks like they install Ubuntu or their own(!) Pop! OS distro which is based on Ubuntu. They probably include LibreOffice installed on the computers, but if they don't, you can just download it and install it. It's free.

https://www.libreoffice.org/get-help/install-howto/linux/

22 posted on 12/03/2017 4:10:06 PM PST by TChad
[ Post Reply | Private Reply | To 8 | View Replies]

To: TChad

Thanks.


23 posted on 12/03/2017 4:18:37 PM PST by deadrock
[ Post Reply | Private Reply | To 22 | View Replies]

To: deadrock
The article below is about a System76 computer with the Pop! operating system. LibreOffice was installed.

https://www.pcworld.com/article/3204910/linux/pop-os-is-a-linux-distro-from-system76.html

Impressive company. I bet their tech support is superb.

24 posted on 12/03/2017 4:33:15 PM PST by TChad
[ Post Reply | Private Reply | To 23 | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Ernest_at_the_Beach; ...

25 posted on 12/04/2017 8:26:16 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Thanks, I will have to check out their distro as well.

CGato


26 posted on 12/04/2017 11:22:52 AM PST by Conservative Gato (There are NOW 4 kind of LIES; Lies, Damned Lies, Statistics, and the Media.)
[ Post Reply | Private Reply | To 25 | View Replies]

To: dayglored; ShadowAce; swordsman

Sounds as if this is an issue with Intel CPU’s and not a particular operating system. Have sent out a ping to the Mac List as well. IIRC, Mac uses Intel Processors.


27 posted on 12/04/2017 2:10:32 PM PST by Calvinist_Dark_Lord ((I have come here to kick @$$ and chew bubblegum...and I'm all outta bubblegum! ~Roddy Piper))
[ Post Reply | Private Reply | To 3 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-27 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson