Stories
Slash Boxes
Comments

SoylentNews is people

posted by martyb on Monday October 16 2017, @01:50AM   Printer-friendly
from the b-b-b-but-I-have-an-AMD! dept.

We've covered that it was possible and in theory how to do so before but I think having a proper How-To written up will save even us nerd types some hair pulling. Here's what you'll need to start:

  • an Intel-CPU-based target PC — that does not have Boot Guard enabled — on which you wish to disable the IME;
    • the target PC may be running an OEM BIOS (such as AMI, Dell etc.), or coreboot;
  • a Raspberry Pi 3 Model B single board computer ('RPi3'), for use as an external flash programmer;
  • a spare >= 8GB microSD card (to hold the 64-bit Gentoo O/S image we will use for the RPi3);
  • an appropriate IC clip for your target PC's flash chip, e.g.:
    • a Pomona 5250 for SOIC-8 chips;
    • a Pomona 5208 for unsocketed DIP-8 chips, or
    • a Pomona 5252 for SOIC-16 chips;
  • 8 female-female connector wires (to attach the appropriate clip to the RPi3's GPIO header);
  • a maintenance manual for your target PC, where available, to assist in safe disassembly / reassembly; and
    • whatever tools are stipulated in the above.

Given the above list, you'll obviously need to be comfortable identifying and connecting an IC clip to your flash chip. So, it's not a procedure for most grandmothers but neither is especially complex or difficult for the vast majority of desktop machines (laptop/other difficulty will vary widely). Also, the guide explicitly does not cover PLCC or WSON flash chips, so you're out of luck here if your board has such.

Happy hacking, folks.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 5, Insightful) by takyon on Monday October 16 2017, @01:59AM (21 children)

    by takyon (881) <{takyon} {at} {soylentnews.org}> on Monday October 16 2017, @01:59AM (#582870) Journal

    Will you buy superior price/performance x86 chips, or pin your hopes on SoylentNews favorite RISC-V to break the monopoly?

    Does this mean Intel is a better buy than AMD?

    Is this just a ruse to get you to disable the management engine you know about?

    --
    [SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
    • (Score: 3, Informative) by Anonymous Coward on Monday October 16 2017, @02:19AM

      by Anonymous Coward on Monday October 16 2017, @02:19AM (#582872)

      Using a turquoise case is the only way to shut down the one the lizard people put in there.

    • (Score: 5, Informative) by The Mighty Buzzard on Monday October 16 2017, @02:22AM (13 children)

      by The Mighty Buzzard (18) Subscriber Badge <themightybuzzard@proton.me> on Monday October 16 2017, @02:22AM (#582873) Homepage Journal

      Well, RISC-V is years away from giving the world a chip comparable with even the low-end x86_64 chips, so that's out. ARM would be a better bet but while finding a respectable ARM chip isn't too hard, finding a board that gives you options comparable to a modern desktop is exceedingly difficult, so that's out as well for a bit longer. If you need a desktop this year, you have no realistic choice but x86_64 unless you're willing to pay thousands of dollars extra for an underperforming Talos II.

      --
      My rights don't end where your fear begins.
    • (Score: 2) by isostatic on Monday October 16 2017, @10:35AM (3 children)

      by isostatic (365) on Monday October 16 2017, @10:35AM (#582949) Journal

      Is this just a ruse to get you to disable the management engine you know about?

      Unless they have some real spy stuff infecting every chip like Uraei or similar, somebody would be able to see traffic passing through their router

      • (Score: 3, Funny) by takyon on Monday October 16 2017, @10:47AM (2 children)

        by takyon (881) <{takyon} {at} {soylentnews.org}> on Monday October 16 2017, @10:47AM (#582953) Journal

        The chips use an internal neutrino router to communicate directly with the NSA.

        --
        [SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
        • (Score: 1, Funny) by Anonymous Coward on Monday October 16 2017, @11:25PM (1 child)

          by Anonymous Coward on Monday October 16 2017, @11:25PM (#583214)

          Great, now I have to build a million gallon tank directly below my house just so I can see what the NSA is siphoning off!?! I have stuff to do this weekend!

          • (Score: 2) by Wootery on Tuesday October 17 2017, @09:55AM

            by Wootery (2341) on Tuesday October 17 2017, @09:55AM (#583383)

            Try siphoning the stream of bile from YouTube comments. You'll have it full in no time.

    • (Score: 2) by crafoo on Tuesday October 17 2017, @02:04AM (1 child)

      by crafoo (6639) on Tuesday October 17 2017, @02:04AM (#583265)

      Days like this I really miss my Amiga. Assembly was more fun on it too.

      • (Score: 1) by anubi on Tuesday October 17 2017, @04:08AM

        by anubi (2828) on Tuesday October 17 2017, @04:08AM (#583306) Journal

        That's the reason I stay with my simple stuff.

        I do not need to refresh a HD screen 60 FPS, but I *must* be able to trust the thing.

        If I can't trust it, I am really afraid to connect anything really important to it.

        I'd be more comfortable knowing my systems are running Arduinos than running something someone else can pwn me anytime he wants.

        --
        "Prove all things; hold fast that which is good." [KJV: I Thessalonians 5:21]
  • (Score: 5, Interesting) by jmorris on Monday October 16 2017, @04:22AM

    by jmorris (4844) on Monday October 16 2017, @04:22AM (#582903)

    It is possible to disable this by the vendor, Intel apparently will allow it.

    Dell Lattitude 14 Rugged Laptop [dell.com]

    Note they ship the default of "No Out-of-Band management" but sell two options, "vPro Enabled" and "vPro ME Disabled, Custom Order" for the same $20.92 upcharge.

    Haven't seen the option on other Dell offerings yet but somebody yelled at their sales rep loudly enough to get that option added. We need to yell until we make that universal, then a zero charge option, finally get it to be the default. PC sales are flat right now, customers have the whip hand. USE. IT.

  • (Score: 2) by bradley13 on Monday October 16 2017, @05:39AM (4 children)

    by bradley13 (3053) Subscriber Badge on Monday October 16 2017, @05:39AM (#582914) Homepage Journal

    It's great that someone has produced this how-to, but it remains a scary process with a non-zero chance of bricking your machine. What I want to know is why. Why does Intel make this necessary? Why not just make the management engine a cleanly switchable option? Is this laziness, of is it more nefarious?

    --
    Everyone is somebody else's weirdo.
    • (Score: 4, Interesting) by Geezer on Monday October 16 2017, @09:40AM (1 child)

      by Geezer (511) on Monday October 16 2017, @09:40AM (#582938)

      Making sure things like DRM and "customer experience research" always work could certainly be described as nefarious. Intel has long been Microsoft's hardware bitch.

      • (Score: 0) by Anonymous Coward on Tuesday October 17 2017, @04:22AM

        by Anonymous Coward on Tuesday October 17 2017, @04:22AM (#583311)

        Intel has long been Microsoft's hardware bitch.

        ref provided https://en.wikipedia.org/wiki/Wintel [wikipedia.org]

    • (Score: 5, Informative) by pkrasimirov on Monday October 16 2017, @11:15AM

      by pkrasimirov (3358) Subscriber Badge on Monday October 16 2017, @11:15AM (#582960)

      > Is this laziness, of is it more nefarious?
      It is more nefarious.

    • (Score: 3, Insightful) by sjames on Monday October 16 2017, @03:34PM

      by sjames (2882) on Monday October 16 2017, @03:34PM (#583020) Journal

      Better yet, remote management alone is a good thing. Why couldn't they stick to BMCs that have control over power, reset, and the serial port, can present a virtual DVD drive on USB, and NOTHING else?

  • (Score: 5, Informative) by RamiK on Monday October 16 2017, @10:23AM

    by RamiK (1813) on Monday October 16 2017, @10:23AM (#582948)

    a Raspberry Pi 3 Model B single board computer ('RPi3'), for use as an external flash programmer;

    Get yourself a CH341A instead. Cheaper and safer since you want a real-time clock doing the R/W which the Pi can't guarantee.

    As an additional side-note, some EEPROMS are 1.8v Vcc and high logic so pushing 3.3v down their lanes is dangerous even for the first probing operation. For those you'll need a relatively expensive TL866CS and its respective 1.8v adapter module (~40$).

    I guess the only caveat with the CH341A is the incomplete linux software compared to the windows software. But I doubt the Pi is doing any better.

    --
    compiling...
(1)