Hacker News new | ask | show | jobs
by close04 2895 days ago
As far as I know while the Management Engine is in all chipsets that accompany Intel CPUs, Apple never shipped any AMT enabled firmware. This is the more exposed component.
2 comments

I've seen some indication that the HECI (mailbox between the main OS and the ME) is disabled as well on most/all Apple machines.

I don't think they've ever used the Intel NIC hardware either, wired or wireless.

Apple is exposed to ME bugs.

https://support.apple.com/en-us/HT208465

See the "EFI" section.

The ME is most definitely there but AMT is not. And AMT is the one with far more exposed security flaws that can be exploited over the network by virtue of AMT's purpose. Like the ones detailed in the article here. Otherwise without a shadow of doubt the ME is present in every Intel chipset since 2006.

Exploiting the ME is possible even without AMT but it definitely raises the bar in the sophistication of the attack.

The me_cleaner tool might do a good job in disabling the ME in most cases but since it's doing it by removing components from the ME FW it probably doesn't work with every OEM implementation.