Is the Intel ME (NSA b/door?) fully disabled on all devices?

Technically there are two aspects to ME cleaner

  • removing unnecessary modules
  • using the HAP bit to send the IME to sleep Edit: i.e. disable after boot of the main CPU

Only the former is useless on that Intel Gen CPU (and presumably all later generations), as I understand it.

1 Like

It was strictly engineered to the purpose: free backdoors, but we never know.

HECI is for sleep, which can still wake up without user consent. HAP is for Disabled permanent and still permit to boot.

Thanks for the correction. I updated my post to be clearer.

I assume by “permanent” you mean … until next power-on.

1 Like

Doesn’t nuke the whole ME region. Always dump a .bin of a BIOS if you’re going to modify it… And always keep a .bin.bak to make sure you have a dump that is known-good…

1 Like