Linux Laptops? System76? Other options?

Not sure what you’re all talking about because numerous well-documented security vulnerabilities in IME have been found (here’s one list of them). Whether it’s spyware or not is up for debate, but it is a concern and should absolutely be disabled if you have the option regardless of whether it’s a spooky backdoor or spyware, in the simple interest of attack surface reduction.

I probably wouldn’t use tools which go beyond (e.g. by ‘neutralizing’ IME firmware) the “supported” method of disabling IME by setting the HAP bit though, due to potential unforeseen consequences. Basically… if your device gives you the option in the BIOS or whatever, do it, but… probably not something most people need to worry about otherwise.

More reading on the topic of IME elsewhere: Intel ME and more


Anyways, all of this being said, it doesn’t sound like hardware vulnerabilities are even a likely threat for you? Seems like you’ll be alright with any hardware given you’re running modern Linux.

I wouldn’t go overboard with this kind of stuff unless you just enjoy it.

2 Likes