Skip to content

Comment on How to verify boot firmware integrity if you prioritize neutralizing Intel ME?parent

Comments

The post is about the scenario where you disabled the TPM

Librem laptops have a TPM separate from Intel ME. The post is about if you have nuked the TPM built into the Intel ME. I'd say "have separate TPM" is a viable alternative.

I don't see it. The post says "when you use me_cleaner to neutralize intel ME, it also removes TPM", which is just not true for my system.

I made a mistake when I wrote the post mixing up disable and neutralized but I hoped everyone would understand I'm talking about disabling it.

My Librem 14 has disabled ME; my Librem 15 has both disabled and neutralized ME. Both with Heads, TPM and Librem Key. I don't understand how the difference between disabled and neutralized matters here.

Yeah I didn't know it was possible because some laptops have the TPM in a seperate chipset than the one that has intel me. I thought they only set the hap bit to neutralize but I learned here that they can also disable it on laptops that have TPM on a 2nd chipset.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.