

Goodacre catalogues this and related scenarios in a 37-page risk assessment prepared for CISOs evaluating Intel vPro hardware connected to corporate networks. Its conclusion is blunt: connecting an untouched-ME device to corporate resources “exposes the organization to a class of compromise that defeats the host security stack in its entirety.”
I hear a lot of concern about backdoors in Chinese hardware but this is just dystopian.


I think you’re attributing a lot more to malice what can can more easily be just greed and stupidity.