<div dir="ltr"><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;font-size:small">OK, thanks for the clarification.</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Aug 29, 2017 at 4:13 PM, Timothy Pearson <span dir="ltr"><<a href="mailto:tpearson@raptorengineering.com" target="_blank">tpearson@raptorengineering.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">-----BEGIN PGP SIGNED MESSAGE-----<br>
Hash: SHA1<br>
<span class=""><br>
On 08/29/2017 02:57 PM, Leah Rowe wrote:<br>
><br>
><br>
> On 29/08/17 19:15, Timothy Pearson wrote:<br>
>> On 08/29/2017 06:10 AM, Rene Shuster wrote:<br>
>>> Wow.<br>
><br>
>> My favorite part is where the NSA itself basically admits that the<br>
>> ME can't be trusted!  I wonder if they are looking at other<br>
>> architectures or if this HAP bit was enough for their needs?<br>
><br>
><br>
><br>
> So is this completely disabled, and not just "neutralized"?<br>
><br>
<br>
</span>No, it's just neutralised.  The kernel, etc. are still required to boot<br>
the platform, it's just that the higher level userspace components are<br>
disabled at runtime.  So, if a flaw is found in the kernel, etc. the ME<br>
remains a serious security threat.<br>
<span class=""><br>
- --<br>
Timothy Pearson<br>
Raptor Engineering<br>
+1 (415) 727-8645 (direct line)<br>
+1 (512) 690-0200 (switchboard)<br>
<a href="https://www.raptorengineering.com" rel="noreferrer" target="_blank">https://www.raptorengineering.<wbr>com</a><br>
-----BEGIN PGP SIGNATURE-----<br>
Version: GnuPG v1<br>
Comment: Using GnuPG with Mozilla - <a href="http://enigmail.mozdev.org/" rel="noreferrer" target="_blank">http://enigmail.mozdev.org/</a><br>
<br>
</span>iQEcBAEBAgAGBQJZpcrLAAoJEK+<wbr>E3vEXDOFbayIH/<wbr>iZuAc88srpBSorCFJI52nya<br>
wGEqUUplz/<wbr>VeqcxH6ojEIT1QA6qRrXOi+<wbr>G7feMNiCOa83EwVjxOfpCsx5fP6WQI<wbr>H<br>
iuIYElJiAQ+GpHAozLtMujRr0E+o/<wbr>W+2iDl4CmwEKeXBydBlRwe2/<wbr>EnhaktMtVy7<br>
LuHOH53dvGxW6m/<wbr>8vPaulccbdJajBN7CYdkSFQ7gE+<wbr>qEMZ0ryMq3JFXjEkgCp8vE<br>
cCkBDSSeVyuqar6ghf+<wbr>IlLDFbLdt6FTKFmWupvL6A6Euveasq<wbr>38WwGvjiUMiKGDq<br>
5G9EjpAUGme2s4yiPdm2TAjvM8Sa5h<wbr>lVLIw3tLa7YjcJMSYeKRPJz7VUhRVX<wbr>7+k=<br>
=PMOh<br>
-----END PGP SIGNATURE-----<br>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr">Tech III * AppControl * Endpoint Protection * Server Maintenance<br>Buncombe County Schools Technology Department Network Group<br><a href="http://comicsanscriminal.com" target="_blank">ComicSans Awareness Campaign</a></div></div></div></div></div></div>
</div>