| भारत | अमरीका | चीन से | रशा | जर्मनी | वियतनाम |
|---|---|---|---|---|---|
| बहुत पिछड़े हुए हैं। जानकारी नहीं है। कुछ मुट्ठी भर जानकार कुछ कर भी नहीं पाए हैं। | माइक्रोसोफ्ट विंडोज (*), एप्पल, Kali Linux | डीपिन लिनक्स, ओपन काइलिन | ओपन सूजी | ||
| क्यूं मामू Qmamu | गूगल खोज | Baidu (blocked in India) | |||
| इंडस ऐप स्टोर | गूगल प्लेस्टोर | ||||
| YouTube, Rumble | RuTube,
app link |
||||
| Koo (now closed) | Facebook, Twitter | Mastodon | |||
| RedNote (Xiaohongshu) | |||||
| Amazon | अलीबाबा , Taobao and Jingdong (JD.com) | ||||
| अरत्ताई ऐप
| WhatsApp, सेशन Session (Open source) | Max, Telegram | |||
| Bhim | Google Pay | AliPay | |||
| Youtube Reels | RedNote (Xiaohongshu) , TikTok, Douyin | RuTube | Libre Office | ||
| Vikram 32-bit chip | Intel (*), AMD | Biren BR100, Huawei Ascend 910C, MetaX, Cambricon | Elbrus | राउटर TP-Link |
Since 2009 all intel processors have a less-transparent and less-documented extra processor within processor die/board. Its called by names - Intel backdoor - Intel AMT (IME).
It is not visible to Linux running on top of system, yet has abnormal access to - memory, devices and ethernet traffic.
Overview video about hacks and possible defenses
3 impact analysis presentations
Hackers sharing their findings -
2017-me_cleaner,
ME version 11.x
| Feature/vulnerability | Security concerns | General safety precautions | Specific solution |
|---|---|---|---|
| ME (management engine) + vPro (AMT) | - Almost all AMT features are available even if the PC/laptop is in a powered-off state but with its power cord attached, if the operating system has crashed, if the software agent is missing, or if hardware (such as a hard drive or memory) has failed. - AMT is available on PCs built on the vPro platform. Platforms equipped with AMT can be managed remotely, regardless of its power state or if it has a functioning OS or not. |
1. Switch off electrical power supply when PC/laptop is not in use. 2. Switch off Wifi/router when not in use. 3. Disable IPv6 on Wifi router. 4. Use MAC filtering and all possible firewall rules on Wifi/router. |
1. ME firmware is stored on SPI flash memory. SPI can be re-flashed to 2. ME hardware utilises network controller chip on motherboard. So install a new network card (PCI based) which will remain independent OR use a USB to LAN adapter Wifi/wired. 3. Get |
| vPro(has AMT/IME) | SA-00086 CSME - (Convergence Security and Management Engine Exploit) - 2017, Gain elevated admin priviledge, Keyboard logging (similar to iphone conclave chip) |
needs physical access to computer | - |
| Spectre | - | - | - |
| Meltdown | - | - | - |
| CSME | - | - | - |
-
Remote control of your Wifi lies with ISP company
-
Wifi modem can track your physical movements within your ़home
Even without Intel ME, manufacturers that don't use open source bios many times include Computrace baked into the bios.
Computrace is an IT asset management and theft recovery software, now known as Absolute Home & Office, that is embedded in the firmware of many computers. It is designed to deter theft and aid in the recovery of stolen devices by using a persistent module that can track the computer even if the hard drive is reformatted or replaced. Users can purchase a subscription to activate and use the service to track their computers and work with law enforcement in case of theft.
Why root access needed for installing packages?
FreeBSD doesn't need root access
Not all of them need root access to run. Something not right. Innovation in making - GUIX