Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disable some Intel PMT kernel modules #237

Merged
merged 2 commits into from
Jul 17, 2024
Merged

Disable some Intel PMT kernel modules #237

merged 2 commits into from
Jul 17, 2024

Conversation

raja-grewal
Copy link
Contributor

Disable some Intel Platform Monitoring Technology Telemetry (PMT) kernel modules.

Disabling was first suggested in Issue #224.

Changes

Add some Intel PMT modules to the list of disabled kernel modules.

Create disabled-intelpmt-by-security-misc.

Mandatory Checklist

  • Legal agreements accepted. By contributing to this organisation, you acknowledge you have read, understood, and agree to be bound by these these agreements:

Terms of Service, Privacy Policy, Cookie Policy, E-Sign Consent, DMCA, Imprint

Optional Checklist

The following items are optional but might be requested in certain cases.

  • I have tested it locally
  • I have reviewed and updated any documentation if relevant
  • I am providing new code and test(s) for it

@raja-grewal
Copy link
Contributor Author

@adrelanos
Copy link
Member

adrelanos commented Jul 15, 2024

Moved my comment to #236 where it belongs. It is a related discussion.

@adrelanos adrelanos changed the title Disable some Intel PMT modules Disable some Intel ME / Intel PMT modules Jul 15, 2024
@adrelanos adrelanos changed the title Disable some Intel ME / Intel PMT modules Disable some Intel ME / Intel PMT kernel modules Jul 15, 2024
@adrelanos adrelanos changed the title Disable some Intel ME / Intel PMT kernel modules Disable some Intel PMT kernel modules Jul 15, 2024
@raja-grewal
Copy link
Contributor Author

As per the discussion at #224 (comment).

For disabling Intel PMT, perhaps we should make it opt-in because I would imagine a large portion of users would prefer to have it preemptively disabled than risk any potential future revelations regarding what was actually being collected.

@adrelanos adrelanos merged commit df80385 into Kicksecure:master Jul 17, 2024
@raja-grewal raja-grewal deleted the intel_pmt branch July 17, 2024 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants