Re: But my friends, it is much worse --
*sigh* Not this canard again.
On all recent Intel PC systems, the ME is responsible for:
- monitoring fan speeds / voltages / temperatures
- running the secure enclave for SGX secure guard extensions
On vPro-branded systems ONLY, the ME runs a more complex firmware that includes a network stack.
Consumer, non-vPro PCs don't have a large enough SPI flash chip to run this firmware - that's one small reason why vPro systems are more expensive, the extra $0.02 or whatever for the larger flash chip, multiplied by the system vendor's usual mark-up. The network stack also relies on the presence of a specific Intel ethernet controller and/or a specific Intel Centrino WiFi card - again, most consumer systems don't use Intel networking parts, and certainly wouldn't use the more-expensive vPro ones for no benefit.
So unless your system says "vPro" on it, nothing below applies:
Out of the box, the network stack ("Active Management Technology" or AMT) on the ME is disabled. Shut off. Inaccessible.
None of it can be used until the owner of the PC (either you, or in a corporate environment, your IT dept) has taken the action to "provision" the AMT capability and switch it on.
That involves: setting access credentials, configuring the IP address etc, and choosing the level of user notification.
Provisioning can only be done from the local PC via the BIOS, or across the LAN (not WAN) with appropriate certificate-based provisos (e.g, if the machine sending the provisioning info is on the kontoso.com domain, your machine must be too, and must have a cert from a recognized provider, valid for the *.kontoso.com domain, embedded in its BIOS at time of deployment).
TL;DR: Hackers from China or Fort Meade aren't going to remotely enable AMT without your knowledge.
Once the provisioning's done, then AMT gives you remote power-on/power-off capabilities, and a built in KVM redirection server (based on the VNC protocol with secure extensions).
If a KVM session is initiated, a great big flashing icon appears in the top-right corner of the screen the whole time, and the screen border changes to a yellow/red stripe pattern. You WILL be aware that the PC is being controlled.
There is so much security built into AMT that it's a PITA to provision and use it. I honestly sometimes wish that the security wasn't so robust - it'd make it a darn sight easier to deploy this stuff. AMT is very cool.
Short version: does your PC say "vPro" on it? Then yes, it has "robust [...] remote control capabilities". For the PC's owner, by their choice.
If not, it doesn't. It physically can't.