T480 vs A485 vs ???

If you dislike Intel ME, you can run ME_Cleaner even on Boot Guard enabled laptops by using the /s flag(only set the HAP bit).

Don't you still need to use an external flasher to program the modified UEFI? At the rate the UEFI is being updated, mostly due to Intel vulnerabilities, that's going to be quite cumbersome.

If you mean the CPU vulnerabilities, you may just wish to update Windows and the Microcodes.

That does not solve all issues with Intel CPUs, just mitigates most of the stuff (at a non-negligible performance loss that can already be measured in lost battery runtime). AMD has only one Spectre variant that will be very hard to fix. On the other side, Intel has a whole slew of micro-architecture vulnerabilities mitigated with band-aids (that cost performance) plus the same unfixed Spectre variant as AMD.

Unless you deal with sensitive data, I don't really recommend disabling HT on Intel CPUs.

"sensitive data" is an ominous cover your ass buzz word in the cybersecurity world.

/r/thinkpad Thread Parent