> <i>Oh, I see.</i><p>No, you don't.<p>Because of the SMI/ACPI/Intel Management Engine/AMD Secure Technology/UEFI, and optionally AMT-complex, where usually only parts of can be deactivated partially, but never all of it.<p>It's actually more bad than the above mentioned ARM-stuff, which is misinformed(maybe because of raspberry piish broadcomisms, or locked down dumbphones), because on ARM, you either <i>can</i> disable that stuff, or even can run your own instead.<p><a href="https://www.trustedfirmware.org/projects/op-tee/" rel="nofollow">https://www.trustedfirmware.org/projects/op-tee/</a><p><a href="https://github.com/OP-TEE" rel="nofollow">https://github.com/OP-TEE</a><p><a href="https://docs.kernel.org/next/tee/op-tee.html" rel="nofollow">https://docs.kernel.org/next/tee/op-tee.html</a>