So can SGX (under certain circumstances). So can your hard disk, your NIC, and probably your firmware via DMI.

Right, but those components typically don't have unchecked access to the rest of the system via back doors.

Your NIC is at least as dangerous as ME if you don’t have the ME connected to the network.

