http://blog.invisiblethings.org/2015/12/23/state_harmful.htm...
Freedom and security issues on x86 platforms
41–50 of 282 posts
Re: Freedom and security issues on x86 platforms
#42So, why is SPARC left off in all these analyses? It's right there ready to pick up and deploy. More open, easy to acquire, and trustworthy (far as licensing) than than a POWER chip although slower for sure.
Re: Freedom and security issues on x86 platforms
#431) requires FOSS users to purchase a license from Microsoft to boot FOSS on affected machines that lack an appropriate Secure Boot override. What "appropriate" Secure Boot overrides are available? 2) the end user is unable to modify the signed software without a license from Microsoft, even though they have the source code available to them under the GPL. Other parts of the posting imply that we have no idea what the…
1b) nuke the platform signing key and replace it with your own (iff the vendor lets you)
2) You're mixing things up. "We have no idea what the software does" refers to the hardware management code, which can run a full OS stack. But that quote refers to the tivoization "feature" of Secure Boot: you can recompile your software, but not run it on the hardware, because you lack the signing keys to make the machine trust your code. But, see 1)
Re: Freedom and security issues on x86 platforms
#44I'd personally like to see the FOSS community try to embrace the POWER architecture: Ubuntu/Canonical are major members of the OpenPOWER foundation [1], so at least an entity sympathetic with our philosophy has an influence on the architecture. [1] http://openpowerfoundation.org
Re: Freedom and security issues on x86 platforms
#45I've been looking into this recently. Basically, the things mentioned on the text, made free software bios and firmwares impossible, some of the free software projects that exist now are mostly "binary blobs loaders", having more binary blob than free software code running. There is some good analysis on why even Intel can't fix this if they wanted to, unless they stopped shipping some features entirely, their Intel…
People have certainly done ME reverse engineering: http://me.bios.io/
I'm supposed to believe this technology is dangerous. But the advocates are children.
Re: Freedom and security issues on x86 platforms
#46I think that, given a large enough group of people willing to make a mass-purchase of CPUs, Intel would be likely to listen to requests for a batch with an open-sourced Management Engine component, or some shim akin to the one RHEL uses to boot UEFI in Secure-Boot mode. (mentioned it on /r/ReverseEngineering a few months back.) I don't know who to reach out to at Intel on that suggestion though. https://www.reddit.co…
Re: Freedom and security issues on x86 platforms
#47I've been looking into this recently. Basically, the things mentioned on the text, made free software bios and firmwares impossible, some of the free software projects that exist now are mostly "binary blobs loaders", having more binary blob than free software code running. There is some good analysis on why even Intel can't fix this if they wanted to, unless they stopped shipping some features entirely, their Intel…
Re: Freedom and security issues on x86 platforms
#48I wonder if Apple might do something about this. They don't care so much for the FOSS side of things, obviously, but I wonder if they might demand chips from Intel without the management engine, because it's a potential attack vector they can't control.
Re: Freedom and security issues on x86 platforms
#49Re: Freedom and security issues on x86 platforms
#50I'd personally like to see the FOSS community try to embrace the POWER architecture: Ubuntu/Canonical are major members of the OpenPOWER foundation [1], so at least an entity sympathetic with our philosophy has an influence on the architecture. [1] http://openpowerfoundation.org