Live data from Hacker News

Freedom and security issues on x86 platforms

mail.fsfeurope.org

91–100 of 282 posts

Re: Freedom and security issues on x86 platforms

#91

It's great that these guys pushing POWER8 at least have a workable situation, but at least for me, throwing $3,700 at a motherboard (Alone!) just isn't feasible. I would love to be free of proprietary firmware, but it would seem that's only for people better off than myself.

It doesn't include the CPU itself?

Re: Freedom and security issues on x86 platforms

#92
While I would love a contemporary performance computer that can be trusted, no such device is even remotely possible in the manufacturing and fabrication ecosystems of today. Consider for just a moment ALL the chips inside the box. All the microcode, all the ROM, all the places something could be intentionally hidden. The idea that you could buy some parts on the internet at retail price that could satisfy the truly paranoid (ie defense & espionage communities) is ridiculous.

On the other hand, it still is probably possible to prevent a computers unrestricted access to the internet. For now at least.

Re: Freedom and security issues on x86 platforms

#93
post #64

Hmm. OK, I have two questions - maybe somebody here has answers: 1) "...these proprietary blobs could easily contain code to exfiltrate encryption keys, remotely activate microphones and cameras..." This seems basically impossible to actually achieve in reality though, because there will still associated network traffic that can be sniffed, and will have been by now, right? I mean, it is plausible that somehow we all…

To your 1): there would indeed be network traffic, but how many people have a machine they can truly trust capturing and analysing enough of the traffic going in and out of their LAN? Unfortunately there are few, if any, machines we can truly trust.

But don't we only need a few to catch them once? And don't we have at least a few?

Re: Freedom and security issues on x86 platforms

#94
The fight is increasingly political, so advocate and donate where you can.

We lose when we give up, I suppose. I know what the Libreboot guy said before on his blog, alluded to here, but this is why, as crusty as some might find him, we most generally support Stallman's politics.

Re: Freedom and security issues on x86 platforms

#95

Unbelievable. Yet again, we have a post on finding x86 alternative that's most FOSS friendly. Yet again, the author is unaware of or ignores the only architecture that's open, has GPL cores, and an ecosystem. That's SPARC. Oracle's T1 and T2 cores are open-source to study. More appropriately, Cobham-Gaisler's Leon3 HW is dual-licensed under GPL and commercial. The Leon4 is 4-cores. SPARC ISA is open. Open Firmware ex…

I'd imagine people don't bother looking at an oracle technology and just assume it is closed or unsupported due to the ways they generally operate. That doesn't make it right to do this, but that'd be my guess. I certainly didn't know SPARC was open until your comment.

There could be a perception problem there. SPARC has been open for a long time with multiple vendors making SPARC chips. There's no restrictions except IRRC a $99 fee to use the trademark for a SPARC compatible chip.

Re: Freedom and security issues on x86 platforms

#96
post #5

I've been looking into this recently. Basically, the things mentioned on the text, made free software bios and firmwares impossible, some of the free software projects that exist now are mostly "binary blobs loaders", having more binary blob than free software code running. There is some good analysis on why even Intel can't fix this if they wanted to, unless they stopped shipping some features entirely, their Intel…

People have certainly done ME reverse engineering: http://me.bios.io/

It seems there are just some basic begining steps on the site. It's far from the fully dissaembled ME. So it seems we still don't even know what's inside of ME.

Re: Freedom and security issues on x86 platforms

#97
post #19

Earlier quoted context omitted.

Apple will be sitting pretty with their own CPU, heh? At least in the iOS devices, but who knowns what the (near) future brings to the Mac line.

I doubt it. The powerpc to Intel switch was really painful because the desktop platform has the perpetual ball and chain of backward compatability. I doubt Apple would try to beat Intel at their own high performance game anyway.

Judging by the specs on their current lineup, it looks like Apple already gave up on performance anyway.

Re: Freedom and security issues on x86 platforms

#98
There is also an additional possibility: Recycle old computers. A Intel 2008 laptop performs OK with a modern GNU/Linux with an efficient Desktop (for example XFCE4). This also helps avoiding CO2 emissions, saves rare earths and energy. And it is a statement against a unsustainable throwaway society.

Re: Freedom and security issues on x86 platforms

#99
post #89

Earlier quoted context omitted.

I'd imagine people don't bother looking at an oracle technology and just assume it is closed or unsupported due to the ways they generally operate. That doesn't make it right to do this, but that'd be my guess. I certainly didn't know SPARC was open until your comment.

As far as I know, Oracle has not made any SPARC intellectual property available since the acquisition of Sun. The T1 and T2 lines were emphatically Sun-era products.

They stay on Slashdot and in my news feed. Here's a few from Oracle and one from Fujitsu:

Oracle T4 http://www.oracle.com/us/corporate/features/sparc-t4-announc...

Oracle M6 http://www.oracle.com/us/corporate/features/sparc-m6/index.h...

Oracle M7 https://blogs.oracle.com/rajadurai/entry/sparc_m7_chip_32_co...

Fujitsu https://en.wikipedia.org/wiki/SPARC64_VI

Re: Freedom and security issues on x86 platforms

#100
post #65
post #24

Earlier quoted context omitted.

I was at FOSDEM this year (2016) and there was a talk from the leader of LibreBoot. Honestly, his talk on the state of the project was very bitter. He literally said that there is absolutely no hope that LibreBoot will ever be able to cope with ME, and that the fight is over since 2008. As much as I would absolutely love to be able to run a free firmware, unless there is a major change/outsider in the hardware manufa…

I've been using a Raspberry Pi 3 for the past week, and have been pleasantly surprised by the performance. It's no speed demon, to be sure, but it's good enough for all my basic tasks. I wish there were a general "open computing" branch of the Raspberry Pi Foundation that would produce a $50-$100 "pro" version with more RAM and faster bus+peripherals.

The Raspberry Pi still relies on a closed-source blob running on a CPU core whose instruction set isn't publicly documented to even boot, but I suppose at least it's possible to reverse-engineer that unlike Intel ME.
Post reply on HN