Live data from Hacker News

Trustworthy Computing in 2021

ariadne.space

31–32 of 32 posts

Re: Trustworthy Computing in 2021

#31

What was the thing that detracted from the corebooted Thinkpad's trustworthiness?

Libreboot has no binary blobs, Coreboot still has a couple. But modern CPU architectures require some of those blobs to function correctly. So Coreboot has broader compatibility with modern hardware than Libreboot. Both are good, but I've always leaned towards Libreboot just cause I think ThinkPads from 2005-2008 look amazing and it's fun to know that there is no proprietary software on my computer.

I flash libreboot first to get rid of the intel management engine and then the latest coreboot to the bios region. I think I configuried it so that it doesn't include any blobs, but I'm not sure. Wish it were easier to tell for non-experts.

Re: Trustworthy Computing in 2021

#32

Earlier quoted context omitted.

> PCs through a subset of the USB standard which only handles HID and nothing else? Yes. Is the device truly limited to doing just that, though? No way to know. I don't know enough electronics to tear it down and analyze its parts, much less dump firmware and reverse engineer it. >Would any snooping be possible through an input device if it only did HID? For all I know, it could be silently storing every keystroke in…

We had that problem with PS/2 keyboards too, you can buy hardware keyloggers for those.

AFAIK it wasn't possible for a PS/2 connected thing to suddenly present itself as some sort of drive, present a file on that, and then have that executed via autoload, or so.
Post reply on HN