Earlier quoted context omitted.
[flagged]
marcan addressed this early on in the project, arguing that Intel platforms including some of those advocated for by the FSF are less open and more at risk of upstream abuse in some very significant ways. https://news.ycombinator.com/item?id=29684585 For example intel systems (and Android) run resident supervisor code you can't get rid of, and that can do remotely initiated updates you have no control over. That's no…
The Oxide Computer folks wrote their own AMD boot loader and have an entire chain of trust and apparently (?) basically got rid of the supervisor code (Ring -2 and -3). They also have custom motherboards with third-party BMCs.
Could something similar be done on Intel?