Live data from Hacker News

Lenovo: Companies working in China may have to install local backdoors

theinquirer.net

11–20 of 90 posts

Re: Lenovo: Companies working in China may have to install local backdoors

#13
Purism is working with coreboot to provide laptops where you can verify the integrity of firmware on your device, within the limits of Intel CPUs.

https://www.tomshardware.com/news/purism-heads-rootkit-tampe...

"Purism announced that, after almost a year of testing, it was able to successfully integrate the Heads firmware into its TPM-enabled and Coreboot-running Librem laptops. The open source firmware, which checks if someone has tampered with the laptops, allows users to freely inspect and customize the code. Purism also recently announced that all of its new Librem 13 and 15 laptops now include a TPM by default, so they all come with the Heads firmware by default, too."

Previously: Google on "Replacing exploit-ridden firmware with a Linux kernel", https://news.ycombinator.com/item?id=15579592

Re: Lenovo: Companies working in China may have to install local backdoors

#15

Purism is working with coreboot to provide laptops where you can verify the integrity of firmware on your device, within the limits of Intel CPUs. https://www.tomshardware.com/news/purism-heads-rootkit-tampe... "Purism announced that, after almost a year of testing, it was able to successfully integrate the Heads firmware into its TPM-enabled and Coreboot-running Librem laptops. The open source firmware, which checks…

Intel microcode updates are encrypted and signed.

Re: Lenovo: Companies working in China may have to install local backdoors

#17
post #15

Purism is working with coreboot to provide laptops where you can verify the integrity of firmware on your device, within the limits of Intel CPUs. https://www.tomshardware.com/news/purism-heads-rootkit-tampe... "Purism announced that, after almost a year of testing, it was able to successfully integrate the Heads firmware into its TPM-enabled and Coreboot-running Librem laptops. The open source firmware, which checks…

Intel microcode updates are encrypted and signed.

Yes, this is about open-source firmware vs OEM (e.g. Lenovo) closed-source firmware.

Re: Lenovo: Companies working in China may have to install local backdoors

#18

I miss the early 90s and 2000s when governments were still struggling to understand what the internet was, rather than trying to control it.

Did that time ever really exist?

https://en.wikipedia.org/wiki/Clipper_chip

https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...

I also remember writing some (naive) crypto tools as a kid and I had to report it to permit re-export from the US.

Also, the DMCA is from the nineties:

https://en.wikipedia.org/wiki/Digital_Millennium_Copyright_A...

Re: Lenovo: Companies working in China may have to install local backdoors

#19
I'm sure they have plenty of examples to go by, all they need to do is consult Yahoo, Google or any of the telecoms for good strategies.

I guess on the plus side at least we know now that it is happening despite the lies the Federal government told us. I worry that as bad as it is for whistle blowers in the US what chance does China have?

Re: Lenovo: Companies working in China may have to install local backdoors

#20
post #14

Earlier quoted context omitted.

My hope is that eventually we would be able to buy a trustworthy computer.

To print all the chips on your own mini-fab - maybe. Eventually.

But your mini-fab might be backdoored and create chips with backdoors.
Post reply on HN