Live data from Hacker News

Why is the latest Intel hardware unsupported in libreboot? (2017)

libreboot.org

101–110 of 132 posts

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#101
post #94

Earlier quoted context omitted.

Really? I am curious to know what observations or evidence you base your arguments/predictions on? Do you believe they have an (even better than 'post-Snowden leaks') search-engine like PRISM, but for private networks all around the world? Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? And are you talking about mainstream proprietary OS'es…

> Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? Intel AMT allows redirecting graphics output and keyboard/mouse/USB input over network connection. It's like a hardware device connected to HDMI port to capture screen and to USB ports to send inputs, but it's built right into the motherboard. It doesn't spawn a process in the operating syste…

Thank you for answering my questions, really insightful!

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#103
post #98

Hypothetical: The keys are available one way or another, now anyone can sign firmware. ... Is this even worse? Sure we can get our SPI programmers out and be sure whats on there, but what about 99% of all other users who are now exposed not only Intels potential abuse of ME, but all vendors and anyone who intercepts devices. I obviously don't like IME/PSP but perhaps the only safe option is to push for removal not op…

The best option is UI for users to add their own keys.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#104
post #65

This is really sad. I am sure hundreds of hours were spent on this project with now essentially does nothing. Does this mean all free software advocates are stuck on archaic pre 2010 hardware?

Pre-2010 hardware is not archaic. I would argue that there was very little progress since 2010.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#105
post #94

Earlier quoted context omitted.

Really? I am curious to know what observations or evidence you base your arguments/predictions on? Do you believe they have an (even better than 'post-Snowden leaks') search-engine like PRISM, but for private networks all around the world? Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? And are you talking about mainstream proprietary OS'es…

> Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? Intel AMT allows redirecting graphics output and keyboard/mouse/USB input over network connection. It's like a hardware device connected to HDMI port to capture screen and to USB ports to send inputs, but it's built right into the motherboard. It doesn't spawn a process in the operating syste…

Occasionally all these features would be quite useful if it was documented and accessible for mere mortals.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#107

What about sbc's? afaik, they wouldn't be subject to any of this and since Intel and amd are doomed, wouldn't something like a pinebookpro or rpi make for a secure, yet affordable, solution?

Perhaps I need more coffee, but I can't tell if there is sarcasm in this or not.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#108
post #51
post #34

I'll preface this question with the disclaimer that I'm a true believer in the mission of Coreboot/Libreboot. Playing devil's advocate, if Intel were to release the signing key for the ME, or Intel Boot Guard, wouldn't this increase the likelihood of a malicious vendor preinstalling a rootkit in hardware that uses Intel CPUs? To answer in advance regarding the likelihood of this happening. There's already been enough…

Any big corporation with security competence is going to seriously care about the security of their corporate and production fleet; the stakes for securing systems only ever increases over time, and threats are only getting more sophisticated. So you don’t necessarily need to believe in the altruism of a corporation to see why their interest in secure computing at lower levels of the stack may actually line up with u…

> ...you don’t necessarily need to believe in the altruism of a corporation to see why their interest in secure computing at lower levels of the stack may actually line up with user’s interests more or less.

Of course. We're not talking about just any corporation here though, not even just any hardware manufacturer. You're right that security is in everyone's interests. My mentioning Google is referencing a company whose business consists of collecting and marketing information on their users. I think this changes the risk profile somewhat.

> ...In theory anyone can inspect the source code and binaries for Corebooted devices...

Pardon me if there's a big hole in my understanding of firmware RE, In reference to the Coreboot'ed Chromebooks, it sounds like this should read "anyone can inspect the source code and binaries of Coreboot". We still have to take at face value what firmware is actually installed on a device. I don't mean to sound nitpicky or mean, I just think that Google's motivations warrant extra scrutiny. I agree with your sentiments overall.

> ...Intel ME may even have been born with genuinely good intentions...

This might be the case, but the way Intel has treated the topic could not possibly foster any kind of trust with its user-base. Also, these features offer extremely little to the average user. I'd like to be corrected on this if I'm wrong, what does Intel ME actually do for a user like myself? Surely it would lower costs in a non-trivial way to just remove it for non-corporate customers if the intentions were even the least bit genuine.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#109

Earlier quoted context omitted.

Yeah, microcode updates are proprietary software too. The weird result is that if you want a system with no proprietary software, you end up having to use the original microcode which is burned onto the chip and counts as hardware. It's not a perfect solution but maybe it's a reasonable place to draw the line, until we have open source hardware processors using RISC-V or something.

Then you have to accept all the bugs with the original...

...and that a backdoor wasn't written into the original microcode, or that a state-sponsored actor didn't intercept during shipping...

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#110
post #63

Earlier quoted context omitted.

Yea, that was disappointing indeed. After reading the first several paragraphs, I was hoping that the answer would be get an AMD processor instead of Intel , but nope. I hope that in the future some manufacturer(s) start making fully open source verifiably secure RISC-V (or ARM) processors, and that we have a migration over to that.

Feel free to call it a conspiracy theory, but I firmly believe the IME/PSP is an operation by one of those three letters. Intel Management Engine is abbreviated as IME, and AMD Platform Security Processor is abbreviated as PSP. Those are each same abbreviation as Input Method Editor, a mandatory keyboard input layer for East Asian languages, and PlayStation Portable, Sony’s game console which cryptographic security i…

> That can't be coincidence

Yes it can.

Post reply on HN