Live data from Hacker News

Why is the latest Intel hardware unsupported in libreboot? (2017)

libreboot.org

21–30 of 132 posts

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#21
post #5

> Traffic is encrypted using SSL/TLS libraries, but recall that all of the major SSL/TLS implementations have had highly publicized vulnerabilities. I'm not sure this is a valid criticism...wouldn't we be more worried if they were using anything else instead?

No SSL => MITMer can definitely read your traffic trivially.

Broken SSL => MITMer can possibly negotiate insecure and read your traffic anyway. MITMer can also possibly cause a denial-of-service, or get arbitrary code execution on that one chip that controls your entire CPU.

If I had to choose, I would take the first option.

(This precludes options like removing the IME entirely, or updating it to a version with non-broken SSL.)

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#22
post #2

AMD's in a similar boat, if you scroll a bit further down too :(

Yea, that was disappointing indeed. After reading the first several paragraphs, I was hoping that the answer would be get an AMD processor instead of Intel , but nope. I hope that in the future some manufacturer(s) start making fully open source verifiably secure RISC-V (or ARM) processors, and that we have a migration over to that.

OpenPOWER/POWER9.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#23
post #2

AMD's in a similar boat, if you scroll a bit further down too :(

Yea, that was disappointing indeed. After reading the first several paragraphs, I was hoping that the answer would be get an AMD processor instead of Intel , but nope. I hope that in the future some manufacturer(s) start making fully open source verifiably secure RISC-V (or ARM) processors, and that we have a migration over to that.

Another candidate for this is OpenPOWER

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#24
post #7

Realistically if some party made use of these backdoors regularly someone would probably have noticed the traffic already.

So they're (probably) not used 'regularly'. That's mildly reassuring. But I have no doubt they're using it as often as they can get away with, which is more than never.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#27

Libreboot is making a strong case for using open firmware in systems, yet it supports only a limited set of mostly outdated system boards. Isn't that a sign that it failed? After so many years? Don't get me wrong, I definitely support the idea of open firmware and I would gladly adopt libreboot and replace any BIOS firmware on all of my systems. But, not a single system (Intel ME in all of them) is supported. I could…

You didn't read the reasoning linked, did you?

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#28

Asking someone who took their last (undergraduate) architecture course more than a decade ago: Is it possible to design a motherboard that will shield the user against Intel ME / AMD PSP-induced shadiness? Would it be possible to do this without performance impact?

Probably something like this should help: https://blog.invisiblethings.org/papers/2015/state_harmful.p...

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#29
Reading this always makes me sad. It's like computing got utterly corrupted post-2008 and there's yet to be a fix.

The tragedy of all this is that a 2008 laptop should be more than enough for today's needs if web development wasn't greedy and was resource aware.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#30
post #4

Since Intel/AMD also designs the processor they can also put in backdoors beyond ME, microcode updates, etc. If you don’t trust proprietary blobs, I respect that. But you can’t trust proprietary silicon either.

https://en.wikipedia.org/wiki/Defence_in_depth
Post reply on HN