Live data from Hacker News

The Google H1 Fritz Chip

loper-os.org

31–37 of 37 posts

Re: The Google H1 Fritz Chip

#31
post #26

Earlier quoted context omitted.

> typically by inhibiting attempts to install modified firmware This also inhibits attempts by malicious third parties to install modified firmware on your machines. For Chromebooks we traditionally tried to find a middle route: locked down by default, since most people care more about nobody tampering with their device than about the ability to do so themselves. For the others, there's dev mode (easy to get at, but…

Why lie to the public ? Pulling the battery does enable rewrite, by the user, of the AP ROM, but not the Cr50 -- the latter remains Tivoized. And every owner of this machine can verify this with his own hands, it is not even necessary to build the USB debug cable. The Cr50 accepts firmware updates at all times, but only when signed with Google's RSA key.

> Why lie to the public?

I don't, and TBH I don't find your writing style (of which this is an example) very engaging.

Cr50 is a replacement for the old TPM. It has approximately the same constraints as the Infineon TPM used in the past: firmware updateable, but not for you.

[edit to add: would a mechanism to disable the update mechanisms, at the price of "no warranty" since RMA becomes impossible be acceptable to you? Or would you suspect that there's another update mechanism anyway?]

> Pulling the battery does enable rewrite

Pulling the battery is non-trivial on a device like Pixel C, hence a new mechanism.

Re: The Google H1 Fritz Chip

#32
post #31

Earlier quoted context omitted.

Why lie to the public ? Pulling the battery does enable rewrite, by the user, of the AP ROM, but not the Cr50 -- the latter remains Tivoized. And every owner of this machine can verify this with his own hands, it is not even necessary to build the USB debug cable. The Cr50 accepts firmware updates at all times, but only when signed with Google's RSA key.

> Why lie to the public? I don't, and TBH I don't find your writing style (of which this is an example) very engaging. Cr50 is a replacement for the old TPM. It has approximately the same constraints as the Infineon TPM used in the past: firmware updateable, but not for you. [edit to add: would a mechanism to disable the update mechanisms, at the price of "no warranty" since RMA becomes impossible be acceptable to yo…

My current alternative appears to be to desolder the Cr50 and fabricate harmless replacements (to e.g. init 3.3v rail).

So naturally voids warranties.

> firmware updateable, but not for you

Finally, honesty. It's a Tivo.

Re: The Google H1 Fritz Chip

#33
post #31

Earlier quoted context omitted.

> Why lie to the public? I don't, and TBH I don't find your writing style (of which this is an example) very engaging. Cr50 is a replacement for the old TPM. It has approximately the same constraints as the Infineon TPM used in the past: firmware updateable, but not for you. [edit to add: would a mechanism to disable the update mechanisms, at the price of "no warranty" since RMA becomes impossible be acceptable to yo…

My current alternative appears to be to desolder the Cr50 and fabricate harmless replacements (to e.g. init 3.3v rail). So naturally voids warranties. > firmware updateable, but not for you Finally, honesty. It's a Tivo.

> firmware updateable, but not for you

Like the Infineon before it.

Re: The Google H1 Fritz Chip

#34
post #31

Earlier quoted context omitted.

> Why lie to the public? I don't, and TBH I don't find your writing style (of which this is an example) very engaging. Cr50 is a replacement for the old TPM. It has approximately the same constraints as the Infineon TPM used in the past: firmware updateable, but not for you. [edit to add: would a mechanism to disable the update mechanisms, at the price of "no warranty" since RMA becomes impossible be acceptable to yo…

My current alternative appears to be to desolder the Cr50 and fabricate harmless replacements (to e.g. init 3.3v rail). So naturally voids warranties. > firmware updateable, but not for you Finally, honesty. It's a Tivo.

The Infineon couldn't force a boot ROM update via USB-C.

Re: The Google H1 Fritz Chip

#35
post #9

Fact: The Snowden leaks confirmed the long suspicion that governments work to backdoor software and hardware at an insane level. Related fact: Governments also try crazy hard to bust into insecure, vulnerable devices to compromise them. So we have this really annoying catch 22, where people like this author report on real security and tamper protection systems as bad -- yet without them, the device would actually be…

> It's plenty easier to buy a hackable and open by default platform... Pray tell, where can I buy a laptop (of new, rather than vintage, manufacture) without blobs and master keys?

Sure thing! I'm not entirely sure if this is 100% open, but it's worth checking out: https://puri.sm/

Re: The Google H1 Fritz Chip

#36
post #35

Earlier quoted context omitted.

> It's plenty easier to buy a hackable and open by default platform... Pray tell, where can I buy a laptop (of new, rather than vintage, manufacture) without blobs and master keys?

Sure thing! I'm not entirely sure if this is 100% open, but it's worth checking out: https://puri.sm/

Intel. No thanks.

Re: The Google H1 Fritz Chip

#37
post #11

>To my knowledge, there has been no detailed public discussion of this NSA-imposed atrocity anywhere on the Net, This blog post asserts that it was imposed by the NSA. Where is the evidence for that? The only source seems to be what appears to be speculation by some person on IRC. >20:23 from my pov, it's nsa rootkit It's hard to take this post very seriously when there's disinformation like this.

> The only source seems to be what appears to be speculation by some person on IRC.

It's not just some person on IRC, it's the author. He's citing himself.

Post reply on HN