Live data from Hacker News

Why is the latest Intel hardware unsupported in libreboot? (2017)

libreboot.org

31–40 of 132 posts

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#32

Libreboot is making a strong case for using open firmware in systems, yet it supports only a limited set of mostly outdated system boards. Isn't that a sign that it failed? After so many years? Don't get me wrong, I definitely support the idea of open firmware and I would gladly adopt libreboot and replace any BIOS firmware on all of my systems. But, not a single system (Intel ME in all of them) is supported. I could…

The problem is that the solution is political, not commercial. In terms of political process the "just leave it to us, we'll look after you" argument is winning.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#33

This is why I have an Apple Powermac G5 or two stored in my basement. These run entirely free of that backdoor.

How does it help that they're in your basement? Are you using them for anything? If not, when will you know to switch to them? What's the threat model and what would be your signal to go start using them and abandoning your presumably more modern system, and how would you keep the software on them secure? Will you use Gentoo, given that Debian has dropped PPC?

https://voidlinux-ppc.org/

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#34
I'll preface this question with the disclaimer that I'm a true believer in the mission of Coreboot/Libreboot. Playing devil's advocate, if Intel were to release the signing key for the ME, or Intel Boot Guard, wouldn't this increase the likelihood of a malicious vendor preinstalling a rootkit in hardware that uses Intel CPUs?

To answer in advance regarding the likelihood of this happening. There's already been enough instances of various hardware vendors using very nefarious means to extend the capabilities of their devices and peripheral device drivers. Also, what reason do we have to assume that Google's own interest in this area is any more trustworthy? I suppose it's a moot point for many whether or not google can get rootkit level access to people's devices when so many people are using Android.

Of course, I consider the presence of the ME to inherently constitute a rootkit for alphabet-soup US government agencies and the Mossad already.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#35
post #29

Reading this always makes me sad. It's like computing got utterly corrupted post-2008 and there's yet to be a fix. The tragedy of all this is that a 2008 laptop should be more than enough for today's needs if web development wasn't greedy and was resource aware.

What sites are you using that you can't force into mobile/low bandwidth mode? Most popular services have a way - and the ones that don't, third party apps/applications.

My 2012 T420's work just fine as daily drivers for anything work or personal.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#36
post #3

By now, it's probably reasonable to assume that NSA, GCHQ, the FSB, the Third Department, and Mossad can all use that backdoor.

It's probably reasonable to assume that half the attendees at DEFCON can use that backdoor. There are several known vulnerabilities listed in the linked Wikipedia article which have to be patched with a firmware update that some OEMs didn't bother to provide and most users didn't bother to install.

Is the Linux kernel one of them?

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#38

This is why I have an Apple Powermac G5 or two stored in my basement. These run entirely free of that backdoor.

How does it help that they're in your basement? Are you using them for anything? If not, when will you know to switch to them? What's the threat model and what would be your signal to go start using them and abandoning your presumably more modern system, and how would you keep the software on them secure? Will you use Gentoo, given that Debian has dropped PPC?

Threat model? Uhm. I think your asking me a bit too parameterized as I don't get your question. I will begin using them permanently of we get even more scandals. Also they are there as a fall back, but precisely for this purpose to protect myself against backdoored CPU architectures.

Ubuntu1604 works perfectly. They are set up and ready to use.

I have Python 3.x and all other major packages ready for me to be productive with.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#39
post #29

Reading this always makes me sad. It's like computing got utterly corrupted post-2008 and there's yet to be a fix. The tragedy of all this is that a 2008 laptop should be more than enough for today's needs if web development wasn't greedy and was resource aware.

> It's like computing got utterly corrupted post-2008 and there's yet to be a fix.

The ironic thing is that OP's posted article were news from 2009. Now, a decade later, we almost expect another total Intel CPU failure every year due to all the problems the architecture had while still promising sandboxed security.

But, as with all self-claimed "secure systems". If there's no audit, it cannot be seen as unsecure. Security through obscurity is pretty much the definition of how the hardware sector protects their IP these days.

And, of course, RISC V will be the solution. But honestly, I stopped believing in it years ago. As long as there's no computer system available in the same price range as the market leaders (aka Intel and AMD), you can forget about it.

Post reply on HN