Live data from Hacker News

Why is the latest Intel hardware unsupported in libreboot? (2017)

libreboot.org

71–80 of 132 posts

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#71
After all this time, I'm still trying to work out what is in it for Intel and AMD to force these technologies into their chips with no supported option to disable them and then to be so secretive about what they're doing and exactly who has access to what. I'm not generally one for crazy conspiracy theories, but I have to wonder what is going on behind closed doors that this is still being done by both of the two big PC CPU manufacturers despite all the negative press over the years and why national information security agencies haven't made more of a fuss about it.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#72
post #43

Earlier quoted context omitted.

I think the market for enthusiast machines shrinking might just help make the case for lower but still meaningful volume of RISC-V machines. That said, I do think it’s unclear how there would ever be a pathway for them to go from hobbyist machines to competing with AMD and Intel.

RISC-V has found a niche in anything embedded that needs some decent performance, especially in storage and networking. With a little imagination you can see some products there merge with other functionalities and take over larger markets, e.g. a NAS product line incorporating smart home and smart speaker functionality, evolving into 'home box' systems.

I would be willing to overpay a fair bit for NAS and other network equipment running open source hardware and software from the ground up. That’s an application of RISC-V I truly believe in.

Still, looking at the struggle ARM has had in spite of its ubiquity in even now fairly high performance devices, I will probably remain skeptical, for now, about such a transition. We have ARM NASes, routers, even competent servers! And yet... no real desktop towers. (At least a few exist, but I am thusfar unable to find any that are sold B2C retail or even second hand that look enticing.)

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#73
post #29

Reading this always makes me sad. It's like computing got utterly corrupted post-2008 and there's yet to be a fix. The tragedy of all this is that a 2008 laptop should be more than enough for today's needs if web development wasn't greedy and was resource aware.

System76 sells coreboot and ME-disabled computers at quite a mark-up. Yay free market.

coreboot utilizes binary blobs though

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#74
post #59

Scrolling up they recommend avoiding Purism hardware because > In particular, the Intel Management Engine is a severe threat to privacy and security, not to mention freedom, since it is a remote backdoor that provides Intel remote access to a computer where it is present. However, the Intel ME has been disabled in Purism hardware since 2017. https://puri.sm/posts/purism-librem-laptops-completely-disab...

See this https://blogs.fsfe.org/tobias_platen/2015/09/22/why-i-wont-b...

...which was written in 2015, so also outdated.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#75
> One module is the operating system kernel, which is based on a proprietary real-time operating system (RTOS) kernel called “ThreadX”. The developer, Express Logic, sells licenses and source code for ThreadX. Customers such as Intel are forbidden from disclosing or sublicensing the ThreadX source code.

Now that Microsoft has acquired Express Project [0], I wonder if those terms will change, especially since they're trying to compete in IoT against Amazon (who acquired FreeRTOS). Of course, this is a relatively small issue compared to the rest highlighted in the post though.

[0] https://blogs.microsoft.com/blog/2019/04/18/microsoft-acquir...

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#78
post #69

Earlier quoted context omitted.

Really? I am curious to know what observations or evidence you base your arguments/predictions on? Do you believe they have an (even better than 'post-Snowden leaks') search-engine like PRISM, but for private networks all around the world? Could a user tell it's happening? What signals would indicate this? Is it increased CPU usage disguised as a system process? And are you talking about mainstream proprietary OS'es…

The mere fact that you would expect a system process or anything else visible to the operating system, indicates that you haven't read much about Intel ME :/

> indicates that you haven't read much about Intel ME :/

I wrote in my comment:

> I already know a little about Intel ME and proprietary silicon

So yes this is true, I know only 'a little'. I have only understood that it is a small proprietary OS running underneath the user's OS. I guess from your comment I learned now that this means it is something you can only get at with a diagnostic tool, and it is outside the control of the user's operating system.

Yes I do not have a CS degree, and I am not a classically trained SWE. Instead I am a self-taught web app developer, with mainly skills in web apps, and not much knowledge yet around OS'es and computing hardware. Yet I am curious to go deeper into Intel ME, since it's existence and the consequences of that do affect me (since I have an intel chip in my computer), hence my questions.

You write:

> The mere fact that

This sounds like you're not wiling to step into a teaching role or share your insights. Do you think it is beneath you to answer questions? It sounds like you want to shame me for my technical incompetence in this area. Is this accurate? If yes, I would like to request that you please not reply to my posts, unless you answer my question authentically and with basic respect/kindness.

I wish HN was friendlier to beginners, or people willing to ask 'stupid' or 'naive' questions and who have a beginners mindset.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#79
post #34

I'll preface this question with the disclaimer that I'm a true believer in the mission of Coreboot/Libreboot. Playing devil's advocate, if Intel were to release the signing key for the ME, or Intel Boot Guard, wouldn't this increase the likelihood of a malicious vendor preinstalling a rootkit in hardware that uses Intel CPUs? To answer in advance regarding the likelihood of this happening. There's already been enough…

>wouldn't this increase the likelihood of a malicious vendor preinstalling a rootkit ? Vendors already fuse their keys using bootguard. So if they want to install rootkits, they can do that now. Lenovo already did that with superfish. Bootguard doesn't make any assurances about the quality of the bios. It just says to the consumer that this machine's bios came from the vendor. Sort of like the https padlock. I think…

The points you make in your post are very valid. My post was made in the context of the Intel ME's wide range of invasive capabilities. If your purpose was to perform surveillance on your customers, the ME would grant you even more reach than BIOS firmware would. You've already addressed the fact that users need to trust the quality of their firmware at face value. This is hard enough already, let alone with hardware vendors being able to access the ME.

Just to clarify ( as if I haven't clarified this enough ), I'm in favor of Intel releasing the keys.

Re: Why is the latest Intel hardware unsupported in libreboot? (2017)

#80
post #56
post #34

I'll preface this question with the disclaimer that I'm a true believer in the mission of Coreboot/Libreboot. Playing devil's advocate, if Intel were to release the signing key for the ME, or Intel Boot Guard, wouldn't this increase the likelihood of a malicious vendor preinstalling a rootkit in hardware that uses Intel CPUs? To answer in advance regarding the likelihood of this happening. There's already been enough…

The ask is not to allow users to install firmware with the vendor's key but with their own key.

Sure. This would seem to imply hardware vendors having prior access to the ME. The vast majority of users don't flash their BIOS with custom firmware, simply using whatever firmware the vendors give them. Users having the ability to install their own firmware would mitigate this risk, at the expense of a riskier overall ecosystem.
Post reply on HN