6 ms·
To be fair, see: https://libreboot.org/faq/#intel https://libreboot.org/faq/#intel
by mikexstudios 11y ago
To be fair, see: https://libreboot.org/faq/#intel https://libreboot.org/faq/#intel
- cwyers 11y agoAnd they don't list any Nvidia hardware at all here, as far as I can tell: https://libreboot.org/docs/hcl/index.html https://libreboot.org/docs/hcl/index.html So I guess their solution is to hoard 2013-vintage hardware for the rest of all time?
- jeremy7600 11y agoOnly one desktop motherboard is supported. Can you even find them anymore? Only 5 listed globally on eBay.
- jlarocco 11y agoActually, if you click through, that desktop motherboard isn't even supported in the 20150518 release :-/
- jandrese 11y agoI was wondering this myself. I was wondering why they were focusing so much on AMD when all AMD did was copy Intel's horrible idea. It seems kind of pointless to continue the Libreboot project if they're not going to work on any modern hardware for the foreseeable future. Their recommended systems are all old and out of production. Fastest recommended laptop seems to be roughly a Core2Duo at 2.0Ghz.
- yuhong 11y agoThey don't even do microcode updates, which is ridiculous when you are running non-free microcode to boot.
- zokier 11y agoWell that's the good old GNU/FSF firmware reasoning; its "better" to have the same firmware permanently burned into a chip than have it software upgradeable. Also happens to be one of the reasons I think FSF has lost its way if they ever even had it in the first place.
- yuhong 11y agoFun quote from http://www.gnu.org/philosophy/free-hardware-designs.en.html http://www.gnu.org/philosophy/free-hardware-designs.en.html for example: "Any program in your computer, that someone else is allowed to change but you're not, is an instrument of unjust power over you"
- tadfisher 11y agoIs it Libreboot who is being ridiculous, or Intel/AMD? Is it worth trusting OEMs with wholesale access to your data and your networks?
- wmf 11y agoIs never-updated proprietary microcode somehow better than updated proprietary microcode?
- chris_wot 11y agoThat's a false dichotomy.
- yuhong 11y agoIt isn't in this case.
- AnthonyMouse 11y agoIn a significant sense it is. It means if it wasn't malicious from the factory then it can't be malicious now. The best security design for software-in-hardware always starts with the software being burned into ROM. Then you can pick from one of two ways to do updates. The first is the updates are received from the operating system during every boot, so removing power is a reset to factory. So if you throw the system disk in the trash and replace it with a clean one you know you have a clean system. This is in nearly every sense the best way to do it, except that you can't fix a firmware bug that exhibits before the OS boots. The second is to have some flash memory on the hardware that can be used to install firmware updates, but have a jumper that determines if the system will look there or in ROM during boot. Then if you want clean updated firmware you set the jumper to ROM, boot and install the clean firmware to the flash and then set it back the other way. The best solution is to support both and then ship the system with the jumper set to ROM. Then you can do 99% of updates automatically through the OS and in the event of a pre-boot firmware bug the affected user can still install the update manually if necessary.
- tadfisher 11y agoThey don't work on mainstream PC platforms, but for embedded use Coreboot/Libreboot has a much better story. For example, Atom and Geode systems support it basically by default, and many boards ship with it preinstalled.
- mtgx 11y agoOr we could keep pressuring AMD and Intel to open up that proprietary code.
- snvzz 11y agoit's time for: http://www.lowrisc.org/ http://www.lowrisc.org/ For desktops, it simply needs to get into the fast enough territory.
- chocolatebunny 11y agoI am both amazed and terrified. I'm amazed that we're in an age where the processor I'm using to do all the things I do has it's own processor that's running it's own OS, has a Webserver and running a Java stack. I'm also terrified about what this processor could do at any moment. Is there away to inspect the IME bytecode to see if they put any backdoors in there? How is this code updated?