4 ms·
It's gotten to the point where I only feel totally comfortable using machines I've hardened myself. My hardened laptop is an older Thinkpad laptop with LibreBo
by deftnerd 10y ago
It's gotten to the point where I only feel totally comfortable using machines I've hardened myself.
My hardened laptop is an older Thinkpad laptop with LibreBoot to replace the BIOS, microphone and speakers and camera disconnected internally, removed the wireless cards, encrypted the partitions, and use Whonix as the OS. I've password protected the BIOS and it's set to boot only from the hard drive and I've also epoxied the screw heads in place as well as put globs of epoxy over all the ports other than USB in order to protect against hardware devices that can access memory through DMA vulnerabilities.
It was mostly an exercise in "how secure can I get". I'm not sure what else is possible.
If someone manufactured and sold a more modern hardened laptop, I would be interested in buying it.
- tychuz 10y agoI'd rather use my closed source safe operating system like Windows instead of having open source stuff with hearthbleed like stuff open for every hacker, thanks.
- avaloneon 10y agoYou might be interested in something like ORWL[1], which is arguably the most secure consumer PC I've ever heard of. It has tamper-resistant features, full disk encryption, and a secure co-processor which does things like disable the USB data paths when the system locks. Admittedly, though, it's not a laptop. As far as laptops go, the librem 13[2], with Qubes OS and coreboot would be a pretty good bet. If you haven't already, definitely take a look at Qubes OS[3]. It offers security by compartmentalizing different workspaces in different vm's managed by Xen so, in theory, even a kernel exploit isn't getting very far into the system. [1] https://www.crowdsupply.com/design-shift/orwl https://www.crowdsupply.com/design-shift/orwl [2] https://puri.sm/librem-13/ https://puri.sm/librem-13/ [3] https://www.qubes-os.org https://www.qubes-os.org