3 ms·
This product makes full disk encryption a bit more convenient, but that's about it. Even that turns something to know in something to have, which you could argu
by bwindels 10y ago
This product makes full disk encryption a bit more convenient, but that's about it. Even that turns something to know in something to have, which you could argue is easier to coerce someone into handing over.
The parent comment is right to point out this computer has a fully functioning Intel ME, running it's secret, unaudited, possibly backdoored, firmware on the co-processer which runs even when switched off, and can interact with the rest of the system undetected. Any "secure" system with this foundation isn't really secure.
IMHO a product which would focus more on this (like libreboot laptops) can make a bigger claim on doing something for security than this.
- talltower 10y agoI respect your opinion on this. We sought to build hardware that is a significant step up from what is available on the market today in terms of access control and tamper protection. We also open source the BIOS and customize it the most we can afford to minimize the ME capability thanks to Eltan's help. Secure cannot be an absolute state, it can only be temporary... till the 1st one finds a way to get in. Execution of non-auditable code is what we deal with on nearly every machine on the market. We are minimizing this, while still staying compatible with peoples use models. We are as open and transparent as we can legally be. In our plan, this is only one step in the direction of taking back control of the machines we all are working on and want to trust completely. https://www.orwl.org/wiki/index.php?title=File:SowDESIGN-SHIFTORWLPUBLIC20160902.pdf https://www.orwl.org/wiki/index.php?title=File:SowDESIGN-SHI...