4 ms·
For the layman, what does this mean/offer?
by Hates_ 10y ago
For the layman, what does this mean/offer?
- dima_medvedev 10y agoCurrently most modern hardware we own contains a backdoor at the BIOS level. It's a black-box blob of code that does all the initialization and can potentially call home (Intel/AMD) and do almost everything on your system. Another thing is that we can't debug and fix BIOS-related problems (like software suspend). More here https://libreboot.org/faq/#intelme https://libreboot.org/faq/#intelme
- throwaway77384 10y agoIntel has been sorta/kinda comprimising every single computer containing their chipsets for quite some time now. The Intel Management Engine will make a lot of tinfoil hats tingle: http://hackaday.com/2016/11/28/neutralizing-intels-management-engine/ http://hackaday.com/2016/11/28/neutralizing-intels-managemen... Libre-boot and coreboot promote a kind of transparency where you know what your system is booting and why. It's much better than having this proprietary walled garden with astounding amounts of power/control inaccessible to anyone but Intel in your machine. Intel would of course argue that this is necessary for good crypto and it's for the users, not against them. Which may hold true a little bit....until it's compromised by someone.
- bantunes 10y agoOpen source "BIOS" and insanely fast (some times <1 sec) time to GRUB menu from power on. More info https://en.wikipedia.org/wiki/Coreboot https://en.wikipedia.org/wiki/Coreboot
- aibrahem 10y agoA couple of years ago both Intel and AMD started developing their own solutions that allows them to offload some the functionality that used to happen on the main processor to another co-processor placed inside the chipset on the motherboard, functionalities like power management, secure booting, USB handling..etc The problem is not only that this co-processor is running it's own operating system with full unrestricted access to the systems main memory and network interface, but also that the main processor can't actually tell what the co-processor is doing with this data or when does it access it, on top of that both Intel and AMD delivers you the software running on the co-processor as a binary blob so we can't really be sure if it's secure, has backdoors, spying on you, etc.. LibreBoot/Coreboot are projects to write an open-source BIOS for x86 hardware, and since a big part of the BIOS is running on this co-processor you only have a choice of either using the binary blob provided by Intel/AMD or lose the functionality provided.
- bryanlarsen 10y agoThis is a feature designed for enterprises. Imagine you had tens of thousands of machines in your company. A secondary processor that's hardened against virtually all attacks running an independent operating system allows you to manage and audit those machines even if those machines have been compromised maliciously or just messed up accidentally.
- madez 10y agoIf that were the use-case then nothing speaks against giving full control to private customers over their chips or not including these features into chips for private customers, while neither of both is done.
- bryanlarsen 10y agoBoth would cost significant money and effort. The first would probably require replacing lots of purchased code with code that can be disclosed, and doing a full security audit of the remaining code. The second would require separate SKU's and validation for consumer vs business use. The first would benefit enterprises too by replacing the current "security by obscurity" scheme with auditable security, so that's where we should probably focus our lobbying.
- madez 10y agoI don't see how giving full control to the user requires significant money and effort. It is not necessary to release the full source code. Providing hardware documentation and a way to flash the firmware is enough. This shouldn't put AMD in front of significant problems.
- wolfgke 10y ago> If that were the use-case then nothing speaks against giving full control to private customers over their chips or not including these features into chips for private customers, while neither of both is done. This is (as far as I know) only one use-case. Another one (that makes Hollywood drool) is implementing DRM.