4 ms·
We spin our own build of Linux using Yocto. We are using an ARM-based SoC from NXP. We chose this to ensure that the device can only run signed, trusted code b
by gsreenivas 8y ago
We spin our own build of Linux using Yocto.
We are using an ARM-based SoC from NXP. We chose this to ensure that the device can only run signed, trusted code by implementing secure boot and signature verification of software updates. We will make a developer program available in the future.
I didn't use Protonet so I shouldn't speculate about what's similar or different about the products. I think we are in a time right now where people have a strong desire to own their data and are looking for a viable alternative to the cloud. They key, beyond building something very private and secure, is in nailing the experience and we're excited to share more about that.
- ThePhysicist 8y agoCool, thanks for sharing that info! While I think your approach is a bit extreme I hope you'll succeed, we need more solutions that put privacy, security and transparency first. It would be awesome if one could run your software on regular hardware though, as I really prefer a securely hosted server at a local data center to a computer sitting in my living room. Also, one year of limited warranty seems rather short for a product that is supposed hold my most important data.
- gsreenivas 8y agoThanks for your encouragement! I appreciate the feedback and keep tabs on our GitHub for what we open source down the road.
- joezydeco 8y agoWe spin our own build of Linux...We are using an ARM-based SoC from NXP. Okay, so that narrows it down to the i.MX family. We chose this to ensure that the device can only run signed, trusted code by implementing secure boot and signature verification of software updates. Maybe read this? https://blog.quarkslab.com/vulnerabilities-in-high-assurance-boot-of-nxp-imx-microprocessors.html https://blog.quarkslab.com/vulnerabilities-in-high-assurance...
- iancarroll 8y agoFrom the technical specs, it's almost certainly the i.MX 8, which as far as I know is not affected or listed on any of the errata for that vulnerability.
- joezydeco 8y agoI missed the part on the tech page that listed the A72, so yeah it's an iMX8. Hopefully the HAB fix is the reason for the 8. Otherwise this seems like overkill for the work involved.
- gsreenivas 8y agoGood guess and we looked at the i.MX but did not select that line of SoCs. We are using the Layerscape line of SoCs from NXP