4 ms·
If you try to read the article, including the linked projects, it helps a lot rather than broadcasting every nascent thought that pops up in the head to the int
by bubblethink 7y ago
If you try to read the article, including the linked projects, it helps a lot rather than broadcasting every nascent thought that pops up in the head to the internet.
All the ingredients have been a long time in the making. To summarise, it builds upon coreboot, heads, nitrokey, and me_cleaner, all of which are open source and have been developed by various people in this domain who also know what they are doing. It uses a thinkpad x230 as it is an ivy bridge processor, the last generation of intel processors whose initialisation is open source and well understood. If you would like to read more about this specific combination, you can also read at https://www.qubes-os.org/doc/certified-hardware/#qubes-certified-laptop-insurgo-privacybeast-x230 https://www.qubes-os.org/doc/certified-hardware/#qubes-certi... .
- andy_ppp 7y ago>> it helps a lot rather than broadcasting every nascent thought that pops up in the head to the internet I think you mean "broadcasting every nascent thought that pops up into your head to the internet". I did read the article! I'm sorry that you feel hurt by me not trusting your hardware company but it's a problem that you will have to overcome if you are going to sell this more secure hardware to people. Maybe not insulting people who have valid concerns about your product might also be a good place to start. Anyway, good luck with it, I hope you find a business here that is useful.
- bubblethink 7y agoIt's not my hardware company. No affiliation with them. I am not hurt; just annoyed because you proclaimed, "I trust this much less". This is precisely the goal of these projects. i.e., To reduce the trusted computing base. And the company is a fairly small part of the puzzle here. A lot of man hours have gone in building and reverse engineering various parts of the stack. Your statement is roughly similar to "I trust this much less" if it had been made sometime in the 90s on the linux announcement thread.
- deleted 7y ago[deleted]
- danShumway 7y agoI also read the article, and did look at the linked projects, and it's not clear to me how they solve GP's issue, because the company is still providing these solutions precompiled on hardware they control. How does GP know that everything is actually being provided unmodified, without any backdoors? > it helps a lot rather than broadcasting every nascent thought that pops up in the head to the internet. I don't think this is helpful, it's unnecessarily antagonistic and dismissive. GP's point seems reasonable to me; I don't see anything here that means that the Thinkpad x230 couldn't be modified before installation/paring, or that the tools themselves couldn't be modified before the laptop was shipped. If there is a reason to trust the initial build process, the linked page isn't explaining what it is.
- bubblethink 7y ago>How does GP know that everything is actually being provided unmodified, without any backdoors? They don't need to. That is precisely the point. The entire software stack is open source and reproducible (except a few KBs of Intel ME). As a press release, the linked post is brief. If you wish to read more on the technical aspects, here are all the constituent projects: https://coreboot.org/ https://coreboot.org/ https://github.com/osresearch/heads/ https://github.com/osresearch/heads/ https://github.com/corna/me_cleaner https://github.com/corna/me_cleaner https://github.com/nitrokey https://github.com/nitrokey A good talk if you prefer video: https://media.ccc.de/v/33c3-8314-bootstraping_a_slightly_more_secure_laptop https://media.ccc.de/v/33c3-8314-bootstraping_a_slightly_mor...
- andy_ppp 7y agoOkay this is interesting then, thanks for informing us better about what this all means and why we don't 100% have to trust the OEM of this hardware.