4 ms·
Do Libreboot supported hardware devices, which appear quite old, still receive CPU patches? If not, it is probably time to stop using it. Coreboot may give you
by forward1 3y ago
Do Libreboot supported hardware devices, which appear quite old, still receive CPU patches? If not, it is probably time to stop using it. Coreboot may give you a fighting chance however.
- justaj 3y agoIIRC LB supports microcode updates, but I don't think older CPUs will receive new microcode updates from CPU vendors. Then again, newer CPUs have a host of other problems, like only supporting platforms where rolling your own boot firmware / UEFI is next to impossible. Personally I think the CPU has a much lower attack surface than something like UEFI (microcode updates are also pretty tiny), so I would rather have an outdated CPU than an outdated / vulnerable UEFI implementation.
- forward1 3y agoDisagree entirely. With an outdated CPU, you could be owned just by running Javascript on the wrong site. Not so with a vulnerable UEFI/BIOS, that requires additional privesc as is seen here.
- justaj 3y agoHmm, I see your point. Couldn't such CPU bugs be patched / mitigated in software (which would then incur some performance penalties) ?