4 ms·
Indeed, mainline linux distros aren't free software either
by bowsamic 1y ago
Indeed, mainline linux distros aren't free software either
- lrvick 1y agoI have run nvidia cards without proprietary drivers for years. Nouveau. With the right hardware choices running blob-free linux is pretty straightforward.
- Andromxda 1y ago> Nouveau. Which Nvidia card do you have, and at which clock speed does your GPU run? > With the right hardware choices running blob-free linux is pretty straightforward. Unfortunately no. Features like SSE are pretty amazing and have made CPUs really fast and efficient, but they're unfortunately also large attack vectors, so vulnerabilities like Spectre or Meltdown occur. You need proprietary microcode blobs to fix those security vulnerabilities in your CPU.
- lrvick 1y agoAn Nvidia GPU is never going to run at maximum clock speed etc on open drivers right now, but the point is if you prioritize security/privacy/freedom you have choices. If you are not running games (which you should not on a system you need to be able to trust) maximum clock speed from a modern GPU is not needed for most workstation applications. I generally choose AMD GPUs for the best experience with open drivers these days on systems I need high GPU performance from. > You need proprietary microcode blobs to fix those security vulnerabilities in your CPU. Really? Which blobs do I need on RISC-V FPGA enclaves or my PPC64le Talos II workstation which has a fully open hardware motherboard and open CPU architecture? I make different tradeoffs on different hardware to be sure depending on the threat model of the task I am working on. x86_64 is a bit of a shit show, but you still only have to trust your CPU vendor even there, as it is possible to have FOSS firmware/software for everything else.
- cherryteastain 1y ago> generally choose AMD GPUs for the best experience with open drivers these days on systems I need high GPU performance from. Do you count binary firmware as 'open' or not? If not, AMD is not 'open' either. If you do, Nvidia now also has open kernel drivers. Mesa developers are exploring ways to get the new Mesa Nvidia Vulkan driver (NVK) to run on top of the open Nvidia kernel driver, which should eventually make Nvidia drivers as open as AMD.
- lrvick 1y agoThe binary firmware on an external module over a PCI bus should not have the ability to manipulate my current operating system and exfiltrate data without being noticed, but it is a non zero chance which is why on all my x86_64 workstations I run QubesOS so most hardware components are well isolated from each other with hypervisors, in addition to only open source code in my operating system and kernel layers, which is best effort today on such systems. I generally only run gaming graphics cards on dedicated gaming machines, not on workstations I need to be able to trust. You can't use accelerated graphics in qubes anyway, specifically because graphics cards are hard to trust. My requirements from a workstation are: 1. MUST have 100% open source code loaded in system memory 2. SHOULD have open source software in the boot trust path (coreboot/tpm2 secure boot, etc) 3. SHOULD have open hardware to the furthest extent possible that meets my use case 4. SHOULD be fully auditable and tamper evident using at-home tools and methods (like the Precursor)
- Andromxda 1y ago> maximum clock speed from a modern GPU is not needed for most workstation applications Well at that point buying a GPU is definitely not worth your money. You're better off using a CPU's integrated graphics unit. > I generally choose AMD GPUs for the best experience with open drivers these days on systems I need high GPU performance from. Yeah I agree on that, I also purchase AMD cards exclusively now. > Which blobs do I need on RISC-V FPGA enclaves or my PPC64le Talos II workstation I assumed we were only talking about x86. But I also believe that POWER9 CPUs don't have SSE, prove me wrong. I guess you're running Linux? I'd be very interested in looking at the output of lscpu from one of these machines. > x86_64 is a bit of a shit show I fully agree there