7 ms·
My second thought on reading this was how can a server be PCI compliant with Intel management engine installed? but a quick search shows that Intel have thought
by ollybee 12y ago
My second thought on reading this was how can a server be PCI compliant with Intel management engine installed? but a quick search shows that Intel have thought of this: http://www.intel.co.uk/content/dam/www/public/us/en/documents/white-papers/vpro-pci-dss-retail-paper.pdf http://www.intel.co.uk/content/dam/www/public/us/en/document...
My first thought was that it seems increasingly clear that Stallman has been right all along.
- morganvachon 12y ago> My first thought was that it seems increasingly clear that Stallman has been right all along. The problem is that being philosophically right doesn't always mean being practically right. In order to create the perfect Stallman-esque machine, one would have to design everything from the logic chips up from scratch, because in the end, no third party can be trusted. He says this himself about the Loongson system he uses daily; he considers it a compromise but one heavily weighted in his favor. In short, Stallman has been right all along, but there's little we can do about it from a practical standpoint.
- throwaway2048 12y agoWe can certainly do a lot better than this, an attitude of "unless its perfect its futile to even try" is defeatist bullshit, and not what Stallman endorses at all.
- morganvachon 12y ago> "unless its perfect its futile to even try" I didn't say that. I said there's little we can do, not nothing we can do. And there are people, Stallman and others, who are doing something. I'm simply acknowledging that it's a mountain, not a foothill.
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- sinetek 12y agothere's plenty we can do. Bunnie's Novena laptop is a great example of moving in the right direction. It all depends on speed I guess; you could have a completely open hardware laptop using an FPGA, but speed would be an issue for sure
- sp332 12y agoThe Novena has a quad-core Cortex A9 as well as the FPGA. A lot of people who buy it probably won't use the FPGA at all. In fact, the Spartan-6 FPGA might have more secrets than the CPU.
- pakled_engineer 12y agorms doesn't have the Loongson netbook anymore, he rolls with a Gluglug X60 now I believe.
- morganvachon 12y agoThanks for that, I'll have to look into that device and see what it's all about. Edit: So it's an off the shelf Thinkpad X60 with fully open source software? I thought that was something he was wary of, given his stance on Intel's partially closed designs. Also, wouldn't the TPM chip be an obstacle given the privacy concerns surrounding it raised by RMS himself?[1] From what I saw from the gluglug website, there is no mention of removing or disabling the TPM module, though I suppose one could remove it from the board themselves after purchase. [1]: https://www.gnu.org/philosophy/can-you-trust.html https://www.gnu.org/philosophy/can-you-trust.html
- dublinben 12y agoFrom my understanding, you can disable the TPM by removing the kernel driver and any other drivers. The X60 is the last Thinkpad model in which it lives in a separate chip.
- morganvachon 12y agoIs it really disabled though? The hardware is still there unless you extract the chip itself. For example, Intel's AMT exists at a level so far below the software and UEFI/BIOS that you can have just power and Ethernet/wifi plugged into the board, and it will "phone home" if it is configured to. Boards with GSM modules can even be controlled remotely via SMS commands. I realize that TPM and AMT are completely different animals, but AMT shows us that a low level "security" device on board can potentially mean compromised privacy and loss of control.
- pgeorgi 12y agoThe TPM can be fully controlled by the user (or ignored altogether). Much misinformation about the TPM stems from the Anderson paper, which mixed up real TPM implementation and then-future Palladium concepts and claimed that this all runs in contemporary TPM chips. In reality, TPM is a chip with (rather slow) crypto functionality and a reasonable secure storage whose content can be "sealed" to certain system states. That state information is pushed to the TPM by the host system, since the TPM is a fully passive component. (Exception: new Intel chipsets feature 'Boot Guard' where the chipset pushes some root trust information to the TPM in a way that code on the CPU can't modify - but the TPM is still passive) If you control the firmware, you can build a reasonably secure environment using the TPM. But coreboot (or its libreboot distribution) by default don't even do that with the TPM.
- gaius 12y agoone would have to design everything from the logic chips up from scratch You mean like http://www.greenarraychips.com/home/products/index.html http://www.greenarraychips.com/home/products/index.html ? Stallman's endorsement of Chinese hardware illustrates tho' that he values software freedom over, y'know, political freedom, which puts him on dodgy ground IMHO.
- morganvachon 12y ago> Stallman's endorsement of Chinese hardware illustrates tho' that he values software freedom over, y'know, political freedom, which puts him on dodgy ground IMHO. Show me a laptop or desktop computer not made wholly in China, or at the very least, containing a majority of parts not made in China, and you might have an argument here. The fact of the matter is, non-Chinese-made hardware meeting all of his requirements is scarce to the point of extinction. Maybe (maybe!) a couple of Korean phones and tablets have no DRM, no NDAs attached, no hidden features, no binary blobs required for full utilization. Or in other words, if you're so worried about political freedom, you'd best throw out that smartphone, that laptop, that desktop, that gaming console, that car stereo, and so on. Dodgy ground indeed, isn't it?
- pgeorgi 12y agoAnd even those Korean phones and tablets are probably built in the Kaesong Industrial Region, more or less directly helping North Korea.
- sedachv 12y ago> The problem is that being philosophically right doesn't always mean being practically right. "Practical" is a code word people use to mean whatever is convenient for them or is on their agenda. You can use the argument "that's just not practical!" with whatever evidence you can come up with as an objection to almost anything, which makes it a poor argument. That's why we need unambiguous and objective philosophical positions to make decisions in specific circumstances. What you're really saying is that working against the development of surveillance and control technologies by private capital and government decision makers is hard and so is not "practical."
- morganvachon 12y ago> "Practical" is a code word people use to mean whatever is convenient for them or is on their agenda. I don't see it as a "code word", I see it as it is defined: In practice, as opposed to in theory. And I don't have an agenda, I'm just making an observation. > What you're really saying is that working against the development of surveillance and control technologies by private capital and government decision makers is hard and so is not "practical." No, I'm not saying that at all; you're putting words in my mouth that I never uttered. I'm simply saying that in theory, fully Free and Open Source methodology is the best way to ensure that we live fully Free digital lives. In practice this is difficult (but not impossible) to achieve, and it certainly is worth striving for. I'm not saying you don't have a valid viewpoint, but you don't have to make up your own version of what I said and attribute it to me to make your point. You can argue on your own merits and not resort to grade school tactics (at least I hope you can).
- sedachv 12y ago> In practice this is difficult (but not impossible) to achieve Why? Without going looking at particular FLOSS situations, this is just defining the word "practice" to mean "difficult to achieve." In "practice," Linux on mobile phones was difficult in 2007 and is easy today. > I'm not saying you don't have a valid viewpoint, but you don't have to make up your own version of what I said and attribute it to me to make your point. You can argue on your own merits and not resort to grade school tactics (at least I hope you can). I'm not arguing with you, I am pointing out that your assumptions are vague and your conclusions circular. There is not a single "practice" that just happens to be some bad guy opposing FLOSS because he hates your freedoms. Is Linux on the phone a good thing? Android benefits a tremendous amount from Linux but at the same time Android phones are locked down black boxes with huge privacy risks. So it's one step forward for FLOSS practice, two steps backward for privacy theory. People accuse Stallman of being impractical, but stricter adherence to theory (GPLv3) would have prevented the practical problems of locked bootloaders on Android phones. It's not as simple as saying "theory easy, practice hard."