Hard, Not Soft, Kill Switches
puri.sm
puri.sm
> As you can see, it is not a trivial matter to
> manufacture these HKSes. A lot of research and
> hard work went into the effort.
I mean, compared to all the other things one has to get right to design a laptop computer, switching these few signals is indeed very, very trivial.And while the webcam/microphone switches will prevent the particular devices from working, I'm not so sure about the WiFi card and Bluetooth. The microphone surely is dead by cutting the single signal line and the webcam by cutting its power.
But there's no guarantee that the W_DISABLE# pins are honored with every firmware of every possible wifi module that could be inserted into that slot. What if W_DISABLE#, on the card, is only a gpio that is checked by the WiFi chip's firmware? It would have been safer to also cut the power there, too. Or at least to verify that W_DISABLE# cuts off power to the RF PAs (transmitter power amplifier) of WiFi and Bluetooth in a way that can't be circumvented.
Maybe it was chosen because the "high" voltage isn't specified and the standard might say: "Pull down to GND to activate, leave open to keep card off." Then you don't have to think about the internal logic voltage of the circuit, you might fry the card if you pull up to 3v3 if the logic input is only 1.8V tolerant.
If the wires to the switch fail then the card fails on.
Much has been written about the fact that Apple controls both hardware and software design. What kind of integrations become possible by combining open-design hardware with OSS software like Linux and Qubes?
It probably costs a lot more than $250,000 to develop a laptop from scratch, so I wouldn't blame them for taking a higher level systems approach and buying in a pre-existing motherboard design. However, doing that inevitably gives up control of the design (which puts into doubt their claims of being completely open). If that's the approach they've taken, they're not particularly open about it.
Novena[1] had a total budget of ~750k$. It was done from scratch, with some nonstandard (and somewhat expensive) components (e.g. an fpga; it had a software defined radio included too, though it was a mostly-off-the-shelf-one).
To design and mass produce a laptop as slim and well integrated as the Purism laptop is significantly more work. To do so having never produced a laptop before would cost even more so. $250,000 really is a small amount of money when you're trying to mass produce cutting edge consumer electronics.
Of course they may (almost certainly do) have other sources of investment.
So, yeah, why all the solder and "chip" modifications?
The reality is that the chip/firmware/driver combination is tested by turning the power on once and then making it pass a few benchmarks that reviewers like. Doing something new and exciting may or may not work.
Certainly, some drivers are way better than others (ath9k is pretty good), but I imagine they tested the power up/power down method, noted that the kernel panics 1 time in 10, and decided nobody would buy their product if they implemented it that way.
EDIT: They use i5 and i7 processors, which IIRC use black-box Intel microcode... Also, i wonder if they support Libreboot? My apologies if it turns out i cannot read. Otherwise they look quite nice. I'm excited to see more "alternatives" in the "free as in liberty" laptop space.
EDIT 2: Some more information here: https://www.crowdsupply.com/purism/librem-13
EDIT 3: At least they're up-front about what's Free and what's not: https://puri.sm/posts/purism-software-freedom-deconstructed/
that's what I thought as well.
About the microcode, this won't be fixed. But see the weekly updates on their blog[1] that states progress they make with the coreboot developers. Hopefully they can free the number one problem with intel chips[2] which is the Management Engine firmware.
[1] https://puri.sm/posts/weekly-update-on-librem-production-201...
You can disable this in software by passing "bt_coex_active=N" to the iwlwifi kernel module, but of course, who knows if that's actually sufficient.
I'm pretty sure the situation with other vendors is similar or worse. Big vendors like Broadcom have terrible open source track records.
In reply to sibling poster about dip switches, it looks like there are little wires running inside the case from the four separate connections to the two DPDT switches, i.e., if you want to find a DIP switch and mount it to your laptop, the 4 wires are easily hackable.
They are going to use coreboot, which is free but includes some binary blobs from Intel. I don't think you can boot any modern x86 without a binary blob from the CPU manufacturer, unfortunately.
I also don't think it's possible to get any modern machine up without some device firmware blobs. The best-case is that all the blobs are provided onboard so the OS doesn't need to provide them, but they're still there and we have to trust them.
Purism seems to me an incremental improvement and I might buy one, but I really hope for a truly free machine someday.
Microcode is only one part of it. I was thinking of the ME firmware, and to a lesser extent the FSP. It's not possible to boot a modern Intel processor without ME. The ME has direct DMA access to all peripherals and can use the network interfaces directly, behind the operating systems back.
I believe AMD has similar things. They are all signed by the manufacturer and the hardware will refuse to load a replacement even if it existed.
If you don't intend to run the CPU at 100% all the time, you want to install those updates.
Similar issues (usually more subtle) exist for other CPUs
http://www.gaisler.com/index.php/products/ipcores/soclibrary
You get an open ISA w/ Open Firmware w/ open HW implementation under GPL that you can fab wherever, including MPW runs that cut costs. Or you can just buy the one's he sells which go up to 4 cores now. Developers porting browsers, flash, servers, whatever can use regular development boards to get most of it done. Gaisler and SPARC have been best option to jump-start open HW/SW movement for a long time. Just not utilized.
A Transmeta approach could be used with underlying RISC core for x86 emulation. Wouldn't be core i7 speed or anything but it could be acceptable. China's MIPS-based Loongson does this.
I am more excited in the continued development of the Novena laptop (https://www.crowdsupply.com/sutajio-kosagi/novena) but it's a shame there aren't any suitable modern processors to use in it.
Most open, security-focused laptop with the most closed, backdoored processor. It's funny shit.
Though I think these hardware kill switches should not be optional. A product that praises itself for privacy and security should have this as a base feature instead of asking $89,- separately for it.
I really wonder who the target market for this is.
Lawyers, activists, crooks are 3 easy examples.
The physical dual-position sliding switch has a lot of advantages, and yet it has almost completely disappeared from the electronics/computing world. I'd like to see it back.
Personally, I would consider having hardware switches to disable external sensors and wireless communications channels in a laptop to be a significant factor in a purchasing decision. Other things being equal, I would opt for such features, and I would be willing to pay a bit extra to have them.
Unfortunately, it appears that other things are not equal. Unless I'm missing something, these systems seem to be relatively expensive for the rest of their spec.
More significantly, there is only so much you can do with hardware alone. For now, we also have the usual problem with installing an entirely free/open source software base, which is that much of the software that is useful for getting real work done is not from the FOSS world and the closest FOSS equivalents are not competitive if they exist at all. Being on-line is essential for a lot of activities, but as soon as you're on-line there is still a problem if you don't trust at least the OS and networking software as well as the hardware, and in a Windows 10 world that surely won't be true for many who would be interested in this kind of hardware in the first place.
Still, this seems like a step in a healthy direction, and for that alone I wish them success.
That's why I'm hoping their next Skylake generation will come with an option for a 6820HQ or 6920HQ CPU [2] (4 cores/8 threads/8MB L3 cache), as well as options for 16 and 32GB of DDR4 RAM (but I assume they'll have that covered) and at least a relatively fast NVMe 256GB SSD drive just so I can run Qubes at maximum performance. Fingerprint authentication (along with software support for two-factor auth at login) would be nice as well.
I do think they need to drive their prices down in the future, though ($2,000 for a "private laptop"). Privacy and security shouldn't be just for the rich. Their laptops feel like they are at least 50% more expensive than what they should be. I imagine this will get better with scale. Their laptops also don't have to be "Macbook Pro quality". I think some compromises there in thinness and build quality can be reasonable, if it means dropping the price by $300 or so.
[2] https://en.wikipedia.org/wiki/Skylake_(microarchitecture)
To me these are better called "hard power switches".
[..]The Librem 13 has a 13.3" 1920x1080 Matte IPS screen that I thought looked great. It is nice and bright and to my eyes looks better than the 1920x1080 IPS screen on my X240. [..]
[..] I'm used to the relatively weak speakers that tend to come with Thinkpads so I was pleasantly surprised at the volume from the Librem 13 speakers. Speaking of sound, I've gotten some questions about how quiet the laptop is. The laptop does have a fan and features vent holes along the bottom. It's kicked on while I've typed with it on my lap and while you can hear it a bit in a quiet room, to my ears it's pretty quiet. Let's put it this way, you can't hear it over my typing and certainly not if you were using the speakers at all. [..]
[..] It's a bit tricky to compare keyboards between the X200 and the two island keyboards but I definitely preferred the Librem 13 to the X240. When it came to the X200 and the Librem 13 I think it's more of a tie. I like the extra key travel of the X200 but the Librem 13 keyboard actually felt a bit crisper, especially when typing heavily with more force. [..]
[..] Honestly the biggest issue for me personally is the touchpad mouse. I'm just a trackpoint person, I can't help it. That said, at my day job I have a buckling spring keyboard with a trackpoint in the middle of it, but since my home setup uses a classic Model M I've sort of been trained to not reach for it and reach for the physical mouse instead (and for the most part I just stick to the keyboard and keyboard bindings anyway). If Purism can fix the issue with palm presses generating mouse events while typing (which the multi-touch driver is supposed to solve), I think the mouse will be fine. [..]
[..] The final hardware feature I want to cover is the hardware kill switches. This was a much-requested feature by the backers of the original Librem 15 and the Librem 13 has them as well. Unlike software-based kill switches or keyboard combos, these switches literally cut the power to the wireless and bluetooth in one case, and the webcam and microphone in the other. I honestly don't know of anyone else who offers a webcam/microphone kill switch like this. I tested the webcam kill switch myself and not only did the video output from Cheese go black, dmesg reported that the USB device was completely gone:
[ 626.880277] usb 2-5: USB disconnect, device number 3
and when I flipped the switch back on, the device reappeared: [..]
I would immediately order a Librem-15 if it had (as an option) a keyboard with a trackpoint with physical buttons and without the separate number block on the right, i.e. a centred keyboard.
That was shocking to read, actually. I assumed that Purism wasn't the only company doing this.
I actually had one on my last laptop, namely a piece of black insulation tape which I had placed over the lens.
And the ME (Management Engine [1]) rears its ugly head. Even Google Chromebooks with a "write protect screw" do not actually wire the write protect screw to the hardware "disable writes" signal on the flash.
And it's because the ME is continuously writing stuff to its region of the flash and the ME cannot be disabled. Such a security fail!
Assuming these guys succeed the ME ceases to become a problem and the SPI chip can finally be write protected.
There are rumors of "back doors" that would let an attacker bypass the "disable writes" signal, but that can be countered by using a large number of manufacturers when sourcing your flash chips. Hint: SPI flash chips can be had from many places.
While it is still possible that some of the chips will have a back door, either the back door will be too hard to create a viable attack for, or users can verify the contents of their flash. (SPI flash chips are too simple to run their own cloaking algorithm.)
Users can take defensive measures if a widespread attack is detected. Defensive measures might include finding out which manufacturer produces vulnerable chips. By avoiding a flash chip "monoculture" it would apply the collective power of the internet to preventing a flash back door, thus making the write protect line an effective security measure.
The laptop that security conscious people buy is a more logical target than the laptop the random consumer buys.
Buying a better rated consumer laptop for cash in person, loading your favorite secure OS and locking it down as well as possible seems like a better path than buying anything label "secure" with your credit card attached to your identifying information.
I want hard buttons for power, audio, radio, and keys I type with. Not "smart" hard buttons either: simple, stupid, old approach to buttons or switches that just worked.
I'm unsure on how that would perform practically with audible soundwaves or if any other research has been done in that area. It would however be hard to mitigate, if possible at all.
Many security conscious companies routinely collect cellphones and other devices during meetings etc. NSA aside things get compromised by regular malware all the time.
I've had a small thought in the past to setup a 'luxury' service to retrofit something similar on smartphones. You would still be screwed during an actual call, since the mic would have to be on.. but a kill switch would still provide a fair amount of damage control in the event of a compromise.
If you go the extra mile and implement a 'read-only' connection to software you could remove most of the hassle for users.
Imagine moving the switch to the on position also answering an incoming call if the phone is ringing. Then when you hang up the software can send a signal to move the physical switch to the off position (but make it physically impossible to move it to the on-position from software).
Complete with a tiny LED to alert the user the switch is on.
But now I'm wondering, what's the purpose of the killswitch besides having no wifi-connection for a certain period of time?
I mean, when you switch back to enable wifi again, everything you did on your computer during 'airgap-time' is still there, waiting to be compromised by corps/govs? Isn't it?
Please correct me if I'm wrong. I'm really curious to this concept.
P.S. I really dig the design of their laptops.
edit: Changed markup and added P.S.
* Heightened risk of compromise in particular physical locations?
* Use in conjunction with something like TAILS so it's harder for someone who breaks into your computer to achieve persistence?
* Decreased risk of compromises that involve multiple machines attacking each other?
* Attackers may be wary of storing huge amounts of data persistently because the associated changes in storage media could be detected by forensic spot-checks?
(The third one probably requires that the forensic examination can get access to everywhere that the data could be stashed ... like nonvolatile memory inside onboard devices, not just the hard drive and main RAM contents.)
The trackpoint should be with three physical buttons and would be great if it comes without a trackpad - but at least an option to disable the trackpad should be there.
The keyboard should NOT have any separate number block like most of 15" laptops have today. Would be great if there would be as well an option to order the keyboard without any labels on the keys.
The trackpoint and keyboard requirements could be options upon purchase. I understand that I am part of a minority. The thing is, I feel helpless without a trackpoint. Mouse and trackpads are no options. And Lenovo makes me desperate.