Purism builds a secure tablet with physical wi-fi and camera switches
techcrunch.com
techcrunch.com
When I closed the case up, I put some globs of epoxy on the inside so it wouldn't be possible to open it back up without major and obvious shell damage.
I do something similar with my laptops. I use older Lenovos compatible with Libreboot and just disconnect the microphones and cameras and seal up the ports with DMA memory access (firewire, eSATA, etc) and seal up the case.
It makes it so I can't repair them if something goes wrong, but since they're ancient machines they're very inexpensive.
$1300 for a 11" Core-M5 tablet, 8GB RAM, 256GB SSD, including the keyboard.
Honestly doesn't seem that bad to me, if the product is well made. It's similar in price and processor specs to the Macbook (Core-M3, 8GB RAM, 256GB SSD for $1300).
I was just saying that if your primary goal is adding a bit of tinfoil to your desire for security and privacy, it's easy to just get an old tablet and modify it to remove some of the most common attack vectors and environmental observation capabilities.
It can probably be used for encrypted communication as well, though there are problems with entering keys of your correspondents into the computer that only sends data.
I don't know how practical this is, but seems resilient against hardware back doors.
That's a "data diode". The chat system that uses data diodes is "Tinfoil Chat".
https://cs.helsinki.fi/u/oottela/tfc.pdf
It should be very robust against attack, but be careful to note the exact features that TFC provides, which are a bit unusual.
https://puri.sm/posts/intel-me-less-petition-goal-met-early/
They delve into x86's freedom and security issues, then discuss the pros and cons of ARM chips versus OpenPOWER chips.
For an open laptop such as Bunnie's Novena, ARM is a fine choice.
For Raptor Engineering's Talos Secure Workstation, OpenPOWER was a better fit.
Intel chips from 2008 or earlier still work. I like the Thinkpad X200, the most recent Intel-based laptop that can be flashed to use Libreboot instead of stock firmware.
For workstations, Raptor Engineering is working on an open hardware motherboard design based on the POWER architecture, which IBM recently opened. https://raptorengineeringinc.com/TALOS/prerelease.php
In the future, RISC-V looks promising.
There is also a subset of ARM chips which seem safe.
While AMD's use of ARM processors (and with it, TrustZone) to fashion a security blackbox on your chip is dishonest and terrifying, it is not evidence that TrustZone is what you're saying it is. I invite you to research more into TrustZone, so you'll be less afraid of ARM.
Here's the conversation I see:
1. How do they deal with the intel management engine in all intel chips? https://libreboot.org/faq/ 2. AMD and ARM have them, as well. It's almost impossible to avoid these hardware backdoors. 3. Cite? and our remarks back and forth.
Who is talking about ARM TrustZone? That wall of text was libre boot's explanation (from the original link) of what AMD and ARM's Intel Management Engine equivalent system is.
further, your "anyone that tells you your emperor is wearing no clothes is trolling" attitude is something HN'ers attempt to avoid.
If Intel is the only vulnerability, we're doing miles better than your average device, where any of a dozen sources can compromise you.
Librem is not perfect. It's just a step forward but if we don't start somewhere the ball will never get rolling.
I'm happy to support them, and hope the next 5 years sees a decent cpu without security problems. We're moving the right direction for once.
A Novena from Bunnie? https://www.crowdsupply.com/sutajio-kosagi/novena
A Lemote Yeelong? They're pretty difficult to even buy... http://www.aliexpress.com/store/product/Yeeloong-Notebook-co...
minifree.org products rely on hardware being available that does not have an Intel ME or equivalent. That hardware will only get harder to find as time goes on.
When faced with a challenging problem like this, I find it saddening to see the Free Software community turning on each other and fighting instead of looking for multiple parallel solutions.
https://www.crowdsupply.com/eoma68/micro-desktop
I prefer the Novena and the EOMA68 over the Purism project because they seem to do more than just promising the impossible.
> what is your proposed solution?
I don't think there is one yet. We need those who don't compromise the vision from the start to win and get enough funds to continue. The EOMA68 project seems most promising to me because it also aims to reduce waste, which is very important to me and something that appears to be ignored by most people.
I'm using Libreboot on my Thinkpad X200s (I did not buy it from minifree). The X200s does have Intel ME/AMT and it can be removed by deleting the BIOS chip.
Exactly! I want statements I can trust, not a marketing spiel.
Take this webpage from the Replicant project [0]. They talk at length about the state of the industry, what is ideal, what is achievable, and what they have managed to accomplish. There is no marketing appeal to buzzwords or glossing over the fact that there is no ideal product right now.
[0] http://www.replicant.us/freedom-privacy-security-issues.php
Purism loudly trumpets their roadmaps[0] and plans[1] so as to suggest a trajectory towards totally free software, but until they achieve it their product is hardly worth the premium compared to installing Linux on an ultrabook of your choice.
[0] https://puri.sm/posts/roadmap-to-a-completely-free-bios/ Here they outline many things that need to be done. But note the language- "Purism’s goal is to publish a Free Software implementation ... as soon as an implementation is available." But who is responsible for implementing it?
[1] https://puri.sm/road-to-fsf-ryf-endorsement-and-beyond/ Note that the FSF hasn't actually endorsed them yet, although this page is supposed to convince you that they're awful close. Why not wait until they're actually endorsed?
So what does a Purism laptop actually give me? A kill-switch and the warm feelies.
There is value in releasing a security-oriented laptop, pre-configured and tested to work with Linux. However their marketing spiel is disingenuous. Constrast with Replicant, who are very open about their shortcomings and that an ideal device is not currently attainable: http://www.replicant.us/freedom-privacy-security-issues.php
1. Purism will only use free/libre and open source software in the kernel,
OS, and all software.
Free/Libre and Open Source Software is software that respects your
freedom. Nonfree, or proprietary, software and installable firmware
will be strictly prohibited within Purism. We promise that a Purism
system and all its components will be free according to the strictest
of guidelines set forth by the Free Software Foundation’s Free
Software Definition.
2. Purism will design and manufacture hardware that respects users’ rights
to privacy, security, and freedom.
We promise that Purism systems will use hardware and software that
respects users’ rights. Nonfree, or proprietary, chipsets that require
installable firmware binaries into the kernel will be strictly
prohibited within Purism.
"Strictly prohibited" my arse. They've been using Intel chips with non-free firmware since day 1.The components which power the management engine are always present. However they lock you out of using those features unless you pay for a vPro chip.
Buying a chip without vPro means the Management Engine still lives on your device, it's just that you aren't allowed to use it.
Firstly there are no labels, so it's unclear which switch is for what, or even the on/off position. Secondly, they've used switches that are entirely unsuitable for exposing on the edge of the laptop - after 1 week of usage one of the switches simply broke off when putting the laptop in a bag, and expect the same thing to happen for the other switches soon.
And it's pretty easy to change the on/off positions this wa, which is a problem because the camera/microphone has no led indicating the position.
That sounds like the sort of scale where the NSA will be intercepting every delivery pro-actively in order to install hardware tapping devices or other security bypasses.
edit: I would recommend that Purism take detailed photos of the insides, front and back, and put signed copies of them on the website.
The idea is from Eric Michaud and Ryan Lackey's presentation at 30C3 (2013 CCC), but this is a decent writeup:
I suppose we could all just abandon computing entirely. But I kind of like the internet and all that.
This product feels like a (most likely unintentional) honeypot.
Expecting someone who needs/wants this sort of security in a laptop to homebrew it is unrealistic. So by your logic everyone should just despair and be completely paralyzed by their inability to protect themselves. Surely there is a better way?
Unless that company has >100M users and turns security on by default.
Im not worried about Purism outside same failures everyone else has. More likely to screw us by accident than anything.
――――――
¹ — https://puri.sm/
For those curious: PureOS is a Debian fork. PureBrowser is an Iceweasel fork which itself is a Firefox fork. [0] Assuming this is the official repo, there are some concerns of mine that security updates are out of date.
[0] https://github.com/purism/PureBrowser
>PureBrowser takes Debian's Iceweasel and includes a number of the changes made for GNU's IceCat, along with some extensions that we like - privacybadger, ublock, https-everywhere, html5-video-everywhere, and decentraleyes.
>DuckDuckGo's search page is the default, as well as the homepage.
We need a legal requirement that you cannot sell a computer without physical switches for camera, audio, networking, and wi-fi. I think selling gear in any other configuration is too dangerous in a non-obvious way to the average consumer.
We can stop this now, or we can go on for another decade or two and try to stop it. It's easier done now, when we're first seeing how this is all going to turn out.
If people truly want to buy equipment that saves cost by removing physical switches, there's no reason the government should be stopping them.
The problem here is that you are effectively making an open-ended, infinite choice. You have no idea what that information could be used for. You might have grandkids who could suffer. There's no reasonable exchange here that makes sense for the individual.
So I just don't see how a free and informed choice could be made, since the person making the choice has no idea what they are choosing. This is a similar question to asking if people have the right to sell themselves into chattel slavery. I think the answer in that case is also "no". Indentured servitude, perhaps -- but that's a discussion for another day.
You could probably do an easier job forcing open source just by requiring all government contract hardware / software to provide you with all design schematics and sources that you then immediately publish for consumers to utilize. Without IP bullshit, once someone is publishing it, you can trust it if you personally verify it securely.
So anyway, the correct software freedom position (what Purism is at least claiming to support) is bigger and independent from libertarianism, so if we were to have the optimal legal framework, it needs 3 things: abolish patents and copyright (not trademark though), mandate source release for published works, prohibit DRM.
I mean if someone is required to be that concerned about security I'm certain they will justify the costs to go pick-up a device versus risking having it compromised.
- Quick and reliable disclosure of and turn around on vulnerabilities
Can you explain this point please. I've not heard it used in this context before.
> "Quick and reliable disclosure of and turn around on vulnerabilities"
Sadly there's only a very loose correlation between the popularity of a product and the corporations ability or willingness to disclose vulnerabilities or release patches in good time, nor even patch them at all (in the worst cases).
An apt example of this is how poor many OEMs are at pushing Android updates to popular tablets and smartphones. However I do appreciate you specified iOS and Apple are generally better at supporting older devices than many Android OEMs. But I'm replying to the "herd" point more generally.
> Can you explain this point please. I've not heard it
> used in this context before.
What I was poorly trying to explain was my feeling that there's sufficiently little data flowing through Tor, and probably sufficiently interesting data in there, that my guess it's it's seen a lot of scrutiny for all sorts of attacks, and there's a real possibility nodes are storing traffic for future decryption when vulnerabilities are shown. I try and lock almost all of my data down to HTTPS over a VPN (F-Secure's Freedome), which my gut feeling is is probably a lot less exciting.In the same vein, a device that's meant purely for TOPSECKRITDATA?! and has a small install base feels like a much bigger target as I'm signalling I have something I am explicitly trying to hide.
>> "Quick and reliable disclosure of and turn around on
>> vulnerabilities"
> I do appreciate you specified iOS
Yeah, I probably didn't express this very well. But I do trust Apple to take it seriously, and I don't think I could take seriously the idea of running an Android device these days from a security and privacy perspective, which is sad.Pragmatically, security needs to match the circumstances in order to get a fair balance between usability and security. For most people, hiding inside the noise is "good enough". However the issue arises if any one person gets the limelight thrust upon them for whatever reason. And we've seen examples of this with the phone hacking scandals in the UK and how some journalists also search social media accounts of previously unknown individuals who might hit the headlines. In situations like this, you can no longer hide your signal amongst the noise of the internet as you're not being specifically targeted.
So I guess the point I'm trying to make is the signaling argument only works because the odds are in your favour. But like with any game of chance, there's always the slim chance that you might be unlucky.
At least with stronger levels of security, your comms might be more visible in some circumstances, but at least very little can be ascertained from those comms. Generally speaking of course. However going back to your VPN vs Tor argument specifically, I do agree with you that the security benefits of Tor are largely overstated, so it's not something I use personally myself either.
[1] https://en.wikipedia.org/wiki/Security_through_obscurity
> in order to get a fair balance between usability and
> security. For most people, hiding inside the noise is
> "good enough".
I'd say it is different. This "herd security" business only matters if your adversary is the NSA. In which case you will need a complex security strategy that goes way beyond just picking OS.
If on the other hand you just want devices that behave reasonably, then you should select your devices based on their behaviour.
If it can be obtained through automated exploits, the cost-benefit ratio changes drastically.
If you have nothing to lose you have nothing to hide
If you have nothing to hide you have nothing to fear.
my moto from the pre snowden/opm hack days.
quite nice that it doesnt get me downvotes anymore.
Of course I know that you can't have freedom and security these days but should we just start re-labeling the states as a different type of government?
I'm by no means an expert however if we are to have freedom to keep our secrets why is it shameful to do so - even if it is "something to hide" is fearful to divulge we should still have that right to make the choice.
Correct me if I'm wrong, please, because I'm still very young with politics and as such am still learning a lot about it.