Librem 13 coreboot report: It’s Alive
puri.sm
puri.sm
I don't know anything about PureOS and I've never seen coreboot in action, but this genuinely sounds like a selling point.
Intel HW without the dreaded ME would be super-nice.
Purism has been talking up their work on a free firmware and disabled ME for two years now. They haven't gotten anything working until now.
I like what they're trying to do, and (roughly) how. I bought a Librem 13 and received it a year ago. But my overall impression is that they just didn't have the familiarity and expertise they needed on the software and firmware (and not enough money to buy enough expertise). Thus the slow and long-stalled progress on the coreboot port, the very slow and still somewhat disappointing development of the touchpad driver (which was the only driver they had to do real work on), and the confused/misinformed promises about the ME for the first year or so of the project.
But there isn't an alternative that's better in all dimensions, at the moment.
Does it even have a supported chipset?
But everything else is great.
I can confirm that pixel does use coreboot and has a backup seabios (also open source) if you want to use that (ended up being slightly easier to run arch via seabios).
Why have hardware companies always wanted to bundle crappy software?
It would be nice if it was open source, but it's a bit more understandable than the Intel ME. The baseband firmware often has regulatory requirements the rest of the phones doesn't have. It comes from a different vendor, and is compartmentalized. I too would like it to be open source, but it seems like a different situation.
The requirements as they stand are nothing more than an excuse for shitty networks to spend less on reliability and security while providing a convenient backdoor for state-level actors.
Imagine if such a firmware had a slider that boosts the transmitting power. People would love it but the network as a whole would suffer.
But:
1. closed-source driver code always has security holes. Having insecure devices is as bad for public policy as jamming.
2. if I really want to jam cell signals I can take the door off my microwave. (kids listening at home -- don't do this). Anyone who's ever flashed an android device will agree that it's easier to hotwire the microwave than build bootable code for the handset.
3. the radio controller runs a sophisticated RTOS that (I assume) can read the phone's RAM and execute wacky RPC. And most cellular networks have experimented in the past with some form of rootkit or spyware. Dear Verizon: I paid for the device. Let me own it.
One answer that compromises between consumer needs & FCC needs is to say signed code has to be open source and verified-build.
I'm guessing there's a lock-in argument for the radio chipset creator. Being the only vendor of software for your hardware means vertical integration, i.e. there are fewer companies expert in any part of your stack.
In principle it might be possible to upload code through an undocumented interface and get it to boot up later. Nobody (outside Intel) knows.