For your portable needs there is: https://puri.sm/posts/purism-librem-laptops-completely-disab...
For your portable needs there is: https://puri.sm/posts/purism-librem-laptops-completely-disab...
— FX 8350 (Piledriver) from AMD with no PSP: very cheap, no flashing necessary, but not the best performance. Single core performance much worse than even Pentium G4620[1].
— Some Intel processors and a Raspberry Pi: much better performance but you have to ME_Clean the firmware, hence the Pi.
— POWER9 processor for amazing performance and completely open & free firmware all around: the CPU is $400 but you get $400 worth of performance, PCIe 4.0 etc., however the only mainboard you can get right now costs $2000, and it’s not x86, so you’d need to run your Windows VMs (if you need) on a seperate box.
Personally I recommend used IvyBridge-EP or Haswell Xeon E5 system, make sure it takes ECC DDR3 Reg ram and you can pick up lots of very cheap DDR3 ECC memory to go along with it.
Performance is pretty good, on par with mid level Ryzen[1], and it’s recent enough to have all the hardware extensions anyone cares about.
[1] http://cpu.userbenchmark.com/Compare/AMD-FX-8350-vs-Intel-Pe...
[2] http://cpu.userbenchmark.com/Compare/Intel-Xeon-E5-1650-v2-v...
EDIT: Post before wrongly stated that you need pre-Skylake chip. Skylake/Kabylake µarch is also an option now, however some restrictions apply. I don’t think it’s very good value though, at least until Coffeelake is compatible.
Err, the ME has been present on every Intel system since 2006 or so.
The only thing that changed with Skylake is that the ME runs on an x86 core, on previous processors the ME ran on some RISC microcontroller.
The Pi also has a binary blob requirement and a Trustzone implementation (which is however open to tinkering).
Are there tutorials do do this?: Some Intel processors and a Raspberry Pi: much better performance but you have to ME_Clean the firmware, hence the Pi.
Second, all system since about....2007 (?) have a Intel ME ROM burned inside the chipset, so there's no telling what is still running there, and what exactly is capable of.
Problem is it's dead.
Going out on a limb here, but we can solve this with another layer of abstraction in the long term. We need to develop a fully portable open source virtual machine model (think p-code machine) that is portable and make that the canonical hardware abstraction. That makes all vendors irrelevant if they can't comply with it and opens the market to new hardware vendors with different sales models to provide an optimised hardware implementation of that abstraction. The incumbents (ARM, Intel, AMD) can't sell a security model if the abstraction denies them that ability. Sure they can sell you out, but new competition which is privacy focused should end that.
and if it's so good, why is sparc dead?
As far as I know, Fujitsu still sells it with high-end servers (attempting to take on IBM POWER), and it's still floating around in embedded designs, but it's a niche choice, with the associated downsides.
https://minifree.org/product/libreboot-t400/
However, I assume any chip released after they added the backdoors also has the backdoors. So, you'd be looking for pre-2007, Pentium-class chips in SMP configuration. Maybe Pentium 4 Prescot-2M or Cedar Mill. Wikipedia shows the latter was on same node as Core Duo with 3-3.6GHz plus 2MB cache.
Far as non-Intel, both PPC and SPARC used Open Firmware. Plenty of them on eBay. Gaisler also made GPL versions of Leon3 you could build yourself or buy as a development board for who knows what price.
https://en.wikipedia.org/wiki/Open_Firmware
In high-assurance security, I remember BootSafe tech letting someone write firmware in Java to benefit from all its testing and verification tech that was then translated into Open Firmware's Forth in a way that preserved the properties. That tech went proprietary but still exists. Something similar could be done in FOSS with a Rust or SPARK to Forth converter leveraging hard work already done by compiler/verification teams of source languages.
So far only option is POWER-based systems and they're costly.