Ministry of Freedom – GNU+Linux laptops with Libreboot preinstalled
minifree.org
minifree.org
I strongly recommend people buying products from people who are willing to make sacrifices to offer a product that respects your freedom.
If we do not support people like her, we assume the future risk of having zero costumer really owned devices.
Whenever you plan to buy a device and care about not being spied and having control over your owned device, please consider supporting vendors listed here: https://ryf.fsf.org/
So, as a sibling comment points out, buying from her helps ensure Libreboot's continued existence.
Additionally, in the past (I'm not sure what the financial situation is today), buying from her has also also gone to actually hiring developers to work on Libreboot and port it to more hardware.
> Why can't people just buy the used laptop made by the big manufacturer and install it themselves?
They can. The founder actually encourages this! At conferences she's run workshops to help people install it themselves.
The company is doing extremely well these days. I'm very grateful for everyone's support!
PS:
New Libreboot release soon.
The current Libreboot 20210522 testing release (from May 2021) is more or less complete, and the most major issue (the reset bug) is now fixed in libreboot Git.
I'm polishing the current Git and aiming for a new stable release.
I think the RockPro64 [1] as well as the rockpi4 can be run without any binary blobs. Why I don't see any vendor considering ryf-certifiying devices based on them?
[1] https://stikonas.eu/wordpress/2019/09/15/blobless-boot-with-...
In fact, I'm interested in their product commercially for Minifree, and also interested in terms of Libreboot. You can replace the default uboot firmware with coreboot, which offers many more features and there's where my company could really offer some nice custom services.
It has been on TODO for Libreboot since May 2021: https://libreboot.org/tasks/#investigate-u-boot
It is mentioned here, in the context of u-boot specifically, but I'm aware that coreboot also supports it.
Also in your list of tasks you list ROCKPro64. Although I really like pine64 steps, I think the best rk3399 device for such a task is the Rock Pi 4 Model A Plus, it's got a faster processor, no wifi and the usb-c port is used for power only: no need to care about blobs for eDP! So, if you are thinking about a board to support, I'd suggest you to think about the Rock Pi 4 Model A Plus.
> The current Libreboot 20210522 testing release (from May 2021) is more or less complete, and the most major issue (the reset bug) is now fixed in libreboot Git.
That's really exciting news! Is there any documentation on how to upgrade libreboot?
Minifree runs me_cleaner which modifies the Intel ME up to the point where it is only active during the boot process, but otherwise disabled during normal operation. Only basic hardware initialization is still performed, but otherwise the Intel ME becomes benign from a security perspective, providing only basic power management. Coreboot is handling the vast majority of the hardware initialization and is 100% Free Software on this laptop.
Proprietary features such as AMT are no longer present or accessible after me_cleaner is used. The me_cleaner program removes all networking from the Intel ME, thus removing any security risks associated with Intel ME."
The store's branding overall and presentation leans hard on being 100% totally free, and once you deviate from that "absolutely totally free of proprietary" status your market options open up dramatically.
This is still a valuable service to some people. I didn't mean to come off so negative, but I also feel people who read the page wouldn't realize they have other market options that are "just as free" as the X230. The benefit of buying from this storefront is supporting Libreboot development and Leah Rowe.
Sandybridge and Ivybridge platforms (e.g. X220/X230) in coreboot are all free software for the x86 part, and that's the majority of it. It's only the ME that isn't. With me_cleaner used, it's very close to Libreboot.
X230 used to be worse in coreboot; for instance, it previously had non-free raminit. Nowadays, it's all GPL code.
The Intel ME still performs minor power management functions and minimal init functions via the BUP (BringUp) module.
For all intents and purposes, osboot-preinstalled X230 is 99% as free as a Libreboot system, and I would argue that it is equally secure.
However, the Libreboot X200 is also sold on the website, and Libreboot is fully endorsed by the Free Software Foundation.
There is also the GbE NVM (non-volatile memory) region, which configures the onboard ethernet chipset.
These configure the hardware, and the format is fully documented by datasheets.
In Libreboot there is a tool that I wrote called ich9gen, which can entirely generate ich9 ifd+gbe from scratch. This does not exist yet for sandy/ivy i think, but yes there is that --dump option in ifdtool.
By the way:
bincfg is a nice tool in coreboot, and you can write a spec file for that, based on intel datasheet, to generate gbe/ifd images. I actually have this on my todo list, as I've been studying it. The datasheets are very confusing especially for the Gbe NVM region, making it look like it's not even documented, but it is, poorly.
That's very good news. I thank you for all the work you've done on this.
A computer in malicious hands is a weapon as much as movable types and the photo-copier are/were.
It’s as if you put a untrustworthy guy on a really far away island and occasionally go to him and ask him what the temperature is. He has no way to observe what is happening on the mainland, and even if he did he has no way to talk to anyone about it.
Either way, it's not just about backdoors. A blob is like a car that you cannot perform maintenance on. You want to be able to fix bugs, and also inspect it to check if there aren't any. Maybe customize it.
And are modern NVMe drives isolated? Is your system secure if you have a malicious PCIe device attached? (Even if disk controllers are isolated, are graphics cards? Couldn’t my NVMe drive just claim to be a GPU and DMA all it likes?)
Such a program could be injected into the firmware of the machine, so it will never be read from disk, and it is unlikely need updating. One could also produce a second, clean room, program which does the same thing. This could serve as a back up in case a buffer overflow or similar exploit is found and leveraged in the first validation program.
Additionally, without the ability to self-update its signature database, version updates would render this hack ineffective.
The drive could do things like serve up a malicious version of a system DLL on boot (within the first 20 seconds of being powered on). Then deliver unmodified copies of the file on subsequent read requests. An attack like that would be difficult to detect even if you plugged the drive into another computer.
And as for self updating, the payload could make internet requests, and fetch updated versions of itself online. The controller could then look out for any write which contains a well known sequence of (seemingly random) bytes. And then flash itself with subsequent bytes written to disk. The system component just needs to write the update to a temporary file, flush to disk, then immediately deletes it again afterwards.
I agree with some other sibling posters that the best protection against this is probably full disk encryption. Is that enabled by default yet on windows or macos?
Only if it's sitting behind an IOMMU. This is rarely the case; although it is starting to improve.
See Spritesmods.com [1] for a PoC from 2013 (!!). Guy managed to run Linux on the firmware.
Actually the ryf certification allows this kind of firmware if they are written in ROM; in such cases, they are considered part of the hardware. I understand the complaints about this stance but I know no other similar certification and I think that having non-replaceable firmware forces the vendors to include the minimum of logic inside it and be more careful, so I'm not entirely against it.
Ideally the source code of the firmware should be available. I try to vote with my wallet for that and encourage people to do the same.
I never really understood this logic... it's still closed-source software, it just happens to be unmodifable?
and the CPU is also closed-source software, just "compiled" into gates (synthesised)
There are companies who continue to strive to build open-source hardware: such as the Talos II workstation, the System76 laptops, and Pinephone.
Of these: the Talos II stuff with POWER9 CPUs seems the "most open source" out of all solutions. Its a bit of a subjective measure for sure. However, Talos II is rather expensive.
I think these older Thinkpad Txxx laptops with libreboot definitely work as a more entry-level introduction to fully free software from the boot-process up. Its clearly a cheaper methodology than Talos II (or System76). So that's probably a good thing that they serve different market niches.
The mere possibility that this is true should be enough for us to seek alternatives, but is there any evidence that it is actually the case? My impression was that the Intel Management Engine was a stupid idea but not intended to undermine security.
https://www.youtube.com/watch?v=bKH5nGLgi08
At 47:10, they mention that they haven't found anything evil. Ofc, this isn't hard proof, but if I trust anyone's answer, then it's theirs. (Btw, watch the whole talk, it's nothing short of incredible.)
If people want to source and flash on their own, it's definitely doable, but IME (as primarily a software person) the difficulty ranges from mild headache to a major one, based on which ThinkPad model and phase of moon. :) https://www.neilvandyke.org/coreboot/
Probably? Do you have a source for that claim? Show me evidence that the NSA pressured for silicon level back doors.
Why would the government backdoor or cripple the security of their own machines?
Right now, if you want a ryf-certified device, you have to choose a very old device (x86) or pay a lot of money for a very powerful one (POWER9). If enough people join the cause, we may, in the future, get affordable freedom respecting devices.
Processor speed improvements have indeed not kept pace in desktop / high TDP offerings.
A lot has however happened in the lower power chips used in laptops/mobiles in the last 10 years.
Apple silicon or most ARM type SoC chips of today are so much much better than anything from late 2010s in performance at that power draw.
This has also coincided with decreasing desktop demand as more people use phones or laptops as their primary or only device.
I don't have enough know-how to state with certainty that it is the just the market movement with more R&D money in lower power processors or if there are hard tech limits but certainly is a factor
My $600 laptop's cpu performance is about double that of the x200. I'm not sure about transistor number, but the performance increase is huge. I upgraded from a Thinkpad T410 this year, using a T60 until 2019. I can't go back.
Obviously, that doesn't make any sense to a consumer - but that's the logic that the manufactures might be following.
Look at the last paragraph. Intel usually document everything, but that thing they refuse...
> "Intel does not and will not design backdoors for access into its products."
> "Intel does not put back doors in its products nor do our products give Intel control or access to computing systems without the explicit permission of the end user."
It would be much easier to say, "there are no backdoors", but they don't.
We really need more options for free and open hardware.
Not DMA or equivalent bus access?
> Do you know have rights? Most computers nowadays will never spy on you and restrict your activities, but not ours! You have 100% control over your Libreboot system, free from surveillance.
It should be:
- never spy
+ spy
right?I'd be really tempted to try to change the keyboard firmware to behave more like my Pok3r keyboard (particularly replacing capslock with a function key and making fn+IJKL act as arrow keys).
That sounds like heaven!
Biggest weird thing I had to do was tune the speakers with PulseEffects. Think only the fingerprint reader isn't supported.
The trackpad isn't as good, goes without saying as Apple have a faustian deal on their trackpad tech, but apparently some folks have replaced the T480's trackpad with the glass one from the the X1 [1] with great results - something I'm thinking of once my T480s goes out of warranty.
[1] https://old.reddit.com/r/thinkpad/comments/fo6hrc/i_replaced...
Only downside is the built-in spekers do not work in Linux, so I have to use headphones on zoom
Pick any major brand and they probably have something great.
The only things you really don't get in alternatives is a) the Mac OS and software software & b) better resale value because Apple sells lifestyle products.
weight, battery life, retina display (or 4.5K/5K display), great trackpad, snappy
There are more than one better laptop across all of those metrics as a whole.
One thing Apple does do significantly differently is moving along tech (for better or worse) because the other OEMs can be timid in their experimentation until a generation after a big switch in Apple hardware.
I bought an ASUS Zenbook last year and I can thank Apple for setting trends for hiDPI, DCI-P3 displays, Thunderbolt, and big trackpads. But on the flipside, I can lament Apple for bad trends and it not having a 1/8" headphone jack and soldered RAM. And because it wasn't Apple I have a touchscreen+stylus and saved a lot of money.
The newest trend of using ARM (and RISC) processors in laptops (could care less about what Apple brands it as) is a good one though. There have been attempts at good ARM chips, like Samsung's flagship ultrabook, but too many applications didn't run on it to make it feasible. I had an old Chromebook I slapped Linux on and it was a mess because certain applications, namely anything leveraging Electron or just having a .deb file, wouldn't run. For better or worse, people have to cater to Apple making such switches. Now you have started to see projects actually release binaries outside of x86.