The Framework Laptop Chromebook Edition
frame.work
frame.work
My hope was that this is just running on the standard Framework laptop hardware, but it looks like it required a bit of a mainboard redesign, as well as a different input cover and keyboard. Extra hardware like that just makes their offering more difficult for a customer to navigate and understand, not to mention the added support and manufacturing burden on the company's side.
Also, completely disagree with your point about locking people into Google ecosystem - this is an OS that just runs a web browser. You need a Google account to log in, sure (actually, there's a guest mode too), but otherwise it's just a browser.
But! It's your fault! They shouldn't be able to sudo!
But that's the point. If they couldn't sudo, they could do something else as disastrous. It is difficult to secure a Linux system if the user is allowed to log in. If I needed to give someone access, I just would give him a freshly installed Linux virtual system, and if he deleted something important, it's his problem, not mine.
If you spend some time configuring the OS, Linux is actually much easier and safe to use than Windows for a series of often overlooked reasons:
1- Application installation and removal is centralized: you fire up the distribution package manager and can install almost all software, including lots of 3rd party, using the same interface; no need to wander around the net with the risk of landing on a malicious page disguised as a download site.
2- Drivers are built at kernel level and nearly all of them are already included: if you buy a new device, chances are that besides not having to insert any drivers CD, they are already included in the distribution.
3- Hardware support doesn't come with added bloatware: say, you connect the new printer and can safely ignore the accompanying CD or their manufacturer's site downloads, which usually will attempt to make you download crippled version of commercial products and other junk along the drivers. Under Linux you use the supplied applications with all hardware of that class.
etc.
Some 20 years ago I was working at a company operating in the sports betting field; we had abut 50 points of sale deployed all over the country and my assignment was to find a way to allow each remote point of sale to work in the safest possible way, no distractions and including remote support on demand. All of this of course in the cheapest possible way. The best thing about working in a small company is that sometimes you can earn the freedom of choosing the rope to hang yourself with: I'm not interested in the betting world, but that problem was intriguing, and I had carte blanche. The solution I came up with after some fiddling was a RedHat distro plus WindowMaker "desktop" with a restricted launcher whose dockapps allowed the operator to check/write emails, file for a remote support connection, open StarOffice and a couple other things I don't recall. The system was essentially in kiosk mode, with the browser set so that it would open fullscreen to operate only on the company webpage. I had to write the scripts to file for remote support since all the points of sale had dynamic IPs which could change by the time we could reach them, therefore the connection had to be the other way around. I solved this by using a remote "pinger" written in Ruby that would periodically send some data about the remote station, so we immediately had the who+where data pair, and a receiving Ruby application on our side would populate a GTK list (I used Glade and Anjuta iirc) with the stations that asked for intervention. As soon as a local operator clicked on one element, a reverse ssh tunnel was opened and we had the remote shell ready. To my memory that contraption never failed; with very slow connections (~2002, so 1 Mbit down/ 128Kbit up when we were lucky) luxuries such as VNC were out of question. 50 points of sales could be easily managed by a single operator.
Of course I'm not suggesting to turn every Linux PC in a tight closed terminal that does 3 things only. My point is that you can effectively turn a Linux desktop into something that non tech people can work without troubles, but that doesn't come out of the box, as it doesn't with Windows: you can have everything from a dumbed down terminal that couldn't be crashed by a colony of cats walking on the keyboard for a week, to something so advanced and full of knobs that you can literally do everything, including shooting yourself in the foot. Some work is needed though.
I would let anyone, even a total stranger, use my Chromebook in guest mode without a second thought (as long as I am reasonably sure they won’t steal it, break it, or disassemble it).
Exactly. I would never let my (non-tech savvy) grandparents near a Linux machine without supervision, but I wouldn't hesitate to let them near a Chromebook in guest mode.
Linux is quite secure in the hands of an experienced user. ChromeOS is secure in the hands of anyone who's not state sponsored attacker-adjacent.
Looking at my Linux machine, I notice that the default permission for home directories is 755. If I don’t think to tweak that, then I’m potentially exposing a lot of sensitive data to other users (and potentially the programs they run).
I’m a proficient Linux user but not an expert, and I’m racking my brains to think of what else might be exposed to other users on my machine.
755 permissions on the home directory lets others see what you have, which isn't great.
The good and bad news is, permissions on the files matter too.
SSH (private) keys for example categorically won't work outside of 600 permissions, meaning nobody else can read your private key - without escalating privileges
Now, if you go defining auth secrets in your shell profile (which is world-readable by default), probably something to reconsider.
Restricting umask is a good protection for this, for what it's worth. You can make it so that newly created files/directories are not accessible to the world
Whoa, what? I'm running Debian, and it's 700 for me. What distro are you running? This seems like a bad choice by the distro maintainers...
Including root?
The permission model is such that the most damage they should be able to do, is to an account you've provided to them
Or are we assuming they get sudo and unlimited time, like the typewriter thing?
I'd be more worried handing it over to a experienced person who's familiar with rd.break, assuming the filesystem isn't encrypted
I specifically give family members Linux so I don't have to go clean hundreds of toolbars and the like, as I've had to with their Windows boxen
Security does not only mean security of your own data stored on the device. A device made by Google will never be secure.
[1] https://www.politico.com/news/2022/07/18/google-data-states-...
Sure, if I carried around a privacy-centric Linux box and told my guest to use Tor browser, I could see how that could change the privacy picture. But that isn’t exactly an apples-to-apples comparison.
If you believe that having the guest user run their search on a typical Linux, Windows, or macOS machine would be better for their privacy, I would be interested to hear how.
Also, if they’re running the search in guest mode and they don’t log into a Google account, nobody can know who’s making the search. It’s not like they’re looking through the webcam or something.
> If you believe that having the guest user run their search on a typical Linux, Windows, or macOS machine would be better for their privacy, I would be interested to hear how.
The main reason is that Google controls the entire environment on a ChromeOS device (kernel, userland, browser), and ChromeOS is closed source so it's not possible for me to easily know what is going on. In addition, Google makes money by collecting data about users, so there is an incentive to collect as much information as they can get away with (and they've shown repeatedly in the past that they do just that). Maybe there's a daemon running in the background shipping URL history off to some Google endpoint in the name of "telemetry", or maybe not. Or maybe it's something more innocuous-sounding like hashed or anonymized data (which could be reconstructed given Google's immense amount of data). But I don't know, and I don't think it's reasonable for anyone to implicitly trust ChromeOS at all given the business model of the company that makes it.
On most Linux distributions, nearly everything is open source and I'm free to audit what's going on. On macOS devices, the software is closed source, but the company's business model does not involve building a dossier on each and every person on the planet, so I trust them more (not fully, but more). In the past I would have said the same about Windows, but lately I'm not so sure and I tend to put them in the same bucket as Google.
edit: Also see my reply to you in a different sub-thread where I explain this in terms of threat models. If you were building a secure OS to protect high-risk individuals like journalists reporting on intelligence leaks, you would be crazy to recommend that the journalists to use an OS built for them by the NSA, MI5, or FSB. Would you feel any better about the recommendation if the government agency said "Don't worry, as long as you use guest mode and don't sign in, we won't collect any data about you"?
I don't doubt the features are there, I'm genuinely curious what they are.
- All user data is encrypted at the login level. A guest user cannot access any other users’ data. Whereas in Ubuntu, for example, home directories have 755 permissions.
- The Linux userspace in ChromeOS is actually running on KVM, so ChromeOS itself is insulated from user-installed malware.
- Verified boot is huge. It is theoretically impossible for a modification to system-level software to survive a reboot. An attacker would have to modify the hardware too. And even if someone stole your Chromebook and modified the hardware to run malware, your data is still encrypted.
If you are interested, a more thorough explanation can be found here: https://chromium.googlesource.com/chromiumos/docs/+/HEAD/sec...
Or, put another way: your threat model is a nefarious hacker or three-letter-agency who might secretly modify your hardware/software to get your data. Mine is surveillance capitalism. ChromeOS is secure under your threat model, but is _built by the attacker_ under mine.
Both of these threat models are important to consider, but one is much more relevant to a larger portion of the population than the other.
(Having said that, I still haven't been able to completely wean myself off Google services, so Google already has plenty of data on me, and gathers more every day.)
> You need a Google account to log in
This is absolutely blatany lock in, let's not sugarcoat or pretend it is not at least.
But more to the point, lock in is when you can't move your data to another system. You need a Google account to log in (these days that's not much different from Windows or Mac basically requiring MS/Mac accounts), but you don't need to use the account for anything else you do on the Chromebook; it's just a browser. If you want to, you can export any data that browser holds (passwords, bookmarks etc) and import into any other browser. That's not lock-in. Lock-in is forcing you to continue to use a particular vendor's product because getting out of it is too difficult (usually proprietary data formats ala MS Office, or not allowing cloud exports)
Could you not access your Google account on a Linux, macOS or Windows computer?
Could you also simply not use that Google account while using those other systems?
The problem with Chromebooks is that they are designed to try to get people to "log in" to Google and to use "the [Google] cloud" for storage. Chromebooks in Guest Mode have an array of Google-authored daemons running the the background from read-only media. There is no way to disable them. You cannot even change the options passed to Chrome, e.g., to disable "Origin Trials". This setup is great if you love everything Google, but not great if you just like computers, you bought the computer for the hardware and drivers, and prefer to choose your own software. With these Google programs always running in the background, it means you do not have ultimate control over the computer, Google does. Another annoying thing is that ChromeOS, as well as Chrome, is a WIP. It is constantly changing. For example, bluetooth may be working fine and then suddenly there is an "automatic update" that breaks it. Then you wait for Google to fix it. I am not too fond of that approach to updates. For the systems I create I choose if and when to update them. I prefer stability as opposed to bleeding edge. Chromebooks OTOH assume the computer user is willingly along for the ride as the Chromebook development teams figures out what they are doing.
1. Google likes to boast about Chromebook security. Indeed the Google programs run from write-protected media, and the user is denied access to parts of the storage media, but this type of setup is nothing one could not achieve, before or after the arrival of the "Chromebook", using an open source project such as NetBSD. IMO, the benefit of the Chromebook project is the hardware support, not the deliberately limited storage, lack of user access to parts of the storage media, mandatory installation and running of Chrome and other Google programs. Additionally, one has to consider the "security" implications of an OS that steers people to use Chrome and cloud storage and to remain online. Those Google programs are constantly probing for internet access. ChromeOS is an OS that encourages risk-taking, i.e., giving more data to Google, including storing user data "in the cloud".
I always make diskless systems to be offline by default. I avoid running X11 unless needed, staying in VGA textmode by default. There is no phoning home for "updates" to an advertising company.
Chromebooks are not designed to be offline by default. ChromeOS forces users to launch a GUI and run Chrome. Google is always trying to collect more data about computer users.
https://nakedsecurity.sophos.com/2017/11/22/chromebook-explo...
I wouldn't use Chrome OS as it is right now. But a degoogled version of it, maybe with some better local only support, or at least support to use a different cloud than Google's cloud, say some NAS in my home, and it would be a really nice device.
It is possible to create customised UNIX-like OS with custom kernels, read-only filesystems (mounted images), writable directories mounted as tmpfs, and encrypted disks, booting from removable USB. Some call this "diskless". There are some drawbacks from using USB media such as lack of a good randomness source on boot but there are many advantages. Kernels and filesystems are just single files on the USB media and can be easily switched/updated. The system stays "clean". It is "like new" on every reboot. I was doing this with a netbook long before the so-called "Chromebook" came along.
The problem with Chromebooks is that they are designed to try to get people to "log in" to Google, to use Google-controlled websites, to use online software controlled by Google and to use online storage managed by Google rather than local storage managed by the computer user. The later may be more convenient but it also poses higher risk for computer users while at the same conferring commercial value to Google. The company wants computer users to use its websites and software in lieu of offline storage and offline software.
Chromebooks in Guest Mode have an array of Google-authored daemons running the the background from read-only media. There is no way to control or disable them. You cannot even change the options passed to Chrome, e.g., to disable "Origin Trials". With these Google programs always running in the background, it means you do not have ultimate control over the computer, Google does.
Another annoying thing is that ChromeOS, as well as Chrome, is a work in progress. It is constantly changing and the computer user is treated as a beta tester. For example, something like Bluetooth may be working fine and then suddenly there is an "automatic update" that breaks it. Then the computer user must wait for Google to fix it. There is no way to go back to the previous working version while waiting for the fix.
One has to consider the "security" implications of an OS that steers people to use Chrome, online storage and genrally to remain online as much as possible. Google programs are constantly running on Chromebooks and probing for internet access. As such, ChromeOS is an OS that encourages risk-taking, i.e., giving more data to Google, including storing more user data online. Chromebooks are not designed to be offline by default. ChromeOS forces users to run Chrome. Google is always trying to collect more data about computer users.
I always make diskless systems to be offline by default. I use offline storage. There is no phoning home for "updates" to an advertising company. I decide when and if I want to "update" the kernel or userland.
http://nakedsecurity.sophos.com/2017/11/22/chromebook-exploi...
Needless to say Chrome defaults favour Google and Google's advertiser customers. Making it impossible^1 for Chromebook users in Guest Mode to save and import privacy and security settings is a dark pattern.
1. Google employees will proclaim this is incorrect. All the computer user has to do is "log in" to Google in order to save her settings. Once logged in, Google can collect more data about the computer user. However non-employees of the corporation may not wish to "log in". Google employees assume that all computer users should trust Google, like they themselves do. Given that Google is collecting as much data about them as the law will allow, and then some, this is a curious assumption indeed.
I would love a streamlined Linux desktop that is as technically sound as what ChromeOS does - isolations, integral updates etc. The fact that it comes with a forced leaky pipe to Google mothership to feed their ad monster is a non-starter. We at HN should stop calling it secure*(except you know Google tracking you).
PS. I feel the same way about Windows. So, may be I’m just a grey beard yelling at the sky.
I'll admit that I don't know for a fact that it does require this, but I just kinda assumed it might. IIRC you can run Android apps on ChromeOS, and if you buy apps from the Play store, then you're stuck with ChromeOS if you want to continue to run them. Otherwise you lose that money you paid.
> You need a Google account to log in
These two sentences are contradictory, aren't they? You do not need a google account to run a web browser.
If it really was an OS that "just" ran a web browser, you would be able to run said browser without being forced to use a google account that spies on your web browsing behavior.
No Chromebook has the desktop class requirements to keep it happy running those Gradle builds.
Sorry, I have a hard time even comprehending your point.
You can run Android apps, right? You can side-load Android APKs, right? Even install F-Droid? You can run Linux apps on many Chromebooks - this one, too?
Most non ARM devices can be fully unlocked to run bare metal linux. Just https://mrchromebox.tech/
> I don't want to be too negative
You are. Though there are certain privacy issues that may be warranted, you seems to make remarks without base.
> Google adware/tracking-ware, locking people into the Google ecosystem
One will always get locked to some ecosystem. Some friends use Facebook as photo storage as REAL-WORLD-USERS do not want to run NAS, RAID, off-site backup. Others having $$$ have iCloud. People that know difference between SAS and SATA run rack-servers.
A simple browser based OS can help run 4GB devices. May be you are comfortable in 4K screen, with dwm tiling wm but others want $200 ChromeOS for just shopping, netflix etc. Oh yes, many people do not have time to download and watch ISO - and get locked into some ecosystem.
> Framework could be spending their time doing much better thin
Lets be honest, Framework knows what is IMPORTANT for themselves than you. This is a good thing. Every bit helps.
The fact that you can unlock it and run regular Linux isn't really the point. Selling a laptop that is pre-loaded with ChromeOS means that it's intended that buyers actually run ChromeOS on it, and I expect most that buy it, will (otherwise they would just get the regular or DIY version). Framework simply endorsing ChromeOS in this fashion is enough of a problem.
> Though there are certain privacy issues that may be warranted, you seems to make remarks without base.
I don't think that's the case, and nothing you've written here seems to contradict what I've said.
> One will always get locked to some ecosystem. Some friends use Facebook as photo storage as REAL-WORLD-USERS do not want to run NAS, RAID, off-site backup. Others having $$$ have iCloud.
That doesn't have to be the state of the world, though. I think all of that is not great, and the solution isn't just to throw up our hands and endorse closed-ecosystem environments.
There are other, less-extreme options in between "I live inside Facebook" and "I run a home server and NAS and host my own social network at home". Unfortunately many of them still aren't quite user-friendly -- though some are -- and the Facebooks of the world wield far too much market power.
> Lets be honest, Framework knows what is IMPORTANT for themselves than you.
You seem to be unreasonably angry over what I said. Maybe cool off a bit? I even acknowledged that there might be good reasons for Framework's business to offer ChromeOS as a product, but you seem to have intentionally ignored that bit.
There are some other smaller differences. To keep the cost down, the top cover is aluminum-formed instead of CNCed, for compatibility reasons we weren't able to bring our fingerprint module in, and we were able to improve both audio quality and speaker loudness with an improved audio CODEC and louder transducers.
Would any collaboration with them regarding CoreBoot be helpful/desirable/possible/planned/etc. ?
This is what I was hoping when I got the announcement via email. The question is if this will be locked down to chromeos or if it's possible to install your own keys to load a linux distro while still retaining verified boot capabilities.
Forging is in no way inferior to CNC, on the contrary, a forget aluminium part should have more rigidity per unit of thickness, depending on the alloy.
I guess, you got to volumes big enough to open the mould for forging?
If you need an audio engineer, I can refer you one fellow. He worked at Apple, Harman, Asus, BBK, and is now looking to relocated from the East Bloc.
The formed top covers are thick aluminium foils that are folded by machines.
They did show signs of lack of rigidity in the usage of the laptops (it was shipped with the first Framework laptops, and later replaced by CNC for this very reason).
In the Markeplace I can see the new speakers but not the new audio board (or is the codec actually on the motherboard?).
They pointed me to this /gb/en/ url, which has the same chromebook slug but seems to just describe the regular 12th gen laptop: https://frame.work/gb/en/laptop-chromebook-12-gen-intel
So to be clear, no fingerprint reader for the Chromebook? Any chance of adding that in the future?
Edit: the article says “receives automatic updates for up to eight years” but an upper bound isn’t so helpful here.
https://support.google.com/chrome/a/answer/6220366?visit_id=...
If you purchase a brand new chromebook whose model has been sold for 3 years already you won't get 8 years of support.
I couldn't find any marketing material pointing out the switches on the originals, so I assumed this was a change for the Chromebooks. But you're right, I managed to find an image of a Framework laptop where the switches are visible.
I'd also love to learn more about the motivation to create this laptop and the target audiences!
Keeping it as a Chromebook with ChromeOS, there are specific firmwares required for the Touchpad and Webcam that required us to create variants. The Fingerprint Module we have is also not compatible with ChromeOS.
- What kind of commitments did each party make to each other?
- Did Google request anything of Framework? What requests did Framework agree to? Which did they deny?
- What differentiates this product from the normal offering?
> we’ve partnered with ChromeOS because of their commitment to long-lasting speed and transparency. The Framework Laptop Chromebook Edition is built with the Titan C security chip and receives automatic updates for up to eight years, all to keep your Chromebook fast and secure.
Besides, now is a terrible time to start offering AMD laptops. You want them to drop a 6000-series laptop when the next-gen mobile Ryzen chips were announced less than a month ago? Have some patience!
Technically the only mobile Ryzen chips announced so far are based on Zen 2 which is about to become two generations old. Expect "next-gen" mobile chip announcements in January.
(The recent Zen 4 announcements have been for desktop parts.)
Here's the segmentation:
* Mendocino (Ryzen 7020 Series) - Everyday Computing
* Barcelo-R (Ryzen 7030 Series) - Mainstream Thin & Light
* Rembrandt-R (Ryzen 7035 Series) - Premium Thin & Light
* Phoenix Point (Ryzen 7040 Series) - Elite Ultrathin
* Dragon Range (Ryzen 7045 Series) - Extreme Gaming & Creator
But the product "launch" will, as you mention, likely take place at CES next year.
That being said, starting w/ Rembrandt, AMD now has full 40Gbps USB4 controllers built on-chip. I'm really looking forward to Ryzen 7040 because Phoenix looks great (Zen4 + RDNA3 on TSMC N4 - yes please) and hopefully USB4 support has matured enough on the AMD side that Framework is able to release something.
My understanding is that the I/O limitation is in the re-timers - currently the Framework uses 4X JHL8040R's (labeled as Burnside Bridge) directly connected to the iTBT: https://github.com/FrameworkComputer/Mainboard/blob/main/Ele... Apple used these for their first M1 MBAs as well: https://github.com/ThomasKaiser/Knowledge/blob/master/articl...
But both Apple and AMD are now using Kandou retimers:
* https://www.gizchina.com/2022/07/25/apple-completely-got-rid...
* https://kandou.com/matterhorn.html
* https://kandou.com/assets/downloads/product-briefs/KB8001-Pr...
When you don't care about single-core performance and compatibility, there really isn't much reason to use x86 at all. For me personally, my priority is by far battery-life (and LTE support is a nice bonus).
I'm refraining from using Framework until they get an ARM device out to replace my current ARM chromebook (Acer Chromebook Spin 513, my NixOS configuration: https://github.com/L-as/NixOS-lazor)
There really isn't any other performant ARM chip that has more ports, enough to work in a framework 4 port type situation.
If we want to go beyond DP alt mode into USB 4 you could forget it.
Is there a sense that there is an untapped 'premium' chromebook audience or will this make sense even without that. Perhaps you're looking for large/discounted partnerships with educational organizations?
I'll need a new laptop soon, and would really love to see either and ideally both of those.
But for the company it's probably a good move. Get help from Google on battery optimisations, open up a new market and hopefully get a sizeable order from Google directly, all without a crazy amount of re-engineering...
you could gamble that they are and get the 11th gen intel kit, then upgrade once (if) an amd kit is released. or wait and see.
[1] https://www.johnlewis.com/google-pixelbook-go-ga00526-uk-lap...
There was a lot of love for the original Pixelbook, so I'm sure it will be an exciting prospect for many.
While cheap Chromebooks abound, the market for Chromebooks has matured significantly and a lot of vendors offer high quality 'premium' solutions that really meet people's needs, while typically costing less than say Apple's offerings. Framework is jumping on that bandwagon.
They're a niche market: C-level executives at companies that use Chromebooks, developers at those companies, Linux fans who will mostly use the Chromebook to run Linux apps. They make more economic sense as an adaptation of a laptop that is already being sold for other markets rather than as a dedicated product.
The Pixelbook line never did enough volume for Google to make money on it. It was a proof of concept, a way of showing that a Chromebook didn't have to just mean a low end and cheaply built Acer or the like, but could be something that higher end users would happily use and not be ashamed to be seen with when they do a presentation. Now that other companies are making premium Chromebooks, there is no longer a need for Google to produce them.
After they hit a supply line issue earlier this year, I decided to try getting a Framework instead.
Been using my Framework laptop for a month or so now consistently for heavy programming work, and it is the best machine I've ever had. Thank you! It also was the catalyst to get me into using Linux (Ubuntu) which has been a huge blessing beyond what I expected.
I posted a photo of myself at a coffee shop to a Discord group, and someone saw the corner of the laptop. They asked "Is that a Macbook I see?" and I explained to them "Nah it's a Framework" and shared the link. Didn't really expect much beyond that, but actually they loved it. Several people looked at it and said "Wow! This sounds amazing! Actually... going to save this for later..."
Ubuntu: Ubuntu 22.04.1 LTS
Linux: 5.17.0-051700-generic
The only problems I've had so far is the "brightness" fn keys don't work, and bluetooth isn't great with certain devices like Airpods.The brightness keys isn't a big deal, can still set brightness in the OS. It's probably fixable through some manual keymapping.
Bluetooth is more annoying but I somehow doubt it's a hardware issue. I just ended up getting Sony wireless earbuds to complete my transition away from Apple.
That being said, I also tried to dual boot Windows. Windows really does not like the hardware, and the Framework driver install package (https://knowledgebase.frame.work/en_us/framework-laptop-bios...) had limited effect in fixing the issues. Lots of bugs with audio and graphics.
So, for now I would say it is too premature for Windows, but great for Linux!
You can enable the hotkey support by blacklisting the hid-sensor-hub driver: vi /etc/modprobe.d/framework-als-blacklist.conf Add the following: blacklist hid-sensor-hub And then restart
It worked, but it needed `hid_sensor_hub` with underscores! and `sudo update-initramfs -u` before the reboot
A sibling comment shared the fix for the brightness keys, but you can also grab that information from our setup guide for Ubuntu: https://guides.frame.work/Guide/Ubuntu+22.04+LTS+Installatio...
https://community.frame.work/t/audio-issues-windows-11/11726
https://community.frame.work/t/windows-no-audio-output-devic...
https://community.frame.work/t/windows-11-audio-no-longer-wo...
Thanks for the tip
Some people have been getting hard graphics lockups (seems to be an Intel 12th-gen GPU / GNOME issue that may be affecting more than just the Frameworks). I'm running Sway and have yet to have any lockups over a month and a half of usage, though. Here's the community discussion thread: https://community.frame.work/t/hard-freezing-on-fedora-36-wi...
* Getting out of sleep (deep RAM sleep, not hibernate)
* Handling password/fingerprint authentication once out of sleep
* Wifi rescan frequency
* Occasionally, plugging/unplugging external screens
And I've got no idea why. Once woken up and plugged to whatever I need to use, it's a really good laptop.
I've been considering a framework as a replacement actually!
One of the things I really care about is battery life + sleep performance.
The article mentions:
> .* At the same time, the Framework Laptop Chromebook Edition is our most power efficient product yet with optimizations from Google and Intel that allow for long-lasting battery life.
Can you provide some numbers around the battery life improvements? Sounds exciting! (And are these going to be backported to the normal 12th gen boards, or is it a feature of the unique mainboard/not firmware?)
Can you speak to the OS image as well? Is there any non-upstream drivers that are relied on? I notice lots of chromebooks have drivers that aren't in the regular upstream kernel, but just in the chromiumos source. I'm hoping that I could eventually swap OS' if needed w/o getting a new mainboard, and want to see how viable that is.
Thanks for the hard work, and in advance for the questions!
(P.S. like everyone else, AMD would be exciting if you don't know that :p)
[edit] one of my biggest disappointments in my slate is that it never received vm-in-vm support with the newer kernel. Is /dev/kvm available in the linux container? I _think_ that goes hand in hand with the steam supuport, but not sure
We actually did learn some things about the Intel re-timers through this product development that let us come up with ways to improve the behavior on the regular 12th Gen Framework Laptops. We are currently developing a firmware update for that that will improve both active and standby battery life.
Is this specific to Intel's 12th gen or can it also be ported to the 11th gen? I have an 11th gen Framework and am delighted with everything about the laptop except for battery life. If that could be improved, I would have absolutely no complaints whatsoever about the laptop.
2. Does this come with the silly Chromebook keyboard that is missing two keys on the left side? If it does, is it compatible with the normal keyboard part?
3. When will you bring a motherboard with an AMD APU?
What is the battery life when running Chrome OS?
If I wanted to, could I later put a full Linux or Windows in some sort of dual boot?
Is there any roadmap for wider distribution in Europe? Especially eastern part.
1. Could I swap mainboards to upgrade the 11th gen framework to the chromebook version? 2. Is the coreboot chip flashable with custom firmware? / Is the boot process locked?
This might well be the mainboard I've been waiting for. Congratulations on shipping this!
When switched into developer mode, it should be possible to update and customize firmware. There is a pretty active community for Chromebook firmware customization out there.
The ChromeOS doc page "Set Up Linux on your Chromebook" [0] links to a supported models list [1] which does NOT include Framework.
[0] https://support.google.com/chromebook/answer/9145439?hl=en
[1] https://sites.google.com/a/chromium.org/dev/chromium-os/chro...
source: https://community.frame.work/t/introducing-the-framework-lap...
Maybe the support sites will get updated to include Frame.Work
I've grown to rely on Windows Hello / Mac FaceID. It's disappointing not to have a bio metric option.
I noticed the 256GB of storage is different from the DIY options. I'm guessing this is driven by hardware support limitations for ChromeOS. I'm wondering if the same is true with the RAM.
The FAQ also says you can add memory and storage later, but I noticed the FAQ mentions "We recommend using modules from Google’s Chromebook compatibility lists, which can be viewed in our Knowledge Base, and are available for purchase on the Framework Marketplace." I didn't find that compatibility list anywhere in the Knowledge Base, but I did find this post (https://community.frame.work/t/introducing-the-framework-lap...) which seems to suggest you can upgrade to 64GB of RAM and 1TB of NVMe storage, though it's not clear if that's using parts that are on Google's compatibility list or not. Can you provide any clarity on this?
On the storage, we use Western Digital SN730 and SN740 drives, which are also what we put in the pre-built Framework Laptops. These are roughly equivalent to the SN750 and SN770 retail drives, respectively.
On the memory and storage, ChromeOS technically has an allow-list for memory and storage, though in practice we have seen modules not on the list work fine. We'll be adding that list onto the Knowledge Base. We will be making parts that are on the list available in the Framework Marketplace for guaranteed compatibility (the memory we already have, and we'll be introducing SN730/SN740 storage up to 1TB).
It'd be nice to see improvements in the mainboard of the standard laptops as well. I imagine, in theory, much of the firmware and OS improvements could be installed on one of them already.
> On the storage, we use Western Digital SN730 and SN740 drives, which are also what we put in the pre-built Framework Laptops.
Ah, now I see it. The pre-built one has 256GB & 512GB options that the DIY ones don't have. I'm always amused by how specs differ between OEM and non-OEM parts.
> On the memory and storage, ChromeOS technically has an allow-list for memory and storage, though in practice we have seen modules not on the list work fine. We'll be adding that list onto the Knowledge Base. We will be making parts that are on the list available in the Framework Marketplace for guaranteed compatibility (the memory we already have, and we'll be introducing SN730/SN740 storage up to 1TB).
Awesome. Thanks. These were really helpful answers. As feedback, I'd say it would be nice to be able to select different starting memory options in particular, but this is a really great offering.
I understand if you can't make promises here, I'm also on a product team :)
How did you see the niche and do you still see it the same way now it is here?
What do you consider to be the value proposition for potential customers of this product?
What is your assessment of the TAM?
Do you have limits on how many differentiated products you are willing to pursue simultaneously in the market?
1. do you have any plans to provide expansion cards for ltr/5g connectivity?
2. do you have any plans to provide more memory for chromebook edition?
I work in metal fabrication (tradesperson) and run a laser cutter as my full time job, and have an interest in most things metallurgical.
Are you able to talk about the 50% post-consumer recycled aluminium. What were the pros / cons of 50% rather than higher or lower percentages.
Do you honestly believe Google respects people?
What measures have you put in place to mitigate Google's surveillance of its users?
I would imagine that regular Linux won't do as well as ChromeOS in terms of battery life, but perhaps still considerably better than the Windows mainboard+firmware.
The first one I got was $550 for the 8GB RAM model with i5 and "retina" screen, that was a refurb from Woot, almost half off. The second one I got around a year ago when Linux container support landed, 16GB RAM, i7, "retina" screen. That one I got off ebay for $120 landed. I also got my son one that he used until a few days ago. Pretty decent little machine for that price.
My son switched to a $120 Windows ASUS laptop this past weekend because the Chromebook wouldn't run Windows games. I was half expecting him to give up on the new laptop because 4GB isn't much RAM, but he says it works great.
My mother in law was recently asking for laptop advice for a "ward of the court" she oversees that could do with a laptop to do zoom meetings for the court appearances, and to use for school. I went looking for Chromebooks and found: they are all priced the same as a similarly speced Windows laptop. The things I value about ChromeOS ("instant" updates, "nothing really on the device", "security") aren't things the average person (let alone teen) really care about... Kind of hard to recommend a Chromebook for the average person these days, unless I'm missing something.
When I was a child we used to disassemble mechanical/electrical things around the house simply because I asked "How does that work?". On occasion the reassembly didn't quite go to plan and a replacement kettle/toaster/VCR had to be sourced rather swiftly :-)
And somehow, this thing got my attention. I don't have any interest in their traditional PC laptop line, but I've been waffling over buying a Pixelbook for years because dealing with Google Support is worse than entering a contract with a devil.
If it helps you reconcile it, Framework doesn't do bulk or business orders right now, anyway, so the target demographic is only individuals.
Is that a misplaced "can't"? (Something like "there's nothing I can't do that I can do on another computer, somewhere else"?)
I fricken lost my titanium SPORKS from my kitchen, one of which was a "businuss card" gift from JD Blair... and I know that nobody stole my sporks... but for the life of me I have no idea where my sporks are, my THREE pairs of $500 glasses that costo made for me and so many other stupid things...(FFS I literally just bought a pair of $150 BT headset, and left it behind within two days of purchase (i was able to get them back - but, yeah...))
I cant imagine if my laptop had removable parts (I leave shit in Ubers all the time)
Nowadays I have a Lenovo Flex 5i Chromebook with an 11th gen intel, 8Gb RAM and a normal Full HD display. It costs approximately half the Framework laptop. The keyboard is really good and backlit, the speakers are MaxxAudio and that actually means they are really good. The flip hinge, touch screen and pen (in the box) work great.
Out of laziness I do developer things on it. Rather than move to the next room to use my 'proper' computer, I install the linux apps and it works really seamlessly. I get that Android is not quite right, but, if you just want to have your notifications come through, it works great.
USB C is a game changer and I no longer want to be able to take my computers apart. I don't want the fans running more than a gentle breeze and I don't want to be taking the machine apart every year to vacuum out the cruft.
In the early Windows/DOS days you would be spending hours moving dip switches and trying to get the machine to work. It was much like automobiles a century ago where constant fiddling was required.
There is a difference between getting work done and tinkering. With a laptop that just works you are doing work not tinkering.
We all want more RAM, CPU speed and so forth and the upgrade option is fine in principle. But do you buy a car with the 1.6 litre petrol engine with the 'benefit' that you can put a 5 litre V8 in there? Nope. But some people make money off YouTube doing this sort of thing so it seems an acceptable 'use case'.
I am not actually negative about the proliferation of Chromebooks at all expense levels, to me they certainly do not have to be bargain basement - hence Chromebook Pixel. But money talks and half of $999 is an unusual spend on a Chromebook, never mind $999.
Would you pay more to have a dumb phone that only does calls, than a smart phone?
As one who always get second hand Chromebooks, right now is the time to get a like new Acer 713 with i5 or a new ThinkPad C13 with R5 on the cheap. I've got both this week (cost C$825 total), will end up keeping the best for my needs, give the other to a relative.
Displays wider color range, CPUs faster, that's pretty much it on the positives side.
Then why partner with such an OS ? It is not just the HW switches when I cannot use the very Framework chromebook without a google account - where is the privacy in that.
I was very excited for Framework and I appreciate your responses here but this feels too early a backward move for Framework. Is the market/partnership worth the trust hit ?
I hope I am wrong but this seems like going the Don't be evil way.
Nuts and gum, together at last.
With CCD, you are pretty much free to mess around with the "BIOS" of the machine, without fear of being put in a bad situation.
It also provides a serial terminal to the "AP" (application processor), e.g. available to the OS.
In other words, the Cr50 provides a controlled and user-controlled (but not user-owned) sideband channel to debug the system, even on consumer hardware.
Why user-controlled? Because it requires asserting presence to "Open", which with the design of ChromeOS basically requires being the owner of the device. Why not user-owned? For official ChromeOS devices, AFAIK that firmware cannot be replaced by a user with their own builds.
[0]: https://chromium.googlesource.com/chromiumos/platform/ec/+/c...
The Cr50 is as far from user-controlled as you can get. It can MITM your keyboard, reflash your firmware, and obeys only the holder of the private key corresponding to `LOADERKEY_A`:
http://www.loper-os.org/?p=2433
If the Chromebook is Google's take on laptops, then Cr50 is Google's take on the IME.
As I clearly stated, what is user-controlled is the sideband channel to debug the system on consumer hardware. The sideband channel under the current implementation of Cr50 is entirely user-controlled. This is a fact, as the end-user of the machine has control over the sideband channel.
I did not state any judgement about the GSC itself and its firmware.
And please don't start spreading FUD around hypotheticals of updates changing that. Yes it is possible. But a lot else and worse is possible under that scenario, so it serves no purpose but to spread FUD. And is still irrelevant to the content of the previous comment.
I am asking you, please do not ever derail what I say with FUD or out-of-context quotes ever again.
Thank you.
Hopefully someone can take that fear away.
It's the same sort of cognitive dissonance as if a Michelin-starred sushi restaurant just announced they're adding a Subway Footlong sandwich to their menu.
The purpose of a privacy switch is to make sure that Google (or anyone else, including hackers) isn't spying on you through your camera or microphone. This one accomplishes exactly that.
I can trust a Linux system.
A system running Google adware (some even call it spyware), not so much.
The switch exists for when you are NOT on a video call. It completely cuts the video feed going into the OS on the hardware level. How is that so hard to understand for people here?
Your argument seems similar to "why would you care about a microphone spying on you 24/7 if you're willing to sometimes have conversations that might be overheard?"
Yes obviously when you use your webcam you're aware that it's not impossible you're being spied on, and some people may choose to never have a webcam for that reason. For those of us who are happy to take that risk for video calls, we don't have to also accept that we can be spied on any time the laptop is open.
I don't care who watches me through my camera, I was just trying to point out that people aren't stupid about the hardware switch. Some just find it ironic that there is a hardware shut off for a camera on a computer operated by Google.
I think regardless of the fact that it is technically possible with any hardware and any operating system, it is difficult to argue that the risk is the same on Linux as it is on windows or ChromeOS.
I doubt ChromeOS or windows are spying on you through your camera either when you are or are not using it, but people can be sure their Linux distro isn't.
Buying parts for a Framework will cost more than parts for a $400 laptop of which there are thousands on ebay of every single part. For example let's assume the screen is broken and we have a $400 laptop which can be replaced on. A new screen is about $100-150 (based on a quick ebay look of $400 laptops). A new screen for a frame.work is $180.
Your ONLY option with a frame.work is to buy through them at the moment, there is no other part providers. You are at the mercy of frame.work to provide support for parts and supply.
With a $400 Lenovo a quick ebay search can provide you every single part from all over the world at a variety of costs. As well as the normal companies that provide parts for them (and Lenovo themselves).
I would be disappointed in framework if they locked out 3rd parties from selling replacement parts. That's the whole point of right to repair.
My hope is that if people rally behind a platform like this, it will drive the price down too.
There's also the fact that we currently aren't pricing in the cost of e-waste, much like how gas in the US doesn't currently price in the cost of climate change related damages. It could be that those $400 laptops are artificially cheap for now, but once you start charging companies for planned obsolescence, it doesn't make financial sense anymore.
Strangely, its easier to get money for purchases than have a repair budget, but that US government funding for you.
For folks wondering "who's the market in this?", the Linux container support in ChromeOS is awesome - my Pixelbook was actually a great dev laptop (I ran postgres, VSCode, Node, etc on it), just with age it's lack of upgrades is starting to show. So for me, on the "ChromeOS side", for me it's a benefit that it's basically just browser and android apps, and then on the Linux side I have everything I need for development.
Can you expand on this? Perhaps a URL with more detail?
In the end though it is cultural and not technical. Debian will bend over backwards to make sure That One Guy can still install the latest version on his old Centaur CPU, from floppies. ChromeOS is laser-targeted for specific, allow-listed hardware platforms. If you are philosophically committed to the eternal comfort of That One Guy, the Debian way makes more sense. If you just want software that's faster and more secure, ChromeOS has the better way.
Which is a roundabout way of saying; it's critically important that we don't over-optimize for the central, happy path (just wanna browse securely on whatever hardware ya got). The most interesting things (and the most valuable) frequently come from the edge cases, which are absolutely supported by keeping an eye on the needs of "That One Guy". Unix interoperability has given us a bounty of awesome shit and I anticipate it will continue to do so.
Battery life of ThinkPad that supports Linux with TLP installed and properly configured will be very similar to Windows. And to address FUD from other reply to your question: AFAIK official Firefox builds for Linux use PGO as well, however PGO has quite less impact on battery life than what another commenter suggests.
I think the real challenge here is for distro vendors to figure out how to provide a better user experience around this. There's no reason that the ephemeral key can't be stored in a sealed state that can be recovered as the machine wakes. There are obviously some security implications to this, but I think it's fair to say that a lot of users would prefer making that trade-off.
What you want is that if someone steals your hibernated laptop, that absent a way to securely authenticate themselves as you, they can't restore the working memory of your laptop. If you think about it, if they could, much of the point of many security precautions would be lost.
As a Fedora user, this is how my disks have been setup for many years, and I don't understand why Fedora have disabled hibernation. During wake from hibernation, the kernel and boot ramdisk would need user input to unlock the PV and to decode the LVs. Then, the hibernation state would be visible at the same time as the other filesystem state, and the kernel could decide whether to load the hibernation image or continue a normal boot sequence.
This seems to provide the protection of content needed for theft of a hibernated machine. I don't know whether there is some unhappy sequencing flaw in the dracut-generated ramdisk (between when the wake-versus-boot decision has to be made and the LVM decryption is done), or, whether someone at Fedora has decided that the threat model is different than we discuss above?
Again, the reason why it's different is the security model for memory is different from the filesystem. This is exactly what I was getting at: the fixed key. Encrypted swap volumes typically are set up to use ephemeral keys that are "forgotten" when you power down. The idea is that you only have access to that memory while the computer is running. When you boot up again, whatever data is in the swap partition is just noise. As mentioned in the link I provided (https://help.ubuntu.com/community/EnableHibernateWithEncrypt...), the current solution is to switch to using a fixed key, much as you described. That fundamentally changes the security model, and not in a subtle way.
I think there's a solution that more closely approximates the security model, with only a minor compromise: when you boot up, you generate an ephemeral key in the secure enclave, and use that to encrypt your swap. When you hibernate, the secure enclave encrypts all the metadata (including the ephemeral key) into a sealed state that is stored on disk with the swap information. When you restore, the sealed data is read back into the secure enclave (and erased) and it can then decrypt swap as needed. This still means the hibernated memory state is fully recoverable by whomever is able to authenticate with the enclave, but that's what everyone wants. On the upside, if you shut down the machine (rather than hibernate), the ephemeral key is lost, so there's no way anyone can recover what's on your swap, even if they have access to whatever fixed key(s) you have used for your LVM volumes.
If you're really paranoid, you could even generate a new ephemeral key on restore and reencrypt the entire swap volume with the new ephemeral key, though I'd question what realistic threat model that would really address.
I adopted the conveniently offered, software-based whole disk encryption mode when installing Fedora. A luks-encrypted LVM PV is the only luks mapping at runtime, and a naked /boot volume is the only volume not allocated as an LVM LV in that encrypted volume group. Thus, I have selected my storage security posture. I expect the cold or detached storage device to be resistant to inspection. Due to the unencrypted /boot, I have doubts that there is tamper-protection of the future running software, should I temporarily lose control of the physical device. I have no illusion that the running kernel lacks access to the plaintext content.
My swap is an LV in that encrypted volume group. Why is hibernation disabled on Fedora? This is where I feel like there is a poorly communicated threat model or some other unstated assumption that I do not appreciate. (But see my last paragraph below for a possible answer!)
Are people concerned about the written hibernation state using the same key as the filesystem volumes? I.e. that knowing how to unlock the whole-disk encryption means you can reconstruct the hibernated image too? I don't see why I, as a user, should care to protect the hibernation image even more than all my regular data. Similarly, if I have the key I can potentially attack the root volume (while offline) to inject all sorts of malware, such that I could exfiltrate RAM state from the running system in the future. Swap isn't required to open me to that attack.
Are people concerned about regular swap state being available on disk during system operation? I.e. the running Linux luks mappings can be abused to inspect swap state? I am not sure I can appreciate this angle, since I think it is farfetched that the swap mapping can somehow be more resistant to attack than the filesystem mappings in the same running kernel.
Are people concerned about regular swap state being left on disk during a non-hibernated shutdown? If so, I would suggest that the swap crypto should not be conflated with the hibernation crypto. Add an ephemeral cipher to swap if you must, but use framing/metadata to reliably distinguish the ephemeral swap "noise" image from a valid hibernation image. I'm OK saying that hibernate must write an entire image and not assuming that regular swapping can opportunistically prepare any hibernation state prior to a hibernation event actually commencing.
While writing all this, I have thought up another possible angle. Maybe this is the actual Fedora issue? I can see that control of an offline hibernation image means control of a future running system image, and this might violate some secure boot agenda? I.e. I can tinker with the hibernated state to introduce a "hacked kernel" and ask the system to restart with that. I can see why secure boot might prevent return from hibernation. This requires some integrity-protection chain to enable the trusted bootloader and kernel to verify a hibernation image before opting to load and restart it. I can see how a variation on your "sealed state" approach could address this. But note, it only requires integrity protection and does not actually need another layer of confidentiality protection.
Yes, we are talking about different scenarios. As I said, you can absolutely set up your swap to use a fixed password and then it will work fine as you describe.
> Are people concerned about the written hibernation state using the same key as the filesystem volumes?
That might be part of the concern, but it's more that it is possible to recover previous memory/swap state with a key that can reasonably be subsequently recovered.
Let's imagine a scenario where I have a secure password, that I enter into my browser, to say, access my bank's website. That's stored in memory by my browser & the GUI, but it is not normally allowed to be put on disk for security reasons. Then I hibernate my laptop and it gets written to the encrypted hibernate volume that uses a fixed password. I restore my laptop and go about my business. I might even reboot the laptop several time subsequently without thinking much about it. Then, someone finds a way to compromise the password used for swap encryption using any number of possible attacks (some you described). Now, not only do they have access to all the stuff on my computer, but they also have access to the contents of the encrypted swap volume, which unless I was lucky and the particular swap page was overwritten, the compromise goes back to the memory of the runtime from long before the machine was compromised. This would include this password that was very intentionally NOT stored on that computer, in order to avert precisely this kind of threat.
> If so, I would suggest that the swap crypto should not be conflated with the hibernation crypto.
That's another possible avenue, not that unlike what I was suggesting. It's worth noting though that these days there may not be much value in having separate passwords for swap vs. hibernate, since swap is rarely used on laptops.
They are all different security trade-offs, and it is debatable which is the right one. I don't think the current default is the right one for most users, but I do understand it.
My anecdotal experience with friends that tried Linux is that it left such a bad impression when they opened they're laptop the next morning and it's lost most of its battery life that some actually went back to Windows.
[1]: https://gist.github.com/RobFisher/abd9b2b9fca4194ac8df112715...
1. Create a swap file. Our rule of thumb is ram + sqrt(ram) for hibernate
fallocate -l 72GiB swapfile
chmod 600 swapfile
mkswap swapfile
swapon swapfile
swapon --show
2. emerge suspend
3. Get the number to use with resume_offset later. In the current case, it was 125798400
swap-offset /swapfile
emerge sys-boot/grub
grub-install --target=x86_64-efi --efi-directory=/boot
vim /boot/grub/grub.cfg
timeout=5
menuentry 'Gentoo Linux 5.18.19' {
root=hd0,1
insmod all_video
linux /kernel-5.18.19 root=/dev/mapper/root resume=/dev/mapper/root resume_offset=125798400
}
4. Fix suspend.conf
vim /etc/suspend.conf
resume device = /dev/mapper/root
resume offset = 125798400
5. Setup an initramfs
cd /usr/src
mkdir initramfs
cd initramfs
mkdir -p bin dev etc proc sys new-root
cp -a /dev/{null,console,tty} /usr/src/initramfs/dev/
cp -a /bin/busybox ./bin
cd bin
for i in `./busybox --list`
do
ln -s ./busybox $i
done
cd ..
cp -a /sbin/cryptsetup ./bin
mkdir -p ./run/cryptsetup
lddtree -l /sbin/cryptsetup
Copy in all of those files until the local cryptsetup works appropriately
vim init
#!/bin/sh
# Define a rescue shell
rescue_shell() {
echo "Error in boot process, dropping to a shell"
exec /bin/sh
}·
# Mount our devices. We sleep prior to dev to hopefully finish loading.
mount -t proc none /proc
mount -t sysfs none /sys
sleep 2 && mount -t devtmpfs none /dev
# Decrypt the root partition
cryptsetup --allow-discards luksOpen /dev/nvme0n1p2 root || rescue_shell
# Attempt to resume
printf '%u:%u\n' $(stat -L -c '0x%t 0x%T' /dev/mapper/root) > /sys/power/resume
# If we're not resuming, mount the new root
mount -o noatime,discard -t ext4 /dev/mapper/root /new-root
# Unmount (cleanup) our devices
umount /proc
umount /sys
umount /dev
# Boot from the unencrypted partition
exec switch_root /new-root /sbin/init
6. Suspend should be working with:
echo shutdown > /sys/power/disk
echo disk > /sys/power/state
or preferably
loginctl hibernate
Anyway, there's a lot of missing detail in there, but the idea is that there's a swapfile inside the normal encrypted root partition. For me, I've enough ram where I don't really use swap unless hibernating, so a swapfile versus a separate encrypted swap partition suffices.I love Linux and I would consider myself a power user (understanding HW arch, working with kernel sources).
Basic Chromebook apps (+ Play Store) are something that "just work" for 80% of time for my use-cases (which is, browser and ssh-ing into a power machine in ze cloud/DC). I also have rather good understanding of threat models here, and the quality of the sandboxes and HW roots-of-trust, hardening and software isolation on a typical Chromebook, so it gives me a relative piece of mind for specific use-cases (personal/family files etc.). Supporting an extended family, if they can get used to Chromebooks (it covers 99% of their needs, esp. that Android apps can be installed here) is a bliss.
Customizing Linux is mental fun, but on a road you probably something that just works, and typical Linux is rough at edges - GFX support, hibernation, esp. if you don't want to stick to some LTS distro, b/c you always need this newer package for dev purposes or tinkering.
The remaining 15% is covered by a VM, which seems really nicely integrated (X11 proxy etc). The remaining remaining 5% cannot be covered - custom kernels, custom USB drivers, occasional need to use Windows, but that's fine, I can do that on a desktop or on some random, cheap, low-power laptop.
In essence, it's just a thin client on steroids, which almost always works in its basic form. But if you want something more interesting, there's always a VM with some Linux distro, or Android apps via the Play Store. But these are optional and don't affect stability of the core system, if you don't use them.
An Android tablet is a muuuuuch better experience for running Android apps than the Pixel Slate. A Framework running Fedora is a muuuuuch better experience for doing dev work than a Chromebook.
ChromeOS is great when used for what it is, and it's cool that it can flex to handle edge casey things with VMs. But if the VM stuff is most of what you want to do, just go a different way.
This is something that jumps out to me - over how many years and why did you replace them?
None of them were replaced because I strictly speaking needed to replace them, and all got handed over to someone else who happily used them.
don't they already support this on the existing framework?
For web browser-based stuff, I have a constantly-updated state of the art browser with full vendor-backed hardware support for everything around graphics, sound, USB, Bluetooth, etc, anything else I might want, plus probably the best sandboxing you can get as far as protecting the core system from any malicious web exploits. It also works rather well in tablet mode with convertible devices. IME, getting all of this on bare-metal Linux and having it stay working for years is very hit-or-miss.
For linuxy CLI stuff, I have a built-in Linux container with a nice terminal. Everything I've wanted to do as far as CLI stuff works great, including Vim + Tmux, developing and compiling in any language, systemd services, docker and k8s CLI support. I've opened at least a dozen or so PRs on various open-source projects and maintained server clusters working entirely on a Chromebook. All the driver and display stuff is taken care of by ChromeOS so I never have to mess with config for it.
ChromeOS has a great separation of concerns and isolation of environments. I have my work profile and my personal profile, which are totally separate. I have my browser environment and my dev VM, which are totally separate. Different activities are cleanly partitioned.
This has obvious security benefits but also is just a really nice, simple way to manage the system. I can fuck up a dev VM without impacting anything else, I can click random links on my personal profile without impacting work, etc.
It also just does what I want it to do. I browse the internet, I program. It's good for those things. So... why Linux?
[1] https://old.reddit.com/r/Crostini/comments/b680wa/external_d...
Biased but informed opinion: I own a Framework Laptop running Ubuntu 22.04.
Linux on a server or a desktop isn't so bad. Linux on a laptop is awful. Hibernation isn't supported. Battery life is mediocre, and battery drain in sleep is significant. If I close the lid on my Framework at 75% and come back the next day, it will be at 25%. If I come back in 3 days, it will be completely dead. Even on a device designed to support Linux (Framework, Thinkpad, whatever) the Bluetooth experience is....err......well, if you don't have anything nice to say don't say anything?
ChromeOS isn't perfect, but as a laptop I'd much rather run it (with Crostini to get a Linux development environment) any day.
I am really waiting for a linux laptop, which is truly mobile. I also rather went with chromebooks so far.
There's apparently a world of difference. Nothing about the Framework suggests it was designed for Linux.
A proper Thinkpad does not have issues with hibernation, or losing battery, or graphics, or any of the other things you mentioned.
I just want something that works, and will receive updates as long as there are users. I don't want to muck about with VMs, or Crostini, or whatever it's called. Sounds like I must never let go of my Thinkpad.
The vast majority of people I know who tried running Linux on their laptop switched to Mac/Windows/ChromeOS. Containers and subsystems like WSLv2 or Crostini make it mostly painless to do Linux development while having a host operating system that has people paid to make the experience great rather than volunteers who generally want to work on shiny algorithms rather than fixing UX bugs.
More specifically: I've run Windows on the Framework and it was generally great (I wished it was a touchscreen, but that's about it). Maybe with the right magical device I could get a great Linux experience, but it's not worth having to search and compromise for me. I can install Windows on anything and it will work. I can buy any of the few Macbooks on sale and it will just work. I can buy any Chromebook and it will largely work out of the box. Linux is the only OS that makes me carefully check that my exact set of chipsets and components will probably not be a complete disaster. I buy laptops based on their hardware specs (screen, keyboard, trackpad, weight, ports) rather than their compatibility with an operating system.
Not necessarily. There's plenty of instances of devices working poorly in Windows before the issues get patched (if they are at all).
If you want something that 'just works', you are indeed better with the Apple ecosystem. They control the hardware and software.
The only way around these issues is to pressure vendors to provide better Linux support. The only reason Windows laptops tend to work better out of the box (or at least with all hardware working to some extent) is because of all the testing done by vendors.
But it's really not. Linux is mainly for users, by users. You're going to a very diverse set of users and experiences. For every tweaker out there you're going to find someone like me who just wants a unix-like operating system, with Perl and Python and everything else available with a minimum of fuss. They just don't speak up very often, because there's not much to something that works.
Of course it's important to mention the problematic bits too, and there's been many. I've mostly run Debian for over twenty years, and there has been several times where I had to fix issues from migrations such as rootless, utf8, python3 things, and file format migrations. For a long time things like hot plugging monitors, projectors and printers were a bit of a gamble.
But for the most part it's given me an environment where I can use a wide range of tools from emacs to nmap, from git to latex without giving a second thought how to configure paths, and how to fix some random missing dependency for a package to build, or why nginx doesn't pick up the changed file date. All those things have been ironed out by someone who went before me. That's worth a lot.
> I buy laptops based on their hardware specs (screen, keyboard, trackpad, weight, ports) rather than their compatibility with an operating system
Yes, that pretty much explains everything.
That's a luxury available to users only of a completely dominant software platform.
A Mac user could never say that. If you want OSX you must carefully buy supported hardware. You can buy a hackintosh, but don't fill up threads with complaints how bad the suspend works, and that the picture quality of the webcam is subpar.
Speaking for myself, I know what software I want to use. I do not care about hardware specifications in any other way than it runs my software reliably. Sometimes that means you can pick any color you want, as long as it's black. Black as my laptop.
Not sure if my E495 would qualify as a "proper thinkpad", although I've read about the same issues on T series laptops, I've almost never managed to make my laptop sleep in the 3 years I've owned this laptop starting from kernel version 5.4.x to the present 5.19.x. Whenever I try to 'systemctl suspend', one of the following things happens
- the laptop sleeps for a few seconds and wakes up
- the laptop sleeps for a few seconds and wakes up completely frozen and I have to perform a hard reboot
- the laptop doesn't sleep and freezes and I have to perform a hard reboot
- the laptop sleeps successfully but when I wake it up, the screen is messed up with green colors all over the place, hard reboot needed
My laptop also kept freezing randomly from 5.4.x to 5.14.x.
Not trying to contradict you. Just noting how even within one manufacturer's footprint (and "linux" however we define that for the purposes of this conversation) YMMV.
I don't know about the E-series specifically, sorry.
I will say I agree, you can't use a Linux laptop and take a video call without being tethered to power.
YMMV
Sounds like something that Framework should fix. There's nothing wrong with the Linux kernel per-se.
I have an older Dell Chromebook (turned into a Linux machine once Google stopped OS updates). Battery drain during sleep is pretty significant with either ChromeOS or Linux.
I have never had a problem with suspend, hibernate, nor excessive battery drain (beyond what the hardware should do) on any of linux laptop setups.
Thats starting from a thinkpad in 1998 (yes), all the way to my current amd 4800 tongfeng (generic chinese oem laptop maker).
Along with quite a few chromebooks thrown in along the way (all of which were developer-mode enabled, WITH secure verified boot turned back on, so had full access to linux apps WITHOUT using crostini vm's).
But, seeing as how chromebooks are essentially machines running GENTOO LINUX with a custom google ebuild overlay, then perhaps their reliability should be another plus checkmark for "linux on laptops", and not somehow a ding against that.
Anyway, take that for what its worth ...
I have not seen a remotely significant difference between ChromeOS and Linux (with Chrome Installed) for the vast majority of users.
It is true that Linux on ChromeOS is annoyingly fiddly and my suspicion is that this is the Google mind (perhaps subconsciously) not wanting to reveal how generally unnecessary "ChromeOS" would be in a world that collectively "knew that the Linux Desktop existed." And I do mean this "without modification," i.e. most of your top 20ish Distrowatch distros fare perfectly well here.
You provide IT support, eg for school kids, and somehow they grok Linux just as well as a browser? That is not my experience.
Google definitely has not lost interest. The Chromebook team at Google is actually involved in almost (all?) Chromebooks made. Since Google is responsible for all firmware/software updates for the life of that Chromebook, they are involved in that way. As well, the hardware/firmware teams here do a lot of the core engineering to getting the core parts of the hardware working (motherboard/cpu at a minimum). And all BSP's end up living in the ChromeOS source tree I believe: https://www.chromium.org/chromium-os/external-bsp-hosting/
If you are looking for a spiritual successor to the Pixelbook, I'd check out the HP Elite Dragonfly: https://9to5google.com/2022/09/15/hp-elite-dragonfly-chromeb...
I have a Pixelbook that still gets ChromeOS updates regularly- the Android and "Linux on ChromeOS" features are still half baked. After wakeup - Android apps hang or show empty windows, Terminal takes minutes to work, and a reboot usually fixes everything. (This is after a powerwash and being on the stable channel)
I will say, the Pixelbook was super underpowered. They use the ultra-portable Intel CPUs that have a TDP of 7W, which makes them super slow with anything CPU intensive. The Dragonfly chrombook has a 15W base power usage, and can boost up to 55W, which allows for way more CPU intensive operations.
Yeah, they are half-baked in that they are trying to be a VM for Android and Linux apps, and neither are perfect yet. As far as I can tell, both are still receiving attention.
1. https://www.intel.com/content/www/us/en/products/sku/97461/i...
2. https://ark.intel.com/content/www/us/en/ark/products/95441/i...
(Disclaimer: I have not been following the Pixelbook news or really even considered the device before today, but people on this forum seem to like it)
As the sibling commenter mentioned, though, Google did just shut down their Pixelbook division, which is what I was referring to. And as a corollary, if you can forward this to anyone that matters, Google's product marketing is the absolute worst. And I say this as a big fan of Google's developer-focused products. Case in point, I'm a giant Pixelbook fan. If Google is shutting down Pixelbook development, why can't Google just put something on their store to point to alternatives, like you have?
As another example, I am heavily invested in GCP, and I'm a big Firebase fan. Yet I can hardly think of any other company that sells to enterprises that is so loath to even show a hint of what's on their roadmap. I get it, priorities can change, and you don't want to put something out there that is (incorrectly) taken as a promise. But tons of other companies have to deal with this problem, and with Google it's almost impossible to get any status about important bug fixes or feature requests.
As long as ‘killed by Google’ continues to be a well-known meme, they could have the best marketing department in the universe and it wouldn’t make a lick of difference..
> As long as ‘killed by Google’ continues to be a well-known meme
However, I don't think this can be used until the Chromebook has been initially setup using some Google account.
I'm not making a 'Google is evil' argument (that would be a different conversation). I just couldn't bear to trust any corporation with that degree of arbitrary power over physical objects in my possession, regardless of whether or not I'd use their webapps. The power imbalance is just too great. Google (or Microsoft or Apple) is, in practise if not in theory, above any law that can be wielded by individuals.
On a more specific (read: paranoid) note, these security chips give me the heebie jeebies. How long until I need to register a program hash with the FAANG-that-be just to run my own software?
There is a single "desktop" user on chrome os - 'chronos'. Even when you login with different accounts, everything is still running as chronos (id 1000).
What happens is that there are separate loopback filesystems, 1 per each "google account", all stored under /mnt/stateful_partition. These filesystems are encrypted (ecryptfs). When you login, the relevant filesystem is decrypted and bind mounted over /home/chronos.
All of this is done locally, no network queries involved. I don't think that you lose your local files if your google account is somehow borked. You just lose the online aspects of that.
But as a general rule, your overall point about not being too reliant on googlopoly is one which should be well taken.
A true laptop-appliance with an immutable-ish OS, decent security and fast/easy updates is actually a quite compelling notion. I'd be pretty uncomfortable with it not being local-first for user data though.
Fedora Silverblue may suit your needs.
Aside from Linux distros per se though, I think there's a need for something like ChromeOS (preinstalled, appliance-like, as foolproof as possible), but without the deep single-corp dependence. Unfortunately I don't think the market in its current state is capable of filling this need.
BTW, chrome os is actually gentoo linux under the hood (with the portage pkg manager stripped out at the end). At one time, there was even a shell script doing the rounds which put portage back on it.
Your larger point re: Google reliance is still a valid one, but one which holds true even if you run chrome on another linux distro. If you really look at it, I'm not sure if a chromebook is less private than that.
Indeed, that was my point. Something like ChromeOS is a great idea.
> Your larger point re: Google reliance is still a valid one, but one which holds true even if you run chrome on another linux distro. If you really look at it, I'm not sure if a chromebook is less private than that.
Privacy's not my main emphasis. The world is in a state of gradual physical collapse. My (wealthy) region has had infrastructure destroyed by successive waves of fire and flood, and it will never recover (eg. we'll never again have year-round roads or always-on internet). We're the vanguard of what is coming to all. Entirely network-dependent devices aren't appropriate technology for our time. a fortiori for single-corporation-dependent devices.
Coincidentally, I've been doing a deep dive into offline-first, mesh & p2p related projects (nncp, yggdrasil, etc).
Would be interesting to see a linux distro with builtin plumbing for such things. Eg: constant snapshots, cached locally and then forwarded on to your other devices (once they are network reachable), all within a local mesh network that you define, which sits on top of the public internet (and bypasses NAT and firewalls)
I always dismissed Chrome OS as a glorified iPad or Android tablet with a keyboard and desktop.
I’m mostly happy with my Linux-based HP dev one, but this is causing me to seriously consider a Chromebook (like this Framework variant) next upgrade.
Chromebooks have easy access to developer mode which gives you root access to the host OS though, so it's kinda moot.
At any rate, Chromebooks sound more capable than I previously gave them credit for, enough so that they will now be part of my evaluation next time I upgrade.
Between the Framework Laptop now supporting Chrome OS and some of the info in this thread, Chromebooks and Chrome OS no longer seem like just the cheap Google Docs appliances for schools that I originally thought they were, which is pretty cool.
Perhaps the next iteration, though that means replacing the whole chassis/screen (those seem harder to repurpose than the mainboard)
It took them awhile to get there, but with virtual desktops, gesture support, the hardware back button, Chrome tab scrolling (actually OP), I found that ChromeOS is the day-to-day best operating system for browsing the web.
As you note, the Linux support is great but requires a pretty beefy processor, my Pixelbook was the i7 and it still chugged a bit. But overall, amazing OS today, really miss that laptop.
It has only one issue for me, it does not have enough power to run MS Teams on the brownser, and the Android app does not work well.
A native app from MS would be quite nice :)
AMD chipsets have SoundWire, and MIPI CSI/DSI support, but there are no way to use them in Windows. Intel is starting to support them as well with Alder Lake mobile.
SoundWire is way simpler than HDA, and availability/cost is better.
Connecting the whole suite of peripherals over i2c allows to dispose of wide LIF cable from the front panel. No LPC EC needed.
MIPI CSI cameras are vastly superior to USB ones, and are dirt chip for price/picture quality due to the size of smartphone market.
Tablet use MIPI DSI panels price/quality is superior to LVDS panels, and you will never get such thin laptop-use panels.
Linux can use non-SMBus battery gauges, and PMICs. Again, you can forego paying the x86 premium on SMBus vs. i2c controlled PMICs.
A production linux laptop is a clear statement, "All of our hardware is immediately compatible with linux. Sure, our distro has little warts, but you can either install your own or `apt-get install fluxbox`, copy in your config files, and get right to work, ISL."
The actual important thing is that all their hardware has Linux drivers.
Most laptops that achieve that require the hardware, OS and browser working together. I've seen laptops that, when running Linux, struggle to last through an hour-long video call.
Edit: It looks like they did indeed put it together with Linux in mind: https://frame.work/nl/en/linux
I wish any vendor would offer a privacy-by-default telemetry-disabled ChromiumOS option I could actually recommend.
1. is it really worse then windows
2. google does has privacy option, partially thanks to the EU forcing them and as far as I can tell they are not randomly "undone" with updates from time to time
3. a lot of more common users do also have instagram and similar, do most things through android/iOS apps and use google search and chrome, or some chrome derivate. How much additional information does using ChromeOs expose?
Don't get me wrong for most people on HN it probably is degrading privacy. But this is not targeting the common HN user.
This is targeting:
- existing ChromeOs users looking for an upgrade
- this includes devs
- this includes less tech affine people
- this includes people which bought that premium Chromebook with a 3:2 Google sold years ago
- this includes a bunch of google (ex-)employs which might have been the driving factor for bringing out a ChromeOs version
- this includes junior devs which grew up with a edu focused chrome book
- people which care about the mission of framework, but are not highly tech affine, they might seem rare but they do exist- presents, Chromebooks can be nice presents to less tech affine users and if they anyway use mainly Chrome and similar it's not necessary "reducing their privacy"
- people feed up by Linux desktop issues but disgusted with Apple Hypocrisy and totally feed up with windows since a while
- especially if they are not supper sensitive wrt. privacy. And while such devs might sound like a myth on HN I have meet docents of them
Lastly it's the same hardware and probably more or less the same driver support issues, so the cost of shipping such a version is probably not too high while at the same time it can give you a bit more supply chain stability (by removing hardware choices outside of cards).The main question is if the firmware is in a state where you could just install Linux or Windows if you want.
I would never recommend Windows or MacOS to anyone for similar reasons so those are not a comparison I care about either. I would certainly recommend a Chromebook over either if someone absolutely has no choice but those three, but there are almost always other choices if you make some time to teach someone.
Most Linux distros are a security shit show so pre-installed linux machines are hard to recommend to anyone that does anything high risk on their machines like financial work or journalism.
Degoogled ChromiumOS feels like a good security/privacy balance for most people but that is not currently a user friendly option for installation and upgrades.
In practice I find myself using and teaching others using their machines for anything remotely privacy or security sensitive to install and use QubesOS. For all the excellent privacy and security design it has a high learning curve and strict hardware requirements making it untenable for low-budget or low-tech users.
Much of the HN crowd has their finances intertwined with forcing these kinds of choices on consumers. Sometimes I dream of an awful de-anonymized internet where your financial holdings are bound to every post that you make online. I think binding that incentive might change how we ingest opinions.
I think many people, if they find a comment really impactful, will take a look and see if this was said by someone using their real name and if there are obviously relevant major corporate biases they didn't disclose. Or maybe I am weird and am just trying to justify that I personally do this often.
Regardless, both anonymous and identified communication are very valuable depending on the particular goal, and it should always be a switch everyone is empowered to be able flip at any time.
Sometimes when I am testing out ideas to decide how I even feel about something myself, I may choose to be anonymous.
Most of the time, I am fine with most of my posts on HN being under my real name and tied to my reputation and that of the security and privacy consulting company I run.
I still reserve the right to change my mind and be wrong sometimes and trust most of my target customers to give me some room for that :)
I'm sure there's some complicated oven i could use that would be way better in the long run but I just wanna make pizza sometimes, not the best pizza in the world at the perfect temperature.
Those that can comprehend significant technical risks are obligated to recommend a low-risk strategy until people have enough relevant understanding to take informed risks for themselves.
I would for instance never let a minor use apps like TikTok known to granularly monitor and sell their location and behavior to keep them maximally addicted and maximally profitable. If the user is an adult tech worker that understands how such apps work and has the means to actually understand the privacy policy... then I will find their choice stupid but it is their life.
I don't have a problem with them making a chromebook but not releasing Coreboot firmware for the existing boards is giving me bad vibes, really worried Framework's leadership is compromised.
https://chromium.googlesource.com/chromiumos/third_party/hdc...
Other than Apple's M1/M2 chips, there aren't any ARM CPUs that can match the raw power of x86, but Apple has demonstrated what's possible. And it would do a lot to resolve the battery life.
I’m really hoping they release a standard keyboard with a generic “super” key instead of a Windows logo at some point.
I searched the Framework Chromebook page for "touch" and found 0 results. I hope they are working towards a touch enabled Chromebook.
I personally think that this Framework Chromebook is way to expensive at 999$, but I do fine from a non USD economy, so many technologies coming from US are too expensive for me. That being said, my vision has always been that Chromebooks are light, affordable and battery life that will last longer then you. I paid around 400€ for my Chromebook, the most important specification was FHD IPS display and at least 12h of battery.
I'm aware that Google made Chromebooks with very high prices, but I don't think many bought those.
That's why seeing this laptop for 999$ seem a bit too much, especially now that you can get M1 MacBook Air for the same price! And it's just as user-friendly, if not slightly more.
That's all I wanted... something newer that runs Vulkan too in Crostini :)
> The Framework Laptop Chromebook Edition […] receives automatic updates through June 2030
I wonder if CodeWeavers CrossOver can run Office on ChromeOS reliably.
And a $300 Chromebook in and EDU environment will last 5-7 years. I wonder if this laptop which is ~4x the price can last 15 years?
Oh well, looks like Apple’s gonna get my money..
ARM chromebooks > Intel chromebooks, and if they continue pushing Intel they’re killing the reason that chromebooks can be both cheap and good
EDIT: And if you want to use it for Crostini… why are you getting a chromebook
I get it, but good luck taking away my Mac from my cold dead hands.
Seems like half of HN readers think Google is the literal devil, but for the other half, why not ChromeOS?
No.
What we're getting is a Framework running a stripped down Linux meant for schools and made by a spy company?
I predict this thing not selling well, but I'm sure someone is excited.
Yup, you're right, this could be a very tough sell.
You think those IT people don't read here too? Its a budget thing sweetie, once you get a real job you understand.
I would think that the upgradability has significant environmental upsides for schools (who otherwise end up ditching computers fairly regularly)
I suspect it also means laptops with minor damage can be fixed more economically or at the very least can be cannibalised for the working parts to fit to other school laptops.
I think we all have different demands. Hopefully with the modularish system they can gradually make us all happy.
Is there really a market for a $999 Chromebook? Didn’t google try this several years ago and flop?
Worth remembering that "stock issues" / wait times etc. are as dependant on the production plans of the product as they are on demand. It can be a sign of lots or customers, or just that hardly any demand was expected and so even a tiny amount more takes a while to catch up on (especially if e.g. there are high-demand components that they'd rather put in products with a high profit margin), or... etc
Chromebooks do have a reputation for being under-powered budget mobile devices because they do serve that sector. They also do a lot more that can't be done as easily on Linux, if you have hardware that can support it.
As others have said, Pixelbooks are still coveted devices, and I've been tempted for years to buy one. I thought the original Framework would serve that niche, but it ultimately didn't.