I get the desire to control the entire chain, but nowadays you’re surrounded by cameras and microphones 24/7, every smart device is a surveillance sleeper agent waiting for the magic word. Certificate chains are the least of your worries.
I get the desire to control the entire chain, but nowadays you’re surrounded by cameras and microphones 24/7, every smart device is a surveillance sleeper agent waiting for the magic word. Certificate chains are the least of your worries.
Yes, it's Coreboot with disabled and neutralized Intel ME.
> Your usb stack?
No, it's isolated in a dedicated, hardware-virtualized VM on Qubes OS.
> Your network card firmware?
Same as above. And it's FLOSS.
> surrounded by cameras and microphones
For those, I have hardware kill switches. On the phone, too.
Pinky swear.
Privacy already is (mostly) lost and the battle now simply is to reliably establish authenticity that can't be impersonated or doubted. That's where encryption remains helpful.
Authenticity isn't important if the message content can be verified. It can even pose a danger. People like to attack the messenger, especially if he has a point.
Don't know about your devices, but mine do not put me under surveillance. Smartphones are critical, but even those are controllable. If you are in public you won't know, but otherwise you can be reasonably safe.
Sure, because I have the complete source code for all three of those things:
Deliberately inserted malware, laying in plain sight in source code, is an existential risk for a company with a reputation like IBM's. Of course, there isn't a 100% guarantee of it being noticed, but a 1% chance of that happening is enough for them to tell the spooks to fuck off.
Special Access Programs only work because God-mode coprocessors like the Intel ME ensure zero risk of blowback for the manufacturer. Force them to have skin in the game and they aren't pushovers anymore.