Librebooting the ThinkPad T480
ezntek.com
ezntek.com
I had a nice chuckle at this. Buying chip clips? A separate Raspberry Pi to wire everything together and perform the flashing process?
Is there really no chance of some kind of click-and-reboot process, same as how official proprietary firmware gets updated?
The general rule of thumb for the security-paranoid is that once you lose sight of your device, you should assume it's been owned (any imaginable variant/combination of evil maid, DMA exploit thru a physical port, etc).
In recent years there has been a steady push to raise the bar (TPM, SecureBoot, etc). Whether that's effective for protecting the median user's privacy and security is a separate matter, but the side effect is of course that this is increasingly becoming a hurdle for power users, enthusiasts, OS developers, etc.
ARM Macs are at a very weird spot on this spectrum. On one hand, we have a new, bespoke, and undocumented system architecture, and keeping a macOS partition is a requirement to continue receiving firmware updates; on the other, Apple has left a clearly labeled escape hatch for OS developers, and kept it from accidentally breaking. You can't have a fully libre boot chain, but it's not like Lenovo (or most other PC vendors) would endorse that either.
Meanwhile, exploding pagers.
Sadly this is harder than it used to be because with devicetree the flash size is hardcoded, where before it was auto-detected (so previously you could swap the flash and continue to use stock firmware, not you need to compile custom firmware).
[0] https://www.digikey.com/en/products/detail/winbond-electroni...
This is coming from an M1 MBP user with 32GB who, even with aggressive paging in and out of an uber-fast disk, manages to fill about ~20GB on a regular basis.
Not having enough RAM slows you work to a halt, I would always go a tier down in CPU or GPU to have enough RAM
And it's also easy to expand later
Otoh, my main rig is also on 16gb today and I never run into issues. But then again I don't run electron apps and don't do webdev or microservice stuff with 30 VMs.
As I pointed out in another comment, RAM is soldered on most non-desktop computers these days. It's not easy to expand later. The hardware companies are well aware of that, pushing overpriced RAM upgrades at the time of purchase and it's not like you can just walk into a store and say "I'd like this laptop but with last year's GPU model and 2x the RAM for the same price."
It's still very easy to choose computers with modular RAM, even in portable formfactors. The classic SODIMM module format seems to have run its course and is not compatible with modern low-power memory but we now have the CAMM module which at least Dell and Lenovo are shipping and major memory vendors like Crucial offer replacement/upgrade parts for.
Obviously if you prefer your computers fruit-flavored you're SOL, but that's not news to anyone either. Their memory packaging in the M-series machines has its own advantages that may be worth the tradeoff depending on your application, but for a normal user it's more of a limitation than a feature.
Unused memory is wasted memory, so makes sense to always have a lot in memory. Doesn't mean that you'd have a worse experience with 16GB.
I accept trade-offs concerning development effort and time-to-market, however the phrase "Unused memory is wasted memory" does not seem appropriate for a developer who's proud if their work.
Little friday rant, sorry :-)
Once you clear the semantics hurdle it's surprising how much people are in agreement that "used" should be optimised, "cached" should fill as much else as possible, and often having large amounts of "free" is generally a waste. The only remaining debate tends to center on how much cache really matters with a fast disk and what percentile of workload burst should you worry about how much "free" you have left after.
It's too easy, and happening too often on HN these days, to reply with a low-effort contrarian statement without engaging with the central point of the argument.
And then seeing people say >I don't understand it either, a 16 GB DDR5 stick costs like $50
50 bucks is a lot of money to a whole lot of people. Yes, actual computations and compilation etc take a lot of memory, but there is so much memory wasted through js bloat, it's just sad. But if you take a little effort and optimize your system, then 16GB is still more than enough and "just works"
_should_ you have to spend more money to support bloated software? No of course not, especially since many users of such software _aren't_ tech bros, but as someone in tech, shelling out a little more money seems like a much more pragmatic solution vs having your computer be slow and/or waiting for the industry to change.
32 is great for editing and such, but I do assume that one would be using linux, and in that case, I can consistenly open over 100 tabs in firefox and do programming and have electron apps open on the side on KDE plasma with no issues, no out of memory errors. Things do get squeezy and noticeably slow at those extremely heavy workloads; for heavy tasks of course get 32 but if 16 can do you that far its fine.
I even won a hackathon with 16gb of ram on an X230, if I can do that and be productive even at home its enough. macOS is just very RAM heavy, theres always at least 50 weirdly names background processes active.
The most you can do is drop it to some kind of reduced functionality mode some time after boot (through the HAP bit, or hackery which overwrites part of the flash memory). This is why dishonest vendors like Purism resort to confusing terminology like "neutralize".
https://x.com/rootkovska/status/939058475933544448 https://x.com/rootkovska/status/939064351008395264
One of the benefits of deguard for Intel MEv11 is that it sets the ME in such a state where you can run unsigned code in there. This is how the Intel Boot Guard was disabled, because it is the ME that enforces such restrictions; more information about deguard is available on a dedicated page.
The deguard utility could also be used to enable the red-unlock hack, which would permit unsigned execution of new CPU microcode, though much more research is needed. Because of these two facts, this makes the T480/T480s the most freedom-feasible of all relatively modern x86 laptops.
With deguard, you have complete control of the flash. This is unprecedented on recent Intel systems in Libreboot, so it’s certainly a very interesting port!
...Dell? I have multiple of their machines which have been configured via their B2B panel to have ME fully disabled.
The bringup module always boot which configures the clock controller, bootguard parameters, and releases the CPU core from reset. When in HAP mode, after that it only handles power management events and doesn't really do anything else. No other ring 3 processes are started on the ME in this mode.
Stuff like even the real read-write VFS, fw updater, HECI comms handerl, AMT, PAVP, ISH server, etc are never started in HAP mode. It effectively reduces your runtime attack vector to data in SPI flash only.
As mentioned in one of the linked tweets, ME was possible to exploit through early-boot attacks before the HAP bit was even checked. So non-negligible things happen while it "boots".
While they are genuine vulernabilties, I wouldn't consider this a worse problem than being able to inject rootkits into other parts of the firmware which is also the case here.
And the understanding that we have is mostly limited to what is in flash memory, e.g. the ME's BootROM hasn't been dumped yet (as far as I am aware).
While yes you cannot strictly disable the ME, what remains of its firmware in this configuration is a bringup module that is stuck in a loop handling power management events.
The network stack, HECI stack, etc are all gone here. Effectively the only way to exploit it is to put your payload into SPI flash, which we are already doing anyways :)
It is also possible to take over the ME firmware and bring up the CPU using open source code, and have full control over the ME at runtime. This isn't implemented currently, but that's the direction this is aiming in.
I think there is a misunderstanding. Intel ME is a hardware feature. Yes there is some flash memory which contains more code and an operating system, but what is stored in flash memory is only part of Intel ME.
Peter Stuge from Coreboot noted during his 30C3 talk that even if you completely zero out the flash, it is possible for Intel ME to send a network packet out of the ethernet interface. The cutoff point when this started happening is the 965 chipset around 2006.
https://media.ccc.de/v/30C3_-_5529_-_en_-_saal_2_-_201312271... (relevant part starts at 17:19)
The only code that is inside the silicon is a 128K bootrom that literally just sets thing up for the real firmware to run.
It runs Minix, as I recall...
it will make you (as of now) unable to use thunderbolt and therefore a dock. Maybe you see that as improvement. I kinda like my thunderbolt
I recently built https://linuxlaptopprices.com/, inspired by diskprices.com.
The mod is complicated and very, very expensive. But possible, if you can find one in your preferred layout, which is very doubtful at this point - they've all been snapped up by people doing what you describe.
I do use the T25 keyboard on my T480. Is it nice? Oh hell yes. Was it worth the time and expense? Absolutely not, unless you are a serious keyboard nerd and have more money than sense. Which I did, at the time.
Now this I don't agree with; I have made no software changes to my T480 whatsoever, and the keyboard works more or less as expected. Some of the Fn-key shortcuts do not match the key labels (behaving instead like a stock T480) and the microphone mute button doesn't work, but otherwise everything's perfect out of the box. Speaker mute, volume keys, navigation keys all fine.
coreboot isnt even in the main tree yet! you have to use libreboot unless if you want to hunt down mate kukri's branch and go off that. you also have to use deguard to disable intel boot guard. It is more work than ivy bridge, which is why I use libreboot; its all done for you, its reliable and updates are done by someone else (you dont have to update your own payload yourself and recompile and retinker etc).