Gluglug X60 Laptop now certified to Respect Your Freedom
fsf.org
fsf.org
They require the BIOS / core boot firmware to be open but allow closed peripheral firmware and CPU microcode.
This is a natural allowance as otherwise no modern computer would ever be certifiable, but it's interesting in that it doesn't require the firmware for wired-in peripherals like webcams or wireless chipsets to be open.
WiFi firmware can in theory allow passive monitoring and forwarding of data. This is because the WiFi card is a small self-contained embedded system.
The CPU microcode (and arguably architecture) is more difficult to modify but it's possible that the microcode for an AES round opcode could be intentionally flawed. Enough press is around not to have to explain this.
USB is the one I find interesting. Anything (webcam/keyboard/mouse) could arbitrarily register itself as an HID device and inject data into your OS.
The whole systems architecture is a mess.
I'm not suggesting we go back to discrete wire-wrapped PDP11's but something needs to be done by putting security and privacy first. That means starting again as where we are isn't good.
Plus without the requirement to release firmware for co-processors, some full machines with the potential for DMA and all sorts of nefarious concepts can exist that nobody even notices (SMC, WiFi, Bluetooth, "fan managers" and so on).
With that being said no modern CPU vendor would even think about open-sourcing their CPU microcode especially, so the FSF are stuck between a rock and a hard place. With a true "every single thing open" requirement in place, the only general purpose PC made in the last ten years or so that could hope to come close to passing would be a Chinese MIPS laptop.
I always thought the sensor power was connected also to the LED, to prevent exactly that type of hackery.
http://www.washingtonpost.com/blogs/the-switch/wp/2013/12/18...
I guess that you mean that it'd still give correct output, but somehow leak the key (incorrect output seems simple to detect, unless it happens for a very small set of keys, and then it seems mostly useless).
I wonder: what ways of leaking the key off the machine would you expect? I (but I'm probably not devious enough) don't see ones that aren't overly complex and don't require additional compromised peripherals. Do you?
It seems unlikely, though, due to the probability that an adversary that controls both CPU microcode and VM placement probably has access to the hypervisor.
The fact that seems so impossible I believe is one of the reasons our IP and information sharing ideologies are so completely fucked right now.
On the other hand, it would typically be detectable and would generally fail to work without significant intervention from the software on the computer. The same goes with the webcam. Theoretically, it could keep its activity LED shut down and snoop you without you knowing it, but how is it going to send data over to No Such Agency?
This is probably not sufficient for high-security matters, of course, but it is IMO good enough to ensure the privacy of a user who doesn't do anything illegal. Working past the security you get simply from running open-source software (at least as far as the peripherals are concerned) is expensive, risky and potentially intrusive enough that it isn't worth doing unless you're trying to tap into a drug dealer's computer. In which case yes, you should be thinking about something else.
> I'm not suggesting we go back to discrete wire-wrapped PDP11's but something needs to be done by putting security and privacy first. That means starting again as where we are isn't good.
More vitality in the open hardware movement would be great. This isn't meant as a way of criticizing its members; if asshole engineers like me would do something about it instead of blabbing on HN, things would probably be better.
Note also that while the software running on your CPU might be beyond reproach (you carefully read every javascript file before you execute it right?), the microcode running on your cpu can do just about anything.
IMHO, it does. The PCI bus isn't something that gets shared on a whim. The functionality you need for this would have to be built in the BIOS.
RMS has been recommending the Loongson Lemote for a long time, which would seem to be a much better choice. The Lemote's firmware and hardware is essentially all open source, including its MIPS CPU.
When these were first announced, I wanted one badly. A cheap, MIPS-based laptop? Yes please. But you couldn't get one for a long time, and queries to the Chinese company were never answered. Now you can get one, but they're now out of date and too expensive.
And it includes a brand new battery and the docking station.
Hmm... I still have fond memories of my X61. This is actually kind of tempting.
If you're that concerned and trust your software stack that little, it wouldn't be that hard to open up the system and physically disconnect the internal microphone, such that you can only use a 3.5mm or Bluetooth microphone. But if you trust your software stack that little, you have bigger problems. Efforts like the one in this article are a good step towards not having to worry about that kind of problem.
http://www.washingtonpost.com/blogs/the-switch/wp/2013/12/18...
Yesterday's news show that some implementations can be unsecure [0].
> But if you trust your software stack that little, you have bigger problems.
I generally trust the software that I run on my main CPU but there are other threats like DMA malware [1] for example.
However, you can disconnect the hardware pretty easy. I've done this on my T400. Took about 5 mins with a Swiss army knife screwdriver (all you need to service a ThinkPad!).
I have taped a piece of aluminum foil over every webcam on my laptops/iMac with a large piece of packing tape (making it possible to pull it aside when I do rather frequent video conferences).
I get dismissed as paranoid (or the next question that's asked is "what do you do in front of your computer!"). What they don't understand is that years ago I wrote software for a building access kiosk that involved a one-way video chat, followed with a photograph taken of the visitor. I used an open source library for interacting with the camera. When video was running, the light was on. I had the worst time getting the camera to take a picture, but after a bit of tinkering (read: shooting bullets randomly), I had it working. It was my coworker that noticed the light didn't come on when the picture was being taken. I had done something wrong (so wrong that every few pictures, the camera would stop working and wouldn't recover until the entire machine was rebooted). Though I've been writing software professionally for twenty years or so, I had never wrote code to interact with a web cam and yet had somehow managed to stumble upon this entirely by accident. It gave me the willies, so from that point forward, I covered my cameras with a bit of ugly aluminum foil.
I've never really worried about the microphone, but it would be nice to have some kind of hardware control to disable devices that can be used to record in that manner.
a post it cut with just the glue part works fine, easy to replace and leaves no marks.
When I use this under linux, it reports an unrecognized keycode; but at the same time the USB device reports as if disconnected, which I can see in dmesg. Close enough for me.
Give me a laptop that can actually replace my MBP, instead of merely sit on the shelf while I watch movies and surf the web, and we'll talk.
The hardware is a bit antiquated, yes, but it's a step in the right direction. There are a good amount of programmers who care about freedom that are using Lemote laptops as their primary computers. So, I think that the Thinkpad X60s is certainly an improvement from a more practical standpoint.
>Give me a laptop...
If you really want freedom, you'll work for it and sacrifice some convenience instead of waiting around for someone to do all of the work for you.
Personally, I made a bit of a compromise and use a Thinkpad X220 with a hacked version of the proprietary BIOS so that I could replace the wireless chip with a free software friendly one.
Mr Hess seems to do ok with a lowish spec netbook and more recently a Lenovo Arm based tablet convertable. Perhaps many programmers need high specification hard ware, but even rounding error would be a significant market for this operation.
Up to last March I was using a first generation eeepc with a resolution of 800x480, 512mb of ram and 4gb ssd. It was stretching it but didn't stop me from doing actual work with vim, compile programs (although slow) and push to github. Plus ssh on my server for heavier work.
now... browsing the Web with elinks and framebuffer was kind of a pain...
An rMBP would be nice to have but in the meantime this laptop suits me just fine. The keyboard is better on this too. Maybe if that iPad Pro rumor pans out and it ends up having a USB port I'd just use that with one of my smaller keyboards (KBC Poker) instead.
For me using cheap low-end hardware is a feature, for development. Plus it saves me monies.
I think your comment demonstrates that most programmers are always going to go for the most awesome laptop and will make the necessary sacrifices. To me, the natural target market for this is probably FSF & EFF members; those that are concerned enough about their privacy that they will accept a laptop that does less, isn't as shiny, etc.
Most of my work revolves around programming devices with no more than a couple of megabytes of RAM, most often with no more than a couple of kilobytes. A MBP is far, far more powerful than what I need.
Just ordered one ;)
see comments for some acer chromebook work too (http://johnlewis.ie/)
If I'm not mistaken, thinkwiki gets their info from the thinkpad service manuals. (I have one too). There are a billion configurations of every laptop, most of which you'll never see because they were restricted to one region or market (or govt or edu). Some of them probably never even made it into production, but they exist as a row in a database.
AFAIK they were only sold for a couple of months.
My sample is a Type 1706-CT0 with product ID 1706WB5 and it was manufactured December 2006 (06/12 on the end of the serial number). Did I get 'lucky'?
Mine ran x64 just fine on Ubuntu.
[1] http://www.cnet.com/laptops/lenovo-thinkpad-x60-1706/4507-31...
[2] http://www.cpu-world.com/CPUs/Core_Duo/Intel-Core%20Duo%20T2...
I know that these CPU's are supposedly dual Pentium M processors in single package.
(also, the Panasonic 9-cell batteries are still good.)
The T61 which is where my main experience lies has hardware whitelists for WiFi cards and restricts the internal SATA port to basic SATA speeds rather than SATA2 speeds which the chipset supports.
There are many hacked BIOSes (I use Middleton's BIOS) out there which fix this though.
On my X1, it's impossible to boot from the SD card reader and only the official ($$$) USB Ethernet adapter will allow PXE-boot.
Is this simply a rearrangement of the standard QWERTY keys? Or a "real" Dvorak keyboard? Specifically, the nubs on [F] and [J] are always an impediment to swapping keys.
I imagine RMS using one while wearing a leather trenchcoat and mirror shades.
You're joking, right? Is this your first encounter with the FSF?