-
Notifications
You must be signed in to change notification settings - Fork 28
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Laptop Hardware Security #244
base: main
Are you sure you want to change the base?
Conversation
Signed-off-by: Tommy <[email protected]>
Deploying privsec-dev with Cloudflare Pages
|
✅ Deploy Preview for privsec-dev ready!
To edit notification comments on pull requests, go to your Netlify site configuration. |
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Post images should not be placed in the /static
directory. Follow the correct format as in https://github.com/PrivSec-dev/privsec.dev/tree/main/content/posts/knowledge/ChromeOS%20Questionable%20Encryption.
Are we gonna start moving other posts later too? Because there are a lot of them in /static |
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
Signed-off-by: Tommy <[email protected]>
To start off, the best laptops I have found are modern the Dell Latitude/Precision laptops with an Intel vPro Enterprise CPU. The second best group of laptops I have found are modern Lenovo Thinkpads with Intel vPro Enterprise or AMD Ryzen Pro CPUs. These are relatively easy to acquire and share these common security properties: | ||
|
||
- Have Intel Boot Guard or AMD Platform Secure Boot to protect the firmware | ||
- Have regular firmware updates ([monthly updates for Dell](https://www.dell.com/support/kbdoc/en-us/000197092/dell-drivers-and-downloads-update-release-schedule), and [bi-monthly updates for Thinkpads](https://support.lenovo.com/us/en/solutions/ht515365-thinkpad-driver-and-firmware-update-release-schedule)) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It seems it's not strictly one update per month. Sometimes there's several months without updates.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Also Dell and Lenovo never promised how long they would support their PCs
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It seems it's not strictly one update per month. Sometimes there's several months without updates.
Yes, its a general rule. It doesn't always hold.
Also Dell and Lenovo never promised how long they would support their PCs
They typically support them for years and years. Even 8th gen Dell and Lenovo are still getting updates.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Lenovo's Product Specification Reference does have an ‘End of Support’ column: https://psref.lenovo.com/Product/ThinkPad/ThinkPad_T14_Gen_5_Intel?tab=model.
520b835
to
c508504
Compare
Have the Microsoft Surface line of laptops been considered? Not the ARM ones (not sure if they they have memory encryption) but the Surface Laptop 6 for example. I'm pretty sure they meet all the requirements and the only downside would be Linux support but this is an article about general Laptop Hardware Security. Thoughts? |
AMD vs. Intel: https://www.qubes-os.org/doc/system-requirements/
Is it still applicable? Looks like there are no Dell Precision/Latitude laptops with AMD processors, but there are ThinkPad ones. |
No, this is not correct today. Both Intel and AMD support microcode updates through the OS, and both also have important firmware components that must be updated by the motherboard vendor. |
We are aware of their existence of course. But the Surface line suffers from a serious lack of technical documentation, and I'm not aware of anyone with access to a modern Surface device who is willing and able to evaluate it against our standards. Here is some technical documentation from Lenovo for comparison (Dell is also much worse than Lenovo in this regard):
It is possible to get a very detailed idea of Lenovo security features without ever touching a Lenovo laptop (though obviously hands-on time is necessary for a truly complete picture). Dell's business lines are so widely deployed that it is easy to get answers just by searching the internet as a supplement to the official documentation. Neither is true for Surface devices. |
https://github.com/QubesOS/qubes-doc/pull/1430/files to address QubesOS/qubes-issues#9485
|
Btw, does anybody know anything about the security of HP ProBooks? HP ProBook 450 G10 got HSI 3 (older models are much worse though). |
No description provided.