[prev in list] [next in list] [prev in thread] [next in thread] 

List:       qubes-users
Subject:    Re: [qubes-users] Qubes Security Bulletin #24 (Critical bug)
From:       Achim Patzner <noses () noses ! com>
Date:       2016-07-26 23:13:29
Message-ID: 78D98A33-C9C9-4FF6-A9F4-230D5A80FA0B () noses ! com
[Download RAW message or body]

> Am 26.07.2016 um 19:42 schrieb Andrew David Wong <adw@qubes-os.org>:
> 
> The updated requirements for Qubes R4.x-certified hardware are
> explained here:
> 
> https://www.qubes-os.org/news/2016/07/21/new-hw-certification-for-q4/
> 
> Although the requirements for Qubes-certified hardware are likely to
> be more stringent than that minimum requirements

If

"Another important requirement we're introducing today is that Qubes-certified \
hardware should run only open-source boot firmware (aka "the BIOS"), such as \
coreboot. The only exception is the use of a (properly authenticated) \
CPU-vendor-provided blobs for silicon and memory initialization (see Intel FSP) as \
well as other internal operations (see Intel ME). However, we specifically require \
all code used for and dealing with the System Management Mode (SMM) to be \
open-source."

is the minimum requirement, Qubes just put itself out of the game by being able to \
run on prehistoric hardware only (see coreboot's list of supported systems and CPUs) \
or being at the mercy of someone being able to provide a system with appropriate \
firmware support by twisting some of Intel's appendages. It's nice to demand free \
beer for everyone but you'll have to find someone providing it. Especially with Qubes \
hardware demands to be more than a fancy typewriter (unlike others I found 64 GB of \
memory and a sufficient number of CPU cores not to be wasted).


Achim

-- 
You received this message because you are subscribed to the Google Groups \
"qubes-users" group. To unsubscribe from this group and stop receiving emails from \
it, send an email to qubes-users+unsubscribe@googlegroups.com. To post to this group, \
send email to qubes-users@googlegroups.com. To view this discussion on the web visit \
https://groups.google.com/d/msgid/qubes-users/78D98A33-C9C9-4FF6-A9F4-230D5A80FA0B%40noses.com.
 For more options, visit https://groups.google.com/d/optout.


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic