Hello. I'd like to ask two questions about running OpenBSD on
Core/Librebooted machines:

(1) I know there's been compatibility issues in the past. Is it still
the case? More importantly, are they such that the setup would more
likely mean just replacing the security risks those projects seek to
address with new ones?

(2) I'm a sysadmin with zero experience writing drivers, firmware,
kernel patches. I want to eventually be able to contribute something
useful to the intersection of both projects, but I don't know where to
begin. Can you point me in some general direction? Topics to learn,
books you've found useful?[1]

Considering that,

A. I've searched the mailing lists (and r/openbsd) for mentions of
"coreboot" and "libreboot," read the changelogs (though, given my lack
of knowledge, I may not have recognized relevant changes), besides
reading (Core/Libre)boot's documentation;

B. My concerns about "features" like amd_psd and intel_me aren't merely
academic. I work with journalists and our government has unique
interpretations of human rights;

C. Theo de Raadt says on the parent subject:[2]

> And meanwhile, Intel added undocumented strong speculation to their
> cpus, which are now easily CVE-identifiable as verifiable giant
> security problems to a majority platform.  And the more we dig, more
> we realize they did this as market force, ignoring the risks they
> identified at conferences a decade earlier.

D. And brynet: "[...] there's only so much operating systems can do to
mitigate against physical hardware bugs, same goes for buggy hypervisor
hosts;"[3]

E. But kmos-ports: "Coreboot and Libreboot were written for use
specifically with Linux. They often skip initializing the hardware
properly and cause problems with OpenBSD."[4]

Thank you,
AJ

[1] I've checked the list of recommended books. I'm currently going
through "The Unix Programming Environment" and will start fleshing out
my C alongside once I reach chapter 6.

[2] https://marc.info/?l=openbsd-misc&m=156238500027310

[3] https://teddit.net/r/openbsd/comments/two0se/\
amd_cpu_firmware_microcode_current/i3in9zm/

[4] https://teddit.net/r/openbsd/comments/l1o0r0/\
openbsd_with_fde_on_a_librebooted_thinkpad_x200/gk1g2dy/

Reply via email to