Re: [qubes-users] Thinkpad T400s RYF

2018-11-26 Thread taii...@gmx.com
On 11/13/2018 05:43 AM, qubes-...@tutanota.com wrote:
> Outch, bad news :-( Basically I have only two options than: run reasonably 
> secure QubesOS on a flawed-by-design-HW, or use RYF HW with not so secure OS. 
> I am not maximalist, but you know, one doesn't go on boat that has holes in 
> it, even he has nicely and safely packed cookies on board.
> 
> Or is there any other RYF laptop which could run QubesOS? Sad days, these 
> days.
> 

pre-sandy/ivybridge intel stuff IOMMU doesn't work on coreboot and would
be almost pointless anyways as it is a very poor implementation security
wise.

I would get a G505s (AMD FT3 platform w/o ME/PSP), it isn't RYF but it
is owner controlled and the video and power management blobs can
theoretically be removed and as the cpu/ram hw init code is foss via
coreboot agesa the IOMMU would theoretically protect you from issues. It
is currently the best choice with the second best being the various
sandy/ivybridge laptops that run coreboot with open cpu/ram init and a
nerfed ME via mecleaner (disabling ME is impossible).

I have gotten like 10+ people to buy them so there is a nice little
community of people to help you with the process including myself if you
run in to any issues.

The main issue that people have is forgetting to properly enable
microcode updates which is required on almost every x86 device.

Installing coreboot isn't that difficult and someone with the aptitude
to use linux can surely pull it off you just need a screwdriver, a USB
CH341A flasher and a SOIC-8 tester clip so like $20 of stuff to do it.

In terms of workstation hardware for qubes there are many more choices
than laptops though and one can really have 100% such as
KGPE-D16/KCMA-D8 etc libreboot/openbmc compatible boards and of course
for non-qubes virt with kvm-qemu there is OpenPOWER.

awokd: Let us not use intel's marketing terms - Qubes requires IOMMU >:D

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/08c89301-42cd-825e-7e37-4bddc042d7c9%40gmx.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Thinkpad T400s RYF

2018-11-13 Thread qubes-fan
Outch, bad news :-( Basically I have only two options than: run reasonably 
secure QubesOS on a flawed-by-design-HW, or use RYF HW with not so secure OS. I 
am not maximalist, but you know, one doesn't go on boat that has holes in it, 
even he has nicely and safely packed cookies on board.

Or is there any other RYF laptop which could run QubesOS? Sad days, these days.


Nov 10, 2018, 4:43 PM by qubes-users@googlegroups.com:

> qubes-...@tutanota.com > :
>
>> Hi, I am thinking about getting the RYF T400s for Qubes 4. Is there anyone 
>> here who is running the T400s successfully with Qubes 4? If yes, how is the 
>> install/setup?
>>
>> https://tehnoetic.com/tet-t400s >>  <>> 
>> https://tehnoetic.com/tet-t400s >> >
>>
> It's a respectable piece of hardware, but I think it is too old to support 
> the hardware virtualization (VT-d) Qubes 4.0 requires.
>
> -- 
> You received this message because you are subscribed to the Google Groups 
> "qubes-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to > qubes-users+unsubscr...@googlegroups.com 
> > .
> To post to this group, send email to > qubes-users@googlegroups.com 
> > .
> To view this discussion on the web visit > 
> https://groups.google.com/d/msgid/qubes-users/8d3d3601-b64e-77c5-3740-f89e41321...@danwin1210.me
>  
> >
>  .
> For more options, visit > https://groups.google.com/d/optout 
> > .
>

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/LRBemDI--3-1%40tutanota.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Thinkpad T400s RYF

2018-11-10 Thread 'awokd' via qubes-users

qubes-...@tutanota.com:

Hi, I am thinking about getting the RYF T400s for Qubes 4. Is there anyone here 
who is running the T400s successfully with Qubes 4? If yes, how is the 
install/setup?

https://tehnoetic.com/tet-t400s 

It's a respectable piece of hardware, but I think it is too old to 
support the hardware virtualization (VT-d) Qubes 4.0 requires.


--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/8d3d3601-b64e-77c5-3740-f89e41321b37%40danwin1210.me.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Thinkpad T400s RYF

2018-11-10 Thread qubes-fan
Hi, I am thinking about getting the RYF T400s for Qubes 4. Is there anyone here 
who is running the T400s successfully with Qubes 4? If yes, how is the 
install/setup?

https://tehnoetic.com/tet-t400s 

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/LQxy5dy--3-1%40tutanota.com.
For more options, visit https://groups.google.com/d/optout.