linuxboot / heads

A minimal Linux that runs as a coreboot or LinuxBoot ROM payload to provide a secure, flexible boot environment for laptops, workstations and servers.
https://osresearch.net/
GNU General Public License v2.0
1.41k stars 185 forks source link

Other suggestions #438

Open PowerPress opened 6 years ago

PowerPress commented 6 years ago

Is there anything else that can done hardware wise then loading Heads on 230 and using Qubes 4.0+ OS? This technology is great just wandering if there is anything else out there that will compliment it or improve security posture?

Is the Lenovo Thinkpad 230 the best laptop for security features with Heads?

osresearch commented 6 years ago

There are some steps that are not part of the stock install that we should considering implementing or documenting better:

Most of these are addressing increasingly esoteric threats, so they may not apply to your use case.

osresearch commented 6 years ago

On the negative side, the x230 is lacking some number of features that would improve its security:

PowerPress commented 6 years ago

Is there another recommended model that will work with Heads and Qubes 4 and still be able to take advantage of these?

On Mon, Aug 13, 2018 at 6:19 AM, Trammell Hudson notifications@github.com wrote:

On the negative side, the x230 is lacking some number of features that would improve its security:

  • Tamper switches (like the X1 or T470)
  • Bootguard Measured Boot mode (like the Librem)
  • Open source EC (like chromebooks)

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub https://github.com/osresearch/heads/issues/438#issuecomment-412486044, or mute the thread https://github.com/notifications/unsubscribe-auth/AGB07yubf3M_Bu-j3cOCNh6tmITUdAPTks5uQWDVgaJpZM4V4Rne .