---------- Forwarded message --------- From: Brian Milliron via coreboot coreboot@coreboot.org Date: Fri, Apr 28, 2023 at 4:52 PM Subject: [coreboot] Re: How open is Google CR50? To: ron minnich rminnich@gmail.com CC: coreboot@coreboot.org coreboot@coreboot.org
Thanks. I'm not really looking to build my own custom hardware, just evaluate what's already out there. I was hoping someone here would know if this chip is fully open or not.
Hi Brian, I'm leading the h/w security (that includes cr50 firmware) team at ChromeOS and I had this message forwarded to me as I'm not on the coreboot mailing list. Not sure if there was more discussion since, but here are some top-level details re cr50/GSC openness. Let me know if you have further questions.
- Google security chip is not an open hardware, the datasheet for it is not generally available. And you won't be able to run arbitrary code on it - it accepts only firmware signed with Google keys. - The bootloader firmware stage for Google security chip is not open source. - cr50 is the name of the main firmware stage that runs on the chip. cr50 implements the applications required for ChromeOS. It is open source on chromium.org.
I also liked the suggestion earlier in the thread of looking at opentitan.org if you are interested in open hardware.
*From:* ron minnich rminnich@gmail.com *Sent:* Friday, April 28, 2023 5:28 PM *To:* Brian Milliron Brian.Milliron@foresite.com *Cc:* coreboot@coreboot.org coreboot@coreboot.org *Subject:* Re: [coreboot] How open is Google CR50?
if you want the open source part, you want to go with opentitan.org, I can put you in touch with folks if your company has interest.
On Fri, Apr 28, 2023 at 2:52 PM Brian Milliron via coreboot < coreboot@coreboot.org> wrote:
I'm trying to decide if the Google Titan Security chip CR50 is trustworthy or not. I see it has some open source, but I'm not certain if the whole thing is open source or if there are some binary blobs included. Does anyone here know?
coreboot mailing list -- coreboot@coreboot.org To unsubscribe send an email to coreboot-leave@coreboot.org
coreboot mailing list -- coreboot@coreboot.org To unsubscribe send an email to coreboot-leave@coreboot.org