[coreboot] Plans for upcoming Broadwell Thinkpads
Zaolin
zaolin at das-labor.org
Fri Feb 6 21:42:30 CET 2015
Hi,
let's say goodbye to all Intel notebooks produced by OEM's which are not
Google ( Chromebooks ). Maybe the haswell/broadwell notebooks of Lenovo
without U/Y processor can be used ( Thinkpad tXX xXX ). It depends if
they are supporting Intel Boot Guard on the southbridge and if they are
locked down...
Regards Zaolin
> On 02/06/2015 06:29 AM, Zaolin wrote:
> > Hi,
> >
> > new thinkpad's can't be used anymore for coreboot. Especially the U and
> > Y Intel CPU Series.
> > They come with Intel Boot Guard and you are won't be able to boot
> > anything which is unsigned and
> > not approved by OEM. This means the OEM are fusing SHA256 public key
> > hashes into the southbridge.
> >
> > For more details take a look at Intel Boot Guard architecture. It could
> > be also confirmed by Secunet AG and Google.
> >
> > Regards Zaolin
>
> That's scary to say the least. No more Thinkpads for us...
>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: This is a digitally signed message part
URL: <http://www.coreboot.org/pipermail/coreboot/attachments/20150206/b6687ddf/attachment.asc>
More information about the coreboot
mailing list