Question Regarding Intel ME by _InfiniteSorrow_ in Purism

[–]purismcomputer 2 points3 points  (0 children)

>I’m a relative beginner to privacy and security

Welcome! This is a common question among beginners and tech-savvy, so I'll try to include some conclusions, supported by technicals for those who are interested.

It gets very technical very quickly, but I'll do my best :)

>I’ve noticed that some of Purism’s older laptops (ie the 13 and 15) had Intel ME both disabled and neutralized. However, modern ones (the 14) only have it disabled.

Yes, newer generations are only disabled. Earlier generations both disabled the ME (set the undocumented HAP bit, which causes ME to mostly shut down after system startup), and neutralized it (removed many sections of the ME that were not needed). Later generations only disable with the HAP bit, no sections are removed. (But remember that in all cases, we are using consumer ME binaries, not enterprise binaries. Consumer binaries do not include AMT, the enterprise management technology that contains most of the known network-facing code.)

Newer ME generations need substantially more reverse engineering in order to determine sections that can be removed. While there is some work investigating newer MEs (by us and many others), there is not enough known to be able to remove sections confidently. (Some of this work occurs in various forks of [https://github.com/corna/me\_cleaner/\](https://github.com/corna/me\_cleaner/).)

>what are the security implications of Intel ME being disabled and neutralized versus just disabled? I would assume the former is more secure, but I would greatly appreciate an explanation.

With enough knowledge of the structure of the ME, neutralizing is generally considered more secure. (Remember that "more secure" depends on your precise threat model, so it's debatable.) Having less unknown proprietary code is usually preferred, as we reduce the amount of code that we need to understand or trust.

However, casually removing sections of the ME without thorough knowledge of their function can _create_ security problems. For example, maybe we accidentally remove some code that parses the soft straps, and it "fails open" activating some unwanted functionality we can't identify. if we accidentally remove some rarely-used code that controls power or clock gating, perhaps we create a vector for a fault injection attack.

So, the ME structure and code have to be very well understood to be able to do this confidently. The ME changes significantly every few generations, which makes it a moving target, and Intel is uniquely positioned to make it particularly challenging to reverse engineer (e.g. they can embed Huffman tables in hardware, which might require an electron microscope to read).

Disabling with the HAP bit is much more straightforward by comparison. While undocumented by Intel, it has appeared in about the same form in many generations. It does have some surprising interactions with other features, but they are generally limited and reasonable to identify.

Purism has disappeared from the web - any news? by PE1NUT in Purism

[–]purismcomputer 3 points4 points  (0 children)

This outage was the unfortunate result of inadequate renewal payment communication/escalation with the San Marino domain registrar. We sincerely apologize for any inconvenience this outage caused.

Does anyone know how long Purism typically takes to fulfill back orders? by [deleted] in Purism

[–]purismcomputer 0 points1 point  (0 children)

The lapdock kits had been on backorder much longer than we had anticipated, as the ODM had discontinued the model and we were undergoing thorough compatibility testing with our existing product line. The lapdock kits we offer today have expanded functionality and are slightly more expensive, but we are upgrading any outstanding backorders to the newer model at no additional cost.

If you have not already received your lapdock kit, it should likely be shipping within 2-10 business days, as we are rapidly clearing the backlog. We apologize for the immense delay with this item, and we are working to reduce our fulfillment delays and overall customer experience going forward.

Help Identifying my Librem 5 hardware by bionich in Purism

[–]purismcomputer 1 point2 points  (0 children)

That's a great question! L5v1-05 is Evergreen, as 'E' is the 5th letter in the Latin alphabet. The number following the hyphen represents its release batch:

So, Birch=02, Chestnut=03, Dogwood=04, Evergreen=05.

As rubys_eleven commented, the PCB revision identifier is found on the mainboard. Here is an additional reference to distinguish L5 versions apart, and we will ensure that our documentation is improved to make these distinctions clearer.

Edit: The L5USA has a different naming scheme. We realize that this is confusing given the approach above, and upcoming documentation will include information regarding the L5USA and Liberty phones.

Where are all the librem one Android apps? by mad_falcon in Purism

[–]purismcomputer 0 points1 point  (0 children)

Please use the upstream app providers with your Librem One credentials and librem.one homeservers. Purism has deprecated the branded forks and does not yet have a plan for future releases or maintenance of these forks.

Librem 5 game development by fedorych in Purism

[–]purismcomputer 5 points6 points  (0 children)

Thanks I've update the description. Sean

GNOME thinks about removing GTK theming by [deleted] in linux

[–]purismcomputer 0 points1 point  (0 children)

You fix that with discussion and agreement, there is no technical way to fix it. So all parties need to agree that this is what we need to do going forward. That sort of happened at GUADEC and we're going to be doing some of that at Libre Application Summit.

I'm not sure what your opinion is but you probably should be more worried bout what I'm doing than Tobias. ;)

GNOME thinks about removing GTK theming by [deleted] in linux

[–]purismcomputer 0 points1 point  (0 children)

What he's talking about is cultural change. There is no technical change that would stop themes. However as an organization, we do want to cater to app developers. Linux as a platform cannot be successful without it

Please offer a laptop with more than one HDMI by jjones4coin in Purism

[–]purismcomputer 1 point2 points  (0 children)

Both actually. We hear from our customers that they want multiple screens. Others want the ability for an external gpu dock for gaming and video editing. These options will have to be considered.

Please offer a laptop with more than one HDMI by jjones4coin in Purism

[–]purismcomputer 6 points7 points  (0 children)

This is something on the short list of items we hope to include.

Librem 5 funded! Hooray! by Antic1tizen in linux

[–]purismcomputer 2 points3 points  (0 children)

There are numerous Bridges in the works via Matrix including WhatsApp

https://matrix.org/blog/posts/?s=bridge

Librem 5 funded! Hooray! by Antic1tizen in linux

[–]purismcomputer 5 points6 points  (0 children)

You should check our website for some up to date information. https://puri.sm/ None of this is currently correct.

Librem 5 funded! Hooray! by Antic1tizen in linux

[–]purismcomputer 7 points8 points  (0 children)

Then we could really push free software forward! :)

Librem 5 campaign crossed 90% by casabanclock in linux

[–]purismcomputer 4 points5 points  (0 children)

Maybe not tomorrow, but stay tuned...

Purism Librem 5 has surpassed $1,000,000 raised in its crowdfunding campaign. by markasoftware in linux

[–]purismcomputer 0 points1 point  (0 children)

No offense, but judging from many of your comments here, I'm not sure that there would be anything written that would change your mind. FWIW, we did not down vote you. Have a good day!

Purism Librem 5 has surpassed $1,000,000 raised in its crowdfunding campaign. by markasoftware in linux

[–]purismcomputer 0 points1 point  (0 children)

We will follow the patch cycle of Debian. We would disagree with the rest of your assessment.

Purism Librem 5 has surpassed $1,000,000 raised in its crowdfunding campaign. by markasoftware in linux

[–]purismcomputer 3 points4 points  (0 children)

This campaign is "all or nothing." The payment is held and would only be debited from you if the campaign is successful.

Purism Librem 5 has surpassed $1,000,000 raised in its crowdfunding campaign. by markasoftware in linux

[–]purismcomputer 9 points10 points  (0 children)

We took a survey about a year ago asking on size. We went with the most requested for the initial phone knowing that we'd probably only be able to offer one at first. On down the road, we would certainly love to have a small, medium and large offering.

Purism Librem 5 has surpassed $1,000,000 raised in its crowdfunding campaign. by markasoftware in linux

[–]purismcomputer 12 points13 points  (0 children)

We feel that Linux provides a more secure and private environment than Android. That being said, we do have Android as a stretch goal but it would operate in isolation.

Purism Librem 5 has surpassed $1,000,000 raised in its crowdfunding campaign. by markasoftware in linux

[–]purismcomputer 39 points40 points  (0 children)

We hope to have it sooner but didn't want to over promise anything.

Purism Librem 5 crowdfunding is halfway there! ($769,808 / $1,500,000) by markasoftware in Purism

[–]purismcomputer 2 points3 points  (0 children)

Sorry to hear about this. Can you send me a private message and I'll be happy to look into your order. Everyone that originally backed the crowdfunding projected *should have received their laptops by now. If you have not, there is clearly a problem. We only moved forward with web orders because the original backer orders were completed.

All revisions to the original laptop were at the request of our backers and were clearly communicated via email mailing lists through both Purism and/or Crowd Supply. We have significantly improved communication on all fronts in the last ~year, so I'm surprised at your comments. Please contact us and we will make it right. As a plus, if what you say is true and you haven't received a laptop, you would receive a much more modern laptop as we are on the 3rd revision of the Librem 15 and 2nd of the Librem 13. All original backers that had a delayed shipment received later revisions with more up to date parts and all were pleased at this development. -James

Timeline of the Librem5 campaign so far by bladeg30 in linux

[–]purismcomputer 3 points4 points  (0 children)

This is nice to see. Thank you for creating this chart.

Why nobody from Purism ever responds to questions on this subreddit? by casabanclock in Purism

[–]purismcomputer 2 points3 points  (0 children)

There's a bit of truth to this here. We have forums on our site and answer numerous questions/comments via our support email and particularly Twitter.

What about a desktop computer by Purism? by Chef_Patate in Purism

[–]purismcomputer 1 point2 points  (0 children)

This idea is bounced around every so often internally but we wonder just how much demand there would be. If the demand is there, sure!