#LibreBoot

Leah Rowe is not a Rowebotlibreleah@mas.to
2025-05-07

Help needed on #libreboot IRC. If you have a *ThinkPad T480*, see:
libreboot.org/docs/build/

Build latest lbmk.git with it BUT BEFORE YOU BUILD, make this config change:

./mk -m coreboot t480_vfsp_16mb

Debug -> Compile debug code in Ada sources

Build:

./mk -b coreboot t480_vfsp_16mb

Flash, and boot with linux option: iomem=relaxed

Now, in lbmk:

make -C src/coreboot/default/util/cbmem

as root:

src/coreboot/default/util/cbmem/cbmem -1 1>cbmem.log 2>cbmem.err.log

give nic-Pi the .log files

Instead of infecting the operating system, bootkits embed into the firmware that controls how the system boots. Once installed, they load before the OS, making them nearly invisible to traditional antivirus tools.

Discovered in the wild as early as 2018, bootkits like LoJax, MosaicRegressor, and CosmicStrand revealed that threat actors, some at the nation state level, were exploiting the Unified Extensible Firmware Interface to gain long term and difficult to remove persistence. Even wiping your hard drive will not help if the firmware is already compromised.

Tools like CHIPSEC and firmware flashing utilities have been developed to detect or cleanse these infections, but prevention often comes down to using secure boot, firmware write protection, and ideally open source firmware projects like coreboot or libreboot that give you back control.

#UEFI #FirmwareHacking #Persistence #CyberSecurity #Coreboot #Libreboot

2025-05-05

🛡️ Libreboot 25.04 Open-Source Boot Firmware Released

"Libreboot is a free and open-source BIOS/UEFI firmware based on Coreboot, designed to replace proprietary ones on specific Intel/AMD x86 and ARM-based motherboards. However, it runs only on select older laptops and desktops due to limitations in supporting modern firmware"

linuxiac.com/libreboot-25-04-o

#libreboot #opensource

freespirit利努克斯 :debian:freespiritlinux@mast.linuxat.de
2025-05-01

Die Open Source Boot Firmware Libreboot 25.04 wurde veröffentlicht!

Was ist Libreboot!

Libreboot ist eine Open-Source-Boot-Firmware, die als Alternative zu proprietären BIOS- oder UEFI-Firmwarelösungen entwickelt wurde. Sie basiert auf der Coreboot-Plattform und zielt darauf ab, eine freie und quelloffene Firmware bereitzustellen, die die Sicherheit und Privatsphäre der Benutzer verbessert. Libreboot unterstützt eine Vielzahl von Hardware und ermöglicht es Benutzern, ihre Systeme ohne proprietäre Software zu starten. Es ist besonders bei Nutzern beliebt, die Wert auf Freiheit, Transparenz und Kontrolle über ihre Computer legen.

libreboot.org/news/libreboot25

#Libreboot #Firmware #OpenSource #Foss #Freiheit #KeinMicrosoft

Libreboot 25.04 “Corny Calamity” released!

lemmy.world/post/28939996

2025-04-19
@lopta@mastodon.social

HELLO from my fifteen year old (shipped 2009-12-23) #Thinkpad X200t running #LibreBoot and #OpenBSD! ;)

Come on in, the technocrochety waters are fine! XD

BIOS level hacking has always been one of the stealthiest and most dangerous forms of attack. Operating beneath the OS, malware embedded in firmware can survive drive wipes and reinstalls. While rare, these attacks are very real. From state actors using BIOS implants for espionage to researchers demonstrating how firmware can be weaponized, this layer is often ignored until it is too late. Projects like Libreboot and Coreboot aim to replace proprietary firmware with open alternatives, giving users more control and reducing the risk of hidden vulnerabilities.

#FirmwareSecurity #BIOSHacking #Coreboot #Libreboot #CyberSecurity #LowLevelThreats #OpenSourceSecurity

Niels Roeterttuxlife
2025-04-07

Now a couple of weeks after buying an Thinkpad T480 to install on, I also bought a Dell OptiPlex 3050 Micro and did the same thing.

noordinaryspiderNoor@ni.hil.ist
2025-04-01

Tweaking my feed a bit to reflect hobbies as well as deeper dives into the purpose of my pod.

Welcome, new friends; old friends, call me out if tmi/shitposting doesn't improve.

Other #mentalhealthmatters include less screen time and more of that being #gnu #linux #freeasinfreedom time.

#grapheneos and #pinephone should help; still grieving #HyperbolaGNULinuxLibre and using #libreboot on new-to-me tablet and laptop.

Niels Roeterttuxlife
2025-03-28

Finally al the needed components arrived and I was able to replace the BIOS off my Thinkpad T480 which I recently bought, with With the documentation and a couple of tutorials online, it was pretty painless to do. Booting the existing Linux distribution afterwards was easy.

2025-03-07
Leah Rowe is not a Rowebotlibreleah@mas.to
2025-03-06

@tlaurion @mkukri tl;dr - we already discussed yoru concerns in #libreboot earlier. As Mate said, the upstreaming will be done at a later date when he feels like it. We're not in any rush . You just have to wait.

By the way: there's also the S model. T480s. your initial patch for Heads seemed to only focus on T480, but there's also T480s. so that ifdef should also handle T480s.

Perhaps a better way is this:

Define HAVE_H8S_EC or something, on the other thinkpads. Because T480 doesn't have it.

Niels Roeterttuxlife
2025-03-04

Bought a used Lenovo Thinkpad T480 yesterday, pretty good specs too, i7-8650U processor, 16GB RAM (1 stick, nice) and 512GB NVMe drive. It's one of the most modern machines that will allow the installation of or which is why I went with it, that's the next step.

2025-03-03

If Elmo #Musk is the world's most hated billionaire than Oracle's #LarryEllison comes in second, as far as I am aware.

#Virtualbox for Linux is one of the biggest P.O.S. programs for Debian Linux. I have a T480 laptop with 1080p resolution. It is a pretty fast machine and everything is set up correctly. I consider myself an expert in Linux GUI on Windows 11 VM's -- kind of a unique area and so what if it is? Linux VM's running on Linux OSes shouldn't be much different, right?

My first hint that the latest iteration of Virtualbox is messed up when installing this on Linux is that a single MOK message came up when running "sudo /sbin/virtualbox" yet there wasn't anything post-install that indicated that I needed to go through the MOK-based steps of registering and then entering in MOK's crypto key password during the host system's boot. I use #Libreboot so that could have been why? Probably not. This is the first #Linux laptop I've owned that uses something besides GRUB. I think Virtualbox's Linux developers forgot to do something regarding MOK.

The last nail in the coffin was Virtualbox's Guest Additions subprogram messing the GUI up after I was able to compile or integrate graphics support directly into the Linux VM's kernel. #NVIDIA started the whole "reversion" or going backwards in time argument over making their video drivers closed and proprietary. The Open Source people really dislike Jensen Huang for this. So, from all the years of recriminations concerning this big fight between the Open Source people who won't take a position and NVIDIA itself; who has a ton of money and a lot more time to waste -- Guest Additions on Virtualbox is a minefield of crap.

When I ran this program it started slowly shrinking my Virtualbox GUI incrementally. I think I need to recalibrate MOK so my system "sees" that Virtualbox's video driver is working properly. I believe Virtualbox's display settings through Debian GNU/Linux is limited to VMSVGA, only. All the other options will not engage, including 3D acceleration.

This is yet another "FU" to the world of Open Source, likely caused in part by others who will not fully and properly maintain some open standard in video drivers. I'm pretty sure I've tried every setting.

PS -- I'm going to check my #MOK configuration again. I don't think something worked the first time like it was supposed to? All the other programs I've used with MOK had something built into said program to run MOK after the fact so when you reboot your system you will then have to take the next step with MOK security. And of course, Oracle's Virtualbox apparently left that one step out because THEY SUCK!

AI's description of MOK setup for Virtualbox on Debian GNU/Linux.
2025-02-27

#Chipflasher : Version v2.1.3 released!

When it comes to #flash a #coreboot or #libreboot #laptop, we are now using #Zerocat’s free-design chip flasher as part of a quite clean & free #toolchain.

zerocat.org

Tim Riemannoctoate
2025-02-26

Bin mal wieder an überlegen, ob ich auf mein altes drauf packe. Warum? Weil's geht... wäre auch mal wieder ein wenig interessante Bastelei. Muss mal schauen, ob ich das wirklich mal mache, schließlich muss man dafür das ganze Notebook zerlegen, um an das BIOS ran zu kommen.

Eugene :emacs: :freebsd:evgandr@mas.to
2025-02-23

@rl_dane One disadvantage is the sleep — while my laptop perfectly sleeps and wake-ups even with #FreeBSD 11 — after switching from proprietary BIOS to #Libreboot this became unreliable.

Looks like there is a some bug in Libreboot causes CPU overheating after wake-up and then FreeBSD shuts down via #ACPI

I thought about disabling ACPI thermal guards before sleep. But it is VERY dangerous and I don't think that I'll find spare parts for my laptop in Russia now, for decent price :dragngrimace:

Leah Rowe is not a Rowebotlibreleah@mas.to
2025-02-13

Someone on #libreboot IRC said this today, when trying to describe a problem:

"it's the equivalent of a parakeet explaining nuclear fusion"

To which I said:

<leah> i personally would pay good money for a parakeet to teach me quantum physics

and the individual said to me:

"I'm  told they don't know squawk"

To which my final response was:
<leah> they do know squark

en.wikipedia.org/wiki/Sfermion

#squark !

Nemo_bis 🌈nemobis@mamot.fr
2025-02-08

@edsu Here you go.

The real reason is that impulse buying this little cutie of a #Libreboot 9020 SFF forces me to find some use for it.

libreboot 9020 sff with an ethernet bundleethernet cable going behind a bookshelf and almost hugging a Doomsday machine

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst