[tor-talk] [OT] Secure laptop advice

Jonathan Marquardt mail at parckwart.de
Sun Mar 24 09:25:05 UTC 2019


I am a big fan of Lenovo (and formerly IBM) ThinkPads. You can buy them online 
refurbished extremely cheap.

I personally have a Lenovo X200 with Libreboot installed. Having a FOSS and 
controllable BIOS replacement can really be quite a security benefit.

For example, with Libreboot it's possible to have true full-disk encryption. 
Normal so called "full-disk encryption" has the crucial weakness that the 
/boot partition is unencrypted, which allows for some attack vectors. 
Libreboot however, as a BIOS replacement, can actually decrypt the /boot 
partition itself. You can also implement some sort of Secure Boot (but under 
your control, not Microsoft's) with PGP verfication of the kernel image file 
before booting it. It's really quite neat.

And you're safe from manufacturer backdoors or scary UEFI systems.
-- 
OpenPGP Key: 47BC7DE83D462E8BED18AA861224DBD299A4F5F3
             https://www.parckwart.de/pgp_key
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.torproject.org/pipermail/tor-talk/attachments/20190324/f289bf36/attachment.sig>


More information about the tor-talk mailing list