Zerocat’s Coreboot Machines
Note the following machines of course aren't true free-design devices! Instead, these are refurbished and modified machines that carry a decent Coreboot 4.7 Firmware and as few proprietary code as possible in their BIOS chips. Regarding Intel’s integrated proprietary Manageability Engine (IME) which pops up severe privacy issues, mind these important categories:
- Machine free of IME hardware on board (ZC-T60, ZC-X60/X60s)
- Machine compromised with integrated IME hardware on board...
- ...and IME firmware untouched (ZC-T430)
- ...but IME firmware stripped down (ZC-X230)
- ...but IME firmware deleted (ZC-X200, ZC-T400)
Please read The Intel Management Engine: an attack on computer users' freedom by Denis GNUtoo Carikli and Molly de Blanc in order to get precise details.
This machine is very common when it comes to delete proprietary blobs in the BIOS chip. It runs blobfree, however the Intel Manageability Engine (IME) architecture still is functioning and we don't know exactly about its hardcoded capabilities.
ZC-X200 | Dual Core | 8GB RAM | 8MB Flash, IME Firmware deleted
Same as ZC-X200, but socketed CPU, integrated disk slot, touch-pad, more ports, stereo speakers, etc...
ZC-T400 | Dual Core in Socket | 8GB RAM | 8MB Flash, IME Firmware deleted
This is an old laptop that still is very interesting for it offers modern 64bit support while lacking the annoying IME architecture:
[...] many Intel computers manufactured in 2006 have the ancestor of the Management Engine which is disabled from the start, such as the Lenovo Thinkpads X60, X60s, X60 Tablet and T60, and many more. --- Denis GNUtoo Carikli Contributions
If you have a strong stance on trust rather than performance, use this machine.
ZC-T60 | Dual Core in Socket | 3GB RAM | 2MB Flash | Free of IME!
Very performant laptop with dual or quad core CPU; IME firmware is not yet deleted but stripped down with ME_Cleaner. Note the heads project may run on this type of machine to gain improved security, but we haven't tried it, yet.
ZC-X230 | Dual/Quad Core | 16GB RAM | 12MB Flash, IME Firmware stripped down
Zerocat’s Coreboot Configuration has been adjusted to provide the GRUB2.02 Bootloader with full authentication support, chainloading SeaBIOS rel-1.11.2 as a secondary payload to allow for booting the Qubes R4.0 OS Installer from CD or USB-Stick.
ZC-X230 with Qubes R4.0 OS Installer
Laptops gain New Qualities
In short summary, these machines gain ethical qualities, as they...
- have been modified by using Zerocat’s free-design chipflasher
- run with coreboot firmware (free software)
- run without (with a reduced set of) binary blobs
- run without IME or with IME’s firmware deleted/cleaned
...are accompanied with free documentation, you can create them on your own!
Our notes on how we configure and tweak the coreboot BIOS images are publically available. You may review or reproduce our approach and get convinced about its integrity.
Since we are developing a true free-design chipflasher, we continue to flash these machines for testing purposes and offer our flash services as well as ready made laptops for purchase. If no related sales page is available in our shop, please feel free to request one.
More Devices that we have Experience with
- Lenovo ThinkPad T430
- Lenovo ThinkPad X220
- Lenovo ThinkPad X200s
- IBM/Lenovo ThinkPad X60/X60s --- 32bit
- ASRock E350M1 Mini ITX Systemboard
Devices that we look for for Testing
- Lenovo ThinkPad X200s
- Lenovo ThinkPad T400s
- Lenovo ThinkPad T500
- Lenovo ThinkPad T60
- Lenovo ThinkPad X60/X60s --- 64bit
Please provide your hardware for tests.
- Zerocat’s Coreboot Machines Documentation
- Git Repository:
- README.md text file
- Zerocat’s Online Shop