[ltp] Can you trust your firmware?

linux-thinkpad@linux-thinkpad.org linux-thinkpad@linux-thinkpad.org
Mon, 18 Feb 2008 15:56:44 -0600 (CST)


On Mon, 18 Feb 2008, Marc Lagies wrote:
> I wonder about how much confidence I can have into my computer system if such 
> a crucial(?) component like the BIOS firmware is proprietary source code?
>
> Or is my concern unfounded?

Marc,

You concern is not unfounded, but there really isn't a lot one can do 
about it, except buy hardware that either already has open firmware or 
is documented well enough to run an open BIOS of some kind.

I have heard of open BIOS efforts, but I'm not up on what they are named 
or in what states they exist.

I would think ThinkPads starting with the T61 would be a bit of an easier 
target since they use the new EFI(?) instead of BIOS, so I know they can 
use MacOS more easily.

I have never heard of any BIOS doing anything suspicious. I suppose the 
best way to be sure of that other than auditing the source would be to 
monitor all your network traffic.

This list hasn't had much traffic on this topic, but I for one would be 
really interested in what you find out.

Chris