Qubes OS A reasonably secure operating system?

@Confused and @catacombs :

ASUS AM1I-A and ASUS A88XM-E

Much much appreciate @mike_banon 's work but do not these boards suffer the same probs as Asus KCMA-D8 and KGPE-D16?

Thank you for your kind words! :wink: A88XM-E & AM1I-A desktop boards + a G505S laptop - while being less powerful than i.e. KGPE-D16 - are based on a newer AMD platform (still without a PSP “backdoor”), and as result they enjoy a newer version of low-level AGESA library (provided by AMD long time ago and subsequently improved by the community) and a more refined coreboot BIOS source code

  • Based on my experience, you can throw any random RAM modules into these three “newer” platform’s AMD boards that I’ve improved a coreboot for (i.e. XMP / custom memory profiles support) - and expect them to work flawlessly , so just pick the fastest RAM within your reach (8GB 1866MHz CL9 9-9-9-24 sticks for desktops, 8GB 1600MHz CL9 9-9-9-24 sticks for a laptop) ; meanwhile, “older” AMD boards seem to be more picky regarding RAM - see my notes about HCL below
  • Although a bit outdated (need to update it soon) , I made a restore_agesa.sh script that brings a modern coreboot to these “newer” boards with a minimal sacrifice of some incompatible commits ; meanwhile, it’d require more efforts to pull off the same trick for the “older” boards - simply because they have been dropped from a coreboot master branch much earlier

However (while not sure about KCMA-D8) - I don’t want to discourage anyone from getting a KGPE-D16, especially since this week I finally ordered a pair of used KGPE-D16 boards & hardware parts for them :sunglasses: And - while being a bit late to a club of humble KGPE-D16 enthusiasts! - considering a lack of privacy respecting alternatives of the same security / firmware freedom level (aside of Talos II workstation which is a different “game”) - I’m very serious about this platform :star_struck: Plenty of earlier problems have been resolved by the opensource community members who have put a LOT of efforts into KGPE-D16:

  • benevolent work by Timothy Pearson (Raptor Engineering)
  • generous donations by Leah Rowe (Libreboot) and others
  • useful patches by Thierry Laurion (@Insurgo)
  • significant improvements by @pietrushnic 's 3mdeb company at Dasharo project
  • and many other good people (sorry if I forgot to mention anyone)

So, while you may choose the newer coreboot-supported AMD-no-PSP boards for their higher “user friendliness” - feel free to dive into KGPE-D16 if you need something more powerful, with a huge RAM for ramdisks and other things, and enjoy this enterprise server hardware (i.e. these top Opterons costed like ~$1k per CPU in the past) and software freedom at the same time - but please be prepared that:

  • With KGPE-D16 you must follow this RAM compatibility list and choose either HMT42GR7AFR4A-PB or M393B2G70QH0-YK0 model of 16 GB RAM based on your local availability (they are dirt cheap nowadays - i.e. 256GB Samsung 16x 16GB 2Rx4 PC3L-12800R DDR3 RAM M393B2G70QH0-YK0 | eBay , a full 256GB set of compatible RAM, $130 for 16 modules - but not all the sellers mention the server RAM’s full model at the product description, making the things more tricky) - and then hunt for 16 same modules in order to achieve 256 GB RAM on your platform, for ramdisk or other purposes; with the “wrong” modules you may hit 192 GB ceiling / encounter other problems and become disappointed

  • The availability of server parts like a spare KGPE-D16 board, top Opteron CPUs (either 6386 SE at 140W , or 6380 which is slightly slower but is more obtainable and less hot at 115W) to squeeze the max possible performance out of this platform, and most importantly a good enough cooler for G34 socket (unless you’re ready to DIY mod an incompatible one) - like those elusive Noctua’s ! - is expectedly lower, the overall price will be higher and you’ll have to hunt for these parts. Even finding a new modern workstation case with SSI EEB motherboard support out-of-the-box (although E-ATX cases can also be modded) and 5.25" slots (that can be used for many awesome things other than DVD/BluRay drives, i.e. see my ProTip: buy a 5.25" fan controller while you still can" post) alone was a daunting task - luckily I stumbled upon Phanteks Enthoo Pro (yes, the 1st version - since “Pro 2” doesn’t have my beloved 5.25") - there are Tempered Glass / Closed Panel editions…

If you’d like to discuss these coreboot-supported AMD platforms in a live chat format, we can do that during our upcoming vPub’s free-for-all section if you would like - see Opensource firm/hard-ware online party "vPub" - this Thursday! (20th March) post for its schedule and join links

3 Likes