I’ve been trying to put together what I believe to be the best laptop for the average person interested in security and QubesOS. The laptop would need the following:
- Ivybridge Generation CPU as a maximum
This is so that Intel ME can be neutered/reduced with me_cleaner (I believe HAP bit is not enough - so no purism, and no modern gen CPUs) - Supports heads!
I see this as an absolute must since there is no real AEM/secure boot on qubes, leaving your device significantly more vulnerable to those with the possibility of physical access. - Reasonable specs
This is a lot more subjective, but some of the devices recommended here are just simply too slow for modern websites and applications. You will have trouble even running 1080p video. It would be a nightmare to get any sort of work done.
After going through these requirements, the following devices stand out to me:
- Thinkpad T430
- Thinkpad W530
- Thinkpad X230
I’ve purchased all three of these, and out of these devices, I’ve stopped using two.
X230 with an i7-3520M (16GB Ram Max) - I made sure to get one with the best possible CPU since it is not replacable, however the CPU is subjectively too slow for daily usage within QubesOS. Even websites struggle to load. I do not recommend this.
W530 with an i7-3840QM (32GB Ram Max) - The performance on this device was a lot more usable and I can actually recommend this, it worked great. However, it came with one big problem, each model of the W530 comes with an Nvidia Quadro card which is wired to the display output port. This means that heads and coreboot have lots of trouble using this. Through extensive testing/flashing of both heads and coreboot I found this to be a huge nightmare and was very finicky. If you do go this route, you will probably not be able to use an external monitor. However, it works.
This leaves me with the final device I can recommend - the T430. It is very similar to the W530 and also has a non-soldered swappable CPU, leading me to use a i7-3940XM which grants great performance. Even though it is limited to 16GB of ram instead of the W530’s 32GB, I have found its a lot more reliable. This is due to one fact alone; the laptop can come in a model without a dedicated GPU, leaving the Intel GPU for display out and allowing usage of an external monitor, and also being less of a large brick with a useless extra GPU inside.
These are my findings as I’ve researched and dealt with this subject a little more than I probably should have. If anybody has anything to critique or add that I have overlooked I would love for it to be brought to my attention.