Hi!

> I checked out the x230 and you are right they are available and cheap. I
> would still be interested in finding some company/individual who I can
> trust to take care of the BIOS flashing for me as a service(I would think
> others would also want this service as well...). The problem is who?
>
I started Insurgo Technologies Libres/Open Technologies exactly for that! (
https://www.facebook.com/InsurgoTech/insights/?section=navPosts)

We actually reprogram A-Grade refurbished x230 with Heads firmware (
http://osresearch.net/), while neutralizing Intel ME (
https://github.com/osresearch/heads-wiki/blob/master/Clean-the-ME-firmware.md)
while being there.

I collaborate with Heads and QubesOS developers for a while now..
QubesOS can even be preinstalled with user's desired customizations (
https://github.com/SkypLabs/my-qubes-os-formula/issues) or shipped with
latest QubesOS ISO on external MicroSD support. Heads validates ISO
integrity with distribution's signing keys prior to boot them (Tails,
Fedora, QubesOS).

Heads, deployed with a Nitrokey Pro v2/LibremKey or by using internal TPM,
validates rom' integrity before booting from it. With the help of a
NitroKey/LibremKey (https://puri.sm/posts/introducing-the-librem-key/), the
boot configurations are signed with user's keys and verified and the
firmware integrity is attested at each reboot through HOTP (led flashing or
TPMTOTP on user's cell phone through Google Authenticator or compatible app.

The user receives the Nitrokey/LibremKey and his computer in distinct
shipping packages and reunites at first laptop boot to attest that the
firmware of the computer has not been tampered with in transit. (
https://puri.sm/posts/introducing-the-librem-key/).

The user, upon bootup integrity attestation, proceeds to the ownership of
his new laptop (TPM) and his LibremKey. The user is then invited to
reencrypt his SSD encrypted content with it's own chosen passphrase (
https://github.com/osresearch/heads/issues/463) and to choose a secondary
disk unlock passphrase, which will unlock encrypted disk content only if
the firmware has boot attested integrity.

Notes:

   - The user will be able to ask *Insurgo* interactive support in the near
   future. (https://github.com/SkypLabs/my-qubes-os-formula/issues/6).
- *Buying from Insurgo (ITL/IOT) funds directly my participation to those
   projects.*
   -
*Bulk discount are available upon request. Insurgo plans to transit into a
   working/buying cooperative in the near future. *



Prices are in Canadian Dollars (CDN)

   - x230 i5 240GB SSD 16GB Webcam and IPS: $620
   - Hardware reprogramming fee: +250$
      - Backlit Keyboard: 40$  (optional)
      - Webcam 10$  (optional)
   - Nitrokey/LibremKey: + 80$

The refurbisher offers a warranty plan on the value of the purchase:

   - 1 Month %5
   - 3 Months %10
   - 6 Months %15
   - 1 Year %25


Thierry Laurion:

   - GitHub: https://github.com/tlaurion/
   - LinkedIn: https://www.linkedin.com/in/thierry-laurion-40b4128/


Insurgo, Technologies Libres / Open Technologies:

   - email: insu...@riseup.net for more information.
      - GPG key:
      http://keys.gnupg.net/pks/lookup?op=get&search=0x79C78E6659DB658F
      - Follow this guide or it's platform equivalent:
      https://securityinabox.org/en/guide/thunderbird/mac/
      - Website: https://Insurgo.ca
   - Facebook: https://www.facebook.com/InsurgoTech/


On Sun, Nov 11, 2018 at 9:26 PM <22...@tutamail.com> wrote:

> Unman your posts have been extremely helpful to me and I can't thank you
> enough for the help(I am sure many others would agree).
>
> However I think your "..Pretty easy to maintain.." would be hell for me.
>
> Librem(and maybe the Majora line) have huge appeal for me as they take
> care of the BIOS flashing.
>
> I checked out the x230 and you are right they are available and cheap. I
> would still be interested in finding some company/individual who I can
> trust to take care of the BIOS flashing for me as a service(I would think
> others would also want this service as well...). The problem is who?
>
> Thanks...
>
> ("-boxy is the new black." Good one and couldn't agree more...very funny!)
>
> --
> You received this message because you are subscribed to the Google Groups
> "qubes-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to qubes-users+unsubscr...@googlegroups.com.
> To post to this group, send email to qubes-users@googlegroups.com.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/qubes-users/26f75d86-0349-4533-8f3a-66fe2e37c1b3%40googlegroups.com
> .
> For more options, visit https://groups.google.com/d/optout.
>


-- 
Thierry Laurion

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAAzJznzOWNrOFTyCNQt-vu5%2BUQXqhZFg-Loxm-oY2oiutORkDQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to