Hi Holger, if this point was to me :), sorry for "hijacking" the thread. The 
flame about Purism laptops here got a bit hot with RYF-puristic guys last time, 
and the questions (one can work with), were mostly unanswered. But they were 
basically right. 

Just to remind you, I had a conversation directly with the Todd Weaver about, 
if I remember properly, 2 weeks before they announced the ME cleanup. He told 
me in the conversation that they will completely remove the ME ( 2 weeks before 
the announcement), and they actually didn't. I am not blaming them, maybe he 
was just misinformed. I am just a semi-tech, and as many others I am not able 
to check stuff in depth, cause my extensive specialization is elsewhere. I am 
depending in Tech-Threat-Modeling on ppl like you or Thierry or Joanna, same 
way as you are depending on psychology specialists on psychology part of your 
Threat  Modeling (right)?

The implications of the claim "ME is completely removed" from Purism, can be 
extensive If I (or anyone else) advice to an organization (lets say a large, 
influential one), as a trusted advisor, the Purism laptops with claim: "ME is 
completely removed and your attack map is shrinked to this or that" and it is 
not.  It can kill the relation and even worse, put the organization in risk by 
not considering the threat in their OpSec. This is THE SHAME.

I can't help myself but, after that "mistake" from Purism I must include this 
to my Trust Model as a handicap for them. They should just make this clear 
somehow.

Thierry finally cleared this up somehow (at least for me), and put some light 
for decision making. This is actually something I can work with. 

Have a nice day :)


Nov 14, 2018, 10:30 PM by hol...@layer-acht.org:

> On Sat, Nov 10, 2018 at 09:24:40AM -0800, Kyle Rankin wrote:
>
>> It's a shame this thread got hijacked by people...
>>
> [...discussing other stuff...]
>
>> Could someone who is responsible for the HCL please update it with the data
>> I've provided in this thread? This would update the HCL with a version of
>> the Librem 13v2 that provides a TPM for people who are considering running
>> Qubes 4.0 with AEM.
>>
>
> has this (updating the HCL for Librem 13v2) happend now?
>
>
> -- 
> cheers,
>  Holger
>
> -------------------------------------------------------------------------------
>  holger@(debian|reproducible-builds|layer-acht).org
>  PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A AA1C
>
> -- 
> You received this message because you are subscribed to the Google Groups 
> "qubes-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to > qubes-users+unsubscr...@googlegroups.com 
> <mailto:qubes-users+unsubscr...@googlegroups.com>> .
> To post to this group, send email to > qubes-users@googlegroups.com 
> <mailto:qubes-users@googlegroups.com>> .
> To view this discussion on the web visit > 
> https://groups.google.com/d/msgid/qubes-users/20181114213042.y4w4qdaogapxq...@layer-acht.org
>  
> <https://groups.google.com/d/msgid/qubes-users/20181114213042.y4w4qdaogapxqvw2%40layer-acht.org>>
>  .
> For more options, visit > https://groups.google.com/d/optout 
> <https://groups.google.com/d/optout>> .
>

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/LRLc0ca--3-1%40tutanota.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to