On 4/15/20 6:05 PM, Catacombs wrote:
I purchased a refurbished Lenovo X 230 Core I5, 4 GB RAM, and a spinning hard 
drive, Windows 7 Pro for $228.00.

I ordered 16 GB RAM for about a hundred dollars. I thought the RAM would be 
less expensive.

My first mistake was to raise the BIOS/EFI to 2.77.  Turns out Intel encrypts 
something to prevent one from rolling back the BIOS/EFI.

The option I had before was to run a jailbreak on the Lenovo that should allow 
me to neutralize the Intel Management Engines ability to get updates from 
Intel.  Intel also had a whitelist that limits which WiFi chip it will allow to 
be used.  I guess to make sure the Intel Management Engine can talk to the 
mothership.    That jailbreak does not one to take apart the laptop. The 
jailbreak is on github 1vyrain.  The site says do not attempt to use the 
jailbreak unless one has the allowed, correct, lower version of BIOS/EFI or it 
will brick it.  As I write this I see some folks who say (Lenovo Forum) they 
have -done something - to roll back BIOS/EFI to 2.6.  So they could use 
1vyrain.  Jailbreak 1vyrain actually accomplishes two of the big items I 
require. Prevent Intel from changing my X230 to something I do not want.  And 
allow me to use another WiFi chip.

The jailbreak doesn't even require hardware access. So no pi, Pomona etc.

However it cannot disable Intel ME if I recall correctly. Just check their site.

Flashing the Lenovo X230 BIOS/EFI w
ith an EEPROM is git hub Skulls.  Which requires I spend money. And the 
documentation for doing that is not obvious, and old.

I decided I should buy a PI to program the X230.  I started to buy one from 
Amazon  and cancelled that when I saw the voltage on the power supply was 2.5 
volts and someone said not use 3.3 Or less as the flash might not work 
correctly.  Someone suggested ADA Fruit for the Pi. But the more complete ones 
are not
In stock. I am waiting on Corona money to buy one so I wil keep looking.  I had 
a link once suggested by Insurgo. But it came from China, and took many weeks 
before the Corona started.

My first questions. I had thought while looking at the Skulls there would be an 
option for Core I5 versus Core I7. I haven’t seen it so far.  Does that matter?

For coreboot it doesn't matter which CPU you have.

For Qubes OS i7 quad core is usually a lot better than i5 dual core on these old platforms. The latter might make Qubes OS almost unusable.

However you'll have to make sure the CPU supports VT-d. There are some which don't - usually the gamer models. Check ark.intel for that.

Clearly states to remove the battery, but did not say the coin CMOS battery.  
In fact I have not found that little turkey.

I'd recommend to also remove that. Check the tons of youtube videos on X230 disassembly on where to find it. There's also a Lenovo hardware maintenance manual describing all steps.

I want to have enough in my bank account to afford a replacement MOBO if I 
brick this one and can’t unbrick it.

There's probably even youtube videos flashing the X230 out there.

And usually unbricking always works with hardware access to the firmware/BIOS chip.

Mostly the available documentation might have some flaw I am not experienced 
enough to catch.


One thing is obvious, while I my income may be to low to buy one, Insurgo 
products are not overpriced.  This project is a lot of trouble.  Parts. Tools. 
are not free.

True.

Anyone have recent experience with flashing Skulls onto Lenovo X230?

I didn't try skulls (it's just coreboot pre-compiled for the X230 if I recall correctly) as I don't like flashing some untrusted binaries from the Internet.

But I have some coreboot flashing experience (!= X230 though).

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/97fb4b49-a9c5-6c7a-d1d5-92c9a73bef8a%40hackingthe.net.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to