[coreboot] Re: Question how to write protect flash

2019-07-14 Thread werner....@siemens.com
IIRC X220 uses Sandy Bridge. I think there is a flag somewhere in the descriptor where you can lock down your BIOS-region as read-only for the x86 host. I never have tried it but in theory this should lead to errors on every write attempt to the BIOS region therefore disabling write access to th

[coreboot] Re: Question how to write protect flash

2019-07-14 Thread Nico Huber
Hi, for the X220, there should be related options in the "Chipset" menu of the coreboot configuration: "Lock down chipset in coreboot" "Flash locking during chipset lockdown" On 14.07.19 23:21, Public Email Account via coreboot wrote: > It seems that flashrom is able to flash the bios ch

[coreboot] Re: Question how to write protect flash

2019-07-14 Thread Public Email Account via coreboot
typo "this is now true." This is NOT true. Sent with [ProtonMail](https://protonmail.com) Secure Email. ‐‐‐ Original Message ‐‐‐ On Sunday, July 14, 2019 9:21 PM, Public Email Account wrote: > It seems that flashrom is able to flash the bios chip internally. This is > frightening. Thi

[coreboot] Question how to write protect flash

2019-07-14 Thread Public Email Account via coreboot
It seems that flashrom is able to flash the bios chip internally. This is frightening. This means that malware or anything that gets sudo rights or anyone who gets physical access to computer is able to rewrite the flash. Dont say "if there is physical access to your computer, its game over" thi

[coreboot] KVM /SVM not working on KGPE-d16

2019-07-14 Thread Kinky Nekoboi
Coreboot build today. Opteron 6300. Latestest Microcode. Debian Buster (10) dont send me emails that state i should install any memelinux distro Linux 4.9 (AS 4.19 is still buggy and does not boot :(( quite frustrated with this board now ... starved 2 month to buy a fucking libre server system)