firmware-open
me_cleaner
Our great sponsors
firmware-open | me_cleaner | |
---|---|---|
111 | 97 | |
934 | 4,352 | |
0.9% | - | |
8.6 | 0.0 | |
11 days ago | over 1 year ago | |
C | Python | |
GNU General Public License v3.0 or later | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
firmware-open
-
[darp8] Anyone try this FW update 42bf7a6 (2023-09-08)?
This reminds me a lot of FW update a8dd6c2, since rolled back, which came out about 4 months ago and caused problems with darp8 (e.g. https://github.com/system76/firmware-open/issues/469, https://www.reddit.com/r/System76/comments/1692nd2/darter_pro_fails_to_resume_after_fw_a8dd6c2/, https://www.reddit.com/r/System76/comments/168oehz/new_coreboot_update/)
-
Is there a way to find the "sweet spot" for fans when running the custom firmware?
I suspect that my current settings are still "overkill", so I'm wondering if there's a nice way (in the absence of https://github.com/system76/firmware-open/pull/365 being merged!) to find out what the minimum speed is I can get away with without my laptop spontaneously combusting? :D
-
System76 support says my HDMI issue is normal and won't fix my warrantied laptop. Is this real?!!
There is an issue about this: https://github.com/system76/firmware-open/issues/407 They closed it (because there was an update), but yeah it's definitely not fixed. You can subscribe to this issue to see what's going on, but do not get your hopes high - they will rarely, if ever, update the issue.
-
Excessive fan noise when on any power mode except "Battery Life"
There isn't a way without flashing the firmware at least once, but there is this PR instead which exposes userspace fan controls, which might work with some of the fan control software in Linux.
-
BIOS has fake (default) serial number
Issue opened: https://github.com/system76/firmware-open/issues/432
- System76 laptops with Intel 10th-13th gen has now a Coreboot bios with management engine cleaner. Is there any other brand offering the same?
-
Any update on framework 16?
What Framework can't offer is Coreboot with Management Engine Cleaner and other great specs. System76 just announced a new fully open source bios for their intel 10th - 13 th gen models: https://github.com/system76/firmware-open/blob/77abfadf24c9a0c45ae042cd71d3ce7be26c846e/FEATURES.md
-
Flashing firmware on oryp10
Hi! I check the firmware-open repository from time to time and noticed that since the initial release a few potentially interesting things have been committed (e.g. Disable ME by default on everything but TGL-U or Support for NVIDIA Dynamic Boost ). Should I wait for the "official" update to show up in firmware-manager? These changes seem to have been released quite some time ago, but there is no trace of them in the GUI. I am inclined to build and flash it myself. I've flashed my ec in the past, but I don't want to set the versions of ec and firmware-open too far apart. What's the policy here? There is this warning here about "normal" users who should not do this themselves. Perhaps I am not normal :-/
- Galago Pro - RTX 3050 windows driver!
- New System Firmware is available on System76's GitHub, but I still don't have a System Firmware update button inside Pop_OS!
me_cleaner
-
Power issue with my X250. Time to upgrade? (more info in comments)
Some times Intel version of Lenovo have a problem with Intel ME , check this out. LINK
-
System76's Coreboot Open Firmware Manages to Disable Intel Me for Raptor Lake
Yes; there are several ways, depending heavily on the version, and ranging from most trustworthy to least trustworthy:
* By patching the ME firmware itself - see the me_cleaner project, and methods documented here: https://puri.sm/posts/deep-dive-into-intel-me-disablement/ . This is Pretty Reliable; the runtime code has been deleted from flash.
* By setting a bit in the flash configuration, assumed to be added for the US High Assurance program: https://github.com/corna/me_cleaner/wiki/HAP-AltMeDisable-bi... , https://www.ptsecurity.com/ww-en/analytics/disabling-intel-m... . This is Mostly Reliable; the mechanism has been fairly aggressively reverse engineered and was added for a program with strict requirements.
* By sending an HECI command that says "hey ME, turn off your runtime" https://review.coreboot.org/c/coreboot/+/52800 . This is Somewhat Reliable; the method is well understood and seems to work but I'm not sure someone has done a deep dive audit into whether it could be re-enabled somehow.
-
Modern CPUs have a backstage cast
"...this is interesting is because POWER9 is basically the first time the public got a real view of how sophisticated the backstage cast actually is of a modern server CPU."
Not quite correct; the OpenSPARC T1 and T2 were publicly released and available by 2008.
https://www.oracle.com/servers/technologies/opensparc.html
"Large parts of this process are handled by vendor-supplied mystery firmware blobs, which may as well be boxes with “???” written in them.
The maintainers of the me_cleaner script likely have the clearest view of what is known.
https://github.com/corna/me_cleaner
- What is the most trusted hardware most OpenBSD people would suggest?
-
Let's find our next HW wallet
Your dedicated laptop with disabled Intel ME running OpenBSD might be the gold standard choice for your hardware wallet. Main discussion here.
-
Laptop with deactivated Intel ME running OpenBSD as a hardware wallet for top cryptos
I consider a dedicated laptop with deactivated Intel ME running OpenBSD (maybe from USB flash) can be a much secure alternative to a proprietary hardware wallet connected to your casual multi-purpose laptop.
-
On Intel ME
On a side note, if Intel has made it this hard to disable Intel ME, is the US government happy with this change? It was them who got the HAP bit part working, and I do not see any news suggesting they have another trick to disable Intel ME. Should I just assume that this still works? Has anybody here tried? And does me_cleaner still work (last updated in 2018: https://github.com/corna/me_cleaner)?
-
I ordered my first laptop from System76. I'm so excited
This is incorrect. Intel ME has an internal disablement mechanism: https://github.com/corna/me_cleaner/wiki/HAP-AltMeDisable-bit this is the mechanism that it used by S76 and Purism.
- linux and tails compromised? if this is real we lost all privacy. found it on twitter
-
Why I Use Old Hardware
If you are sensitive about the Intel Management Engine, the original Core 2 Duo/Quad systems are the last where it could be fully disabled.
Anything later will forcibly shut down after 30 minutes if (at least a fragment of) Intel's closed & bug-ridden monitoring code is not present.
I ran me_cleaner on a few of these systems, and I do all my finances with them running OpenBSD (usually on q9550s).
Yes, this effort to run old hardware is worth it for me. Below are the bios images that I was able to produce:
https://github.com/corna/me_cleaner/issues/233
What are some alternatives?
tuxedo-control-center - A tool to help you control performance, energy, fan and comfort settings on TUXEDO laptops.
thinkpad-firmware-patches - Collection of ThinkPad UEFI patches.
coreboot - Fork of coreboot repo
t430-coreboot - coreboot rom for thinkpad t430
system76-galapago-pro-fan-unfucker - Ubuntu fan control indicator for Clevo laptops
coreboot - DEPRECATED: coreboot on the w541. See link below.
clevo-indicator - Ubuntu fan control indicator for Clevo laptops
cadmium - [Moved to: https://github.com/Maccraft123/Cadmium]
edk2 - EDK II
thepyphone - Voice and SMS/MMS on a Raspberry Pi 3B+
ec - System76 Open Source Embedded Controller
Remove_IntelME_FPT - A guide for disabling Intel Management Engine using FPT on PCH SPI