I ordered a laptop a while back, and it has not shipped yet, but now Purism is talking about a new Heads boot tamper security feature I don’t really understand. Will I have that on my laptop? Is there any way for me to install the new Heads firmware on it after the fact if I ordered too late?
This is a good question. I ordered Friday.
From what I understand, because I asked a similar question…
They do not want to change the hardware, in most cases. The hardware on current laptops will stay the same on future laptops. The software will probably have to be updated by you requiring some understanding of unix.
I just received my laptop this week and the hardware included TMP but I had to flash the new CoreBoot image from 1.6 to 1.7 to get TMP and a few other updates working.
Now as far as the Heads thing goes, I do not completely understand it. But from what I do understand… I think there will be implementation for new software and hardware. The hardware aspect would be something along the lines of… for example “putting tape over a hardware part as tamper evidence”. I doubt that would be the exact case, because tape is known to not work. You can remove the tape and reglue the tape without anyone knowing.
You would not receive the hardware aspect of this. But any software updates will be released and updated through software releases/CoreBoot images. No problem there.
On Hardware: I asked them and they said that they have no plans to make major hardware changes, which I think would include Heads.
We are not shipping Heads yet on our laptops. While we have gotten it working, we want it to be an accessible feature to everyone so we are working a lot behind the scenes to improve its accessibility before we include it by default.
When it’s ready to release, we will include instructions so existing users who have Librem laptops with the TPM chip will be able to update if they want to.