Hacker News new | past | comments | ask | show | jobs | submit login

Sure! coreboot + LinuxBoot (with u-root) in the integrity-protected SPI flash memory, which then netboots (download and kexec) a Linux system. All artifacts need to be reproducible. For the CT Log probably trillian.

As for choosing this board, I alluded to it in a post down below. Note that I'm not a firmware expert though. Support for x86 was obviously already there, as well as for the microarch if I recall correctly, so "all" our technology partner 9eSec ( https://9esec.io ) had to do was support the specific board. Had we chosen another microarch or something with multiple CPUs we could have spent months on it. Just another example of how important it is to work with experts.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: