Skip to content

Commit 53889a6

Browse files
committed
Externally reviewed with deduplication of repeated content
Signed-off-by: Thierry Laurion <insurgo@riseup.net>
1 parent 1d85099 commit 53889a6

File tree

1 file changed

+25
-17
lines changed

1 file changed

+25
-17
lines changed

About/Vendors_resellers.md

Lines changed: 25 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -32,30 +32,33 @@ devices.
3232
- **Products:** Servers
3333

3434
### Nitrokey (Heads)
35-
Nitrokey offers Heads preinstalled on some of their devices. Nitrokey is also
36-
a reseller of some of NovaCustom's laptops with BootGuard unfused. Additionally,
37-
Nitrokey sells refurbished laptops with Intel ME neutralized for their older
38-
refurbished models.
35+
Nitrokey offers Heads preinstalled on some of their devices. They also sell
36+
older refurbished laptop models with Intel ME neutralized and Nitrokey USB
37+
security dongles. Additionally, Nitrokey resells some of NovaCustom's laptops.
3938

4039
- **Website:** [Nitrokey](https://www.nitrokey.com)
41-
- **Products:** Laptops, servers, workstations, USB security dongles, and
42-
refurbished laptops with ME neutralized
40+
- **Products:** Laptops, phones, servers, workstations, mini-PCs, USB security
41+
dongles, and older refurbished laptop models with ME neutralized
4342

4443
### NovaCustom (Heads)
4544
NovaCustom offers devices with Heads preinstalled. They focus on providing
46-
customizable and secure devices for their customers. They also resell Nitrokey
47-
USB security dongles. NovaCustom sells Clevo laptops with BootGuard not fused,
48-
meaning the final manufacturing step of fusing BootGuard keys is not done. This
49-
ensures that the firmware remains user-controlled.
45+
customizable and secure devices for their customers. NovaCustom buys Clevo
46+
laptops in bulk, ensuring BootGuard keys are not fused at the last manufacturing
47+
steps. They also resell Nitrokey 3 USB security dongles bundled with their
48+
Heads-based firmware devices.
5049

5150
- **Website:** [NovaCustom](https://novacustom.com)
5251
- **Products:** Laptops and USB security dongles
5352

54-
### Purism (Pureboot Heads fork)
55-
Purism offers their Pureboot (a fork of Heads) preinstalled on their devices.
53+
### Purism (PureBoot Heads distribution)
54+
Purism offers laptops, tablets, mini PCs, and servers with PureBoot (a
55+
distribution of Heads) preinstalled. BootGuard is unfused to ensure firmware
56+
remains user-controlled. Purism makes and sells the Librem Key, which is a clone
57+
of the Nitrokey Pro 2. The Librem Key is made in the USA.
5658

5759
- **Website:** [Purism](https://puri.sm)
58-
- **Products:** Laptops, phones, workstations, tablets, and USB security dongles
60+
- **Products:** Laptops, phones, tablets, mini PCs, servers, and USB security
61+
dongles
5962

6063
## General Information
6164

@@ -68,13 +71,18 @@ Many of these vendors offer additional services and features, including:
6871
- **QubesOS Certification:** Some devices may be QubesOS certified, ensuring
6972
compatibility and security.
7073
- **CSME/ME Status:** Some vendors offer options to neutralize or disable Intel
71-
CSME/ME. "Neutralized" means most parts of the ME are removed, while "disabled"
72-
means the ME is deactivated. Users should verify these options on the respective
73-
vendor websites. For more information, refer to Purism's blog post on this topic:
74-
[Deep Dive into Intel ME Disablement](https://puri.sm/posts/deep-dive-into-intel-me-disablement/).
74+
CSME/ME. "Neutralized" means most parts of the ME are removed, while
75+
"disabled" means the ME is deactivated. Users should verify these options on
76+
the respective vendor websites. For more information, refer to Purism's blog
77+
post on this topic: [Deep Dive into Intel ME Disablement](https://puri.sm/posts/deep-dive-into-intel-me-disablement/).
7578
- **Blob Status:** The newer the platform, the more it relies on proprietary
7679
blobs. Users should consider their threat model when choosing a device. For
7780
more information, refer to the [threat modeling page](/Heads-threat-model/).
81+
- **HOTP Security Dongles:** Purism and Nitrokey are makers of HOTP-compatible
82+
security dongles. USB security dongles are used for both remote attestation
83+
and to authenticate and sign boot content. Heads relies on HOTP for tamper
84+
evidence. Users should verify the specific offerings on the respective vendor
85+
websites.
7886

7987
Please verify the specific offerings and services on the respective vendor
8088
websites.

0 commit comments

Comments
 (0)