@@ -32,30 +32,33 @@ devices.
32
32
- ** Products:** Servers
33
33
34
34
### Nitrokey (Heads)
35
- Nitrokey offers Heads preinstalled on some of their devices. Nitrokey is also
36
- a reseller of some of NovaCustom's laptops with BootGuard unfused. Additionally,
37
- Nitrokey sells refurbished laptops with Intel ME neutralized for their older
38
- refurbished models.
35
+ Nitrokey offers Heads preinstalled on some of their devices. They also sell
36
+ older refurbished laptop models with Intel ME neutralized and Nitrokey USB
37
+ security dongles. Additionally, Nitrokey resells some of NovaCustom's laptops.
39
38
40
39
- ** Website:** [ Nitrokey] ( https://www.nitrokey.com )
41
- - ** Products:** Laptops, servers, workstations, USB security dongles, and
42
- refurbished laptops with ME neutralized
40
+ - ** Products:** Laptops, phones, servers, workstations, mini-PCs, USB security
41
+ dongles, and older refurbished laptop models with ME neutralized
43
42
44
43
### NovaCustom (Heads)
45
44
NovaCustom offers devices with Heads preinstalled. They focus on providing
46
- customizable and secure devices for their customers. They also resell Nitrokey
47
- USB security dongles. NovaCustom sells Clevo laptops with BootGuard not fused,
48
- meaning the final manufacturing step of fusing BootGuard keys is not done. This
49
- ensures that the firmware remains user-controlled .
45
+ customizable and secure devices for their customers. NovaCustom buys Clevo
46
+ laptops in bulk, ensuring BootGuard keys are not fused at the last manufacturing
47
+ steps. They also resell Nitrokey 3 USB security dongles bundled with their
48
+ Heads-based firmware devices .
50
49
51
50
- ** Website:** [ NovaCustom] ( https://novacustom.com )
52
51
- ** Products:** Laptops and USB security dongles
53
52
54
- ### Purism (Pureboot Heads fork)
55
- Purism offers their Pureboot (a fork of Heads) preinstalled on their devices.
53
+ ### Purism (PureBoot Heads distribution)
54
+ Purism offers laptops, tablets, mini PCs, and servers with PureBoot (a
55
+ distribution of Heads) preinstalled. BootGuard is unfused to ensure firmware
56
+ remains user-controlled. Purism makes and sells the Librem Key, which is a clone
57
+ of the Nitrokey Pro 2. The Librem Key is made in the USA.
56
58
57
59
- ** Website:** [ Purism] ( https://puri.sm )
58
- - ** Products:** Laptops, phones, workstations, tablets, and USB security dongles
60
+ - ** Products:** Laptops, phones, tablets, mini PCs, servers, and USB security
61
+ dongles
59
62
60
63
## General Information
61
64
@@ -68,13 +71,18 @@ Many of these vendors offer additional services and features, including:
68
71
- ** QubesOS Certification:** Some devices may be QubesOS certified, ensuring
69
72
compatibility and security.
70
73
- ** CSME/ME Status:** Some vendors offer options to neutralize or disable Intel
71
- CSME/ME. "Neutralized" means most parts of the ME are removed, while "disabled"
72
- means the ME is deactivated. Users should verify these options on the respective
73
- vendor websites. For more information, refer to Purism's blog post on this topic:
74
- [ Deep Dive into Intel ME Disablement] ( https://puri.sm/posts/deep-dive-into-intel-me-disablement/ ) .
74
+ CSME/ME. "Neutralized" means most parts of the ME are removed, while
75
+ "disabled" means the ME is deactivated. Users should verify these options on
76
+ the respective vendor websites. For more information, refer to Purism's blog
77
+ post on this topic: [ Deep Dive into Intel ME Disablement] ( https://puri.sm/posts/deep-dive-into-intel-me-disablement/ ) .
75
78
- ** Blob Status:** The newer the platform, the more it relies on proprietary
76
79
blobs. Users should consider their threat model when choosing a device. For
77
80
more information, refer to the [ threat modeling page] ( /Heads-threat-model/ ) .
81
+ - ** HOTP Security Dongles:** Purism and Nitrokey are makers of HOTP-compatible
82
+ security dongles. USB security dongles are used for both remote attestation
83
+ and to authenticate and sign boot content. Heads relies on HOTP for tamper
84
+ evidence. Users should verify the specific offerings on the respective vendor
85
+ websites.
78
86
79
87
Please verify the specific offerings and services on the respective vendor
80
88
websites.
0 commit comments