Comment by subway
7 years ago
Awesome post, but a very minor nitpick:
> Chromebooks use both, coreboot on x86, and u-boot for the rest.
This isn't entirely true. Coreboot is used on a number of ARM Chromebooks, including rk3288 and rk3399 based devices. It seems like u-boot is used less and less in the space. Libreboot has builds for a few devices that kill the annoying "untrusted os" message, and even allow you to set your own trust root.
Is there a way to flash Pixelbooks?
Being able to reflash a current nvme Pixelbook with my own trust root and build and sign my own OS images would be super excellent.
The platform security of the Pixelbook is lovely; the only way it could be better is if I were able to control it.
I'm not sure -- I haven't messed with a Pixelbook. On Chromebooks, the trust root lives in the bootloader's flash with no security beyond the write protect screw.
A quick googling led to a reddit post that indicates it's possible with the Pixelbook, but likely a PITA:
https://www.reddit.com/r/PixelBook/comments/7kv944/does_anyo...
https://mrchromebox.tech