Grade B – Insurgo PrivacyBeast I5 X230 Laptop – QubesOS Certified & preinstalled

CAD $1,250.00

In stock

This QubesOS certified refurbished laptop is lower-end Lenovo Thinkpad i5 X230 model, with following specifications:

  1. Intel Core i5 3rd gen 2×2.5Ghz+ cores CPU (Not i7 2.9ghz highest end for X230)
  2. 16GB DDR3 memory (maximum capacity for that model)
  3. 250GB Solid State Drive, SSD-III 6GB/s Hard drive (option not customizable)
  4. Trusted Module Platform (TPM) v1.1
  5. TN Display Panel (Not IPS panel)
  6. Intel HD 4000 graphic card
  7. Built-in Webcam
  8. 2x Fast USB 3. 0 ports (left side blue ports) + 1x USB 2.0 port (right side yellow port)
  9. HD Mini-DisplayPort TV-Out (Mini-DP port)
  10. Non-Backlit USA keyboard (Only Thinklight when doing FN+Space)
  11. WiFi controller: Atheros AR5BHB116 a/b/g/n 300Mbps MINI PCI-E
  12. Ethernet controller: Intel Corporation 82579LM Gigabit Network Connection
  13. Original Lenovo USA AC Adapter (Input: 100-240V, 2.5A-0.5A 50/60Hz, Output: 20V, 4.5A, Connector: M11)
  14. Original Lenovo Working Battery (60% capacity, guaranteed for 14 days upon delivery)

It comes with a HOTP enabled USB Security dongle, required for visual firmware integrity attestation. It is also used to attest boot files integrity after each system components upgrade, for which integrity is validated against user’s public key inserted into the ROM.

It also comes with 16Gb sdcard, permitting to put it into Read Only mode through a mechanical switch when to be put in untrusted computers. It comes with the latest installation media and signatures files of QubesOS, while original Lenovo firmware files and provisioned secrets are stored in an encrypted partition for which randomly selected diceware passphrase to unlock it will be communicated to you through secure communication channel.

You pay a fixed fee of 500$CAD (included in price) for the Intel ME neutering, Heads installation, QubesOS preinstallation and tamper evidence seals, while helping me maintain Heads and integrate it to a larger number of models, collaborating on QubesOS to ease user experience and facilitate hardware acquisition from freedom defenders all around the world.

*Note that 25% of the net profits are given to Insurgo’s Initiative OpenCollective fund to continue NlNet PET0 funded Accessible Security related projects.

In stock

Category:

Description

Insurgo’s PrivacyBeast X230 I5 laptops are refurbished B quality Lenovo ThinkPad X230 laptops, in which Intel ME has been Neutered+Deactivated and the proprietary boot firmware and unused space replaced with Heads Open Source firmware to attest it’s integrity at each boot, making it trustworthier.

Insurgo preinstalls latest QubesOS on it, with diceware randomly selected passphrases to encrypt disk content,  seals the boot and firmware integrity with the provided Librem Key/Nitrokey Pro v2 for you to visually validate that nothing has been tampered with during transit. Insurgo also owns the Librem Key/Nitrokey Pro v2 (USB Security dongle) with diceware selected Admin and User PINs, injecting a temporary public GPG key into the firmware. Insurgo seals the integrity of the firmware both through TPMTOTP (using laptop’s Trusted Platform Module aka TPM) which secret is also sealed into USB Security dongle through HOTP, providing the user with two ways of making sure the hardware has not been tampered with since it left his hands: with a QR Code to scan on his smartphone prior to hardware reception and by plugging USB Security dongle at first boot, which should flash green to attest laptop firmware and boot configuration trustability.

Upon reception, you will be asked to re-own your new hardware by: re-encrypting your QubesOS installation, selecting a new Recovery Disk Key passphrase to replace OEM’s, factory resetting your USB Security dongle which will generate a new GPG key pair for desired e-mail address, asking you to choose your own Admin and User PINs to use this USB Security dongle also externally, to encrypt/sign files and E-Mails. At the end of this re-ownership process, the firmware will contain your public key injected and measured in it. Your USB Security dongle will be required to sign each QubesOS boot related upgrades, the signature of the files digest (sha256sum of files) being validated against USB Security dongle’s /boot signed version with your public key present in ROM, automatically at each boot. Your new USB Security dongle will need to be plugged in at each boot, visually attesting that the boot firmware (root of trust of the computer) has not been tampered with by a third party, by flashing its LED green if in a known state or red if taken measurements mismatches.

 

 

Additional information

Weight 5.6 lbs
Dimensions 16 × 12 × 3 in

Reviews

There are no reviews yet.

Be the first to review “Grade B – Insurgo PrivacyBeast I5 X230 Laptop – QubesOS Certified & preinstalled”
Go to Top