# Corebooting a Thinkpad T430 + other Hardware recommendations

**URL:** https://discuss.privacyguides.net/t/corebooting-a-thinkpad-t430-other-hardware-recommendations/14165
**Category:** General
**Tags:** hardware, guide
**Created:** 2023-09-28T10:52:47Z
**Posts:** 4

## Post 1 by @Torsten — 2023-09-28T10:52:47Z

The T430 is one of the most affordable yet powerful used Coreboot laptop available on the market. W530 is not that well supported and very rare.

In this thread I want to discuss the process, list parts needed and in the end a guide on how to do it, including pictures, will be available.

I will be using Heads, as this coreboot Distribution has measured boot and support for Hardware based verification (HOTP), as well as Time based verification (TOTP).

## What is coreboot?

Roughly, coreboot is a replacement for the old, slow and proprietary BIOS on your PC or Laptop. It allows to initialize your hardware, boot your Operating System, and more:

- run [memtest86](https://www.memtest86.com/)
- verify your kernel
- boot an UEFI ([Tianocore](https://github.com/tianocore)), legacy BIOS ([Seabios](https://www.seabios.org/SeaBIOS)), a minimal Linux Kernel ([LinuxBoot](https://linuxboot.org/)) or directly use [grub](https://www.coreboot.org/GRUB2) to boot Linux
- configure the fancurve
- [play Tetris](https://youtu.be/S-fObtQfFAc)…

These features depend on the payload you add to your coreboot installation.

## Devices preinstalled

Coreboot comes preinstalled and supported in these devices:

- [System76](https://system76.com/) Desktops and Laptops
- [Novacustom NV41, NS51, NS70](https://configurelaptop.eu/coreboot-laptop/), as well as the Nitrokey variants and the matching OEM Clevo laptops ([Awesome Video Tutorial](https://youtu.be/yTc-bDNyzI0))
- [Starlabs](https://starlabs.systems) Machines
- [Nitropad](https://shop.nitrokey.com) T430 and X230, premodified Thinkpads
- all Chromebooks ([some run Linux](https://mrchromebox.tech/#devices))
- some more PCs
- [Purism Librem](https://puri.sm/) (if you can get one, lol)

## Distributions

Common Coreboot Distributions you can install on existing hardware:

- [Libreboot](https://libreboot.org/), now also with binary blobs
- [Skulls](https://github.com/merge/skulls): simple T430 distribution
- [Heads](https://osresearch.net): secure distribution with all the nice benefits
- [dasharo](https://docs.dasharo.com/): for Novacustom for example, EDK2 with measured boot, also Heads variants available
- [MrChromebox Coreboot](https://mrchromebox.tech), using EDK2 (UEFI) and running on basically all x84 Chromebooks and Chromeboxes.
- …

## Hardware for flashing

If you want to be sure its official, or dont have it preinstalled, you will need to flash Coreboot onto your BIOS chips.

Needed tools:

- a Linux PC with `flashrom` installed
- a CH431a (the a is crucial!) Programmer, [Guide how to mod the voltage to not burn your chip](https://www.chucknemeth.com/usb-devices/ch341a/3v-ch341a-mod)
- a matching clip, cable and connector (often a combined package)
- something to open your PC
- when running Heads, a [Yubikey](https://www.yubico.com) or [Nitrokey](https://nitrokey.com/) with gpg storage
- For corebooting ChromeOS devices: a SuzyQ cable that you can solder yourself or sometimes buy from eBay. [Official account of the original maker](https://www.ebay.de/usr/chromebook_kid), here is his [chrultrabook forum account](https://forum.chrultrabook.com/u/chocolateloverraj)

Note: for Thinkpads there is [1vyrain](https://1vyra.in/), which uses a BIOS exploit to flash without hardware. This can only use a part of your available BIOS space though, and the [Intel ME](https://github.com/corna/me_cleaner) is not neutered when flashing another Coreboot Distro during Install. So [Hardware flashing](https://osresearch.net/Flashing-guides) is recommended.

## Procedure

1. Remove any BIOS password to be sure!

2. Turn off your Laptop and screw it open. Make sure you have no static electricity on your hands (touch a heater or wear a band).

3. Remove the battery and power supply, afterwards press the power button several seconds to remove and electricity from the board.

4. Install flashrom on your other PC. Connect the CH431a programmer with its clip and cable and plug it into a USB port.

5. Disassemble your to-be-flashed laptop or PC and find the BIOS chips. Attach the clip to one of the chips.

6. To test the attached connection, read the BIOS image from that chip twice, dont move the Laptop in the meantime. Save the two images under different names and compare using `diff` or `sha256sum`.

7. If the images match, your clip is attached correctly. Flash your Coreboot Distribution of choice. Make sure to use the right chip and image.

8. You may have a top and bottom image, if yes, attach your clip to the other BIOS chip and repeat step 6, flash the other BIOS chip with the matching image.

…

Update: If there are further steps, I have forgotten them.

- Make sure to wait a bit after the flashing is done, then power off.
- You might need to hard reset (remove battery and power cable, long press the power button) but unlikely
- You can use HEADS on its own, but it only really makes sense with a nitrokey.
- The nitrokey has a default pin of 123456. You can change some pins using their software, the GPG pin using GnuPG.

Generally, HEADS is very clunky and makes little sense if your booting system always changes, as there is no signature, you blindly trust the system every time. So if you constantly need to blindly trust it, that makes little sense of course. Using a stable distro like Almalinux or Debian might make sense here.

The only protection you will get is: if you know you didn’t make an update and someone has tampered with your system, the signature verification will fail and you would need to store it new in your Nitrokey.

The laptop works with Fedora Atomic Desktops and normal Linux distros, but apart from that it is lying in my wardrobe.

The T480 is a semi recent laptop that can be gotten used, supplied with used RAM and corebooted.

Otherwise, see the hardware vendors mentioned above.

---

## Post 2 by @sycamore — 2023-09-28T13:23:57Z

This is cool stuff, thanks a lot Torsten! :slight_smile: I have no knowledge regarding firmware flashing but it’s something I want to do long-term (and if I ever find a T430 I can buy irl). Hence, a low-bar explanatory walk-through like you seem to want to create here is highly appreciated! :star_struck:

---

## Post 3 by @Torsten — 2023-09-28T13:40:22Z

The QubesOS forum has some people that did it, but gathering all the infos is hard. I will try it anyways and things are coming together well

---

## Post 4 by @Torsten — 2026-07-17T15:48:58Z

Update: a T430 can house at least 16GB DDR3(L) RAM, terabytes of storage, and it is pretty repairable (although it is pretty painful).

Though, for a modern laptop, slim, good screen, long batterylife, a Chromebook is WAY better.

I have a Lenovo Flex 3, which is okaaay but pretty low power. 16GB RAM are recommended for a normal desktop Linux experience.

For corebooting you might need a SuzyQ cable, which you can solder yourself, or buy [from this guy](https://forum.chrultrabook.com/u/chocolateloverraj) and from some re-sellers on ebay
