Hello everyone, trying to decide between two builds for a Qubes machine with open firmware and could use some input from people who’ve actually done this.
Option A is an Ivy Bridge box, probably an HP Z220 with a Xeon E3-1245 v2 (or an Optiplex 9010 with an i7-3770). ECC, VT-d, coreboot + Heads, me_cleaner on the ME. Seems like the “normal” choice.
Option B is a dual socket G34 board with Opteron 6300s. Appeal is no ME and no PSP at all. But it’s huge, power hungry, slow per core, and I’m not sure what the firmware situation even looks like anymore.
Threat model is basically targeted stuff + someone getting physical access to the machine, so tamper detection matters to me.
Few things I’m unsure about:
- is coreboot/libreboot for the G34 boards still maintained or is it kind of abandoned?
- can I even get Heads style measured boot on option B? if not that feels like a big loss
- how does Qubes actually run on Opteron 6300?
- is a me_cleaned ME really a meaningful risk vs no ME at all, or is that mostly theoretical?
Leaning A but B keeps tempting me. What would you pick?