mazzilius_marsti

@mazzilius_marsti@lemmy.world · Joined ⁨Jul⁩ ⁨2024⁩

posted in Asklemmy

How was your experience with Clevo/Tong Fang laptops as an ODM?

I’m getting a new laptop with hardware that supports Linux very well. Although my old thinkpad is still working, i need something with better CPU and higher RAMs (when i am able to afford) for work. I could get a new Thinkpad too but recently Intel made suspend/standby in Linux to be unreliable.

I notice that for the Linux first vendors, there are 2 types: ones who design their own chassis (Framework, Starlabs), and those who use an existing ODM design and put their own software tweaks on (Sys76, Tuxedo, Novacustom).

For the ODM, these vendors usually go with either Clevo or Tong Fang. From most comments i read, Clevos are criticized for being flimsy, weak hinges and the batteries can get swollen.

Anyone with laptops from these vendors? How is the quality? I heard great things about coreboot, but if the hardware sucks then theres no point.

Replying to @⁨modem_down@thebrainbin.org⁩

i use a yubikey and still have the ability to type my LUKs password in. Yubikey is just more convenience: plug in and it auto type the password field. On Fedora this means it populates the field with asterisks. Still, i think using password is the best method.

With that said, i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop. So far i know of only Dasharo boot and the stuff from Purism that can do these…

So the layout is: Boot verification -> LUKs-> your data

Or if you have the juices and powers: Boot verification -> LUKS -> QuebeOS dom0 -> choose your Quebess.

Replying to @⁨badbytes@lemmy.world⁩

yes you can. On Graphene you can set the main profile as just there with nothing except to control wifi/add esim/etc. Then you can create many profiles with their own passwords. You can store your work stuff in 1 profile, private stuff in another. You can even create a dummy profile with fake Google. .

The downside currently is that the OS autoboot to main profile. Then you switch to your other profiles.

Replying to @⁨madeindex@lemmy.world⁩

GrapheneOS - the only OS that i just installed and forget about it. Sure i spend time to tweak things like profiles but thats it.

And I am a distro and rom hopper.

The security model is that good: duress pin, scrambled pin, separate profiles with their own passwords, usb c restriction (you can set it charge only, charge while phone is off (most secure state).