


Capabilities
Boot & firmware
Measured boot + TOTPstock (upstream)
Heads + TOTP
Heads measures the firmware at boot and proves its integrity via a TOTP code. Requires flashed Heads with the TPM bound — done at the workshop.
SourceOpen firmware (Coreboot)stock (upstream)
Coreboot
The boot firmware is Coreboot — open-source and auditable — instead of the vendor BIOS.
SourceNo Intel MEabsent
No active Intel Management Engine. On AMD there is no Intel ME (but the proprietary AMD PSP remains). Neutralization is never total.
SourceSecure elementstock (upstream)
TPM
Dedicated chip that stores keys and throttles PIN attempts (Titan M2 on Pixel, dTPM on some ThinkPads).
SourceGuaranteed updatesabsent
Security-update window documented by the manufacturer. Shown only when it is guaranteed.
SourceSystem & data
Encrypted at restonsecret workshop
LUKS
Data is encrypted while the device is locked (FBE on phones, LUKS applied at the workshop on laptops).
SourceCompartmentalization (Qubes)option
Qubes
Qubes OS isolates your activities in walled VMs — a compromise does not spread to the rest.
SourceAmnesic (Tails)option
Tails
Tails leaves no trace: everything runs in RAM and vanishes at shutdown, save an optional persistent volume.
SourceWorkshop & support
Installed, verified at the workshoponsecret workshop
We flash, verify integrity and re-lock every unit. For USB keys we provide the signature-verification procedure — don't take our word for it.
Tamper-evident seal appliedonsecret workshop
A tamper-evident seal is applied at the workshop: opening it leaves a visible mark.
● stock (upstream)◆ onsecret workshop○ option— absent
What this does not protect against
- Older-generation hardware (Intel 10th gen): performance and battery below modern.
- No protection once the machine is unlocked and running.
- Internal radios (WiFi/WWAN) remain proprietary firmware.
- Intel ME present (partially neutralized per platform, never fully).
What the workshop does to this device
Our pipeline
- Coreboot/Heads flash depending on the model (X1C G8: measured boot + TOTP; X1C G11: stock firmware kept — this generation is unsupported, we won't tell you otherwise).
- Chosen OS install (Qubes, Tails, Debian) + LUKS encryption.
- Tamper-evident seal applied, where claimed.
- Integrity check and unit sheet handed over.
What you can ask us
- Questions and advice: Signal / PGP / anonymous ticket (see /support).
- Help re-flashing or changing the OS.
- Verification: we show you how to check our work.
What we do not do
- No RustDesk-style remote support on laptops: the managed stack only covers Android phones.
- No vendor-firmware update guarantee.
- On the X1C G11 we do not claim to neutralize Intel ME or set up measured boot — the hardware does not allow it.
Choose within the range
| ThinkPad X1 Carbon Gen 8 — hardenedHERE« Maximum firmware trust »€665 Monero€950 card | ThinkPad T14 Gen 3 AMD — hardened« No Intel ME »€1,015 Monero€1,450 card | ThinkPad X1 Carbon Gen 11 — hardened« Recent hardware »€1,463 Monero€2,090 card | |
|---|---|---|---|
| Differences | |||
| Measured boot + TOTP | Heads + TOTP | ||
| Open firmware (Coreboot) | Coreboot | if supported*perConfig | |
| No Intel ME | AMD | ||
| Secure element | TPM | dTPM 2.0 | |
| Compartmentalization (Qubes) | Qubes | Qubes | Qubes |
| Tamper-evident seal applied |
More expensive does not mean safer: the recent model keeps its vendor firmware where the older one offers measured boot.
Top threat = evil-maid / firmware → X1C G8. Refusing Intel ME and needing performance → T14. Recent hardware with Qubes compartmentalization as your defence → X1C G11.
What it is
What this is
An X1 Carbon Gen 8 reflashed with Coreboot + Heads: firmware measures boot into the TPM and shows a TOTP at startup. If firmware or config were tampered with, the code no longer matches — you see it before typing your passphrase.
Honest positioning
The affordable tier: strong security-per-euro, but dated hardware. For those who want verifiable *measured boot* and Qubes/Tails without the modern price.
Usage guide
First boot
- Heads shows a TOTP: compare it to your authenticator (key provided). Match = firmware intact.
- Check the anti-tamper seal (reference photo provided) before first opening.
- Unlock the disk (LUKS), then your Qubes/Tails session.
Daily use
- Qubes OS: compartmentalize by domain (personal, work, banking, disposable). See qubes-os.org.
- Tails: amnesic, all via Tor; optional encrypted persistence — tails.net.
- Re-seal after any hardware work.
Specifications
| Model | Lenovo ThinkPad X1 Carbon Gen 8 (Intel 10th gen) |
|---|---|
| Firmware | Coreboot + Heads (measured boot) |
| Attestation | Boot-time TOTP via key + TPM |
| Storage | 512 GB NVMe (LUKS) |
| OS | Qubes OS (compartmentalized) or Tails (amnesic) |
| Condition | Refurbished, anti-tamper seal applied |
After purchase
Your device arrives already prepared — this guide is for redoing everything yourself or checking our work.
Open the full guide
Premier démarrage
- Au boot, Heads affiche un TOTP : comparez-le à votre app d'authentification (clé fournie). Concordance = firmware intègre.
- Vérifiez le sceau anti-tamper (photo de référence fournie) avant la première ouverture.
- Déverrouillez le disque (LUKS), puis votre session Qubes/Tails.
Au quotidien
- Qubes OS : compartimentez par domaine (perso, travail, banque, jetable). Voir qubes-os.org.
- Tails : amnésique, tout via Tor ; volume persistant chiffré optionnel — tails.net.
- Re-scellez après toute intervention matérielle.
Verifiable sources
- coreboot Verified on: 15 June 2026
- Heads (osresearch) Verified on: 15 June 2026
- Documentation Qubes OS Verified on: 15 June 2026
- Tails Verified on: 15 June 2026