Pages123456789101112
Explained comic · 12 pages

coreboot: Firmware Without the Cruft

Read it as a flipbook →

The source is the coreboot getting-started documentation, explaining what coreboot is as an open-source BIOS/UEFI replacement focused on boot speed, security, safety, flexibility, and freedom. It also lists community distributions and vendors shipping coreboot hardware.

the quick read, page by page

Coreboot is a lightweight, open-source firmware replacement for BIOS/UEFI that prioritizes fast boot times, security, and flexibility across diverse hardware platforms.

Proprietary firmware has grown bloated from 100kb to 8mb of code, creating security and performance problems that coreboot addresses through a minimal design.

Coreboot's open-source model enables engineers to share improvements across vendors, producing more stable and better firmware than closed systems.

Coreboot supports multiple boot payloads including SeaBIOS for legacy systems, iPXE for network boot, and UEFI, with customization possible through libpayload.

Coreboot enables flexible boot customization such as custom splash screens, debug output over serial or USB, and rapid boot with post-OS log retrieval.

Coreboot minimizes attack surface through a small Trusted Computing Base, VBOOT2 secure boot, MISRA-C compliance, and hardware security features like IOMMU and flash protection.

Coreboot's unbrickable firmware update architecture ensures that firmware updates are as safe as installing a mobile application.

Coreboot achieves dramatic boot speed improvements, reducing desktop/laptop boot time to under one second and cutting server boot time by over 70% compared to OEM BIOS.

Coreboot requires building custom firmware images from source code for specific hardware, but community-maintained distributions like Canoeboot, Libreboot, and Dasharo provide ready-to-flash alternati

Google's Chromebooks represent the largest coreboot deployment, while vendors like Minifree, NovaCustom, and Purism sell consumer laptops and desktops with coreboot pre-installed.

Specialized vendors including Protectli, System76, and Star Labs offer coreboot-based systems designed for security, Linux compatibility, and open-source software ecosystems.

Embedded and enterprise coreboot solutions are available from vendors including PC-Engines, Raptor Engineering, and Portwell for specific industrial and in-vehicle applications.

Page One
KEY IDEA

coreboot is an open, minimal, fast firmware that replaces your BIOS or UEFI.

Key idea & notes ▾ WHY THIS MATTERS

The code that runs before your OS is usually closed and bloated, and coreboot makes it transparent.

SOURCE Read the source LEARN MORE doc.coreboot.org
Page Two
KEY IDEA

Firmware is the first code that runs, sitting between hardware and the operating system.

Key idea & notes ▾ WHY THIS MATTERS

Understanding this hidden layer explains why replacing it changes speed, security, and trust.

SOURCE Read the source LEARN MORE doc.coreboot.org
Page Three
KEY IDEA

Firmware has grown large and closed, so coreboot pursues openness and user freedom.

Key idea & notes ▾ WHY THIS MATTERS

Whoever controls the first code that runs on your machine effectively controls the machine.

SOURCE Read the source LEARN MORE doc.coreboot.org
Page Four
KEY IDEA

Open collaboration means one vendor's fix improves everyone's firmware.

Key idea & notes ▾ WHY THIS MATTERS

Shared fixes give end users more stable firmware than isolated closed development can.

SOURCE Read the source LEARN MORE doc.coreboot.org
Page Five
KEY IDEA

coreboot keeps a minimal core and hands off to a swappable payload you choose.

Key idea & notes ▾ WHY THIS MATTERS

Payload choice lets one firmware serve legacy, network, and modern UEFI boot needs.

SOURCE Read the source LEARN MORE doc.coreboot.org
Page Six
KEY IDEA

coreboot exposes flexible boot output, from splash images to multi-channel debug logs.

Key idea & notes ▾ WHY THIS MATTERS

Rich, configurable boot output makes diagnosing and tuning early startup practical.

SOURCE Read the source LEARN MORE doc.coreboot.org
Page Seven
KEY IDEA

A small trusted base plus verified boot and hardware protections shrinks the attack surface.

Key idea & notes ▾ WHY THIS MATTERS

Trusting less code and verifying each boot step makes firmware harder to compromise.

SOURCE Read the source LEARN MORE doc.coreboot.org
Page Eight
KEY IDEA

Strict coding standards and optional formal proofs make coreboot more trustworthy.

Key idea & notes ▾ WHY THIS MATTERS

Provable and disciplined code reduces the subtle bugs that plague low-level firmware.

SOURCE Read the source LEARN MORE doc.coreboot.org
Page Nine
KEY IDEA

coreboot is built so firmware updates cannot brick the machine.

Key idea & notes ▾ WHY THIS MATTERS

Safe, reversible updates remove the fear that keeps firmware dangerously out of date.

SOURCE Read the source LEARN MORE doc.coreboot.org
Page Ten
KEY IDEA

coreboot can boot in under a second on laptops and cut minutes on servers.

Key idea & notes ▾ WHY THIS MATTERS

Faster boot saves real time on desktops and meaningful downtime on server fleets.

SOURCE Read the source LEARN MORE doc.coreboot.org
Page 11
KEY IDEA

coreboot is built from source, and community distributions offer prebuilt flashable images.

Key idea & notes ▾ WHY THIS MATTERS

Prebuilt distributions let non-experts adopt coreboot without compiling from source.

SOURCE Read the source LEARN MORE libreboot.org
Page 12
KEY IDEA

The simplest way to use coreboot is buying hardware with it preinstalled.

Key idea & notes ▾ WHY THIS MATTERS

Preinstalled coreboot hardware removes the flashing risk and lets newcomers start immediately.

SOURCE Read the source LEARN MORE puri.sm
Share to LinkedIn Share to X Share to Bluesky