![]() |
|
Hardware Feature Suggestion for Quartz64: SPI Flash Hardware Write-Protect - Printable Version +- PINE64 (https://forum.pine64.org) +-- Forum: Quartz64 (https://forum.pine64.org/forumdisplay.php?fid=166) +--- Forum: Quartz64 Hardware and Accessories (https://forum.pine64.org/forumdisplay.php?fid=169) +--- Thread: Hardware Feature Suggestion for Quartz64: SPI Flash Hardware Write-Protect (/showthread.php?tid=20366) |
Hardware Feature Suggestion for Quartz64: SPI Flash Hardware Write-Protect - Independent Researcher - 08-30-2026 Hardware Feature Suggestion: SPI Flash Hardware Write-Protect & Factory-Flashed Secure Boot First of all, thank you for providing amazing open-source hardware to the community. I am a developer, privacy enthusiast, and independent researcher, and I would like to propose a simple yet high-value hardware revision for future batches of the Quartz64 or upcoming single-board computers. Currently, the board relies on DIP switches for boot priority, which is firmware-based and does not physically cut the power line for the SPI Flash write operations. For users focused on sovereign security, physical containment, and preventing persistent firmware implants (rootkits), having a Hardware Write-Protect (WP# linked to GND via a physical Jumper or a Screw mechanism)—similar to the Chromebook write-protect screw—is crucial. Adding small exposed copper jumper pads (open pads) between Pin 3 (WP#) and Pin 4 (GND) on the PCB layout would allow advanced privacy users to bridge them and achieve true physical, air-gapped read-only isolation for the Tow-Boot/SPI flash. Furthermore, for PINE64 boards that come with a pre-soldered SPI Flash from the factory, we strongly suggest shipping them with a clean, verified, and officially signed open-source bootloader (like Tow-Boot) pre-flashed out of the box. Many security-conscious buyers operate in highly compromised, untrusted, or heavily monitored network environments where flashing a clean image locally from scratch is incredibly risky or nearly impossible without immediate interception. Shipping the hardware with a factory-guaranteed clean bootloader would provide a secure and immutable root of trust immediately upon unboxing. I highly recommend offering these as design standards in your upcoming revisions, or even as an optional manufacturing configuration toggle for a small extra fee. It would make PINE64 the ultimate choice for the global privacy and secure-boot developer community. Looking forward to hearing your thoughts on this hardware implementation. |