4 hours ago
Hardware Feature Suggestion: SPI Flash Hardware Write-Protect & Factory-Flashed Secure Boot
First of all, thank you for providing amazing open-source hardware to the community. I am a developer, privacy enthusiast, and independent researcher, and I would like to propose a simple yet high-value hardware revision for future batches of the Quartz64 or upcoming single-board computers. Currently, the board relies on DIP switches for boot priority, which is firmware-based and does not physically cut the power line for the SPI Flash write operations.
For users focused on sovereign security, physical containment, and preventing persistent firmware implants (rootkits), having a Hardware Write-Protect (WP# linked to GND via a physical Jumper or a Screw mechanism)—similar to the Chromebook write-protect screw—is crucial. Adding small exposed copper jumper pads (open pads) between Pin 3 (WP#) and Pin 4 (GND) on the PCB layout would allow advanced privacy users to bridge them and achieve true physical, air-gapped read-only isolation for the Tow-Boot/SPI flash.
Furthermore, for PINE64 boards that come with a pre-soldered SPI Flash from the factory, we strongly suggest shipping them with a clean, verified, and officially signed open-source bootloader (like Tow-Boot) pre-flashed out of the box. Many security-conscious buyers operate in highly compromised, untrusted, or heavily monitored network environments where flashing a clean image locally from scratch is incredibly risky or nearly impossible without immediate interception. Shipping the hardware with a factory-guaranteed clean bootloader would provide a secure and immutable root of trust immediately upon unboxing.
I highly recommend offering these as design standards in your upcoming revisions, or even as an optional manufacturing configuration toggle for a small extra fee. It would make PINE64 the ultimate choice for the global privacy and secure-boot developer community.
Looking forward to hearing your thoughts on this hardware implementation.
First of all, thank you for providing amazing open-source hardware to the community. I am a developer, privacy enthusiast, and independent researcher, and I would like to propose a simple yet high-value hardware revision for future batches of the Quartz64 or upcoming single-board computers. Currently, the board relies on DIP switches for boot priority, which is firmware-based and does not physically cut the power line for the SPI Flash write operations.
For users focused on sovereign security, physical containment, and preventing persistent firmware implants (rootkits), having a Hardware Write-Protect (WP# linked to GND via a physical Jumper or a Screw mechanism)—similar to the Chromebook write-protect screw—is crucial. Adding small exposed copper jumper pads (open pads) between Pin 3 (WP#) and Pin 4 (GND) on the PCB layout would allow advanced privacy users to bridge them and achieve true physical, air-gapped read-only isolation for the Tow-Boot/SPI flash.
Furthermore, for PINE64 boards that come with a pre-soldered SPI Flash from the factory, we strongly suggest shipping them with a clean, verified, and officially signed open-source bootloader (like Tow-Boot) pre-flashed out of the box. Many security-conscious buyers operate in highly compromised, untrusted, or heavily monitored network environments where flashing a clean image locally from scratch is incredibly risky or nearly impossible without immediate interception. Shipping the hardware with a factory-guaranteed clean bootloader would provide a secure and immutable root of trust immediately upon unboxing.
I highly recommend offering these as design standards in your upcoming revisions, or even as an optional manufacturing configuration toggle for a small extra fee. It would make PINE64 the ultimate choice for the global privacy and secure-boot developer community.
Looking forward to hearing your thoughts on this hardware implementation.

