NitroPC - Leistungsfähiger und sicherer Mini PC

Wir freuen uns, unseren neuen NitroPC zu veröffentlichen - ein sicherer Mini-PC mit neuester Intel i7 CPU (10. Generation) und vollständig quelloffener Firmware und Software.

Leistungsfähige, aktuelle Hardware

Der NitroPC verfügt über einen aktuellen Intel Core i7-10510U Prozessor der 10. Generation mit bis zu 4,9 GHz und über eine m.2 SSD mit 6 Gb/s, und kann damit für leistungshungrige Anwendungen wie z.B. Programmierung/Kompilierung und Grafikanwendungen verwendet werden. Natürlich ist er damit auch für Büro- und Web-Anwendungen ausreichend dimensioniert.

Open Source Firmware/BIOS

Die Firmware ("BIOS") besteht aus den Open-Source-Systemen Coreboot und Tianocore UEFI. Dies ermöglicht die unabhängige Sicherheits-Überprüfung der Firmware und verhindert unerkannte Hintertüren. Zudem bootet der PC schnell und zukünftige Weiterentwicklungen sind möglich. Es lassen sich alle PC-Betriebssysteme inkl. Windows verwenden.

Deaktivierte Intel Management Engine

Verwundbare und proprietäre Low-Level-Hardwareteile werden deaktiviert, um die Hardware robuster gegen fortgeschrittene Angriffe zu machen. Die Intel Management Engine (ME) ist eine Art separater Computer innerhalb aller modernen Intel Prozessoren (CPU). Die ME fungiert als Master-Controller für Ihre CPU und hat weitgehenden Zugriff auf Ihren Computer (Systemspeicher, Bildschirm, Tastatur, Netzwerk). Intel kontrolliert den Code der ME und es wurden bereits schwere Schwachstellen in der ME gefunden, die lokale und entfernte Angriffe ermöglichen. Daher kann ME als Hintertür betrachtet werden und ist im NitroPC deaktiviert.

Vorinstalliertes Ubuntu Linux mit Festplattenverschlüsselung

NitroPC wird mit einem vorinstallierten Ubuntu Linux 20.04 LTS mit vollständiger Festplattenverschlüsselung ausgeliefert. Ubuntu ist eine der beliebtesten, stabilsten und am einfachsten zu bedienenden Linux-Distributionen. Der Umstieg von Windows auf Linux war noch nie so einfach.

Optional: Vorinstalliertes Qubes OS für höchste Sicherheitsanforderungen

Anstelle von Ubuntu Linux erhalten Sie auf Wunsch Ihren NitroPC mit vorinstalliertem Qubes OS 4.0 und vollständiger Festplattenverschlüsselung. Qubes OS ermöglicht stark abgeschottetes Arbeiten mittels virtueller Maschinen (VM). Für jede Anwendung bzw. jeden Arbeitsbereich wird eine eigene VM gestartet. Dieser Ansatz isoliert Anwendungen und Prozesse wesentlich stärker als herkömmliche Betriebssysteme. Qubes OS hält Ihr System sicher, auch wenn eine Schwachstelle in einer der verwendeten Software ausgenutzt wurde. Beispiel: Wenn Ihr PDF-Anzeigeprogramm oder Webbrowser erfolgreich angegriffen wurde, kann der Angreifer den Rest des Systems nicht kompromittieren und wird ausgesperrt, sobald die VM geschlossen wird. Zudem können getrennte virtuelle Arbeitsumgebungen verwendet werden, z.B. eine Offline-Arbeitsumgebung für geheime Daten und eine Online-Arbeitsumgebung zur Kommunikation. NitroPC mit Qubes OS ist technisch ähnlich wie SINA Clients (für Behörden), bleibt dabei aber transparent dank Open Source. Qubes OS ist für Benutzer, die maximale Sicherheit wünschen.

Versiegeltes Gehäuse

Um das Manipulieren Ihres NitroPCs zu erschweren, werden die Gehäuseschrauben individuell versiegelt. Wir senden Ihnen Fotos der Versiegelungen, mit denen Sie erkennen können, ob das Gehäuse während des Transports oder zu einem späteren Zeitpunkt unberechtigt geöffnet wurde.

Anwendungsfälle

Für jeden

Mit dem NitroPC müssen Sie nicht auf die Sicherheit proprietärer BIOS-Firmware oder auf die Hintertür Intel Management Engine vertrauen. Stattdessen basiert der sichere NitroPC vollständig auf Open Source Software. NitroPC wird mit vorinstallierter Festplattenverschlüsselung ausgeliefert und - auf Wunsch - mit dem hochsicheren Qubes OS. Da er über einen leistungsfähigen Intel i7 Prozessor der 10. Generation verfügt, ist der NitroPC auch für leistungshungrige Anwendungen geeignet.

Für Unternehmen

Der NitroPC kann als gehärteter Arbeitsplatz für Zertifizierungsstellen (Certificate Authorities) und andere Anwendungsfälle dienen, die Hochsicherheits-Rechner erfordern.

Für Behörden

Behörden können sich mit dem NitroPC vor Advanced Persistent Threats (APT) schützen, ohne sich auf fremde proprietäre Technologien verlassen zu müssen.

Für Journalisten

Wenn Sie es als investigativer Journalist mit dem Schutz Ihrer vertraulichen Quellen ernst meinen, hilft Ihnen NitroPC dabei.

Als Mini-Server

Der NitroPC eignet sich als kleiner Server für zu Hause und im Büro.
 

NitroPC im Shop

25.7.2024

Comments

No, there are no additional measures against video signal eavesdropping
World it run Witze a Ryzen 7 5700g ?
There is no Ryzen configuration available for the NitroPC currently.
Hi, when you install Qubes 4.0 does it set up sys-USB correctly? I mean does sys-USB work and contain all the USB outlets and then work the mouse, monitor, etc.? Also do you know of any reason why the NitroPC would not support Qubes 4.1? Thanks,
Yup, we can confirm that mice, keyboards work without further configuration out-of-the-box with Qubes. Further we don't see any readon why the NitroPC should not work with Qubes 4.1, we've been already playing around with the 4.1 alpha release and did not encounter any issues so far.
Hi again, further to my last question . . . has the NitroPC got a '14-1 mother board header' and would that mean it could accept an after market TPM like the ASUS Tpm-m R2.0 14 Pin Trusted Platform Module E241819 or the MSI MS-4462 TPM 2.0 Motherboard Module? Could you buy one, plug it in and use it as in the NitroPad use case? Thanks,
There is no such header on the motherboard and we are not aware of any other TPM modules, which might work. So, the answer is: no, this is not possible.
Hello, can I install any linux distro on NitroPC? (I'm asking because on your wiki you have dedicated OS images for this device) How iso from your docs differ from those provided by os maintainers (e.g. canonical)?
Generally you can install any distribution which supports UEFI. We provide the OEM iso-images for transparency reasons, as those are the ones being used for installation before they are shipped. They differ just marginally from the original iso images with things like: oem start (on first boot set up a user etc.), nitrokey-app is pre-installed, some amazon ads are removed. You can see the details on github in the repositories ending with -oem, e.g., https://github.com/Nitrokey/ubuntu-oem
Hello, Can you tell me what is the generation of USB 3 and USB-C? Is it USB 3.2 Gen 2 or Gen 1?
The Type-A slots are USB 3.0, the Type-C Slot is USB 3.1 without monitor delivery.
With which desktop environment is the NitroPC delivered when ordering Debian 10 German? Could it be possible to have only the desktop of my choice preinstalled?
The package 'task-gnome-desktop' is installed, which will lead to a gnome based desktop. Our products are prepared for shipping using fully automated tools to maximize security and minimize efforts, please understand that we cannot manually install alternative/additional software without compromising the aforementioned.
Ordered on December 7th, but still haven't received a delivery confirmation. Are there currently delivery delays due to the pandemic?
Currently the main reason for delays is the holiday-season i.e., December. I would suggest to wait some more days, or write an E-Mail to [email protected] with your order-number (SOxxxxxx) to check for your status.
Good day! Would you mind if I share your blog with my facebook group? There's a lot of people that I think would really appreciate your content. Please let me know. Many thanks
Of course not, feel free to share it
What about the heat in that small case? I have concerns that either temperature warnings might pop up or the fan (if there is one) keeps blowing all the time?
Hey, inside a NitroPC a "U"-type CPU is working, which is mostly used within laptops. There have been no reports about temperature warnings popping up and during regular use the fan noise rarely can be noticed.
Dear, 2 questions: 1. I can see that i7-10510U has possibility to set TDP-down to 10 W. Is it possible to set NitroPC to have 10 W permanently? 2. Is it possible to change/add hard drive without loosing guarantee?
1. Yes, technically this would be possible, but we do not offer this right now. So sorry, this is not possible within the scope of this product. 2. Yes, you can replace the hard-drive w/o voiding the warranty - obviously the hard disk itself cannot be used as a reason for the warranty anymore.
Do you mind if I quote a couple of your posts as long as I provide credit and sources back to your site? My blog site is in the exact same niche as yours and my visitors would truly benefit from a lot of the information you present here. Please let me know if this okay with you. Thanks a lot!
Hey Kira, sure no problem feel free to quote and link our posts, while providing credit and sources.
Hi, please consider an audio-out port on the rear panel for the next revision. This allows to conveniently connect speakers in the back and head phones can be connected to the front port without having to constantly reconnect speakers and headphones, and without having to connect speakers to the front port which is really not ideal. Majority of mini PCs don't have rear audio ports which is really disappointing and it forces me to build my own mini PC on an ITX board. Thanks
Hey thanks for the input, we'll consider this if possible for a next revision. Generally you could also try a USB soundcard for your use-case, maybe this helps.
Thanks for your reply! Yes, I've considered using a USB sound card but the downside is that the speakers will not be automatically switched off when I connect head phones to the front port. Also external sound cards often have poor quality of the mic port.
Question, is boot guard disabled in the nitroPC? also, if you put coreboot and intel me in disabled mode, is there any way that it can be undone? Aka, supposedly there is something called Intel's Firmware Support Package Also, I thought intel's 10th gen, or for that matter even as early as their 4th gen and onward blocked people from using the graphics onboard or the sound as well from working without blobs. In essence, wondered if there are any enabled remote backdoors enabled that still work when you do your changes to the NitroPC. And as a last note, wondering if you guys ever plan to make your own, durable, low heat usage netbook type device with the above ideas in place, more or less. I probably will send you a message via email at some point, regarding this, for more info.
Intel ME is to the best of our knowledge disabled through the mechanism common for the 10th gen. Although there still is the FSB blob from intel inside the coreboot image otherwise the system would not work. This means that the risk for backdoors is significantly reduced, although there might be risks we don't know due to the FSB, but as of today we are not aware of any. Building our own netbook type device with your ideas is not really possible for us as Nitrokey at this point.
Hello, Are you planning, in the near future, on offering a newer version of the nitro PC with more recent hardware? Thanks
Hey hey, nope - not in the near future.
Thanks
Is it possible to install the most recent an encrypted version of Debian or MX or Arch on the NitroPC? I remember that some time ago there was an issue with Heads on your Laptops, so that Debian 11 couldn't be installed right away. I don't know if it ever was a problem on the PC. I´m just asking. Second question: can I connect a 4K display, i.e. is the graphics adapter in NitroPC good enough? Do you habe the NitroPC in stock?
Yes, there is no issue in installing latest Distributions on the NitroPC, it comes with Tianocore, which is a UEFI enabled firmware. For displays, please check the product description in the shop (i.e., the display details), generally 4K works fine - it's better to use DisplayPort compared to HDMI. The shop gives an accurate indication, if some product is not in stock, so you can rely on that. As of today the NitroPC is in stock.
Do you delivery it to Russian federation?
Nope, sorry we do not offer shipping to Russia currently.
What ram is compatible with the nitro pc mini I have CORSAIR Vengeance SODIMM 32GB (2x16GB) DDR4 3200MHz but having issues with unresponsive shell
For 32GB we usually use Crucial CT32G4SFD832A. Please try to avoid asking the same question on multiple channels if possible, thank you.
The last question is more than 15 months old, so I would like to ask again: Can you promise your customers a newer version of the Nitro PC in the near future? Thank you very much!
We are currently investigating a new revision, thus we have at least some hopes that the NitroPC will be available again - but currently we have no specific candidate for a successor with a more powerful CPU.
Thanks for your reply! My use case would be a home server with a low power consumption. It could it be a good idea to offer at least two CPUs for different use cases. ;-)

Pages

Add new comment

Fill in the blank.