Desktop hardware for higher HSI levels
Privacy Guides Community [Unofficial]
June 6, 2026
Recently I’m preparing to update my desktop (most likely to use Secureblue with full AMD and AM5) and have a few questions regarding its hardware. I’m aware that security of desktop is mediocre compared to mobile, nevertheless I aim for something reasonably secure and with higher HSI level. From what I understand, you want Pro CPU for HSI 4, but with desktop motherboards you may be not even able to reach 2 or 3, as some security features may be disabled by OEM or even not available.
Hence my question, can you recommend a desktop motherboard (preferably AM5 to use with Ryzen CPU) that has a decent support and updates, and lets you reach HSI 2/3, or even 4 with Pro CPU? From my understanding motherboard is a main bottleneck for that, but maybe I should also pay attention to something else.
Also, does anyone have an opinion on Dasharo Coreboot? If I understand it correctly, flashing it on a motherboard replaces its firmware completely and from now on you get all updates and features from Dasharo team, so in theory it should let you get better support, updates and higher HSI level that what OEM motherboard would normally have.
@dngray I remember in other topic you mentioned Pro CPUs, but what exactly are benefits of using one? I know you need them for HSI 4 and encrypted RAM, but are they worth getting for desktop, assuming physical attacks are out of scope?
Discussion in the ATmosphere