NitroPad NS50

https://shop.nitrokey.com/web/image/product.template/488/image_1920?unique=40f2be7
(0 review)
  • Processor (CPU)
  • RAM (DDR4)
  • Hard Disk NVMe M.2 SSD
  • Keyboard
  • Wireless interfaces
  • Webcam and microphone
  • Operating System (OS)
  • Tamper-evident packaging
  • Shipment of Nitrokey
  • Type
  • Firmware
  • Color

This combination does not exist.

1,066.50 € 1066.5 EUR 1,422.00 €

1,140.00 €

ADD TO CART

NitroShred can't be bought together with other products. Please place a separate order.

Provisioning time until shipment: 5 Work days

Worldwide Delivery

Accepted Payments:
☑ Wire transfer (SEPA)
☑ Credit card
☑ PayPal
☑ Bitcoin


### Only available with original BIOS/UEFI ###


Secure Working in Insecure Environments Thanks to Unique Hardware Protection

Do you think your computer hardware is secure? Can you rule out that in your absence no one has manipulated your computer? In a world, where most users do not have any real control over their hardware and have to blindly trust the security promises of vendors, NitroPad unlocks a refreshingly new security experience. NitroPad NS50 is significantly more secure than normal computers. With NitroPad, you'll have more control over your hardware than ever before while maintaining ease of use.

Features

  • Tamper Detection Through Measured Boot
    Thanks to the combination of the open source solutions Coreboot, Heads and Nitrokey USB hardware, you can verify that your laptop hardware has not been tampered with in transit or in your absence (so-called evil maid attack). The integrity of the TPM, the firmware and the operating system is effectively checked by a separate Nitrokey USB key. Simply connect your Nitrokey to the NitroPad while booting and a green LED on the Nitrokey will show that your NitroPad has not been tampered with. If the LED should turn red one day, it indicates a manipulation.
    As an alternative to Heads and therefore without Measured Boot, TianoCore is offered, which enables the use of Windows.


  • Deactivated Intel Management Engine
    Vulnerable and proprietary low-level hardware parts are disabled to make the hardware more robust against advanced attacks.
    The Intel Management Engine (ME) is some kind of separate computer within all modern Intel processors (CPU). The ME acts as a master controller for your CPU and has broad access to your computer (system memory, screen, keyboard, network). Intel controls the code of the ME and severe vulnerabilities have been found in the ME enabling local and remote attacks. Therefore ME can be considered as a backdoor and has been deactivated in NitroPad.


  • Preinstalled Ubuntu Linux With Full-Disk Encryption
    NitroPad ships with a preinstalled Ubuntu Linux LTS with full-disk encryption. Ubuntu is one of the most popular, stable and easiest to use Linux distributions. Switching from Windows to Linux has never been easier.

  • Optional: Preinstalled Qubes OS For Highest Security Requirements
    Instead of Ubuntu Linux, on request you can get your NitroPad with preinstalled Qubes OS and full-disk encryption.
    Qubes OS enables highly isolated working by means of virtual machines (VM). A separate VM is started for each application or workspace. This approach isolates applications and processes much more than conventional operating systems. Qubes OS keeps your system secure, even if a vulnerability has been exploited in one of the software applications used. Example: If your PDF viewer or web browser has been successfully attacked, the attacker cannot compromise the rest of the system and will be locked out once the VM is closed.
    In addition, separate virtual workspaces can be used, such as an offline workspace for secret data and an online workspace for communication. NitroPad with Qubes OS is technically similar to SINA clients (for governments), but remains transparent thanks to open source. Qubes OS is for users who want maximum security.

  • Keys Under Your Control
    All individual cryptographic keys are generated directly on the NitroPad exclusively during installation and are not stored by us. However, all individual keys can be replaced by you. Unlike "Secure Boot", the keys for securing the operating system remain under your control and do not depend on the consent of the vendor.

  • Nitrokey USB Key Included
    NitroPad comes with a Nitrokey (different models). Their security features include for example email encryption (PGP, S/MIME), secure server administration (SSH) and two-factor authentication. The Nitrokey Storage 2 additionally contains an encrypted mass storage with hidden volumes.

  • Modern Hardware
    Modern Intel processor Core i5 or i7 of the 12th generation (Alder Lake). In addition, there are numerous, high-quality (no stickers) keyboard layouts (languages) to choose from. Small and light form factor.

  • Out-of-the-Box User Experience
    With NitroPad, you don't need to take care of opening the hardware casing to flash the BIOS chip, installing and configuring Linux, or pairing the Nitrokey Pro/Storage. We do this work for you. The Nitrokey is already configured with your NitroPad so that it can be used for tamper detection without any further configuration effort.

  • Security Conscious Shipping
    To make it more difficult to intercept and manipulate your NitroPad, the NitroPad and the Nitrokey USB key can be shipped in two separate shipments if desired.

Use Cases

  • For Everyone
    NitroPad enables you to detect hardware tampering. For example, if your laptop is being inspected while crossing the border or if you leave your device unattended in a hotel or during travelling, you can check the integrity of your NitroPad with the help of the Nitrokey.

  • For Enterprises
    NitroPad can serve as a hardened workstation for certificate authorities and other use cases requiring high-security computers. On business trips, the NitroPad protects against evil maid attacks while the computer is unattended in a hotel or baggage.

  • For Governments
    Governments can use NitroPad to protect themselves against advanced persistent threats (APT) without relying on foreign proprietary technology.

  • For Journalists
    If you as an investigative journalist are serious about protecting your confidential sources, NitroPad helps you getting there.

Technical Details

  • Processor (CPU): Intel Core (Alder Lake), 12th generation, i5-1240P 4x 3.30 GHz (Turbo: 4.30 GHz) or i7-1260P 4x 3.40 GHz (Turbo: 4.70 GHz)
  • Intel Management Engine: Disabled
  • RAM: 8-64 GB, dual channel DDR4, 3200 MHz
  • Hard disk: 250-4000 GB SSD
  • Graphics: Intel Xe Graphics
  • Display: 15.6" (39.62 cm) Full HD (1920×1080), 16:9, matte, IPS-like, LED backlight, brightness: 300 cd/m², contrast ratio: 700:1
  • Audio: HD audio
  • WLAN, Bluetooth: WiFi 6, 802.11ax, 2400 Mbps, Bluetooth 5.0, Intel AX200/201 or blob-free WiFi 4, Qualcomm Atheros QCNFA222 802.11a/b/g/n, Bluetooth 4.0 (optional)
  • Webcam: 1.0 MP
  • Card reader: microSD
  • Connections:
        1 x USB 3.1 Gen. 2, Type A
        1 x USB 3.1 Gen. 2, Type C with Thunderbolt 4, charging via USB-C with 87 Watt and up to two external displays
        1 x USB 3.1 Gen. 2, Type C
        1 x HDMI (with HDCP)
        1 x combined audio input/output
        1 x RJ45 LAN Gigabit Ethernet
        1 x DC-in audio jack
  • Battery: 73 Wh, lithium-ion
  • Charger: 90 W, 19 V, 4.73 A
  • Keyboard: Keyboard backlight with four brightness levels
  • Pointer device: Integrated touchpad with Microsoft PTP multi-gesture and scroll function
  • Security: TPM 2.0, Kensington connector
  • BIOS/UEFI: Coreboot, Tianocore or Heads
  • Operating system: Linux
  • Color: Black or silver gray
  • Dimensions: 357 mm x 220.5 mm x 19.9 mm
  • Weight: approx. 1.7 kg incl. battery
  • Device condition: new
  • Scope of delivery: laptop, power adapter, power cable, Nitrokey (different models)
  • 2 years warranty
  • Illustrations similar

Restricted Standby

With Qubes OS, standby (S3 Suspend Resume) cannot be used on the NS50. Use the NitroPad NV41 instead. Apart from standby, Qubes OS works without problems. For Linux and Windows, modern standby (S0) works without problems.