Bonum Certa Men Certa

Microsoft Fanatics Were Wrong, Linux Indeed Attacked by UEFI (Updatedx2)

Ed Bott



Summary: More information about UEFI leaves no doubt about Microsoft's intentions to sabotage and cheat

IN OUR previous posts about UEFI (aka "secure" boot) [1, 2, 3] we showed that Microsoft was still a corrupt company looking to break the rules to make money. Aaron Williamson from the SFLC writes the article "Microsoft confirms UEFI fears, locks down ARM devices":



At the beginning of December, we warned the Copyright Office that operating system vendors would use UEFI secure boot anticompetitively, by colluding with hardware partners to exclude alternative operating systems. As Glyn Moody points out, Microsoft has wasted no time in revising its Windows Hardware Certification Requirements to effectively ban most alternative operating systems on ARM-based devices that ship with Windows 8.

The Certification Requirements define (on page 116) a "custom" secure boot mode, in which a physically present user can add signatures for alternative operating systems to the system's signature database, allowing the system to boot those operating systems. But for ARM devices, Custom Mode is prohibited: "On an ARM system, it is forbidden to enable Custom Mode. Only Standard Mode may be enable." [sic] Nor will users have the choice to simply disable secure boot, as they will on non-ARM systems: "Disabling Secure [Boot] MUST NOT be possible on ARM systems." [sic] Between these two requirements, any ARM device that ships with Windows 8 will never run another operating system, unless it is signed with a preloaded key or a security exploit is found that enables users to circumvent secure boot.


Glyn Moody adds:

In December 2011, Microsoft published a document entitled "Windows Hardware Certification Requirements" for client and server systems. As the introduction explains:
This release to web (RTW) document contains the Windows Hardware Certification requirements for Windows 8 Certified Systems. These requirements are Microsoft’s guidelines for designing systems which successfully meet Windows performance, quality, and feature criteria, to assure the optimum Windows 8 computing experience. Successfully following this guidance will allow a partner to receive certification for their system.
On page 116 of this document, there are some details about the circumstances under which Secure Boot can be disabled:
MANDATORY: Enable/Disable Secure Boot. On non-ARM systems, it is required to implement the ability to disable Secure Boot via firmware setup. A physically present user must be allowed to disable Secure Boot via firmware setup without possession of Pkpriv. Programmatic disabling of Secure Boot either during Boot Services or after exiting EFI Boot Services MUST NOT be possible. Disabling Secure MUST NOT be possible on ARM systems.
This confirms that it is indeed possible to disable Secure Boot - but only on non-ARM systems (i.e. traditional PCs.) In other words, it would appear that Microsoft is still locking out GNU/Linux from installation on ARM-based Windows 8 machines.

So this leaves me confused. The document was published some time after Microsoft's post where it states "Microsoft does not mandate or control the settings on PC firmware that control or enable secured boot from any operating system other than Windows", and yet it seems to contradict it. So what's going here? Was Microsoft's blog statement only about non-ARM systems, as the new documentation suggests? And if so, why the discrimination? And finally, is ARM really happy to see Microsoft apparently locking out GNU/Linux from its systems in this way? Let's hope Microsoft can clarify this situation as it did on the previous occasion.


This leaves no room for excuses. Microsoft's bribed systematic liars/spinners, such as Ed Bott, were just trying to keep regulators away. It's time to nail down Microsoft for interfering with fair competition in more than a single way. Just because Microsoft is imploding or collapsing does not entitle it/give it a right to sabotage competitors. This harms everyone.

Update: SJVN weighs in shortly afterwards:

Microsoft and its vendor friends said that there’s no Windows 8 plot to lock other operating systems from Windows 8 devices, but now we know Microsoft was not telling the whole truth.

Journalist Glyn Moody dug around Microsoft’s Windows Hardware Certification Requirements for Windows 8 client and server systems and found on page 116 that will Windows 8 Secure Boot can be disabled: on Intel systems, “Disabling Secure [Boot] must not be possible on ARM systems.”


Update #2: Microsoft now receives the Slashdot treatment. As one person put it: "Oh boy, the lawyers must be rubbing their hands over this. The flaw in Microsoft's aim of course is that next to no one wants a Microsoft mobile gadget."

Comments

Recent Techrights' Posts

Oracle's Debt Grew by Over 50 Billion Dollars in 6 Months
Larry Ellison spent a lot of money buying a lot of the corporate media
What Linus (Torvalds, the Linux Dude) Meant by "Show Me the Code"
"Show Me the Code" is a common cultural reference
XBox Will Not Last Much Longer, XBox Chief Admits Problems
Microsoft's latest "results"
What May 1 Means to Us (and to Many Others)
To me, May 1 means something
Microsoft Lunduke is 'Pulling a Garrett' by Turning Technical and Legal Debate Over Rust Into a 'Trans Debate'
Don't fall for the demagogue
Microsoft "Buyout" Offer is Less Than One Year's Salary
So our assumption about this was correct
 
Gemini Links 02/05/2026: Leaving Session, Alhena 5.5.7, and Slop Failing Customers
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 01, 2026
IRC logs for Friday, May 01, 2026
Links 01/05/2026: Microsoft 'Headcount' Decreasing, Apple Quietly Killing Vision Pro
Links for the day
In Praise of Debian
30 hours ago we began an upgrade
Yes, GNU/Linux Can Run on Playstation 5, But Don't Buy It, Learn From Sony's Past of Rootkit and PS3 Betrayal
Millions of Playstation 3 owners will never forget what Sony did to them
Dealing With Demagogue in Free Software
Don't spread their ideology and never participate in any of their projects
Links 01/05/2026: Regulatory Trouble for Apple, Now Even Mozilla Pushes Back Against Google
Links for the day
The Corrupt Lecture the Non-Corrupt - Part X - European Patent Office Managers Have Crossed Red Lines, According to Themselves
The girlfriend of the President of the European Patent Office (EPO) is trying to muzzle EPO critics
Techrights is Still Growing, Attacking Techrights Does Not Weaken the Community
Bullying us for 2+ years does not result in fear, it results in us feeling more emboldened and motivated
SLAPP Censorship - Part 63 Out of 200: Graveley as a Stripped-Down Version of Garrett in the Particulars of Claim (5RB Barrister Could Do This in One Minute)
Lazily and sloppily, it looks like the barrister took Garrett's claims and tweaked them a little (shortened) for Graveley
Lots of People Leave IBM, Today IBM Has About 1,000 Workers Fewer Than Yesterday
Confluent "last day" for 800+ people
Been a Very Busy Week
Next week, as we have no upgrades to prepare for, we should be able to publish at the usual pace of 20+ pages per day
In New Letter Sent to Chair and Heads of Delegation of the Administrative Council of the European Patent Organisation the Staff Union Explains How to End European Patent Office Strikes
If Campinos continues to behave as he does right now, the Council can show him the door
Links 01/05/2026: Poems and Continuous Privacy Policy
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 30, 2026
IRC logs for Thursday, April 30, 2026
Microsoft Debt Rose Almost $50 Billion Since We Moved to Debian
GAFAM has a new name for debt
Google News Sloppy Again
Today was disappointing
European Patent Office Management Mocked for Trying to 'Bribe' Staff With a Little Food
The Office is having a crisis; a little breakfast treat won't solve it
SLAPP Censorship - Part 62 Out of 200: Garrett and Graveley Issue Astounding Copy-Paste Masterpiece Asserting Publicly-Accessible Embarrassing Facts Must Remain Hidden
Are Garrett and Graveley twins separated at birth but joined by GNOME and Microsoft?
Links 30/04/2026: Barrage of Lawsuits Against Slop, Microsoft's Stock Crashes
Links for the day
Microsoft Says Mass Layoffs Are Coming and Puts a Price on Them
Microsoft will shrink
The Corporate Media Intentionally Overlooks How Google's Debt Trebles in Just Over a Year
We'll soon see how much more money Microsoft has borrowed
(Trigger Warning) Jeremy Bicha & Debian-Edu, TecKids, Ubuntu incest scandal at DebConf25
Reprinted with permission from Daniel Pocock
Upgrade Successful
we had a downtime of only 1-2 minutes overall (for two reboots)
Links 30/04/2026: Slop Industry Cannot Keep Up With Bills, "The World Is Getting Too Hot to Feed Itself"
Links for the day
Then Come the DDoS Attacks
Is someone trying to 'kill' Techrights?
The Corrupt Lecture the Non-Corrupt - Part X - Deliberately Violate European Patent Convention (EPC), Tolerate Cocaine Use in Management, Hide That From Staff and Stakeholders
The "Alicante Mafia" (as staff calls it) is a disgrace to Europe
The Register MS Running Spam Pieces for Huawei, a Banned Company
Money does not excuse bad behaviour
Apparently Last Day for Nearly 1,000 Confluent Workers IBM Laid Off Last Month
IBM is a dying company pretending to be strong because of its age
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, April 29, 2026
IRC logs for Wednesday, April 29, 2026
Gemini Links 30/04/2026: Outdoor Time, Old Computers, and Joining Geminispace
Links for the day