EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

07.17.12

TechBytes Episode 69: Richard Stallman on Restricted Boot (UEFI), Coreboot, GRUB, and Boot Freedom

Posted in TechBytes at 8:22 am by Dr. Roy Schestowitz

Techbytes 2012

Direct download as Ogg (0:13:28, 5.5 MB)

Summary: The first part of our interview with Richard Stallman covers Restricted Boot and related issues

I first interviewed Richard Stallman about 5 years ago. Yesterday I spoke to him about the subject of much debate in the Free software world right now. Here is a transcript of our conversation.

Dr. Roy Schestowitz: I want to know how big a threat you think the so-called “secure” boot is considered to be to the Free software movement.

Richard StallmanDr. Richard Stallman: It’s a disaster. Well, except that it’s not secure boot that’s a disaster, it’s restricted boot. Those are not the same. When it’s front of the control of the user, secure boot is a security feature. It allows the user to control what programs can run on a machine and thus prevent — you might say — unexpected malware from running. We have to distinguish the unexpected malware such as viruses from the expected malware such as Windows or Mac OS or Flash Player and so on, which are also malware; they have features that hurt the user but users know what they are installing. In any case, what secure boot does is that it causes the machine to only work with (?) programs that are signed with a certain key, your keys. And as long as the user controls which keys they are, then it’s a security feature. However, it can be chained into a set of digital handcuffs when the user doesn’t control the keys. And this [is] happening.

“We have to distinguish the unexpected malware such as viruses from the expected malware such as Windows or Mac OS…”Microsoft demands that ARM computers sold for Windows 8 be set up so that the user cannot change the keys; in other words, turn it into restricted boot. Now, this is not a security feature. This is abuse of the users. I think it ought to be illegal.

It’s a matter of control by the vendor of course, not control by the user himself

Exactly, and that’s why it’s wrong. That’s why non-free software is wrong. The users deserve to have control of their computers/

I think that not only Windows is going to be an issue in fact, if you consider the fact that even a modified kernel is going to be in a position where it’s perhaps not seen as verified for execution. Right, I’m saying, it might not only be a malicious feature in case of something like Windows running on it, it’s also for — let’s say — a user of the offered operating system but it’s free if the user wants to modify the operating system, for example…

The thing is, if the user doesn’t control the keys, then it’s a kind of shackle, and that would be true no matter what system it is. After all, why is GNU/Linux better than Windows? Not just ’cause it has a different name. The reason it’s better is because it’s freedom-respecting Free software that the users control. But if the machine has restricted boot and the users can’t control the system, then it would be just as bad as Windows. So, if the machine will only run a particular version of GNU/Linux, that is a restriction feature. And I haven’t heard anyone doing that yet with GNU/Linux, but that’s what Red Hat and Ubuntu are proposing to do things — somewhat like that — for future PCs that are shipped for Windows. But it’s not exactly that. And my reason is, the users will be able to change the keys. They will be able to boot their own modified version of the system of Fedora or Ubuntu if they want. So, what Fedora and Ubuntu were proposing doesn’t go all the way there. They’re proposing to do things to make it more convenient for users to install the standard version of those systems. But if things go as it has been announced, users will still be able to change the keys and boot their own versions. So, if all the restricted boot — but it will be something that goes sort of half-way there — it’s somewhat distasteful.

“The thing is, if the user doesn’t control the keys, then it’s a kind of shackle, and that would be true no matter what system it is.”On the other hand, with Android, which is another mostly Free operating system which contains Linux but doesn’t contain GNU, it’s quite common for the product to have something equivalent to restricted boot, and people have to struggle to figure out how they can install a modified and more free version of Android. So, the presence of the kernel Linux in a system doesn’t guarantee it’s going to be better. And I’ve heard someone say — oh, it hasn’t been checked — that a particular or kind of Android device is actually using an Intel chip with restricted boot.

One of the concerns that I think is worth raising is the fact that, as far as I know, with many of the embedded devices, especially those based on ARM, I believe it’s not even possible to get into boot menu to disable so-called “secure”…

That’s where Microsoft is really going all out, because Microsoft has ordered essentially — demanded — that those shipping ARM devices for Windows 8 make it restricted boot with no way to get around it.

Yeah, which also means of course waste of… all sorts of impacts on the environment. Any time that hardware become obsolete with the operating system itself is not being used of course…

“So it’s a very damaging thing that Microsoft is doing and so we need to look for every possible way to stop them or tweak what they’re doing.”Well, it’s worse than that. It means basically that those devices, you have to throw them out if you want to escape to the free world. And this — in the past — we were able to install, to liberate a computer by installing Free software on it instead of its user-restricting operation system, and this of course was tremendously helpful to the spread of GNU/Linux because it meant that users could move to freedom. It would be much harder if they had to buy another computer to do so. So it’s a very damaging thing that Microsoft is doing and so we need to look for every possible way to stop them or tweak what they’re doing.

Well, I wanted to ask you, one of our readers — his name is Will — is asking me if you have seen any new good hardware that can take coreboot.

I’m sorry, what?

One of my readers — a guy called Will — he has asked me if you have seen any new good hardware that can take coreboot.

“So, what we really need to do is make coreboot libre, just as we make Linux libre (which doesn’t have the blobs)…”I don’t know. Basically, I don’t keep track of hardware models. I only remember their names anymore, except for the one I use, which is, the Lemote Yeelong and it doesn’t run coreboot but it will run timar [?] in GRUB, it has a Free BIOS. When it comes it has a Free BIOS, which is why I chose it. But in terms of running coreboot, well, the machine which you run coreboot on are Intel-type machines. Now, there are a couple of… there is a problem, and that is, a lot of the Intel — and also AMD — CPUs require a microcode blob, and coreboot has these microcode blobs, which is the same kind of problem as firmware blobs in Linux. So, what we really need to do is make coreboot libre, just as we make Linux libre (which doesn’t have the blobs), keep (?) the coreboot libre (which doesn’t have the blobs) and then we need to see which processors actually run adequately without any microcode blob. And we’re looking for somebody who wants to lead this project ’cause it takes work. Now, leading this project doesn’t mean that you personally get all these kinds of hardware; oh, no, it would be asking the whole community to test things, but somebody has got to ask the community to do it, spread the word, receive the responses, put them together, and publish the list. Would (?) he like to do that? If he is really interested in having the answer to this question, maybe he’d like to help get the answer, and that would help the whole community.


More from Stallman is to be published in coming days.

We hope you will join us for future shows and consider subscribing to the show via the RSS feed. You can also visit our archives for past shows. If you have an Identi.ca account, consider subscribing to TechBytes in order to keep up to date.

As embedded (HTML5):

Keywords: UEFI Coreboot GRUB GNU FSF

Download:

Ogg Theora

Past shows in this series:

Show overview Show title
Episode 66: Tim and Roy TechBytes Episode 66: First of the Second Series
Episode 67: Tim and Roy TechBytes Episode 67: Nokia Down, Android Up
Episode 68: Roy TechBytes Episode 68: Solo With Patents, Apple Bans, and Android World Domination
Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. USPTO and EPO Faking Growth by Granting Patents on Everything in Nature, But Campaigners Strike Back

    The patent microcosm is eating the world; everything under the Sun must be patented, they insist, even life itself (so they can 'pirate' the Commons and then charge us a tax for 'access' or 'license' to it)



  2. IBM Happy That Patent Quality at EPO Collapsed and It's Easy to Get Software Patents

    The EPO keeps granting illegal European Patents and the media almost never mentions this illegality because it's in too amicable a relationship (typically financial) with the EPO



  3. The Linux Foundation's Staff Uses Windows and Microsoft. Now the Foundation Outsources the Coding and Hosting, Too (to Microsoft of Course).

    The disturbing turns of the self-described "Linux" Foundation, which seems to be promoting proprietary software and even Microsoft rather than Linux and Free/Open Source software while the role or capacity of Torvalds is being gradually diminished



  4. Links 25/6/2019: Raspberry Pi 4, Ubuntu's Change of Mind, Wayland’s Weston 6.0.1

    Links for the day



  5. Patent Extremism: Stacking the Panels, the Surveys, the Hearings, the Debates

    Projection tactics would have the public believe that those who oppose corruption are simply radicals; patent polarity has come to the point where if one isn't a "true believer" in blackmail (patent trolls) or opposes bribery, then one is simply a "fringe" and akin to terrorists



  6. Links 24/6/2019: Linux 5.2 RC6, Skrooge 2.20.0, ZFS vs. OpenZFS

    Links for the day



  7. The EPO Needs a President Who Obeys the Law, Not One Who Obeys Battistelli

    Succession based on nepotism at Europe's second-largest institution served to shown how inherently broken things had become and why cover-up of injustices is nowadays paramount (not fixing the flaws/ills but merely perpetuating them)



  8. With Water (Treatment) Already Patented It Won't Take Long for Patents (and Patent Royalties) on Air

    A 'paper economy' is what Europe turns into if the current trajectory is followed (led by lawyers, not producers)



  9. Bill Gates Said He Was on a “Jihad” Against GNU/Linux, But GNU/Linux Users/Developers Engaged in Self-Defense Are Foul-Mouthed 'Microsoft Haters'?

    Microsoft, which routinely commits very serious crimes, tries to come across as some sort of philanthropy whereas those who share their work with the public (for greater good) are described as erratic, rude and unworthy of respect from corporations (outcasts basically, deprived of income source)



  10. What Patents the EPO Has Just Awarded (With a Special Reward), Not Just Granted

    The EPO's practice of elevating some patents over the other patents (European Patents) is perhaps more of a societal liability than the EPO cares to realise



  11. Required Reading: Mental State of Team Battistelli/Campinos

    On the heels of yesterday's article about Team Battistelli/Campinos, here are some recommended/required papers on the problem which likely plagues the Office



  12. Links 23/6/2019: Wine 4.11, FreeBSD 11.3 RC2

    Links for the day



  13. Microsoft Apparently Did a Patrick Durusau on Wim Coekaerts to Broaden Its Control Over GNU/Linux

    Microsoft tactics for defection and takeover of the competition (without coming across as hostile) aren't new tactics; internal documents from Microsoft explain how to achieve this



  14. EPO Directors Would be Wise to Rebel Against Team Campinos While They Still Have the Job

    As the EPO continues its bold journey towards dictatorship (where presidencies are passed between friends and ‘circles’ are former colleagues or close confidants) Techrights urges those who have power to speak out — e.g. EPO judges and Directors — to do something before it’s too late



  15. American Front Group Open Invention Network (Riding the Linux Brand) is a Proponent of Software Patents in Europe

    The impact of American multinationals in Europe is difficult to deny; in fact, we're observing the same old lobbying/lobbies still working hard albeit more covertly (typically using front groups)



  16. Say 'Hey Hi' to Software Patents

    Using the “AI” (“HEY HI”) hype the ‘community’ of patent maximalists hopes that every little (and possibly very old) algorithm will suddenly sound amazing and innovative — to the point where it becomes unthinkable to deny a patent monopoly on it



  17. A Personal Note From Ted MacReilly (How Microsoft Works Against GNU/Linux)

    A tongue-in-cheek write-up highlighting the ways Microsoft insiders think and how they strategise against GNU/Linux and Free/libre software



  18. The Linux Foundation's New Vice Chair, Wim Coekaerts, Worked for Microsoft

    The Linux Foundation is boosting the Microsoft boosters and calls that "community"



  19. Links 21/6/2019: GNOME 3.33.3, 32-Bit Support Further Neglected, DragonFlyBSD 5.6.1 Released

    Links for the day



  20. Leaked: Harassment of EPO Directors by Team Campinos

    “New BIT organisation and staff changes,” a novel kind of newspeak, means that Directors are being severely punished without due process at all (“hidden disciplinary measure without disciplinary proceedings”)



  21. Patent Professionals in Europe Have Devolved Into a Marketing Industry

    Lies, buzzwords and hype waves is all that the patent bubble in Europe boils down to these days; loads of bogus patents get granted only for European judges to smack these down (if one can afford the court battle)



  22. Almost Six Months After Iancu Said He Would Make Software Patents Great Again Nothing Has Actually Changed

    We're just a fortnight away from the ludicrous plan of Iancu celebrating 6 months (without accomplishing anything)



  23. Links 20/6/2019: Kubernetes 1.15, Alpine 3.10.0 and Librem 5 June Software Update

    Links for the day



  24. Ignore the EPO's Dumb Festival and Focus on the Abuses Against the Workforce and Its Quality of Work

    Don’t lose sight of the appalling behaviour of the management of the EPO; the last thing it wants is press coverage about its gross abuses and corruption — an aspect it spent literally millions of euros to bury (gaming the news cycle)



  25. Microsoft Attempting to Destroy the Careers of Its Critics, Including Free Software Proponents

    Microsoft isn't changing and has not changed; the tactics described above are still being used, even by its "Open Source" (or "Open at Microsoft") people, who did this to me



  26. Links 19/6/2019: Linux Mint Vs Vista 10, Qt 5.13 Released

    Links for the day



  27. The Linux Foundation's Business Model

    The Linux Foundation's plan, illustrated



  28. Links 18/6/2019: i386 Abandoned by Canonical and a New osquery 'Community'

    Links for the day



  29. Indifference or Even Hostility Towards Patent Quality Results in Grave Injustice

    The patent extravaganza in Europe harms small businesses the most (they complain about it), but administrative staff at patent offices only cares about the views of prolific applicants rather than the interests of citizens in respective countries



  30. Links 18/6/2019: CentOS 8 Coming Soon, DragonFly BSD 5.6 Released

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts