EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS


TechBytes Episode 69: Richard Stallman on Restricted Boot (UEFI), Coreboot, GRUB, and Boot Freedom

Posted in TechBytes at 8:22 am by Dr. Roy Schestowitz

Techbytes 2012

Direct download as Ogg (0:13:28, 5.5 MB)

Summary: The first part of our interview with Richard Stallman covers Restricted Boot and related issues

I first interviewed Richard Stallman about 5 years ago. Yesterday I spoke to him about the subject of much debate in the Free software world right now. Here is a transcript of our conversation.

Dr. Roy Schestowitz: I want to know how big a threat you think the so-called “secure” boot is considered to be to the Free software movement.

Richard StallmanDr. Richard Stallman: It’s a disaster. Well, except that it’s not secure boot that’s a disaster, it’s restricted boot. Those are not the same. When it’s front of the control of the user, secure boot is a security feature. It allows the user to control what programs can run on a machine and thus prevent — you might say — unexpected malware from running. We have to distinguish the unexpected malware such as viruses from the expected malware such as Windows or Mac OS or Flash Player and so on, which are also malware; they have features that hurt the user but users know what they are installing. In any case, what secure boot does is that it causes the machine to only work with (?) programs that are signed with a certain key, your keys. And as long as the user controls which keys they are, then it’s a security feature. However, it can be chained into a set of digital handcuffs when the user doesn’t control the keys. And this [is] happening.

“We have to distinguish the unexpected malware such as viruses from the expected malware such as Windows or Mac OS…”Microsoft demands that ARM computers sold for Windows 8 be set up so that the user cannot change the keys; in other words, turn it into restricted boot. Now, this is not a security feature. This is abuse of the users. I think it ought to be illegal.

It’s a matter of control by the vendor of course, not control by the user himself

Exactly, and that’s why it’s wrong. That’s why non-free software is wrong. The users deserve to have control of their computers/

I think that not only Windows is going to be an issue in fact, if you consider the fact that even a modified kernel is going to be in a position where it’s perhaps not seen as verified for execution. Right, I’m saying, it might not only be a malicious feature in case of something like Windows running on it, it’s also for — let’s say — a user of the offered operating system but it’s free if the user wants to modify the operating system, for example…

The thing is, if the user doesn’t control the keys, then it’s a kind of shackle, and that would be true no matter what system it is. After all, why is GNU/Linux better than Windows? Not just ’cause it has a different name. The reason it’s better is because it’s freedom-respecting Free software that the users control. But if the machine has restricted boot and the users can’t control the system, then it would be just as bad as Windows. So, if the machine will only run a particular version of GNU/Linux, that is a restriction feature. And I haven’t heard anyone doing that yet with GNU/Linux, but that’s what Red Hat and Ubuntu are proposing to do things — somewhat like that — for future PCs that are shipped for Windows. But it’s not exactly that. And my reason is, the users will be able to change the keys. They will be able to boot their own modified version of the system of Fedora or Ubuntu if they want. So, what Fedora and Ubuntu were proposing doesn’t go all the way there. They’re proposing to do things to make it more convenient for users to install the standard version of those systems. But if things go as it has been announced, users will still be able to change the keys and boot their own versions. So, if all the restricted boot — but it will be something that goes sort of half-way there — it’s somewhat distasteful.

“The thing is, if the user doesn’t control the keys, then it’s a kind of shackle, and that would be true no matter what system it is.”On the other hand, with Android, which is another mostly Free operating system which contains Linux but doesn’t contain GNU, it’s quite common for the product to have something equivalent to restricted boot, and people have to struggle to figure out how they can install a modified and more free version of Android. So, the presence of the kernel Linux in a system doesn’t guarantee it’s going to be better. And I’ve heard someone say — oh, it hasn’t been checked — that a particular or kind of Android device is actually using an Intel chip with restricted boot.

One of the concerns that I think is worth raising is the fact that, as far as I know, with many of the embedded devices, especially those based on ARM, I believe it’s not even possible to get into boot menu to disable so-called “secure”…

That’s where Microsoft is really going all out, because Microsoft has ordered essentially — demanded — that those shipping ARM devices for Windows 8 make it restricted boot with no way to get around it.

Yeah, which also means of course waste of… all sorts of impacts on the environment. Any time that hardware become obsolete with the operating system itself is not being used of course…

“So it’s a very damaging thing that Microsoft is doing and so we need to look for every possible way to stop them or tweak what they’re doing.”Well, it’s worse than that. It means basically that those devices, you have to throw them out if you want to escape to the free world. And this — in the past — we were able to install, to liberate a computer by installing Free software on it instead of its user-restricting operation system, and this of course was tremendously helpful to the spread of GNU/Linux because it meant that users could move to freedom. It would be much harder if they had to buy another computer to do so. So it’s a very damaging thing that Microsoft is doing and so we need to look for every possible way to stop them or tweak what they’re doing.

Well, I wanted to ask you, one of our readers — his name is Will — is asking me if you have seen any new good hardware that can take coreboot.

I’m sorry, what?

One of my readers — a guy called Will — he has asked me if you have seen any new good hardware that can take coreboot.

“So, what we really need to do is make coreboot libre, just as we make Linux libre (which doesn’t have the blobs)…”I don’t know. Basically, I don’t keep track of hardware models. I only remember their names anymore, except for the one I use, which is, the Lemote Yeelong and it doesn’t run coreboot but it will run timar [?] in GRUB, it has a Free BIOS. When it comes it has a Free BIOS, which is why I chose it. But in terms of running coreboot, well, the machine which you run coreboot on are Intel-type machines. Now, there are a couple of… there is a problem, and that is, a lot of the Intel — and also AMD — CPUs require a microcode blob, and coreboot has these microcode blobs, which is the same kind of problem as firmware blobs in Linux. So, what we really need to do is make coreboot libre, just as we make Linux libre (which doesn’t have the blobs), keep (?) the coreboot libre (which doesn’t have the blobs) and then we need to see which processors actually run adequately without any microcode blob. And we’re looking for somebody who wants to lead this project ’cause it takes work. Now, leading this project doesn’t mean that you personally get all these kinds of hardware; oh, no, it would be asking the whole community to test things, but somebody has got to ask the community to do it, spread the word, receive the responses, put them together, and publish the list. Would (?) he like to do that? If he is really interested in having the answer to this question, maybe he’d like to help get the answer, and that would help the whole community.

More from Stallman is to be published in coming days.

We hope you will join us for future shows and consider subscribing to the show via the RSS feed. You can also visit our archives for past shows. If you have an Identi.ca account, consider subscribing to TechBytes in order to keep up to date.

As embedded (HTML5):

Keywords: UEFI Coreboot GRUB GNU FSF


Ogg Theora

Past shows in this series:

Show overview Show title
Episode 66: Tim and Roy TechBytes Episode 66: First of the Second Series
Episode 67: Tim and Roy TechBytes Episode 67: Nokia Down, Android Up
Episode 68: Roy TechBytes Episode 68: Solo With Patents, Apple Bans, and Android World Domination
Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New

  1. Links 23/10/2016: Alcatel's New Android Smartphones, Another Honorary Doctorate for Stallman

    Links for the day

  2. Open Letter Exposing the Farce Which Was Battistelli's 'Social Conference' Coinciding With Further (New) Attacks on EPO Staff Representatives

    A detailed letter reveals legitimate concerns expressed by staff representatives at the EPO ahead of the so-called Social Conference, in which we have highlighted severe factual flaws

  3. Translation of Latest Rant From French MP Philip Cordery About Benoît Battistelli's Abuses at the EPO

    Philip Cordery crosses horns with Benoît Battistelli, who has become a source of embarrassment for France with his autocratic tendencies and misguided policies that rapidly ruin the European Patent Office (EPO)

  4. Battistelli-Commissioned PwC ‘Study’: Leaked Document Shows PwC's Dishonesty and Misrepresentation of EPO Staff

    An in-depth analysis (but not comprehensive, just preliminary) of the so-called 'study' from PwC, which basically did what it was paid for (pay to say)

  5. Links 22/10/2016: Deus Ex for GNU/Linux, Global DDoS (DNS)

    Links for the day

  6. Battistelli-Commissioned PwC ‘Study’: Survey Comparison Shows Serious Deterioration and Efforts by PwC to Disguise the Truth

    The latest output from PwC turns out to be even worse than initially thought, indicating that not only did it find a degradation in the EPO but also attempted to hide/obscure it

  7. EPO Teaser - The "Iberian Connection" - Some Photos of García-Escudero and His Royal/Government Connections

    A look at the undeniably close connections between Mr. García-Escudero and the most powerful people in Spain

  8. Disruption to Site's Service

    A technical note about why Techrights has not been publishing many articles recently

  9. Links 21/10/2016: MPV 0.21, Mad Max for GNU/Linux

    Links for the day

  10. EPO Caricature: Battistelli's High Five

    Another cartoon about the sad state of the EPO

  11. Battistelli Ruins Not Only the EPO But Also the Whole of Europe By Ushering in Software Patents That Patent Trolls Love So Much

    Battistelli's bad leadership at the EPO threatens to bring to Europe all the ills and menaces of the patent system in the United States

  12. EPO Spokesman Lies to IP Watch in Order to Save Face and Save the King (Battistelli)

    Rewriting history (revisionism) regarding Battistelli and what was demanded amidst abusive behaviour from him

  13. Unitary Patent (UPC) is Dead, But 'Managing IP' and Selfish Patent Law Firms Still Try to Resurrect It

    The latest attempts to shore up the Unitary (or Unified) Patent Court and who's behind it other than the usual suspects

  14. Links 20/10/2016: Linux 4.10 Preview, ONF and ON.Labs to Merge

    Links for the day

  15. Battistelli-Commissioned PwC 'Study': The Raw Outcome Shows Distortion of the Facts at the EPO's Notorious 'Social Conference'

    Results of the Staff Survey carried out by PwC, in order to provide some propaganda for Battistelli's expensive Social Conference

  16. Addendum: EPO's Alberto Casado Cerviño, WIPO's Francis Gurry, and EUIPO's Archambeau

    Photos taken as part of an IP event which took place in Riga (Latvia) in March 2015

  17. Worrisome Connections Between EPO VP2 Alberto Casado Cerviño and Patricia García-Escudero Márquez

    Exploring the potential conflicts of interests implicating the EPO's Boards of Appeal Committee

  18. Site's Infrastructure Under Attack and Upgrades Ahead of Major New Publications

    Protections for the Web site have been improved and capacity increased in order to avoid or at least prepare for another week of abusive/spam traffic

  19. Team Battistelli's Conspiracy Theory: SUEPO is Behind Everything, EPO Management is Trying to Tell the Media

    Attempts to blame SUEPO, the staff union of the EPO, even though SUEPO has nothing to do with articles that are critical of the EPO while many thousands of EPO employees are disgruntled

  20. Links 19/10/2016: Canonical Livepatch Service, Plasma Plans

    Links for the day

  21. The 'Sarah Sharps' of Microsoft: Not the Kind of Scandal the Media Cares Enough to Write About

    Another example of the large (industrial) scale of sexual discrimination at Microsoft -- a company that tries to advertise itself as diverse or tolerant and stigmatise Free/Open Source software (FOSS) as intolerant and/or not diverse

  22. EPO Caricature: EQE Questions

    The latest EPO cartoon, this time about European qualifying examination (EQE)

  23. The Long History or Seeds of Control by Fear and Punishment at the EPO

    The latest hogwash from Team Battistelli (Pinocchio), the latest instance of software patents promotion by EPO Principal Director, and an old (decade-old) nugget of information from the Forum for Principal Directors

  24. Subject of the European Patent Office's Abuses Raised in European Parliament by Ulrike Müller (ALDE)

    A local copy of a bunch of questions asked less than a month ago by Ulrike Müller at the European Parliament, regarding the unacceptable state of affairs at the European Patent Office (EPO)

  25. French Article About the EPO "Crisis"

    Le Monde, which covered EPO suicides and nervous breakdowns a year and a half ago, revisits the subject

  26. Battistelli Wants Us to Believe a Patent Office in a Freefall (EPO) is “Stronger and More Sustainable”

    Still in denial (or self-deluding for self indulgence), Battistelli writes about the EPO as though everything is rosy and people are happy

  27. Leaked Documents Shed More Light on What Happened to Alison Brimelow and How Battistelli Rose to Power

    How Battistelli's (almost) all-male (and all-white, mostly French) management came into being, not too long after Ms Alison Brimelow got elbowed out the Office

  28. Leaked: Outcomes of 149th Administrative Council's Meeting at the European Patent Organisation

    The raw details or a summary thereof, based on the above which serves to confirm what we wrote about several days ago, right after the quarterly meeting had ended

  29. Danish Press Coverage of the European Patent Office and the Problems Explored by Techrights

    Jesper Kongstad does virtually nothing to deny the arguments (or "accusations") and instead alludes to the style of the writings about him

  30. Links 18/10/2016: Release Candidate of Leap 42.2, Looking Ahead at GTK4

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time


Recent Posts