Bonum Certa Men Certa

Microsoft Proves Techrights Right by Screwing UEFI 'Partners'

UEFI



Summary: Linux booting still an issue on new PCs as Microsoft fails to deliver hardware keys

James Bottomley, who had been paid by Novell (Microsoft) before he left, is developing "secure boot" and finding out that UEFI promises are empty. From his blog:



Asked support why the process was indicating failed but I had a valid download and, after a flurry of emails, got back “Don’t use that file that is incorrectly signed. I will get back to you.” I’m still not sure what the actual problem is, but if you look at the Subject of the signing key, there’s nothing in the signing key to indicate the Linux Foundation, therefore I suspect the problem is that the binary is signed with a generic Microsoft key instead of a specific (and revocable) key tied to the Linux Foundation.

However, that’s the status: We’re still waiting for Microsoft to give the Linux Foundation a validly signed pre-bootloader. When that happens, it will get uploaded to the Linux Foundation website for all to use.


So they are losing time and they gave Microsoft the carte blanche to carry on with UEFI.

Will Hill wrote: "Predictable, jerk around. Restricted Boot is defective by design."

Katherine Noyes says:



In any case, the end result is that, despite paying its $99 fee, the Linux Foundation so far still does not have a validly signed pre-bootloader.


Steven J. Vaughan-Nichols also complains:

By design, Microsoft has made installing and booting Linux on Windows 8 PCs with UEFI (Unified Extensible Firmware Interface) Secure Boot troublesome. Many of the major Linux distirbutors, including Fedora, openSUSE, and Ubuntu, have proposed different ways of addressing this problem. The Linux Foundation, which supports all Linux, recently proposed a universal plan for addressing the UEFI Secure Boot issue. Unfortunately, it's been delayed.

The plan was, as James Bottomley, Parallels' CTO of server virtualization and well-known Linux Kernel maintainer, explained on October 10th, 2012, to "obtain a Microsoft Key and sign a small pre-bootloader which will, in turn, chain load (without any form of signature check) a predesignated boot loader which will, in turn, boot Linux (or any other operating system)."


Red Hat too was bamboozled by Microsoft, the longtimes convicted thug. This is what happens when you become UEFI 'partners' with the monopolist rather than file an antitrust complaint. As Larabel puts it:

Linux Foundation Struggles With Microsoft UEFI Signing



James Bottomley has written about the problems being faced by the Linux Foundation in having a Microsoft-approved validly-signed UEFI pre-bootloader.

There's many hurdles to jump from Microsoft and Verisign/Symantec for obtaining a valid signing key. There's third-party open-source tools for handling much of the signing process, but in the end Windows is still needed due to a Silverlight-based file uploader for the UEFI binary. The Mono-based Moonlight doesn't work with the Silverlight uploader. After uploading the cabinet file for signing, there's a seven-stage process.


That is how bad it is. Pogson puts it more crudely:

M$ Sabotages UEFI “Secure Boot” for Linux Foundation



[...]

I have always thought it was a mistake to do anything in GNU/Linux the M$’s way. They will do anything to prevent GNU/Linux being more widely accessible for consumers. Expect nothing but “accidents”, failures, disasters and the inevitable legal suits to result. They’re all good for M$ keeping the cash-cow flowing a bit longer.


Muktware says:

Microsoft may have attracted some headlines and discussion on Slashdot for being a 'sponsor' at the Linux Foundation's Europe event LinuxCon. But this sponsor is not giving the Linux Foundation any special treatment when it comes to UEFI Secure boot.

If you remember the Linux Foundation earlier announced their workaround for the UEFI Secure boot for the Linux community. That's getting delayed.

James Bottomley, chair of the Linux Foundation's Technical Advisory Board, explains in his blog the 'technical' and 'paper' challenges there are to get a Microsoft signed key and implement it.

He detailed the entire painful process to get a Microsoft signed key. While is extremely easy to pay $99 and get a Verisign verified key the rest of the process is quite daunting and challenging, which also requires one to use Microsoft technologies.

[...]

The foundation somehow managed to create and upload the file which had to go through seven stages and "unfortunately, the first test upload got stuck in stage 6 (signing the files)."

There were some email exchanges between Microsoft and Bottomley to sort the problem but at the moment the cart is stuck in mud.
We're still waiting for Microsoft to give the Linux Foundation a validly signed pre-bootloader. When that happens, it will get uploaded to the Linux Foundation website for all to use.


UEFI apologists hopefully learned their lesson by now. Microsoft has crooks trying to save Windows by breaking Linux.

Comments

Recent Techrights' Posts

Software In The Public Interest Inc. Turned Against The Public Interest and Turned Into "Red" (Heavy Losses)
Censoring the community
Android on 9 Out of 20 Web-Connected Devices for First Time Ever?
According to statCounter, Android has just topped 45%
The Paradoxical State of GNU/Linux Coverage
so much happening, so little reporting
 
Microsoft-, IBM-, and Google-Funded 'FSFE' Don't Follow Their Own Inclusive Language Guidelines
They've deposited that in more official sites
More Cybercrimes Committed Today by the Misogynists Who Attack My Family and Myself
These people openly boast about avoiding arrest
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, July 06, 2024
IRC logs for Saturday, July 06, 2024
Just Say the Truth, People Will Come
Uttering lies is a short-term "strategy" (like social control media clickbaiting), it won't last
Microsoft Windows in the Bolivarian Republic Of Venezuela: From Almost 98% (2010) to Just 28% (This Summer), Android Reaches New Highs
the Bolivarian Republic Of Venezuela is gradually exiting Microsoft, even faster than its neighbours, maybe for political reasons
[Meme] Not Winning Arguments and Not Winning Allies, Either
Misusing civil rights causes to censor people for billionaires is basically an attack on these civil rights causes
Microsofters and Their Chaos Theory
censorship is not the way to go
Love Always Wins (Truth Also)
I am still working on lengthy bodies of text
"Streamline Workforce" is the Same as Mass Layoffs, Apparently
we deserve better media than this
Back on the Saddle, Good News
Justices Jeremy Johnson and Victoria Sharp can focus on "real" cases instead
Truth is Not a Crime
They try to censor, not to correct, rebut etc.
Maldives: Estimates of GNU/Linux Userbase Rose From Less Than 1% Last Year to 4% This Month
Desktop Operating System Market Share Maldives
Labour Party Should Transfer Its Web Site and Communications Back to the United Kingdom
The "take back control" (Brexit) rhetoric overlooks the real issues.
New DW Documentary on Julian Assange (After Release From Prison)
By Turkish journalist Can Dündar
[Meme] A Diversity of Options: YouTube (Proprietary) or YouTube (Proprietary)
Rikard Grossman-Nielsen: 'will there be some online streaming of it?'
Wryl Explains the Software Crisis or Why "Counterculture Movements are Health Signals, and a Fever is Brewing"
"(the software crisis)"
Move to Microsoft Because... Bribes (to FreeBSD Developers)?
Don't do drugs, kids, even if the first sample is 'free'
[Meme] [Teaser] Microsoft's Covert Control of the British Government
Coming soon...
statCounter: GNU/Linux Now at 4.3%
statCounter isn't a gold(en) measure, the ground truth or a perfect yardstick, it's just an approximation, which may or may not tell us many people move from Vista 11 to GNU/Linux
Larissa Brown Shapiro & Mozilla concerned other organizations taking advantage of kids in open source
Reprinted with permission from Daniel Pocock
Links 06/07/2024: More on Microsoft Layoffs
Links for the day
Gemini Links 06/07/2024: Usenet Comeback, Web Economics
Links for the day
Links 06/07/2024: Shapeways Files For Bankruptcy, Cloudflare Subpoena Emerges
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, July 05, 2024
IRC logs for Friday, July 05, 2024
Links 05/07/2024: Science and War Updates
Links for the day
Gemini Links 05/07/2024: SSH Software and Serving Gemtext Files From Caddy
Links for the day
Links 05/07/2024: OpenText Layoffs and More Google/Alphabet Cuts
Links for the day
[Meme] That would be great (at Microsoft)...
To get to the top at Microsoft you must step on the weak
Thrown Under the Bus on July 4th (Along With Mass Layoffs at Microsoft)
When to bury bad or embarrassing news
News Calm Now (July 4th), Time for Microsoft to Unearth First Batch of Mass Layoffs for July? (According to Microsoft's Media Operative, Tom Warren)
many links
GNU/Linux Now at 4.2% Worldwide as Seen by statCounter
Will it hit 5% by year's end?
Pardoning Julian Assange as the Next Objective (to Undo Dangerous Precedent Worldwide, Where the United States Asserts Extended Reach)
Reach or overreach?
Microsoft Fell 1% (From 4.68% to 3.79%) in the UK Since the LLM Hype, Now There Are Mass Layoffs Again (During National Holiday!)
Google went up, Microsoft is down again
[Meme] EPO Needs More Patent Profits For...
Granting loads and loads of fake, invalid, and illegal patents
EPO Cannot Recruit Examiners in Compliance With the European Patent Convention (EPC) Because the Goal is to Lower Patent Compliance/Standards
Monopolies. Monopolies everywhere. That alone is the goal.
Yanis Varoufakis About Turning Technology Back Against "Sources of Power"
video of Varoufakis has been circulating lately
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, July 04, 2024
IRC logs for Thursday, July 04, 2024
Labour Policy on Technology in the UK May Seem Vague, Lots of Greenwashing
Tech PR?
A Shift to the Centre-Left in the United Kingdom
To be clear, we don't endorse political parties
Links 05/07/2024: Personal Stories and Software Commentary
Links for the day