EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS


UEFI Restricted Boot: Torvalds Asks Developers Not to “Please Microsoft by Doing Idiotic Crap Approach”, Petition Set Up to Nail Microsoft for This Antitrust Abuse

Posted in Antitrust, FSF, GNU/Linux, Kernel, Microsoft at 6:03 am by Dr. Roy Schestowitz

Photo by Alex Dawson, 2002


Summary: “Because it really shouldn’t be about MS blessings, it should be about the *user* blessing kernel modules,” Torvalds explains

THE MAN who habitually dismisses some Microsoft critics proves his older statements to be somewhat hypocritical. He too treats Microsoft exceptionally.

Torvalds recently made headlines by using strong language and addressing a controversial subject. It is about UEFI with restricted boot and here is some more relevant coverage he generated, helping to raise awareness of the issue:

  • Torvalds blasts Howells, Garrett over secure boot

    A push by Red Hat kernel developer David Howells and ex-Red Hat developer Matthew Garrett to get code supporting secure boot merged into the mainline kernel to meet some of Microsoft’s requirements has led to a sharp rebuke from Linux creator Linus Torvalds.

    Howell made a request for a patchset to be pulled into the mainline kernel last Thursday, writing, “It (the patchset) provides a facility by which keys can be added dynamically to a kernel that is running in secure-boot mode.

  • Linus Torvalds blasts Microsoft in sweary tirade

    Linux guru Linus Torvalds is at it again. After telling Nvidia to go forth and multiply, the outspoken Torvalds has decided to share some of his thoughts on Microsoft’s signing techniques in a heated online argument with fellow Linux developers.

    The developers were discussing ways of improving the Linux kernel with a bit of code that makes it easier to boot on Windows 8 PCs. The process of booting Linux on PCs shipped with Windows 8 has been complicated due to the widespread use of UEFI firmware with Secure Boot feature enabled. Red Hat developers emailed Torvalds to discuss the addition of new keys to the Linux kernel, which should get around the issue.

  • No Microsoft certificate support in Linux kernel says Torvalds

    Red Hat’s Secure Boot support is a case of the company wanting to “deep-throat Microsoft”, according to a forthright posting from Linus Torvalds on the Linux kernel developer mailing list. Torvald’s comments were made in response to plans by a Red Hat developer to extend Linux support for Secure Boot. The comments have given rise to an ongoing discussion, during which several prominent kernel developers have shared their thoughts on Secure Boot support in Linux.

Moreover, as it turns out, US citizens can now sign this petition calling for the White House to get involved to tackle the antitrust abuse (reports suggest that Microsoft’s fine for antitrust abuses in Europe is only weeks away).

James Bottomley wrote about this in his blog, but being former Novell staff who had worked on Microsoft projects, we expect no strong opposition from him. Steven J. Vaughan-Nichols, a Novell-sympathetic writer, wrote this followup:

No one, but no one, in the Linux community likes Microsoft’s mandated deployment of the Unified Extensible Firmware Interface (UEFI) Secure Boot option in Windows 8 certified PCs. But, how Linux should handle the fixes required to deal with this problem remains a hot-button issue. Now, as the debate continues hot and heavy, Linus Torvalds, Linux’s founder and de facto leader, spells out how he thinks Linux should deal with Secure Boot keys.

Swapnil Bhartiya, not a strong critic of Novell because he likes SUSE, sure isn’t a fan of what Microsoft is doing here. He is in good company when he writes along the same lines of Torvalds, whom he interviewed last year:

There is a heated (heat is a bit colder word) debate going on within the Linux community over how should Linux handle the Microsoft’s secure boot keys.

In an ongoing discussing Linus Torvalds has made some suggestions which he believes put users in control of their system and not Microsoft.

Torvalds was sarcastic when saying, “let’s please Microsoft by doing idiotic crap approach.”

This attitude is not exactly news (Torvalds alleges that so-called Secure Boot has nothing to do with security). “Because it really shouldn’t be about MS blessings, it should be about the *user* blessing kernel modules,” Linus Torvalds believes. He basically agrees with Richard Stallman and the FSF then.

Dr. Garrett, on the other hand, continues to push for the agenda that Microsoft hoped for, facilitating its control over Linux, Here is part of this whole long discussion where Torvalds says:

So instead of pleasing microsoft, try to see how we can add real security:

- a distro should sign its own modules AND NOTHING ELSE by default. And it damn well shouldn’t allow any other modules to be loaded at all by default, because why the f*ck should it? And what the hell should a Microsoft signature have to do with *anything*?

- before loading any third-party module, you’d better make sure you ask the user for permission. On the console. Not using keys. Nothing like that. Keys will be compromised. Try to limit the damage, but more importantly, let the user be in control.

– encourage things like per-host random keys – with the stupid UEFI checks disabled entirely if required. They are almost certainly going to be *more* secure than depending on some crazy root of trust based on a big company, with key signing authorities that trust anybody with a credit card. Try to teach people about things like that instead. Encourage people to do their own (random) keys, and adding those to their UEFI setups (or not: the whole UEFI thing is more about control than security), and strive to do things like one-time signing with the private key thrown out entirely. IOW try to encourage *that* kind of “we made sure to ask the user very explicitly with big warnings and create his own key for that particular module” security. Real security, not “we control the user” security.

Sure, users will screw that up too. They’ll want to load crazy nvidia binary modules etc crap. But make it *their* decision, and under
*their* control, instead of trying to tell the world about how this should be blessed by Microsoft.

Because it really shouldn’t be about MS blessings, it should be about the *user* blessing kernel modules.

Quite frankly, *you* are what he key-hating crazies were afraid of. You peddle the “control, not security” crap-ware. The whole “MS owns your machine” is *exactly* the wrong way to use keys.

Sam Varghese, consistently an opposer of restricted boot, says that it would put “Linux is at Microsoft’s mercy”:

Linux companies or organisations that have paid for, and obtained, keys from Microsoft to ensure that their distributions can be booted on secure boot-enabled devices, have to abide by the terms of a contract or else may have their keys revoked.

Whatever some Linux developers with past in Novell may say, at least we know Torvalds’ approach is perhaps more similar to the FSF’s than his employer’s.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New

  1. Links 17/3/2018: Varnish 6, Wine 3.4

    Links for the day

  2. Deleted EPO Tweets and Promotion of Software Patents Amid Complaints About Abuse and Demise of Patent Quality

    Another ordinary day at the EPO with repressions of workforce, promotion of patents that aren't even allowed, and Team UPC failing to get its act together

  3. Guest Post: Suspected “Whitewashing” Operations by Željko Topić in Croatia

    Articles about EPO Vice-President Željko Topić are disappearing and sources indicate that it’s a result of yet more SLAPP from him

  4. Monumental Effort to Highlight Decline in Quality of European Patents (a Quarter of Examiners Sign Petition in Spite of Fear), Yet Barely Any Press Coverage

    he media in Europe continues to be largely apathetic towards the EPO crisis, instead relaying a bunch of press releases and doctored figures from the EPO; only blogs that closely follow EPO scandals bothered mentioning the new petition

  5. Careful Not to Conflate UPC Critics With AfD or Anti-EU Elements

    The tyrannical Unified Patent Court (UPC) is being spun as something that only fascists would oppose after the right-wing, anti-EU politicians in Germany express strong opposition to it

  6. Links 15/3/2018: Qt Creator 4.6 RC, Microsoft Openwashing

    Links for the day

  7. PTAB Continues to Increase Capacity Ahead of Oil States; Patent Maximalists Utterly Upset

    The Patent Trial and Appeal Board (PTAB) sees the number of filings up to an almost all-time high and efforts to undermine PTAB are failing pretty badly -- a trend which will be further cemented quite soon when the US Supreme Court (quite likely) backs the processes of PTAB

  8. Patent Maximalists Are Still Trying to Create a Patent Bubble in India

    Litigation maximalists and patent zealots continue to taunt India, looking for an opportunity to sue over just about anything including abstract ideas because that's what they derive income from

  9. EPO Staff Has Just Warned the National Delegates That EPO's Decline (in Terms of Patent Quality and Staff Welfare) Would Be Beneficial to Patent Trolls

    The staff of the EPO increasingly recognises the grave dangers of low-quality patents -- an issue we've written about (also in relation to the EPO) for many years

  10. The EPO is a Mess Under Battistelli and Stakeholders Including Law Firms Will Suffer, Not Just EP Holders

    As one last 'gift' from Battistelli, appeals are becoming a lot more expensive -- the very opposite of what he does to applications, in effect ensuring a sharp increase in wrongly-granted patents

  11. The EPO Under Battistelli Has Become Like China Under Xi and CPC

    The EPO is trying very hard to silence not only the union but also staff representatives; it's evidently worried that the lies told by Team Battistelli will be refuted and morale be affected by reality

  12. Links 14/3/2018: IPFire 2.19 – Core Update 119, Tails 3.6

    Links for the day

  13. Links 13/3/2018: Qt Creator 4.5.2, Tails 3.6, Firefox 59

    Links for the day

  14. Willy Minnoye (EPO) Threatened Staff With Disabilities Said to Have Been Caused by the EPO Work Pressures

    Willy Minnoye, or Battistelli's 'deputy' at the EPO until last year, turns out to have misused powers (and immunity) to essentially bully vulnerable staff

  15. IAM and IBM Want Lots of Patent Litigation in India

    Having 'championed' lobbying for litigation Armageddon in China (where IBM's practicing business units have gone), patent maximalists set their eyes on India

  16. The Patent Trolls' Lobby (IAM) Already Pressures Andrei Iancu, Inciting a USPTO Director Against PTAB

    Suspicions that Iancu might destroy the integrity of the Office for the sake of the litigation ‘industry’ may be further reaffirmed by the approach towards patent maximalists from IAM, who also participated in the shaming of his predecessor, Michelle Lee, and promoted a disgraced judge (and friend of patent trolls) for her then-vacant role

  17. Patent Trolls in the United States Increasingly Target Small Businesses Which Cannot Challenge Their Likely-Invalid Software Patents

    South by Southwest (SXSW Conference/Festivals in Austin, Texas) has a presentation about patent trolls, whose general message may be reaffirmed by recent legal actions in Texas and outside Texas

  18. EPO Staff Union Organises Protest to Complain About Inability “of the Office to Recruit the Highly Qualified Staff it Needs.”

    Having already targeted union leaders and staff representatives, the EPO may soon be going after those whom they passionately represented and the staff union (SUEPO) wants the Administrative Council to be aware

  19. Battistelli Likes to Describe His Critics as 'Nazis', Team UPC Will Attempt the Same Thing Against UPC Critics

    Demonising one's opposition or framing it as "fascist" is a classic trick; to what degree will Team UPC exploit such tactics?

  20. Session in Bavaria to Discuss the Abuses of the European Patent Office Later Today

    The EPO shambles in Munich have gotten the attention of more Bavarian politicians, more so in light of the Constitutional complaint against the UPC (now dealt with by the German FCC, which saw merit in the complaint)

  21. Links 12/3/2018: Linux 4.16 RC5, KEXI 3.1, Karton 1.0, Netrunner 18.03, Debian 9.4

    Links for the day

  22. EPO Patent 'Growth' Not Achieved But Demanded/Mandated by Battistelli, by Lowering Quality of Patents/Services

    Targets at the EPO are not actually reached but are being imposed by overzealous management which dries up all the work in a hurry in order to make examiners redundant and many European Patents worthless

  23. Doubt Over Independence of Judges at the EPO Clouds Reason in Deciding Regarding Patents on Life

    With the growing prospect of a Board of Appeal (BoA) having to decide on patentability of CRISPR 'innovation' (more like explanation/discovery), questions linger or persist about judges' ability to rule as they see fit rather than what some lunatic wants

  24. Patent Academics and CAFC Make a Living Out of Patents, But Both Must Begrudgingly Learn to Accept That Patents Went Too Far

    A look at academic pundits' views on the patent system of the United States and where the Federal Circuit (a high patent court) stands on these matters after the US Supreme Court (highest possible court) lashed out at many of its decisions, especially those from the disgraced Rader years

  25. Patent Maximalists Cause a Crisis of Legitimacy for Patent Law

    The patent extremists who nowadays equate monopolies on mere ideas to "property" and "rights" gradually cause the public to lose respect for patents, more or less in the same way copyright maximalists (and copyright trolls) cause the population to seek alternatives (both legal and illegal)

  26. We Shall Soon Find Out Where Trump Appointees Such as Neil Gorsuch Stand on Patent Policies

    Staff shuffles at top-level roles will soon reveal what Donald Trump's changes mean to patent law and caselaw

  27. Trump's USPTO Changes Patent Designs, Changes Director/Deputy Director, and Anticipat 'Ranks' Patent Examiners Based on How They Deal With Section 101

    Today's USPTO isn't the same USPTO which was managed by Michelle Lee and anti-PTAB groups (proponents of software patents) have begun profiling examiners based on their stance on abstract/software patents -- a form of neo-McCarthyism

  28. Links 10/3/2018: Amarok 2.9.0, Debian 9.4, Sparky 5.3

    Links for the day

  29. Alice/§ 101 is Improving the Quality of Patents in the United States and Patent Law Firms Are Panicking

    Patent maximalists in the United States not only freak out over Alice but also distort the outcome of recent court cases (Federal Circuit) in order to make it seem as though Alice is going away

  30. Watchtroll is Back to Attacking Judges of the Patent Trial and Appeal Board (PTAB) Because It Can't Tolerate Justice

    The attacks on judges at PTAB seem to be culminating again, perhaps mere weeks before the US Supreme Court delivers a decision regarding PTAB's patent review process (IPRs)


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time


Recent Posts