EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

03.02.13

UEFI Restricted Boot: Torvalds Asks Developers Not to “Please Microsoft by Doing Idiotic Crap Approach”, Petition Set Up to Nail Microsoft for This Antitrust Abuse

Posted in Antitrust, FSF, GNU/Linux, Kernel, Microsoft at 6:03 am by Dr. Roy Schestowitz

Photo by Alex Dawson, 2002

Linus

Summary: “Because it really shouldn’t be about MS blessings, it should be about the *user* blessing kernel modules,” Torvalds explains

THE MAN who habitually dismisses some Microsoft critics proves his older statements to be somewhat hypocritical. He too treats Microsoft exceptionally.

Torvalds recently made headlines by using strong language and addressing a controversial subject. It is about UEFI with restricted boot and here is some more relevant coverage he generated, helping to raise awareness of the issue:

  • Torvalds blasts Howells, Garrett over secure boot

    A push by Red Hat kernel developer David Howells and ex-Red Hat developer Matthew Garrett to get code supporting secure boot merged into the mainline kernel to meet some of Microsoft’s requirements has led to a sharp rebuke from Linux creator Linus Torvalds.

    Howell made a request for a patchset to be pulled into the mainline kernel last Thursday, writing, “It (the patchset) provides a facility by which keys can be added dynamically to a kernel that is running in secure-boot mode.

  • Linus Torvalds blasts Microsoft in sweary tirade

    Linux guru Linus Torvalds is at it again. After telling Nvidia to go forth and multiply, the outspoken Torvalds has decided to share some of his thoughts on Microsoft’s signing techniques in a heated online argument with fellow Linux developers.

    The developers were discussing ways of improving the Linux kernel with a bit of code that makes it easier to boot on Windows 8 PCs. The process of booting Linux on PCs shipped with Windows 8 has been complicated due to the widespread use of UEFI firmware with Secure Boot feature enabled. Red Hat developers emailed Torvalds to discuss the addition of new keys to the Linux kernel, which should get around the issue.

  • No Microsoft certificate support in Linux kernel says Torvalds

    Red Hat’s Secure Boot support is a case of the company wanting to “deep-throat Microsoft”, according to a forthright posting from Linus Torvalds on the Linux kernel developer mailing list. Torvald’s comments were made in response to plans by a Red Hat developer to extend Linux support for Secure Boot. The comments have given rise to an ongoing discussion, during which several prominent kernel developers have shared their thoughts on Secure Boot support in Linux.

Moreover, as it turns out, US citizens can now sign this petition calling for the White House to get involved to tackle the antitrust abuse (reports suggest that Microsoft’s fine for antitrust abuses in Europe is only weeks away).

James Bottomley wrote about this in his blog, but being former Novell staff who had worked on Microsoft projects, we expect no strong opposition from him. Steven J. Vaughan-Nichols, a Novell-sympathetic writer, wrote this followup:

No one, but no one, in the Linux community likes Microsoft’s mandated deployment of the Unified Extensible Firmware Interface (UEFI) Secure Boot option in Windows 8 certified PCs. But, how Linux should handle the fixes required to deal with this problem remains a hot-button issue. Now, as the debate continues hot and heavy, Linus Torvalds, Linux’s founder and de facto leader, spells out how he thinks Linux should deal with Secure Boot keys.

Swapnil Bhartiya, not a strong critic of Novell because he likes SUSE, sure isn’t a fan of what Microsoft is doing here. He is in good company when he writes along the same lines of Torvalds, whom he interviewed last year:

There is a heated (heat is a bit colder word) debate going on within the Linux community over how should Linux handle the Microsoft’s secure boot keys.

In an ongoing discussing Linus Torvalds has made some suggestions which he believes put users in control of their system and not Microsoft.

Torvalds was sarcastic when saying, “let’s please Microsoft by doing idiotic crap approach.”

This attitude is not exactly news (Torvalds alleges that so-called Secure Boot has nothing to do with security). “Because it really shouldn’t be about MS blessings, it should be about the *user* blessing kernel modules,” Linus Torvalds believes. He basically agrees with Richard Stallman and the FSF then.

Dr. Garrett, on the other hand, continues to push for the agenda that Microsoft hoped for, facilitating its control over Linux, Here is part of this whole long discussion where Torvalds says:

So instead of pleasing microsoft, try to see how we can add real security:

- a distro should sign its own modules AND NOTHING ELSE by default. And it damn well shouldn’t allow any other modules to be loaded at all by default, because why the f*ck should it? And what the hell should a Microsoft signature have to do with *anything*?

- before loading any third-party module, you’d better make sure you ask the user for permission. On the console. Not using keys. Nothing like that. Keys will be compromised. Try to limit the damage, but more importantly, let the user be in control.

– encourage things like per-host random keys – with the stupid UEFI checks disabled entirely if required. They are almost certainly going to be *more* secure than depending on some crazy root of trust based on a big company, with key signing authorities that trust anybody with a credit card. Try to teach people about things like that instead. Encourage people to do their own (random) keys, and adding those to their UEFI setups (or not: the whole UEFI thing is more about control than security), and strive to do things like one-time signing with the private key thrown out entirely. IOW try to encourage *that* kind of “we made sure to ask the user very explicitly with big warnings and create his own key for that particular module” security. Real security, not “we control the user” security.

Sure, users will screw that up too. They’ll want to load crazy nvidia binary modules etc crap. But make it *their* decision, and under
*their* control, instead of trying to tell the world about how this should be blessed by Microsoft.

Because it really shouldn’t be about MS blessings, it should be about the *user* blessing kernel modules.

Quite frankly, *you* are what he key-hating crazies were afraid of. You peddle the “control, not security” crap-ware. The whole “MS owns your machine” is *exactly* the wrong way to use keys.

Sam Varghese, consistently an opposer of restricted boot, says that it would put “Linux is at Microsoft’s mercy”:

Linux companies or organisations that have paid for, and obtained, keys from Microsoft to ensure that their distributions can be booted on secure boot-enabled devices, have to abide by the terms of a contract or else may have their keys revoked.

Whatever some Linux developers with past in Novell may say, at least we know Torvalds’ approach is perhaps more similar to the FSF’s than his employer’s.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. IRC Proceedings: May 12th, 2013-May 18th, 2013

    IRC logs for May 12th, 2013 (and subsequent days until May 18th, 2013)



  2. Microsoft Spin Regarding Skype Spying Does Not Withstand Scrutiny

    Microsoft's response to allegations that Skype is spying on all users is full of holes



  3. MPEG-LA Ruined the Licence of WebM, Made it Less Freedom-Respecting

    The Microsoft-, Nokia-, and Apple-backed patent troll appears to have ruined the freedom assured by Google's multimedia format, which was previously made free only after public pressure



  4. Microsoft-controlled Nokia is Lobbying to Enable Bans on Android Imports (Linux Phones as a Whole in Danger)

    Nokia is shown lobbying for embargoes while it is also suing -- with limited success -- Android handsets makers



  5. Courtroom and New Book Recognise That Software Patents Correspond to Mathematics and Mathematics Abused in Court

    Important observations about the nature of computer-implemented 'inventions', or software patents



  6. The Reality Distortion Field of Patent Lawyers Helps Impede Abolition of Software Patents

    How widespread coverage and talking points from the tiny minority which is patent lawyers have contributed to biased and at times utterly distorted reporting on the subject of software patents around the world



  7. Eugene Kaspersky Says Patents Harm Innovation

    Some more criticism of the patent system and software patents in particular, courtesy of Eugene Kaspersky



  8. UEFI Restricted Boot Good for Microsoft Agenda, Not for Security

    News and analysis of UEFI 'secure boot' (lockdown), including the new role played by the Microsoft-funded SUSE



  9. Anniversaries

    Sites that deal with patents and with FUD as well as their respective ages



  10. EFF, Newegg, and the Canadian Patent System All Take a Stance Against Software Patents

    Hostility towards the practice of patenting software is seen in a nonprofit organisation, a corporation, and a government branch responsible for patenting



  11. Microsoft's Fake 'Open Source' Front is "Pushing Software Patents" (Updated)

    Microsoft's front group which pretends to support Free/Open Source software (FOSS) is using a guest post to entertain the idea of software patents inside Free/Open Source software



  12. Links 17/5/2013: 0.9 Billion Android Activations, New Devices, Android Studio

    Links for the day



  13. Links 16/5/2013: Firefox 21 Out, Android 4.3 Foreseen

    Links for the day



  14. More Android FUD From Former Microsoft Staff in CBS

    New examples of anti-Android sentiments being spread by the Apple- and Microsoft-funded media conglomerate, CBS, which pays current and former Microsoft staff to act as "journalists"



  15. Where Fear of FOSS Comes From

    More Microsoft ties to some of the latest FUD about Free/Open Source software (FOSS)



  16. Microsoft Skype Messaging Surveillance Not the Main Issue, Audio Recording (Bugging) and Computer Hijacking Are

    Debates about the dangers of Skype focus on one of the least dangerous aspects of Skype



  17. Links 15/5/2013: Android 4.3, Antergos Debuts

    Links for the day



  18. Man From Microsoft Runs the Ubuntu Project Now

    How the leadership of Ubuntu has changed and how it may relate to some strategic decisions inside the project



  19. Has Microsoft Irreversibly Taken Over ZDNet (CBS) to Disseminate Its Lies?

    ZDNet promotes Microsoft in the editorial sections, not just in the ads, and it employs Microsoft people who habitually also censor commenters for expressing views that may upset the customers (advertisers like Microsoft)



  20. Microsoft is Attacking Boston Over Brand Ideology

    Another hypocritical attack of Microsoft against Google, this time in Boston



  21. Software Patents Reality Distortion Field

    How press coverage of software patents in the EU and New Zealand (NZ) varies depending on the source; allegations that the US press tries to dismiss end of software patents by twisting an outcome of a major trial



  22. Links 14/5/2013: Android Growth Explosion

    Links for the day



  23. Links 13/5/2013: New Linux/Open Source Documentary, Lots More About International Space Station

    Links for the day



  24. Prominent GNU/Linux/KDE Developer Jonathan Riddell Complains About UEFI Restricted Boot, Calling it "a giant Microsoft conspiracy to make installing Linux more faffy than it already is."

    UEFI abuses continue, but Microsoft PR, lies, and attempts to silence the media go a long way, ensuring evidence gets insufficient coverage



  25. Facebook and Microsoft Get Closer, Now Reaching Their Relationship's Peak as Facebook Declines

    Facebook starts leaning on Microsoft for help now that its users (products) no longer log in and give data (content) to consume advertisements (Facebook's real clients) as much as they used to



  26. Dr. Ravitch: Gates Foundation Underwrites Almost Every Organisation in its Quest to Control American Education

    More complaints about yet more rogue influence that is masqueraded as "public interest" or "for education" (whilst in fact having the opposite effect)



  27. Formerly Microsoft, But New FUD

    Microsoft FUD by proxy; or, how the old claims that FOSS is complex and dangerous are now coming from firms created by people from Microsoft Corp.



  28. Matt Asay is Wrong, Microsoft Does Sue (SLAPP Action), Doesn't Just Threaten

    Misleading article helps portray the aggressor as a negotiator, using patently false claims that are easily disprovable



  29. Todd Simpson From Mozilla Joined an Angry Patent Troll, IBM Tries to Warp Debate About Software Patents to Focus Just on Trolls

    Revisiting the stance of FOSS proponents on software patents and patent trolls; Mozilla, IBM, Red Hat, and Nokia (also before Microsoft takeover) discussed



  30. Unitary Patent Impediments Covertly Addressed by EU Member Governments

    The UK is modifying its law to accommodate takeover of national interests by foreign interests which may usher in software patents among other nasty elements of protectionism (primarily exported by multinational corporations from across the Atlantic ocean)


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts