Bonum Certa Men Certa

Nothing Says 'New' Microsoft Like Microsoft Component Firmware Update (More Hardware Lock-in)

"One thing I find myself wondering about is whether we shouldn't try and make the "ACPI" extensions somehow Windows specific.

"It seems unfortunate if we do this work and get our partners to do the work and the results is that Linux works great without having to do the work.

"Maybe there is no way to avoid this problem but it does bother me.

"Maybe we could define the APIs so that they work well with NT and not the others even if they are open.

"Or maybe we could patent something related to this."

--Bill Gates





Summary: Vicious old Microsoft is still trying to make life very hard for GNU/Linux, especially in the OEM channel/s, but we're somehow supposed to think that "Microsoft loves Linux"

YESTERDAY we saw Red Hat's (now IBM's) Richard Hughes complaining about Microsoft [1], whereupon Phoronix picked that up [2] and it was then discussed in our IRC channels, Phoronix forums etc. The corporate media obviously showed no interest in it. All it can do is post "Microsoft loves Linux" images because Microsoft asks for that. To quote Richard: "All the dependency resolution should be in the metadata layer (e.g. in the .inf file) rather than being pushed down to the hardware running the old firmware."



“All the dependency resolution should be in the metadata layer (e.g. in the .inf file) rather than being pushed down to the hardware running the old firmware.”
      --Richard Hughes
As Michael Larabel put it, "implementation has a number of issues that complicate the process and could quickly evolve into another troubling specification from Microsoft in the hardware space."

Remember UEFI 'secure boot'? How did that work out for security?

Microsoft certainly loves Linux with a knife in the back -- hence Bill Gates' "Jihad" remark (about Intel's support for Linux). MinceR at the #techrights IRC channel said: "you can tell something from Microsoft is _really_ _really_ shit when their sycophants at GNOME say it's shit..."

"Nowadays Zemlin is mostly quoted by the media as saying wonderful things about Microsoft. Most GNU/Linux user just want to vomit."It is worth remembering that Richard's work is now supported by the Linux Foundation (since months ago when it adopted LVFS), so maybe Richard can explain to the Linux 'genius' Jim Zemlin (who never uses Linux) what Microsoft does here and why it is anticompetitive. We don't suppose this will happen though. Zemlin is a 'true believer' in Microsoft and his wife managed a close partner of Microsoft when Microsoft paid the Linux Foundation. Nowadays Zemlin is mostly quoted by the media as saying wonderful things about Microsoft. Most GNU/Linux user just want to vomit. Money talks; people who love money are therefore a vulnerability. Jim Zemlin and his wife are the sorts of people whose life aspiration is to have dinner with Bill and Melinda Gates. It's all about class and power (Harvard). A decade ago Jim Zemlin said negative things about Microsoft and now (after/since Microsoft had given him $500,000) he says Microsoft is a good company while ignoring the below among many other things, patent extortion included (it's still going on). His wife worked for a Gold Microsoft Partner at the time (as a General Manager and Global VP of a SaaS Business Unit). Her business was moving companies to something like Microsoft Azure. In his own words (Jim Zemlin's interview with Jeremy Allison; 1m:30s), "I'm about as much [boss of Torvalds] as I am the boss of my wife..."

Related/contextual items from the news:



  1. Musings on the Microsoft Component Firmware Update (CFU) Protocol

    CFU has a bazaar pre-download phase before sending the firmware to the microcontroller so the uC can check if the firmware is required and compatible. CFU also requires devices to be able to transfer the entire new transfer mode in runtime mode. The pre-download “offer” allows the uC to check any sub-components attached (e.g. other devices attached to the SoC) and forces it to do dep resolution in case sub-components have to be updated in a specific order.

    Pushing the dep resolution down to the uC means the uC has to do all the version comparisons and also know all the logic with regard to protocol incompatibilities. You could be in a position where the uC firmware needs to be updated so that it “knows” about the new protocol restrictions, which are needed to update the uC and the things attached in the right order in a subsequent update. If we always update the uC to the latest, the probably-factory-default running version doesn’t know about the new restrictions.

    The other issue with this is that the peripheral is unaware of the other devices in the system, so for instance couldn’t only install a new firmware version for only new builds of Windows for example. Something that we support in fwupd is being able to restrict the peripheral device firmware to a specific SMBIOS CHID or a system firmware vendor, which lets vendors solve the “same hardware in different chassis, with custom firmware” problem. I don’t see how that could be possible using CFU unless I misunderstand the new .inf features. All the dependency resolution should be in the metadata layer (e.g. in the .inf file) rather than being pushed down to the hardware running the old firmware.



  2. Microsoft's Component Firmware Update Is Their Latest Short-Sighted Spec

    Microsoft's newest specification is the "Component Firmware Update" that they envision as a standard for OEMs/IHVs to be able to handle device firmware/microcode updating in a robust and secure manner. While nice in theory, the actual implementation has a number of issues that complicate the process and could quickly evolve into another troubling specification from Microsoft in the hardware space.

    Red Hat's Richard Hughes who is the lead developer on Fwupd and LVFS for firmware updating on Linux has written a lengthy blog post with his thoughts after studying the specification. Now that vendors have begun asking him about CFU, he's getting his opinions out there now and there are issues with the specification. Ultimately though if there is enough interest/adoption, he could support Component Firmware Update via Fwupd but he certainly isn't eager to do so.



Recent Techrights' Posts

Happy 20th Birthday to OpenDocument Format (ODF)
nowadays many companies use "online" "webapps" to collaborate on various things
Passkeys Are Vendor Lock-in and Imperialism, Not Security, So Escape Them Before They Latch Onto Your Workflows
This is their 'grand vision' of computing. You merely 'rent' what you assumed you truly bought to own.
Let's Put Slop In the Casket Once and for All (Call Out the Sites and People Who Produce and Spread Slop)
Together, through a movement of integrity and solidarity, we can marginalise the spread of slop in all its forms, including code
Windows Down in the Largest Countries, Microsoft Cannot Dodge This Reality Forever
Talking about "clown" and "hey hi" (AI) - sometimes "Quantum" - is like telling bedtime stories to infantile investors who don't understand those buzzwords
 
Microsoft's Debt Grew 2.1 Billion Dollars in the Past 3 Months Alone or 8.2 Billion in the Past Half a Year
That's very different from what the mainstream press tells the public, including shareholders
Links 03/05/2025: Amazon and Apple Problems (the A's in GAFAM), Hard to Hide Any Longer; Australia’s Election
Links for the day
Why Law Firms and Courts in Particular Should Dump Microsoft
Giving a notoriously corrupt and chronically law-breaking company control over one's systems and data is a recipe for disaster
Gemini Links 03/05/2025: Showerhead Mod and Micro Dosing on LSD
Links for the day
Links 03/05/2025: Bribery in Dutch Microsoft DC Probe, Zuckerberg Conflates Slop With 'Friends'
Links for the day
Today is World Press Freedom Day, 3rd of May
2025 World Press Freedom Day
Gemini Protocol's Momentum Ahead of Its 6th Anniversary (Next Month)
The more capsules go online, the more people participate in writing, not just reading
Corporate Media, a Cheerleader of Wall Street Facade, Spent Days Saying "META" and "MSFT" Lifted "the Market", But Their Debt Soared
Facebook's debt has never been higher
Microsoft Windows Falls to a Meager 9% "Market Share" in South Africa While GNU/Linux Rises Above 5% in Desktops/Laptops
South Africa is where the founder of Ubuntu (or Canonical) comes from
Links 03/05/2025: Australian Election and manpage for Gemini Considered
Links for the day
Links 03/05/2025: UK Arrests for Bribery Connected to Microsoft Datacentres
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 02, 2025
IRC logs for Friday, May 02, 2025
Not Just an OSU Open Source Lab Issue
Prominent and very prolific news sites about Linux ask for help
GNU/Linux Has Risen to All-Time High in South America, Windows Has Fallen a Lot Due to Android
What will the rest of the year bring?
Richard Stallman (RMS) Says US "Magats" Have Destroyed Press Freedom in the US
Now they're exporting their attacks on the media to the UK
In Africa, GNU/Linux Rose From 3% to 4% in Just Two Months
So says statCounter anyway... What will it be like by the end of this year?
Gemini Links 02/05/2025: Bandcamp and Spying "Smart Glasses"
Links for the day
Microsoft Says Demand/Budget for "AI" is Decreasing, Bing is Also Moving Down and Down This Year ("Bing Chat" Was an Utter Failure, People Want Sites, Not Slop)
Skype is about to shut down, XBox will likely die soon
Asia is Running Away From USA-ware (Trump or 'Tariff Regime'), Including Microsoft Windows
The nationalism harms Microsoft
Data Shows Largest EU Economies Shifting to GNU/linux
all-time highs
Microsoft President Panics Over Europe's Abandonment of Microsoft/GAFAM/Trump's USA, These Figures Show Us Why
Microsoft is bluffing
Microsoft Windows Falls Below Quarter in "Market Share" (While Microsoft Fakes Rising Dominance... in Buzzwords and Fake Accounting)
Cooking the books while Windows gets 'cooked'
Links 02/05/2025: Expedia Group Undergoes Layoffs, Twitter Exodus in Europe
Links for the day
Techrights Statement: The Solution is Not More Censorship or Moving to Another Mastodon Instance, the Core Problem is Social Control Media Including Mastodon
Censorship typically leads to additional (new) issues
Good News, Bad News: Groklaw is Back Online, SoylentNews Apparently Loses Editor
Jan ought to change the resignation into a mere pause
Manchester Computing Centre (MCC) Made the First GNU/Linux Distro, But You Probably Never Heard of It
People like Owen are barely remembered, not because they didn't do valuable work but because they didn't suck up to "The Establishment"
Online Mobs and Crabs: Doing to Fabrice Bellard What They Did to Richard Stallman and Linus Torvalds
They just don't want skilled people to be productive
E-mail is Not HTML, Web Pages Aren't a Form of E-mail
as an associate remains us, always use "plain text, it was good enough for Shakespeare"
Slopwatch: Stigma-Baiting by the Serial Sloppers and Latest Garbage From the Slopfarm LinuxSecurity.com (Also Slopping Away at "OpenBSD" With SEO SPAM Made by LLMs)
Microsoft et al are trying to profit from blurring away information
Links 02/05/2025: Mineral Selloff and Chinese Sanctions
Links for the day
Gemini Links 02/05/2025: Hens and Tmux
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, May 01, 2025
IRC logs for Thursday, May 01, 2025
Gopher/Gemini Links 01/05/2025: Slop/LLM Bot Troubles and Driving Angry
Links for the day
Links 01/05/2025: Apple Lies to Courts, European Patents Thrown Out by British Courts Again
Links for the day
Microsoft's CEO is Hyping Up 'AI' (Plagiarism) to Distract From Falling Interest in It and Missed Expectations (Investors Run Out of Patience as Reality Does Not Meet or Match Early False Promises)
Microsoft clearly needs 1) a distraction and 2) hype about "AI"
No, Microsoft, Plagiarism is Not "AI"
"Satya Nadella says as much as 30% of Microsoft code is written by AI"
Microsoft Has Become Almost Extinct in Web Servers, Netcraft Now Ranks It in Only One Category (Microsoft Down Sharply), Deranked/Outranked in All the Rest
Microsoft used to be in all categories, now it's in just one
Gemini Links 01/05/2025: Small Web and Going Offline
Links for the day
Microsoft Has Hundred of Layoffs Again, Same Week as the Company's Fake Results
those people were in effect Microsoft employees, just classified as contractors
Sirius Open Source in Court
I personally was a witness and an alibi
What GNU/Linux Means to Us
Linux without freedom is like becoming a vegetarian "except on special occasions"
Links 01/05/2025: Slop Blowback, Social Control Media as Vehicle of "Sextortion"
Links for the day
Disinformation and Marketing Spam From and For OIN (GAFAM's and IBM's Weapon Against Free Software Activists and Reformists Against Software Patents)
All in all, this anniversary is just a PR stunt with revisionism
Some of the Evidence We'll Be Relying Upon in the Lawsuits Against Matthew J. Garrett
Finally facing the consequences for his actions
Symptom or Hallmark of Ponzi Schemes: Microsoft Says It Gains Over 100 Million Dollars in "Goodwill" and Its Speculative "Value" Nearly Doubled to $119,329,000,000 in the Past Year Alone
Total liabilities are now over $240,000,000,000
Gemini Links 01/05/2025: Trying OpenBSD and Usenet Reborn Released
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, April 30, 2025
IRC logs for Wednesday, April 30, 2025