Bonum Certa Men Certa

Matthew Garrett’s Twitter Log Shows Exactly Why We Need to Give Security Theater the Boot

Guest post by Ryan, reprinted with permission from the original

Matthew Garrett put Security Theater Boot support into the Linux kernel some time ago, and he got a Free Software Treachery Award for it from the joke that the FSF has turned into.



"Bootkits just really aren’t much of a problem on desktop GNU/Linux..."Now on his Twitter log, he shows us some of the mess he has caused.



See, if you have “Secure” Boot turned on, and you shouldn’t, but if you do, you’ll see the Linux kernel complain that it is disabling hibernation support, and while that alone really isn’t a huge problem because as long as you can suspend and resume (which still is far from given these days even though we were lied to and told uEFI would be better, over ten years ago), it really shows where we’re at now.



Bootkits just really aren’t much of a problem on desktop GNU/Linux, and I doubt they were ever a real problem on much of anything involving a competently-administered GNU/Linux systems, except maybe embedded hardware, where they can lock it down all they want, but those people don’t care about security. If some asshole at Netgear can make a cable modem based on a Linux 2.6 kernel, you’d better believe they’ll do it. After all, you probably won’t know if your modem is compromised.



In reality, I strongly suspect that even on the Windows side, Security Theater Boot was implemented to make it harder to crack Windows using a boot activation exploit. While it’s true that Microsoft laid off the locking people out of their computer over activation failures, for now, the truth is that after Windows 11 requires Security Theater Boot, OEMs may just make it mandatory and stick you with it, and then Microsoft could decide at any time to stop signing shim, and there’s no way to boot GNU/Linux on a PC anymore. The minute they think they can, they will. The only reason you could turn it off up until now was that they had legacy software and hardware in support, but that’s going away.



"But in exchange for false security which doesn’t gain us anything, we’re forced to deal with no hibernation..."It’s part of the “Up yours, buy new stuff!” theme of Windows 11 where lots of expensive computers won’t run it because they’re 36 months old. (But switching to GNU/Linux on these is probably an option for you.).



But in exchange for false security which doesn’t gain us anything, we’re forced to deal with no hibernation, an entire “kernel lockdown” (unauthorized access… by you, the owner of the machine) patch set whose entire goal was to remove the user’s control over kernel settings from userspace (which Microsoft didn’t even publicly demand in exchange for signing the shim bootloader after Red Hat and Canonical bent the knee instead of filing lawsuits), and has left us unable to extend the kernel that runs our own machines with out-of-tree drivers that we feel like running.



Since people can delete tweets and make them unavailable for critical comment, here’s what this sanctimonious asshole has been up to lately.



UEFI troll tweet



UEFI troll tweet

UEFI broken
Yes, that FAMOUS GNU/Linux bootloader, “Windows Bootloader”. There it is, under P:\EFI\Microsoft\Boot\en-us. I’d recognize it anywhere!



He guesses and gets it into the kernel, and you get to wonder if your OS will work later. He also exaggerates, misdirects, and misleads. (see above) But that’s what carnival barkers do.



That is sort of what happens when you have a failed biologist implementing Security Theater from Microsoft. Getting money from them by proxy to do it with.



The company that brought you Windows.



The operating system that goes “Herr! Derr! Here you go, have some files dumped on this here flash drive because the letter belonged to your portable hard disk earlier! Here’s some Microsoft Defender, don’tcha know!?”.



Anyway, I really do wish I had all day to read his Twitter blogs where he pontificates about how the police who protect him from the rioters are evil murderers. But I’ve thought about him too much for one day just for this post.



Anyway, enjoy Windows 11. I’m sure it’ll be great.

Recent Techrights' Posts

The U.S. Patent and Trademark Office Hijacked Again by Patent Litigation Industry, as President Cheeto Prioritises Aggressors
The "mafia" has taken over the "industry" and the Federal system (justice and constitutions trampled upon)
Ubuntu Slop and FUD Manufactured With LLMs and Funded (by Oneself) 'Studies'
Slop and FUD are ruining the Web
Gemini Links 01/04/2025: Games and More
Links for the day
Why We're Reporting Brett Wilson LLP for Apparently Misusing Their Licence to Protect American Microsofters Who Attack Women
For those who have not been keeping abreast
Stefano Maffulli and His Microsoft-Funded OSI Staff Are Killing the OSI and Killing "Open Source" (All for Money!)
This is far from over
Techrights Headlines as Semaphore
"If you are hearing this, thank you"
 
Gemini Protocol Has Growing Appeal (the Web Got Too Bloated and Full of LLM Slop)
For any "data plan" with bandwidth limits or "tiers" it would be cheaper to use/browse Geminispace
The Web Can Survive LLM Slop, But Only If We Collectively Shun and Discourage Serial Sloppers
Doing nothing ought not be a possibility
Amid Secret Shut-downs and Mass Layoffs at Microsoft (4 Waves of Layoffs in 3 Months of 2025) Some Microsoft Staff Expected to Go On Strike
workers going on strike
Gemini Links 02/04/2025: No more on Mastodon and Gemini Mention Script in Go
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, April 01, 2025
IRC logs for Tuesday, April 01, 2025
My Motion Disbarring or “Striking Off” Brett Wilson LLP for Enabling Violent Americans Who Try to Crush Microsoft Critics in the United Kingdom by Multiple SLAPPs
"Guns for hire" (for Microsoft people who received Microsoft salaries)
Links 01/04/2025: Apple Fined $162M for Privacy Abuses, Disinformation Online a Growing Concern
Links for the day
Newer Press Reports Confirm That Microsoft Shuts Down 'Hey Hi' (AI) Labs Despite All the Hype
The "hey hi" (AI) bubble is not sustainable
Links 01/04/2025: Mass Layoffs at Eidos and "Microsoft Pulls Back on Data Centers" (Demand Lacking); "Racist and Sexist" Slop From Microsoft
Links for the day
Gemini Links 01/04/2025: XKCDpunk and worldclock.py
Links for the day
50 Years of Sabotage and a Gut Punch to Computer Science (and Science in General)
Will we get back to science-based computing rather than cult-like following?
3 Months in 2025, 4 Waves of Mass Layoffs at Microsoft, Now Offices Shut Down Permanently
"A recent visit by the South China Morning Post confirmed that the office was dark, unoccupied, and had its logo removed."
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, March 31, 2025
IRC logs for Monday, March 31, 2025
Links 31/03/2025: China Tensions, Bombs Falling in Myanmar After Earthquake
Links for the day
Gemini Links 31/03/2025: Falling Out of Love With Tech, Sunsetting openSNP
Links for the day
R.T.O. at IBM in Texas and Atlanta (State of Georgia) Expected as "Soft Layoffs" Catalyst This Coming Year
It also sounds like more IBM layoffs are in the making
Law Firms Can Also Lose Their Licence for Clearly Misusing It
The bottom line is, never made the false assumption that because you can pile up SLAPPs in a docket you will not suffer from bad reputation or even get disbarred
Link between institutional abuse, Swiss jurists, Debianism and FSFE
Reprinted with permission from Daniel Pocock
LLM Slop Piggybacking News About GNU/Linux and Distorting It
new examples
Links 31/03/2025: Press and Democracy Under Further Attacks in the US, Attitudes Towards Slop Sour
Links for the day
Open Source Initiative (OSI) Privacy Fiasco in Detail: The OSI Does Not Respect Anybody's Privacy
The surveillance mafia that bans dissent or key people (even co-founders) with dissenting views
Gemini Links 31/03/2025: More X-Filesposting and Dreaming in Emacs
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, March 30, 2025
IRC logs for Sunday, March 30, 2025