Bonum Certa Men Certa

UEFI Firmware Code Bricks Linux. Another Reason 'Security Threatre' Placebo of Microsoft and Intel Must be Avoided.

posted by Roy Schestowitz on Oct 31, 2023

Lenovo forums

Reprinted with permission from Ryan Farmer.

Bad Lenovo UEFI Firmware Causes Nine Models to Freeze on Resume from Suspend. Delays Linux 6.6.

I don’t even want to write about Lenovo again in my life, since they are such a nasty company, but Roy asked me to say something.

Ever since 2016 when they admitted to me that there was a deal with Microsoft to lock Linux out of the Yoga 900 ISK2, but then proceeded to defame me after the media reported on a Reddit post I made on the subject that went viral, and then quietly fixed it after I took legal action against them, I’ve been telling people what a super shitty company they are.

Lenovo is a Chinese company, so it probably shouldn’t come as any shock that they banned everyone in the State that I live in from commenting on their forum until the scandal died down.

In China, when someone is talking, you typically figure out abhorrent ways to stop them from talking, which don’t work in a Free country. For Lenovo, really all they could do was try to silence people on their own support forum, but by then it was too late.

They also indiscriminately banned anyone who talked about “hacking” the board with an external flasher to unhide the “ACPI” option (to allow other operating systems to see the storage device), which was always present, but hidden as per their illegal contract with Microsoft, which they quickly got scrapped after the State of Illinois started investigating them.

The late 2020 Tiger Lake-based ThinkBook 15 I have is a little better.

Lenovo’s advice was to disable “Secure Boot”, as all it has ever done for Linux is cause problems due to extra complexity and bugs, as it is a Microsoft requirement to license Windows to OEMs, which is the default state of the laptop. “Secure Boot” actually does nothing to secure the computer from most any actual security threat that anyone really faces.

In at least one case, on my Yoga 900 ISK2, Ubuntu updated the “Secure Boot” dbx due to “Boothole”, and the revocation update (dbx) caused Fedora to fail to boot with a “Security policy violation.”

To unjam it I had to reset “Secure Boot” to the factory settings and that apparently wiped the dbx update. At that point I turned “Secure Boot” off and have never turned it on after removing Windows from a PC since then.

Lenovo’s other advice for this laptop, even though the “fake RAID” support was added to Linux after the 2016 incident by Intel (after they refused to document it for over a year!), is to turn that off and set the disk controller to “AHCI”.

Matthew Garrett claimed that this had something to do with power management, but he was either wrong or lying, because when I run powertop as a system service (to set all power management tunables to on), I always get better battery life than Windows does.

He’s very obtuse, and it’s probably because his job at various points in time involved implementing Microsoft nonsense like “Secure Boot” in Linux.

They need to get rid of the “Free Software Award” because they have such a bad habit of giving it to the wrong people.

(It’s like watching Donald Trump putting the Presidential Medal of Freedom on people at this point.)

Other than a bunch of “FIRMWARE BUG” crap on my 2020 Lenovo laptop that prints to the screen (which Windows and IBM Fedora hides, but Debian doesn’t), the laptop works fine with Linux.

But Lenovo released, apparently, more than nine models of AMD-based laptops with UEFI bugs that prevent the user from resuming from suspend due to fatal ACPI errors, which includes the AMD option for the laptop model I’m writing this on.

Although, mine’s an Intel, so in your face to all those “AMD is better” people. 🙂

The Linux kernel’s 6.6 release was delayed while workarounds that added 78 more lines of firmware bug workarounds was added.

Linus Torvalds was obviously furious, but criminals and idiots put him in therapy for yelling at them with incompetent code in the past, and he put Linux under the control of a now Microsoft-controlled “Linux Foundation” and so to keep his job, he can’t say much anymore.

According to Roy Schestowitz, the culprit was something that a Chinese man exhaling some sort of smoke (to look macho I guess?) on his Microsoft GitHub page did in the ACPI code in the Linux kernel.

Apparently, his name is Huacai Chen and he works at Loongson.

Linus Torvalds very obviously wanted to scream at him (backscroll and read down) for moving ACPI code around to fix something and then breaking other things, then hiding that they were broken until users started writing in saying they upgraded their kernel, some stuff happened, and kersplat.

I don’t even plan to stay on the PC after this laptop unless I decide to buy a model with open source firmware from System76 instead of this Lenovo garbage which is barely even code.

UEFI is garbage, Microsoft is garbage, Lenovo is fucking garbaaaage. The entire PC situation is cat shit wrapped in dog shit. And the people working on things like “Secure Boot in Linux” just make it so much worse from there.

This is the worst time to own a x86 PC, EVER.

Lenovo has never supported updating your UEFI firmware on most of their products using anything available to Linux users, even LVFS, which is a backdoor, and I wouldn’t trust them not to brick my computer or make it worse if they did.

I uninstalled LVFS because it started spitting an error message into Debian. It’s in charge of updating the dbx, but fuck dbx, fuck “Secure Boot” (which makes it harder to plug actual security holes), fuck Microsoft, and fuck the people Microsoft gets to make this my problem.

As a user, I just think these things are deplorable, but large corporations have turned Linux into some shitty colony where they can put DRM malware, universal backdoors, and absolutely broken shit with no repercussions. None. Not even that Linus Torvalds might yell at them.

So the last time the UEFI in my ThinkBook 15 was updated was August 2021, when I switched it over to Linux.

By that point, they had fixed most of the really nasty bugs they shipped the laptop with, which were even causing problems in Windows, but as firmware upgrades are dangerous and I have no warranty now, and they require Windows, I don’t plan to touch the firmware on this laptop ever again.

It’s just not worth it. One of the bigger problems with UEFI is that it’s just such a monster that you can keep fixing bugs forever, and that’s why “Secure Boot” will never work even if they wanted it to.

If you could get past the issues like “This is barely even code. It’s just a pile of garbage.”, the x86 PC might be worth plodding along with.

Now that they make the Raspberry Pi 5, and it’s several times faster than its predecessor, I wonder why we’re even talking about sticking around for more abuse.

When the UEFI firmware Lenovo ships is so fragile that a guy working for a hardware company making totally unrelated MIPS processors in China bumps something and an x86 Lenovo laptop that people bought THREE GODDAMN YEARS AGO starts malfunctioning if anyone installs that kernel, it’s time to look for greener fields.

UEFI is such a catastrophe, that it’s not even just a Freedom issue.

It’s such a massive fucking colossal failure on a code level that Google, which certainly doesn’t care about your Freedom, based the Chromebook firmware on a variation of Coreboot.

My next system will probably just be Linux running off some cheap flash memory on a ~$80 ARM computer. The fact that the Pi 5 finally has a SKU with 8 GB RAM really REALLY helps. With the help of ZStandard compressed ZRam, you can make KDE work with this.

No more of these $1,000 Lenovo PC laptops full of LULZ for firmware and Chinesium keyboards where buttons randomly break and need to be remapped to another key because they’re three years old, and playing “How do I brutally murder Windows 11 this time? Hmm…. DIE DIE DIE!!!!!” â–ˆ

Lenovo forums

Other Recent Techrights' Posts

'Dark Patterns' or a Trap at the European Patent Office (EPO)
insincere if not malicious E-mail from the EPO's dictators
There's an Abundance of Articles About the New Release of Kali Linux, But This One is a Fake
It can add nothing except casual misinformation (fed back into the model to reinforce lies)
IBM's Leadership Ruining Lives of People Who Thought Working for IBM Would be OK
Nobody gets fire-lined for buying IBM?
The United States' Authorities Ought to Become Enforcers of the General Public License (GPL) for National Security's Sake
US federal agencies ought to pursue availability of code and GPL compliance (copyleft), not bans
The Problem of Microsoft Security Problems is Microsoft (the Solution is to Quit Microsoft) and "Salt Typhoon" Coverage Must Name CALEA Back Doors
Name the holes, not those who exploit them.
A "Year of Efficiency"
No, we don't mean layoffs
 
LLM Slop Disguised as Journalism: The Latest Threat to the Web
A lot of it is to do with proprietary GitHub, i.e. Microsoft
Gemini Links 20/12/2024: Regulation and Implementing Graphics
Links for the day
Links 20/12/2024: Windows Breaks Itself, Mass Layoffs Coming to Google Again (Big Wave)
Links for the day
Microsoft: "Upgrade" to Vista 11 Today, We'll Brick Your Audio and You Cannot Prevent This
Windows Update is obligatory, so...
The Unspeakable National Security Threat: Plasticwares as the New Industrial Standard
Made to last or made to be as cheap as possible? Meritocracy or industrial rat races are everywhere now.
Microsoft's All-Time Lows in Macao and Hong Kong
Microsoft is having a hard time in China, not only for political reasons
[Meme] "It Was Like a Nuclear Winter"
This won't happen again, will it?
If You Know That Hey Hi (AI) is Hype, Then Stop Participating in It
bogus narrative of "Hey Hi (AI) arms race" and "era/age of Hey Hi" and "Hey Hi Revolution"
Bangladesh (Population Close to 200 Million) Sees Highest GNU/Linux Adoption Levels Ever
Microsoft barely has a grip on this country. It used to.
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, December 19, 2024
IRC logs for Thursday, December 19, 2024
Gemini Links 19/12/2024: Fast Year Passes and Advent of Code Ongoing
Links for the day
Twitter is Going to Fall Out of Top 100 Domains as Clownflare (DNS MitM) Sees It
evidence of Twitter's (X's) collapse
[Meme] Making Choices at the EPO
Decisions, decisions...
Large and Significant Error Correction in South America?
Windows now has less than half what Android achieved in terms of "market share"
Links 19/12/2024: Astronaut Record and Observer Absorbed
Links for the day
Links 19/12/2024: Seven Dirty Words and Isle Release v0.0.3 (Alpha)
Links for the day
Links 19/12/2024: Nurses Besieged by "Apps", More Harms of Social Control Media Illuminated
Links for the day
15 Countries Where Yandex is Already Seen to be Bigger Than Microsoft (in Search)
Georgia, Syrian Arab Republic, Cyprus, Moldova, Ukraine, Armenia, Azerbaijan, Kyrgyz Republic, Uzbekistan, Kazakhstan, Turkmenistan, Tajikistan, Belarus, Turkey, and Russia
Links 19/12/2024: Magnitude 7.3 Earthquake and Privacy Camp
Links for the day
Gemini Links 19/12/2024: Port Of Miami Explosion, TurboQOA, Gnus
Links for the day
Fake Articles About 'Linux'
Dated yesterday
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, December 18, 2024
IRC logs for Wednesday, December 18, 2024
FSF Has Made It Halfway to Its Target (Funding Goal) a Week Before Christmas Day
$400,000 definitely seems reachable now, especially if they extend the "deadline"
[Meme] The Master Churnalist
Speaking of press releases being passed off as "journalism"
Spamnil's TFiR: Still Pretending Press Releases Are 'Articles' (TFiR 'Originals' as Plagiarism or Fluff)
Same as last year
Links 18/12/2024: Zakir Hussain Dies, TuneIn Layoffs
Links for the day
Links 18/12/2024: Karate Love and Advent of Code
Links for the day
Windows (or Microsoft) Has Become the "One Percent" (Market Share) in Chad
How long before it falls below 1%?
Arvind Krishna, IBM's CEO, Will Eventually Suck Up to Donald Trump Like His Predecessor Did or the Watson Family Did With Adolf Hitler
Literally Hitler
Being a Geek Need Not Mean Being Sedentary
"In the past 18 months," Berkholz writes, "I’ve lost 75 pounds and gone from completely sedentary to fit, while minimizing the effort to do so (but needing a whole lot of persistence and grit)."
GAFAM Kissing the Ring of the Mafia Don
"resistance" to dictatorship and defenders of democracy?
Slop Spaghetti From the Chef, Second Time Today
Fresh slop ready out the oven!
IBM - Like Microsoft - Lies About the Number of People It's Laying Off (Several Tens of Thousands, Not Counting R.T.O. "Silent" Layoffs and Contractors/Perma-Temps)
How many waves of silent layoffs have we seen so far at IBM this year?
Links 18/12/2024: EU Launches Probe Into TikTok (At Last!)
Links for the day
Links 18/12/2024: Doha/Qatar Trafficking, Bloat Comfort Zone, and Advent of Code 2024
Links for the day
Saving What's Left of Decent and Independent Journalism on the Web
We increasingly (over time) try to make local copies (hosted on our server) of important documents; it's hard to rely on third parties
[Meme] Microsoft's Latest Marketing Pitch
"Stop Being Poor; buy a new PC with TPMs"
In South Africa, a Very Large Nation, Web Developers Can Already Ignore Microsoft Browsers (Edge Measured Below 3% in 55 Nations)
The dumb assumption you must naively test with Microsoft browsers is no longer applicable in a lot of places
Open Source Initiative (OSI) is the Voice of Bill Gates and Satya Nadella
Not hard to see what they've done with the money
Microsoft Boasts That Its (Microsoft-Sponsored) "Open Source AI" Propaganda Got Cited in Media (That's Just What the Money Did)
This is a grotesque openwashing campaign
In Many Places Around the World, Perhaps as Expected, Yandex is Nearly Bigger Than Microsoft (Like in Several African Countries)
Microsoft may soon fall to "third place" in search
Keeping Productive This Christmas
We've (pre)paid for hosting till almost January 2026 and fully back on the saddle
IBM and Canonical Leave Money on the Table Because Microsoft Pays Them Not to Compete and Instead Market Windows, WSL, Microsoft 'Clown Computing', and TPMs
Where are the regulators?
Other Editors Who Agree "Hey Hi" (AI) is Just Hype But Won't Say So Publicly as It Might Upset Key Sponsors
Some media would gladly participate in a scam to make money
Brian Fagioli's Latest "Linux" Article Appears to be Fake
Another form of plagiarism/ripoff using bots?
IBM (and Red Hat) is a Patent Troll, Still Leveraging Software Patents to Extract Money Out of Other Companies by Suing Them
Basically, when it comes to patents, IBM is demonstrably part of the problem, not the solution
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, December 17, 2024
IRC logs for Tuesday, December 17, 2024