Bonum Certa Men Certa

UEFI Firmware Code Bricks Linux. Another Reason 'Security Threatre' Placebo of Microsoft and Intel Must be Avoided.

posted by Roy Schestowitz on Oct 31, 2023

Lenovo forums

Reprinted with permission from Ryan Farmer.

Bad Lenovo UEFI Firmware Causes Nine Models to Freeze on Resume from Suspend. Delays Linux 6.6.

I don’t even want to write about Lenovo again in my life, since they are such a nasty company, but Roy asked me to say something.

Ever since 2016 when they admitted to me that there was a deal with Microsoft to lock Linux out of the Yoga 900 ISK2, but then proceeded to defame me after the media reported on a Reddit post I made on the subject that went viral, and then quietly fixed it after I took legal action against them, I’ve been telling people what a super shitty company they are.

Lenovo is a Chinese company, so it probably shouldn’t come as any shock that they banned everyone in the State that I live in from commenting on their forum until the scandal died down.

In China, when someone is talking, you typically figure out abhorrent ways to stop them from talking, which don’t work in a Free country. For Lenovo, really all they could do was try to silence people on their own support forum, but by then it was too late.

They also indiscriminately banned anyone who talked about “hacking” the board with an external flasher to unhide the “ACPI” option (to allow other operating systems to see the storage device), which was always present, but hidden as per their illegal contract with Microsoft, which they quickly got scrapped after the State of Illinois started investigating them.

The late 2020 Tiger Lake-based ThinkBook 15 I have is a little better.

Lenovo’s advice was to disable “Secure Boot”, as all it has ever done for Linux is cause problems due to extra complexity and bugs, as it is a Microsoft requirement to license Windows to OEMs, which is the default state of the laptop. “Secure Boot” actually does nothing to secure the computer from most any actual security threat that anyone really faces.

In at least one case, on my Yoga 900 ISK2, Ubuntu updated the “Secure Boot” dbx due to “Boothole”, and the revocation update (dbx) caused Fedora to fail to boot with a “Security policy violation.”

To unjam it I had to reset “Secure Boot” to the factory settings and that apparently wiped the dbx update. At that point I turned “Secure Boot” off and have never turned it on after removing Windows from a PC since then.

Lenovo’s other advice for this laptop, even though the “fake RAID” support was added to Linux after the 2016 incident by Intel (after they refused to document it for over a year!), is to turn that off and set the disk controller to “AHCI”.

Matthew Garrett claimed that this had something to do with power management, but he was either wrong or lying, because when I run powertop as a system service (to set all power management tunables to on), I always get better battery life than Windows does.

He’s very obtuse, and it’s probably because his job at various points in time involved implementing Microsoft nonsense like “Secure Boot” in Linux.

They need to get rid of the “Free Software Award” because they have such a bad habit of giving it to the wrong people.

(It’s like watching Donald Trump putting the Presidential Medal of Freedom on people at this point.)

Other than a bunch of “FIRMWARE BUG” crap on my 2020 Lenovo laptop that prints to the screen (which Windows and IBM Fedora hides, but Debian doesn’t), the laptop works fine with Linux.

But Lenovo released, apparently, more than nine models of AMD-based laptops with UEFI bugs that prevent the user from resuming from suspend due to fatal ACPI errors, which includes the AMD option for the laptop model I’m writing this on.

Although, mine’s an Intel, so in your face to all those “AMD is better” people. πŸ™‚

The Linux kernel’s 6.6 release was delayed while workarounds that added 78 more lines of firmware bug workarounds was added.

Linus Torvalds was obviously furious, but criminals and idiots put him in therapy for yelling at them with incompetent code in the past, and he put Linux under the control of a now Microsoft-controlled “Linux Foundation” and so to keep his job, he can’t say much anymore.

According to Roy Schestowitz, the culprit was something that a Chinese man exhaling some sort of smoke (to look macho I guess?) on his Microsoft GitHub page did in the ACPI code in the Linux kernel.

Apparently, his name is Huacai Chen and he works at Loongson.

Linus Torvalds very obviously wanted to scream at him (backscroll and read down) for moving ACPI code around to fix something and then breaking other things, then hiding that they were broken until users started writing in saying they upgraded their kernel, some stuff happened, and kersplat.

I don’t even plan to stay on the PC after this laptop unless I decide to buy a model with open source firmware from System76 instead of this Lenovo garbage which is barely even code.

UEFI is garbage, Microsoft is garbage, Lenovo is fucking garbaaaage. The entire PC situation is cat shit wrapped in dog shit. And the people working on things like “Secure Boot in Linux” just make it so much worse from there.

This is the worst time to own a x86 PC, EVER.

Lenovo has never supported updating your UEFI firmware on most of their products using anything available to Linux users, even LVFS, which is a backdoor, and I wouldn’t trust them not to brick my computer or make it worse if they did.

I uninstalled LVFS because it started spitting an error message into Debian. It’s in charge of updating the dbx, but fuck dbx, fuck “Secure Boot” (which makes it harder to plug actual security holes), fuck Microsoft, and fuck the people Microsoft gets to make this my problem.

As a user, I just think these things are deplorable, but large corporations have turned Linux into some shitty colony where they can put DRM malware, universal backdoors, and absolutely broken shit with no repercussions. None. Not even that Linus Torvalds might yell at them.

So the last time the UEFI in my ThinkBook 15 was updated was August 2021, when I switched it over to Linux.

By that point, they had fixed most of the really nasty bugs they shipped the laptop with, which were even causing problems in Windows, but as firmware upgrades are dangerous and I have no warranty now, and they require Windows, I don’t plan to touch the firmware on this laptop ever again.

It’s just not worth it. One of the bigger problems with UEFI is that it’s just such a monster that you can keep fixing bugs forever, and that’s why “Secure Boot” will never work even if they wanted it to.

If you could get past the issues like “This is barely even code. It’s just a pile of garbage.”, the x86 PC might be worth plodding along with.

Now that they make the Raspberry Pi 5, and it’s several times faster than its predecessor, I wonder why we’re even talking about sticking around for more abuse.

When the UEFI firmware Lenovo ships is so fragile that a guy working for a hardware company making totally unrelated MIPS processors in China bumps something and an x86 Lenovo laptop that people bought THREE GODDAMN YEARS AGO starts malfunctioning if anyone installs that kernel, it’s time to look for greener fields.

UEFI is such a catastrophe, that it’s not even just a Freedom issue.

It’s such a massive fucking colossal failure on a code level that Google, which certainly doesn’t care about your Freedom, based the Chromebook firmware on a variation of Coreboot.

My next system will probably just be Linux running off some cheap flash memory on a ~$80 ARM computer. The fact that the Pi 5 finally has a SKU with 8 GB RAM really REALLY helps. With the help of ZStandard compressed ZRam, you can make KDE work with this.

No more of these $1,000 Lenovo PC laptops full of LULZ for firmware and Chinesium keyboards where buttons randomly break and need to be remapped to another key because they’re three years old, and playing “How do I brutally murder Windows 11 this time? Hmm…. DIE DIE DIE!!!!!” β–ˆ

Lenovo forums

Other Recent Techrights' Posts

12 Days Have Passed Since the Edward Brocklesby Revelations and Debian Project Has Said Absolutely Nothing About That
One must therefore assume they have nothing to say in their defence (covering up severe security failings)
Coercion From the "Consent" and "CoC" Crowd is a Self-Defeating Tactic
Freedom of the press; Nothing less
According to statCounter, GNU/Linux Increased From 3.77% to 3.89% This Month (Worldwide), Windows Now Below 20% in 78 Nations, Below 10% in 27 Nations
Highest since March (for GNU/Linux)
 
One More (Failed) Attempt to Deplatform the Sites by Harassing and Threatening Webhosts
What we're seeing here is a person who abuses the system in Canada at Canadian taxpayers' expense trying to do the same in the UK, at British taxpayers' expense
[Meme] Shitburger of an LLM
IBM and the Hololens
Links 17/06/2024: Chatbot Nonsense Thrown Under the Bus (Severe Failure, Pure Hype), How to Finance Free Software 'Hackers'
Links for the day
Debian's Personal Attacks Are Upsetting Women, Too
Female Debian Developer: "I Believe Daniel [Pocock] is On the Right Track."
Microsoft's Bing is So Irrelevant in Moldova (1%) That Russia's Yandex is About 5 Times Bigger
How much longer before Microsoft throws in the towel?
Yes, You Can
Unless you live somewhere like Russia...
[Meme] Listen to the Experts
Bill Gates didn't even finish university]
Roy and Rianne's Righteously Royalty-free RSS Reader (R.R.R.R.R.R.) and the Front-End Interfaces
As the Web deteriorates the availability, quality and prevalence of RSS feeds is not improving, to put it mildly
Algeria Shows High GNU/Linux and Android Adoption, All-Time High and Almost Three-Quarters of Web Requests
GNU/Linux was below 3%, now it is above 3%
Mass Layoffs at Microsoft-owned GitHub (About 80 Percent of the Staff in India Laid Off)
It's not just in India
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, June 16, 2024
IRC logs for Sunday, June 16, 2024
Gemini Links 16/06/2024: Scarecrows, Moles, Ham Radio, and No IPs
Links for the day
Africa is Android and Green (Chrome, Not Just Android Logo)
In Africa Firefox is almost below 1% now
Covering Abuses and Corruption
We'll never surrender to blackmail
Ubuntu Running Out of Energy
Its planet too is deteriorating
Links 16/06/2024: In Defence of Email and Why Recycling Symbol Lost All Meaning
Links for the day
Gemini Links 16/06/2024: Computer Science Course Union and Potentiometer
Links for the day
Cross border crime: sale of Swiss insurance in France and European Union without authorisation
Reprinted with permission from Daniel Pocock
Letting Microsoft systemd Manage /home Was a Terrible Idea All Along
systemd-tmpfiles, deleting /home
Patriotism is OK, But We Need Facts and Reason, Not Blind Obedience to Authority
Very seldom in the history of human civilisation has groupthink proven to be of real merit
When You Touch One of Us You Touch All of Us
We have a principled, uncompromising stance on this matter
Links 16/06/2024: New Sanctions Against Russia, Fentanylware (TikTok) Causing More Problems
Links for the day
Social Control Media in Japan: Twitter (X) Has Collapsed, YouTube Rising (Apparently)
What a genius Mr. Musk is!
Windows Cleansed in South Africa (Already Hovering Around 10% Market Share)
Plus Microsoft's mass layoffs in Africa
[Meme] Satya Nadella's Windows PC RECALLS Not What He Did
Satya got lucky
Usage of Let's Encrypt in Geminispace Has Collapsed (That's a Good Thing!)
Ideally, or eventually, all capsules will sign their own certificates or have their own CA
North Macedonia: Windows Down From 99.2% to 28.5%
Last year it was even measured at 26%
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, June 15, 2024
IRC logs for Saturday, June 15, 2024
Gemini Links 16/06/2024: Hand Held Maneuvering Unit and Hugo Static Files
Links for the day
Removing the Tumour From IRC
looking back
[Meme] The Free(dom) Software Engineer in European Elections
β€œWhen the debate is lost, slander becomes the tool of the loser.”
Vista 11 Was 'Leaked' Exactly 3 Years Ago and This One Picture Says It All
how 'well' Vista 11 has done
A Smokescreen for Brad Smith
Maybe the key point was to say "Linux is not secure either" or "Windows and Linux are equally vulnerable", so don't bother dumping Microsoft
Windows Sinking Below 13% Market Share in the Island of Jamaica
Microsoft's decline continues and will mostly likely continue indefinitely in Jamaica and its neighbours
Links 15/06/2024: Microsoft's Intellectual Ventures Attacks Kubernetes With Software Patents, More Layoff Waves
Links for the day
Gemini Links 15/06/2024: On Lagrange and on YouTube Getting Worse
Links for the day
Edward Brocklesby: hacker received advance notice of zero-day vulnerabilities in MH and NMH email software
Reprinted with permission from Daniel Pocock
[Meme] Code Liberates Kids
Matthias Kirschner: I can't code, but I can write a book
In Armenia, Bing is Measured at 0.6%, About Ten Times Less Than Yandex
Bing will probably get mothballed in the coming years
[Meme] A Pack and Pact (Collusion Against Computer Users)
They never really cared about users, no more than drug dealers care about drug users...
GNU/Linux in Azerbaijan: From ~0.1% to 7%
Azerbaijan is around the same size as Portugal
Women in Free Software (FOSS) Need Action, Not Mere Words
the men who are loudest about women's rights are some of the very worst offenders
Embrace, Extend, Extinguish Minecraft
These folks should check out Minetest
Techrights Statement on Men Who Viciously Attack Women in Free Software
history shows women will win
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, June 14, 2024
IRC logs for Friday, June 14, 2024
[Meme] People Who Cannot Find Gainful Employment Because of Their Poor Behaviour Online (Not the People Who Merely Call Them Out on It)
Imagine trying to become a lecturer while talking like this in public
You Too Would Get Nervous
countries where Windows is down to 2%
[Meme] The Two Phases (and Faces) of Microsofters
Microsofters: stalk IRC, then troll IRC
The 'Nobody Reads Techrights Anyway' Crowd
Send In the Clowns
Books in the Making
I intend to spend a considerable amount of time explaining what my family and I were subjected to for the 'crime' of promoting/covering Free software
Microsoft is Still Losing Malta
And GNU/Linux is doing well on laptops and desktops
Tux Machines: Third Party Impending
There will be more next week