Bonum Certa Men Certa

TechBytes Episode 69: Richard Stallman on Restricted Boot (UEFI), Coreboot, GRUB, and Boot Freedom

Techbytes 2012
Direct download as Ogg (0:13:28, 5.5 MB)



Summary: The first part of our interview with Richard Stallman covers Restricted Boot and related issues

I first interviewed Richard Stallman about 5 years ago. Yesterday I spoke to him about the subject of much debate in the Free software world right now. Here is a transcript of our conversation.

Dr. Roy Schestowitz: I want to know how big a threat you think the so-called "secure" boot is considered to be to the Free software movement.

Richard StallmanDr. Richard Stallman: It's a disaster. Well, except that it's not secure boot that's a disaster, it's restricted boot. Those are not the same. When it's front of the control of the user, secure boot is a security feature. It allows the user to control what programs can run on a machine and thus prevent -- you might say -- unexpected malware from running. We have to distinguish the unexpected malware such as viruses from the expected malware such as Windows or Mac OS or Flash Player and so on, which are also malware; they have features that hurt the user but users know what they are installing. In any case, what secure boot does is that it causes the machine to only work with (?) programs that are signed with a certain key, your keys. And as long as the user controls which keys they are, then it's a security feature. However, it can be chained into a set of digital handcuffs when the user doesn't control the keys. And this [is] happening.

"We have to distinguish the unexpected malware such as viruses from the expected malware such as Windows or Mac OS..."Microsoft demands that ARM computers sold for Windows 8 be set up so that the user cannot change the keys; in other words, turn it into restricted boot. Now, this is not a security feature. This is abuse of the users. I think it ought to be illegal.

It's a matter of control by the vendor of course, not control by the user himself

Exactly, and that's why it's wrong. That's why non-free software is wrong. The users deserve to have control of their computers/

I think that not only Windows is going to be an issue in fact, if you consider the fact that even a modified kernel is going to be in a position where it's perhaps not seen as verified for execution. Right, I'm saying, it might not only be a malicious feature in case of something like Windows running on it, it's also for -- let's say -- a user of the offered operating system but it's free if the user wants to modify the operating system, for example...

The thing is, if the user doesn't control the keys, then it's a kind of shackle, and that would be true no matter what system it is. After all, why is GNU/Linux better than Windows? Not just 'cause it has a different name. The reason it's better is because it's freedom-respecting Free software that the users control. But if the machine has restricted boot and the users can't control the system, then it would be just as bad as Windows. So, if the machine will only run a particular version of GNU/Linux, that is a restriction feature. And I haven't heard anyone doing that yet with GNU/Linux, but that's what Red Hat and Ubuntu are proposing to do things -- somewhat like that -- for future PCs that are shipped for Windows. But it's not exactly that. And my reason is, the users will be able to change the keys. They will be able to boot their own modified version of the system of Fedora or Ubuntu if they want. So, what Fedora and Ubuntu were proposing doesn't go all the way there. They're proposing to do things to make it more convenient for users to install the standard version of those systems. But if things go as it has been announced, users will still be able to change the keys and boot their own versions. So, if all the restricted boot -- but it will be something that goes sort of half-way there -- it's somewhat distasteful.

"The thing is, if the user doesn't control the keys, then it's a kind of shackle, and that would be true no matter what system it is."On the other hand, with Android, which is another mostly Free operating system which contains Linux but doesn't contain GNU, it's quite common for the product to have something equivalent to restricted boot, and people have to struggle to figure out how they can install a modified and more free version of Android. So, the presence of the kernel Linux in a system doesn't guarantee it's going to be better. And I've heard someone say -- oh, it hasn't been checked -- that a particular or kind of Android device is actually using an Intel chip with restricted boot.

One of the concerns that I think is worth raising is the fact that, as far as I know, with many of the embedded devices, especially those based on ARM, I believe it's not even possible to get into boot menu to disable so-called "secure"...

That's where Microsoft is really going all out, because Microsoft has ordered essentially -- demanded -- that those shipping ARM devices for Windows 8 make it restricted boot with no way to get around it.

Yeah, which also means of course waste of... all sorts of impacts on the environment. Any time that hardware become obsolete with the operating system itself is not being used of course...

"So it's a very damaging thing that Microsoft is doing and so we need to look for every possible way to stop them or tweak what they're doing."Well, it's worse than that. It means basically that those devices, you have to throw them out if you want to escape to the free world. And this -- in the past -- we were able to install, to liberate a computer by installing Free software on it instead of its user-restricting operation system, and this of course was tremendously helpful to the spread of GNU/Linux because it meant that users could move to freedom. It would be much harder if they had to buy another computer to do so. So it's a very damaging thing that Microsoft is doing and so we need to look for every possible way to stop them or tweak what they're doing.

Well, I wanted to ask you, one of our readers -- his name is Will -- is asking me if you have seen any new good hardware that can take coreboot.

I'm sorry, what?

One of my readers -- a guy called Will -- he has asked me if you have seen any new good hardware that can take coreboot.

"So, what we really need to do is make coreboot libre, just as we make Linux libre (which doesn't have the blobs)..."I don't know. Basically, I don't keep track of hardware models. I only remember their names anymore, except for the one I use, which is, the Lemote Yeelong and it doesn't run coreboot but it will run timar [?] in GRUB, it has a Free BIOS. When it comes it has a Free BIOS, which is why I chose it. But in terms of running coreboot, well, the machine which you run coreboot on are Intel-type machines. Now, there are a couple of... there is a problem, and that is, a lot of the Intel -- and also AMD -- CPUs require a microcode blob, and coreboot has these microcode blobs, which is the same kind of problem as firmware blobs in Linux. So, what we really need to do is make coreboot libre, just as we make Linux libre (which doesn't have the blobs), keep (?) the coreboot libre (which doesn't have the blobs) and then we need to see which processors actually run adequately without any microcode blob. And we're looking for somebody who wants to lead this project 'cause it takes work. Now, leading this project doesn't mean that you personally get all these kinds of hardware; oh, no, it would be asking the whole community to test things, but somebody has got to ask the community to do it, spread the word, receive the responses, put them together, and publish the list. Would (?) he like to do that? If he is really interested in having the answer to this question, maybe he'd like to help get the answer, and that would help the whole community.




More from Stallman is to be published in coming days.

We hope you will join us for future shows and consider subscribing to the show via the RSS feed. You can also visit our archives for past shows. If you have an Identi.ca account, consider subscribing to TechBytes in order to keep up to date.

As embedded (HTML5):







Keywords: UEFI Coreboot GRUB GNU FSF

Download:

Ogg Theora



Past shows in this series:



Show overviewShow title
Episode 66: Tim and RoyTechBytes Episode 66: First of the Second Series
Episode 67: Tim and RoyTechBytes Episode 67: Nokia Down, Android Up
Episode 68: RoyTechBytes Episode 68: Solo With Patents, Apple Bans, and Android World Domination

Recent Techrights' Posts

The Administrative Council of the European Patent Organisation Has More Reasons Than Cocainegate to Vote for Real Change in the European Patent Office
This is about democracy and accountability in Europe
 
Every Site That Uses Clownflare Had Worse Downtime/Uptime Record Than Ours
And the same goes for Azure and AWS
Software Freedom Conservancy (SFC) Does Not Work for Freedom, It Works to Secure the Massive Salary of Its President And Executive Director
We must be very effective then
Why (and When) I Become an 'Activist' Against Corruption and Abuse
The dictatorship bans criticism of the dictatorship. That's when there's a deadlock.
EPO Call for Action: Get Ready to Contact Your National Delegates, We Need to Remind Them That They Represent People
Today or tomorrow we'll publish contact details for national representatives in nearly 50 European nations
Links 05/12/2025: More Restrictions on Social Control Media and Slop, "Hype Can Turn to Backlash"
Links for the day
Like With Red Hat and Other IBM Acquisitions, the RAs (Layoffs) Seem to Already Extend to HashiCorp
Of course it is possible that HashiCorp staff just got PIP'ed or saw the writings on the wall and left [...] IBM is just a dying giant
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, December 05, 2025
IRC logs for Friday, December 05, 2025
Massachusetts Institute of Theft (MIT) Nowadays in the Business of Selling SPAM to Prop Up Fashionable Pyramid Schemes
There is nothing benign about it, more so when they misuse the MIT brand to lend credibility to elaborate schemes or scams
Many IBM Departures Today (Last Friday)
Way to go, IBM leadership
Gemini Links 05/12/2025: Need for Simpler Systems, Molecular Dynamics, and More
Links for the day
Slopwatch: Not Much Today, Same as in Recent Weeks
Google News got 'conned' (maybe willingly) by one operator of several (at least 3) slopfarms that trash "Linux"
On IBM: "More Layoffs in Minnesota Are Coming" (Unverified Hearsay, for Now)
IBM is having loads of layoffs before the holidays
Links 05/12/2025: Openwashing by Microsoft's 'Open Source' Initiative, Unauthorised War Without Boundaries/Borders Waged by US
Links for the day
Finnish Politician Aura Salla Says Finland Must Dump Microsoft, Citing Security and Control Reasons, Not Costs
She says Finland should quit using Microsoft
Does This Pass the NDA "Sniff Test" at IBM?
In many companies, those who suck up to management get ahead
Links 05/12/2025: Slop Harming Democracy/Elections, More Bans Around the World on Kids' Use of Social Control Media
Links for the day
IBM Has No Layoffs, According to IBM, and According to the Media Parroting IBM
Another day of parrots (losers) who call themselves "journalists"
IBM Will Make You Unemployed On Christmas Eve
lists of people to cull
Within Weeks, Clownflare Has Collapsed Again, Time to Dump Clownflare
It's run by amateurs who, even if you maintain your site perfectly well, will render it inaccessible without prior notice
Cars Getting Worse and More Lethal
Who will be held accountable?
To "Take Back Control" Start With Actions Against 'Tech' (Mass Surveillance, Mass Censorship, Mass Control) Monopolies
collusion, price-fixing, a "cartel" of sorts
Beyond the Hype: Almost Nobody Uses Chatbots, Not Even 1% of Activity Online
3 years ago when Scam Altman (Microsoft) acted as if Google (search) was doomed a lot of the press got paid to pretend this was true
Rumour That Another IBM Round of Mass Layoffs (RAs) in Preparation Before the Current One is Even Completed
IBM still has strong brand recognition (because of its age and past might), but that won't last forever
Techrights Publication Pace to Increase Next Year
one is encouraged to stay indoors
Upgrading the Site
Debugging might be needed, so feedback helps
Why Microsoft is Panicking
Keep advocating (or "marketing") GNU/Linux to Vista 10 (or Vista 7) users... there are still over a billion of them "out there".
Web Developers in the US Can Already Disregard Mozilla, Firefox, and Firefox Users
"Last month, Firefox turned 21"
The Fate of "Blockchains" and "Metaverse" as a Sign of Things to Come for Slop ("AI")
Doesn't that tell us a lot about the modus operandi of these companies?
A Year After the Owner of X (Twitter) Performed Several Nazi Salutes on Stage the Germany-Based and Microsoft-Funded 'FSFE' Decides to Exit X (Twitter)
Will the real Free Software Foundation (FSF) follow suit?
EPO: What Comes Next
European media seems to have been sedated by soft bribes from cocaine addicts
Slopwatch: The Volume of Slop Has Certainly Gone Down a Lot Lately, Slop Image Providers Abandoned/Changed
It's a big improvement compared to past months
Thousands Laid Off at IBM, "Last Day" Yesterday
IBM is a dying company. This is a problem for Red Hat.
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, December 04, 2025
IRC logs for Thursday, December 04, 2025
Gemini Links 05/12/2025: Espressif ESP32-C5 UEXT Module, Pixelfed, and the Web Getting Much Worse
Links for the day
Links 04/12/2025: "People Hooked on [Slop] Far Are More Likely to Experience Mental Distress", Monopolies in Europe, and "Blogging Makes Me Feel Like A Worse Writer"
Links for the day
Dr. Andy Farnell: Can we regain control (of technology)?
"Technology as spiralling mass hysteria has the unsettling potential to draw even rational sceptics like myself into disaffection"
Links 04/12/2025: "Hey Hi" Implosion and Half of Europeans See Cheeto Trump as Enemy of Europe
Links for the day
Communication Needs Open Standards and Open Data
Standards are imperative
The "Hey Hi" House of Cards
The "Hey Hi" bubble is living on borrowed time (days or weeks) and it can implode any time now
Supporting the Free Software Foundation (FSF) Also Supports GNU Development
The FSF is mostly raising money to pay salaries
IBM's "AK Sez" Campaign
In today's media, to be characterised as important and smart one needn't be important and smart
Microsoft's Vista 11 Not Gaining, Just Plateauing or Even Going Down (Over Time)
"Desktop Windows version Market Share Worldwide"
Bubbles Popping, "Hey Hi" (AI) a Passing Fad
"Microsoft slides amid report it's cutting software sales quotas tied to AI"
At The Register MS, "Exclusive Webinar" Means Sponsored Video Ad Disguised as an Article
Why would one choose to watch these?
IBM Forces Staff to Sign an NDA If They Want Severance Package, in Effect Bribing Them or Denying Them Money They're Entitled to If They 'Disparage' IBM
We wrote about the legality or illegality of this in relation to Microsoft two years ago
IBM and Red Hat Not Done With 2025 Layoffs ("RAs") Yet
IBM isn't quite done laying off people this year, with only 3 weeks till Christmas
Gemini Links 04/12/2025: Christmas Looms, Devuan, and Programming
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, December 03, 2025
IRC logs for Wednesday, December 03, 2025