Bonum Certa Men Certa

Nothing Says 'New' Microsoft Like Microsoft Component Firmware Update (More Hardware Lock-in)

"One thing I find myself wondering about is whether we shouldn't try and make the "ACPI" extensions somehow Windows specific.

"It seems unfortunate if we do this work and get our partners to do the work and the results is that Linux works great without having to do the work.

"Maybe there is no way to avoid this problem but it does bother me.

"Maybe we could define the APIs so that they work well with NT and not the others even if they are open.

"Or maybe we could patent something related to this."

--Bill Gates





Summary: Vicious old Microsoft is still trying to make life very hard for GNU/Linux, especially in the OEM channel/s, but we're somehow supposed to think that "Microsoft loves Linux"

YESTERDAY we saw Red Hat's (now IBM's) Richard Hughes complaining about Microsoft [1], whereupon Phoronix picked that up [2] and it was then discussed in our IRC channels, Phoronix forums etc. The corporate media obviously showed no interest in it. All it can do is post "Microsoft loves Linux" images because Microsoft asks for that. To quote Richard: "All the dependency resolution should be in the metadata layer (e.g. in the .inf file) rather than being pushed down to the hardware running the old firmware."



“All the dependency resolution should be in the metadata layer (e.g. in the .inf file) rather than being pushed down to the hardware running the old firmware.”
      --Richard Hughes
As Michael Larabel put it, "implementation has a number of issues that complicate the process and could quickly evolve into another troubling specification from Microsoft in the hardware space."

Remember UEFI 'secure boot'? How did that work out for security?

Microsoft certainly loves Linux with a knife in the back -- hence Bill Gates' "Jihad" remark (about Intel's support for Linux). MinceR at the #techrights IRC channel said: "you can tell something from Microsoft is _really_ _really_ shit when their sycophants at GNOME say it's shit..."

"Nowadays Zemlin is mostly quoted by the media as saying wonderful things about Microsoft. Most GNU/Linux user just want to vomit."It is worth remembering that Richard's work is now supported by the Linux Foundation (since months ago when it adopted LVFS), so maybe Richard can explain to the Linux 'genius' Jim Zemlin (who never uses Linux) what Microsoft does here and why it is anticompetitive. We don't suppose this will happen though. Zemlin is a 'true believer' in Microsoft and his wife managed a close partner of Microsoft when Microsoft paid the Linux Foundation. Nowadays Zemlin is mostly quoted by the media as saying wonderful things about Microsoft. Most GNU/Linux user just want to vomit. Money talks; people who love money are therefore a vulnerability. Jim Zemlin and his wife are the sorts of people whose life aspiration is to have dinner with Bill and Melinda Gates. It's all about class and power (Harvard). A decade ago Jim Zemlin said negative things about Microsoft and now (after/since Microsoft had given him $500,000) he says Microsoft is a good company while ignoring the below among many other things, patent extortion included (it's still going on). His wife worked for a Gold Microsoft Partner at the time (as a General Manager and Global VP of a SaaS Business Unit). Her business was moving companies to something like Microsoft Azure. In his own words (Jim Zemlin's interview with Jeremy Allison; 1m:30s), "I'm about as much [boss of Torvalds] as I am the boss of my wife..."

Related/contextual items from the news:



  1. Musings on the Microsoft Component Firmware Update (CFU) Protocol

    CFU has a bazaar pre-download phase before sending the firmware to the microcontroller so the uC can check if the firmware is required and compatible. CFU also requires devices to be able to transfer the entire new transfer mode in runtime mode. The pre-download “offer” allows the uC to check any sub-components attached (e.g. other devices attached to the SoC) and forces it to do dep resolution in case sub-components have to be updated in a specific order.

    Pushing the dep resolution down to the uC means the uC has to do all the version comparisons and also know all the logic with regard to protocol incompatibilities. You could be in a position where the uC firmware needs to be updated so that it “knows” about the new protocol restrictions, which are needed to update the uC and the things attached in the right order in a subsequent update. If we always update the uC to the latest, the probably-factory-default running version doesn’t know about the new restrictions.

    The other issue with this is that the peripheral is unaware of the other devices in the system, so for instance couldn’t only install a new firmware version for only new builds of Windows for example. Something that we support in fwupd is being able to restrict the peripheral device firmware to a specific SMBIOS CHID or a system firmware vendor, which lets vendors solve the “same hardware in different chassis, with custom firmware” problem. I don’t see how that could be possible using CFU unless I misunderstand the new .inf features. All the dependency resolution should be in the metadata layer (e.g. in the .inf file) rather than being pushed down to the hardware running the old firmware.



  2. Microsoft's Component Firmware Update Is Their Latest Short-Sighted Spec

    Microsoft's newest specification is the "Component Firmware Update" that they envision as a standard for OEMs/IHVs to be able to handle device firmware/microcode updating in a robust and secure manner. While nice in theory, the actual implementation has a number of issues that complicate the process and could quickly evolve into another troubling specification from Microsoft in the hardware space.

    Red Hat's Richard Hughes who is the lead developer on Fwupd and LVFS for firmware updating on Linux has written a lengthy blog post with his thoughts after studying the specification. Now that vendors have begun asking him about CFU, he's getting his opinions out there now and there are issues with the specification. Ultimately though if there is enough interest/adoption, he could support Component Firmware Update via Fwupd but he certainly isn't eager to do so.



Recent Techrights' Posts

IBM: We Pay You to be Obedient or Deny You What You're Entitled to If You Don't Act Obediently
Good luck starting legal battles with a company that has almost as many lawyers (including aggressive patent lawyers) as it has geeks
Russian "Hybrid Attacks" Are Typically Microsoft TCO and/or Windows TCO (Total Cost of Ownership)
Information-related warfare relies a lot on computer systems
It Seems Like IBM is Firing 'Everybody' (Anywhere, Any Age, No Matter What Team)
Healthy companies would sack IBM's management (sacked by Board, bylaws etc.) but IBM is a sick company
Latest Stallman Talk (Event in Argentina) Published
Less than a day ago they released his talk
LLM Slop Becoming Rarer
Today we've found no LLM slop in our RSS feeds regarding "Linux"
 
A Utopian and Very Dumb Vision of Technology, Based on Accounting Fraud
the "industry" has become insane and a lot of "the media" is going along with it
Links 14/12/2025: "The Slop of Things to Come", Goldman Sachs Nervous About Slop Bubble
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, December 13, 2025
IRC logs for Saturday, December 13, 2025
Google News is Google Noise
Google News is really hopeless, even on weekends
Links 13/12/2025: Jimmy Lai and Media Freedom on Trial, "OpenAI Researcher Quits, Saying Company Hiding the Truth"
Links for the day
Gemini Links 13/12/2025: Extensive Catchup With Gopherholes
Links for the day
Deliberate Lies or Glaring Distortions
Calling Torvalds anything "Soviet" or "Russian" would overlook the fact he comes from Finland and has Swedish roots
Canonical and Ubuntu: Working for Microsoft, Promoting Proprietary Surveillance (Dis)Services
Canonical started with a rich and overambitious Debian Developer. He wanted to become richer.
EPO People Power - Part XI - The Media in Europe is Ill and Complicit in Ills
We must all recognise that there's a problem here
Running With Technology
At least they always run Linux (all of them, since 2015)
Dealing With "Tech Cults"
If you think you identified a "Tech Cult", walk away
GAFAM is a Financial Problem and Sovereignty Risk, a Policy-Level (National Level) Boycott is Needed
Europe has plenty of skilled computer engineers
2026 Could Very Well be Last Year of XBox, Microsoft Dropped the Ball
It would be shocking is XBox can stage any kind of comeback
Links 13/12/2025: Social Control Media Bans and "Could Finland be Hiding a Blue Zone?"
Links for the day
Expecting Mass Layoffs, More Microsoft Workers Join Unions
they see tough times ahead
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, December 12, 2025
IRC logs for Friday, December 12, 2025
Links 12/12/2025: GAFAM Now Trying to Settle With Remaining News Sites It Plagiarised, "NATO's Rutte Says Alliance Is 'Russia's Next Target'"
Links for the day
Gemini Links 12/12/2025: Bad Joke, Western Union Blues, and More
Links for the day
Life Began at 40
This is what I wanted to do all along
To Linus Torvalds, the Microsoft Linux Foundation is Increasingly a Liability and Risk to the Brand
If Torvalds is no longer in control or "in charge", then somebody else is
EPO People Power - Part X - Together, We Can Fix the EPO
every call for action matters
IBM Layoffs in Europe as Well
IBM is a collapsing, dying old brand
EPO People Power - Part IX - Insiders Say the EPO's Chief Propagandist Effectively Ousted (on Fake 'Sick Leave') Because of Reporting by Techrights
So the EPO is in effect rewarding a cocaine addict
Litigation Transparency Until 2030 or 2031
The ultimate goal is to 1) improve the British legal system and 2) raise awareness of how this system works
Links 12/12/2025: Thunderbird Adds Proprietary Plug, "Catch-22 of Canadian Digital Sovereignty" Explained by Michael Geist (About GAFAM/US)
Links for the day
Developing Some New Software for the Sites
Sites that are static are in more control over their future and present direction
Julian Assange on Fake Activists in Silicon Valley
Julian Assange on Fake Activists in Silicon Valley
"In a modern economy it is impossible to seal oneself off from injustice."
― Julian Assange
EPO People Power - Part VIII - The Chipmunk on Cocaine, Now Deleting Videos
video has been removed
What If the Economy Isn't "Down" But Mostly Diverted? (While "AI" Fills a Gap for Capital That No Longer Exists in Tech)
"AI" is an "Arms Race", because they need to be bailed out by taxpayers' money
Techrights Site Search Was a Success After All
A few hiccups dealt with, ironed out
Valve's SteamOS, Microsoft Canonical's Ubuntu, and Other Platforms That Only Leverage Free Software (But Won't Protect It)
Ubuntu "took off" not because it was very good or very easy. Ubuntu "took off" because of ShipIt, i.e. because of a multi-millionaire subsidising its mass distribution (at a personal cost).
The Free Software Foundation (FSF) Paid Respect to Its Founder This Year, Now It Wants You to Join
We're glad to see the FSF paying respect to its founder in its Web site
2026 Guaranteed to Give Us Compromised Media Funded by "AI" Boosters to Promote "AI" and Sometimes be Composed by "AI" (Chatbots)
follow the money of the Ponzi scheme
Under IBM, Things Culminate at "AI-Equipped Customer Experience Transformation" at Red Hat
Whatever that even means
Andy Farnell and Helen Plews Now at the Wheel in Cybershow
Cybershow (Cyber|Show) has very good blog posts and episodes
Microsoft Trims More Jobs
The worst layoff year in 20 years, by the numbers
EPO People Power - Part VII - The Corporate Media and the Reference Sites (e.g. Wikipedia) Are Already Compromised and Complicit
Looking back at the whole thing, it's clear to me that Europe does not really have free press
EPO People Power - Part VI - Criticism Not Permitted, Media Subjected to Contempt by Cocaine Addicts Who Manage the Press for the EPO
Why won't any large publisher in Europe cover this? What does that say about the state of journalism in Europe?
"Smart" or "Intelligent" Agents and "Vibe Coding" Deletes Everything You Have
A high price to pay, no?
New Paper Shows That EPO "Growth" is Dictated From Above, Not Earned (More Monopolies Granted by Breaking Rules, Laws, Conventions)
"Targets for 2026 are currently being handed down to individuals."
EPO People Power - Part V - The European Media is Practically Dead When It Comes to Covering European Patent Office (EPO) Corruption
That sort of sums up where European media/press stands
Datacentre and Server Maintenance Next Week
The last time we rebooted into the latest stable kernel was 96 days ago
Afraid of Words, Not Afraid of Actions
Those corporations want us to bicker over words, not their actions
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, December 11, 2025
IRC logs for Thursday, December 11, 2025
IBM Workers Still Blast IBM Management for Firing Loads of Workers While Overpaying to Buy Useless Companies
IBM's CEO is killing the cow
LLM Slop About Linux Still Seems Scarce
LLMs aren't dead, but metrics published online say that their usage is fast declining
Links 12/12/2025: Oracle Shares Collapse After Slop Bubble Inflated (Circular Funding/Financing One's Own 'Clients'), "Trials by Jury" in UK Considered
Links for the day
Gemini Links 12/12/2025: 'Kinetic Energy' and Browsing Geminispace With a GUI, TUI, or CLI Client
Links for the day