Bonum Certa Men Certa

Microsoft Fanatics Were Wrong, Linux Indeed Attacked by UEFI (Updatedx2)

Ed Bott



Summary: More information about UEFI leaves no doubt about Microsoft's intentions to sabotage and cheat

IN OUR previous posts about UEFI (aka "secure" boot) [1, 2, 3] we showed that Microsoft was still a corrupt company looking to break the rules to make money. Aaron Williamson from the SFLC writes the article "Microsoft confirms UEFI fears, locks down ARM devices":



At the beginning of December, we warned the Copyright Office that operating system vendors would use UEFI secure boot anticompetitively, by colluding with hardware partners to exclude alternative operating systems. As Glyn Moody points out, Microsoft has wasted no time in revising its Windows Hardware Certification Requirements to effectively ban most alternative operating systems on ARM-based devices that ship with Windows 8.

The Certification Requirements define (on page 116) a "custom" secure boot mode, in which a physically present user can add signatures for alternative operating systems to the system's signature database, allowing the system to boot those operating systems. But for ARM devices, Custom Mode is prohibited: "On an ARM system, it is forbidden to enable Custom Mode. Only Standard Mode may be enable." [sic] Nor will users have the choice to simply disable secure boot, as they will on non-ARM systems: "Disabling Secure [Boot] MUST NOT be possible on ARM systems." [sic] Between these two requirements, any ARM device that ships with Windows 8 will never run another operating system, unless it is signed with a preloaded key or a security exploit is found that enables users to circumvent secure boot.


Glyn Moody adds:

In December 2011, Microsoft published a document entitled "Windows Hardware Certification Requirements" for client and server systems. As the introduction explains:
This release to web (RTW) document contains the Windows Hardware Certification requirements for Windows 8 Certified Systems. These requirements are Microsoft’s guidelines for designing systems which successfully meet Windows performance, quality, and feature criteria, to assure the optimum Windows 8 computing experience. Successfully following this guidance will allow a partner to receive certification for their system.
On page 116 of this document, there are some details about the circumstances under which Secure Boot can be disabled:
MANDATORY: Enable/Disable Secure Boot. On non-ARM systems, it is required to implement the ability to disable Secure Boot via firmware setup. A physically present user must be allowed to disable Secure Boot via firmware setup without possession of Pkpriv. Programmatic disabling of Secure Boot either during Boot Services or after exiting EFI Boot Services MUST NOT be possible. Disabling Secure MUST NOT be possible on ARM systems.
This confirms that it is indeed possible to disable Secure Boot - but only on non-ARM systems (i.e. traditional PCs.) In other words, it would appear that Microsoft is still locking out GNU/Linux from installation on ARM-based Windows 8 machines.

So this leaves me confused. The document was published some time after Microsoft's post where it states "Microsoft does not mandate or control the settings on PC firmware that control or enable secured boot from any operating system other than Windows", and yet it seems to contradict it. So what's going here? Was Microsoft's blog statement only about non-ARM systems, as the new documentation suggests? And if so, why the discrimination? And finally, is ARM really happy to see Microsoft apparently locking out GNU/Linux from its systems in this way? Let's hope Microsoft can clarify this situation as it did on the previous occasion.


This leaves no room for excuses. Microsoft's bribed systematic liars/spinners, such as Ed Bott, were just trying to keep regulators away. It's time to nail down Microsoft for interfering with fair competition in more than a single way. Just because Microsoft is imploding or collapsing does not entitle it/give it a right to sabotage competitors. This harms everyone.

Update: SJVN weighs in shortly afterwards:

Microsoft and its vendor friends said that there’s no Windows 8 plot to lock other operating systems from Windows 8 devices, but now we know Microsoft was not telling the whole truth.

Journalist Glyn Moody dug around Microsoft’s Windows Hardware Certification Requirements for Windows 8 client and server systems and found on page 116 that will Windows 8 Secure Boot can be disabled: on Intel systems, “Disabling Secure [Boot] must not be possible on ARM systems.”


Update #2: Microsoft now receives the Slashdot treatment. As one person put it: "Oh boy, the lawyers must be rubbing their hands over this. The flaw in Microsoft's aim of course is that next to no one wants a Microsoft mobile gadget."

Comments

Recent Techrights' Posts

SLAPP Censorship - Part 194 Out of 200: The Court Needs to Also Look Into Microsoft-Controlled Restricted Boot Advanced by An American (Garrett) to Promote Monopoly and Back Doors Everywhere
Kill switch sold as 'security' is like euthanasia sold as a cure
Linux Kernel Becoming a Slopfest - Part 7 - Infested With or Plagued by Bot-Generated Slop, Committed by Microsofters
Slop is a security threat; even the person committing slop to Linux might not be aware that there's a back/bug door in the code
Edward Snowden Lost His Voice, Then His Leaks Lost Exposure (Access Denied)
When states want to deny people access to some information they have many tools at hand
Things Will Only Get Better (as We Go Backwards)
It only gets better. If you go back in time.
UK High Court Shows SRA is Totally Useless in Curbing SLAPPs, This Has Impact on Our Reporting on the SRA Next Week
We'll carry on our coverage and soon finish the current series that so we can get on with more time-sensitive ones
 
The EPO's Central Staff Committee (CSC) Shows Job Insecurity at Europe's Second-Largest Institution
Who would want to join a company with such low job security?
There Are Thousands More Microsoft Layoffs (Including Silent Layoffs), Not Hundreds
Microsoft does have layoffs and today is no exception (except Microsoft talks about it)
Gemini Links 22/09/2026: Disability Studies, Slop Boosters, and TkInter
Links for the day
Links 22/09/2026: Flock is Collapsing Amid Mass Backlash and Internet Society Collaborates With the 'Epstein Class' (Trafficking of Women)
Links for the day
Raspberry Pi Has Microsoft Secrets Inside, Now DRM
now we deal with SBCs that have DRM in them, put there for commercial reasons
2 Hours Ago The Register MS Published a Page That Says "AI" 42 Times Because It Was Paid to Do So
Still inflating the bubble for money
Gemini Links 22/09/2026: Scout Night, Cybernetic Capitalism, and Thoughts on Companies Forcing People to Adopt Plagiarism Engines
Links for the day
Links 22/09/2026: "An Arsenal of Surveillance" and Slop Bots Suggest Starting Wars
Links for the day
SLAPP Censorship - Part 193 Out of 200: Breaks GNU and Linux, Tries to Silence Critics, Loses All Money, Looks for Microsoft Allies and Sponsors
The latest emotional knee-jerk reactions serve to confirm what we have long said
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, September 21, 2026
IRC logs for Monday, September 21, 2026
Links 21/09/2026: "Lies of the Hey Hi (AI) Industry" and Solar Power Is Getting Cheap
Links for the day
Gemini Links 21/09/2026: Equinox and Beginner's Guide to Gemini
Links for the day
Links 21/09/2026: "Back On My Bicycle" and American Regime's War on Media Escalates Further
Links for the day
SLAPP Censorship - Part 192 Out of 200: The Hired Guns of Garrett and Graveley Sent Us USB Sticks (One to Me, One to My Wife) Showing Lozza Talking to Garrett About Censoring/Deplatforming Techrights the Same Time Graveley Was Copy-Pasting Garrett's Lawsuit
Next year we plan to bring this matter to the Court of Appeal
Linux Kernel Becoming a Slopfest - Part 6 - Seeing Who Contaminates Linux With Slop (And Also Admits It)
Today we begin looking at some culprits
2026: The Year Galleries Realised the Need to Flag or Cull Slop Images
Society needs to shun slopfarms, people who use LLM slop (for anything at all), companies that use bots (which they dub "agents"), and so-called 'coders' who volley garbage into project and software hubs
Software Freedom Day Celebrated in 5 or 6 Continent
Software Freedom Day (SFD) 2026 was big this year
SLAPP Censorship - Part 191 Out of 200: Garrett, Graveley and Lozza
They talk to and coordinate with one another
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, September 20, 2026
IRC logs for Sunday, September 20, 2026
Gemini Links 21/09/2026: Digital Hoarder, GTD, Minimalism vs Digital Minimalism, Rejection of LLMs
Links for the day
Links 20/09/2026: "Google Now Asking For Users’ Video Selfies" and Energy Prices Set to Rise
Links for the day
Enjoy the Giving/Sharing, Not Taking
We've long supported what we believed in, even with the little money we had
Links 20/09/2026: Amazon Layoffs, Flock 'Buyouts' (Silent Layoffs)
Links for the day
USCIS and Microsoft Rumours: Curbs on Lowering Salaries by Importing Cheaper Replacements?
It seems like Microsoft's mass layoffs and efforts to cheapen the workforce face obstacles
Gemini Links 20/09/2026: "Music While Working" and Radio Silence
Links for the day
Clownflare Data From Canada
We've like to think many people are attempting to install GNU/Linux over the weekend
SLAPP Censorship - Part 190 Out of 200: Plagiarism, Back Doors, and Sabotage of Linux
This can go on for a decade or longer
Linux Kernel Becoming a Slopfest - Part 5 - Kernel Dependency on Plagiarism Giant Microsoft is a Death Blow to Any Kernel
Microsoft is bringing copyright-infringing slop into Linux
GNU/Linux Has Grown a Lot Lately
Based on Clownflare
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 19, 2026
IRC logs for Saturday, September 19, 2026