Bonum Certa Men Certa

UEFI Debate Rages on While New Workarounds and Advice Surface

Defence



Summary: Routes that are less complicit with Microsoft are noted in light of the anti-competitive UEFI scheme

THE UEFI saga has got booting freedom at stake and within a day or two I will have a chance to speak to Dr. Stallman about it. Canonical did not follow the FSF's advice, as we noted before. "There's been plenty of speculation as to Canonical's rationale," writes this one pundit. "Meanwhile, reports of murmurings on the topic among Debian developers have kept imaginations active, as has the arrival of the first retail PCs to support UEFI Secure Boot. Bottom line? No proverbial "fat lady" is going to be singing around here anytime soon. On Slashdot and beyond, the flames of controversy just keep getting higher."



The Debian position was mentioned here before [1, 2, 3] and it intersects with the attempt by Debian to fully satisfy the FSF. Brian from Linux Today fame says that "[t]he Debian Project, developers of the Debian GNU/Linux distribution, are making a concerted effort to get within the good graces of the Free Software Foundation.

"The Debian position was mentioned here before and it intersects with the attempt by Debian to fully satisfy the FSF.""Debian Project Leader Stefano Zacchiroli proposed the plan over the US holiday last week, specifically stating that project members "should either get Debian in FSF free-distros list, or document (from our [point of view]) why Debian is not there."

The FSFE's advice was something along the same lines that Steven J. Vaughan-Nichols mentioned in his latest coverage where he speaks to a GNU/Linux-friendly vendor. To quote: "Will the advent of Windows 8 really mean that Microsoft's secure boot lock-in will be on every PC? Cathy Malmrose, CEO of the Linux PC vendor ZaReason doesn't think it should.

"Malmrose told me “With UEFI's Secure Boot around the corner, we are hoping to raise awareness that [GNU/]Linux distributors don't need to sign with Microsoft [or use their secure boot. Computers that are rooted with open bootloader are available. That's what we ship.”

“ZaReason's mission isn't just to make free/open hardware: it's to ensure that there is always a free-as-in-free-speech option for your computing needs.”
      --Cory Doctorow
"She knows, “UEFI's Secure Boot is implemented at OEM (originial equipment manufacturer) level, all new PCs purchased (with the intent of loading your favorite distro) will have Secure Boot." This cripples them as far as Malmrose is concerned.

"“Yes, you can disable it. But 'disabling' something that's 'secure' makes you bad.” Besides as Malmose told me, “the keystroke(s) needed to get [GNU/]Linux to run on machines post-2012 will be simple at first, becoming increasingly complex at a non-shocking rate. It's a monumental shift at OEM level.” Malmrose fears that this will desktop [GNU/]Linux “too difficult to new users, [and this will cause] slow death by suffocation” for [GNU/]Linux.

"So what can [GNU/]Linux users do instead? Malmrose thinks we can avoid a "Greek Tragedy “ by recognizing that Linux needs hardware vendors, like ZaReason, “who can keep things open, [who keep our collective foot in the door at the factories.” Malmrose insists that it isn't about her particular company. “There is 0 profit.* If we ever did have profit, we would donate to support the EFF, FSF, Software Freedom Conservancy, LinuxFests, GNOME Foundation, various conferences, the works. Hopefully someday there will be but most months it's a stretch to make payroll.”

"So why take this stance? Cory Doctorow, in describing ZaReason, put it well, “ZaReason's mission isn't just to make free/open hardware: it's to ensure that there is always a free-as-in-free-speech option for your computing needs.”

"She's right. We need to support [GNU/]Linux-friendly hardware vendors. There is no law that says computers with UEFI must use Secure Boot. Yes, Microsoft may want it that way, but if we support companies that offer open systems we can still get open hardware to go with our open-source software.

“The myth that it contributes to security will be spread again and there will be no defence against secure boot being mandated by governments.”
      --Sam Varghese
Another writer who has criticised Red Hat's and Ubuntu's (or Canonical's) decision right from the start notes that "[b]y going along with Microsoft, and not even bothering to join together and raise a stink, the rest of the computer industry has created a situation where Microsoft can surface again a couple of years down the track and lobby for making secure boot mandatory for all devices. After all, the company can argue that secure boot has been widely accepted - this will be true - and nobody has objected. Everyone has adapted and started to use it.

"The myth that it contributes to security will be spread again and there will be no defence against secure boot being mandated by governments. Is there any guarantee that the cost of a key to implement secure boot will cost $US99 at that stage? It will turn out to be a nice little earner."

This analysis from Sam Varghese hits many of the important points -- the same points stressed by Techrights right from the get-go. The above will prove handy for future reference.

Recent Techrights' Posts

Red Hat Offers DRM, TPM, and Backed Doored 'Confidential' Containers (CoCo) for Microsoft (Proprietary Spyware)
No kidding!
[Meme] Plagiarism Does Not Eliminate Jobs by Replacing Humans, It Replaces Human Knowledge With False Cruft
We need to boycott sites that fake their output
[Meme] Doing Dog's Job (Not God's Job)
The FSF did not advertise the talk by RMS (its founder), who spoke in France almost exactly 23 hours ago
 
Of Note: The Misguided, Infiltrated, Weakened Electronic Frontier Foundation (EFF) Now Operating at a Loss of Over a Million Dollars
Worst since the COVID-19 lockdowns
Free Software Foundation's Miriam Bastian: We Surpassed Our Year-end Goal of $400,000 USD Thanks to You!
Miriam Bastian: We surpassed our year-end goal of $400,000 USD!
[Meme] Omit Microsoft When It's a Scandal or a Breach, Whereupon It Becomes Just an 'IT Company'
Microsoft is like a cult. Members of this cult promote the opposite of security, expecting to be financially rewarded for it.
Calling Out Windows (TCO) is Apparently Impermissible in Some News Sites
The online news sites are failing us (and corporate sponsors play a role)
Richard Stallman's Remarks on His Pain
Published two days ago
Focusing on the Issues
we'll do our best to find the news and not talk about "Mr. T"
Only About 3.6% of Web Users in Pakistan Use Vista 11, According to statCounter
It's not hard to see why so far in 2025 Microsoft has already had several waves of mass layoffs - more than any other company
Rumour: In IBM, Impending "25% Reduction in Finance Roles"
25% to be laid off?
[Meme] Fake Articles From linuxsecurity.com (Just Googlebombing "Linux" With LLM Slop)
Google should really just entirely delist that site
RedHat.com Written by Microsoft Staff, Promoting Microsoft' Proprietary Software That Does Not Even Run on Linux!
This is RedHat.com this week...
Links 22/01/2025: Mass Layoffs at Stripe, Microsoft's Illegal Accounting Practices Under Scrutiny
Links for the day
Fake 'Article' by Brittany Day (Guardian Digital, Inc) About Linux Mint 22.1 'Xia'
Apparently they've convinced themselves that this is OK
Red Hat Dumps "Inclusive Language", Puts "Master" In Official Communications and Headlines
Red Hat: you CANNOT say "master" (because it is racist). Also Red Hat: we put in it our headlines.
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, January 21, 2025
IRC logs for Tuesday, January 21, 2025
Gemini Links 21/01/2025: Media Provocations and Nazis Not Tolerated
Links for the day
Slopwatch: BetaNews Plagiarism and LLM Slop by UNIXMen
"state-of-the-art" plagiarism
What Fedora, OpenSUSE, and Debian Elections Teach Us About the State of Weak (or Fake) Communities
They show a total lack of trust in these communities
Links 21/01/2025: Mass Layoffs in "Security" at Microsoft (Despite Microsoft Promising It Would Improve After Many Megabreaches), Skype is Dead (Quietly)
Links for the day
Alternate Version of Daniel Pocock's 2024 Talk, "Technology in European Parliament Election Campaign"
There's loud ovation at the end of the talk
Gemini Links 21/01/2025: London Library, Kobo Sage, and Beyerdynamic DT 48 E
Links for the day
The January 20 Public Talk by Richard Stallman (Around Midday ET), Livestream 'Assassinated' by Google's YouTube
our guess is that the 'cancel mob' sabotaged it, possibly by making a lot of false reports to YouTube
[Meme] Free Software and Socially-Engineered Groupthink (to Serve Big Sponsors Like Google and Microsoft)
They do this to RMS all the time
[Video] Daniel Pocock's Public Talk About Free Software Politics, Social Engineering, Debian Deaths and Suicides, Coercion and Exploitation of Women
took many months to get
BetaNews Cannot Survive If Its Fake Articles Are Just SPAM for Companies Like AOHi and Aren't Even Composed by Humans
This is what domains or former "news" sites do when they die and look very desperately for "another way"
Pocock shot in the face, shot in the back, shot on Hitler's birthday saving France, Belgium and FOSDEM
Reprinted with permission from Daniel Pocock
Dr Richard Stallman in Montpellier, Robert Edward Ernest Pocock in France
Reprinted with permission from Daniel Pocock
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, January 20, 2025
IRC logs for Monday, January 20, 2025
Links 20/01/2025: Conflict, Climate, and More
Links for the day
Gemini Links 20/01/2025: Conflicted Feelings and Politics
Links for the day
Daniel Pocock's ClueCon 2024 Presentation Was Also Streamed Live in YouTube and Later Removed by Google, Citing "Copyrights". Now It's Back.
The talk covers social control media, Debian, politics, and more
Google 'Cancels' RMS
Is the talk happening?
Microsoft Revisionism Debunked by Microsoft's Own Words About “the Failure of OS/2”
The Register on “the failure of OS/2”
Improving Daily Links by Culling Spam, Chaff, and LLM Slop
the Web is getting worse
Links 20/01/2025: Indonesia to Prevents Kids' Access to Social Control Media (Addiction and Worse), Climate News Catchuo
Links for the day
[Meme] EPO Targets
Targets mean nothing if or when you measure the wrong thing
EPO Union Says Monopoly-Granting Targets at EPO "Difficult to Achieve Without Compromising [Staff] Health, Personal Time or the Quality of the Final Products" (Products as in Monopolies, Not Real Products)
To those of us (over 99.999% of people impacted by this) who do not work at the EPO the misuse of words like "products" (monopolies are not products) should be disturbing
The EPO is Nowadays Trying to Trick Staff Into Settling Instead of Solving the Underlying Problems of Corruption and Injustice
This seems like a classic case of "divide-and-rule" or using misled/weak people to harm the whole group (or "the village")
Links 20/01/2025: More PR Stunts by ByteDance and MLK’s Legacy Disrespected
Links for the day
Gemini Links 20/01/2025: Magnetic Fields, NixOS, and Pleroma
Links for the day
BetaNews Spreads Donald Trump Propaganda, Promotes Scams, and Publishes Fake 'Articles' About "Linux"
This is typical BetaNews
Richard Stallman 'Unveils' His January 20 Talk in Montpellier, France
It's free (gratis)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, January 19, 2025
IRC logs for Sunday, January 19, 2025