Re: Secure boot
Carl Symons <[email protected]>
| Newsgroups | gmane.comp.kde.events |
|---|---|
| Message-ID | <CAPu7pz+0U8BWvm4HpWaBCyKQ1R7O+zDPkLgxPpLqdPOfgtmHXg@mail.gmail.com> |
On Thu, Oct 20, 2011 at 7:06 AM, Pau Garcia i Quiles <[email protected]> wrote: > Hi, > > IMHO this is not Microsoft's fault. > No it's not Microsoft's fault. They have the right to set conditions on UEFI. They will mandate that equipment manufacturers enable secure boot. They will mandate the use of NTFS as the file system. They have all those rights and they will most likely exercise all of them. It's the fault of equipment manufacturers who knuckle under to Microsoft's market power. If PC manufacturers want to offer Windows 8, they will do Microsoft's bidding...absent any opposition. If the end result is that Microsoft's near-monopoly power is expanded, Microsoft will gladly take it. Microsoft may not be at fault, but they most certainly could do something about this. [just read your blogpost at http://www.elpauer.org/?p=1056] Where is their voice in support of the users of poorly funded projects? No it's not Microsoft's fault. But if they are in a great position to resolve what you call "a serious defect in the standard. A huge omission". Absent Microsoft's support of a fair resolution, they represent an attractive leverage point. Particularly for KDE. Does KDE have the organizational horsepower to get the Linux Foundation to take up the cause? From your blogpost... "Given that there is no Secure Boot Certification Authority, Microsoft asked BIOS (UEFI) developers and manufacturers to include their certificates, which looks 100% logical to me. The fact that Linux distributions do not have such power is unfortunate, but it is not Microsoft’s fault at all." It is just an accident. They just asked for their certificates to be included. They didn't do anything wrong. I've watched Microsoft pull this for years...do whatever they can get away with. Include Microsoft's proprietary and partially implemented OOXML as an open standard? Well it came to a vote; it's not Microsoft's fault that their distributors crashed the proceedings. What's illogical about Microsoft's action is that they could have chosen another course...one that had a more equitable outcome. They didn't. They could have recognized that they were abetting a restriction on freedom. No they are not at fault for the standard. They are simply the party that gains the most from it. In light of their continued previous behavior, they're suspect. As long as the standards bodies can be more-or-less bought, "open" means less and less. And Microsoft stands to win almost always. Screaming at Microsoft will do little good. Screaming at the U.S. Government, Inc. will do little good. Instead people can support the Free Software Foundation. Sign the statement. Urge FSF and FSFE to lean on the Linux Foundation. Aiming at Microsoft's wallet and reputation may do something. I would be satisfied to hear that Microsoft had recognized its near-monopoly situation and was volunteering to vet and support certificates for less well funded, but respected FOSS OSs. No it's not Microsoft's fault. But they are in a great position to resolve it. They won't do that without pressure...no one will. This really comes ultimately to what I wrote before...if your computer is a name brand...one that originally came with Windows...from a manufacturer that is de facto controlled by Microsoft...absent any change in direction, it's likely that you will not be able to run your choice of a KDE distro sometime in the near future. At minimum, your freedom has just been eroded. Microsoft has the most to gain from this initiative. They have contributed the most to its need. They have the most resources to resolve it and are in the best position to do so. Finding fault or not resolves nothing. Carl > The UEFI secure boot standard should have defined an organization (a "Secure > Boot Certification Authority") that would issue and/or receive certificates > from organizations/companies (Red Hat, Oracle, Ubuntu, Microsoft, Apple, > etc) that want their binaries signed. This SBCA would also be in charge of > verifying the background of those organizations. There is actually no need > for a new organization: just use an existing one, such as Verisign, that > carries on with this task for Microsoft for kernel-level binaries > ("AuthentiCode"). > > Given that there is no Secure Boot Certification Authority, Microsoft asked > BIOS (UEFI) developers and manufacturers to include their certificates, > which looks 100% logical to me. The fact that Linux distributions do not > have such power is unfortunate, but it is not Microsoft's fault. > > Now: solutions? Given its strong ties with Intel, AMD and others, maybe The > Linux Foundation could start a task force and a "Temporary Secure Boot > Certification Authority", and act as a proxy for minorities such as Linux, > BSD, etc distributions. IMHO this is our best chance to get something done > in a reasonable amount of time. Complaining will not get us anything. We > need to propose solutions. > > > > On Thu, Oct 20, 2011 at 3:09 PM, Agustin <[email protected]> wrote: >> >> Hi, >> >> I've received the last few days several mails related with Microsoft >> strategy to deliver secure boot implemented in a way that adds restrictions >> for installing free software based distros. >> >> Is this being discussed in Kde? Where? >> > > -- > Pau Garcia i Quiles > http://www.elpauer.org > (Due to my workload, I may need 10 days to answer) > > > _______________________________________________ > This message is from the kde-promo mailing list. > > Visit https://mail.kde.org/mailman/listinfo/kde-promo to unsubscribe, set > digest on or temporarily stop your subscription. > _______________________________________________ This message is from the kde-promo mailing list. Visit https://mail.kde.org/mailman/listinfo/kde-promo to unsubscribe, set digest on or temporarily stop your subscription.