Re: Secure boot

Carl Symons <[email protected]>
Newsgroups gmane.comp.kde.events
Message-ID <CAPu7pz+0U8BWvm4HpWaBCyKQ1R7O+zDPkLgxPpLqdPOfgtmHXg@mail.gmail.com>
On Thu, Oct 20, 2011 at 7:06 AM, Pau Garcia i Quiles
<[email protected]> wrote:
> Hi,
>
> IMHO this is not Microsoft's fault.
>

No it's not Microsoft's fault.

They have the right to set conditions on UEFI. They will mandate that
equipment manufacturers enable secure boot. They will mandate the use
of NTFS as the file system. They have all those rights and they will
most likely exercise all of them.

It's the fault of equipment manufacturers who knuckle under to
Microsoft's market power. If PC manufacturers want to offer Windows 8,
they will do Microsoft's bidding...absent any opposition.

If the end result is that Microsoft's near-monopoly power is expanded,
Microsoft will gladly take it. Microsoft may not be at fault, but they
most certainly could do something about this. [just read your blogpost
at http://www.elpauer.org/?p=1056] Where is their voice in support of
the users of poorly funded projects?

No it's not Microsoft's fault. But if they are in a great position to
resolve what you call "a serious defect in the standard. A huge
omission". Absent Microsoft's support of a fair resolution, they
represent an attractive leverage point. Particularly for KDE. Does KDE
have the organizational horsepower to get the Linux Foundation to take
up the cause?

From your blogpost...
"Given that there is no Secure Boot Certification Authority, Microsoft
asked BIOS (UEFI) developers and manufacturers to include their
certificates, which looks 100% logical to me. The fact that Linux
distributions do not have such power is unfortunate, but it is not
Microsoft’s fault at all."

It is just an accident. They just asked for their certificates to be
included. They didn't do anything wrong. I've watched Microsoft pull
this for years...do whatever they can get away with. Include
Microsoft's proprietary and partially implemented OOXML as an open
standard? Well it came to a vote; it's not Microsoft's fault that
their distributors crashed the proceedings.

What's illogical about Microsoft's action is that they could have
chosen another course...one that had a more equitable outcome. They
didn't. They could have recognized that they were abetting a
restriction on freedom. No they are not at fault for the standard.
They are simply the party that gains the most from it. In light of
their continued previous behavior, they're suspect. As long as the
standards bodies can be more-or-less bought, "open" means less and
less. And Microsoft stands to win almost always.

Screaming at Microsoft will do little good. Screaming at the U.S.
Government, Inc. will do little good. Instead people can support the
Free Software Foundation. Sign the statement. Urge FSF and FSFE to
lean on the Linux Foundation.

Aiming at Microsoft's wallet and reputation may do something. I would
be satisfied to hear that Microsoft had recognized its near-monopoly
situation and was volunteering to vet and support certificates for
less well funded, but respected FOSS OSs.

No it's not Microsoft's fault. But they are in a great position to
resolve it. They won't do that without pressure...no one will. This
really comes ultimately to what I wrote before...if your computer is a
name brand...one that originally came with Windows...from a
manufacturer that is de facto controlled by Microsoft...absent any
change in direction, it's likely that you will not be able to run your
choice of a KDE distro sometime in the near future. At minimum, your
freedom has just been eroded.

Microsoft has the most to gain from this initiative. They have
contributed the most to its need. They have the most resources to
resolve it and are in the best position to do so. Finding fault or not
resolves nothing.

Carl





> The UEFI secure boot standard should have defined an organization (a "Secure
> Boot Certification Authority") that would issue and/or receive certificates
> from organizations/companies (Red Hat, Oracle, Ubuntu, Microsoft, Apple,
> etc) that want their binaries signed. This SBCA would also be in charge of
> verifying the background of those organizations. There is actually no need
> for a new organization: just use an existing one, such as Verisign, that
> carries on with this task for Microsoft for kernel-level binaries
> ("AuthentiCode").
>
> Given that there is no Secure Boot Certification Authority, Microsoft asked
> BIOS (UEFI) developers and manufacturers to include their certificates,
> which looks 100% logical to me. The fact that Linux distributions do not
> have such power is unfortunate, but it is not Microsoft's fault.
>
> Now: solutions? Given its strong ties with Intel, AMD and others, maybe The
> Linux Foundation could start a task force and a "Temporary Secure Boot
> Certification Authority", and act as a proxy for minorities such as Linux,
> BSD, etc distributions. IMHO this is our best chance to get something done
> in a reasonable amount of time. Complaining will not get us anything. We
> need to propose solutions.
>
>
>
> On Thu, Oct 20, 2011 at 3:09 PM, Agustin <[email protected]> wrote:
>>
>> Hi,
>>
>> I've received the last few days several mails related with Microsoft
>> strategy to deliver secure boot implemented in a way that adds restrictions
>> for installing free software based distros.
>>
>> Is this being discussed in Kde? Where?
>>
>
> --
> Pau Garcia i Quiles
> http://www.elpauer.org
> (Due to my workload, I may need 10 days to answer)
>
>
> _______________________________________________
> This message is from the kde-promo mailing list.
>
> Visit https://mail.kde.org/mailman/listinfo/kde-promo to unsubscribe, set
> digest on or temporarily stop your subscription.
>

_______________________________________________
This message is from the kde-promo mailing list.

Visit https://mail.kde.org/mailman/listinfo/kde-promo to unsubscribe, set digest on or temporarily stop your subscription.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.