Slashdot Mirror


FSF Criticises Ubuntu For Dropping Grub 2 For Secure Boot

sfcrazy writes "The Free Software Foundation (FSF) has published a whitepaper suggesting how free operating systems can deal with UEFI secure boot. In the whitepaper, the foundation has criticized the approach Canonical/Ubuntu has taken to deal with the problem. The paper reads: 'It is not too late to change. We urge Ubuntu and Canonical to reverse this decision, and we offer our help in working through any licensing concerns. We also hope that Ubuntu, like Fedora, will actively support users generating and using their own signing keys to run and share any versions of the software, and not require users to install a key from Canonical to get the full benefit of their operating system.'"

18 of 296 comments (clear)

  1. Re:I suppose the ultimate solution is... by crazyjj · · Score: 5, Funny

    hack the secure boot BIOS

    Citizen, you have advocated criminal violation of the Digital Millennium Copyright Act. Please place your hands in the yellow circles and await a police action.

    --
    What political party do you join when you don't like Bible-thumpers *or* hippies?
  2. Re:I suppose the ultimate solution is... by Anonymous Coward · · Score: 5, Insightful

    I'd say the ultimate solution is for every linux fan to stop recommending computers with locked BIOSs, push hardware with coreboot, and to ignore distros which aren't playing ball. Cracking it is the pragmatic solution.

  3. Ubuntu Following Novell by GeneralTurgidson · · Score: 5, Insightful

    Go ask Novell how well chasing that Microsoft interoperability trains works.

  4. They also criticized Fedora.. by gQuigs · · Score: 5, Interesting

    not as much, but still (for planning to use the MS key). It's a very bad position we (Free Software) are in with Restricted/Secure boot. I think it's time the Linux friendly vendors really get behind CoreBoot [http://www.coreboot.org/Welcome_to_coreboot] and let us be truly independent.

    As it is setup right now:
    Binaries can only be signed with one key. If you use Microsoft's key, you can't use your own.
    Not all vendors may support letting users add their own keys. (and even if they do it certainly complicates a fresh install).
    ARM will be completely locked down if vendors want MS to run on it.
    If you use the Microsoft key, they can revoke your access (they likely need cause, but still)

    1. Re:They also criticized Fedora.. by SuricouRaven · · Score: 5, Insightful

      Microsoft's key is the only one that you can be sure all computers will have, and so the one all vendors will have to sign with. Making it pointless for them to even have their own keys. By design, I am quite sure: The limit is one-key-only because it was always intended that only one vendor would survive. Microsoft.

    2. Re:They also criticized Fedora.. by Lennie · · Score: 5, Informative

      AMD commited last year for all their products to support Core Boot:

      http://blogs.amd.com/work/2011/05/05/an-update-on-coreboot/

      --
      New things are always on the horizon
  5. Re:I suppose the ultimate solution is... by shentino · · Score: 5, Insightful

    Sadly I think this may well be true in the future if hacking your own PC is treated by Microsoft the same way that modchipping your PS is treated by Sony

  6. Re:people who use ubuntu are linux posers anyways by Anonymous Coward · · Score: 5, Funny

    Linux users in general are just Unix posers. If you aren't running HPUX on a home Itanium server, then you're just using watered down bullshit.

    Also, my dick is bigger than yours.

  7. Re:I suppose the ultimate solution is... by SuricouRaven · · Score: 5, Informative

    You can now, yes. But remember the big push for Secure Boot is from Microsoft. A company with a long history of using every dirty and underhanded trick in the book, including a few of their own invention. I do not trust them: Today they only make it enabled by default, but in a few more years they may take away the capability to disable it entirely.

  8. Re:I suppose the ultimate solution is... by Anonymous Coward · · Score: 5, Insightful

    So far there's no indication that you need to hack anything. Microsoft requires that PC's sold as certified for for Windows 8 allow you to enter custom mode and load your own certs. The reason Linux Distros are going the routes they are, using a Microsoft Signed boot loader, is that they want something that will be bootable on any machine out there with out having to enter the bios. While your typical users here on slashdot probably doesn't have any problems entering their bios and adjusting Bios settings for many other users is something they've never done and it's going to be extremely specific to that mfgs implementation on that particular hardware so no general set of instructions is possible.

  9. Re:people who use ubuntu are linux posers anyways by Anonymous Coward · · Score: 5, Funny

    Linux is mainstream everywhere except the desktop, and I heard the desktop is dead anyway.

  10. Re:people who use ubuntu are linux posers anyways by jellomizer · · Score: 5, Interesting

    Linux has gone mainstream... Just not on the desktop. Where is remains a distant 3rd behind Windows and OS/X.
    With Android, Linux is quite popular with mobile. Linux is also strong on the server side too.
    Linux never made it to the desktop, because there were too many drivers to support. When you luck out and get a System that is well supported by Linux... Linux rocked on that system. However if you try to put Linux on a poorly supported system, it usually sucked, and felt like a cheap OS.

    If Microsoft make "Windows 9" a Linux Distribution with a Windows themed UI. It would probably be just like Vista, many people complaining about hardware compatibility, systems crashing all the time (due to improper drivers)

    --
    If something is so important that you feel the need to post it on the internet... It probably isn't that important.
  11. a sea change by Anonymous Coward · · Score: 5, Insightful

    This is the start of a sea change in who controls our computers. Yes, for now you can turn it off (oh, sorry, unless you're using an ARM system), but this is just the first step. They can't go the entire way all at once. They've tried before, and learned they have to go one step at a time. Each step doesn't seem so bad, until finally, all the cards fall into place.

    Already most of our mobile devices no longer belong to us, unless you manage to defeat the device's security that is meant as security against YOU, the owner of the device. Bought anything with iOS, or about 95% of the Android devices? Or WP7? Sorry, someone else owns it even after you purchased it. That's the world that many powers like Microsoft and many governments desire for the whitebox PC. A locked down device that obeys other masters, only booting "trusted" OSs that let those masters have the final say over what your computer does. Because a world where a billion individuals had control over their own computers could not be allowed to persist. It threatens too many corporations and governments.

    Of course, people will buy these increasingly locked down PCs just like they are falling all over themselves to buy tablets, so this world WILL come to pass. All we can do is figure out how to deal with it.

  12. Re:With all due respect by betterunixthanunix · · Score: 5, Insightful

    Canonical is making the right choice for their users.

    Funny how when I was growing up, free/libre software meant that the users did not have to rely on companies like Canonical to make their choices for them.

    --
    Palm trees and 8
  13. Re:people who use ubuntu are linux posers anyways by tripleevenfall · · Score: 5, Funny

    OS/X? Finally, the successor to OS/2 the market has been waiting for!

    They can call it WARP 10!

  14. Atom by mdmkolbe · · Score: 5, Informative

    they may take away the capability to disable it entirely

    They already are taking it away on ARM based systems. "On an ARM system, it is forbidden to enable Custom Mode. ... Disabling Secure MUST NOT be possible on ARM systems" (page 122 of Windows Hardware Certification Requirements)

  15. Re:I suppose the ultimate solution is... by JerkBoB · · Score: 5, Insightful

    Sadly I think this may well be true in the future if hacking your own PC is treated by Microsoft the same way that modchipping your PS is treated by Sony

    I haven't really been paying attention to what Sony has been doing (don't own a PS3), but I wonder if Sony really cares about modchipping itself, or if they just want to keep modded consoles off of PSN?

    The latter seems reasonable to me... If you want to mod the console, fine. Just don't expect to be allowed to play in the sandbox with all of the unmodded consoles. You know if they let modded consoles on that games would be flooded by griefers and other annoying breeds of adolescent (chronological or mental).

    Not picking a fight, just wondering if I'm missing something...

    --
    A host is a host from coast to coast...
    Unless it's down, or slow, or fails to POST!
  16. Re:people who use ubuntu are linux posers anyways by serviscope_minor · · Score: 5, Funny

    Also, my dick is bigger than yours.

    That is probably the most common logical phallusy.

    --
    SJW n. One who posts facts.