5 ms·
"What Minnich would like to see happen is for Intel to dump its MINIX code and use an open-source Linux-based firmware. This would be much more secure. The curr
by tsujamin 9y ago
"What Minnich would like to see happen is for Intel to dump its MINIX code and use an open-source Linux-based firmware. This would be much more secure. The current software is only secured by "security by obscurity".
Changing to Linux would also enable servers to boot much faster. According to Minnich, booting an Open Compute Project (OCP) Server takes eight minutes thanks to MINIX's primitive drivers. With Linux it would take less than 17 seconds to get to a shell prompt. That's a speedup of 32 times."
Anyone else think this is article is pretty FUD and crap? Not saying Minix has been security audited or is more/less secure than a Linux alternative, but there's something to be said for microkernels at the ME layer.
The OpenCompute annecdote (uncited?) doesn't designate whether Minix in ME is the bottleneck, or whether it's just slow to boot (it probably is when you're booting it with a platform worth of devices).
Good to know my involuntary shudder when opening a ZDNet article isn't entirely unfounded.
- PeachPlum 9y agoI know Ron, he used to work at Sandia National Laboratories in Livermore, running Plan 9 on IBM's Deep Blue among other things. e.g. running 1 million Linux kernel at once https://share-ng.sandia.gov/news/resources/news_releases/sandia-computer-scientists-successfully-boot-one-million-linux-kernels-as-virtual-machines/ https://share-ng.sandia.gov/news/resources/news_releases/san... He's also one of the people behind CoreBoot or whatever its called now
- watersb 9y agoHoly cow, I just realized that I met him at a backyard barbecue... Very sharp guy.
- tomxor 9y agoYes, it's complete FUD. It's also moot, because it really doesn't matter much whats in ME, ME just needs to not exist. The primary reason for choosing MINIX is memory footprint and reliability, additionally GNU is never popular for proprietary blobs like this... it would actually harm users with ME's current strategy if you think about it, GNU forces them to publish their likely buggy striped down version of linux, yet only intel can sign the firmware, so users are helpless and malicious people can find bugs in the code while intel sits on their hands. I don't find it hard to believe that Minix drivers are slow and primitive... Minix is not widely used like Linux, that doesn't really mean anything more than that, it's an amazing kernel and there is no better choice for an embedded system that you can't afford to fail and require user intervention. I guess the TL;DR is that Minix was the right system for the job, it's just that the job was unfortunately pure evil, so arguing about Minix is stupid.
- wolfgke 9y ago> additionally GNU is never popular for proprietary blobs like this... it would actually harm users with ME's current strategy if you think about it, GNU forces them to publish their likely buggy striped down version of linux I don't know whether Intel ME contains the usual userland tools that are typical for UNIX-like operating systems. But it is well-known that a lot of MINIX 3's userland was taken/ported from NetBSD, as the MINIX 3 developers openly admit: http://wiki.minix3.org/doku.php?id=developersguide:portingnetbsduserland http://wiki.minix3.org/doku.php?id=developersguide:portingne...
- tomxor 9y agoYes I am aware this is why Minix has the BSD license throughout. To be clear in-case their is confusion: in the text you quote I am describing the hypothetical scenario where Intel used Linux + GNU userland to build ME.
- jabl 9y agoPerhaps's it's unclear from reading the zdnet article, but anyhow, the idea is not to replace Minix in the ME, but rather get rid of, or at least disable, the ME as much as possible, then replace the upper levels of the UEFI stack + the bootloader with a minimal Linux + u-root userspace. When the final distro kernel is booted by the firmware one, it replaces it. The firmware Linux kernel is thus NOT left running anywhere in the background doing insidious things.
- cure 9y agoThis article is not FUD and crap. The source of the numbers quoted is here: https://schd.ws/hosted_files/osseu17/84/Replace%20UEFI%20with%20Linux.pdf https://schd.ws/hosted_files/osseu17/84/Replace%20UEFI%20wit... I know Ron Minnich. He is one of the founders of the coreboot project. He's been at this (replacing proprietary firmware with a free software alternative) for a very long time and he knows what he is talking about.
- cperciva 9y agoBut... replacing Minix with Linux wouldn't be replacing proprietary code with a free alternative. It would be replacing free software with a less free alternative.
- comatose 9y agoYour use of 'free' here is correct from the perspective of a developer working for intel, but as a user with a cpu running modified and previously opensource, but now closedsource, software it isn't applicable to me. GPL would have protected more of my freedom, provided they didn't just violate the GPL.
- cure 9y agoNone of the four freedoms are available in this context, Minix as part of the Intel ME. cf. https://www.gnu.org/philosophy/free-sw.en.html