6 ms·
My main concern with this is the fact that if Secure Boot is forced (UEFI Class 3/+) users might not be able to change or manage trusted keys. It is quite sad t
by bobcallme 9y ago
My main concern with this is the fact that if Secure Boot is forced (UEFI Class 3/+) users might not be able to change or manage trusted keys. It is quite sad that every few years we have to yet again have this conversation or defend the right to freely install software on machines that we bought or own.
- colemickens 9y agoA concern that has been repeated for 5+ years at this point, and one that has proven to be almost completely unsubstantiated by any real world devices. Don't get me wrong, the day I can't install Linux on my laptops, I'll grab the pitchforks, but the claims that this is going to happen almost exclusively hinge on some boogeyman ideology related to Microsoft that is fully unconvincing to me. edit: Please, tell me a single consumer laptop that doesn't allow key enrollment or complete Secure Boot disablement, otherwise, please stop with the FUD.
- mtgx 9y agoWasn't the previous backlash what got Microsoft to allow Verisign and others to make Secure Boot keys, too? Wasn't it originally only Microsoft the one that could do that, and it's why everyone freaked out that they may act their usual monopolistic-self and deny Linux distros the keys?
- Nullabillity 9y agoLook at Microsoft's certification requirements for ARM devices. This will be a problem much sooner than you think...
- joe_the_user 9y agoI may not be especially competent but I had significant difficulty installing Linux the last time tried. Thankfully it was possible but there are now significant hurdles. That's problematic. Whether it gets worse is unknown but the situation now is bad if anyone wants Linux to be freely available.
- colemickens 9y agoCan you elaborate on the "significant hurdles"? I've heard this before, but it never comes with any specifics - examples, error messages, forum posts, nothing. If nothing else, if there is seriously a manufacturer that is botching their implementation, please tell the community so that we can avoid them. I've installed Linux on dozens of laptops. Here are the "significant hurdles": 1. Literally none, because mainstream distros are signed and boot under Secure Boot 2. Literally a single toggle in the BIOS to disable SecureBoot. (Enrolling user keys is more steps, but optional) And then since most people really mean "UEFI" or other miscellaneous compatibility problems when they say SecureBoot: 3. Literally a single toggle in the BIOS to enable CSM mode for distros/install media that don't support UEFI. 4. Laptops that ship with the SSD in RAID mode (only very, very new kernels ship with support for it). I've only heard of one laptop that didn't allow it to be toggled and it was fixed within two weeks.
- joe_the_user 9y agoI mucked about the bios quite a bit and had to create a custom boot CD. I'm not super familiar with bios and the five hours I spent might have added up just finding "Literally a single toggle in the BIOS" for all I remember but so what? If you think this isn't a serious impediment to most users, you know less about the average user than I know about bios configuration. Argue "this is the way to do it" all you want. But arguing things into easiness is inherent ridiculous.
- smichel17 9y agoI observed a friend's computer that shipped with no hotkey to access the BIOS settings or boot menu. In order to get into the computer to boot to a usb drive for installing Linux, you had to either accept the Windows license agreement or disassemble the computer and pull the hard drive.
- digi_owl 9y agoThe laptop i am tying this on supposedly had a "BIOS" key combo, but i never got it to work. What i had to do was hold a key (shift i believe) while clicking restart in Windows, and then i would get a menu that could take me to the menu...
- LordKano 9y agoWhen that day comes, it'll be too late. You'll be the frog who was slow boiled in the pot.
- mtgx 9y agoI wonder if Linux machines would start getting more traction then, as everyone wouldn't just have the excuse that they might as well buy a Windows machine and then get to use either Windows or Linux if they want. Post-2020 a greater number of people may actually be forced to choose Linux. I'd rather we weren't forced to validate this theory of mine, but I'm cautiously optimistic about it.
- wmf 9y agoYeah, every time you buy a Windows PC and install Linux, you're telling the market you want Windows and you're starving the Linux ecosystem of revenue that could be used for better hardware support.
- joe_the_user 9y agoUnless you can buy a laptop with no OS for less than I can buy a laptop with Windows, buying from Linux ecosystem is going to be essentially an act of charity.
- wmf 9y agoIIRC Dell is now charging less for Linux than Windows.
- eat_veggies 9y agoDo you have a link? I'm in the market for a new laptop right now and a cheaper Dell with Linux installed sounds optimal.
- akubera 9y agoHere's an example of one of the options, it's ~$100 less if configured with Ubuntu-16.04: http://www.dell.com/en-us/work/shop/dell-laptops-and-notebooks/new-precision-3520/spd/precision-15-3520-laptop/xctop3520hwus_2 http://www.dell.com/en-us/work/shop/dell-laptops-and-noteboo... Canonical posted a short review of the available Dell models recently: https://insights.ubuntu.com/2017/11/14/new-dell-precision-machines-available-with-ubuntu-pre-installed/ https://insights.ubuntu.com/2017/11/14/new-dell-precision-ma... (HN on the article https://news.ycombinator.com/item?id=15702680 https://news.ycombinator.com/item?id=15702680)
- zanny 9y agoBecause you don't own them. Because you never actually owned them. You've never been told how your chipset works, or how your CPUs transpiler works, or what that extra chip that has system level access above ring 0 does, how to modify it, or how to disable it until people randomly found the magic bit to turn it off. You don't know what your hard drive firmware does or how secure it actually is. You don't know what the controllers on your RAM sticks are doing. You have no way to find out, either, because its all proprietary. It doesn't even matter that you are not really able to modify the firmware on RAM or in a hard drive, and that it takes way more work than almost any individual is capable of to actually even try to verify the firmware on any of these devices regardless of if you have the purported source code or not. Its all magic, its all black boxes, and you have no control over any of it, which is why companies regularly volunteer just going one step further all the time - they already have power over your hardware, what is a bit more amidst everything else being an obscured secret?
- kobeya 9y agoI certainly do legally own the chunk of semiconductor metal and plastic I am writing this on. I don’t appreciate the hyperbole.
- emn13 9y agoThe physical silicon is almost worthless. What's valuable is how you can use it; and there too I suspect "you don't own it" is hyperbole - but perhaps not entirely, given all IP involved. What's certainly not hyperbole is that you are not in control and that this lack of control can be a feature to others (e.g. DRM). Whether you legally would be allowed to mod your chip to "unlock" it is moot if you simply don't have that ability.
- kobeya 9y agoIt's one thing to lack the knowledge to use the device. It's another to lack the authority, if said knowledge could be acquired or reverse engineered. If I own the device, I should be allowed to send whatever control bits I want. I understand the DMCA and related laws change this, but that is a flaw of our legal system that needs to be corrected.
- MichaelBurge 9y agoA quick google search shows that Linux has between 3% and 7% of the desktop marketshare. It seems like an unwise business decision to make AMD the only possible choice for 5% of heavy purchasers, who also help with server purchasing decisions at IT jobs.
- wmf 9y agoLinux (the distros that people actually use) works fine with secure boot. Also, if MS mandates secure boot that means AMD will also use it.
- vetinari 9y agoThese distros also either do not enforce signing kernel modules, thus making the Secure Boot moot (Ubuntu), or enforcing valid signature on the modules, but making it easy to enroll your own Machine Owner Key (Fedora), so your custom-built kernel modules for VirtualBox, Nvidia, ZFS or whatever else you need, will still work.
- crdoconnor 9y agoIt still seems to fail whenever I install those distros until I turn it off.
- closeparen 9y agoAre companies where technical people have sway over IT purchasing decisions worth anything to suppliers? I'd assume all the margin is in deals made between salespeople and MBA CTOs on golf courses. Look at the landing page for the server/networking division of any major player in the space - that's clearly not pitched at engineers. Hell, this may even by why AWS is so popular: the landing page actually explains to engineers what their services even are.
- izacus 9y ago> My main concern with this is the fact that if Secure Boot is forced (UEFI Class 3/+) users might not be able to change or manage trusted keys. It is quite sad that every few years we have to yet again have this conversation or defend the right to freely install software on machines that we bought or own. Most of this pretty much comes from the copyright industry and DRM push. After all, if you can freely install kernel drivers and software, they can't do their DRM stuff.
- sliverstorm 9y agoTechies seem to understand the value of chained secure boot on Android, where shady vendors in east asia routinely try to sneak malware onto phones they sell. What is different about PC? How do you defend against such attacks without a secure boot chain & a fixed trusted key set?
- keiyakins 9y agoHonestly, a fixed trusted keyset with a jumper you can use to switch to a programmable keyset. Ideally with a jumper to set that in programmable or read-only mode. That makes it extremely obvious when something wants to mess with it, without actually preventing you if that's actually what you want.
- digi_owl 9y agoSomething akin to the ChromeOS developer switch?
- khedoros1 9y agoI'm happy with the Android device as long as I can unlock the bootloader and flash my own OS. I'm happy with the PC as long as security settings don't stop me from installing my own OS. If I'm prevented, then I don't care about the security arguments; the device isn't useful to me. My solution there is to avoid buying from vendors that I consider shady.