5 ms·
IMO, the problems that [U]EFI introduces (that far exceed the historical limitations it overcomes) should be self-evident. IMO, he should not have to argue aga
by aplorbust 9y ago
IMO, the problems that [U]EFI introduces (that far exceed the historical limitations it overcomes) should be self-evident.
IMO, he should not have to argue against having multiple, redundant copies of drivers, shells and utilties each accessible only in its own "OS" (UEFI, GRUB, OS). It should not be a debate. This is definitely not "defense in depth". IMO, whomever controls the first OS controls the computer because there is no need for the second and third OS in order to do work (make network connections, move files across the network, etc.).
These "hardware features", whether its [U]EFI or ME or whatever acronym, IMO is a land grab by hardware vendors over what we know as the "OS". Less computer owner control, more vendor control. The sum effect of all these "features" is that verification that something is the way that the owner wants it and has not been modified is far too complex and is ultimately under control of the vendor, not the computer owner.
I do most work on the commandline in text-mode (no graphics layer) and as such I only need one OS, with some basic utilities. When the news came that new computers would have [U]EFI, I considered whether I should just switch from the OS I am using to [U]EFI. It seemed to have all the utilities I would need to do work, along with the ability to extend with new programs.
I only need one OS to boot to a working environment. I should be able to choose that OS. I hope that Minnich and Hudson and others will consider that the user may want to choose a kernel other than Linux as a source for drivers, e.g., BSD, Plan9, others incl. future OS not yet written, etc., even if it today it has inferior driver support compared to Linux, or Intels UEFI, or whatever.
The speaker seemed a bit perplexed when someone in the audience questioned whether Linux is a "TCB". What is and what is not a "TCB" should be the computer owners decision, and not anyone elses. If the computer owner wants to cede authority for that decision to a third party, then she can make that choice. But IMO it should be a choice made by the computer owner, and not anyone else.
- Santosh83 9y agoThis is in the hands of the firmware/hardware manufacturers. AFAIK, for instance, the version of Minix that serves as Intel's ME will continue to be operational even if the UEFI is replaced by Linux. The issue is that 'firmware' actually means many different blobs of software in various ROMs spread throughout the system, from disk controllers to GPUs to memory controllers to NIC and so on. You will never be able to verify you have full control over your system unless all these firmware have the ability to be reflashed/replaced. LinuxBoot/Coreboot are a step in the direction, but without major concessions from hardware vendors this is an uphill battle.
- madez 9y agoThat's why it is important to not buy random shiny devices. Open source hardware like for example the Teres-1 [0] are what allows us to stay in control. I can't wait for even more open successors based on RISC-V processors. [0] https://www.olimex.com/Products/DIY-Laptop/ https://www.olimex.com/Products/DIY-Laptop/
- katastic 9y agoIf you don't buy a random shiny device, how do you think the people in charge of those companies are even going to know? Even if they DID care, how is your one "not purchase" going to show up in any of their marketing analysis?
- morganvachon 9y agoI wonder why they are using the Allwinner A64 if they are concerned with FOSS though? It's one of the more serial offenders when it comes to GPL violations[1], and it has a backdoor in its custom kernel config that could be used to take over the system[2]. I'm not trying to crap on your efforts, it's just smart to vet any system even if they claim to be FOSS or open hardware friendly. [1] http://linux-sunxi.org/GPL_Violations http://linux-sunxi.org/GPL_Violations [2] https://arstechnica.com/information-technology/2016/05/chinese-arm-vendor-left-developer-backdoor-in-kernel-for-android-pi-devices/ https://arstechnica.com/information-technology/2016/05/chine...
- madez 9y agoActive mainlining of Allwinner chips is under way.[0] I only use the devices with kernels from trustable sources, like Debian. The A20-Olinuxino-Micro works already quite good with Debian out of the box. It is even recommended by FreedomBox.[1] Because mainling for the A64 isn't at a usable state right now, I'm holding back on buying a Teres-1. [0] http://linux-sunxi.org/Linux_mainlining_effort http://linux-sunxi.org/Linux_mainlining_effort [1] https://wiki.debian.org/FreedomBox/Hardware https://wiki.debian.org/FreedomBox/Hardware
- gwes 9y ago
- deleted 9y ago[deleted]
- johncolanduoni 9y ago> These "hardware features", whether its [U]EFI or ME or whatever acronym, IMO is a land grab by hardware vendors over what we know as the "OS". Less computer owner control, more vendor control. What control did you have with an old PC BIOS that you now are missing with UEFI? Things like SMM and Intel ME that keep running after your actual OS has started existed and were pretty much ubiquitous before UEFI became common in consumer hardware. They aren't required to implement UEFI, and UEFI doesn't enable them any more than PC BIOS did. > I only need one OS to boot to a working environment. I should be able to choose that OS. You weren't able to choose your PC BIOS any more than you can choose your UEFI implementation now. There are PC BIOS and UEFI motherboards that can accept coreboot or something similar, and in all other cases you're stuck with an opaque vendor blob. At least with UEFI you have an opportunity to write your own software that can be part of the boot process, doing so with a BIOS was usually impossible unless you could install an option ROM. > I do most work on the commandline in text-mode (no graphics layer) and as such I only need one OS, with some basic utilities. When the news came that new computers would have [U]EFI, I considered whether I should just switch from the OS I am using to [U]EFI. It seemed to have all the utilities I would need to do work, along with the ability to extend with new programs. That's great for you but a lot of people want to be able to install different OSes on their hardware. Having to duplicate the hardware initialization code for each would be a major pain and would probably result in a lot of hardware only supporting one OS (e.g. many consumer motherboards would probably be Windows only in this situation). I really don't see how having the firmware wedded to a particular OS is going to give people more choice.
- chriswarbo 9y ago> What control did you have with an old PC BIOS that you now are missing with UEFI? I had a PC with a BIOS once. It didn't seem as slick as the Kickstart I'd used for the previous decase on my Amigas. It was also much less configurable/programmable than the OpenFirmware that came on my subsequent PC. My current machine uses libreboot, which is fine but I much prefer OpenFirmware. tl;dr "BIOS vs EFI" is a false dichotomy, and "it's better than BIOS" is pretty weak praise for a boot system.
- 9y ago
- dajt 9y agoThese "hardware features", whether its [U]EFI or ME or whatever acronym, IMO is a land grab by hardware vendors over what we know as the "OS". Less computer owner control, more vendor control. As long as you can still run the OS of your choice at the top of this stack of vendor OSs, what do the vendors gain by this 'land grab'? Particularly the HW vendors. I can imagine Apple and MS are happy to lock things down so only their OSs run easily but What benefit does any HW vendor get from from UEFI? Surely the benefit to Intel from IME is being able to say "you can remotely manage and recover a borked server if you have our IME enabled", but I can't think what else it gives them. I like the idea of a system running hardware that does the minimum of initialisation before running code of the user's choice but that is more due to my being an 8-bit kid and worries of buggy vendor blobs than assuming the HW vendors are being nefarious.
- deleted 9y ago[deleted]
- gatmne 9y ago> What do the vendors gain by this 'land grab'? One thing is that it could be used to as a venue to pursue new recurring revenue streams. While not exactly the same thing, I've seen some people joke about intel locking owners from cpu features behind monthly subscriptions. This kind of exploitation requires disallowing owners from fully controlling their devices in order to be effective. The more control vendors have, the more elaborate and exploitative these schemes can be, and the less likely owners will be able to do anything about it.
- whyagaindavid 9y agoWell said. I remember a cheaper model of Sony laptop in which you cannot enable hyperthreading though it had same chipset of an expensive model.
- aplorbust 9y ago50+ points. Amazing. Anyones guess what this means but at the least I think it shows users1 have opinions about UEFI. I think it is a good thing if computer owners care about initialization, bootloaders, owner control and freedom of choice. Clearly some do care. Hats off to those folks. 1 Besides only this one: http://yarchive.net/comp/linux/efi.html http://yarchive.net/comp/linux/efi.html
- heeen 9y ago> I do most work on the commandline in text-mode (no graphics layer) I'm pretty sure there is some graphics layers even in your work environment.
- aplorbust 9y agoVGA textmode. I stopped using X11 many years ago. Theres no graphics drivers compiled into the custom kernel that I use (not Linux). The term "no graphics layer" seemed like adequate shorthand.