3 ms·
No. You're wrong. We want open source because we want control of what run on our machines. That standard goes against it. Why not have a per machine signature
by gcb 14y ago
No. You're wrong. We want open source because we want control of what run on our machines.
That standard goes against it.
Why not have a per machine signature that you sign your code against?
Centralize it and have no more control. That's no catch22 whatsoever.
- recoiledsnake 14y ago>We want open source because we want control of what run on our machines >That standard goes against it. >Why not have a per machine signature that you sign your code against? And the Microsoft UEFI rules for getting a Windows 8 Logo REQUIRES UEFI setup to provide to a physically present user the option to turn off secure boot and add/delete your own keys. How many times has this to be repeated to the same seasoned and regular commentators on this site and many others in similar stories from the past few months? Is there a problem with communication here? Or is it intentional misunderstanding with an aim to spread FUD? Sorry for the outburst, but I am really lost here with the same people making the same 50 silly wrong comments many, many times over and over again about UEFI secure boot. It's like they just see the headline like 'Red Hat to pay MS for booting Linux' and don't care or bother to read Microsoft's, Red Hat's and Ubuntu's take before spouting off in the comments about evil lockdown.
- miles 14y agothe Microsoft UEFI rules for getting a Windows 8 Logo REQUIRES UEFI setup to provide to a physically present user the option to turn off secure boot and add/delete your own keys. Can you please provide an authoritative link for this? The only thing I turned up was this "Secure Boot Overview" updated a few weeks ago: http://technet.microsoft.com/library/hh824987.aspx http://technet.microsoft.com/library/hh824987.aspx [This topic is pre-release documentation and is subject to change in future releases. Blank topics are included as placeholders.] [A]fter final firmware validation and testing, the OEM locks the firmware from editing, except for updates that are signed with the correct key or updates by a physically present user who is using firmware menus, and then generates a platform key (PK). The PK can be used to sign updates to the KEK or to turn off Secure Boot. EDIT: Just found this (tl;dr - disabling Secure Boot is mandatory for x86 and forbidden for ARM): Windows Hardware Certification Requirements http://download.microsoft.com/download/a/d/f/adf5bede-c0fb-4cc0-a3e1-b38093f50ba1/windows8-hardware-cert-requirements-system.pdf http://download.microsoft.com/download/a/d/f/adf5bede-c0fb-4... 17. MANDATORY. On non-ARM systems, the platform MUST implement the ability for a physically present user to select between two Secure Boot modes in firmware setup: "Custom" and "Standard". Custom Mode allows for more flexibility as specified in the following: a) It shall be possible for a physically present user to use the Custom Mode firmware setup option to modify the contents of the Secure Boot signature databases and the PK. This may be implemented by simply providing the option to clear all Secure Boot databases (PK, KEK, db, dbx) which will put the system into setup mode. b) If the user ends up deleting the PK then, upon exiting the Custom Mode firmware setup, the system will be operating in Setup Mode with SecureBoot turned off. c) The firmware setup shall indicate if Secure Boot is turned on, and if it is operated in Standard or Custom Mode. The firmware setup must provide an option to return from Custom to Standard Mode which restores the factory defaults. On an ARM system, it is forbidden to enable Custom Mode. Only Standard Mode may be enabled.
- recoiledsnake 14y ago>EDIT: Just found this: Ahh, I went to the trouble of finding that and had it in my clipboard :) Took me a few mins and was really hard to find on Google and was buried amongst all the noise generated by these FUD stories and discussions about UEFI secure boot. It's almost as if it was Google-Bombed.
- miles 14y agoSorry about that, recoiledsnake. Thanks for the followup. Do you not consider Secure Boot and the prohibition against disabling it on ARM devices a slippery slope?
- recoiledsnake 14y ago>Do you not consider Secure Boot and the prohibition against disabling it on ARM devices a slippery slope? Yes, it definitely is. But the seeds for that were planted by Apple which can't keep their devices in stock, so when I see the ragefest directed towards Windows RT and Microsoft evil dominance with nary a mention of Apple(see Mozilla's FSF, and EFF's(?) blog posts about UEFI Secure Boot and almost all the discussions on HN and other sites) it feels like people are actively trying to avoid mention of Apple since it undermines the point they're making about Microsoft. And many of these folks call it an antitrust issue because Microsoft was previously declared a monopoly on the PC and had successful antitrust suits against it. But forcing MS to open up Windows RT while leaving the iPad alone(which has tremendous marketshare and profitshare in tablets) will only leave Windows RT weaker against the iPad(because they can't subsidize them with the app and media sales on Windows RT, see XBox). And every time I mention this, I hear crickets as people move on to other threads to continue piling on MS and ignore Apple.
- miles 14y agoI am in complete agreement with you on this. It is very sad to see the direction Apple has taken computing devices in, the blind acceptance by the public, and perhaps most disturbingly, the thunderous silence of the geeks. (Downvotes away! (assuming anyone is reading this far in.))