8 ms·
> But recently we found a more problematic issue that also affects many > more distributions and all the previous GNU Boot release candidates. > The vboot sourc
by tlhunter 2y ago
> But recently we found a more problematic issue that also affects many
> more distributions and all the previous GNU Boot release candidates.
> The vboot source code used in Coreboot and in the vboot-utils package
> available in many GNU/Linux distributions contains nonfree code in
> their test data in tests/futility/data (nonfree microcode, nonfree
BIOS, nonfree Management Engine firmwares, etc).
Test data doesn't seem like a huge deal
- viraptor 2y agoGNU is strict about this. Strict to a dogmatic level which causes patching out firmware updates from Guix, leaving people with buggy/insecure systems. But they're free.
- mediumsmart 2y agoall systems are buggy and insecure and there are causes for that, not sure about dogmatic though.
- viraptor 2y agoYes, they're dogmatic in the literal meaning of that word. Other systems may have bugs too, but they don't take extra time to make sure you can't patch those bugs without additional work and going against the system.
- Propelloni 2y ago> Yes, they're dogmatic in the literal meaning of that word. Debatable. Guix has adequate grounds to build their beliefs on and they accept other stances besides their own. Guix may think the others are wrong, but that's their privilege, just like you are privileged to think they are wrong. So they seem to be more principled than dogmatic.
- User23 2y agoA belief being dogmatic isn’t about adequacy of evidence or lack thereof. It’s about that belief being one that must be held to be in fully good standing with the organization for which it is a dogma. I think we can reasonably say the FSF’s teaching on software freedom is at least something very much like dogmatic. I happen to believe they’re essentially right, but we live in an imperfect world and I still want my microcode bugs patched so I do that.
- Retric 2y agoI’ve only seen something called dogmatic when it lacks obvious justification. Don’t operate heavy machinery while drunk is a lesson people and organizations learn over and over. Would you say it’s dogmatic?
- deleted 2y ago[deleted]
- Propelloni 2y agoHmh, that's not what the dictionary says.
- kleiba 2y agoThere's no reason a bug fix for a free software needs to be non-free.
- viraptor 2y agoIt's about a bugfix and firmware for your hardware, not for free software.
- kleiba 2y agoGNU Boot is not free software?
- viraptor 2y agoSorry for the misunderstanding, I referred to the mentioned guix there, not boot.
- kleiba 2y agoAh, okay. Thanks for clarifying, I was getting confused. But guix is free software, too, no?!
- akerl_ 2y agoYes. And the commenter is pointing out that if Guix has a bug, and the available fix is via non-free firmware, they will not pull in the fix. Users thus continue to be affected by the bug.
- dullcrisp 2y agoThey make it sound like they’ve discovered a secret
- poincaredisk 2y agoThey make it sound like they're dogmatic about their views, which of exactly what they claim. I, for contrast, use free software almost exclusively, but I have no moral problems with using proprietary drivers.
- CodesInChaos 2y agoI always found the point of view silly that it's somehow better to ship proprietary firmware with the hardware, rather than shipping the same proprietary firmware bundled with an otherwise free operating system and uploading it to the hardware when booting.
- anthk 2y agoROM in hardware can be phisically mitigated up to a discrete time. The potential damage would be something, but never more. With nonfree firmware, you are a slave from the vendor, because he could release a new backdoored firmware anytime making even more damage to the users' freedom. OFC libre firmware is the best, such as the ath9k supported wireless devices.
- rlpb 2y ago> With nonfree firmware, you are a slave from the vendor, because he could release a new backdoored firmware anytime making even more damage to the users' freedom. You don't have to take the updated firmware, though?
- prmoustache 2y agoWe are talking about binary blobs that are bundled with drivers usually and sent to the device at initialization time which means you'd have to individually fix the version of n drivers in the package manager of your distro to avoid thay. This is doable but some people think it is easier to not have your distro shipping them in the first place.
- mistrial9 2y agois it the same?
- tourmalinetaco 2y agoI would much rather have a “buggy” system made for the user that was written with free software than a highly functional blob of proprietary code sending all of my data to an advertiser. Dogmatism in software is important, particularly regarding user freedoms. The very moment you relax on user freedoms you get horrible devices like the iPhone which doesn’t respect the user at all and uses them as resources to be mined for capital.
- argsnd 2y agoThe proprietary code is still there, you're just refusing to update it. Dogmatic FSF people think that hardware that has proprietary blobs stored in ROM is "free" but having to load it yourself makes it non-free.
- exe34 2y ago> Dogmatic FSF people think that hardware that has proprietary blobs stored in ROM is "free" Do they? Or do you think you might have exaggerated their position to make your point? I seem to remember they consider it as undesirable but inevitable, whereas passing around non-free code helps to normalize it.
- viraptor 2y agoYes they do. https://news.ycombinator.com/item?id=29286715 https://news.ycombinator.com/item?id=29286715
- exe34 2y agoI've read the link from the comment that you refer to: https://lists.gnu.org/archive/html/info-gnu/2018-04/msg00002.html https://lists.gnu.org/archive/html/info-gnu/2018-04/msg00002... I don't see where they claim that "proprietary blobs stored in ROM is "free", would you care to point it out please? Or were you referring to the opinion piece in the comment that you link? That does not appear to be the official position of the people doing the actual work.
- rwmj 2y agoAfter dealing with the xz backdoor I've become a lot more suspicious of binary blob test data which can't be explained or reproduced. Of course in some cases it's unavoidable.
- anthk 2y agoRead the comments about Guix, it's all about avoiding blobs in every process. Even engines from Scummvm had to be cut out because the supported games didn't had a way to recompile those from source (Broken Sword, Drascula)... And I think it's fair. If Broken Sword or Drascula were implemented with libre bytecode, I would be totally ok on redistributing the game data as freeware. But it's not the case. You are not redistributing game data with the bass, queen1, and the rest of packages under Trisquel, Debian or Ubuntu, but executables for a virtual a machine plus the game data. It's the same as running a freeware Minecraft libre and free Java VM (OpenJDK).
- 3np 2y agoThe issue is not that one of a binary blob, it's one of licensing.
- krater23 2y agoNo information which code was nonfree, no information how it was spotted. Rereleasing tarballs with the same verison number, which means there are now two official versions of the same tarball with the same version but with another md5 hash. In my opinion not the best information politics. p.s.: Do they have a so small overview about the own code that they need 3 versions to detect that there is non free code in the release?