Live data from Hacker News

I Love Arch, but GNU Guix Is My New Distro

boilingsteam.com

291–300 of 318 posts

Re: I Love Arch, but GNU Guix Is My New Distro

#291
post #269

Earlier quoted context omitted.

This is completely obtuse. Why isn’t your anger at the Guix or Linux-libre maintainers’ supposed withholding of information (‘censorship’) directed instead at publishers of closed-source, unauditable binary blobs, which constitute a fundamentally greater security risk than any auditable code repository ever could? How does it even make sense for Linux-libre to publish notifications about available binary blobs of any…

You're ignoring the crux if the issue. This isn't about running proprietary microcode or not. All x86 Guix users are running proprietary microcode . Period. This is a fact, whether they know about it or not. It's not optional. Would it be great if they didn't have to? Sure. But that's not the world we live in. This is about withholding information about an update to the proprietary microcode they are already running…

Leaving aside the fact that binary blobs already existing in x86 processors doesn’t mean much for users because they can’t help that - I mean, GNU existed before Linux, and only became a completely free operating system when Linux was released, so it’s not like the position of the GNU project was to completely rule out the possibility of running any software or hardware if there was a sniff of non-free software within a 5km radius …

No, you’re ignoring the crux of the issue, which is user freedom. Why are you so insistent that Guix wave the flag for Intel and allow its users’ freedoms to be even more flagrantly violated by shipping updated microcode? Why does the FSF not openly publishing certain kinds of information amount to censorship? - do you think that, if they were to remove certain blobs from the kernel but leave in these nebulous notifications that microcode updates are available, it wouldn’t be censorship?

Talk about a bad user experience by the way - what you suggest is for the maintainers of Linux-libre to say ‘oh, by the way, there are critical updates to microcode running on your processor, but we’re not going to give them to you.’ That’s antisocial nonsense. Should they tell users about updates to all the other drivers in the kernel which they don’t ship either? Give me a break.

I am currently, at this very moment, running updated Intel microcode on my Guix machine. Every Guix user who has used the distro for more then 5 minutes knows that a) you can track any channel you like containing packaged software, and b) there is a popular channel which contains some useful non-free software. They know this because it takes about 5 minutes to use a search engine for, say, ‘How do I get Nvidia drivers on my Guix System’, which will lead you to nonguix. What exactly is your problem? Do you think Guix users need to be babied?

> Auditability doesn't mean things get audited or all bugs fixed.

Correct! But it means that they can.

Why won’t you respond to the fact that Guix users simply don’t feel hurt by this? You have taken it upon yourself to speak on behalf of a community which is perfectly happy with the existing arrangement - that the default kernel is built on Linux-libre, and they are free to use any other compatible kernel they like, including the upstream.

If you don’t like Linux-libre, don’t use it. If you don’t like Guix, don’t use it. Your pearl-clutching about these projects’ violation of their users’ rights is unwarranted, unwanted, obtuse, and very annoying. If I didn’t know better, I’d think you had it out for FSF.

I’ll leave that as my final word on this because this conversation is fruitless and pointless. You are moralising on the behalf of a community that you are not a member of and that doesn’t care for much of what you have to say for them.

Re: I Love Arch, but GNU Guix Is My New Distro

#292

Earlier quoted context omitted.

>Unfortunately I have not seen anyone actually give a reason why the line should be drawn there instead of closed source blobs are not ok period this makes it sound like FSF supports these blobs. how i understood the situation is that they tolerate them until an alternative presents itself. this is a valid position to take and does not make them hypocrites/cult/religion etc

They are literally endorsing Bluetooth dongles with half a megabyte of proprietary ROM as "respecting your freedom". That goes a little beyond "tolerating", don't you think?

'Respects Your Freedom' is a (trademarked?) label that comes with clear and readily available certification rules. according to FSF, these are products that are simply the best options available as far as FSF's free-software ethics are concerned. in this sense it is simmilar to 'fair trade' labels you find on products. since you guys love extreme examples, i could ask you if when you use an Apple computer do you expect to be able to eat it

actually since you work with macs, do you think Apple respects your freedom or do you think they are more ethical than FSF?

Re: I Love Arch, but GNU Guix Is My New Distro

#293
post #287

Earlier quoted context omitted.

then you must disagree with alexvoda who said that FSF "pretends to hold an ethical position"? to clarify my previous post, i was using the term dogmatic in the context of some people claiming that FSF is a cult

To go big picture, I think all of this is rooted in the fact that "capitalism as practiced" has addled our brains into thinking that there can only be two kinds of organizations, companies that go for profit at all cost, and pure-of-heart non-profits that must be on some monk-like religious stuff. What it can't conceive of is an organization with big picture goals that aren't "making a profit" that require strategy a…

i dont think FSF is a religion. actually i am arguing against this labeling

Re: I Love Arch, but GNU Guix Is My New Distro

#294
post #272

Earlier quoted context omitted.

>There is no reason to trust IBM not to include a silicon backdoor Yeah ok now we are in the religion side of things, since you cannot check the silicon...well i stop here, not worth my time. BTW: The power microcode is opensource.

You can backdoor silicon just as well as you can backdoor software or microcode. Why do you only care about trusting the latter?

>>since you cannot check the silicon...

READ.

The microcode is opensource..

Re: I Love Arch, but GNU Guix Is My New Distro

#295
post #291

Earlier quoted context omitted.

You're ignoring the crux if the issue. This isn't about running proprietary microcode or not. All x86 Guix users are running proprietary microcode . Period. This is a fact, whether they know about it or not. It's not optional. Would it be great if they didn't have to? Sure. But that's not the world we live in. This is about withholding information about an update to the proprietary microcode they are already running…

Leaving aside the fact that binary blobs already existing in x86 processors doesn’t mean much for users because they can’t help that - I mean, GNU existed before Linux, and only became a completely free operating system when Linux was released, so it’s not like the position of the GNU project was to completely rule out the possibility of running any software or hardware if there was a sniff of non-free software withi…

very well said

>If I didn’t know better, I’d think you had it out for FSF

given the ammount of bad faith in the threads i think it definitely looks like a campaign

Re: I Love Arch, but GNU Guix Is My New Distro

#296
post #269

Earlier quoted context omitted.

This is completely obtuse. Why isn’t your anger at the Guix or Linux-libre maintainers’ supposed withholding of information (‘censorship’) directed instead at publishers of closed-source, unauditable binary blobs, which constitute a fundamentally greater security risk than any auditable code repository ever could? How does it even make sense for Linux-libre to publish notifications about available binary blobs of any…

You're ignoring the crux if the issue. This isn't about running proprietary microcode or not. All x86 Guix users are running proprietary microcode . Period. This is a fact, whether they know about it or not. It's not optional. Would it be great if they didn't have to? Sure. But that's not the world we live in. This is about withholding information about an update to the proprietary microcode they are already running…

>Every single die-hard FSF fanboy needs to learn about the 27 blobs running in little ROMs inside their computer, so they stop believing they live in a fake freedom utopia and come to terms with the reality we live in. Maybe then we'll have even more people pushing for firmware freedom

who believes this? why are you constantly being insulting? a lot of linux fanboys think that if you run linux you can't get hacked. does that make linux dishonnest? of course not! there are misinformed people everywhere. having been in this exchange for about two daya i learned that FSF does a very good job to inform users about what using their products entails

Re: I Love Arch, but GNU Guix Is My New Distro

#297

Earlier quoted context omitted.

You're ignoring the crux if the issue. This isn't about running proprietary microcode or not. All x86 Guix users are running proprietary microcode . Period. This is a fact, whether they know about it or not. It's not optional. Would it be great if they didn't have to? Sure. But that's not the world we live in. This is about withholding information about an update to the proprietary microcode they are already running…

>Every single die-hard FSF fanboy needs to learn about the 27 blobs running in little ROMs inside their computer, so they stop believing they live in a fake freedom utopia and come to terms with the reality we live in. Maybe then we'll have even more people pushing for firmware freedom who believes this? why are you constantly being insulting? a lot of linux fanboys think that if you run linux you can't get hacked. d…

https://ryf.fsf.org/products/TET-BT4

No mention of the half megabyte of proprietary Bluetooth stack firmware (with significant security and privacy implications) that's in that dongle which supposedly "Respects Your Freedom".

https://ryf.fsf.org/products/VikingsX200

No mention of:

* Proprietary CPU microcode ROM (full access to CPU/memory, security critical)

* Proprietary embedded controller firmware (H8S, connected LPC bus, full access to all memory, security critical, might be able to cause physical destruction / a fire with the right GPIO abuse)

* Proprietary TPM firmware (connected to LPC bus, full access to all memory, security critical)

* Proprietary USB camera firmware (connected to USB port, very large attack surface for OSes)

* Proprietary Bluetooth module firmware (connected to USB port, etc.)

* Proprietary USB card reader module firmware (connected to USB port, etc.)

* Proprietary SATA HDD firmware (can access/modify all user data, security critical if you don't use FDE + integrity)

And those are just the ones I could quickly pick out from the schematic; pretty sure there's at least a couple more major ones and even more minor ones. All the other laptops they endorse are in a similar situation.

How, exactly, are the FSF informing users about the devices they endorse?

Re: I Love Arch, but GNU Guix Is My New Distro

#298

Earlier quoted context omitted.

>Every single die-hard FSF fanboy needs to learn about the 27 blobs running in little ROMs inside their computer, so they stop believing they live in a fake freedom utopia and come to terms with the reality we live in. Maybe then we'll have even more people pushing for firmware freedom who believes this? why are you constantly being insulting? a lot of linux fanboys think that if you run linux you can't get hacked. d…

https://ryf.fsf.org/products/TET-BT4 No mention of the half megabyte of proprietary Bluetooth stack firmware (with significant security and privacy implications) that's in that dongle which supposedly "Respects Your Freedom". https://ryf.fsf.org/products/VikingsX200 No mention of: * Proprietary CPU microcode ROM (full access to CPU/memory, security critical) * Proprietary embedded controller firmware (H8S, connected…

their certification process as oitlined on https://ryf.fsf.org/about/criteristates:

BEGIN

> there is one exception for secondary embedded processors. The exception applies to software delivered inside auxiliary and low-level processors and FPGAs, within which software installation is not intended after the user obtains the product. This can include, for instance, microcode inside a processor, firmware built into an I/O device, or the gate pattern of an FPGA. The software in such secondary processors does not count as product software.

>We want users to be able to upgrade and control the software at as many levels as possible. If and when free software becomes available for use on a certain secondary processor, we will expect certified products to adopt it within a reasonable period of time. This can be done in the next model of the product, if there is a new model within a reasonable period of time. If this is not done, we will eventually withdraw the certification.

END

this explains their decisions in terms of their software freedom ideals, and its perfectly clear. i keep trying to explain to you that FSF is not about doing their best in terms of security. FSF is about doing what they believe is best for software freedom. althought it would be nice, i just dont see why they MUST inform their users about security entailments

of course, it is perfectly fine to point out security flaws in such an approach, but FSF is not selling security, and since the original topic is GNU Guix distro, GNU Guix does not market itself as a security-centric distro. why is this so hard for you to accept

alot of your argument rests on failure of their logic and bluring of a clear distinction between hardware and software. fine, it is a VALID point, but it is a corner case. FSF has taken an approach they believe deals best with such corner cases and explained their reasoning. they might be right in their approach, they might be wrong. you cannot satisfy everyone and not accepting that is just simply infantile

FSF is a pretty large organisation. for large organisations some form of bureocracy becomes necesary to achieve normal functioning. however, bureocracy will always entail some ilogical elements, esspecially in corner cases. that is just life, i believe

Re: I Love Arch, but GNU Guix Is My New Distro

#299

Earlier quoted context omitted.

https://ryf.fsf.org/products/TET-BT4 No mention of the half megabyte of proprietary Bluetooth stack firmware (with significant security and privacy implications) that's in that dongle which supposedly "Respects Your Freedom". https://ryf.fsf.org/products/VikingsX200 No mention of: * Proprietary CPU microcode ROM (full access to CPU/memory, security critical) * Proprietary embedded controller firmware (H8S, connected…

their certification process as oitlined on https://ryf.fsf.org/about/criteristates : BEGIN > there is one exception for secondary embedded processors. The exception applies to software delivered inside auxiliary and low-level processors and FPGAs, within which software installation is not intended after the user obtains the product. This can include, for instance, microcode inside a processor, firmware built into an…

> doing what they believe is best for software freedom

It is quite self-evident that not being open about the existence of proprietary code is not the best for software freedom.

I know about their certification process; my entire argument is that their criteria are terrible and the lack of transparency about specific devices and what firmware they contain deceptive. You bringing up their criteria repeatedly isn't helping you counter that point. This silly loop of "The criteria suck. / These are the criteria." doesn't get us anywhere.

If the FSF believe in software freedom, why are they not informing their users about the nonfree software that exists in the devices they sell as "Respects your Freedom"? I'm not saying "why are they certified here"; fine, they have their rules. Why are they not documenting how these devices interact with those rules? Why are they obscuring all of this? What do they have to gain by keeping people in the dark?

To me it is just very clear that they're doing this because they are trying to build a narrative that is different from reality, and the only way that narrative works is if people don't discover the problems with it. Your opinion may differ, but everything I've seen about the FSF's behavior in recent years points towards that. If they wanted to be honest there would be no reason not to document those firmware blobs.

Re: I Love Arch, but GNU Guix Is My New Distro

#300

Earlier quoted context omitted.

their certification process as oitlined on https://ryf.fsf.org/about/criteristates : BEGIN > there is one exception for secondary embedded processors. The exception applies to software delivered inside auxiliary and low-level processors and FPGAs, within which software installation is not intended after the user obtains the product. This can include, for instance, microcode inside a processor, firmware built into an…

> doing what they believe is best for software freedom It is quite self-evident that not being open about the existence of proprietary code is not the best for software freedom. I know about their certification process; my entire argument is that their criteria are terrible and the lack of transparency about specific devices and what firmware they contain deceptive. You bringing up their criteria repeatedly isn't hel…

arguing that FSF is some crazy sect or a religion is certainly not constructive to improving what they do

i think that how you framed your concern in this last point is valid from a security point of view. as someone who values knowing security implications i support the argument that they should improve their work on security matters. in saying that, to me FSF is certainly no worse (i would think alot better) than closed source vendors, including ms, apple, intel, nvidia etc as far as making their users aware of security problems is concerned. i actually think that every device should come with a cigarete packet style label that says "might include backdoor inside", not just FSF products. in fact, maybe if only FSF did this, it might create an impression that only their products have this issue

Post reply on HN