Live data from Hacker News

Torvalds clarifies Linux's Windows 8 Secure Boot position

zdnet.com

121–130 of 147 posts

Re: Torvalds clarifies Linux's Windows 8 Secure Boot position

#121
post #84

Having read through the entire thread instead of just the expletives, in my opinion it's a rare case of Linux and Greg being totally wrongheaded on the issue. The problem crops up because redhat submitted a pull request to enhance the existing in kernel live inclusion of additional trusted x.509 certificates. Note that this is 100% upstream and live. The pull was to add the ability to extract these x.509 certificates…

> Linus is really smart, but sometimes he makes a snap decision and then will perform whatever mental gymnastics are necessary to defend it to the death.

Hmm, could it be argued that this is less a snap judgement and more one of strengthening the long-term political and technical health of the OS? Rather than take the easier short-term path, which may eventually put Linux's metaphorical balls into a Microsoft vice, he would rather expose some pain now to defend as much as possible long-term autonomy. I would imagine this to be true given Torvald's historic ability to keep Linux healthy and viable in spite of one of the world's most powerful corporations.

Thus, in the short term, the user must perform some gymnastics to boot new kernels, but if this inconvenience is really that painful, it will create market disequilibrium that will motivate creative solutions. Some naive, off-the-cuff ideas:

- vendors pre-installing trusted root certs for Linux distros or a consortium of them,

- vendors making it easy to disable SecureBoot (physical switch?),

- vendors forcing SecureBoot configuration/opt-in on very first boot,

- UI, tools, or documentation enhancements to make local key management and signing easier, or

- simply a slightly more aware userbase (the same way phone locking/unlocking became a mainstream concept).

Re: Torvalds clarifies Linux's Windows 8 Secure Boot position

#122
post #107
post #84

Having read through the entire thread instead of just the expletives, in my opinion it's a rare case of Linux and Greg being totally wrongheaded on the issue. The problem crops up because redhat submitted a pull request to enhance the existing in kernel live inclusion of additional trusted x.509 certificates. Note that this is 100% upstream and live. The pull was to add the ability to extract these x.509 certificates…

For the average linux user, key signing isn't really a big deal, imho. Running as a user and protecting root without running unnecessary services is your first step, after that it's all kind of iffy. Signing something from an untrusted source (Having dealt with having to revoke a bunch of Microsoft signed stuff not too long ago, I assure you Microsoft is not infallible) doesn't buy you a whole lot. If you build a dri…

The average Linux user is technical by definition. They will care a big deal about this issue.

Re: Torvalds clarifies Linux's Windows 8 Secure Boot position

#123

Earlier quoted context omitted.

Secure Boot.

Well, duh. You aren't responsible for users getting rootkits installed on their computer. Obviously you would find it useless.

Sounds more like a user education problem to me. We don't let people drive without a license I don't see why we should worry about the people who use computers and don't bother to read up and understand what they're using.

In before "everyone should be able to use computers and they should just work" - I agree, it should be like this; however, the hardware, software, and usability has just never been at that level - and won't be for some time. Thus I dislike that argument.

I do understand this means we should be making things better as we go, I just don't see how this is one of those things, nor do I see how proper education should be lacking for the time being. To put that in the car analogy: Should we let people drive around because they need to get to work today but don't have time to sit the license right now?

Disclaimer: Opinion, and I'm a huge usability fan and hope one day things do "just work", I'm just also a realist and don't see the logic behind letting people use something before they or the thing is ready for them.

Edit: Just realised I went on a bit of a mad rant and kind of went a bit off topic. Apologies.

Re: Torvalds clarifies Linux's Windows 8 Secure Boot position

#124

Earlier quoted context omitted.

>In fact the whole UEFI in general I think it is a clusterfuck of mishmashed random ideas, some good, many bad. Care to explain why or how, instead of just throwing a general statement around?

Because UEFI is overly complicated and more akin to a mini-OS. All most people really want is for the firmware to set up the hardware and then hand over to the bootloader.

Isn't the BIOS supposed to be a mini-OS. It provides a common interface for different hardware platforms so software works on all of them. Of course then our address space increased, so you can only use many of those BIOS features in real mode. Then modern OS's reimplented those BIOS features. What we have now is an old mini-OS that has been hacked around to run modern OSes. UEFI is a welcome solution to that problem.

Re: Torvalds clarifies Linux's Windows 8 Secure Boot position

#125
post #121
post #84

Having read through the entire thread instead of just the expletives, in my opinion it's a rare case of Linux and Greg being totally wrongheaded on the issue. The problem crops up because redhat submitted a pull request to enhance the existing in kernel live inclusion of additional trusted x.509 certificates. Note that this is 100% upstream and live. The pull was to add the ability to extract these x.509 certificates…

> Linus is really smart, but sometimes he makes a snap decision and then will perform whatever mental gymnastics are necessary to defend it to the death. Hmm, could it be argued that this is less a snap judgement and more one of strengthening the long-term political and technical health of the OS? Rather than take the easier short-term path, which may eventually put Linux's metaphorical balls into a Microsoft vice, h…

"Naive" is an overly polite way of describing ideas which lead in with an idea that flies in the face of pretty much the whole history of Linux.

Re: Torvalds clarifies Linux's Windows 8 Secure Boot position

#126
post #84

Having read through the entire thread instead of just the expletives, in my opinion it's a rare case of Linux and Greg being totally wrongheaded on the issue. The problem crops up because redhat submitted a pull request to enhance the existing in kernel live inclusion of additional trusted x.509 certificates. Note that this is 100% upstream and live. The pull was to add the ability to extract these x.509 certificates…

Alternatively, Microsoft could sign x.509 certs. Why are they placing certificate data into Windows binaries in the first place? The Linux kernel is simply not the place to parse Windows binaries. It's not Linus's fault the de facto standard is a Windows binary, it's just another harmful side-effect of the Windows monopoly. Really SecureBoot should just die on the vine. But the monopolist wants to force it on their c…

EFI uses the PE executable format.

Re: Torvalds clarifies Linux's Windows 8 Secure Boot position

#127
post #121

Earlier quoted context omitted.

> Linus is really smart, but sometimes he makes a snap decision and then will perform whatever mental gymnastics are necessary to defend it to the death. Hmm, could it be argued that this is less a snap judgement and more one of strengthening the long-term political and technical health of the OS? Rather than take the easier short-term path, which may eventually put Linux's metaphorical balls into a Microsoft vice, h…

"Naive" is an overly polite way of describing ideas which lead in with an idea that flies in the face of pretty much the whole history of Linux.

:) DH2, or DH3, at best. http://www.paulgraham.com/disagree.html

Market-driven vendor support of Linux is not unprecedented. Ever heard of Dell, Lenovo, Acer, Nvidia, or the Android ecosystem?

Re: Torvalds clarifies Linux's Windows 8 Secure Boot position

#128
I'm just going to put my fingers in my ears and not listen to anything anyone might say (write) that gets close to excusing the current situation or defending Secure Boot!

As such: Secure Boot is just another lame attempt by Microsoft to slow down/control the competition; they are abusing their position on the market once again, like they did in the past, like they will do in the future. This is their way, "the wolf changes its coat, but not the disposition".

This shows that now more than ever Microsoft is shitting their pants because of Linux/Android/Google/Ubuntu/RHEL/LibreOffice/FOSS SQL/etc; they are slowly but surely losing the war, they are losing market share on every front. The way things are now in 10-15 years I bet they will no longer have the 90% of PCs share they have today, but Secure Boot might give them some help.

I can already imagine mr. Ballmer rubbing his hands in satisfaction: "oh, nice, we'll have the keys to all PC hardware".

My advice: do not buy Microsoft, do not buy hardware on which Secure Boot cannot be disabled. We _must not_ have all PC hardware controlled by a single company - it is just stupid.

And of all systems they chose CA? Really? After the epic way it failed time and again in the SSL cert industry - think Komodo or DigiNotar.

Not to mention keys given to USA and other governments that will be able to easily install malware and other crap to control the "sheep" (the germans already have some "official" trojans lol).

This is madness people.

Re: Torvalds clarifies Linux's Windows 8 Secure Boot position

#129

Earlier quoted context omitted.

>In fact the whole UEFI in general I think it is a clusterfuck of mishmashed random ideas, some good, many bad. Care to explain why or how, instead of just throwing a general statement around?

If you need an explanation as to why a encrypted only closed platform shouldn't exist, you're already off the mark.

You know what, this comment is really rude. UEFI is a pretty complex topic, and it's reasonable for people to ask questions about it.

Re: Torvalds clarifies Linux's Windows 8 Secure Boot position

#130
post #118
post #84

Having read through the entire thread instead of just the expletives, in my opinion it's a rare case of Linux and Greg being totally wrongheaded on the issue. The problem crops up because redhat submitted a pull request to enhance the existing in kernel live inclusion of additional trusted x.509 certificates. Note that this is 100% upstream and live. The pull was to add the ability to extract these x.509 certificates…

> Every distro should parse the PEs and add every key of every 3rd part module they wish to allow to run and embed these in their signed kernels, issuing a new kernel every time a driver revs. Why do they have to embed the ID of whitelisted modules in the signed kernel? Why not have a kernel that will load any module the root user tells it to load, then have userland insmod utility verify the signatures using a confi…

Because then your trust path includes the userspace insmod utility and every library and system service it depends on, all of which would themselves need signature verification and hardening against things like LD_LIBRARY_PATH (even from root).

Otherwise, you can easily construct a harmful payload consisting of the distro-signed Shim, that kernel, and a modified userspace that loads an arbitrary module which takes over the kernel and runs arbitrary code in ring 0. And then that distro's Secure Boot signing key gets revoked.

Post reply on HN