Live data from Hacker News

In Defense of Free Software: My Case Against Lenovo in Mexico

globalvoices.org

21–30 of 33 posts

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#21
post #6

Earlier quoted context omitted.

Secure Boot is designed to prevent malware from tampering with the BIOS by verifying bootloader (and sometimes kernel-mode driver) signatures. In this case, it looks like Lenovo either accidentally or intentionally borked the implementation of Secure Boot, because you are supposed to be able to turn it off when using non-Microsoft operating systems. FWIW, I believe Fedora supports Secure Boot by signing a static boot…

> loads GRUB As your link mentions, that loader only loads signed kernels (with signed modules). edit: > designed to prevent malware That's the official story. Anybody familiar with Microsoft's history knows they have been trying to lock down the wintel platform for a long time. Creating a "Trusted Computing" environment specifically for DRM purposes has been a goal since "Palladium".

I thought twice about responding to this.

I worked on Palladium from very early days in 2002 through renaming to NGSCB and the eventual shutdown/transition of the project to ship BitLocker in Vista

The team never saw DRM as being an interesting use case. Remember that the Darknet paper [1] was written by the Palladium architects and product manager. The team fully understood that DRM wasn't an effective use of a secure computing environment.

The scenarios that we were interested in were more like credential management, or being able to run remote sessions from a trusted space within an otherwise untrusted machine, etc.

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#22
If you can't disable "secure boot" - you should return that piece of lock-in trash and request a refund.

Lenovo are also infamous for refusing the refund the Windows tax (i.e. when you want refund the price of Windows that came with computer pre-installed, because you don't want to use it). Only taking them to court can help.

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#24
post #7

There's a collective of quixotic Mexican software developers and users that is quite active. I wonder why is it that FSF's philosophy with its exhortation to viciously defend freedom resonates so well in some parts of Mexico. It was those groups, which congregate on the Hackmitin[1], Hacklab Autónomo[2] and Rancho Electrónico[3] that helped Jacobo Nájera with his legal proceedings against Secure Boot. I went a couple…

> The whole "security" thing is a sideshow; the real goal here with "Secure" Boot is to make it harder to install unlicensed copies of Windows.

How does that make sense? The Lenovo laptop in question, like most non-Apple PCs sold in the West, came with a licensed copy of some version of Windows; and Microsoft's strategy lately has been to offer (almost coerce) free OS upgrades, apparently valuing users being up-to-date over the revenue it could gain from the meager fraction of users who'd pay for upgrades. So there's little reason for users to ever install pirated copies of Windows on such devices, or for Microsoft to care if they do (in order to downgrade or whatever).

In China and elsewhere the situation is different, but since the manufacturers are "in on" the piracy, there is no reason they'd enable any firmware features that could hinder users from installing pirated Windows; and even if a future version of Windows requires Secure Boot, that would just be patched out along with the activation checks. (That is, if China ever gets off Windows XP!)

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#25
post #13
post #6

Earlier quoted context omitted.

> loads GRUB As your link mentions, that loader only loads signed kernels (with signed modules). edit: > designed to prevent malware That's the official story. Anybody familiar with Microsoft's history knows they have been trying to lock down the wintel platform for a long time. Creating a "Trusted Computing" environment specifically for DRM purposes has been a goal since "Palladium".

Microsoft is in an impossible position here. Signed kernels are the only way to prevent rootkits. If they don't move in this direction people will complain about insecurity. If they do we get complaints about locking down the platform.

How about letting the owner uploading keys combined with a hardware switch to enable that?

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#26
post #14

I’m not defending Lenovo, I think they broke the law here and should fix their UEFI firmware. However, when you throw away your OEM windows, you’re essentially throwing away money. There’re good laptops that come with Linux or FreeDos preinstalled. They mostly targeted towards enterprise market (who get their Windows through volume licensing). But I find it’s a good thing: besides OS choice I usually get upgradabilit…

> However, when you throw away your OEM windows, you’re essentially throwing away money. Can you actually get these *nix laptops for cheaper than their Windows equivalents? I personally consider Windows these days to be just one more piece of bloatware to remove, but I never got the impression that it added much to the bottom line cost.

That's an error if you want Linux [0] to work on client hardware.

Manufacturers pay the distributions to do hardware enablement if they think there is a customer for the OS on their hardware: alternative OS users are invisible if they buy Windows laptops. Every quarter when the distributions meet with the manufacturers the main topic of conversation is how many units shipped with their OS - this guides investment.

Furthermore, manufacturers are the main way that other parts of the ecosystem learn about demand for an OS. As a Linux distribution, if you can't get Intel to give support for a chipset then the main thing you do is phone up HP/Dell/Lenovo etc and get them to convince Intel for you. That's not going to happen if the manufacturer doesn't know that there are client side Linux users.

[0] I don't know about the hardware enablement story for alternatives like *BSD

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#27

What is Lenovo's incentive for DRM'ing their bootloader?

Secure Boot is designed to prevent malware from tampering with the BIOS by verifying bootloader (and sometimes kernel-mode driver) signatures. In this case, it looks like Lenovo either accidentally or intentionally borked the implementation of Secure Boot, because you are supposed to be able to turn it off when using non-Microsoft operating systems. FWIW, I believe Fedora supports Secure Boot by signing a static boot…

Shouldn't laptop manufacturers go the extra mile to help people install alternative operating systems on their laptops ? If these operating systems provide additional value to consumers, it makes their product ( the laptops ) more valuable. These manufacturers do not exist solely to make money for Microsoft.

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#28

Earlier quoted context omitted.

Secure Boot is designed to prevent malware from tampering with the BIOS by verifying bootloader (and sometimes kernel-mode driver) signatures. In this case, it looks like Lenovo either accidentally or intentionally borked the implementation of Secure Boot, because you are supposed to be able to turn it off when using non-Microsoft operating systems. FWIW, I believe Fedora supports Secure Boot by signing a static boot…

Shouldn't laptop manufacturers go the extra mile to help people install alternative operating systems on their laptops ? If these operating systems provide additional value to consumers, it makes their product ( the laptops ) more valuable. These manufacturers do not exist solely to make money for Microsoft.

> These manufacturers do not exist solely to make money for Microsoft.

These manufacturers do primarily exist to make money for Microsoft. Their margins are stupidly low, sometimes even negative, and yet Microsoft always enjoys very, very healthy margins on Windows itself.

If the industry stopped racing to the bottom they'd be fine. Until then they need the Microsoft marketing money they get to survive.

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#29
post #7

There's a collective of quixotic Mexican software developers and users that is quite active. I wonder why is it that FSF's philosophy with its exhortation to viciously defend freedom resonates so well in some parts of Mexico. It was those groups, which congregate on the Hackmitin[1], Hacklab Autónomo[2] and Rancho Electrónico[3] that helped Jacobo Nájera with his legal proceedings against Secure Boot. I went a couple…

> The whole "security" thing is a sideshow; the real goal here with "Secure" Boot is to make it harder to install unlicensed copies of Windows.

This is an utterly ridiculous conspiracy theory with zero connection to the reality.

Not only does Secure boot not affect someone trying to install a pirated copy of Windows, but it singlehandedly does more against malware than the entire AV industry ever.

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#30
post #21
post #6

Earlier quoted context omitted.

> loads GRUB As your link mentions, that loader only loads signed kernels (with signed modules). edit: > designed to prevent malware That's the official story. Anybody familiar with Microsoft's history knows they have been trying to lock down the wintel platform for a long time. Creating a "Trusted Computing" environment specifically for DRM purposes has been a goal since "Palladium".

I thought twice about responding to this. I worked on Palladium from very early days in 2002 through renaming to NGSCB and the eventual shutdown/transition of the project to ship BitLocker in Vista The team never saw DRM as being an interesting use case. Remember that the Darknet paper [1] was written by the Palladium architects and product manager. The team fully understood that DRM wasn't an effective use of a secu…

Interesting; I stand corrected. Thank you for responding!
Post reply on HN