Live data from Hacker News

In Defense of Free Software: My Case Against Lenovo in Mexico

globalvoices.org

1–10 of 33 posts

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#5

What is Lenovo's incentive for DRM'ing their bootloader?

Secure Boot is designed to prevent malware from tampering with the BIOS by verifying bootloader (and sometimes kernel-mode driver) signatures.

In this case, it looks like Lenovo either accidentally or intentionally borked the implementation of Secure Boot, because you are supposed to be able to turn it off when using non-Microsoft operating systems.

FWIW, I believe Fedora supports Secure Boot by signing a static bootloader ("shim") that loads GRUB after checking its signature[0].

[0] http://mjg59.dreamwidth.org/12368.html

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#6

What is Lenovo's incentive for DRM'ing their bootloader?

Secure Boot is designed to prevent malware from tampering with the BIOS by verifying bootloader (and sometimes kernel-mode driver) signatures. In this case, it looks like Lenovo either accidentally or intentionally borked the implementation of Secure Boot, because you are supposed to be able to turn it off when using non-Microsoft operating systems. FWIW, I believe Fedora supports Secure Boot by signing a static boot…

> loads GRUB

As your link mentions, that loader only loads signed kernels (with signed modules).

edit:

> designed to prevent malware

That's the official story. Anybody familiar with Microsoft's history knows they have been trying to lock down the wintel platform for a long time. Creating a "Trusted Computing" environment specifically for DRM purposes has been a goal since "Palladium".

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#7
There's a collective of quixotic Mexican software developers and users that is quite active. I wonder why is it that FSF's philosophy with its exhortation to viciously defend freedom resonates so well in some parts of Mexico. It was those groups, which congregate on the Hackmitin[1], Hacklab Autónomo[2] and Rancho Electrónico[3] that helped Jacobo Nájera with his legal proceedings against Secure Boot.

I went a couple of times to the Hacklab. It's an interesting place. At the time, it looked like they were squatting in an abandoned building and they looked like Hollywood hacker stereotypes. If it weren't for the proliferation of hardware with Debian and Trisquel logos, their appearance make you would think these were just ordinary anarchist punks. In a way, that's what they are, except they are technoanarchist punks, and obviously not completely anarchist as they know how to work with the legal system. They were very left-leaning, distrustful of all corporations, completely aligned with FSF philosophy; radical, feminist, and fiercely protective of their rights.

I rather miss that scene. I haven't found quite something like it here in Canada.

I hope Nájera manages to get somewhere, but it seems like a hopeless fight against MSFT, the one that is really ensuring that installing the OS of your choice is impossible. The whole "security" thing is a sideshow; the real goal here with "Secure" Boot is to make it harder to install unlicensed copies of Windows.

---

[1] http://hackmitin.espora.org/

("mitin" in Spanish is from English "meeting" but has left-leaning political connotations such as protests and marches.)

[2] http://hacklab.espora.org/

[3] http://ranchoelectronico.org/

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#9
post #6

Earlier quoted context omitted.

Secure Boot is designed to prevent malware from tampering with the BIOS by verifying bootloader (and sometimes kernel-mode driver) signatures. In this case, it looks like Lenovo either accidentally or intentionally borked the implementation of Secure Boot, because you are supposed to be able to turn it off when using non-Microsoft operating systems. FWIW, I believe Fedora supports Secure Boot by signing a static boot…

> loads GRUB As your link mentions, that loader only loads signed kernels (with signed modules). edit: > designed to prevent malware That's the official story. Anybody familiar with Microsoft's history knows they have been trying to lock down the wintel platform for a long time. Creating a "Trusted Computing" environment specifically for DRM purposes has been a goal since "Palladium".

> That's the official story. Anybody familiar with Microsoft's history knows they have been trying to lock down the wintel platform for a long time. Creating a "Trusted Computing" environment specifically for DRM purposes has been a goal since "Palladium".

Are you implying Microsoft encouraged Lenovo to disable the firmware toggle for Secure Boot? Even though it's only defective on one model of one manufacturer's computer, and literally any other computer (including the Surface x86 line) can toggle it?

I don't see why they would maliciously introduce Secure Boot and only sabotage it on a very small number of computers.

Re: In Defense of Free Software: My Case Against Lenovo in Mexico

#10
I’m not defending Lenovo, I think they broke the law here and should fix their UEFI firmware.

However, when you throw away your OEM windows, you’re essentially throwing away money.

There’re good laptops that come with Linux or FreeDos preinstalled.

They mostly targeted towards enterprise market (who get their Windows through volume licensing). But I find it’s a good thing: besides OS choice I usually get upgradability, reliability, and reasonable prices (IMO companies are better at tracking their expenses). For example, take a look at HP ProBook series: they are good, include wide range of specs, and if you want to, you can get one without Windows.

Post reply on HN