Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I sent a private e-mail to Neelie Kroes saying that I support the position of HispaLinux and that I regard it as an anticompetitive, exclusionary practice for there to be only microsoft's encryption key by default on all new motherboards, to the exclusion of say the GNU/Linux community's key.

The whole problem is that there is no "GNU/Linux community's key" because no one is stepping up to provide it. The big OEMs had already told Red Hat that they're willing to include the community's keys so I fail to see the "anticompetitive, exclusionary practice". Microsoft does not mandate that only its key should be included by default on all new motherboards. The OEMs are free to include any other keys.



Who do you trust to maintain a GNU/Linux community key? The Free Software Foundation, which takes an extreme position that even excludes Fedora? The Linux Foundation, which talks about compliance with proprietary vendors' requirements? Linus Torvalds, who takes no issue with TiVO?

There is no single vendor I trust with the decision about which distro's bootloaders can be signed. I only trust the distro I am using, and only because I can switch to another distro at will (which I have done three times since I began experimenting with Linux all those years ago). That is the problem with the UEFI design: it does not let me, the user, decide who to trust, unless I am technically adept enough to install custom keys (I personally am, but even a lot of people at the local LUG and 2600 meetups are not).

What we really need a system that allows me to install whatever OS I want, and allows that OS to optionally enable bootloader signing with its own key. I should be able to hit a button while booting up to enable a special "OS installation mode," which will boot from a USB device or a DVD to install an OS. During that process, the OS installer can load keys for bootloader signing. The user should always be able to install the OS of their choice, and should not have to rely on Microsoft or anyone else to "approve" a bootloader, OS, or anything else.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: