Asahi Linux Add Support for the Broadcom FullMAC WiFi Chips Used on Apple T2/M1
twitter.com
twitter.com
https://lore.kernel.org/linux-acpi/20211226153624.162281-1-m...
> As you might expect, the firmware for these machines is not available
> under a redistributable license; however, every owner of one of these
> machines is implicitly licensed to posess the firmware, and the OS
> packages containing it are available under well-known URLs on Apple's
> CDN with no authentication.
>
> Our plan to support this is to propose a platform firmware mechanism,
> where platforms can provide a firmware package in the EFI system
> partition along with a manifest, and distros will extract it to
> /lib/firmware on boot or otherwise make it available to the kernel.
>
> Then, on M1 platforms, our install script, which performs all the
> bootloader installation steps required to run Linux on these machines in
> the first place, will also take care of copying the firmware from the
> base macOS image to the EFI partition. On T2 platforms, we'll provide an
> analogous script that users can manually run prior to a normal EFI Linux
> installation to just grab the firmware from /usr/share/firmware/wifi in
> the running macOS.
You have the implicit right to the proper operation of the hardware you purchased. Such rights historically trump the rights of IP holders upon conflict.
There is no reason for us to play fast and loose with copyright law; our installer just downloads everything it needs (which is a lot more than just WiFi firmware) from their CDN and uses it. No redistribution required. There is literally zero impact to users, and nothing to be gained from redistributing.
For people who want to do fully offline installs, we'll provide a way of using a OS image on local media instead (though in that case users will have to download a complete OS image; when you use our script online, it does partial HTTP fetches and only grabs what it needs, so you only end up downloading ~1GB instead of a full 15+GB macOS image - though we could provide a script to download only the required bits and re-pack it as one file anyway...)
What happens when those CDNs go down? A mad scramble to find out who still has the files? This same thing keeps happening and nobody pushes back. There may be zero impact to users now but accepting this hostage situation is ridiculous.
Thankfully, that hasn't happened for any platforms and you can still download the OS for and perform authorization for all Apple devices going back to the iPhone 2G (3GS for auth, since it's the first one with that requirement), so I'm not too worried.
Here's the latest firmware available for the original iPhone:
http://appldnld.apple.com.edgesuite.net/content.info.apple.c...
And you can download not just the latest version, but all prior versions, for every device, ever released. https://ipsw.me/ has all the links.
Of course, this is merely a practical argument; Apple have shown that they will continue to support all their old devices as far as this process is concerned, but this cannot be proven. If you're the kind of person who worries about any and all external dependencies and doesn't want to trust the vendor for anything, then I would advise you to not buy one of these machines; they are not for you. These machines value a rather sophisticated security paradigm (that has real benefits for users, especially the average user) over not having vendor dependencies; that is a trade-off that you need to be aware of.
I expect if Apple ever decide to retire the signing server for older platforms, they'll just publish a signed global ticket for them to remove the phone home dependency. It would be stupid not to do that. And plenty of people have OS images lying around. Just download one and keep it safe if you're worried about that. Though you'd still be screwed if you lose your Flash contents including platform config data, but nothing Apple does can save you from that; at that point you'd better have a backup yourself, since you wouldn't be able to rely on Apple's service to fetch their copy.
(Please don't reply with a tirade about freedom and evil vendors and boiling frogs; I'm really, really tired of those, and the people who write them invariably refuse to listen to any explanation about the security rationale behind why things are this way, and I've given up trying to explain it to them. Please just go buy a Pinebook instead.)
>and the people who write them invariably refuse to listen to any explanation ...
Actually I was listening very carefully and I was ready to continue listening even after you've took discussion toward being personal and disrespectful ( let's assume by mistake/misunderstanding)[1]. Due to my forgiving nature I even tried not to take personally what you wrote because all people can make mistakes with the hope that you can also forgive to other people certain mistakes and keep being respectful. I even apologized in details for my possible misuse of English words to make it easier for you to continue[2].
Still you didn't provide your arguments even after apology and it's hard to listen when arguments are not delivered.
I prefer to give people chance to fix their possible mistake before attacking them and I hope you can do the same. I hope that I didn't waste my time second time.
[1]https://news.ycombinator.com/item?id=29691816 [2]https://news.ycombinator.com/item?id=29693634
Can you please just drop it? You didn't listen with your original reply; nothing I say will change your opinion. I don't need more gratuitous comparisons to dictatorships and ad hominem attacks, thanks. It's always like this whenever I try to explain things calmly to people like you.