Lenovo shipping new laptops that only boot Windows by default
mjg59.dreamwidth.org
mjg59.dreamwidth.org
Hit Enter or F1 at the red Lenovo boot screen, go into the BIOS settings and find the setting and change it.
Until someone confirms that there is no such BIOS setting, there is no story here.
And even then if they have the option, the entire process is designed to make the user feel as uncomfortable as possible while doing it. Disabling perfectly unrelated features (e.g. fast boot), going through Scary Boot Prompts, etc. are NOT acceptable requirements for booting a non-MS OS.
It's not the first time a vendor disables the MS UEFI CA signature by default (e.g. Microsoft itself has done it on ARM _and_ x86 Surfaces).
For the record, Google has also been doing the same for a lot of time now (Scary Boot Prompts if you try to run Linux on bare metal, but all is fine if you run containerized Linux on top of Google's OS). They don't get a free pass from me, either.
T2 Macs had some complications with Linux, but that was due to a lack of support on the Linux side. My understanding is that recent kernels work fine.
There is Windows fast boot and UEFI fast boot, which are two diffent things. Sometimes vendors support only Windows fast boot, and at least then it is perfectly acceptable to force removal of that option.
Also, for example the purpose of secure boot is to prevent modification and changes on boot options and underlying files, which makes it also to be fine to force disabling, until you set new keys for your new OS.
And that's ignoring all the general usability issues like the subpar battery life, the dreadfully terrible state of video playback, the touch screen constantly causing gnome to glitch internal state and get confused, etc...
On my Debian desktop I had a webcam completely take out the USB stack. Like all ports just dead, had to yank the power to reboot. I also had a btrfs array just go read-only for seemingly no reason after restoring from standby, and it wouldn't tell me why. After a reboot all was suddenly fine. Also it took an awfully long time to get that machine working after having been powered off for 3 months. If you go too long without updating, it seems all the package migrations just bitrot and break.
But yeah, year of Linux on the desktop. Any day now.
I run dual monitors on docking station with lots of peripherals.
Its my daily driver. Very happy with it.
Some Ubuntu LTS highlights:
Ubuntu 14: By default, Dell display backlights toggle on/off 30 times a second
Ubuntu 16: By default, BIOS boots broken due to boot files landing in too high of a sector
Ubuntu 18: By default, Solid State boot drives break because /dev/sda was hardcoded
Ubuntu 20: By default, Bluetooth and fans broken. Never fixed. Sleep broken but fixed.
Ubuntu 22: By default, NVidia graphics get 100% screen saturation after install.
"Then don't use Ubuntu"Ubuntu isn't my daily driver. It isn't even a majority of my installs. I'm using it as a benchmark for conservative linux choices because smaller distros tend to be worse, not better. I know this because I daily drive a less popular distro, and I also distro hop for fun, and these all tend to be worse, not better. Besides, many hardware and software vendors target Ubuntu, and "works on Ubuntu but nowhere else" is a very common problem. Across the board, the Linus Tech Tips linux experience is the rule, not the exception. Many desktop linux users just have selective community-enforced amnesia.
Look, I am super thankful for the maintainers. I have gotten so much more value from them then they have asked in payment, but Linux is nowhere near Windows in the "just works" department. That is to be expected, given the price, but the rhetoric has gotten out of line with reality. Desktop linux still has a lot of rough edges and new rough edges appear at a rate that is not converging to 0.
"It works if you buy dedicated Linux hardware."
Yes. This is how you make it work.
I had my share of problems but none as bad as the ones you wrote. Currently there are two problems
1. Poweroff is reboot, so I press the shutdown button when the BIOS starts. It has been like that for ages through more than one LTS but I shutdown very few times per year.
2. The fn brightness control keys don't work so I made two hotkeys to run a X11 brightness control program that steps up or down the backlighting by 5 points, 0 to 100. This is probably on NVidia's driver.
Everything else is fine and that's great considering that probably HP never tested these laptops with Ubuntu.
Two nuisances is still better than the alternatives: the very same hardware with Windows or an Apple machine with OSX (I can't stand the UI.)
The biggest issue is that on the Mac side, it is really easy to get the OS and the optimal hardware together, and know that it "just works". For Linux, we have several small vendors, and a couple larger ones, that have Linux-advertised hardware, but most of the Linux optimal hardware doesn't advertise itself as Linux (Android phones/tablets, Chrome OS, etc).
So, it is not that linux does not work with a lot of consumer hardware. It's that most consumer hardware cannot be bothered to work with linux and invests itself in working with windows.
There is also a factor in-kernel vs out-of-kernel drivers.
"It works if you buy dedicated Linux hardware."
Yes. This is how you make it work.
You buried the lede.It doesn't seem much different from the F12 menu that lets you select an alternate boot device.
How exactly does this mean they "prevent booting alternative operating systems"?
Of course this is a mechanism to further advertise locking down general computing and nothing else. It is not new and security is a bad excuse.
That's incorrect. There is malware out there that can only work if you don't have Secure Boot enabled. The setting OP didn't disable, Device Guard, prevents the abuse of 3rd party signed bootloaders, another attack vector basically.
This is a step up for most people that ever stay on Windows and doesn't affect the slightest someone who wants to install Linux, they still have to boot from an external device or wish to change a few UEFI settings.
> Of course this is a mechanism to further advertise locking down general computing and nothing else. It is not new and security is a bad excuse.
Framing Secure Boot as some kind of Secure Boogeyman is not conducive, brings the discussion into tinfoil scenarios without any potential practical outcome (nobody is going to remove SB or DG).
As long as Linux vendors or people can get or enroll their own keys and disable any potential presets, it's a step up in security for everyone.
Giving the user more hops to jump through, when they want to try alternate (signed!) operating systems? Like, you have nice encrypted disk here, are you willing to lose it, when you flip the setting?
it's a very dangerous attack vector.
EDIT: writing from a Lenovo laptop where Linux it's the sole OS installed.
Allowing Linux to boot was a hundred times simpler than allowing DOOM to run on my 486 with 4MB of RAM.
This is defense-in-depth level stuff.
At this rate it prevents someone from booting in a 'malicious' OS quickly.
> [...] the firmware defaults to not trusting bootloaders or drivers signed with the Microsoft 3rd Party UEFI CA key.
The whole point of secure boot was that there is a known set of "good actors" who are trusted by default, so that you can boot 1. Windows 2. common Linux distros - without any fuss, and 3. Any other system - with a few extra steps to prove you know what you're doing.
They've de-ranked the set #2 and threw it in the bag with #3, which doesn't really do much at all to improve security, but it does inconvenience and disincentivise the users from using a Linux distro on this hardware.
It's most likely an honest mistake, a sign of incompetence, or a dick move. Write them an angry letter and carry on.
Well no, it's not Lenovo really, it's Microsoft and its Device Guard / Secured Core that has done so. You can disable that just as easily as you can boot from an USB stick.
[1] Modern TPMs have 24 PCRs that can be used to measure different parts of the boot process, but the general expectation is that only 0-7 will be used by the firmware. On UEFI systems, PCR 7 contains information about what the platform's secure boot policy is, and which keys were used to verify the boot process. Booting something signed with a different key will result in PCR 7 having a different value, which is something that can be detected by tying encryption keys to specific PCR values.
Key quote here; a good practice is to never trust e.g. USB sticks.
What's the news here?
The reality is: installing a replacement OS post-sale is never, ever going to be the way to grow linux marketshare, if that's what you care about (it shouldn't be, but some people live-and-breathe year of the linux desktop so whatever, you do you). Its a lot more important that it ship with the hardware, and extreme attention to detail has gone into making sure it works well with that hardware. Certainly, some vendors already do this. Moreover, I'd also argue its even more important that that hardware be modern and desirable; the only vendor I've seen pull this off is Dell (genuinely sorry, because I love what Framework/System76 are doing, but their machines look like branded OEM Clevos, because they probably are, or were in the recent past. I support them; I own a Framework; but only because I want them to do better, not because what they're doing today is enough).
[1] UEFI GUIs are an improvement, but they still have 95% of the same usability issues of text-based BIOS: 1000+ settings with no hint what each of them means, XTLAs only understandable by hardware+kernel experts, unfamiliar interaction patterns like not having a big friendly button to just save and reboot, and so on.
Linux is not an OS for the average user, it's for tech savvy geeks and an extremely small subset of those people too.
Nothing wrong with what Lenovo is doing here, there just are no other OS in the market.
In a nutshell, this is bad no matter how you look at it.
What you think as "not tech knowledge" is a serious skill that is severely lacking in billions of people.
The user needs the install medium, they need to get it, download it, create it, get a USB or blank CD/DVD, etc. They need to either have the courage (or curiosity or aloofness or determination) to modify their computer on such a drastic level, they need to understand abstract concepts, follow a written manual that uses those concepts, they need to recognize those abstract concepts as they are implemented on the computer they are currently tinkering with, and so on, and so on.
> In a nutshell, this is bad no matter how you look at it.
True, but it's bad because the whole "personal computing" thing is bad. This detail is largely irrelevant.
I was 12 when I first installed linux and barely knew what I was doing. I easily would have given up if I couldn't figure out that my machine had a secret hidden bios setting. I learned a ton from that experience, that easily could have been missed if I'd happened to own one of these anti-competitive machines.
Installing a user-friendly linux distro has gotten quite simple too, requiring only a couple simple steps using some clean tools. Modifying hidden BIOS settings is a significantly more complicated leap than the plug-and-play imaging tools available today.
Asking her to install Ubuntu herself, though, would be another matter entirely. Installing any OS (including Windows, since it's about as complex as Ubuntu these days) is way beyond the skill level needed to actually use it.
Only on hacker news would people be so far removed from real life that they would say 'Ubuntu is for the average user'
And as you said, most people would not be able to install it let alone the fact they likely have no idea what it is, so in relation to this post about consumer lenovo laptops, it's irrelevant and doesn't matter to the vast vast majority of people.
the average user does not install operating systems. linux is perfectly fine for the average user if it comes preinstalled.
I recently installed Linux Mint and Windows 10. Linux was faster and easier to install, and has a friendlier UI. Have you seen the Windows start menu recently? It's cluttered with crap: I couldn't figure out how to do basic things with it, even searching was hard. You might do everything through the command line, but that's not the only way, the GUI does work.
Software's a different story, though a lot of things are online these days.
Entering the recovery key is enough but the problem is my work uses software to rotate the recovery key and the last time the stored key didn't work. Probably it was just rotated but not updated in the system yet. So I had to restore fully and I removed Linux.
Good to know, thanks! To be honest in this day & age of virtualisation I hardly ever dual-boot anymore.
For example :
https://docs.microsoft.com/en-us/windows/win32/sysinfo/acces...
https://wikileaks.org/ciav7p1/cms/page_26968097.html
https://wiki.archlinux.org/title/Unified_Extensible_Firmware...
There is also NtSetBootEntryOrder() in Windows ntddl
I tend to see them as the easiest path when looking for a good opensource OS compatibility as many Linux and BSD devs are using them.
They're just locking people and making it difficult for them to grow and explore other OS such as Linux.
That's a bad attitude!
And this isn’t Evil Microsoft dictating what vendors can do. I can install Linux on my Surface device.
If the PC laptop would boot by default, off of any random USB plugged into the laptop, then HN mob would (rightfully) cry that this is a major PC security issues and that's how grandma could be pwned and get scammed, unlike a super-secure M1 MacBook which won't boot any other foreign OS by default without major hoop jumping.
If the PC laptop doesn't boot by default off of any random USB drive (just like a Mac), requiring the user to go into the BIOS and change this setting first, then it must be malice from Microsoft and the PC OEMs to restrict user freedom and destroy Linux's 2,43% PC market share.
It is ridiculous that people still downplaying Linux's PC market share when the latest version of Windows ships NOT ONE but TWO Linux emulators/virtualizers BOTH designed to allow you to run Linux binaries (desktop & Android) under Windows in the most user-friendly way possible.
Obviously this is because no one Windows customer cares about Linux or Linux software.
AT THE SAME TIME they take steps (and everyday larger steps) to prevent booting the same Linux on bare hardware, making their virtualization options more attractive for both the regular user and the advanced user.
At this point we're way past the "assume incompetence" point.
Mate, you're contradicting yourself here more than you are contradicting me. WSL and Linux as a main desktop OS are two completely different things, and nobody is downplaying Linux's desktop market share, which is <3% no matter how you try to spin it, those are the statistics.
How can anyone argue with this that MS couldn't care less about Linux's market share ?
With these changes, MS "accidentally" makes running non-MS OSes harder, and this includes both Android and desktop Linux, OSes for which they have as per the above shown an interest in capturing their market share. "Accidentally", the fact they become harder to run natively also makes their new virtualization features more attractive for users.
The "accidentally" part is what I don't believe.
One weird trick to ruin your day, surely.
Edit: Looks like Windows has changed since I left it, please disregard this comment, thank you. The comment is left intact for context correctness.
You just have to enter your recovery key, that's it.
> If you want security here you're paying attention to the values measured into the TPM, and thanks to Microsoft's own specification for measurements made into PCR 7, switching from booting Windows to booting something signed with the 3rd party signing key will change the measurements and invalidate any sealed secrets.
This is a new "feature" of Pluton Coprocessor.
At worst you'll have to enter a Bitlocker recovery key...
Also, for some people, they will trade-off the possibility of data loss as long as the data can be reliably destroyed if the data falls into the wrong hands. Maybe not for you, but it's there for enterprise.
You don't have to use TPM-backed BL if you don't want to.
The war on general-purpose computing is well underway, and I fear we'll lose it. The billions of already completely locked down computers (e.g. every iOS device) does prove that people just don't care, and many (including people here!) will even defend it that they prefer it that way. Eventually we won't have a choice.
And then someone like Microsoft or whoever will buy their way in, corrupt a bunch of xbox users into thinking they're the good guys again, and we'll start again.
https://psref.lenovo.com/Product/ThinkPad_Z13_Gen_1?tab=spec
The UI even warns about not being able to use other OSs when it's enabled.
Linux is way too big to attack on servers today, but why WSL + this shenanigans feel so aligned?
Please feel free to counter. I'm not trying to start a fight here.
WSL is part of Microsoft's internal push to embrace open source. Its feature development.
Source: I work on the windows kernel and have met people who work/ed on WSL.
I have an honest question: How Microsoft is planning to restore trust in open source / free software circles?
We have seen pretty horrific things back in the day, and some of us can't trust you, even if we want, and some moves still relight this fire instantly.
I want a more friendlier computing environment overall, regardless of the OS we use, and want to be able to interop with other OSes on many levels (protocols, hardware, developers of said OS).
Does Microsoft has a plan for this?
Because Opening VSCode and slowly putting into proprietary domain & using GPL code in Copilot doesn't inspire trust, to be honest.
What you can see from the outside that this is a move of the Visual Studio management to preserve their revenue stream (against which they get bonus etc). It is just stupid incentive management with the idea that the developer division is a profit center (which it should not .. in favor of Azure).
This secure boot topic is IMHO related to some product manager thinking that Windows laptop should be protected walled gardens like Apple devices are.
They're not planning to, not really. FAANG + MS are so big that at this point they stopped caring about Open Source and Free Software. The licenses are intentionally permissive that every tool can be used internally if they need it (Linux, bash, etc) plus even more permissive licenses like MIT can be used in commercial products. With web services even GPL can be used in their commercial cloud services.
They control a huge chunk of Open Source anyway through their contributors.
Plus the level they compete at is so far from Open Source that Open Source basically doesn't matter. It's all services and clouds now.
Open Source had its moment circa 2005, now it's just asphalt. Yeah, we use it everyday, but nobody writes home about it.
And regular users don't care.
WSL is part of Microsoft's push to eliminate Linux. Microsoft has always weaponized support. With one hand they support Linux binaries and with the other they force hardware makers to disallow Linux.
Source: I work on the Linux kernel and met people who work on Linux kernel.
You'll lose these secrets and keys, forever. They may be private keys, decryption tokens and more.
You may not be able to regenerate them and get everything back.
Edit: Windows (license) keys are not in the TPM apparently, my bad, sorry. Keeping the above text for context correctness.
BitLocker uses TPM to store HDD encryption keys.
I suppose you need it to resize the partition without deleting your encrypted Windows data, at least.
I have said may because I'm not using Windows on my systems for the last 20 years. IF they're not doing that, it's great, honestly.
I don't claim to be 100% correct, and kindly pointing that I'm wrong is enough to update my wrinkly muscle.
iirc whatever cert grub was using has been blacklisted by Lenovo because of some recent security issue in grub (I can't find the details right now).
Whatever your stance on Secure Boot, this increases friction and raises the tech bar for people to install other OSes. I imagine that even a "power" user wanting to try Linux would be very confused and would probably give up after not being able to boot from USB.
So they don't trust software signed by Microsoft, but they trust an OS made by Microsoft?
Fedora, Ubuntu, and rEFInd were some of the first to get their own certs.
So it's more "They don't trust who microsoft trusts"
They do whatever Microsoft tells them to do, because the alternative is being forced to pay extra $200 per laptop sold.
I don't mean to merely refer to this particular issue/non-issue. I refer to the entire industry pre-loading Microsoft Windows on every new computer as IF this were the desire of everyone in the world.
I'm not suggesting that there isn't a market for Windows, I'm suggesting that an industry-wide forced-Windows-ONLY world is bad for the market, bad for consumers, and probably bad for OEMs... If it's some shady Microsoft OEM contract FORCING this to be the case, let's see an example. Didn't anyone challenge it?
Why don't Dell or Lenovo sell 10-20% Linux laptop preloads? Surely one can understand that developers and plenty of other users require Linux not Windows, right?
Why are Linux preloads expensive and odd? Why are more OEMs not ALSO selling Linux preloads?
So annoying!
This stuff largely doesn't exist for Linux, so they're missing out on this profit for any Linux preloads. It's also why you see Linux preloads mostly done by more boutique PC builders -- they've already charged a reasonable premium on the build.
Realistically, the reason OEMs pre-install Windows has nothing to do with the storage space or even with the logistics for developing a "choose your os" program. It's that they get extra revenue from bloatware contracts.
Boutique PC or even laptop manufacturers are more than happy to provide Linux. They do not make enough machines to be viable for bloatware contracts, so for them it is often instead more profitable to get extra buyers by catering to niche user bases like Linux users.
and as a tech person, i would not care which linux distribution they choose. let the OEM pick one and use that as their differentiation point, if that's of any worth. ubuntu, fedora, suse, pop! os, whatever. it doesn't really matter, as long as there is an alternative to windows.
As an anecdote, every developer that I know and I personally use Windows or Mac laptops and desktops. 1 guy in the group has a linux setup, but primarily uses Windows or Mac. While most of us have installed Linux on a device at some point, none of us use it as our daily driver. I'm talking about a network of roughly 100 devs that worked together or are a friend of a friend that chat on Slack daily. Yes, it is a small sample size, but it is relatively representative of what I've seen from devs at all of my previous companies over a 14 year software dev/engineering career.
This is a Secured Core / Device Guard requirement, different things and still optional.
> Trying to boot Linux from a USB stick failed out of the box for no obvious reason, but after further examination the cause became clear - the firmware defaults to not trusting bootloaders or drivers signed with the Microsoft 3rd Party UEFI CA key.
Isn't that precisely what the GP linked to? If it's just a matter of changing a BIOS switch then this is a non-issue imo.
However, navigating the scary BIOS menus, in a foreign language, with technical jargon even I can't always understand (and I do assemble my desktops from parts). Even keeping running Ubuntu (or Fedora or whatever) on a new laptop would probably not happen for many non-technical folks, if this sort of 1990s level dark arts boot time shenanigans were encountered.
At least that's my experience with relatives and friends who need computers for non-technical work or entertainment. Not all, but most have found Linux overall nicer user experience than Windows, so this would be a net negative development. Defaults matter, so this is definitely an issue in my opinion!
RDNA2 is the most powerful open source friendly GPU out there.
This has been a long time coming for us Linux fans.
Then there's stuff like this: https://unix.stackexchange.com/questions/692552/no-linux-wil...
Which is why I never upgrade BIOS.
Anyone know the obvious replacement offhand? Ryzen + runs Linux.
edit: article says 'default' a lot, are we talking flash new firmware to get something working or changing a setting like secure boot = off, as they're not really comparable.
They are not available yet, but my SO has a 840 G8 (Intel 11th) and it's a very decent machine.
The latter, you need to change a setting.
But it did take some fiddling with efibootmgr to fully purge the Windows shit.
MS still gets paid for the license, even when it's not used.
I tried installing Ubuntu on it and it was a nightmare. I am pretty sure Lenovo made this laptop so any OS other than Windows will not work well.
I had Ubuntu on dual boot for about 4 months. And I had to fuck with the BIOS at least a dozen times a week because something or other would stop working. Never happened to me on any other laptop I have owned.
Windows is a nightmare for me as a web developer. Ubuntu seems much easier to me and more intuitive somehow. Maybe I'll get an M1 Macbook or build a PC finally... :)
Nobody's perfect, and IBM has plenty to answer for, but Lenovo's been doing shady shit for years.
Thinkpads (T): Decent keyboards, fwupd. Everything else is mediocre to poor.
Dell Precision: About the same as thinkpads.
S76, Starlabs: coreboot, upgradable. Mediocre screen, keyboard, trackpad, audio etc.
Framework: Not enough to differentiate for the price premium.
I have mostly given up on this. If macbooks get gpu linux drivers, I am willing to jump ship.
Although, to be honest, I probably would have given up on Thinkpad/x86 entirely if they didn't offer AMD, because in my experience Intel mobile processors are terrible for pro work. I got so fed up with my T480s i7 thermal throttling at pretty much any task that I gave it away.
I would say, overall, this is an excellent machine for doing work and build quality is excellent. It's a shame that Lenovo have such dubious ethical standards.
For some reason, people on HN praise Lenovo for Linux compatibility, but in my experience it is quite a bad experience. Yet, every time I bring up this subject, there is someone commenting about how their T430 runs just fine on Linux. Newsflash: the T-series is a 20(!) year old laptop, build by IBM.
Nowadays, the whole 'Linux compatible' thing with Lenovo seems like a marketing afterthought. My X1E is now a couple years old, and yet nobody at Lenovo bothered to provide any fixes for basic stuff like the ACPI driver.
Repairable, upgradable, open and user-tinkering friendly. What is your requirement?
"After setting these two items, on the lowest brightness idle you will see the CPU hit C8 states on the second tab of powertop and the overall usage be roughly 2.5W if you have a single DIMM. Without ASPM enabled, the power usage will be between 3-4W."
Hanging around the Framework forums https://community.frame.work/ made me feel a lot more comfortable w/ them and I put in a pre-order for a DIY barebones system. To me the price difference didn't seem too bad (I have my own 64GB DDR4-3200 and 2TB PCIe 4.0 M.2s already).
Even if there's a premium, it's a bit weird to argue against the lack of "differentiation" since not another laptop manufacturer offers a parts store like https://frame.work/marketplace or the ability/support to swap or build your own expansion cards.
https://frame.work/marketplace/expansion-cards
https://community.frame.work/c/developer-program/85
Maybe it doesn't matter to you or others, but it's a heck of a unique differentiator IMO.
If they don't care about user's freedom of choice and wants to lock them into that M$ thing, then i'll simply won't care about them either!
If people want a general purpose PC that runs OSs other than Microsoft's, they should buy their hardware from a 3rd-party company that isn't Microsoft, who explicitly make a point of supporting other OSs.
/s
And as others have said, as long as you can enroll your own keys this isn't really a bad thing. It improves security by default for the default OS shipped with the device. You have to go away from the defaults to use Linux anyways, so one more toggle isn't going to kill anyone.
I know the post is about the Z-series. Perhaps somebody already knows... It seems the AMD-based T14 Gen3 Thinkpads actually don't support Thunderbolt. Some people speculated, it is a firmware matter on AMDs side and will be added in the future but that doesn't sound reassuring at all to me. On the product pictures, you can clearly see the Thunderbolt lightning logos besides the USB-C ports but that doesn't mean anything.
99.9999999% of people will want Windows, if you are going to run a obscure OS then you would choose a machine that runs that best, so just don't buy one of these.
It's not up to hardware OEM's to support or even allow you to install some weird OS.
You can't do whatever you want with most things that you buy and most consumers do not care like most hacker news readers do, people just want something that does the task they bought it for and don't need to tinker with it.
Most people buying a laptop don't really think of the OS is running, they just expect it to be Windows and assume that it is part of computer itself.
Modern Windows instead delivers OEM payloads of various qualities over Windows Update.
But.
Lenovo are between a rock and a hard place. Because today, whether they like it or not, Microsoft does have that leverage. And if Lenovo come out too forcefully in support of Linux (desktop Linux in particular), they risk having Microsoft screw them over. So as much as they might like to start shipping every laptop with Linux pre-installed tomorrow, they really can't. So they have to be selective and strategic about how much they push in that direction.
Source: was a Lenovo employee for a while up through 2019. Little was said about this internally through official channels, but it was all well known. I won't say any more or go into any more detail to avoid the risk of violating some NDA or something that might technically still be in effect or whatever.
How?
https://en.wikipedia.org/wiki/Lenovo
Here it says 2.43% of desktop (non-mobile/tablet) OSes are Linux.
https://gs.statcounter.com/os-market-share/desktop/worldwide
This makes a dent.
You sponsor a company that SUPPORTS dual-booting instead of one that doesn't. That has double the effect of the price of your laptop: one company loses a sale, the other gains one.
Completely out of my hat but I would not be surprised if a good 20%/30% of Thinkpad users are Linux users.
Hard to confirm/infirm though.
The 3rd party UEFI CA key is implemented by the Shim, which is an attack vector. To be certified by default for the shim, the workflow is a github issue [0]. This is not necessarily bad, but a vector for social-engineering and more.
If an attacker is signed by the shim, he can execute trusted code on most machines without problems.
IMO it is better to leave this choice to the user to take this risk and enable the shim. Who installs linux should make this choice consciously
The machine supports Linux. You may have to hop into the firmware settings first.
I am never buying a Lenovo product again.
Framework[0] is looking more and more attractive as my next machine.
[0]: https://frame.work/
A stark contrast with an HP laptop that died after the same daughter spilled sweet tea. There was no option for self-repair. It was possible to open the back lid and save the NVME, and that's pretty much it.
Framework > HP
I like your positioning of her being the recurring root cause :)
Surprisingly it all worked fine, apart from one thing... when attending meetings, they would turn the laptop ion at the start, and after about half an hour, someone would usually ask "Can anyone else smell banana?"
(I can't remember the model, but I think it was a small (like 10-12" or so) HP with an extremely slow, awful hard disk, maybe 1.8").
Framework laptops are looking more and more like the future for Linux users tho.
I doubt their anti-consumer behavior and security claims are some “rogue decision that will be reversed”.
It's a setting that can easily be turned off in the BIOS UI. One could argue that this shouldn't be the default (and I would agree), but in practice this is a none issue.
Not sure if Lenevo actually does care at all.
It's great in many ways but I just am very disappointed in the keyboard. It's really a lot less nice than the Thinkpad keyboards (even the new models). I wouldn't dream of buying Lenovo though.
Disabling UEFI Secure Boot has been step 1 for installing Linux for as long as UEFI had existed, hasn't it?
What exactly is the problem here? I remember doing the same when installing Ubuntu on an ASUS laptop like 10 years ago.
The linked article is dumb, doesn't have any technical details, but has a stupid sensational headline.
Many people did a lot of work to ensure that Linux could be installed on systems with UEFI Secure Boot enabled.
Otherwise it all works on latest XPS and X1 Extreme.
"Note: The official installation image does not support Secure Boot (FS#53864). To successfully boot the installation medium you will need to disable Secure Boot."
https://wiki.archlinux.org/title/Unified_Extensible_Firmware... https://bugs.archlinux.org/task/53864
(Heck, I use my own keys on OpenSUSE even though my distro signs the kernel, because I want to use systemd-boot instead of mokutil since the latter is broken on my motherboard.)
Not the entire picture here, that option is a part of a more holistic set of measures Microsoft calls Device Guard (part of Secured Core)
> it has no real use, except maybe delaying an attacker by a few seconds (and then again, that attacker won't access any data, so…).
It does prevent potential abuse of the signed shim that's not very difficult to get signed by. E.g. nobody can install the signed shim to rootkit a Windows installation.
How would that worked if combined with FDE + TPM ?
Though seeing a recovery screen will not inform you that your bootloader has been tampered with and by entering a recovery key you're basically authorizing the malware to run.
Does this not assume that the bios is not password protected, old dell laptops you need to jump 2 pins on the motherboard to bypass password protected bios and reset it. Don't think this works on newer ones.
Do you also log in to a desktop shell as root? Use "hunter2" as your SSH password? Run every random thing you download from the Internet?
Almost every sensible distro has been supporting secure boot for ages, and on things like Ubuntu it should just work out of the box, without the user ever noticing unless they dug. This is what TFA is complaining about - Lenovo broke it.
This is part of the design problem of secure boot, it only works if everyone updates their trusted key sets and motherboard manufacturers aren't exactly known for their plentiful, easy to install, reliable updates.
Microsoft should obsiously add a setting to enable normal secure boot ("Windows only", "allow Linux", "off") but it's not as if secure boot is much of a safety system for your average Linux user. You can configure a whole secure boot chain in Linux but enforcing that requires a lot of work that's not easily accessible. You'll also need to ensure you hook into the right update functions so your nvidia/AMD proprietary drivers are signed correctly or you won't be able to boot with a working display.
My reaction is because through all the unnecessarily complicated security measures (like SELinux, UAC, Secure Boot, etc) we've taught people to run to google for "Disable Secure $WHATEVER", which is a good indicator that the technology has failed to actually secure anything.
The best security is invisible. OpenBSD gets it. There are no "how to disable pledge" blog posts, because 1. pledge(2)[0] can't be easily disabled (you'd probably need to make a custom patch for the kernel to make the syscall a no-op); 2. there is no user-visible difference to doing do, because as long as the program is doing what it's expected to do, pledge is 100% invisible. This is how e.g. Secure Boot should have worked from day one, for everyone.
I know I'm kinda contradicting my earlier post here, but there's no reason to disable Secure Boot in 2022 any more, even if it failed to provide the security guarantees it promised.
Unless there was so much FUD out there about security and signing this would just be a minor hurdle to learning how to do security properly.
Yes mom&pop will never do it. But frankly. MOM&POP NEVER USED AN UBUNTU DISK TO INSTALL A CUSTOM DISTRO. They just used the laptop as provided by a trusted 3rd party. That will never change.