UEFI and Secure Boot: The Hell I Went Through
prismdragon.wordpress.com
prismdragon.wordpress.com
If you need a workstation, more specifically a linux workstation, maybe you should have bought a workstation. Like HP z-series which support (and some models even ship with) Linux.
> I did a first boot, and had an error come up that it couldn’t boot to Windows. “Well… Recovery media time!”
What error? If even first boot fails, I'd suspect hardware fault, which would make the whole post moot. Instead of trying to force Fedora on a machine that doesn't boot in the first place, more sensible solution would be to return the machine to the store.
> “Feature Byte” The system was using Secure Boot
False conclusion. Idk what "Feature Byte" stuff is, but it seems completely unrelated to UEFI and SecureBoot. Quick googling even reveals that some HP BIOS have Feature Bytes too.
> Yes, I’m aware that OEMs are supposed to give an option to turn it off, but when has this ever happened?
Is there actually any SecureBoot enabled systems out there which do not allow disabling SB?
> All this said, I refuse to support UEFI until some real standards are put into place and enforced. I’ll take something like OpenBIOS, but NOT UEFI
The UEFI standard is clearly at fault here, right? And the Windows Logo program is exactly about laying out standards and enforcing them. I'd also note that UEFI and the MS stuff are independent entities. UEFI is an industry standard, and predates all this secure boot fuss by years.
This blog post is full of plain old FUD, and it's sad that open source advocates spread such stuff. Especially in matters of such importance imho posts like this only cloud the real issues and erodes the credibility of FOSS camp.
It doesn't bode well for the future. Maybe there will be some kind of online cataclysm that will end this madness. Who knows? In the meantime, check that your motherboard has legacy boot options. Or just don't upgrade to Windows 8 and vote with your wallet
Secure Boot, when enabled, will not let you boot anything that isn't signed, including removable media. Fedora 17 isn't signed so SB wasn't enabled.
Expecting GRUB2 to work when your Windows bootloader didn't work isn't logical.
Like it or not PC's are designed for Windows. If Windows doesn't work on it, take it back. Very likely the harddrive had problems, this would explain it not booting and the install running slow as it retried when getting errors from the drive.
Also, since he is not just a prophet of doom but has spend a major part of his life trying to turn the tide, creating and inspiring stuff most of us have profited from, he deserves a hell of a lot more respect than he usually gets.
You might find that Ivan Illich might be worth reading for a wider view (Illich wrote before PCs let alone the Internet).
This really is getting out of hand Microsoft - this stupidity that Secure Boot is - it isn't solving any real problem for the user. It is only creating nuisance.
Still though this whole thing is nonsensical - wonder if they were waiting for the antitrust era oversight to end (May 2011) before trying this schtick.
That's the whole purpose of it - creating enough nuisance so that average Joe can't get out of Windows ecosystem. Each OEM will implement the disabling option in their own obscure way, and some of them will even fail to work properly. I remember when I needed one boot pendrive for each of my computers.
And what makes you think they give two shits about what users want? Anyone who has been paying any attention at all to the computer industry for the last three decades would have learned by now that Microsoft doesn't serve "users"; they have always been the "safe" choice for "business" ("no one ever got fired for choosing Microsoft!"), and recently they have become dogs in the laps of the crony capitalist cartels of the entertainment industry. Microsoft has always been about anti-competition and locking the user to their platform; this recent offensive of "secure boot" just gives a bonus of the DRM that the entertainment racketeers so badly want.
Not "supposed to". They must. Why would OEMs waste their time implementing Secure Boot for the logo program, and then disqualify themselves by hiding the option to disable it?
I just ranted about this happening in the Apple community; don't think it doesn't happen everywhere [1]. It's toxic, and I really wish there was more critical thinking going on.
For now, this doesn't really matter, but the situation may change if/when Windows on ARM becomes a serious platform.
Yet it's completely accepted on the market leader's products. Funny how that works.
The reason for this particular fooferaw, I think, is the misconception that this will apply to x86.
It was my goal to clear that up, not to specifically endorse Microsoft-bashing.
What's stopping them from pushing for that once secure boot is widespread enough?
You do remember their lawsuit that spanned almost the entirety of the 90's, right? The lawsuit that cost them hundreds of millions and almost saw Microsoft split into two companies? That's what would prevent it. If they tried it again, the company would be shut down faster than you can say "But Apple does it too!"
The fact that is in front of us right now is that Microsoft is requiring that it can be turned off. Requiring. So telling people that Microsoft won't let you turn it off goes so far beyond a flat-out, bald-faced lie: it becomes flagrant and malicious disinformation designed to scare people into staying away from a product, to scare them into continuing to spread this disinformation. Even you saying "but it could happen in the future!" is complete garbage. It's not relevant. There's no way to know what Microsoft will do in the future, so spreading rumors now based on pure speculation and fantasy... no, this goes beyond spreading rumors about the future, you're applying future speculation to what they're doing now, pretending that what you're fantasizing about is actually happening as we speak. It's not.
You're not thinking critically, you're making wild accusations and presenting them as reality. In short, you're perpetuating fear, uncertainty, and doubt. This argument completely blows my mind.
The way it's currently done just looks like a setup for making a claim on windows 9 release "see, there's nothing wrong with enforcing it on ARM, we're going to enforce it on x86 too".
Market opportunity for people who assemble Linux capable PCs?
Market opportunity for people selling reliable slightly older technology laptops? Plenty of sellers on UK ebay (their laptops are ex-corporate so a bit too old for here I suppose)
http://www.h-online.com/open/news/item/Fedora-18-to-support-...
Opportunity for followup post trying a beta/testing install of Fedora 18?
Bullshit. I'll provide my reason supporting my statement: they require that it can be turned off. Now you provide your reasons.
FWIW.