Secure Boot isn't the only problem facing Linux on Windows 8 hardware
mjg59.dreamwidth.org
mjg59.dreamwidth.org
In fact, i'd go so far as to say that if Microsoft ever actually tried to enforce, it would run them into serious regulatory trouble.
If push came to shove, i'm sure they would take the position that this was a hardware issue, and not their legal intention.
(I completely agree this is a ridiculous situation, and you shouldn't have to agree to anything. But it actually makes for great facts to fight a clickwrap fight on)
How is it legal to _deny_ me full access (defined by the removal of all Microsoft software, something the European Commission has repeatedly upheld) until I have completed some Microsoft-controlled procedure? I don't want Windows on the machine.
Assuming I buy from the 3 largest vendors, excluding Apple, is it not anti-competitive to _lock_ me into it since no other option is offered?
Note: I realize that it may seem redundant to beat this dead horse again, but there's a really good reason so many are upset about Secure Boot. Of course, Microsoft mandates that Secure Boot can be disabled for Win8 logo compliance, which is neatly avoided in this case.
However that is a direct contradiction of the person you are responding to, who mentions that this is a vestige of a certain set of configuration options that are common on Windows 8 machines.
This is not intended, and will likely be patched if enough complaints are heard. Remember they are just requiring that you accept their EULA to boot their OS, denying you access to the firmware was never their intent.
Lovely as it is that Microsoft didn't mean for it to work like this, they're the one who will get the service of process saying "please appear in court and defend your position," if/when this is litigated. That is the kind of complaint they might actually "hear" that would get a response.
I don't care about their good intentions. Get out of my hardware, get out of my life, Microsoft.
Unlikely. With a new person or company it's sporting to give them the benefit of the doubt. With Microsoft if you're still ignoring everything illegal and anti-competitive they do you're on the payroll.
Microsoft specifically modified its products to sabotage a competitor, and lied about it. Microsoft faked evidence to use in Federal court and Bill presented that evidence though it was clearly wrong to anyone who'd used windows.
Why on Earth would anyone give them the benefit of the doubt?
The BSA, which they support, wouldn't give you the benefit of the doubt.
So for example, a contract for sale that said "i give you a copy of windows, and you agree not to marry anyone for 3 years and give me $50" would generally be valid, at least in the US.
Everything else is an argument about whether the contract is "against public policy", or whether the use of that contract constitutes "anticompetitive behavior".
These are two very difficult questions, and in general very fact/doctrinal specific. The Sherman Antitrust act in the US is a very vague piece of law that, if read strictly, outlaws all contracts (Since it outlaws contracts in restraint of trade, but basically all contracts are restraints on trade in one way or another)
Fun fact: Technically you can get 10 years in jail for violating antitrust law.
And Microsoft probably knows this, and would avoid it at all costs. But having an overly broad EULA helps them push around the n00b Linux installer who doesn't know any better.
New-egg should essentially be able to take the trolls to court and part them out for sale, down to their CEO's organs, for trying this in the first place.
System.Fundamentals.Firmware.FirmwareSupportsUSBDevices
System.Fundamentals.Firmware.FirmwareSupportsBootingFromDVDDevice
are required for Windows Logo Certification for both Windows 7 and 8: http://msdn.microsoft.com/en-us/library/windows/hardware/jj1...Doesn't that directly contradict the hypothetical scenario presented in the article? Additionally, there's Windows 8 hardware out there already. Can the author provide no examples of this happening in real life?
The USB controller and USB devices must be fully enumerated when: * Anything other than the Windows Boot Manager is at the top of the system boot order. * A boot next variable has been set to boot to something other than the Windows Boot Manager. * On a system where the Windows Boot Manager is at the top of the list, an error case has been hit, such that the firmware fails over from the Windows Boot Manager to the next item in the list. * Resuming from hibernate, if the system was hibernated when booted from USB. * Firmware Setup is accessed.
ie, it's not required for most normal boots on systems that already have Windows installed. System.Fundamentals.Firmware.FirmwareSupportsBootingFromDVDDevice merely states that the system must support booting from DVD, not that it must attempt to by default. And yes, I've observed this behaviour on real hardware.
[1] I'm assuming that if a working OS install is required to access it, should anything go wrong you're screwed.
I think it only applies to "getting into a USB boot / install environment".
I can't imagine that there would be any cryptographic verification that the boot loader is actually "Windows Boot Manager". This is because the crypto logic is essential to check that the binary is signed by a trusted key. This process would happen before the UEFI thinks about entering the boot loader. It would also not make sense for the crypto section to make any associations between the keys and who signed them (apart from giving the user information).
Still, it seems like a bad spec to create special cases for named hardware. Hopefully, we will arrive at a standard where the OS can signal if the feature should be disabled, or make it a toggleable setting (which, from what I understand of UEFI, the OS can toggle). Unfourtuantly, depending on how strict MS is with their certification standards, this would prevent the computers from being certified.
Anyway, if this is a problem, you should still be able to use a bootloader to provide the selection menu. I think it should be possible for this bootloader to leverage UEFI to avoid increasing the boot time noticeably. But I do agree that hardcoding names like "Windows Boot Manager" is horrible spec design (and maybe grounds for an anti-trust suit?).
A think I am more open to this type of workaround because I already have set up simmilar systems on my computer. For example, Java does not play nice with window managers that do not re-parent. This caused a problem in Sun's window manager "LG3D", which was non-re-parenting, so they hardcoded a special case for LG3D so things would work. So now, if software asks, I am running LG3D.
You can also look through the Linux kernel device drivers for many special cases.
Mandatory. Enable/Disable Secure Boot.
On non-ARM systems, it is required to implement the
ability to disable Secure Boot via firmware setup. A
physically present user must be allowed to disable
Secure Boot via firmware setup without possession of
PKpriv.
Doesn't this mean that (definitely on certified non-ARM systems, and possibly on some ARM systems) you can just enter the UEFI, disable secure boot, and boot your OS of choice?Alternatively, as a workaround, find someone who has already accepted said agreement elsewhere and have them accept it on your device, disable secure boot and wipe the boot device.
I believe that would void most warranties.
Mandatory. On non-ARM systems, the platform MUST implement
the ability for a physically present user to select
between two Secure Boot modes in firmware setup: "Custom"
and "Standard".Disabling Secure Boot is forbidden on ARM systems. Point 18 ends with:
Disabling Secure Boot must not be possible on ARM systems.The main interest of Microsoft is to keep their OEMs in control. Even if it is legal for the end-user to circumvent the protection, the following will probably still hold true:
- Microsoft can still contractually bind their OEMs to implement the protection scheme
- Microsoft can still prevent installations on machines without protection
So, in the best case regulatory action will allow users with hardware implementing the protection scheme to install custom OS (i.e. free them from prosecution when cracking the protection scheme). There is no way of forcing Microsoft to allow installations or usage on devices not implementing the protection scheme or on devices where the protection scheme has been circumvented and this circumvention can be detected by the affected Microsoft OS.
It because http://stervozzinka.dreamwidth.org/15580.html contains information that it is possible to kill itself by shooting into head.
Has anyone experienced the problems described in the article actually in practice or is the article purely theoretical?
Dell almost certainly preloaded some software in exchange for compensation that almost certainly exceeded what Dell paid for their Windows license. Even ignoring the testing, support and return issues people usually bring up, Dell probably couldn't sell the computer for a lower price with no OS or a free OS without losing money.
In short, third parties effectively paid for Windows 8 when you bought your Dell, not you.
I find this hard to believe, even when considering all the mechanisms you mentioned. Do you have any evidence for this very counter-intuitive hypothesis?
IOW: Citation needed
However, it seems this is no longer possible. I've searched Dell's site and the only Vostro 2420 I see with Ubuntu has different hardware (i3 vs celeron). Very disappointing. I will not pay the MS tax.
Even if you skip the huge cost of qualifying parts for a different operating system, and sell PCs without any hardware or software support, there are still extra tracking and stock-keeping costs, and probably extra marketing costs. These will be high, in unit terms, because of the small number of units shipped.
Not being a lawyer, I've no idea whether an OEM could get away with refusing to support the systems it sells. If it can't, you'd have to add the cost of testing and qualifying parts, and I'm not sure how you'd do that. Could you do it for a single version of Linux? Would you have to test for _anything_ the user might install? I don't want to open that can of worms....
The Windows 8 EULA says:
The manufacturer or installer and Microsoft exclude all implied warranties, including those of merchantability, fitness for a particular purpose, and non-infringement.
It's my understanding (IANAL) that laws in the US and most other developed countries attach a warranty to all products sold that they're suitable for sale (merchantability) and for use the way a reasonable person would expect (fitness for a particular purpose). I believe software usually gets around that requirement by being licensed with such terms included rather than sold.
I think there's a good counterargument here to the claim I often see on HN that a PC with Windows preloaded is an integrated product rather than two independent products sold as a bundle. The license terms very clearly state that the Windows part is not guaranteed to work as expected, or indeed to do anything at all. The hardware, on the other hand generally comes with a written warranty stating that it will work, or the manufacturer will repair or replace it.
Which is absolutely irrelevant for example in Germany, as customers (a) buy the computer/license before agreeing to the EULA and (b) most of the statements in the EULA (no warranties, e.g.) cannot be legally included in any contract with a customer/end-user.
Otherwise, you should just be an honest buyer. If you don't want a Windows laptop, don't buy one. It's that simple.
1) companies paying to have their software preinstalled on a laptop
2) the previously mentioned companies software only working on windows
To me this seems like one of the, if not the most, plausible explanation for windows systems being cheaper than Ubuntu
A windows license costs Dell $X. Each trial software they preload earns Dell $Y.
If they preload enough stuff, the sum of the $Y amounts can exceed $X.
Not saying that will happen, I honestly don't think Microsoft cares that much (my own opinion, speculation based on Linux's market share despite my own love of it).
Just... "always" is a strong word. People used that word when talking about secure bootloaders on devices like Droid2, etc. Things that were ultimately only circumvented by kexec. Something that would be much different in a SecureBoot scenario.
I'm even highly interested in PKI and SecureBoot and have been quelling FUD about it for sometime but if I ever buy a non Pixel/MBA device, I'll leave the MS key in there almost assuredly.
What happens if you crtl-alt-del at the EULA prompt?
As above, in this specific situation, where you are agreeing because that is the only way to effectively remove the software, i have trouble seeing any court holding you to those terms.
If you were trying to get around agreeing to the license but still using windows 8, sure.
Make no mistake, I have not been one of the hand-wringers over this whole secure boot thing. But this recent development could turn me into one.
I'm genuinely curious - does there exist some relevant and concerning precedent here?
If this turns out to actually become an issue, it would probably harm Microsoft more than anyone - and would be a boon to manufacturers willing to bundle Linux on pre-built machines (such as the Alienware x51 or "developer" x13). However, I sincerely can't see anything coming of this threat.
It would probably harm Microsoft eventually. It would harm whoever gets turned into a legal test case immediately - which is the sort of thing you avoid by not electronically signing randomly selected legal documents.
Any attempt to 'tie' the hardware to a proprietary OS can be met with a legal challenge on these grounds. So, regardless of what manufacturers would like customers to think, it is possible to obtain an OS-free computer, even if it entails refusing an EULA and getting a refund for the unused OS.
Many people think this argument applies to Apple, too. But that's a mistake: Apple computers are not marketed as 'PCs'; and their computing system, from hardware to OS, is Apple throughout.
Microsoft works with PC manufacturers to pull off this anti-competitive hoodwink on an ignorant computing public. If it were tested properly in court, the whole corrupt practice would be torn to pieces.
You can claim it's an "anti-competitive hoodwink" but Microsoft just spent a decade with the US Justice Department's foot on its neck, specifically to prevent any anti-competitive hoodwinking.
There's also nothing to prevent PC manufacturers shipping whatever they like. Many if not most now sell Android tablets, some sell Chromebooks, the server suppliers support Linux, and so on. Some sell Linux on PCs, including Dell and Asus.
The idea that the market failure of Linux is down to some sort of evil conspiracy might make you feel better but it doesn't square with the facts.
Furthermore, the fact is that if I want a particular laptop PC, Windows is bundled in almost every instance, and I have to jump through hoops to force the manufacturer to take it back.
It's not a conspiracy. But it is illegal.
Also, these are integrated packages so the idea that the OEM should take Windows back is illogical and nonsensical. It is a delusion that bears no relation to reality.
If you want a comforting thought, price is largely a function of volume, so you are getting massive benefits by riding on the back of the economies of scale created specifically by and for Windows. You are gaining far more in real cash savings than the trivial amount that you pay the OEM for its version of Windows.
In the long term, however, you should try to see this for what it is: a very pragmatic business. It's not religion.
It was annoying. Reading the headline, it appears that a similar annoyance is continuing even now.
Either way, dealing with unprofitable customers is a losing strategy for any business.
Given your actual intent is to get the keyboard working enough to boot from CD (or whatever), not to agree to the agreement, and you didn't actually avail yourself of any of the benefits of the software, any retailer on the other side would have a hard time winning any class action lawsuit.
Among other things, assent must be meaningful
Assume there's no communication back to Microsoft and no need for a license under copyright law. Couldn't I just click the "I agree" button while not actually accepting the EULA? Surely, the tablet itself can't be a party to a contract, right?
Right.
A signed piece of paper is neither necessary nor sufficient to form a contract. It's prima facie evidence that an agreement took place, but that's not the same thing.
In practice, of course, it's just about solidifying lock-in with a cover story that's obviously weak to those with technical experience but is justifiable to politicians and regulators who would otherwise be all over MS for facilitating this kind of funny business.
That's debatable. For Microsoft, it's preferable you run a pirated Windows (and, hopefully, a pirated Office) than become part of a non-Microsoft ecosystem. Network effects apply and, as soon as too many people switch to non-Microsoft ecosystems, the value of using Microsoft decreases.
The default setup of these computers (no full-disk encryption, easy to disable secure boot) typically means that it offers no such security. Look at Chromebook for an example of apparently doing it right.
It wipes your hard disk if you enable developer mode(which is a painful process in itself). And then at every single boot you either have to wait thirty seconds to go past a very scary warning or press Ctrl-D. Every single time you boot. If you switch back to ChromeOS, the hard disk is wiped again.
I would love to see HN commenters' reactions if on disabling Secure Boot, the Windows 8 partition is wiped along with any documents and files you saved locally and if you wanted Windows 8 back, it wiped your Linux partition in the name of security.
I'm not saying it's actually secure; I haven't analyzed it in that kind of detail, and I don't even own one.
The equivalent to a Windows 8 partition on ChromeOS is cloud storage like Google Drive, Dropbox or Skydrive. This cloud storage is not being wiped when you switch to or from developer mode.
The local storage is just a temporary storage for downloads and caching.
Oh, and entering developer mode on my Pixel was as easy as holding 3 keys down at the same time.
My PC has one such thing, and it's garbage. I managed to find out how to put it into some sort of 'information' mode with less graphics and more info... but isn't a BIOS screen supposed to be a wholly info thing anyway?
If anything, what you're talking about has more to do with EFI
I imagine the USB stacks are full of paranoid "let things settle for 200ms" sleeps that make more crappy devices work, or that give external HDDs time to spin up. I'll bet you could remove those if all you care about is a keyboard.
Not only are they pretty expensive but there already are many cheap good Android Pads running a Linux kernel. There are also plain Linux pads on the market, and even Ubuntu plans to sell a Ubuntu pad soon.
So, what's the gain?
At least the device manager in Windows says so.
That said, I'm very much in the geeks' camp. "Secure Boot" doesn't really protect the end-user, viruses and trojan mostly operate in the user-space and exploit kernel security holes anyways. This term is misleading, what it secures is Microsoft's position, letting them dictate whatever they want to manufacturers.
Want to scrub the system and start from scratch? Use rEFIt (http://refit.sourceforge.net) and replace the loader.
If Apple encouraged jail-breaking that would dramatically alter the nature of their product line-up. If the jail-broken phones developed a reputation for crashing, for apps not working properly, or for being a vehicle for rampant piracy, that would taint their brand.
It's a tough position they're put in. As an enthusiast I'd really like to see the iOS hardware sold without locks, specifically for hacking, but Apple isn't interested in that market.
The good news is that whatever Apple pushes hard, be it iPads or iPhones or iPods, puts enormous pressure on the supply channel to deliver parts at scale. Where touch-screen panels used to be stupidly expensive, you can buy them for under $50 from many vendors.
Like an ice-breaker, Apple's enormous volume causes the price of components to plunge across the board. Everything they touch becomes commoditized in time. This is good for consumers, they get better products from third parties, and amazing for hardware hackers that want to build or customize their own gear. Want a quad-core ARM CPU? It's a couple of bucks. Think about that.
You can get an OEM tablet from some random vendor in China that's as good as an iPad 2 hardware-wise, and you can get them cheap. For a little extra, you can get them customized. This is not a bad thing.
Apple will keep their hardware locked down, it's their call, but it opens up enormous opportunities in the open-hardware arena.
Microsoft is not allowing arbitrary OSs to run on Dell's, Acer's, Lenovo's and Toshiba's hardware. If Microsoft wants to limit what Microsoft hardware can do, I'm fine with it - I just won't buy from them.
We lost the apple devices as general purpose, android is not much better and the walled gardens are encroaching the PC.
What if the EFI is so locked down, the hardware so Windows-specific, you can't make Linux work on it?
That's the future people are trying to avoid.