Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #13760

Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion

From Johannes Schauer Marin Rodrigues <josch@debian.org>
Newsgroups linux.debian.project, linux.debian.devel
Subject Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion
Date 2025-03-08 16:30 +0100
Message-ID <Ko2SB-4ywi-5@gated-at.bofh.it> (permalink)
References <KnK9j-4m3r-1@gated-at.bofh.it> <KnKM2-4mAk-1@gated-at.bofh.it> <Ko0e5-4wRd-1@gated-at.bofh.it> <Ko1MR-4xLh-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Hi,

Quoting Simon Josefsson (2025-03-08 13:43:26)
> My point was that there is no reasonable way to gain confidence about
> security properties of any piece of non-free microcode.  Everyone can now
> produce AMD microcode that corrupts your machine in advanced ways that evade
> detection, but we don't know if such malicious corruption is included in the
> official microcode.  Having source code for the microcode would help gain
> confidence in it, and is the reasonable request.  If the request is denied, I
> would consider the vendor not trustworthy and look into options.

I do not understand something about this argument.

If you don't trust the vendor, then it makes no difference whether or not new
official firmware/microcode can be uploaded/flashed or not. If you don't trust
the vendor, then the initial microcode that came with your device might already
be doing things that go against your interests.

Of course we cannot have much confidence in a piece of microcode of which we do
not have the source code. But we also cannot have much confidence in a piece of
hardware with non-flashable firmware of which we don't have the vhdl/verilog
sources. So what is the difference?

If I don't trust vendor X, then I cannot buy hardware from them independent of
whether or not the vendor allows me to flash proprietary binary blobs from
them. If I do trust vendor X, then why would I not trust their proprietary
binary blobs?

I do not think you will find many on this list who will disagree with the
sentiment that it would be great if we had sources, schematics etc for many
more things. On the other hand, I don't think you can currently buy a device
that is capable to run, for example, a modern web browser and is fully open.
This is why I voted in the last GR as I did. I'm typing this on an MNT Reform
which is probably among the most open computers you can buy today but the chips
in it are *not* open silicon. Yes, it would be great if they were and it would
be great if the firmware blobs I need would not be proprietary. But I already
chose to trust the manufacturers of the chips in my laptop or otherwise I would
not be typing these lines. Why would I trust the silicone from vendor X and
distrust the firmware/microcode from vendor X? Having non-free-firmware enabled
by default in the Debian installer just continues pursuing a trust relationship
you already decided on entering when you bought the hardware, no?

Thanks!

cheers, josch

Back to linux.debian.project | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion Simon Josefsson <simon@josefsson.org> - 2025-03-07 22:00 +0100
  Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion Bill Allombert <ballombe@debian.org> - 2025-03-08 12:50 +0100
    Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion Simon Josefsson <simon@josefsson.org> - 2025-03-08 13:50 +0100
      Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion Aurélien COUDERC <libre@coucouf.fr> - 2025-03-08 14:30 +0100
      Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion Simon Josefsson <simon@josefsson.org> - 2025-03-08 16:30 +0100
        Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion Matthias Urlichs <matthias@urlichs.de> - 2025-04-10 11:20 +0200
          Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion <tomas@tuxteam.de> - 2025-04-10 14:00 +0200
          Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion Simon Josefsson <simon@josefsson.org> - 2025-04-10 14:00 +0200
          Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion Henrik Ahlgren <pablo@seestieto.com> - 2025-04-10 14:00 +0200
      Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion Johannes Schauer Marin Rodrigues <josch@debian.org> - 2025-03-08 16:30 +0100
        Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion <tomas@tuxteam.de> - 2025-03-08 16:50 +0100

csiph-web