Secure Boot: The Linux Foundation to the Rescue.

Fedora / Red Hat came first saying that it would use Microsoft keys (which openSuse would also do). Then came Ubuntu who thought of having its own key and also removing GRUB2 (which caused criticism from the FSF worse than the Fedora solution). Now, James Bottomley, technical advisor to the Linux Foundation comes with the salvation………… for all your distributions (not only those already mentioned)

This is a slight change to Fedora's solution of using Microsoft keys. They will also sign a pre-bootloader what will loadwithout any signature verification) a pre-built bootloader which in turn will load Linux (or other operating system). That pre-bootloader can be used for LiveCD distributions, CD / DVD installers or even boot in safe mode a distribution that is already installed and choose to use it. The solution would not only benefit to users of GNU / Linux, but also to the users of the Operating Systems BSD.

Sources: Linux Foundation | Muktware


Leave a Comment

Your email address will not be published. Required fields are marked with *

*

*

  1. Responsible for the data: Miguel Ángel Gatón
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.

  1.   Edgar J Portillo said

    WHAT WILL MICROSOFT BE! Ashhhh, what a damn company ... Those millions are disgusting ... It is worth more, there is a solution 😀 ...

    1.    Anonymous said

      But remember that the monopoly is theirs, and when they want to do something similar again, we will have a bad time again.

  2.   Algave said

    Very good solution !! 🙂

  3.   auroszx said

    It's good to hear (read xD) that! 😀

  4.   Blitzkrieg said

    Already expected

  5.   Carlos-Xfce said

    He knew that sooner or later there would be a solution. What's more, I think it will not be just one, but there will be more solutions from various fronts in the GNU / Linux world.

  6.   Garbage_Killer said

    great news.

  7.   jorgemanjarrezlerma said

    That such.

    The well-known SECURE BOOT is one more of the samples of the useless and insecure of the Microsoft operating systems as well as its applications. Even a system as closed as MacOS is less meope and more liberal than the "geniuses" of Microsoft.

    I am also pleased that the Ubuntu team (Cannonical in general) has downloaded the sumos and continues on the path that it should always follow, which is linux and not being another MacOS or yet another Microsoft.

    On the other hand, it is good news for users of BSD (Unix), Linux and other operating systems on the market, which indicates that the advancement of these environments continues to walk (slowly but surely). I'm glad to hear it and I just hope that like GRUB also SYSLINUX.

    I am also pleased to see in the image that you can disable this stupidity of the "geniuses" of Microsoft and be able to install and put what we want with OUR EQUIPMENT (because they are ours, not rented or licensed).

    1.    Windousian said

      In my humble opinion, if Microsoft is the bad boy of the class, Apple is the snake of original sin. Apple doesn't just shut down the software, it also limits the hardware. Without compatible PCs we would lose a lot. We couldn't easily change parts and all computer equipment would be like cell phones: welded components and special screws everywhere. Just thinking about it gives me goose bumps.

    2.    oscar said

      meope xD

  8.   sieg84 said

    and there was the «secure»

  9.   Nonamed said

    but why so much complication?

    it is deactivated in the bios and it is already solved

    1.    Shiba87 said

      What if the manufacturer does not see fit to include the possibility of disabling it?
      Keep in mind that Microsoft forces manufacturers to include and enable Secure boot by default and it is the manufacturer who then decides whether to disable it or not.

      There will be motherboards that allow it and we will only have to access the UEFI and disable Secure boot, but there will be cases where the manufacturer does not allow it or does not bother to include a deactivation option.

      1.    Nonamed said

        but people will ask in the store if it has secure boot, and if so, they will ask if it can be disabled

        It is not possible?

        Well, to buy from another manufacturer that allows it

        1.    Manual of the Source said

          I pay you $ 5000 for every person you see asking that. xD

          1.    Adoniz (@ NinjaUrbano1) said

            He will have to pay you because the numbers of people who ask that surely do not exist or even I would have asked.

            XD

    2.    RudaMale said

      I think it is in case you want to have double boot with windor, if you deactivate it the infamous system does not start

  10.   Brutosaurus said

    It is great news, however I wonder if it will allow a dualboot, since some of us are doomed to use Win on our computers ...

    1.    sieg84 said

      hum, that's to allow dual boot ...

      1.    Brutosaurus said

        Well, I interpreted it as that it would not need to be signed to run it ... even so, my question is whether it will also allow the windows installed on the pc to boot (the one that needs the secure boot, go xD)

        1.    Shiba87 said

          In theory yes. The Pre-Bootloader is basically a launcher that runs the actual bootloader after it has passed the Secure boot "check."

          The only requirement is that the prebootloader and the bootloader are on the same partition and that the pre-bootloader is pointing to the bootloader executable, whatever it is.

          Beyond that I don't know how it will be in the case of Windows, I imagine something more complicated than in the case of grub, but
          possible.
          And if it is a dual boot, configure it to start with grub and let him take care of the rest.

  11.   Diego Silverberg said

    UUUUYY DOES BILL HURT? IT HURTS MUCH? YOU SHOULD HAVE USED VASELINE, AGAINST THE FREE SOFTWARE YOU CANNOT SEE THE DOORS

    1.    proper said

      What does Bill Gates have to do with all this? If you were a little more informed you would know that the CEO of Microsoft is currently Steve Ballmer.

  12.   Linda said

    I have windows and Ubuntu on different partitions and I have to say that day by day I am more satisfied with free software, now I am doing a class assignment with Libre Office version windows, but it seems strange to me that I notice it more fluid in windows than in Ubuntu . I have a DualCore Intel and a Gforce 9400GT plus 2G of ram.
    ALREADY TO THE SEN ~ ORS OF mICROSOFT WHO WILL ROT WITH THEIR SHIT CLOSED, NOT TO MENTION THE SEN ~ ORS OF La Manzanita THERE IS ALWAYS OUT FOR EVERYTHING. Sorry for the enhes, my keyboard is not Spanish

  13.   Fernando Monroy said

    On the part of the community there will always be a solution.

  14.   semproms said

    The community always has a solution for this kind of thing, it's the good thing about free software.

    A greeting.

  15.   user said

    according to this news http://www.taringa.net/posts/linux/15732411/La-Fundacion-Linux-tiene-un-plan-para-evadir-Secure-Boot.html

    »THIS PRE-BOOTLOADER WOULD HAVE AN AUTHENTIC AND VERIFIED SIGNATURE OBTAINED FROM MICROSOFT

    and it would be the one that would be in charge of mediating with secure boot during boot. Once secure boot verifies the authenticity of the signature of this pre-bootloader, it in turn will launch the authentic bootloader of the system we want to start, thus preventing Secure boot from blocking it.
    »
    if so then IT IS NOT A SOLUTION BECAUSE LINUX WOULD DEPEND ON MICROSOFTT

    I HOPE SOME HACKER WILL TAKE SOME SOLUTION WITHOUT DEPENDING ON THOSE KEYS

    1.    KZKG ^ Gaara said

      Linux has never depended and will never depend on Microsoft, don't worry, a solution is always found 😉

    2.    Shiba87 said

      The signature for the prebootloader will have to be obtained through the Microsoft service (whose name I cannot remember now) that is responsible for supplying the signatures for secure Boot, you will have to pay and fill out the corresponding paperwork, but that does not mean much less than Microsoft will have control over the Prebootloader or will be able to block it or anything like that, it is only a procedure that once it is passed, it does not imply anything else, the key is obtained, the software is authenticated and the problem is over «to forever".
      The Prebootloader authenticated as it should be will not have problems with Secure Boot, which will give us a universal solution to the problem, for any bootloader.

  16.   Alf said

    There is something that is not clear to me, and in the various forums and blogs it is not commented (or I did not see it), if I install Linux completely removing windows, what happens?

    1.    Shiba87 said

      Secure boot is a UEFI feature, it has nothing to do with Windows, it is in the motherboard firmware.
      If Secure boot is enabled, regardless of whether Windows, GNU / Linux, BSD or any system or combination of systems are installed, it will still verify that the software is signed during boot.