Secure Boot complaint filed against Microsoft


Recommended Posts

Hispalinux[1]Spain-95ce387c68887fa0.png, an 8,000 strong Spanish association of Linux users and developers, has filed a complaint with the Madrid office of the European Commission claiming, according to a Reuters[2] report, that Windows 8 contains an "obstruction mechanism" called UEFI Secure Boot. This mechanism, it says, controls the system boot up and means users must seek keys from Microsoft to install another operating system.

Hispalinux head, lawyer Jos? Maria Lancho, told the news agency that it was "absolutely anti-competitive" and a "de facto technological jail for computer booting systems". The complaint[3]Spain-95ce387c68887fa0.png says that although Microsoft says UEFI Secure Boot is a security measure, its implementation would not mean the end of malware and viruses.

The complaint comes just over three weeks after the EU Competition Chief Joaqu?n Almunia said, in a written answer[4] to parliamentary questions, that the "Commission is monitoring the implementation of the Microsoft Windows 8 security requirements. The Commission is however currently not in possession of evidence suggesting that the Windows 8 security requirements would result in practices in violation of EU competition rules".

UEFI Secure Boot is a mechanism that was added to the UEFI firmware and uses keys registered in firmware to check a digital signature on any operating system's bootloader and kernel to ensure that they have not been tampered with. The idea is to avoid situations where malware modifies the operating system or boot process itself as part of its camouflage mechanisms. Microsoft requires that machines sold with Windows 8 pre-installed are configured to use this mechanism to validate the operating system. This means that machines with Windows 8 have Microsoft's key registered in the firmware and, with no other operating system vendor offering a similar key, it is the only key that comes on most of these machines.

Booting another operating system on these machines would, therefore, mean disabling secure boot, adding a key for validation of the other operating system to the firmware, or getting the bootloader for the operating system signed by Microsoft. The first two options are paths that Microsoft requires vendors implement on x86-based systems, although there are no common or standard ways of implementing the features.

Therefore, Linux vendors such as Red Hat, SUSE and Canonical, and the Linux Foundation all looked at approaches where a bootloader or pre-bootloader was signed by Microsoft and would go on to load Linux once booted and verified. This would, the vendors believed, give users an easier way to install Linux on any arbitrary Windows 8 pre-installed PC system.

These solutions require Microsoft to sign the bootloader and have reinforced the Free Software Foundation's objections[5] to what it has dubbed "Restricted Boot". The Hispalinux complaint appears to follow the FSF's reasoning and seems to request a simple way for consumers to disable or override Secure Boot. But, as the Commissioner notes: "In particular, on the basis of the information currently available to the Commission it appears that the OEMs are required to give end users the option to disable the UEFI secure boot". It may be that this case will hinge on whether the Commission continues to feel that this is sufficient.

URL of this Article:

http://www.h-online.com/open/news/item/Secure-Boot-complaint-filed-against-Microsoft-1830714.html

Links in this Article:

[1] http://www.hispalinux.es/

[2] http://www.reuters.com/article/2013/03/26/us-microsoft-eu-idUSBRE92P0E120130326

[3] http://www.hispalinux.es/node/758

[4] http://www.europarl.europa.eu/sides/getAllAnswers.do?reference=E-2013-000162&language=EN

[5] http://www.h-online.com/news/item/FSF-warns-of-Windows-8-Secure-Boot-1363531.html

Couldn't find any forums search entries on this, so posting it here.

For the supposed self proclaimed computer elite. Linux users keep coming off as inept computer illiterates....

Even the knowledgeable ones (Timothy Lottes for one example) seem to believe MS did it just to block competition. I'm really not sure what to think of these people.

  • Like 2

Their whole argument is that secure boot isn't a silver bullet that stops all malware, but just one piece of a big system. But since every little piece of security is just that, why don't we remove all of them... Oh wait... Then you're unprotected. Every little brick helps.

  • Like 2

While people are crying about how unsecure Windows OS, but then still cry when they try to implement something to make it more secure.

It is only unfair if they buy the computer without any OS, and still can't install Linux because of UEFI Secure Boot. However, the computer is sold as computer with pre-installed Windows OS.

Stop crying and buy a Linux computer instead.

  • Like 3

Stop crying and buy a Linux computer instead.

It's kind of irrelevant when you can install Linux fine now.

Which is what I told people would happen. MS can't afford another huge run in with the DoJ and it's bloody unlikely they'd go out of their way to **** off the EU either.

Only a matter of time until the bootloader/UEFI is bypassed/hacked

The ASUS Transformers have ether SBK1 or SBK2 models, the SBK1 models key was leaked so we could use NVFlash to flash custom ROMs, SBK2 key was never leaked, but eventually the guys at XDA found a way around it and now both models can flash whatever OS/Recovery they want on them

Is there some reason that companies like RedHat and Canonical can't get a bootloader signed?

Probably because theoretically, They are knocking at the door and microsoft is behind the locked door giggling while Linux users scratch their heads.

Is there some reason that companies like RedHat and Canonical can't get a bootloader signed?

I think most people who are upset are upset over the fact that Microsoft holds all the keys. Those keys should be held by a third party for all.

  • Like 3

I think most people who are upset are upset over the fact that Microsoft holds all the keys. Those keys should be held by a third party for all.

Fairly certain you can use secure boot without Microsoft at all. Fedora and some others opted to use the Microsoft key because it was easier.

I think most people who are upset are upset over the fact that Microsoft holds all the keys. Those keys should be held by a third party for all.

I don't think MS holds all the keys, I believe they are held by VeriSign.

Secure Boot is not a MS technology. They are just using it and I believe they also had to buy a key to use Secure Boot.

Other companies could also buy a key and use that in combination with Secure Boot.

  • Like 2

I think most people who are upset are upset over the fact that Microsoft holds all the keys. Those keys should be held by a third party for all.

We all know what happens when keys are given to Linux.

  • Like 3

Is there some reason that companies like RedHat and Canonical can't get a bootloader signed?

I think RedHat already implemented it in Fedora.

It costs $99 from Verisign:

The last option wasn't hugely attractive, but is probably the least worst. Microsoft will be offering signing services through their sysdev portal. It's not entirely free (there's a one-off $99 fee to gain access edit: The $99 goes to Verisign, not Microsoft - further edit: once paid you can sign as many binaries as you want), but it's cheaper than any realistic alternative would have been.

http://mjg59.dreamwidth.org/12368.html?style=light

Plus you can just disable secure boot, it isn't that hard and since you'll be installing a new OS chances are you already know how to.

Pathetic lawsuit to try and earn money, that's really all it is.

  • Like 4

I think you'll find a lot of us like Linux..

There's also a cross-party bootloader that's been signed. The idea being that it can load up any distro you want.

The complaint is pretty pants on head.. Especially given Microsoft submitted a patch Linux could use (which was ****, but they did it) and Linus Torvalds booted it out.

I think Linus made the right call on that one, but it does rather defeat the "anti-competitive" argument >.>

Things like this is why no one likes Linux and Linux users.

No this has nothing to do with LINUX not being good but Microsoft forcing Windows 8 on you....

I mean let me take Linux out of the equation for you.

Windows 8 runs like a snail or you just don't like it and you decide you want to buy and install Windows 7 instead

Whoops Not GOING TO ALLOW IT...

. you can't because the only OS your computer thinks is a Valid install is Windows 8.

And in some of the OEM's there is no bios option to remove or disable this check.

The easy way to edit this is allow the OEM's to have a bios that can be downloaded to allow people to turn it off.

What this boils down to is Allow the user the choice.

I mean what if people buy a PC with Windows 8 and decide they don't like it at all... and they want to install the following.

Windows 7

Linux

Hackintosh

But their computer won't allow them to do this.

This is as they are trying to show is the same option as Microsoft locking people into having IE installed by default.

-snip-

However, the computer is sold as computer with pre-installed Windows OS.

Stop crying and buy a Linux computer instead.

The other thing to look at is -- people say "BUY a Linux Computer" well that limits the choices and those choices are not very strong computers.

Other than -

https://www.system76.com

But still there are not a lot of options- They don't even offer any AMD chip-sets.

Some of these people don't mind paying for a computer with Windows but also like the CHOICE to have a dual boot as well.

I mean would you want a computer where you can't even choose which OS you want on it?


Side note-
And for my Wife that is a necessity to be able to boot to a USB key that has Suse for her work.

The is what her company uses as it's business OS.

So for her it is that she get a computer that is not so new than?
[/CODE]

That is the complaint in an easy nutshell. Where they claimed to secure an OS but it has side effect and that is limiting the choices people can have with their computers.

That is the complaint in an easy nutshell. Where they claimed to secure an OS but it has side effect and that is limiting the choices people can have with their computers.

Every security solution has side effects. You don't like Secure Boot? TURN IT OFF. Then you can install whatever OS you like. Some claim some OEMs disable this, but I've never actually seen an example.

The difference between UEFI providing an option to secure your computer and MS locking down said computer should be fairly obvious. That some people don't see the distinction does no credit to their logic.

  • Like 3

Every security solution has side effects. You don't like Secure Boot? TURN IT OFF. Then you can install whatever OS you like. Some claim some OEMs disable this, but I've never actually seen an example.

The difference between UEFI providing an option to secure your computer and MS locking down said computer should be fairly obvious. That some people don't see the distinction does no credit to their logic.

Acer- Emachine - Gateway to name a few... There is no option to disable it at all-- it is missing.

The logic is there but the point is -- locking out user choice.

I personally like to dual boot either with WUBI or a true Dual boot.

And such like my wife needs for her work the newer systems don't allow it. (namely SUSE her job uses)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • GitHub removes manual model selection from Copilot free and student plans by Karthik Mudaliar GitHub is removing the ability to manually select an AI model from its Copilot Free and Student plans, making its automatic routing system the default and only way to choose a model. This means users on these tiers will no longer be able to deliberately select a particular OpenAI, Anthropic, Google, or Microsoft model for a task. In its announcement, GitHub said Copilot Auto will dynamically choose what it considers the best model for each request. Free and Student accounts will retain access to models from multiple families, although the available selection will continue to depend on the restrictions attached to each plan. GitHub did not identify a fixed pool of models that Auto will always use, and its documentation warns that model availability can change over time. GitHub describes Auto as more than a random fallback system. On supported surfaces, its task-optimization technology evaluates the complexity of a request alongside real-time information about model health and availability. Straightforward prompts can be routed to faster and less expensive models, while more demanding coding tasks may be sent to higher-cost reasoning models. The company says this approach should reduce rate limiting, latency, and failed requests. Auto generally selects one model along natural prompt-caching boundaries rather than repeatedly switching models during a session, as GitHub found that mid-session changes increased costs without producing sufficient improvements in output quality. Users can still check which model generated a response. In Copilot Chat, the information appears when hovering over an answer, while Copilot CLI and the Copilot cloud agent display the selected model alongside their output. Auto is available in Copilot Chat, Copilot CLI, and the cloud agent, with the exact implementation and release status varying between supported development environments. The latest restriction follows several months of adjustments to Copilot’s individual plans. GitHub temporarily halted new Pro, Pro+, and Student subscriptions in April as it sought to manage demand and service reliability. It later introduced token-based billing and began gradually reopening individual-plan registrations on June 17. Alongside the picker change, GitHub is retiring the “Preview” label from Microsoft-developed models. It argues that the label is no longer necessary because Auto handles model routing and models are continuously updated behind the scenes.
    • Look up 'inflation' kid. Ask an AI for the numbers between both games.
    • Google reportedly set to lose two key Gemini and DeepMind researchers to Anthropic by Karthik Mudaliar Google is reportedly preparing to lose two more prominent artificial intelligence researchers, with Gemini contributors Jonas Adler and Alexander Pritzel planning to join rival AI developer Anthropic. According to a report from Bloomberg, both researchers are viewed internally as important contributors to Google’s flagship Gemini model family. Adler worked on Google’s AI coding efforts, while Pritzel was involved in the process used to train AI systems. Neither company has publicly confirmed the moves. The report also does not say when the researchers will formally leave Google or what positions they will hold at Anthropic. Training a large AI model requires decisions covering its architecture, data preparation, distributed computing infrastructure, and post-training methods that shape how the finished system behaves. Researchers with experience operating at the scale of Gemini are consequently difficult to replace quickly. Both Adler and Pritzel have previously contributed to Google DeepMind’s scientific research as well. They are listed among the authors of the company’s work on expanding AlphaFold protein-structure predictions across entire proteomes, alongside AlphaFold researchers including John Jumper. The reported departures arrive shortly after another important change within Google’s Gemini organization. Gemini co-lead Noam Shazeer is leaving Google for OpenAI, after returning to the search company in 2024 through its deal with Character.AI. Shazeer is particularly well known as one of the authors of the Transformer paper, whose architecture became the foundation for most modern large language models. Anthropic, meanwhile, has been recruiting recognizable figures from other leading laboratories. OpenAI co-founder and former Tesla AI director Andrej Karpathy joined Anthropic’s pre-training team in May. His move, followed by the reported recruitment of several Google researchers, suggests Anthropic is strengthening the research teams responsible for the core capabilities of future Claude models rather than concentrating solely on product and enterprise sales. The competition is complicated by the companies’ extensive commercial relationships. Anthropic competes directly with Google’s Gemini models, but it also relies on Google as an infrastructure partner. In April, Anthropic announced an expanded agreement with Google and Broadcom covering multiple gigawatts of next-generation Tensor Processing Unit capacity. TPUs are Google-designed accelerators used to train and run large AI models. via Bloomberg
    • This article makes my head hurt. Lots of confusing words
    • Google adds built-in computer control to Gemini 3.5 flash by Karthik Mudaliar Google has added Computer Use as a built-in tool in Gemini 3.5 Flash, giving developers a single model that can reason about a task and operate graphical interfaces across browsers, mobile devices, and desktop environments. The feature is available through the Gemini API and Google’s Gemini Enterprise Agent Platform, although it remains a preview feature for now. Computer Use enables an AI agent to examine screenshots and return actions such as mouse clicks, scrolling, and keyboard input. A developer’s application must execute those actions, capture the resulting screen, and send it back to Gemini, creating a continuous loop until the task is completed. Google says the integration can be used for activities including repetitive form filling, application testing, research across multiple websites, and longer enterprise workflows. Gemini 3.5 Flash can work with browser, mobile, and desktop environments, whereas Google’s earlier standalone Computer Use model was primarily positioned around browser interaction. The main change is consolidation. Computer control was previously offered through the separate Gemini 2.5 Computer Use preview model. As Neowin reported when that model was introduced, it was designed to interpret a visual interface and generate actions without requiring a website-specific API. Google later brought Computer Use to preview versions of Gemini 3 Pro and Gemini 3 Flash in January 2026. The latest release now incorporates the tool into the stable Gemini 3.5 Flash model rather than requiring developers to select a specialized model solely for interface automation. Gemini 3.5 Flash itself was announced in May as Google’s latest fast model for coding and multi-step agent workflows. It supports a one-million-token input context window and up to 65,000 output tokens, along with adjustable thinking levels that let developers trade additional reasoning for lower latency and cost. Google also added that Gemini 3.5 Flash received targeted adversarial training for computer-use scenarios. The company is also offering safeguards that can require user confirmation before sensitive or irreversible actions and automatically stop a workflow when suspected prompt injection is detected. Its developer documentation describes configurable protections for areas such as financial transactions and changes to sensitive records. Google isn't the first to bring Computer Use to its platform. Anthropic has made computer control available through Claude, while OpenAI has continued improving computer-use performance in its recent models. Microsoft has also applied the concept to business workflows, including a Computer Use capability for the Researcher agent in Microsoft 365 Copilot.
  • Recent Achievements

    • Dedicated
      Scoobystu earned a badge
      Dedicated
    • First Post
      Tom Schmidt earned a badge
      First Post
    • One Month Later
      D0nn13 earned a badge
      One Month Later
    • Rookie
      +ChiefOfNeo went up a rank
      Rookie
    • One Year In
      Tom Schmidt earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      463
    2. 2
      +Edouard
      177
    3. 3
      PsYcHoKiLLa
      124
    4. 4
      Michael Scrip
      79
    5. 5
      Xenon
      76
  • Tell a friend

    Love Neowin? Tell a friend!