Free Software Foundation certifies 2 new devices for ‘Respect Your Freedom’ program

Actually, these two devices were certified back in May, recent FSF RYF program activity is a status update:

Re: ChipFlasher: https://firmwaresecurity.com/2018/05/30/zerocat-chipflasher/







GNU/Linux Libre: concerns with microcode being non-Free Software

The date for this was April 2nd. I checked twice to see if it was April 1st…

[…]Another significant change in this release is that it was pointed out that there were error messages in Linux suggesting users to update x86 CPU microcode. Since such microcode is non-Free Software, such messages don’t belong in GNU Linux-libre. We now have patterns to detect and clean up this sort of message. A number of them were introduced recently, relying on microcode changes to mitigate Spectre and Meltdown problems, but there might be others that go farther back. I haven’t yet made my mind on whether to go back, check and possibly respin such earlier releases.[…]

Finally, to celebrate Easter on this date, I couldn’t help mentioning in this release announcement the Easter Eggs I put in. Let me know if you enjoy the surprises.[…]




GRUB 2.02 in the works…

See the FOSDEM slides for some of the features listed in the Phoronix article.






FSF increases focus on firmware

The Free Software Foundation has updated their list of Campaigns, which includes mention of reversing firmware, and a blob-free version of Coreboot:

Reverse engineering projects.
We haven’t analyzed these in detail yet, but more broadly free drivers and free firmware (the goals of nearly all of the listed projects) have all four of our characteristics. Reverse engineering is one way to obtain free drivers and firmware, but the ideal is for manufacturers to publish full specifications and ship free drivers and free firmware, and this is what users should demand. We may want to reframe this page around free drivers, firmware, and hardware designs, noting priority reverse engineering tasks, but also encouraging users to make requests to vendors. The page also lists Replicant, a free version of Android. Phone operating systems were one of the most popular suggestions and merit their own entry (see potential additions below).

A free BIOS has at least the universal and frontier characteristics. Several people suggested adding “and Libreboot,” the project to ship a version of Coreboot with no blobs, pushing further in the frontier direction. We intend to take this suggestion. We are also discussing whether to move this listing to the reframed page about free drivers, firmware, and hardware designs mentioned above.
Free software drivers for network routers.
The text of this listing concerns mesh networking, which may be too narrow to satisfy our criteria. In general free drivers for network routers probably meet the universal and frontier criteria, but it may make sense to fold this listing into a listing/page concerning free drivers and firmware for a large category of hardware (see reverse engineering above).




FSF: back the Raptor Talos Secure Workstation

A message from Donald Robertson of the Free Software Foundation, quoted verbatim:

Support the Talos Secure Workstation by January 14th Raptor Computing Systems is crowdfunding on Crowd Supply to produce, from the ground up, a high-powered computer with no proprietary software or firmware blobs called the Talos Secure Workstation. The project’s decision to raise funds via [Crowd Supply][0] means that you can support their work with anonymous payments, and without the use of [proprietary JavaScript][1]. We wrote about this project previously, and encouraged people to [voice their support][2]. While there are several companies that offer refurbished computers that have been freed to [Respect Your Freedom][3], the Talos Secure Workstation will be built from its inception with freedom in mind. But in order for that to happen, the project needs your help to meet their fund raising goal. The project has set a crowdfunding goal of $3.7 million and still has a ways to go to reach that mark. It may seem like they are asking for a lot of money, but relative to the scope of what the folks at Raptor Computing are trying to accomplish, it is a small amount. As Raptor Computing Systems Senior Electrical Engineer Timothy Pearson explained:

‘Large, complex systems such as Talos require minimum order quantities to be met for the component parts in use, in addition to R&D expenditure for prototyping, validation, and conformance testing. We have set the goal at the minimum level required to ensure that we can not only design the Talos systems, but also purchase the parts needed to manufacture these complex machines.’

They need every dollar they can get to make this system a reality. It is a difficult goal, but also one that is critical for the future of free computing. As they note in their explanation[4] of the problem:

‘As of this writing, all currently manufactured, low- to mid-range and higher x86 devices, with the exception of two obsolete AMD CPUs, incorporate a security processor that is cryptographically signed, updateable, unauditable, and for which no source code or documentation has been made public. Worse, these security processors must load and continually execute this signed firmware for the system to either be brought online (AMD) or for it to remain operational (Intel).’

If we want a future in which we can continue to have fully free systems that run only free software, we have to build that future ourselves. The Talos Secure Workstation is a proposed system to help secure that future. Their plans are to create a device that will meet the criteria for [Respects Your Freedom][3] certification, but in order for their plans to come to fruition, they need your help. You can support their work by backing the project via their [crowdfunding page][0], or even better, by purchasing a mainboard andaccessory package. Every little bit counts. Will you help support the future of free computing?

[0]: https://www.crowdsupply.com/raptor-computing-systems/talos-secure-workstation
[1]: https://www.gnu.org/philosophy/javascript-trap.en.html
[2]: https://www.fsf.org/blogs/licensing/interested-in-a-powerful-free-software-friendly-workstation
[3]: https://www.fsf.org/resources/hw/endorsement/respects-your-freedom
[4]: https://www.crowdsupply.com/raptor-computing-systems/talos-secure-workstation/updates/a-word-on-lockdown



Libreboot and GNU: update

A few months ago a GNU/Libreboot issue occurred, and I just got around to blogging about it the other day. Well, a few days, later, there is an update from FSF. Also see comment from a reader of previous post, for good background.






FSF asks you to support the Libre Tea Computer Card

The Free Software Foundation is supporting the Libre Tea Computer Card’s crowdfunding effort.

“The Earth-friendly EOMA68 Computing Devices project is a crowdfunding campaign run on Crowd Supply to produce a line of hardware products that are ecologically responsible and built based on royalty-free, unencumbered hardware standards. […] After working closely with the developers and reviewing a sample test board, we are confident that their plans are to create a device that can achieve our Respects Your Freedom (RYF) certification. […]  The project is being developed by Luke Kenneth Casson Leighton of Rhombus-Tech and is sponsored by Christopher Waid of ThinkPenguin, a company that sells [multiple RYF-certified hardware products. […]  The Libre Tea Computer Card is built with an Allwinner A20 dual core processor configured to use the main CPU for graphics; it has 2 GB of RAM and 8 GB of NAND Flash; […]