It sounds like Lenovo's BIOS is using a RAID mode with the internal SSD that Linux does not understand. Lenovo apparently provides a driver for this RAID mode for Windows 10. If you want to install something else (Linux, Windows 8) you are out of luck until someone produces a driver for that operating system.
It is much worse because Lenovo programmed the BIOS to lock the system so if you try to toggle it to AHCI mode with an EFI variable from EFIshell, it immediately sets itself back to RAID mode.
> Nope. You can turn Secure Boot off on the Lenovo Yoga models that this affects.
> They have the SSD in some strange "RAID" mode where Linux can't see or be installed to it, and neither can Windows unless you add some drivers to your Windows installer media. They removed AHCI mode from the BIOS. Then they wrote additional code so if you try to toggle it to AHCI mode with an EFI variable from EFIshell, it immediately sets itself back to RAID.
> For the last 11 months, they were silent on why this machine was configured this way. The only reason we know why now is because Lenovo answered my Best Buy review by stating it is locked due to the agreement they signed with Microsoft for the Signature Edition PC program, so it's very likely that all Ultrabooks in the Microsoft Store, and some outside the MS Store (such as at Best Buy) will eventually be configured so that Linux can't be installed, even if there are some now where you can install Linux.
> So consider "Signature Edition" a warning label that means "You aren't allowed to run Linux, per Microsoft.".
If this [1] Lenovo employee's answer is a real deal, and this was in fact sanctioned by MS, I wonder if their actual goal was to prevent people from installing Windows 8/7/whatever. MS did go on record by saying they are willing to block people from installing old versions on new hardware. [2]
Given the quality of answers to questions that I'm used to by computer manufacturer "product experts" online... it's really unlikely that that's actually the case.
RAID mode? WTF? Why would they be using RAID mode on a machine with a single SSD, and according to the other posts here, deliberately make it nearly impossible to change?
Maybe because good-old-IDE or even AHCI was too simple and open.
I don't think being able to change the drive to AHCI mode would fix the problem. The BIOS (actually UEFI) "locking" and storage driver are two separate issues. I mean, hell, if someone wants to send me one of these laptops I'll test it and do a full writeup.
Of course Reddit has gone off without anyone actually confirming what the issue is. Microsoft would be smart to come out with a statement on this if it picks up any steam.
I'll spell it out: a Lenovo representative said "This system has a Signature Edition of Windows 10 Home installed. It is locked per our agreement with Microsoft." This is what people are reacting to.
Now, of course the rep might be mistaken. We need official clarification from someone higher up. But we won't get that until we go off on one and this goes viral.
Yes, but has anyone verified that? The person posting it even said they've booted a Linux installer - if it was "locked" at firmware level you wouldn't even be able to do that.
What needs to be verified, and by whom? Right now we have one assertion, from a person claiming to be a Lenovo representative (an "expert" even), on a Lenovo-hosted forum.
It is not up to the rest of the world to divine meaning from Lenovo's PR policy. If they are happy to allow nitwits to make public statements like that, they should be fully prepared to handle the fallout.
The screenshot that particular quote comes from appears to be from a Best Buy review section not a Lenovo hosted site, so it's unclear whether the Lenovo Product Expert is even a Lenovo employee or just the Best Buy droid assigned to answering Qs for Lenovo products.
> Thank you for confirming it is still not possible to install Linux on Yoga 900-13ISK2 systems.
> This issue has been escalated to the Development team. I am unable to offer a timeframe for fix at this stage in the investigation. With previous cases, BIOS fixes have been delivered anywhere from several weeks to several months.
> I will post again when I have more information on the investigation.
"I don't think being able to change the drive to AHCI mode would fix the problem."
One user Bownairo confirmed that changing the drive to AHCI mode did fix the problem by allowing the drive to be recognized in Linux, after manually flashing a modded BIOS by soldering chip programming hardware:
/r/linux is the most ridiculously paranoid forum I've seen.
You have to go there to see it for yourself. Imagine the way that HN is paranoid of the US government, but then double that and apply it to Microsoft, which makes even less sense. To them, MS is the boogeyman that will stop at nothing to prevent them from being the glorious 1% that doesn't use Windows. It's still the 90's on /r/linux, in many many ways.
Yea but sometimes you need a group of extreme people to offset the other extreme you get with locked bootloaders etc. Not saying they are always right, but I am happy we still have people around with 0 trust in MS.
I doubt that. It's more likely that Best Buy's "Lenovo Product Expert" misunderstood the review and referred to the agreement to not install any software on Signature Edition devices.
I have no serious position on whether Microsoft is currently enforcing secret deals to sabotage Linux, but I'm sure the employee assigned to respond to product reviews would not be given such inside information.
The one point where he might got confused is to what is locked and why. I had to recherche that for a Laptop I wanted to fix, and found out that Lenovo is known to lock down the Bios to an absurd degree. My model had an accessible Bios, but you could only change the most basic parameters, like the time. There was some talk about needing to flash another Bios, sadly I found nothing for the specific model I worked with.
But there Linux should've booted, I was trying to change some energy saving settings.
So it might be that this is not a "by contract with Microsoft we locked down the Laptop to only boot Windows", but a "by contract with Microsoft we locked the Bios, which has the side effect of preventing booting Linux because the Kernel does not support yet a specific setting, which will change". Who knows.
It's still a bad policy, and even if it were an accident they have to fix it. They can not be allowed to prevent Linux from booting.
It is entirely possible that Microsoft asked for them to be locked down.
While OEMs try to spin crapware as a value add for the consumer, it's actually paid product placement. The OEMs make money off of installing crapware on your PC.
So, if the Signature Editions don't have crapware then that eats into the OEM's profit margins. What incentive do OEMs have to deploy the Signature Edition? Does Microsoft offer it at a lower cost? Do they pay OEMs to make Signature Editions?
It's entirely possible that if Microsoft is selling the Signature Edition for less or even paying OEMs to deploy it, then they might also make greater demands about system configurations and even ask that the devices be locked.
Microsoft requires Secure Boot on all Windows machines but only requires locked firmware on Mobile/RT devices. It's possible they could require locked firmware on Signature Editions as well.
The website is down from the load, it will come back after a while.
The article is based on many sources, in the original forum thread on Lenovo forums there are many people who faced the problem with other models, some weren't even Lenovo but the problem with Lenovo is that the BIOS is locked completely, those people (using ASUS and Dell laptops) confirmed the problem is solved after the switch to AHCI from RAID.
Have a look lenovo forums [1] (also linked prominently from original article), where OP has following to say:
I am attempting to install ubuntu 16.04 on my yoga 900.
The bios can see the 512 gb samsung hard drive and so can Windows.
The ubuntu installer can not see it at all.
...and first person to reply adds:
I have the same issue with the 900S model.
I have tried the newest kernel 4.6 but linux doesn't
even list the pci express device in lspci.
So no, positively not the 3.2.x kernel to blame here.
Right. Thanks for that. I am reacting to the claims that it's "locked by Microsoft". This looks to be missing Linux support for an Intel device. Sad, but not unusual.
This article could certainly use some clarification. I bought a Lenovo Yoga 500 two weeks ago and had no problems whatsoever with installing Ubuntu 16.04 after setting the UEFI to 'legacy' and nuking the complete drive after making a disk image backup for warranty purposes.
Did I dodge a bullet here? It came with Windows 10, but perhaps it wasn't this 'signature edition'.
That's a total different thing, I did the same with my Lenovo G50-80 laptop, but the problem with the model in the thread is the Signature Edition and the BIOS lock, it's different from normal UEFI stuff.
Microsoft has already used SecureBoot to <s>lock out Linux</s> 'offer better security' on their phones and tablets. Is it really such a stretch for people to be afraid that they're going to require desktop/laptop vendors to leave SecureBoot on in the future? (and conveniently only recognize the key for Windows?)
Probably our best saving grace against that is how rapidly mobile is cannibalizing the desktop/laptop market. Probably not even worth the antitrust probes in Europe to attempt that anymore.
But I don't blame people for being immensely skeptical given Microsoft's actions on mobile. Best case, we're paranoid, PCs end up fine. Worst case, PCs are locked down, and "I told you so" won't help reverse it.
Yes, I do think it's a stretch considering their agreement with OEMs requires OEMs allow for diabling SecureBoot and require allowing users to enroll their own keys.
The PC market and mobile phone markets are very different, with a huge precedent already being set that mobile ARM devices are locked down. Are you equally upset that iPhones and virtually all Android devices also have locked down bootloaders?
On top of this, Microsoft cross signs the keys used to sign the Linux bootloaders so that they work out of the box even on computers that have only the default MS keys enrolled.
Considering that most people fail to grasp those two salient points when presenting their conspiracy theories... yes... I feel comfortable dismissing most of them out of hand.
> their agreement with OEMs requires OEMs allow for diabling SecureBoot
Nobody ever goes from one extreme to the other. Restrictions are added a little at a time to minimize the outrage.
Look at Gatekeeper on OSX. "Oh it's just an option", then it's enabled by default. "Oh you can just turn it off." Now it automatically turns itself back on every 30 days. Their next move will likely be to require all apps to be signed. Again, if I'm wrong, great! As someone who releases OSX software but won't pay Apple for the privilege, I hope I am.
Further, you don't always have to go 100% restrictive to achieve the same effect. Look at web browsers and self-signing certificates. Sure, you can still accept and install them, but it's been made such a pain that nobody can really pull off a self-signed website.
What serious OSX developer is going to release unsigned software that requires people to go in and turn Gatekeeper off every 30 days? It might as well be mandatory for all the choice developers looking to earn a living on that platform have these days.
> Are you equally upset that iPhones and virtually all Android devices also have locked down bootloaders?
Yes! There's not really much of a market for alternative phone operating systems; but even still, I buy Android because I can sideload regular applications without hacking ("jailbreaking") my own property.
That Linux lacks drivers for something and Microsoft somehow got the blame for it as part of some grand conspiracy? Certainly predictable for /r/linux. I thought HN was better than that.
I have a recent X260 running Fedora 24 and I'm very happy with it, and with Fedoras support. I use both smartcard and 4G data module with it. Only thing I don't use is the fingerprint reader.
Only sad bit is that I had to disable SecureBoot to run VirtualBox. I would have happily signed the VirtualBox kernel modules if it wasn't for Lenovo missing a small detail in the implementation of the UEFI spec that enables users to write their own MOK.
But Linux doesn't care and lets them run. Unless you mean those on the Windows side. In which case - why does virtualbox honor bios settings of the host machine?
No, it doesn't, at least on Fedora[0]: “When Secure Boot is enabled, the EFI operating system boot loaders, the Fedora kernel, and all kernel modules must be signed with a private key and authenticated with the corresponding public key.”
I said I was running Fedora 24 on an X260, implied that it's on metal.
However, I also want to run VirtualBox inside Fedora, because my job requires me to have a Windows VM. And VirtualBox has its own kernel modules, with SecureBoot they need to be signed. Unfortunately the poor UEFI implementation Lenovo has provided won't let me enter my own MOKs into the UEFI because coincidentally that little write call is missing.
I dunno, tinfoil hat surgically implanted under my scalp, it feels like they're not making it easy for Linux, when the Linux community is doing their best to adapt to SecureBoot.
Edit: And just to be clear, I did of course disable SecureBoot at this discovery but it was sad to do so because I had hoped to see how well Linux had adapted to this new tech that came out several years ago and was heralded as a Linux blocker. ;)
I've been leaning that way lately, having only just tried kvm virtualization on a server at home.
The discovery of kimchi made me try KVM and it's a very nice web gui for home use, or laptop use. So yes I might just replace VirtualBox with kvm soon. I just have no experience with the guest drivers for Windows provided by libvirt.
Supposedly Intel's NVMe variant of Rapid Storage Technology is currently unsupported on Linux. I find this puzzling because conventional RST doesn't really do anything that matters to the OS other than changing the AHCI controller's id, so Linux "support" is trivial. But conventional RST relies on the PCIe target being on-board and, with NVMe, the target is the SSD itself, so I don't fully understand what the newer NVMe does.
My laptop won't even POST with RST on, so I can't meaningfully experiment.
Just out of curiosity, what's the rationale for MS & Lenovo to do this, why to risk PR? The number of people wanting to install Linux is marginal and they are already "on the wrong side".
It is not gibberish. They put it in quotes to imply that it is not literally true that they are on the wrong side, but that for the purposes of Microsofts efforts they are on the wrong side in the sense that they are not Microsoft customers and are not likely to be swayed by this or anything else so they are not worth targeting for Microsoft.
So the only real outcome from this would at first glance appear to be to antagonise people who won't consider their product either way and cause bad PR.
The question is if there's any other/better rationale.
Ah, thanks for clarifying. Guess it was my impulse reaction as a long-time Lenovo + Linux user / dev. Should've asked before jumping the gun too soon. Sorry, Yaggo.
Today in 2016, Linux is the superior platform for both user-friendliness and stability. It is easier to use and install on a wider variety of hardware. The old belief that Windows is "easier" is deprecated, and it is time to change the conversation to reflect that truth.
I think it should be considered that the vast majority of Windows systems are pre-installed and pre-configured out of the box. If this were the case with Linux, there might be an argument. Most Windows users couldn't easily install, configure and use, e.g. Server Enterprise Edition. Likewise, I doubt Gentoo would be a common candidate for ease of use. The various *buntus have really come a long way in regard to user friendliness, maybe far enough.
That was part of my reasoning. Installing Windows is a huge pain in the ass compared to installing Linux. If you need a service pack you have to go to their website, the download links are always difficult to find and buried under walls of text that nobody cares to read. And there's always a chance that the download link simply won't work for some stupid bureaucratic reason, such as "Use Windows Update". And if Windows Update fails, you're really SOL.
In Linux, if you're missing something it's a simple matter of "apt-get install something" and it almost always works. The rate of failure for Windows updates and installing proper drivers and software in windows is much higher.
And Linux is far more likely to work out of the box on most hardware. Windows installs never have more drivers available than what ships on the CD/DVD. With Linux Net Installs, as long as your Ethernet is supported, and it probably is supported, the rest of the system will be up-to-date.
I have recently installed Windows 7, Windows 10, and Linux, I've used each for a number of months. Linux was the easiest and friendliest. I've been using Windows for years so I'm not a newbie, it's a terrible operating system.
This failure to innovate presumably includes touch screens, Windows Hello biometric sign-in, running sandboxed apps from a Windows Store, integrated Cortana AI, Notification Center, cloud integration via OneDrive, Continuum mode, Device Guard, Universal apps that work across PCs, tablets, phones and the Xbox One, Xbox app for streaming live games to a PC or Tablet, touch-optimized Office apps on Windows, iOS and Android, and half a dozen other things.
So I understand that these features took a great deal of engineering effort, but except for sandboxing I have zero interest in any of them. So maybe it's innovation, but I don't see a whole lot of innovation that I care about. In particular, many of these features deal with touch interfaces, which I have no desire ever to use for serious work. And why would I ever run Windows if I didn't have to for work?
It would still be useful to distinguish between innovations that hundreds of millions of people use -- including me -- and your personal requirements. Sadly, the whole IT world does not actually revolve around those ;-)
Sure, and I'm careful not to impose my value judgements about whether an innovation is actually interesting to the question of whether it's an innovation. But personally I find that improving touch interfaces is this decade's version of adding a wheel to the mouse.
You said Linux was "a real threat, especially with MS failing to innovate."
This was an unrestricted claim that ignored a massive amount of Microsoft innovation. I pointed out that you were wrong and now you're quibbling about another of your personal opinions. Why make the same mistake twice?
Seems to me that the whole Microsoft Windows ecosystem -- across Azure, PCs, games consoles, smartphones, and iOS and Android devices -- shows far more innovation than Linux.
If you want to provide a list of Linux innovation to compare with my incomplete list above, I'd be interested to see it.
Be even better if you could address the whole market, without restricting it to your personal peccadilloes.
> You said Linux was "a real threat, especially with MS failing to innovate."
You're quoting somebody else there, friend. I jumped on this particular subthread because I wanted to point out that your list of innovations boils down to "Microsoft improved the user interface for touch devices."
> your personal peccadilloes
Peccadilloes? I do not think that means what you think it means.
> I jumped on this particular subthread because I wanted to point out that your list of innovations boils down to "Microsoft improved the user interface for touch devices."
No, it doesn't. I use most of them on a desktop PC that doesn't include touch. Also, cloud and cross-platform capabilities go beyond touch.
> Peccadilloes? I do not think that means what you think it means.
I know what it means. And in the UK, it's not specifically sexual in connotation. However, I did spell it wrong ;-)
Microsoft wants to kill "old" hardware and force you to use only the one they've certified, so they don't have to support 2 years old CPU and GPU, backport changes to between Windows 7 and botnet10. If they can force hardware manufacturers to lock hardware to only certain software, and apparently they can, they won't need to port drivers back to archaic to Windows 7 or 8. You will be forced to use 10.
It's not that users would want to install Linux (historically, they don't know or care about the OS), it's that a manufacturer might want to either to reduce costs or differentiate their products. In today's browser-focused world that's not too much of a stretch to envision happening at least on some low-end/consumer devices... for a start. Want to see what that looks like for Microsoft? See Microsoft's mobile market share...
I guess they just wanted to lock out Windows 7/8. They don't gain anything by denying Linux to a few people. But preventing that the buyer can downgrade to Windows 7 fits exactly to their strategy and makes sense for Microsoft.
Also, an agreement to lock out Linux might not be legal from an antitrust perspective, whereas an agreement to restrict usage to the current version of the OS is much less critical.
The app store, Cortana and Edge (with Bing as standard search engine) are closely tied to Windows 10. That's where revenue will come from in the future, not from licenses.
Money, lots of money. Microsoft gives away special deals for OEM versions of Windows that cost manufacturers of devices peanuts in comparison to the ordinary pricing. I've heard figures like $20 per Windows license.
So people have suggested in the past that Microsoft might ask for favours in return, basically telling OEMs that if they do not comply they might loose cheap OEM versions or even all access to OEM version of Windows, which would make their products unfit for competition.
Other people have suggested that this would be illegal, that Microsoft would never do something as anti-competitive like that, and that Microsoft just gives away nicely priced OEM versions of Windows to manufacturers because they are really nice guys and want disseminate their products even if they don't earn much from them.
By "might", you mean of course "repeatedly demonstrated in court, and we have piles of source documents substantiating the claim submitted in discovery".
The year of Linux on the desktop was 2007. That's when netbooks first showed up, and manufacturers put them out with Linux on because an XP license cost so much relative to the cost of the gadget. This was the first time MS had to treat Linux as an actual direct competitor.
True. And Microsoft responded with a ULCPC (Ultra Low Cost PC) version of XP that cost them $11-$16 or so -- which they could easily get back by installing crapware.
This left Linux with no cost advantage on parts, or a negative cost advantage, if you added more crapware.
The much higher costs of shipping Linux then killed off the Linux netbooks.
The higher costs included extra testing and parts qualification, extra shipping and advertising costs, and, in particular, massively increased support costs. (One Linux user support call wiped out the profit margin on multiple sales.)
Right. Obviously there is some justification, but if you hung out at slashdot way too long, you'd know there is a bunch of paranoid schizophrenic people manufacturing bizarre Microsoft conspiracy theories every single day.
The post even describes the issue pretty explicitly as "Linux isn't loading the correct disk driver", yet it still spun as some intentional FU "block". I guess with a domain like "fossboss.com" you should expect the lowest form of the Slashdot mentality. I very much hope HN doesn't start to deal with this sort of pure flame bait.
Which is more likely? That Lenovo shipped a crappy BIOS, like plenty of OEMs have done before? Or that Microsoft is engaging in a covert conspiracy to block Linux users via forcing Lenovo to put the HD into Intel RST mode rather than ACHI?
It just doesn't make a bit of sense. If Microsoft wanted to block Linux, they would just require that SecureBoot not be disabled and require disablement of user key enrollment.
Besides, a clean copy of the Windows installation media doesn't boot normally either unless you slip the Intel RST driver into a custom built version of the install media.
This is just another conspiracy that I don't think makes any practical or logical sense.
Seriously, though-. If Microsoft blocked Linux overtly, they probably couldn't get away with it so easily; they'd end up with a PR disaster and/or an antitrust lawsuit. Plausible deniability helps them; now you can bet some people are going to say "come on, firmware screw-ups are no news, what are you, some kind of conspiracy theorist?" I mean, they have already taken advantage of ACPI in this way once.
(Tongue in cheek. It's not so totally implausible.)
>It just doesn't make a bit of sense. If Microsoft wanted to block Linux, they would just require that SecureBoot not be disabled and require disablement of user key enrollment.
Their modus operandi is to violate their antitrust agreement with the DOJ as non-obviously as possible with a nod and a wink and funnel campaign contributions to the relevant parties. If it becomes too blatant, however, the DOJ will be forced to punish them.
> Lenovo for example confirmed that they singed an agreement with Microsoft for this.
If true, it's illegal product tying, and those who signed such "agreement" are violating antitrust law. Someone should sue them until they stop doing this. Lenovo are infamous for refusing to refund Windows tax until brought to court, but this is a new low for them.
Preinstalled software you can (probably) quite easily uninstall is slightly different though. I personally don't care what the computer comes with, as long as I can reformat and reinstall a new OS.
It is a different situation, IMHO. The guy purchased a Sony laptop with a Windows license, and pretended that by refusing the EULA he was entitled to getting the cost of the Windows license refunded. Sony refused, offering instead that he returned the laptop for a full refund. The guy refused and filled the lawsuit.
Seriously. If this does turn out to be intentional on Microsoft's part, then there goes every last shred of trust and goodwill they've spent the last 10 years rebuilding.
(and, honestly, were finally succeeding at, to the point where I'm very close to willing to give them the benefit of the doubt here: how the hell could the benefits of such a thing come anywhere near to outweighing the amount of damage it would do?)
Meh. For me, the last drop was "You WANT the X, admit it! (Not like you have a choice, we force-upgraded your computer anyway, no matter what you chose)" This is just Business As Usual.
They might be misguided. Until there's an official announcement one way or another, I wouldn't pay too much attention to some random Lenovo customer service guy.
Right, but there isn't going to be an official announcement, unless a hundred thousand people jump to premature conclusions and bring out their pitchforks. I agree that it's not terribly smart to draw a conclusion at this point in time, but it's potentially more malicious, if we don't.
Regardless of whether such an agreement exists, and regardless of whether it's a secret if it does exist, I still have my pitchfork out. Lenovo had already lost my good will for their various other shenanigans over the last couple of years, but locking down the machine in a way that makes it impossible to install an alternative OS has decisively lost them my business.
"of course Apple and Sun can sell computers, but not to the two most lucrative markets for computers, namely, the corporate desktop and the home computer."
- Joel Spolsky, 2004
Well, with around 8-10% today (9.6% according to StatCounter), Apple which targets higher-end, higher-margins gets most of the profits from the home computer market, at least in the US.
It is also doing quite well recently in the corporate desktop (see IBM adopting Macs, etc). Heck, they almost dominate the "startup founder/employee" desktop, as well as the "university student" desktop.
>gets most of the profits from the home computer market, at least in the US.
Do you have a source for this? I know it's the case with their phones, but they also have a much larger market share there. It's hard for me to believe they get "most of the profits" from the PC market with their minuscule share, especially when their computers are competitively priced.
Source? It has been reported again and again, along with the relevant stats. Examples:
Apple sells 5% of the world’s PCs and takes home 45% of the profit. (1)
During the recent third quarter, Apple commanded a 7.5 percent share of the computer market, up from 6.9 percent a year ago, IDC said. That was enough to move Apple up to No. 4 in market share for the computer market, pushing past Acer, which is now No. 5. (...) Each of the top five personal computer makers suffered a decline in total shipments, but four — Lenovo, HP, Dell and Apple — all captured a larger share of a shrinking market. (2)
* Apple's total share of the global PC market grew to 7.4 percent in the first quarter of calendar 2016, good for fourth place globally, according to IDC. That's up from 6.7 percent in the same period a year ago. (3)*
In fact Apple has such high per-PC revenues that it’s actually now the third-biggest PC maker by revenue – excluding Dell, because we don’t know what Dell’s revenues are, because it is privately owned. (4)
So, add a distro's keys (to the firmware) or use a distro signed with the default (MS) key.
Or get those Linux community to organize, and establish some body to create, and secure, keys for Linux that will be installed by default alongside MSs.
As someone who suffered from at least a couple BIOS-based malware back on Windows PCs back in the day, I'm all for securing the bootloaders...
A centralized key is not secure. A secure key is not centralized. If you want any security, the computer owner must be the only person allowed to install keys on the boot sequence - what is the exact opposite of what MS mandates.
>Or get to learn something about key management. A centralized key is not secure. A secure key is not centralized.
A centralized key IS secure, just not AS secure as a not private key.
(That's theoritically: in practice it can be even safer than a private key, because most end users are incompetent in managing their keys much more than the central entity would usually be).
And it's wrong to think it as a key in the sense of a physical key. It actually used as a signature.
You can't have "private signatures" because the very purpose of a signature is to verify that the thing it signs is signed by a specific (and in the case of operating systems, central: the vendor) entity.
An OS the user signs itself is worthless, as the OS data he signed could have come from anywhere or tampered, etc, before the signing.
Let your wallet do the speaking. It's an open market and you have the choice of just buying from Lenovo's competitors - 'they' will then realise there's value in not doing this.
No they won't. Lenovo doesn't care about losing you guys as customers, they care about the companies who buy thousands of the damn things so their employees can run Excel on Windows.
You are probably right but the PR backslash could make them think twice before doing the same thing again. So it's still worth complaining and, why not, buying from somebody else and be very vocal about it. For sure, after SuperFish and this I won't consider or recommend Lenovo anymore.
I don't disagree with you, but nor do I particularly care about losing Lenovo as a supplier.
If Lenovo lose customers over this, it may be the case that they won't care, but in that case a competitor will surely swoop in to catch those customers by supplying PCs that run Linux.
In any case, the market should continue to supply machines that run Linux, as long as there is a demand for them. So if you demand a machine that runs Linux, just vote with your wallet!
C'mon, have some class. You're really going to co-opt a quote decrying war crimes and genocide to complain about not being able to install an alternative OS on your hardware?
With closed source software, such as the firmwares and MacOSes of the world, it is impossible to have 'checks and balances'. Yet without computers to run and develop open software on, it is that much harder to create alternatives to those closed systems.
I think this is very much a sliding scale. And that therefor the quote very much applies.
I'm still a bit flabbergasted: you really truly believe that disallowing installing Linux on a particular brand/model of laptop is directly comparable to the forced labor and extermination of millions of Jewish people during WW2?
I reluctantly comment here, but.. The misuse of technology (see: end of encryption; end of privacy; end of freedom; slippery slopes, etc.) could (by my perspective) lead to massive problems, including political/ideological persecution. However, "directly comparable" it probably isn't, yet.
If (IF) a time comes when the only software available is proprietary, restrictive, invasive and possibly insecure, in a world where software is ubiquitous and often essential, I think that could be bad. The definition of fascism does come to mind.
I suspect a three-letter agency or two may be taking some steps, certainly not impaired by telemetry, backdoors or hording vulnerabilities - all of which I sort of prefer to try and avoid by using the OS and configuration of my choice.
Of course I do not believe it the way you portray it. It is called a 'sliding scale' for a reason, my friend. A 'slippery slope'[0], if you will. Completely different from 'directly comparable'.
At the top of the slope, it's "merely firmware, what is the problem?". At the bottom of the slope are warcrimes and genocide. It is very hard to stop sliding down a slippery slope once you've started.
So when you disallow Linux on a laptop you are very much at the top of the slope. And there is a long way to go. But my, oh my, it sure is slippery.
Because we live in a digital age. More and more so. And in this age, there is no way to have 'checks and balances' without access to the source code of the software. And without checks and balances, it is very hard to have Separation of Powers[1].
Interestingly enough, I've found that survivors of WW2 tend to understand this better than most.
There's no need for every slippery slope argument to make an allusion to the genocides committed by the Nazis.
Otherwise, "my friend", one invites analogies to Godwin's law, and rejection out of hand for using a reductio ad Hitlerum.
People make slippery slope arguments all the time, but often (and quoting your [0]), "as a form of fear mongering, in which the probable consequences of a given action are exaggerated in an attempt to scare the audience. The fallacious sense of "slippery slope" is often used synonymously with continuum fallacy, in that it ignores the possibility of middle ground and assumes a discrete transition from category A to category B. In a non-fallacious sense, including use as a legal principle, a middle-ground possibility is acknowledged, and reasoning is provided for the likelihood of the predicted outcome."
What was missing, in the recasting of Niemöller's poem, was the 'reasoning ... provided for the likelihood of the predicted outcome'.
I believe control and misuse of computers will have everything to do with the next genocide of that scale and had a bit to do with that one. I also believe genocides like that start with an alignment of corporate interests and government interests against individual privacy interests.
Certainly bugs in Telegram and the use of the wrong social software among dissidents (or software that unknowingly leaks, or is endemic like windows) has everything to do with how they are spied upon. Many of those dissidents are from ethnic minorities that are targeted or will be targeted.
The holocaust was a terrible thing, but not talking about any road signs to the next genocides to avoid upsetting people isn't the prevention mechanism my history teachers had in mind.
Come on. Do you really wan't to demonize people from using allegories?
User languagewars is in good company. Orwell compared early dissidents in USSR to chickens in his Animal farm. Jesus compared Kindom of Heaven to mustard seed, himself to wine and bread, redemption to finding a coin and true faith to freaking oil lamp. Plato compared whole human existence to group of dudes sitting in a cave. Socrates compared himself to gadfly.
This is one of the most used literary vehicle. By the best and most famous thinkers of all times.
This is probably the standard "firmware is sending different data to different OSes", which has existed since forever. Or maybe it's just a shitty firmware bug or even a kernel bug.
However, I'm glad this is making this type of fuss. It means bad PR for Lenovo if they don't do any Linux QA (as they mostly never did). Good.
Something like tradition. The IBM PC has been an "open" system since the late 70's. Tablets etc (palmtops!) started appearing in the 90's, and were walled gardens from the get go.
That was the whole thing about PCs - if my memory of Cringley's "Triumph of the Nerds" serves, the genesis of this category was IBM rushing to a market where other "closed" vendors such as Apple were already established. It wasn't that PCs were open "by design" but more that they did things quickly and gathered other vendors "off the shelf" notably Microsoft and Intel, and had a copyrighted "BIOS" holding the whole thing together. Once Compaq reverse engineered this BIOS (through some legally clean techniques) the market was blown open to the clone manufacturers and Intel and MS were happy to play along since at the end of the day they were just shipping more units .... probably couldn't do it these days due to DMCA and other modern copyright legislation in other jurisdictions.
We're still waiting to hear what's acceptable in terms of "fair use" but yeah I guess reverse-engineering to create a competing clone probably wouldn't be covered :)
You're both wrong. The IBM PC was made by IBM in 1981 and it was absolutely not open. (Just hurriedly implemented using commodity parts so, other than the BIOS, it was pretty easy and legal to copy most of it) Then Compaq came along in 1982 and sold a clone of it... and in some ways it was even less open than the IBM. Neither one of those companies had any interest in the PC being 'open'.
It was the 3rd party suppliers (i.e. BIOS by companies like Phoenix, Award, AMI along with motherboard manufacturers etc.) selling picks and shovels to the would-be prospectors (i.e. clone assemblers) that allowed for the 'open' PC standard. For example, there was a company call PCs Limited that licensed AMI BIOS so that they make some IBM clones... they did kind of OK and soon renamed themselves Dell...
I think so. Compaq just proved that it could be done without being bankrupted by an IBM lawsuit. IBM was the 800lb gorilla like Microsoft was in the 90's or Apple/Google are today. Being sued into oblivion was the real fear, not that it was technically a difficult job.
Some of the other companies I mentioned were the ones that followed Compaq's lead and did their own clean room versions which they then sold to everyone else who came flooding into the market.
As an aside, this was actually a problem for the first few years: take multiple independent clean room implementations, bake in some silly things that the manufacturers did with them (gotta customize, right?), and combine it with the bad programming practices of the day (i.e. programs written in assembly doing jumps into undocumented portions of the BIOS because, hey, it worked on the IBM and saved a few bytes/cycles or did something useful...) It was similar to how well web standards worked not too many years ago with multiple browser implementations doing/interpreting things slightly differently and developers doing things they shouldn't because they could... and that was with a public spec designed to be copied. Eventually things get worked out, but both had a rough start.
Just a nitpick - Spectrum was pretty open (at least if we are talking about 48/128). My father bought us Spectrum specifically because it was more open than alternatives (Atari or Commodore), and he later bought the PC for the same reason (and I would never buy a Mac for the same reason).
Unlike its competitors, Spectrum had standard phone jack connectors for sound and magnetic tape recorder (so you could use any recorder). It also had a direct circuit board connection to the system bus on the back, and the schematics were available. My father built us the 8255 interface to have joystick and other peripherals connected.
Actually, that was pretty doable too. Later, my father bought D40, which was a 5.25 inch disk unit produced by Czech company. The D40 had its own 16kB ROM which got mapped instead of the standard Spectrum ROM when NMI was invoked (the D40 ROM contained code to handle the disks). So it was totally possible for an external device to remap original ROM with something else, even RAM.
Regarding the RAM remapping: There was Didaktik Gama (made by the same company, that made D40), that had 80kB RAM. It was done by switching the 32768-65535 address range between two banks.
There wasn't an OS to talk about. The 16kB ROM contained a BASIC interpreter, which was ignored by most applications you would load from the tape. If you wanted to talk to the hardware (joystick, printer), you did the I/O yourself.
Not from inside; but an external device could remap the address range (not that it was made often, except for D40/D80 which did that, replacing microdrive code with a floppy one) and the ZX128, which actually had two ROM banks.
There weren't many useful things in the ROM, if you were writing your application. Maybe the font table and tape loader. On the other hand, if you were able to ignore the ROM, you got few bytes more of RAM, because you were able to repurpose the "system variables" area.
The biggest "problem" with ROM that you were unable to replace it with RAM (until next reset, for example), thus taking precious 16kB out of 64kB address range.
When was it okay to prevent me to do what I want to something I own ? Absolutely never ever. Region locking of DVDs, DRMs of all sorts, smartphones locking are plain, shameless abuse.
It's however particularly unacceptable to lock down what used to be open.
Is worth saying that for most things, you buy them in the state they're in - there's no "right" to openness, as much as we might want it. Just because you own a house, doesn't mean you can just put a 6 storey extension in the garden.
Then tension is that we've almost always been able to install Linux on standard Windows machines and so have gotten used to it being open, but I'd be loathed to say (if the manufacturers have decided to make it tricky deliberately or just not thinking) we have a fundamental right to do it.
But there is a right not to buy this stuff and a right to tell other people not to buy it, too. There is also a right to tell the vendors how much you abhor them for selling such closed products and there is a right to tell journalists or other people why buying closed products is a really bad idea. And you have a right to lobby to make producing/buying closed products socially unacceptable.
Exactly. If you want openness then tell the manufacturers you want openness and people can put their money where their mouths are, however, I still don't believe expecting it as default when exceptionally few people (relatively speaking) ever have or will, is an entirely rational thought process.
Interestingly alcometer locks on cars and speed limiters are very rare. Except for minorities, like truck or taxi drivers. Small groups of voters, so politicians can do what they wish with them.
Seems like it's "okay" when you can get away with it. But not okay when large group of people get some slight inconvenience.
Car speed limiter is completely trivial, cheap and potentially life saving.
"Most Japanese domestic market vehicles are limited to 180 km/h (112 mph) or 190 km/h (118 mph)." Almost twice the common maximum speed limit (100km/h).
It's part of the PC culture, and the Thinkpad/Lenovo heritage as ideal Linux laptops. But you're right, it's no different from what Apple/LG/Samsung/etc. do.
Neither did home computers (Personal Computers), only the IBM PC clones did thanks to Compaq and their reverse engineering process not being invalidated in court.
Well, the IBM PC followed a generation of 8-bit CP/M microcomputers that were pretty much open.... though they were mainly used by businesses rather than home users.
I see the confusion now, by free to modify I meant you can go and replace your operating system, bootloader or hardware. Do you need more RAM, just get some and put it into your MOBO, third screen? Just get it and plug-in. Recently I replcated screen in my laptop to a matt one, keyboard one with harder keys and it all works. When I want to change screen in my phone, I can't only one certain model will work as expected, some models might fix, but they won't support the same resolution, can't upgrade camera or RAM there, so basically, it's not my hardware, I have to use what manufacturer pre-selected for me.
It's not ok, but the way most of us use our devices makes it less ok for PCs because we have far more reason to insist on our own software there.
E.g. with an unlocked Android device, I will typically at most install a different rom that's largely the same as the stock rom. Various small enhancements but nothing I can't live without.
But a PC that can't run Linux is entirely useless to me.
I hope I never have to deal with a locked down TV. Region-locked DVDs are bad enough.
Once, just before Blu-ray was a thing, I encountered a "HD DVD" which was a data DVD containing a Windows Media file. This used the embedded DRM licensing system to call home to a server when you played it, and refused to run if your source IP was not in the US.
> Why is it OK to lock down smartphones, TV devices, consoles, but not OK for PCs?
IMHO, it is not OK to lock down things you own. I have been a victim. I bought an AppleTV v2 and a planned obsolescence by Apple and Google rendered it useless (with a YouTube API version requirement).
PCs are special in that, they are general purpose devices and not appliances. If you are using it as an appliance, chances are, you are not interested in running another operating system on it.
The other HN thread suggests this not actually a dark conspiracy by Microsoft but simply a case of missing linux drivers for the storage devices.
This sounds believable to me. But I'll put my tinfoil hat on just for fun and pretend it was an intentional move. Could this make sense as a new twist on the old strategy, making it "Embrace, Extinguish, Extend"?
With the WSL, they made it theoretically possible to run Linux software on Windows. With that in place, locking existing users out of Linux might cause a lot less negative backlash as the users can still continue to use their old programs - except under the supervision of Windows. If this catches on, it could actually allow Microsoft to grab some if the more consumer-oriented parts of the Linux ecosystem.
If you read the original reddit thread, you would understand that this is not just a drivers issue. Lenovo intentionally programmed their BIOS so that it reverts any changes to RAID mode making it impossible to install Linux.
RAID on a machine with a single SSD (and no provision to add another)? It'd make far more sense if the BIOS was setup so the RAID option was always disabled.
Edit: it'd be rather amusing and saddening if this whole controversy was caused merely by someone misunderstanding/misreading a perfectly sensible requirement to disable the RAID mode, and instead disabled the other options. Given the level of communication fluency among some programmers, I would not be surprised if this were the case; and the fact that the machine still boots into Windows because it has drivers might've let this slip past QA...
The choice seems to be between AHCI and sorta-NVMe, with the latter enabled in 'RAID' mode.
Sure, real/standards-conforming NVMe would be better -- and wouldn't require driver shenanigans in either Windows or Linux -- but there should be a performance advantage to 'RAID' mode in this case.
True - but as the other HN thread (that I can't seem to find anymore ><) pointed out, if Microsoft's requirements were planned as an attack against free software, it would be an unnecessarily complicated and ineffective one: There is nothing stopping anyone from writing Linux drivers for the new RAID mode - and I guess if more models with this setup show up, eventually someone will write one.
On the other hand, Microsoft could have easily gotten a much more "robust" lockdown - by simply demanding mandatory, unchangeable Secure Boot like on the ARM tablets. But they didn't do that.
>On the other hand, Microsoft could have easily gotten a much more "robust" lockdown - by simply demanding mandatory, unchangeable Secure Boot like on the ARM tablets. But they didn't do that.
Didn't you hear that Secure Boot is basically broken?
Can they not modify that BIOS code to not skip those pages?
I'm sure anyone with enough knowledge to decompile a BIOS would have obviously thought of that idea though. I'm guessing the BIOS images are signed or something?
According to a comment there, it's not hardware, it's a BIOS setting.
> I've been able to successfully get past Lenovo's lock through direct bios flashing. I'm looking into better solutions, hopefully I can find a way to do this without an external programmer. I was going to keep people updated from the Lenovo forum, but as this is no longer an option I will keep people updated from here.
I agree completely with that. I responded because I partially disagreed with your earlier statement; I think it misses the point.
It's a locked UEFI setting causing a problem: true. The setting is causing a piece of hardware to behave in a mode not handled by the current Linux driver: also true. So there are two ways of looking at it.
First: It's a software issue that Lenovo should clear up (i.e. remove the locks on the appropriate parts of the UEFI configuration)
Second: It's a hardware issue that the Linux community can address by writing a driver for the alternate hardware mode.
For RAID hardware, it's not that unusual to have a device that isn't supported by standard Windows install media. To install Windows, you'd put the Intel-provided driver on another medium (or slipstream it into the Windows one), and click "load driver" in the installation GUI.
Lenovo apparently wants to treat that computer as an appliance; if someone borks their installation enough that even a system restore won't fix it, it's a call to Lenovo support, and a bill if the machine's out of warranty.
For customers whose Windows installations are working correctly, it's access to a faster, more power-efficient driver. That's how it makes sense, IMO.
More likely, it's a conspiracy against Win7/Win8 users, which hurts Linux users as collateral damage. What likely happened was the ms/lenovo deal was "And Lenovo will make sure win7 and win8 are not supported on laptop", which lenovo solved by switching the hard drive to a mode not even win10 supports, locking it that way (that's the evil part), and putting drivers for it on the lenovo install media, which are win10 only.
Thus, this laptop can only ever be installed from the Lenovo win10 media. No win7, no win8, no retail win10 (for now), and .... probably as a (not unwelcome) side effect, no linux.
I'm speaking of Windows drivers in general. I can't make any specific guarantees for these particular drivers, but I don't see why they should be different.
Not at all. To be effective, it doesn't need to stop a very determined user (as evidence, someone reflashed the bios so they could install Linux).
And it does effectively stop users from installing Linux, Win7, Win8 and even Win10 - except from the provided Lenovo install media; which makes Microsoft happy (no Win7/Win8) and Lenovo happy (full control of installed versions).
A serious question: What gives Linux users the right to expect that Linux will run on any given PC / laptop?
Think about it. These PCs/laptops are designed to adhere to Microsoft's Windows PC hardware standards doc (which was never, ever an open standard) and, with few exceptions, only tested against various versions of Windows. Linux users are failing to receive a feature that they were never promised in the first place so it's unclear that they have any valid cause for complaint.
Perhaps Linux, BSD, etc. users should be creating their own PC standards doc and asking OEMs to adhere to it instead?
I get your point; I don't buy an iPhone and then complain when it won't load android. however, I've been able to load linux on almost any laptop I've bought for the last 20 years, so they are making a significant change here, and haven't made it particularly widely publicized.
What gives Linux users the right to expect that Linux will run on any given PC / laptop?
Nothing. It's very well possible that in future, we have Apple devices that only run iOS, Google devices that only run Android/ChromeOS/Whatever and Microsoft devices that only run Windows 10 - and a large server market with a tiny consumer segment of devices that run linux.
We'll all be fine in that world. We just won't have any control about our devices anymore.
Perhaps Linux, BSD, etc. users should be creating their own PC standards doc and asking OEMs to adhere to it instead?
That's actually a good idea in theory - so far that "standard" had been the x86/x64 IBM compatible PC. Except that I fear they lack the market power to actually make such a standard more than a stack of paper. You'd need an OEM network the size of Microsoft or enough capital and brand trust so you can make your own devices. I see neither for linux.
Does that include your cable company DVR, your PS4, your doorbell, your wifi-enabled refrigerator, your thermostat, and the 50 other devices in your home that contain (or are) computers?
Personal computers are perceived as the last vestige of this sort of freedom in a consumer product, hence the outrage.
None of those other examples are sold with the intention of the user changing the system in a way unexpected by the vendor.
PCs are supposed to be open-ended, and for this you typically pay more for the hardware capability than a product which serves as a gateway into a walled-garden ecosystem (phones, gaming consoles, etc.)
Any cpu in my household is mine (presumably.) I don't care what peripherals it has, it's just a computer.
From my POV all those devices are just computers with various peripherals. I don't see any way in which attaching a specific peripheral changes the universal nature of the cpu.
The laptop supports a Linux-compatible option, and effort was expended specifically to disable that option. If some hardware isn't supported by Linux drivers, that's understandable. If software is added to restrict the modes that the hardware is allowed to operate in, and the restriction wasn't disclosed at the time of sale, I'll return the hardware, because the product doesn't match what I thought I was buying.
If I buy some hardware, I've done research on whether all of its chipsets and devices have Linux driver support just as a matter of course, because I don't expect that Linux will run on every PC. But I feel like I have a right to know if a company puts a non-standard artificial restriction on their hardware. Apparently in this case, Windows 10 doesn't even have the driver included by default, so I can't even reload the software that the machine was designed to run, on my own. That sounds like a defect in the product, to me.
Intel's RAID is implemented in their driver. Switching the option from AHCI to RAID switches the disk controller's ID so it doesn't bind to the OS's standard driver (whichever OS that is), and binds to Intel's instead (assuming it's present). Intel provides its driver (and only for Windows), Lenovo locks the option so that hapless users mucking about in the UEFI settings don't make their machines unbootable.
Lenovo can deny "deliberately blocking Linux", but they can't deny "practically blocking Linux".
If I buy a microsoft windows laptop, I don't expect it to be locked so I can't install.... microsoft windows.
How else am I going to avoid the crapware/malware that lenovo is famous for?
Happens that the same BIOS tweak that prevents windows from working also prevents linux from working.
I don't expect lenovo to spend time/effort accommodating linux, but I also expect them to not artificially limit when I can do with a laptop I purchase.
This might be the case for this particular issue. But in the long term saying no to a deal is not a sufficient defense against freedoms being taken away.
Does anyone own novena or librem? I think they have became worth their prices. They're quite expensive, but you don't have to bother with crap like some day you won't be install Linux or BSD distro because someone loves your hardware too much and want to force you to being spied on.
Are you seriously equating the Novena with Librem? The former is a fully open hardware/software platform built from the ground up with openness and hackability in mind; some assembly required, configure it the way you want to. The latter is a rebranded x86 laptop with Intel's Management Engine firmly embedded and operational; it's a $600 midrange at best laptop being resold with Linux preinstalled for three times the price because it's "open".
Sure. The Novena is not for everyone; it's a hacker's dream laptop but not necessarily a power user's. Still, I strongly suggest not wasting money on a Librem and instead spend a little time researching a good Linux compatible laptop.
The last I heard, Dell still ships Ubuntu on some of their XPS models, and there are a few companies whose business model is based on officially supporting Linux on their own branded machines. System76[1] and ZaReason[2] immediately come to mind, but if you're seeking a fully open machine with no closed source drivers, look to Libiquity[3] for an older but FSF certified ThinkPad. Yes, it's a rebranded Lenovo so it may be a sour choice given the subject of this article, but it's a solid buy if you don't need today's CPU power. Ditto Minifree[4].
Somebody managed to circumvent the problem on a Yoga 900 by flashing a new BIOS which allowed access to extra configurations. Some soldering required. The details start at https://forums.lenovo.com/t5/Linux-Discussion/Yoga-900-13ISK... Check the link to imgur in that post. Not for the faint of heart. There are other posts with extra details from the same author in the next pages of the forum.
Lenovo again. As if the recent thinkpad scandal was not enough.
Incidentally I know of another company that went to bed with MS and it didn't work out very well - enter Nokia.
493 comments
[ 0.18 ms ] story [ 279 ms ] threadQuoth BaronH:
> Nope. You can turn Secure Boot off on the Lenovo Yoga models that this affects.
> They have the SSD in some strange "RAID" mode where Linux can't see or be installed to it, and neither can Windows unless you add some drivers to your Windows installer media. They removed AHCI mode from the BIOS. Then they wrote additional code so if you try to toggle it to AHCI mode with an EFI variable from EFIshell, it immediately sets itself back to RAID.
> For the last 11 months, they were silent on why this machine was configured this way. The only reason we know why now is because Lenovo answered my Best Buy review by stating it is locked due to the agreement they signed with Microsoft for the Signature Edition PC program, so it's very likely that all Ultrabooks in the Microsoft Store, and some outside the MS Store (such as at Best Buy) will eventually be configured so that Linux can't be installed, even if there are some now where you can install Linux.
> So consider "Signature Edition" a warning label that means "You aren't allowed to run Linux, per Microsoft.".
[1] http://imgur.com/a/niewu
[2] http://www.theverge.com/2016/1/16/10780876/microsoft-windows...
Maybe because good-old-IDE or even AHCI was too simple and open.
http://webcache.googleusercontent.com/search?q=cache:fossbos...
The article looks dangerously uninformed, from a brief skim.
It's based on https://www.reddit.com/r/linux/comments/53ri0m/warning_micro...
I can't find any info on what SSD the Lenovo Yoga uses but if it's anything like the NVMe drive in my Dell XPS, it's just the way the card is set up.
Depending on which kernel your installer is using it won't see the NVMe drive as it simply has no drivers for it.
Of course Reddit has gone off without anyone actually confirming what the issue is. Microsoft would be smart to come out with a statement on this if it picks up any steam.
Now, of course the rep might be mistaken. We need official clarification from someone higher up. But we won't get that until we go off on one and this goes viral.
It is not up to the rest of the world to divine meaning from Lenovo's PR policy. If they are happy to allow nitwits to make public statements like that, they should be fully prepared to handle the fallout.
> Thank you for confirming it is still not possible to install Linux on Yoga 900-13ISK2 systems.
> This issue has been escalated to the Development team. I am unable to offer a timeframe for fix at this stage in the investigation. With previous cases, BIOS fixes have been delivered anywhere from several weeks to several months.
> I will post again when I have more information on the investigation.
One user Bownairo confirmed that changing the drive to AHCI mode did fix the problem by allowing the drive to be recognized in Linux, after manually flashing a modded BIOS by soldering chip programming hardware:
https://imgur.com/a/ox4Ey
I wonder what it'll take to get Linux to see the drive in RAID mode.
djpohly and the BIOS hackers deserve some credit too for their REing:
https://www.bios-mods.com/forum/Thread-Request-Lenovo-Yoga-9...
Conditional flag locking users out of the Advanced settings page (with the RAID settings) of the BIOS, as shown in disassembled code:
https://lnv.i.lithium.com/t5/image/serverpage/image-id/76843...
You have to go there to see it for yourself. Imagine the way that HN is paranoid of the US government, but then double that and apply it to Microsoft, which makes even less sense. To them, MS is the boogeyman that will stop at nothing to prevent them from being the glorious 1% that doesn't use Windows. It's still the 90's on /r/linux, in many many ways.
I have no serious position on whether Microsoft is currently enforcing secret deals to sabotage Linux, but I'm sure the employee assigned to respond to product reviews would not be given such inside information.
But there Linux should've booted, I was trying to change some energy saving settings.
So it might be that this is not a "by contract with Microsoft we locked down the Laptop to only boot Windows", but a "by contract with Microsoft we locked the Bios, which has the side effect of preventing booting Linux because the Kernel does not support yet a specific setting, which will change". Who knows.
It's still a bad policy, and even if it were an accident they have to fix it. They can not be allowed to prevent Linux from booting.
While OEMs try to spin crapware as a value add for the consumer, it's actually paid product placement. The OEMs make money off of installing crapware on your PC.
So, if the Signature Editions don't have crapware then that eats into the OEM's profit margins. What incentive do OEMs have to deploy the Signature Edition? Does Microsoft offer it at a lower cost? Do they pay OEMs to make Signature Editions?
It's entirely possible that if Microsoft is selling the Signature Edition for less or even paying OEMs to deploy it, then they might also make greater demands about system configurations and even ask that the devices be locked.
Microsoft requires Secure Boot on all Windows machines but only requires locked firmware on Mobile/RT devices. It's possible they could require locked firmware on Signature Editions as well.
The article is based on many sources, in the original forum thread on Lenovo forums there are many people who faced the problem with other models, some weren't even Lenovo but the problem with Lenovo is that the BIOS is locked completely, those people (using ASUS and Dell laptops) confirmed the problem is solved after the switch to AHCI from RAID.
[1] https://forums.lenovo.com/t5/Linux-Discussion/Yoga-900-13ISK...
Did I dodge a bullet here? It came with Windows 10, but perhaps it wasn't this 'signature edition'.
The "issue" that came up today in this article has absolutely nothing to do with SecureBoot.
Probably our best saving grace against that is how rapidly mobile is cannibalizing the desktop/laptop market. Probably not even worth the antitrust probes in Europe to attempt that anymore.
But I don't blame people for being immensely skeptical given Microsoft's actions on mobile. Best case, we're paranoid, PCs end up fine. Worst case, PCs are locked down, and "I told you so" won't help reverse it.
The PC market and mobile phone markets are very different, with a huge precedent already being set that mobile ARM devices are locked down. Are you equally upset that iPhones and virtually all Android devices also have locked down bootloaders?
On top of this, Microsoft cross signs the keys used to sign the Linux bootloaders so that they work out of the box even on computers that have only the default MS keys enrolled.
Considering that most people fail to grasp those two salient points when presenting their conspiracy theories... yes... I feel comfortable dismissing most of them out of hand.
Nobody ever goes from one extreme to the other. Restrictions are added a little at a time to minimize the outrage.
Look at Gatekeeper on OSX. "Oh it's just an option", then it's enabled by default. "Oh you can just turn it off." Now it automatically turns itself back on every 30 days. Their next move will likely be to require all apps to be signed. Again, if I'm wrong, great! As someone who releases OSX software but won't pay Apple for the privilege, I hope I am.
Further, you don't always have to go 100% restrictive to achieve the same effect. Look at web browsers and self-signing certificates. Sure, you can still accept and install them, but it's been made such a pain that nobody can really pull off a self-signed website.
What serious OSX developer is going to release unsigned software that requires people to go in and turn Gatekeeper off every 30 days? It might as well be mandatory for all the choice developers looking to earn a living on that platform have these days.
> Are you equally upset that iPhones and virtually all Android devices also have locked down bootloaders?
Yes! There's not really much of a market for alternative phone operating systems; but even still, I buy Android because I can sideload regular applications without hacking ("jailbreaking") my own property.
That Linux lacks drivers for something and Microsoft somehow got the blame for it as part of some grand conspiracy? Certainly predictable for /r/linux. I thought HN was better than that.
With a tweaked BIOS (one that permits the AHCI setting), Linux can be installed.
I would classify this as a hack rather than "can be installed"
I have a recent X260 running Fedora 24 and I'm very happy with it, and with Fedoras support. I use both smartcard and 4G data module with it. Only thing I don't use is the fingerprint reader.
Only sad bit is that I had to disable SecureBoot to run VirtualBox. I would have happily signed the VirtualBox kernel modules if it wasn't for Lenovo missing a small detail in the implementation of the UEFI spec that enables users to write their own MOK.
And if on virtualbox - you don't actually know if it would run on metal. VirtualBox hides quite a lot from you.
(I expect that it will run on metal - I just don't think you have evidence one way or another if you are running it on vbox)
No, it doesn't, at least on Fedora[0]: “When Secure Boot is enabled, the EFI operating system boot loaders, the Fedora kernel, and all kernel modules must be signed with a private key and authenticated with the corresponding public key.”
[0] https://docs.fedoraproject.org/en-US/Fedora/24/html/System_A...
However, I also want to run VirtualBox inside Fedora, because my job requires me to have a Windows VM. And VirtualBox has its own kernel modules, with SecureBoot they need to be signed. Unfortunately the poor UEFI implementation Lenovo has provided won't let me enter my own MOKs into the UEFI because coincidentally that little write call is missing.
I dunno, tinfoil hat surgically implanted under my scalp, it feels like they're not making it easy for Linux, when the Linux community is doing their best to adapt to SecureBoot.
Edit: And just to be clear, I did of course disable SecureBoot at this discovery but it was sad to do so because I had hoped to see how well Linux had adapted to this new tech that came out several years ago and was heralded as a Linux blocker. ;)
It's virtualbox which for some reason won't upstream their kernel modules, so they have to be compiled and installed by its users.
The discovery of kimchi made me try KVM and it's a very nice web gui for home use, or laptop use. So yes I might just replace VirtualBox with kvm soon. I just have no experience with the guest drivers for Windows provided by libvirt.
And PR: https://github.com/rhinstaller/shim/pull/60
Hopefully $DISTRO will patch it soon so you can enroll keys. : )
My laptop won't even POST with RST on, so I can't meaningfully experiment.
So the only real outcome from this would at first glance appear to be to antagonise people who won't consider their product either way and cause bad PR.
The question is if there's any other/better rationale.
I've successfully switched both parents to Linux and non tech at our company run completely on Linux.
It's a real threat, especially with MS failing to innovate.
Today in 2016, Linux is the superior platform for both user-friendliness and stability. It is easier to use and install on a wider variety of hardware. The old belief that Windows is "easier" is deprecated, and it is time to change the conversation to reflect that truth.
Linux does not exceed windows at user friendliness.
Stability completely depends on your hardware, distro, and use case.
It has made great strides, and windows is regressing, but it's not done yet.
In Linux, if you're missing something it's a simple matter of "apt-get install something" and it almost always works. The rate of failure for Windows updates and installing proper drivers and software in windows is much higher.
And Linux is far more likely to work out of the box on most hardware. Windows installs never have more drivers available than what ships on the CD/DVD. With Linux Net Installs, as long as your Ethernet is supported, and it probably is supported, the rest of the system will be up-to-date.
I have recently installed Windows 7, Windows 10, and Linux, I've used each for a number of months. Linux was the easiest and friendliest. I've been using Windows for years so I'm not a newbie, it's a terrible operating system.
This was an unrestricted claim that ignored a massive amount of Microsoft innovation. I pointed out that you were wrong and now you're quibbling about another of your personal opinions. Why make the same mistake twice?
Seems to me that the whole Microsoft Windows ecosystem -- across Azure, PCs, games consoles, smartphones, and iOS and Android devices -- shows far more innovation than Linux.
If you want to provide a list of Linux innovation to compare with my incomplete list above, I'd be interested to see it.
Be even better if you could address the whole market, without restricting it to your personal peccadilloes.
You're quoting somebody else there, friend. I jumped on this particular subthread because I wanted to point out that your list of innovations boils down to "Microsoft improved the user interface for touch devices."
> your personal peccadilloes
Peccadilloes? I do not think that means what you think it means.
Sorry. My apologies!
> I jumped on this particular subthread because I wanted to point out that your list of innovations boils down to "Microsoft improved the user interface for touch devices."
No, it doesn't. I use most of them on a desktop PC that doesn't include touch. Also, cloud and cross-platform capabilities go beyond touch.
> Peccadilloes? I do not think that means what you think it means.
I know what it means. And in the UK, it's not specifically sexual in connotation. However, I did spell it wrong ;-)
Also, an agreement to lock out Linux might not be legal from an antitrust perspective, whereas an agreement to restrict usage to the current version of the OS is much less critical.
This seems to be the most reasonable theory in the entire discussion.
Data looks like the new business model of Windows.
Some organizations (including, I think, London police) are still rolling out Windows 8.1 with full Microsoft support.
Windows 7/8/8.1 are all supported for 10 years under Microsoft's standard published software lifecycle.
So people have suggested in the past that Microsoft might ask for favours in return, basically telling OEMs that if they do not comply they might loose cheap OEM versions or even all access to OEM version of Windows, which would make their products unfit for competition.
Other people have suggested that this would be illegal, that Microsoft would never do something as anti-competitive like that, and that Microsoft just gives away nicely priced OEM versions of Windows to manufacturers because they are really nice guys and want disseminate their products even if they don't earn much from them.
The Comes trial is a good start http://www.groklaw.net/articlebasic.php?story=20070220083801...
This left Linux with no cost advantage on parts, or a negative cost advantage, if you added more crapware.
The much higher costs of shipping Linux then killed off the Linux netbooks.
The higher costs included extra testing and parts qualification, extra shipping and advertising costs, and, in particular, massively increased support costs. (One Linux user support call wiped out the profit margin on multiple sales.)
The post even describes the issue pretty explicitly as "Linux isn't loading the correct disk driver", yet it still spun as some intentional FU "block". I guess with a domain like "fossboss.com" you should expect the lowest form of the Slashdot mentality. I very much hope HN doesn't start to deal with this sort of pure flame bait.
It just doesn't make a bit of sense. If Microsoft wanted to block Linux, they would just require that SecureBoot not be disabled and require disablement of user key enrollment.
Besides, a clean copy of the Windows installation media doesn't boot normally either unless you slip the Intel RST driver into a custom built version of the install media.
This is just another conspiracy that I don't think makes any practical or logical sense.
Seriously, though-. If Microsoft blocked Linux overtly, they probably couldn't get away with it so easily; they'd end up with a PR disaster and/or an antitrust lawsuit. Plausible deniability helps them; now you can bet some people are going to say "come on, firmware screw-ups are no news, what are you, some kind of conspiracy theorist?" I mean, they have already taken advantage of ACPI in this way once.
(Tongue in cheek. It's not so totally implausible.)
Their modus operandi is to violate their antitrust agreement with the DOJ as non-obviously as possible with a nod and a wink and funnel campaign contributions to the relevant parties. If it becomes too blatant, however, the DOJ will be forced to punish them.
If true, it's illegal product tying, and those who signed such "agreement" are violating antitrust law. Someone should sue them until they stop doing this. Lenovo are infamous for refusing to refund Windows tax until brought to court, but this is a new low for them.
http://arstechnica.com/tech-policy/2016/09/sony-wins-pre-ins...
> However, the CJEU doesn't rule on the dispute itself. It's left up to the national court, in this case the French Cour de Cassation.
And actual Cour de Cassation already ruled in the past in case of Lenovo, that they must refund Windows license to those who reject the EULA:
https://www.legifrance.gouv.fr/affichJuriJudi.do?oldAction=r...
Hopefully Sony will go bust on this one and will be forced to pay what's due.
Meet the new boss, same as the old boss.
(and, honestly, were finally succeeding at, to the point where I'm very close to willing to give them the benefit of the doubt here: how the hell could the benefits of such a thing come anywhere near to outweighing the amount of damage it would do?)
I remember the lawsuit against TomTom in 2009, because they used the FAT32 filesystem through open source drivers. https://en.wikipedia.org/wiki/Microsoft_Corp._v._TomTom_Inc.
No, the title and "secret agreement" theory is just BS.
https://en.wikipedia.org/wiki/Occam%27s_razor
>Meet the new boss, same as the old boss.
MS hasn't been the boss of anyone much ever since 2005 or so...
http://www.paulgraham.com/microsoft.html
http://www.joelonsoftware.com/articles/APIWar.html
It is also doing quite well recently in the corporate desktop (see IBM adopting Macs, etc). Heck, they almost dominate the "startup founder/employee" desktop, as well as the "university student" desktop.
Do you have a source for this? I know it's the case with their phones, but they also have a much larger market share there. It's hard for me to believe they get "most of the profits" from the PC market with their minuscule share, especially when their computers are competitively priced.
Apple sells 5% of the world’s PCs and takes home 45% of the profit. (1)
During the recent third quarter, Apple commanded a 7.5 percent share of the computer market, up from 6.9 percent a year ago, IDC said. That was enough to move Apple up to No. 4 in market share for the computer market, pushing past Acer, which is now No. 5. (...) Each of the top five personal computer makers suffered a decline in total shipments, but four — Lenovo, HP, Dell and Apple — all captured a larger share of a shrinking market. (2)
* Apple's total share of the global PC market grew to 7.4 percent in the first quarter of calendar 2016, good for fourth place globally, according to IDC. That's up from 6.7 percent in the same period a year ago. (3)*
In fact Apple has such high per-PC revenues that it’s actually now the third-biggest PC maker by revenue – excluding Dell, because we don’t know what Dell’s revenues are, because it is privately owned. (4)
(1) http://fortune.com/2013/04/16/pie-chart-of-the-day-apples-ov...
(2) http://www.siliconbeat.com/2015/10/09/report-apple-widens-sh...
(3) http://forums.appleinsider.com/discussion/192668/apple-grows...
(4) https://theoverspill.wordpress.com/2015/07/13/the-deaths-of-...
Or get those Linux community to organize, and establish some body to create, and secure, keys for Linux that will be installed by default alongside MSs.
As someone who suffered from at least a couple BIOS-based malware back on Windows PCs back in the day, I'm all for securing the bootloaders...
A centralized key is not secure. A secure key is not centralized. If you want any security, the computer owner must be the only person allowed to install keys on the boot sequence - what is the exact opposite of what MS mandates.
A centralized key IS secure, just not AS secure as a not private key.
(That's theoritically: in practice it can be even safer than a private key, because most end users are incompetent in managing their keys much more than the central entity would usually be).
And it's wrong to think it as a key in the sense of a physical key. It actually used as a signature.
You can't have "private signatures" because the very purpose of a signature is to verify that the thing it signs is signed by a specific (and in the case of operating systems, central: the vendor) entity.
An OS the user signs itself is worthless, as the OS data he signed could have come from anywhere or tampered, etc, before the signing.
I think he means about character of those persons, who were something upfront and really creaky behind.
Like BillGates, who have done some bad things in past...
So sure, they want ubuntu to run on windows, so they can get into the container market.
So sure they will sell office in the cloud to target the legions of chromebook users. Not that they would ship office for linux.
Nor would they consider supporting linux on their surface books.
The locking linux out of various platforms with EFI seems to be progressing nicely.
But sure, microsoft will meet you half way to steal your customers and try to find out some other way to lock them into a microsoft platform.
Then they came for spammer license deals, and I did not speak out— Because I was not a Windows User.
Then they came to install back doors, and I did not speak out— Because I was not a Windows User.
Then they came for my ability to install Linux—and there was no one left to speak for me.
If Lenovo lose customers over this, it may be the case that they won't care, but in that case a competitor will surely swoop in to catch those customers by supplying PCs that run Linux.
In any case, the market should continue to supply machines that run Linux, as long as there is a demand for them. So if you demand a machine that runs Linux, just vote with your wallet!
I think this is very much a sliding scale. And that therefor the quote very much applies.
If (IF) a time comes when the only software available is proprietary, restrictive, invasive and possibly insecure, in a world where software is ubiquitous and often essential, I think that could be bad. The definition of fascism does come to mind.
Microsoft blocking installs of Linux on computers that I own, seems one of those steps to me.
You mean like up to the late 90's when most of us used to pay for software?
At the top of the slope, it's "merely firmware, what is the problem?". At the bottom of the slope are warcrimes and genocide. It is very hard to stop sliding down a slippery slope once you've started.
So when you disallow Linux on a laptop you are very much at the top of the slope. And there is a long way to go. But my, oh my, it sure is slippery.
Because we live in a digital age. More and more so. And in this age, there is no way to have 'checks and balances' without access to the source code of the software. And without checks and balances, it is very hard to have Separation of Powers[1].
Interestingly enough, I've found that survivors of WW2 tend to understand this better than most.
[0]https://en.wikipedia.org/wiki/Slippery_slope
[1]https://en.wikipedia.org/wiki/Separation_of_powers
Otherwise, "my friend", one invites analogies to Godwin's law, and rejection out of hand for using a reductio ad Hitlerum.
People make slippery slope arguments all the time, but often (and quoting your [0]), "as a form of fear mongering, in which the probable consequences of a given action are exaggerated in an attempt to scare the audience. The fallacious sense of "slippery slope" is often used synonymously with continuum fallacy, in that it ignores the possibility of middle ground and assumes a discrete transition from category A to category B. In a non-fallacious sense, including use as a legal principle, a middle-ground possibility is acknowledged, and reasoning is provided for the likelihood of the predicted outcome."
What was missing, in the recasting of Niemöller's poem, was the 'reasoning ... provided for the likelihood of the predicted outcome'.
Certainly bugs in Telegram and the use of the wrong social software among dissidents (or software that unknowingly leaks, or is endemic like windows) has everything to do with how they are spied upon. Many of those dissidents are from ethnic minorities that are targeted or will be targeted.
The holocaust was a terrible thing, but not talking about any road signs to the next genocides to avoid upsetting people isn't the prevention mechanism my history teachers had in mind.
User languagewars is in good company. Orwell compared early dissidents in USSR to chickens in his Animal farm. Jesus compared Kindom of Heaven to mustard seed, himself to wine and bread, redemption to finding a coin and true faith to freaking oil lamp. Plato compared whole human existence to group of dudes sitting in a cave. Socrates compared himself to gadfly.
This is one of the most used literary vehicle. By the best and most famous thinkers of all times.
1. http://ec.europa.eu/competition/consumers/web_browsers_choic...
However, I'm glad this is making this type of fuss. It means bad PR for Lenovo if they don't do any Linux QA (as they mostly never did). Good.
Why is it OK to lock down smartphones, TV devices, consoles, but not OK for PCs?
It was the 3rd party suppliers (i.e. BIOS by companies like Phoenix, Award, AMI along with motherboard manufacturers etc.) selling picks and shovels to the would-be prospectors (i.e. clone assemblers) that allowed for the 'open' PC standard. For example, there was a company call PCs Limited that licensed AMI BIOS so that they make some IBM clones... they did kind of OK and soon renamed themselves Dell...
Some of the other companies I mentioned were the ones that followed Compaq's lead and did their own clean room versions which they then sold to everyone else who came flooding into the market.
As an aside, this was actually a problem for the first few years: take multiple independent clean room implementations, bake in some silly things that the manufacturers did with them (gotta customize, right?), and combine it with the bad programming practices of the day (i.e. programs written in assembly doing jumps into undocumented portions of the BIOS because, hey, it worked on the IBM and saved a few bytes/cycles or did something useful...) It was similar to how well web standards worked not too many years ago with multiple browser implementations doing/interpreting things slightly differently and developers doing things they shouldn't because they could... and that was with a public spec designed to be copied. Eventually things get worked out, but both had a rough start.
Unlike its competitors, Spectrum had standard phone jack connectors for sound and magnetic tape recorder (so you could use any recorder). It also had a direct circuit board connection to the system bus on the back, and the schematics were available. My father built us the 8255 interface to have joystick and other peripherals connected.
And you surely could not overwrite it.
There weren't many useful things in the ROM, if you were writing your application. Maybe the font table and tape loader. On the other hand, if you were able to ignore the ROM, you got few bytes more of RAM, because you were able to repurpose the "system variables" area.
The biggest "problem" with ROM that you were unable to replace it with RAM (until next reset, for example), thus taking precious 16kB out of 64kB address range.
It's however particularly unacceptable to lock down what used to be open.
Then tension is that we've almost always been able to install Linux on standard Windows machines and so have gotten used to it being open, but I'd be loathed to say (if the manufacturers have decided to make it tricky deliberately or just not thinking) we have a fundamental right to do it.
But there is a right not to buy this stuff and a right to tell other people not to buy it, too. There is also a right to tell the vendors how much you abhor them for selling such closed products and there is a right to tell journalists or other people why buying closed products is a really bad idea. And you have a right to lobby to make producing/buying closed products socially unacceptable.
Ever since not preventing you also meant not preventing others, and thus malware, exploits, pwnage, stolen data and passwords, etc.
And ever since what you wanted to do was hurting others (e.g. not driving while drunk, even if its your car) or violating other's copyright.
Seems like it's "okay" when you can get away with it. But not okay when large group of people get some slight inconvenience.
If the technology gets convenient and cheap enough, they might not be.
"Most Japanese domestic market vehicles are limited to 180 km/h (112 mph) or 190 km/h (118 mph)." Almost twice the common maximum speed limit (100km/h).
E.g. with an unlocked Android device, I will typically at most install a different rom that's largely the same as the stock rom. Various small enhancements but nothing I can't live without.
But a PC that can't run Linux is entirely useless to me.
Once, just before Blu-ray was a thing, I encountered a "HD DVD" which was a data DVD containing a Windows Media file. This used the embedded DRM licensing system to call home to a server when you played it, and refused to run if your source IP was not in the US.
It isn't - and this is why I don't own a smartphone, smart TV or game console.
IMHO, it is not OK to lock down things you own. I have been a victim. I bought an AppleTV v2 and a planned obsolescence by Apple and Google rendered it useless (with a YouTube API version requirement).
PCs are special in that, they are general purpose devices and not appliances. If you are using it as an appliance, chances are, you are not interested in running another operating system on it.
But a monopoly mandating interacting products to lock down is a completely different game.
This sounds believable to me. But I'll put my tinfoil hat on just for fun and pretend it was an intentional move. Could this make sense as a new twist on the old strategy, making it "Embrace, Extinguish, Extend"? With the WSL, they made it theoretically possible to run Linux software on Windows. With that in place, locking existing users out of Linux might cause a lot less negative backlash as the users can still continue to use their old programs - except under the supervision of Windows. If this catches on, it could actually allow Microsoft to grab some if the more consumer-oriented parts of the Linux ecosystem.
I'm scratching my head here. Help me out. I've seen extremely limited consumer take-up of desktop Linux.
Edit: it'd be rather amusing and saddening if this whole controversy was caused merely by someone misunderstanding/misreading a perfectly sensible requirement to disable the RAID mode, and instead disabled the other options. Given the level of communication fluency among some programmers, I would not be surprised if this were the case; and the fact that the machine still boots into Windows because it has drivers might've let this slip past QA...
Sure, real/standards-conforming NVMe would be better -- and wouldn't require driver shenanigans in either Windows or Linux -- but there should be a performance advantage to 'RAID' mode in this case.
On the other hand, Microsoft could have easily gotten a much more "robust" lockdown - by simply demanding mandatory, unchangeable Secure Boot like on the ARM tablets. But they didn't do that.
Didn't you hear that Secure Boot is basically broken?
Flagged as a dupe. It's here: https://news.ycombinator.com/item?id=12545966
I'm sure anyone with enough knowledge to decompile a BIOS would have obviously thought of that idea though. I'm guessing the BIOS images are signed or something?
Regardless, this smells evil to me...
http://imgur.com/a/niewu
In reality the agent probably misunderstood what's bring asked.
In reality the script read, "can I buy this with linux installed?", the answer would be only "windows 10 signature edition".
They probably don't even know what linux is.
> This system has a Signature Edition of Windows 10 Home installed. It is locked per our agreement with Microsoft.
> I've been able to successfully get past Lenovo's lock through direct bios flashing. I'm looking into better solutions, hopefully I can find a way to do this without an external programmer. I was going to keep people updated from the Lenovo forum, but as this is no longer an option I will keep people updated from here.
https://www.reddit.com/r/linux/comments/53ri0m/warning_micro...
As a default it would be fine, if it could be changed without removing the BIOS chip.
It's a locked UEFI setting causing a problem: true. The setting is causing a piece of hardware to behave in a mode not handled by the current Linux driver: also true. So there are two ways of looking at it.
First: It's a software issue that Lenovo should clear up (i.e. remove the locks on the appropriate parts of the UEFI configuration)
Second: It's a hardware issue that the Linux community can address by writing a driver for the alternate hardware mode.
Lenovo apparently wants to treat that computer as an appliance; if someone borks their installation enough that even a system restore won't fix it, it's a call to Lenovo support, and a bill if the machine's out of warranty.
For customers whose Windows installations are working correctly, it's access to a faster, more power-efficient driver. That's how it makes sense, IMO.
Thus, this laptop can only ever be installed from the Lenovo win10 media. No win7, no win8, no retail win10 (for now), and .... probably as a (not unwelcome) side effect, no linux.
Still, just as evil and despicable.
So using that install media you can extract the drivers and install older windows versions anyway.
So it's a pretty crappy conspiracy :)
The API/ABI for drivers didn't change between 7,8,10
And it does effectively stop users from installing Linux, Win7, Win8 and even Win10 - except from the provided Lenovo install media; which makes Microsoft happy (no Win7/Win8) and Lenovo happy (full control of installed versions).
A serious question: What gives Linux users the right to expect that Linux will run on any given PC / laptop?
Think about it. These PCs/laptops are designed to adhere to Microsoft's Windows PC hardware standards doc (which was never, ever an open standard) and, with few exceptions, only tested against various versions of Windows. Linux users are failing to receive a feature that they were never promised in the first place so it's unclear that they have any valid cause for complaint.
Perhaps Linux, BSD, etc. users should be creating their own PC standards doc and asking OEMs to adhere to it instead?
Nothing. It's very well possible that in future, we have Apple devices that only run iOS, Google devices that only run Android/ChromeOS/Whatever and Microsoft devices that only run Windows 10 - and a large server market with a tiny consumer segment of devices that run linux.
We'll all be fine in that world. We just won't have any control about our devices anymore.
Perhaps Linux, BSD, etc. users should be creating their own PC standards doc and asking OEMs to adhere to it instead?
That's actually a good idea in theory - so far that "standard" had been the x86/x64 IBM compatible PC. Except that I fear they lack the market power to actually make such a standard more than a stack of paper. You'd need an OEM network the size of Microsoft or enough capital and brand trust so you can make your own devices. I see neither for linux.
I expect any computer I own to run anything I put on it.
Locking out software is like a car maker trying to control what brand of gas you put in your car.
None of those other examples are sold with the intention of the user changing the system in a way unexpected by the vendor.
PCs are supposed to be open-ended, and for this you typically pay more for the hardware capability than a product which serves as a gateway into a walled-garden ecosystem (phones, gaming consoles, etc.)
Any cpu in my household is mine (presumably.) I don't care what peripherals it has, it's just a computer.
From my POV all those devices are just computers with various peripherals. I don't see any way in which attaching a specific peripheral changes the universal nature of the cpu.
A offline (PDF) version is available at the bottom-most link on the page.
If I buy some hardware, I've done research on whether all of its chipsets and devices have Linux driver support just as a matter of course, because I don't expect that Linux will run on every PC. But I feel like I have a right to know if a company puts a non-standard artificial restriction on their hardware. Apparently in this case, Windows 10 doesn't even have the driver included by default, so I can't even reload the software that the machine was designed to run, on my own. That sounds like a defect in the product, to me.
Where? I'm looking at http://shop.lenovo.com/us/en/laptops/yoga/900-series/yoga-90... and the specs page lists only Windows 10 Home and Pro in the operating systems section.
> and effort was expended specifically to disable that option
Lenovo has issued a formal statement denying it. http://www.techrepublic.com/article/lenovo-denies-deliberate...
I was imprecise. The chipset supports a Linux-compatible option, were it not explicitly disabled in the firmware.
> Lenovo has issued a formal statement denying it.
They deny purposefully disabling Linux, and I don't have any evidence against that denial. They don't deny disabling AHCI, because they clearly did. In the disassembly of the code: https://lnv.i.lithium.com/t5/image/serverpage/image-id/76843...
Intel's RAID is implemented in their driver. Switching the option from AHCI to RAID switches the disk controller's ID so it doesn't bind to the OS's standard driver (whichever OS that is), and binds to Intel's instead (assuming it's present). Intel provides its driver (and only for Windows), Lenovo locks the option so that hapless users mucking about in the UEFI settings don't make their machines unbootable.
Lenovo can deny "deliberately blocking Linux", but they can't deny "practically blocking Linux".
How else am I going to avoid the crapware/malware that lenovo is famous for?
Happens that the same BIOS tweak that prevents windows from working also prevents linux from working.
I don't expect lenovo to spend time/effort accommodating linux, but I also expect them to not artificially limit when I can do with a laptop I purchase.
The last I heard, Dell still ships Ubuntu on some of their XPS models, and there are a few companies whose business model is based on officially supporting Linux on their own branded machines. System76[1] and ZaReason[2] immediately come to mind, but if you're seeking a fully open machine with no closed source drivers, look to Libiquity[3] for an older but FSF certified ThinkPad. Yes, it's a rebranded Lenovo so it may be a sour choice given the subject of this article, but it's a solid buy if you don't need today's CPU power. Ditto Minifree[4].
[1] https://system76.com/ [2] http://zareason.com/shop/home.php [3] https://shop.libiquity.com/product/taurinus-x200 [4] https://minifree.org/
I'll see if i can pick one of these up on my way home and do some testing :)