All of lore.kernel.org
 help / color / mirror / Atom feed
From: Thomas Horsten <thomas@horsten.com>
To: Linus Torvalds <torvalds@osdl.org>
Cc: Chase Venters <chase.venters@clientec.com>,
	"linux-os \\\(Dick Johnson\\\)" <linux-os@analogic.com>,
	Kyle Moffett <mrmacman_g4@mac.com>, Marc Perkel <marc@perkel.com>,
	"Jeff V. Merkey" <jmerkey@wolfmountaingroup.com>,
	Patrick McLean <pmclean@cs.ubishops.ca>,
	Stephen Hemminger <shemminger@osdl.org>
Subject: Re: GPL V3 and Linux - Dead Copyright Holders
Date: Fri, 27 Jan 2006 21:33:56 +0000 (GMT)	[thread overview]
Message-ID: <Pine.LNX.4.40.0601272112590.29965-100000@jehova.dsm.dk> (raw)
In-Reply-To: <Pine.LNX.4.64.0601251728530.2644@evo.osdl.org>

On Wed, 25 Jan 2006, Linus Torvalds wrote:

> And quite frankly, I don't see that changing. I think it's insane to
> require people to make their private signing keys available, for example.
> I wouldn't do it.

Linus, I think you are missing the point here. I see this provision as one
of the most important fixes in GPL v3. It might not be perfect in the way
it is presented in the draft, but the rationale is certainly laudable.

This closes a very serious loophole, that in certain situations renders
the GPLv2 almost worthless. The problem is embedded systems, but
especially cellphones.

A typical smartphone has a baseband processor (running the GSM stack under
a proprietary OS - let's call it the Baseband OS) and an application
processor (running the PDA features and GUI, for example Symbian OS or
Linux, let's call it the Application OS). Newer phones use a microkernel
architecture where the two OS's each run as tasks under a microkernel so
that a single CPU can be shared, but that's not relevant for this point.

The practice for many phone manufacturers is to heavily encrypt and sign
all ROM images that go on the phone. They do this for several reasons, but
mostly to prevent end-users from modifying the baseband code (where things
like SIM-locks and network locks are stored) or changing the IMEI number
of stolen phones.

However, most manufacturers extend this protectin to also encompass the
PDA-side code. This is understandable (to an extent) where the operating
system is proprietary or licensed (e.g. Symbian OS) and not available for
end-users to modify in any case.

But when Linux is used instead (something that most major handset
manufacturers are working on at the moment), this whole picture changes.
Suddenly the whole point of "Free Software" goes away. Because the handset
manufacturer modifies, adapts and uses the Linux kernel (for free),
without having to give anything back to the community. Yes, they have to
make their modified source available, but there is no way a casual user
(read: someone not a member of the phone-unlocking mafia) can update the
kernel with a modified, recompiled version.

But it goes further. The manufacturer is free to embed "trusted
computing" technology into the kernel (e.g. digital signing of all
executables that can run on the phone), as long as the encryption
technology is included in the kernel (they can even embed the
public key in the published sources, and you have no way of
obtaining the secret key) - thereby preventing the user from running ANY
code on the phone not pre-approved by the manufacturer.

Their main motivation for doing this is basically to protect the mobile
network operators' revenue, by preventing (or at least limiting)
installation of things such as VoIP clients and instant messenger systems
that could lead towards an "open TCP/IP" infrastructure that all the
operators fear so much.

The prime example of this is what is already implemented is Symbian OS. In
Version 9, used by the latest handsets from Nokia and Sony Ericsson, it is
impossible to install applications that are not signed by an independent
testing house, something that effectively locks small businesses and
independent hobby coders out of the market. There are even certain
"capabilities", needed for example to implement networking protocols, that
can only be signed if approved by the phone manufacturer.

The only way to prevent Linux from being abused in this way is to require
that the end-users have a method of installing the modified code on the
device for which it was intended (such as your phone). If they don't want
to disclose their primary signing keys, fine, but then they need to make
another method available of replacing any free software used in the device
with a modified (by the end-user) version. I understand the need to
protect the non-GPL'ed "baseband" OS from tampering, but it has to be
possible to replace the GPL'ed software. This is what this provision is
all about (for me), and I think it is an extremely important one.

Of course I have focused on cellphones, but the same is equally true for
other embedded devices, such as digital TV boxes (e.g. PVR's). If I want
to add a nice feature (and share the patch with my friends who bought the
same box) I should be free to do so. Isn't that what Free Software is all
about?

Thomas



  parent reply	other threads:[~2006-01-27 21:35 UTC|newest]

Thread overview: 214+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-01-20 16:49 GPL V3 and Linux Jeff V. Merkey
2006-01-20 19:11 ` Stephen Hemminger
2006-01-20 19:34   ` Patrick McLean
2006-01-20 18:22     ` Jeff V. Merkey
2006-01-20 18:30       ` Jeff V. Merkey
2006-01-20 19:45     ` Alan Cox
2006-01-25 18:46     ` GPL V3 and Linux - Dead Copyright Holders Marc Perkel
2006-01-25 17:14       ` Jeff V. Merkey
2006-01-25 17:30         ` Jeff V. Merkey
2006-01-25 19:24           ` Marc Perkel
2006-01-25 19:50             ` Kyle Moffett
2006-01-25 20:44               ` linux-os (Dick Johnson)
2006-01-25 21:20                 ` Chase Venters
2006-01-25 22:39                   ` Linus Torvalds
2006-01-25 23:26                     ` Chase Venters
2006-01-26 17:59                     ` Paul Jakma
2006-01-26 16:28                       ` Jeff V. Merkey
2006-01-26 18:25                       ` Filip Brcic
     [not found]                         ` <Pine.LNX.4.64.0601261233150.17225@turbotaz.ourhouse>
2006-01-26 16:55                           ` Jeff V. Merkey
2006-01-26 22:54                             ` Olivier Galibert
2006-01-27  2:15                             ` David Schwartz
2006-01-27  2:23                               ` Dave Jones
2006-01-27  2:37                                 ` David Schwartz
2006-01-27  2:53                                   ` Dave Jones
2006-01-27 19:50                                     ` David Schwartz
2006-01-27  3:40                                   ` Diego Calleja
2006-01-27  7:34                               ` Arjan van de Ven
2006-01-27  8:09                               ` Valdis.Kletnieks
2006-01-27 13:38                               ` Olivier Galibert
2006-01-27 19:50                                 ` David Schwartz
2006-01-27 20:30                                   ` Olivier Galibert
2006-01-27 21:12                                     ` David Schwartz
2006-01-27 19:30                                       ` Jeff V. Merkey
2006-01-27 15:56                               ` Roland Kuhn
2006-01-26 18:52                         ` Paul Jakma
2006-01-26 18:53                       ` Diego Calleja
2006-01-26 18:57                         ` Chase Venters
2006-01-26 19:22                           ` Marc Perkel
2006-01-26 19:52                             ` Chase Venters
2006-01-26 20:04                               ` Marc Perkel
2006-01-26 20:21                                 ` Chase Venters
2006-01-26 20:51                                   ` linux-os (Dick Johnson)
2006-01-26 22:28                                   ` GPL V3 and Linux - V3 adds new restrictions Marc Perkel
2006-01-27  6:58                                     ` sean
2006-01-27  6:58                                       ` sean
2006-01-28  4:44                                     ` Linus Torvalds
2006-01-26 19:33                           ` GPL V3 and Linux - Dead Copyright Holders Diego Calleja
2006-01-26 18:57                         ` Paul Jakma
2006-01-26 22:16                     ` Marc Perkel
2006-01-26 22:23                       ` Al Viro
2006-01-28  1:33                       ` Linus Torvalds
2006-01-28 19:45                         ` Michael Buesch
2006-01-28 19:04                           ` Jeff V. Merkey
2006-01-27 10:46                     ` Simon Oosthoek
2006-01-27 13:39                       ` Al Viro
2006-01-27 14:00                         ` Simon Oosthoek
2006-01-27 14:18                           ` Olivier Galibert
2006-01-27 14:42                             ` Simon Oosthoek
2006-01-27 15:20                               ` Al Viro
2006-01-27 15:32                                 ` Simon Oosthoek
2006-01-27 14:46                           ` Chris Bergeron
2006-01-27 14:47                           ` Kyle Moffett
2006-01-28  1:53                           ` Linus Torvalds
2006-01-28 23:23                           ` Horst von Brand
2006-01-28  1:46                         ` Linus Torvalds
2006-01-30  7:00                           ` Giacomo A. Catenazzi
2006-01-31 23:18                             ` David Schwartz
2006-01-28  4:39                       ` Linus Torvalds
2006-01-28  4:57                         ` Chris Adams
2006-01-28 20:38                         ` Simon Oosthoek
2006-01-29 14:30                         ` Matthias Urlichs
2006-01-28 15:38                       ` Florian Weimer
2006-01-27 21:33                     ` Thomas Horsten [this message]
2006-01-28  5:38                       ` Karim Yaghmour
2006-01-28  8:31                         ` Thomas Horsten
2006-01-28 10:37                           ` Peter Read
2006-01-30 18:15                           ` Karim Yaghmour
2006-01-30 19:43                             ` Glauber de Oliveira Costa
2006-01-30 22:00                               ` Filip Brcic
     [not found]                                 ` <5d6222a80601302012v22196faci3ce81320fb534f30@mail.gmail.com>
2006-02-01 15:30                                   ` Georg C. F. Greve
2006-02-01 16:32                                 ` Karim Yaghmour
2006-02-01 22:31                                   ` Linus Torvalds
2006-02-01 23:43                                     ` Karim Yaghmour
2006-02-02  0:18                                     ` Alan Cox
2006-02-02  8:39                                     ` Pierre Ossman
2006-02-02  9:00                                       ` Linus Torvalds
2006-02-02  9:32                                         ` Emilio Jesús Gallego Arias
2006-02-02 10:30                                           ` Helge Hafting
2006-02-04 17:45                                             ` Valdis.Kletnieks
2006-02-02 10:46                                           ` James Bruce
2006-02-02 11:13                                             ` Emilio Jesús Gallego Arias
2006-02-02 12:31                                               ` Helge Hafting
2006-02-02 13:31                                                 ` Emilio Jesús Gallego Arias
2006-02-02 16:23                                                   ` Helge Hafting
2006-02-02 11:50                                           ` David Schwartz
2006-02-02 16:04                                           ` Linus Torvalds
2006-02-02 17:40                                             ` Emilio Jesús Gallego Arias
2006-02-02  9:37                                         ` Pierre Ossman
2006-02-02 14:45                                           ` Gene Heskett
2006-02-02 14:38                                         ` Alan Cox
2006-02-02 16:19                                           ` Linus Torvalds
2006-02-02 17:08                                             ` Pierre Ossman
2006-02-02 17:44                                               ` Linus Torvalds
2006-02-02 17:54                                                 ` Pierre Ossman
2006-02-02 18:12                                                   ` Lennart Sorensen
2006-02-02 18:27                                                     ` Pierre Ossman
2006-02-06 16:11                                                       ` Horst von Brand
2006-02-02 18:53                                                   ` Linus Torvalds
2006-02-02 19:20                                                     ` Pierre Ossman
2006-02-02 19:46                                                       ` Mark v Wolher
2006-02-02 19:52                                                       ` Karim Yaghmour
2006-02-02 23:07                                                         ` Pierre Ossman
2006-02-02 23:52                                                           ` Karim Yaghmour
2006-02-03  8:14                                                       ` Helge Hafting
2006-02-02 18:13                                                 ` Ian Kester-Haney
2006-02-02 18:49                                                   ` Lee Revell
2006-02-02 19:11                                                     ` Christopher Friesen
2006-02-02 19:18                                                       ` Lee Revell
2006-02-05  3:58                                                       ` Luke-Jr
2006-02-05  7:06                                                         ` Zan Lynx
2006-02-06 21:07                                                         ` David Schwartz
2006-02-06 22:38                                                           ` Kyle Moffett
2006-02-07 13:44                                                             ` Luke-Jr
2006-02-07 13:40                                                           ` Luke-Jr
2006-02-03 21:33                                                 ` Ingo Molnar
2006-02-01 16:06                               ` Karim Yaghmour
2006-02-02 22:02                                 ` Pavel Machek
2006-02-02 22:24                                   ` Lee Revell
2006-02-02 23:04                                   ` Karim Yaghmour
     [not found]                     ` <1138387136.26811.8.camel@localhost>
2006-01-28  2:06                       ` Linus Torvalds
2006-01-28  5:22                         ` Linus Torvalds
2006-01-28  6:25                           ` Al Viro
2006-01-28 23:14                             ` Linus Torvalds
2006-01-30 11:26                         ` Alan Cox
2006-01-31 17:57                           ` Linus Torvalds
2006-01-31 17:24                             ` Jeff V. Merkey
2006-01-31 19:07                               ` Linus Torvalds
2006-01-31 18:48                                 ` Jeff V. Merkey
2006-01-31 20:38                                   ` Linus Torvalds
2006-01-31 19:57                                     ` Jeff V. Merkey
2006-02-02 19:52                                       ` Matan Peled
     [not found]                                         ` <3e1162e60602021207o5893055fqe8a20c99ff8a19b6@mail.gmail.com>
2006-02-02 20:29                                           ` Matan Peled
2006-01-31 21:45                                     ` Paul Jakma
2006-01-31 21:47                                       ` Stephen Hemminger
2006-01-31 22:25                                       ` Linus Torvalds
2006-02-01  6:52                                       ` Gene Heskett
2006-01-31 22:04                                     ` Rene Herman
2006-01-31 23:08                                       ` Linus Torvalds
2006-01-31 23:32                                         ` Paul Jakma
2006-02-01  0:20                                         ` Paul Jakma
2006-02-01 14:29                                         ` Rene Herman
2006-02-01 22:13                                           ` Linus Torvalds
2006-02-01 23:29                                             ` Rene Herman
2006-02-02  0:01                                               ` Linus Torvalds
2006-02-02  0:16                                                 ` Alan Cox
2006-02-02  1:08                                                 ` David Schwartz
2006-02-02  9:50                                                 ` Rene Herman
2006-02-02  6:39                                               ` Andrew James Wade
2006-02-02  6:57                                                 ` Kyle Moffett
2006-02-02  7:11                                                   ` David Schwartz
2006-02-03  3:56                                                     ` Andrew James Wade
2006-02-03  5:35                                                       ` David Schwartz
2006-02-03 13:31                                                         ` Andrew James Wade
2006-02-03  3:35                                                   ` Andrew James Wade
2006-02-03  5:35                                                     ` David Schwartz
2006-02-01 22:46                                         ` David Schwartz
2006-02-02 12:31                                           ` Krzysztof Halasa
2006-01-31 23:48                                     ` Alan Cox
2006-02-01  0:18                                       ` Linus Torvalds
2006-02-01  0:45                                         ` Alan Cox
2006-01-31 19:55                                 ` Marc Perkel
2006-01-31 19:10                                   ` Jeff V. Merkey
2006-01-31 20:16                                     ` Marc Perkel
2006-01-31 19:27                                       ` Jeff V. Merkey
2006-01-31 23:57                                 ` Alan Cox
2006-02-01 10:01                                   ` Rogier Wolff
2006-02-01 13:59                                     ` GPL V3 -- PLEA FOR SANITY Theodore Ts'o
2006-01-31 20:32                             ` GPL V3 and Linux - Dead Copyright Holders Diego Calleja
2006-01-31 20:43                               ` Josh Boyer
2006-02-01  0:06                             ` Alan Cox
2006-02-01  1:02                               ` Marc Perkel
2006-01-26  0:53                 ` Kurt Wall
2006-01-21  2:27 ` GPL V3 and Linux Alexander Shishckin
2006-01-21  4:08   ` Chase Venters
2006-01-21  5:56     ` Alexander Shishckin
2006-01-21 18:28       ` Chase Venters
2006-01-21 19:01       ` Geert Uytterhoeven
2006-01-21 20:43       ` Horst von Brand
2006-01-23 22:10         ` linux-os (Dick Johnson)
2006-01-24  0:34           ` Chase Venters
2006-01-24  0:52           ` Harald Arnesen
2006-01-24  1:55             ` Ian Kester-Haney
2006-01-24  3:08               ` Kyle Moffett
2006-01-24  9:10               ` Bernd Petrovitsch
2006-01-24 15:49               ` Alan Cox
2006-01-24  9:37             ` Wartan Hachaturow
2006-01-24 10:23           ` David Schwartz
2006-01-24 10:38             ` Lee Revell
2006-01-24 13:53             ` linux-os (Dick Johnson)
2006-01-24 16:13               ` Jeff V. Merkey
2006-01-25  1:21                 ` Ian Kester-Haney
2006-01-25  9:42                   ` Bernd Petrovitsch
2006-01-25 16:02                     ` [OT] " Steven Rostedt
2006-01-27  3:10                     ` Valdis.Kletnieks
2006-01-27  9:54                       ` Bernd Petrovitsch
2006-01-27 10:13                         ` Bas Westerbaan
2006-01-27 10:25                           ` Bernd Petrovitsch
2006-01-27 13:29                         ` Olivier Galibert
2006-01-27 17:51                         ` Valdis.Kletnieks
2006-01-28 11:38                           ` Bernd Petrovitsch
2006-01-27  2:01                   ` Rik van Riel
2006-01-28 20:18                   ` Graham Murray
2006-01-23  9:09       ` Helge Hafting
2006-01-23  9:52       ` Bernd Petrovitsch
2006-02-02 18:48 GPL V3 and Linux - Dead Copyright Holders Shawn Starr

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Pine.LNX.4.40.0601272112590.29965-100000@jehova.dsm.dk \
    --to=thomas@horsten.com \
    --cc=chase.venters@clientec.com \
    --cc=jmerkey@wolfmountaingroup.com \
    --cc=linux-os@analogic.com \
    --cc=marc@perkel.com \
    --cc=mrmacman_g4@mac.com \
    --cc=pmclean@cs.ubishops.ca \
    --cc=shemminger@osdl.org \
    --cc=torvalds@osdl.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.