Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion

2025-03-08 Thread Aurélien COUDERC
Le 8 mars 2025 13:43:26 GMT+01:00, Simon Josefsson a écrit : > Having source code for the >microcode would help gain confidence in it, and is the reasonable >request. If the request is denied, I would consider the vendor not >trustworthy and look into options. How about you try asking the v

Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion

2025-03-08 Thread tomas
On Sat, Mar 08, 2025 at 02:51:29PM +0100, Johannes Schauer Marin Rodrigues wrote: > Hi, > > Quoting Simon Josefsson (2025-03-08 13:43:26) > > My point was that there is no reasonable way to gain confidence about > > security properties of any piece of non-free microcode. Everyone can now > > pro

Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion

2025-03-08 Thread Simon Josefsson
Johannes Schauer Marin Rodrigues writes: > Hi, > > Quoting Simon Josefsson (2025-03-08 13:43:26) >> My point was that there is no reasonable way to gain confidence about >> security properties of any piece of non-free microcode. Everyone can now >> produce AMD microcode that corrupts your machin

Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion

2025-03-08 Thread Johannes Schauer Marin Rodrigues
Hi, Quoting Simon Josefsson (2025-03-08 13:43:26) > My point was that there is no reasonable way to gain confidence about > security properties of any piece of non-free microcode. Everyone can now > produce AMD microcode that corrupts your machine in advanced ways that evade > detection, but we d

Re: Do we need a conflict of interest policy?

2025-03-08 Thread Jonathan Dowland
I stumbled across this Debian Wiki page I'd forgotten about. We have had a voluntary Register of Interests here since 2017: https://wiki.debian.org/RegisterOfInterests -- Please do not CC me for listmail. 👱🏻 Jonathan Dowland ✎j...@debian.org 🔗 https://jmtd.net

Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion

2025-03-08 Thread Simon Josefsson
Bill Allombert writes: > Le Fri, Mar 07, 2025 at 07:33:53PM +0100, Simon Josefsson a écrit : >> pan...@disroot.org writes: >> >> > I urge Debian to rethink its decision to officially include non-free >> > firmware and correct the social contract. Instead of making non-free >> > firmware the defa

Re: Reconsidering Debian’s Inclusion of Non-Free Firmware - A Call for Discussion

2025-03-08 Thread Bill Allombert
Le Fri, Mar 07, 2025 at 07:33:53PM +0100, Simon Josefsson a écrit : > pan...@disroot.org writes: > > > I urge Debian to rethink its decision to officially include non-free > > firmware and correct the social contract. Instead of making non-free > > firmware the default, Debian should ensure that u