I am glad that we could find some common ground and agree that everyone is free to determine their own values and discuss them. I definitely agree with that sentiment. However, you don’t appear to be providing a real, concrete reason explaining why Framework shouldn’t expose Platform Secure Boot to its end-users, giving them the option to enable the extra security if they want to.
You asked for real-world examples of threats that PSB could help defend against and DHowett provided you with some sources. Yet, you claim you were never given any examples at all. Do the sources have to come from me to be credible? Is it possible that DHowett was correct when they stated:
Arguments that start with “give me one real example” usually end with “that one doesn’t count”.
Just because you have not seen these types of attacks in the mainstream media doesn’t mean they aren’t real threats. Additionally, there is a huge difference between what is acceptable for Linux kernel development and an optional platform security feature, which already exists, being exposed to end-users. This appeal to authority is a bit misplaced and it doesn’t even explain why you feel like this security feature (again, which already exists and should be supported by the platform) shouldn’t be exposed to give people the freedom to use it or not.
It is also kind of selfish to say:
They most always require physical access to the device, which any normal, self-aware computer user would never give to somebody who would do such a thing. And if they would, then they deserve what they get.
People can’t always prevent someone from having physical access to their device. It may be difficult for you to understand this, but some people simply have higher threat models than others. It is entirely possible that they work with classified information, live in high risk areas, are an activist or investigative journalist. There are many valid reasons why someone could reasonably expect that their device may unknowingly fall into the hands of a skilled adversary through no fault of their own. In these situations, it would be really great to know that there is at least some trust in the firmware running on your system.
You’re absolutely correct when you say that I am security biased though. I am very open about that and fully admit that I am extremely security focused. However, as much as I require a higher level of security, I would happily accept Framework rejecting the idea to improve platform security if it meant forcing that change on anyone, even if it is one single user, who doesn’t want it. Like I said in my previous post, I don’t want to impose my needs on anyone else. I’d just really like for users to have the option to opt into PSB if it is something they would like to use.
Once again, I am also sorry that you and others seem to be having a difficult time with your devices. I truly do hope they are able to promptly address the issues. However, just because someone is asking them to expose a feature, which already exists, doesn’t mean they won’t fix the things you care about too. We can both happily coexist and there is no need for our personal interests to compete here. It isn’t an all-or-nothing proposition.
I’ll just end my side of the conversation here because I feel like I have said everything that I really needed to. In the end, you and I have no real say over what Framework as an OEM chooses to work on or not. If they see merit in my request, maybe it will be considered. If not, they will disregard it and move on. I was honestly hoping to have a more interesting discussion about this, but I don’t really think that is going to happen.
Good luck with your Framework device(s) and I hope you get all of your problems sorted out soon.