Conversation

Replying to
I've never understood how having entirely proprietary hardware and firmware but avoiding shipping and loading the firmware from the OS somehow makes it open and not proprietary. It's really doing the opposite and making it harder to inspect and control along with less secure.
1
2
Not shipping the firmware in the OS doesn't mean it stops existing and doesn't make the hardware open. I don't know how they get away with portraying proprietary hardware as open because they ship an open source OS guaranteeing users are insecure by not shipping firmware updates.
1
2
Far better to have stateless components where OS has to provide firmware. It makes it clearer which firmware exists and needs to be updated, reduces attack surface, allows OS verified boot to cover firmware instead of trusting each component does signature checks properly, etc.
2