-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

The situation isn't ideal, but I can see where Debian are coming from here.

The Intel microcode is non-free. It comes pre-installed in the processor. It contains a security vulnerability.

Intel releases a security update to said non-free microcode. What's a free distribution to do? If they don't pass on the update, their users are stuck with the vuln for ever.

AIUI this update does not contain any non-free code that is executed by the system. It's simply a free package (from contrib) to load the firmware into the chip. The firmware itself is non-free (Intel's fault), and is therefore stored in the non-free repository.

Consider the alternative - a distro like Trisquel refuses the update because it's non-free. The old version of the microcode continues to reside inside its users' CPUs, and they are vulnerable to the security issue indefinitely. The irony is that Trisquel's users will still have non-free code in their system, just an older version. Worst of both worlds.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iF4EAREIAAYFAlIzDDEACgkQgijxUCZnvltjYQD/UBi7YR9r9ONmj6pNShEnqkHY
7iibTfU1a1AMxtgk8EUA/0/iYQ9ambQyr4fwQ7uYHqOZx34tWiibsUubsa+SHcc4
=RdtM
-----END PGP SIGNATURE-----

Reply via email to