Snarky Technology (fwupd)

When I was a kid, I used to play a video game that tracked who purchased it using a secret key entered on game startup. After 10 or so years, I discovered that the “secret” key was actually stored inside the game in a folder called “font” because font files are boring and it was unlikely that anyone would find it. This kind of “hiding in plain sight” seems like a snarky technology.

The PureOS system has something called the “Firmware update daemon.”

I feel like if I search these forums for how to update the firmware on my Librem 14, the forums describe a clear, manual process for doing so that has nothing to do with the “firmware update daemon.” So the idea that in parallel to that, the Librem 14 with default PureOS is constantly polling a site other than PureOS website for automatic updates over at LVFS: Search Results sounds like a Snarky Technology to me, because I don’t understand what it’s actually doing.

The Gentoo page to describe fwupd dedicates the first sentence to claiming that this technology is safe and effective. I feel like it’s usually the snark technologies that have to declare themselves as safe and effective, and it’s the good technologies that you discover naturally are safe and effective because they were so busy being good technology that they didn’t bother to tell you.

What gives? Can you change my mind here? What’s the important use of the automatic firmware update service?

That Gentoo wiki to me feels a lot like the Wikipedia pages about aliens. If you look up government whistleblowers who say the US government is hiding aliens, they dedicate the wiki to saying that these people are liars. Sometimes they even copy the same sentence multiple times in the article to highlight how important it is to say that these people are liars. Is that maybe a similar feeling to being told point blank that fwupd is safe and effective?

4 Likes

My guess is that the automatic firmware update thing is something that’s in Debian by default and PureOS has simply not done anything about it, so it’s there. Probably it should be removed.

But at my link, Purism literally has like an account on fwupd.org for automatically covertly deploying automatic firmware updates or whatever that’s for.

Why do that if it was just randomly inherited from debian?

2 Likes

You are right, it looks not just inherited.

Another attempt at explaining how it could be reasonable for the thing to exist: firmware updates are not inherently evil, there can (and should) be FLOSS firmware and Purism have done something like that for some kind of laptop firmware I think. Then the firmware update service you found can be useful to distribute that.

Firmware is software, and like any software it can be proprietary (closed) or free (open, FLOSS).

I think the fwupd software itself is free software, and that it can be used in a way where things are okay because (1) it does not install anything automatically and (2) the firmware it installs is FLOSS.

I’m aware that most firmware distributed that way is proprietary, but I’m saying that it does not have to be that way, and having ways to upgrade firmware is good as long as it’s FLOSS and the user is in control.

It took many years to finally have an easy way to update firmware on Linux. I’m really happy about that. It’s not always about tracking or governmental espionage. You can just disable it in Gnome/PureOS Software if you had any doubts. But I doubt that would make you a harder target, more the opposite.

1 Like

I do NOT recommend LVFS. It is a evil floss program to me.

If i worked to Purism developing: Gnu PureOS Inception or Palladium security-level, LVFS will fully blocked.

The shadow of a shadow.
63 61 72 6c 6f 73 67 6f 6e 7a

fwupd package comes from Debian and its use is disabled in PureOS Store. Purism currently doesn’t use its LVFS account (not saying that it never will though) and all this rant about “snarky technology” is just ridiculous when fwupd isn’t a secret in any way and is a Free Software tool that does exactly what it claims to do.

5 Likes

Interesting post. Does the fwupd daemon run by default on PureOS or is it disabled as indicated by dos???

Also, I’m not sure about the use of the word “snark”. “snarky” is different than “sneaky”. “snarky” is closer to “sarcastically” combined with a certain amount of “rudeness”.

“snarky” = acting in a rude and sarcastic way (rude and non-funny sarcasm)

“sneaky” = acting in a sly, secret, or dishonest way

As far as I can see, fwupd is installed by default on desktop images (and only there). Nothing uses it though (at least on the GNOME image, haven’t inspected Plasma one), so the only way to interact with it and make it do anything real without installing anything else (such as gnome-firmware or gnome-software) is through its CLI tool fwupdmgr.

I’m not exactly sure why it’s being installed at all though. It’s been added as a “recommends” relation to metapackages in 2017 and AFAIK there were some plans to use LVFS back then (and that’s where that unused test account comes from), so it may just be an artifact of the past. Can’t tell for sure though, it was before my time here. Nothing depends on it so it can be simply removed if not desired (but leaving it there is, of course, fine too).

In Dr. Who: “The Invasion of Time” S15 E25. Tom Baker was looking for the Great Key, he remembered that “If you wanted to hide a tree where would you put it? in a forest.” (It was a paraphrase of Gilbert K. Chesterson on where to hide a leaf.)

1 Like

I have on at least one occasion, while monitoring network traffic from a Librem 14 using a fairly standard PureOS installation with minimal modifications observed that communications with fwupd website were made despite me never knowingly doing anything that would activate this software directly. So that is kind of entirely my point, if we perceive it to be some “optional” and “disabled” thing and if it is also calling home on the side despite being in that alleged state, that is weird.

I think it is not ridiculous at all that someone can hide Snarky Technology in plain site. Case in point, a very popular and useful video recording application called OBS is available in PureOS. I often install this, something like sudo apt install obs-studio from PureOS directly so that I can video record my desktop or other applications.
It is public knowledge that one of the contributors of this app put into the code that it periodically pings his personal website, effectively giving him visibility into all of the computers that are running OBS. It’s also public knowledge that the feature is provided as the default behavior under the auspices of supporting load balancing.

Still, this is likely a case where you are right and I am wrong, and being paranoid. I won’t deny that. But I don’t follow your logic. Simply because a tool is free software, and because it does exactly what it claims to do, does not mean it doesn’t also do or accomplish more than what it claims to do.

Why would firmware updates need their own automatic updater? Why can’t they be distributed through the ppa from PureOS via apt or something?

I observed that it was running without my prior knowledge on one of my machines about a year ago. I happened to randomly think of it today when I was installing a different OS onto the Librem 14 temporarily, and this other (less good, less free than PureOS) system had a serious of installation issues and hickups when setting up the fwupd service automatically on the Librem 14. Since it was already using my time, it reminded me that I don’t know why this program even exists or how it’s anything but bloatware/spyware in a world where I can just go to Purism’s website and cleanly download BIOS updates for SeaBIOS or PureBoot or whatever and that all seems to work fine, and outside of that I get stuff from apt. My machine is sufficiently old that as far as I know, it has no firmware jail – instead having one of those Atheros chips from before the switch to Intel.

Edit: Good point but maybe it is a snarky thing to do to put sneaky things in software alleging to be Free Software. Like something you would expect from a Microsoft employee who by working there has a relationship so necessarily toxic with technology that they feel it’s only right to treat people in a “rude and sarcastic way (rude and non-funny sarcasm)” if those people are fighting to use Free Software.

3 Likes

Because it makes much more practical sense to do it this way. The firmware this tool is dealing with usually resides in external storages on devices that may need to be put into specific firmware update modes, often requiring user input, rebooting into UEFI capsules etc. The devices being upgraded may also be removable (e.g. Thunderbolt docks, USB sticks). The system-wide package manager, even though it can easily manage kernel-uploaded firmware in /lib/firmware, is not equipped to handle all of that complexity in any other cases; fwupd is.

Also, fwupd won’t update any firmware automatically. What you’re seeing is merely checking the list of available updates, similar to “apt update” or pressing the “refresh” button in PureOS Store. Since the default PureOS installation offers no frontends to fwupd other than its CLI tool, nothing is ever done with that information. On a regular Debian system you would see the list of available updates (should there be any) in GNOME Software (in fact, you can achieve that in PureOS too if you replaced PureOS Store with plain GNOME Software); PureOS doesn’t do that as it would need a way to filter proprietary firmware out since we don’t want to nag the user to install proprietary stuff by default, and AFAIK nobody has written such a filter so far.

Of course this begs the question - is there any reason to install the daemon by default then? And my answer would be: no, right now there’s not, we could remove it from the metapackages and I’ll likely do that soon now that I’m aware of it. The thing is - there was no need to coin any weird conspiracy theories to achieve that outcome, simply asking would be enough.

5 Likes

Regardless, having functionality enabled that is not being used is an unnecessary expansion of the attack surface. So best to disable it or wait until dos does that.

A small amount of information about fwupd: fwupd - Wikipedia and Debian – Details of package fwupd in trixie

The above Wikipedia article observes that, before fwupd existed,

Previously, the initiation of UEFI firmware updates within an operating system could, on most systems, only be performed using Microsoft Windows or DOS-specific software.

and I think we would all agree that that is badness. So, for general Linux users, who want those firmware updates, it is better not to have to keep Windows around.

Obviously this only applies to Linux distros that use or support UEFI. That doesn’t apply to Purism hardware, as far as I know, but you are free to attempt to run PureOS on non-Purism hardware - and some Linux distros use UEFI by default, with the intention of running on mainstream hardware that is sold with the anticipation of running Microsoft Windows.

3 Likes

Respect you. I think your frustration with me on this is justified.

But if I want to think constructively and maybe this should become a suggestion ticket that I send to fwupd:

Despite these similarities I tend to make the (perhaps naive) assumption that apt update exists as a command because the computer isn’t polling it automatically without being told to. Or at least wouldn’t be if I turn off automatic updates in the PureOS store GUIs.

One of my biases is that I want to pretend the computer works how I perceived computers to work many years ago. To that end, I like the idea of a computer who only does its networking when I tell the computer to do the networking, rather than a system that is maximally “easy” by being in constant communication with the world of devices around it. (This being also why I tend to disable anything with avahi or geoclue in the name, for example.) Is fwupd actually different from apt on this or did I just basically fail to turn off automatic updates setting (perhaps applies to both) in the PureOS store?

If they are different, that might be the case of what I could suggest to fwupd, to make a mode (even if they don’t make it the default mode) where the automatic communication part is off by default and it really is analogous to apt update by giving me a command I’m supposed to type for the fwupd update.

In my case often I use something like sudo apt install mate and then switch to MATE desktop in the gdm login screen. Is that subtly messing with a default and introducing my issue?

Well this is definitely true, especially on a PureBoot machine which may be incapable of booting Windows at all by design. But if there’s a possibility for a legitimate coherent constructive suggestion that I could give fwupd to have a command based polling instead of automated polling here, I don’t want to distract away from that by saying “Windows bad” which really should have been self-evident regardless.

1 Like

sudo systemctl disable fwupd

?

Probably check with sudo systemctl status fwupd first.

PS That points at https://fwupd.org/ and maybe there is good documentation and explanation there.

Actually, apt can do it on its own with its apt-daily service and there are systems that set it up by default. Of course you can configure this behavior.

Apparently in case of fwupd getting rid of this is simply a matter of disabling fwupd-refresh.timer systemd unit, which just calls fwupdmgr refresh daily.

1 Like

It might be a true observation, but there is zero causality … and I’m not even sure it’s true. In terms of what I mean by “zero causality” … one could say “before the introduction of [anything beginning in 2013] one could only do firmware updates using MS Windows”.

The fact is that most major motherboard manufacturers adopted the ability to do OS independent updates of their firmware just from UEFI menus. My current desktop, for example is on a ASUS H87Iplus motherboard which was released in 2013 (fwupd was 2015). It has “EZ Flash” built in. I updated my firmware before installing any OS.

Also many firmware suppliers allowed downloads of a bootable firmware loader (and a lot of that was based on FreeDOS).

Slightly off topic, but I just noticed my Librem 14 had an update to PureOS Store but my Librem 15 doesn’t even have it installed. I upgraded both machines to PureOS 11 Crimson in early June 2026.

Is there any reason to have PureOS Store on a laptop? I mostly update via the command line, but sometimes use Synaptic because it knows all the command line switches that I don’t use every day. I haven’t used GNOME Software in ages because it was so buggy. Maybe PureOS Store fixed them all? :smiling_face_with_sunglasses:

1 Like

Is there a word that starts with “s” and ends in “y” that is the reverse of “snarky”: e.g. (non-rude and funny sarcasm)?

Smarmy?
10

1 Like