The researchers' writeup, in a very fun form, can be found at https://rol.im/securegoldenkeyboot/ With text as follows for those whom the joviality of the original presentation is undesirable: irc.rol.im #rtchurch :: https://rol.im/chat/rtchurch Specific Secure Boot policies, when provisioned, allow for testsigning to be enabled, on any BCD object, including {bootmgr}. This also removes the NT loader options blacklis…
We should just swap the top-link to this post, thanks for the detailed write-up!
Microsoft proves backdoor keys are a bad idea
21–30 of 106 posts
Re: Microsoft proves backdoor keys are a bad idea
#22Re: Microsoft proves backdoor keys are a bad idea
#23(disclaimer, MS employee, non-security expert here). I've read through the article, here, and in other places, and I'm seeing sentiment that this is a big fuck up on Microsoft's part. I might be completely misunderstanding, but I just don't see it. In order to use the backdoor, you've got to flash firmware, so, you've got to have physical access to the device. If an attacker has physical access to your device, you're…
The point the register makes is not that this allows unlocking devices (though that's interesting in it's own right), but that is done via a "secret key" that now got exposed. Very similar to what the government wants with key escrows and other backdoor mechanisms for decryption of communication. Maybe to clarify: it highlights the mechanism (golden key) is flawed. That Microsoft uses it for boot loaders is unimporta…
Re: Microsoft proves backdoor keys are a bad idea
#24Re: Microsoft proves backdoor keys are a bad idea
#25> The policy was effectively inert and deactivated on these products but present nonetheless.
Whenever I read things like this, I always envision that it's not a cock-up at all, but instead a deliberate effort by righteous free software-minded people who happen to work at Microsoft and are dismayed by the things they're asked to do.
But that is probably because I wish it so.
Re: Microsoft proves backdoor keys are a bad idea
#26(disclaimer, MS employee, non-security expert here). I've read through the article, here, and in other places, and I'm seeing sentiment that this is a big fuck up on Microsoft's part. I might be completely misunderstanding, but I just don't see it. In order to use the backdoor, you've got to flash firmware, so, you've got to have physical access to the device. If an attacker has physical access to your device, you're…
The point the register makes is not that this allows unlocking devices (though that's interesting in it's own right), but that is done via a "secret key" that now got exposed. Very similar to what the government wants with key escrows and other backdoor mechanisms for decryption of communication. Maybe to clarify: it highlights the mechanism (golden key) is flawed. That Microsoft uses it for boot loaders is unimporta…
Unfortunately, I don't think that's the message that's being interpreted by the vast majority of readers. I'm delving into opinion territory now, but when the word 'backdoor' is used, aren't most people going to assume that it's an FBI backdoor, instead of a test/development backdoor? This seems like the kind of article that fans the fuels of conspiracy theorists, and no one seems to be doing anything to correct the record.
Re: Microsoft proves backdoor keys are a bad idea
#27Earlier quoted context omitted.
> Isn't a secure boot policy that can be bypassed with physical access more secure than none? Of course it isn't. Impossibility of bypassing is the only reason for secure boot technologies to exist. They are invented so that you are NOT automatically screwed if an attacker has physical access to your device. Secure boot technology is fine in principle, it's just stupid position the manufacturers hold. They ignore rec…
You need admin rights, but not physical access.
Re: Microsoft proves backdoor keys are a bad idea
#28What does leaking your private key have to do with backdoor keys? Isn't this like saying that CAs are backdoored because somewhere there exists a private key for those certs?
Re: Microsoft proves backdoor keys are a bad idea
#29Earlier quoted context omitted.
The point the register makes is not that this allows unlocking devices (though that's interesting in it's own right), but that is done via a "secret key" that now got exposed. Very similar to what the government wants with key escrows and other backdoor mechanisms for decryption of communication. Maybe to clarify: it highlights the mechanism (golden key) is flawed. That Microsoft uses it for boot loaders is unimporta…
Ok, I get it. The message is "don't use backdoors, because they'll inevitably get leaked", which I agree with. Unfortunately, I don't think that's the message that's being interpreted by the vast majority of readers. I'm delving into opinion territory now, but when the word 'backdoor' is used, aren't most people going to assume that it's an FBI backdoor, instead of a test/development backdoor? This seems like the kin…
If you let backdoors in the system, of course the secret services will demand to have it.
In fact, backdoors that were put in place because secret services' pressure, will be suited as developer backdoors as an excuse when found by the mainstream.
First they install backdoors in systems, in order for MS or the US gobertment to have complete access to any computer in the world, then they worry when the Chinese and Russians find them.
Re: Microsoft proves backdoor keys are a bad idea
#30What does leaking your private key have to do with backdoor keys? Isn't this like saying that CAs are backdoored because somewhere there exists a private key for those certs?