Live data from Hacker News

What is an SBAT and why does everyone suddenly care

mjg59.dreamwidth.org

41–50 of 276 posts

Re: What is an SBAT and why does everyone suddenly care

#41
IMO secure boot is a waste of time for most scenarios, if theres closed source EUFI code running god knows what in the background, it dosn't matter how signed and secure your OS kernel is.

Ive never been sucessfully able to dual boot windows and linux on a mobo with secure boot turned on, it seems that is a feature not a bug I'm sure MS would never influence hardware vendors to make it dissadvantage a growing number of linux users.

Re: What is an SBAT and why does everyone suddenly care

#42
post #32

Earlier quoted context omitted.

> widespread rootkit level malware and they are trying to stay ahead of the curve Microsoft is within US-legislation. So a three-letter agency already has the keys and their spyware is a signed UEFI module.

[flagged]

Certificate transparency is intended to solve this issue.

Re: What is an SBAT and why does everyone suddenly care

#44

Earlier quoted context omitted.

[flagged]

I think you underestimate how close big tech and telecom companies are to three letter agencies. See the "Protect America Act" of 2007 which covered everyone's asses for warrantless spying.

Ahh memories: Long before Snowden there was good ole 641a

https://en.wikipedia.org/wiki/Room_641A

Re: What is an SBAT and why does everyone suddenly care

#45

Earlier quoted context omitted.

> widespread rootkit level malware and they are trying to stay ahead of the curve Microsoft is within US-legislation. So a three-letter agency already has the keys and their spyware is a signed UEFI module.

[flagged]

Oh, you mean like the time Microsoft was the first company in the Prism program uncovered by Snowden, later followed by Yahoo, Google, Facebook, YouTube, Skype, AOL, and Apple? The program allowing the NSA to decrypt any traffic* or data of these vendors? The publication of which had, like, no consequences for Microsoft or the others?

Yeah. I don't think they're really afraid of repeating that.

Re: What is an SBAT and why does everyone suddenly care

#46

I think there's more than meets the eye here. I think part of the reason MS is enforcing TPM2.0 and now this SBAT update is that there is widespread rootkit level malware and they are trying to stay ahead of the curve. When it comes to the realities of dual-booting, I had tons of problems with Win7/8/10 with suspend-to-hiberfile.sys issues and updates 10 years ago breaking grub. 10 years ago I finally decided, "You k…

hibernate always have been more trouble than it's worth. and specially now when boots takes less time than loading your webmail.

it just screams you have no data hygiene. it's the extra step after living years with 723 open tabs.

qemu passtrhu is the way. and if you don't own expensive hardware (i.e. only integrated graphics like all feasible laptops), just dual boot with your own signing keys so you don't have yo worry about revocation crap. either its signed or not. revocation is just replacing the root PK keys.

Re: What is an SBAT and why does everyone suddenly care

#47

Earlier quoted context omitted.

> widespread rootkit level malware and they are trying to stay ahead of the curve Microsoft is within US-legislation. So a three-letter agency already has the keys and their spyware is a signed UEFI module.

[flagged]

I lost all illusion this was the case after hushmail https://www.wired.com/2007/11/encrypted-e-mai/

Re: What is an SBAT and why does everyone suddenly care

#48

I think there's more than meets the eye here. I think part of the reason MS is enforcing TPM2.0 and now this SBAT update is that there is widespread rootkit level malware and they are trying to stay ahead of the curve. When it comes to the realities of dual-booting, I had tons of problems with Win7/8/10 with suspend-to-hiberfile.sys issues and updates 10 years ago breaking grub. 10 years ago I finally decided, "You k…

>tweak QEMU for performance and passthrough Any guide you could link to that covers all of this? I would like to setup a very performant windows VM.

Re: What is an SBAT and why does everyone suddenly care

#49
Something seems to be wrong with the whole security model.

> those versions of grub had genuine security vulnerabilities that would allow an attacker to compromise the Windows secure boot chain

This feels like a "my secure compartments are all connected together" moment. If Microsoft want to verify that they're in an all-Microsoft boot chain, sure, whatever, fine. But somehow the compromise of any loader allows compromise of Windows? And in turn Microsoft are able to break grub installations? Why is that acceptable?

(also, I feel a bit "I told you so" about this. Back when all this was being introduced I felt that (a) secure boot increases the risk of locking you out of your machine and/or data loss and (b) a situation where Linux is dependent on the collaboration of Microsoft in order to boot is very dangerous long-term.)

Re: What is an SBAT and why does everyone suddenly care

#50

IMO secure boot is a waste of time for most scenarios, if theres closed source EUFI code running god knows what in the background, it dosn't matter how signed and secure your OS kernel is. Ive never been sucessfully able to dual boot windows and linux on a mobo with secure boot turned on, it seems that is a feature not a bug I'm sure MS would never influence hardware vendors to make it dissadvantage a growing number…

agree its a waste of time, but we pay the paranoid cost is special occasion. it does make breaking FDE just a little bit more annoying/expensive.

the only time it's worth the hassle for we to enable it: travel to the USA, Russia and most of africa (if the country have USA backed airport security, like uganda). pause updates, enable secure boot with a disposable key we don't store anywhere. that on top of the usual FDE with plausible deniability dual boot.

but we still prefer to just fly contributors with blank devices if we can.

Post reply on HN