Earlier quoted context omitted.
If it's turned off by default, it might as well be useless to protect the hundreds of millions of non-technical users who are more prone to get malware. >But if I were to remove a MS key, am I right in assuming that that would prevent anybody from running windows on that machine (at least without installing the key or turning it of)? Windows 8 boots fine without Secure Boot enabled or even supported. However, if you…
The only real reason that I (as a Linux user) can see is for the amusement value, as well as the opportunity to watch others fail to boot Windows on this machine and the opportunity to engage in an extended philosophical discussion regarding this event. Mind you, I might be a niche case.
Torvalds clarifies Linux's Windows 8 Secure Boot position
131–140 of 147 posts
Re: Torvalds clarifies Linux's Windows 8 Secure Boot position
#132Is it possible to "sign" windows 8 and other windows drivers with your own root key so you can have your own key in UEFI and have windows still work? I'm guessing that microsoft has no options for this at all, but I don't know for sure.
Microsoft has no way to prevent this (short of requiring vendors not to allow people to add keys).
Re: Torvalds clarifies Linux's Windows 8 Secure Boot position
#133Re: Torvalds clarifies Linux's Windows 8 Secure Boot position
#134Having read through the entire thread instead of just the expletives, in my opinion it's a rare case of Linux and Greg being totally wrongheaded on the issue. The problem crops up because redhat submitted a pull request to enhance the existing in kernel live inclusion of additional trusted x.509 certificates. Note that this is 100% upstream and live. The pull was to add the ability to extract these x.509 certificates…
Alternatively, Microsoft could sign x.509 certs. Why are they placing certificate data into Windows binaries in the first place? The Linux kernel is simply not the place to parse Windows binaries. It's not Linus's fault the de facto standard is a Windows binary, it's just another harmful side-effect of the Windows monopoly. Really SecureBoot should just die on the vine. But the monopolist wants to force it on their c…
Re: Torvalds clarifies Linux's Windows 8 Secure Boot position
#135Physical access is god access. Admin/root is god access. Guard them both with your life. I fail to see how handing over control of your boot to some 3rd party who clearly doesn't have the same interests that you do is anything but a horrible idea. Just physically secure your boxes(or VDI them) and use permissions and ACLs to do what they were designed to do[control and delegate authority]. A good first step for Micro…
It's actually a good idea if you're the party who's getting authority over the world's computers handed over to it.
> use permissions and ACL
I still have no idea how these work in the Windows world [1]. There's nowhere obvious in the UI or the "dir" command that shows you what the ownership and permission is [2], unlike Linux's ls -al.
My one experience with Windows permissions is, in the early '00s, I put an NTFS partition on an external drive because I wanted to put >4GB files on it. I copied them and got a bunch of permissions errors opening them on another computer. My impression of Windows access controls from this: They're invisible things the OS attaches to your files which will potentially make them unreadable later.
[1] I understand there's something called ACL's in Linux too, but I never use them.
[2] I don't have much experience with multi-user Windows systems, and Linux has been my main OS for 3-4 years so I don't have as much experience with post-XP OS's.
Re: Torvalds clarifies Linux's Windows 8 Secure Boot position
#136Having read through the entire thread instead of just the expletives, in my opinion it's a rare case of Linux and Greg being totally wrongheaded on the issue. The problem crops up because redhat submitted a pull request to enhance the existing in kernel live inclusion of additional trusted x.509 certificates. Note that this is 100% upstream and live. The pull was to add the ability to extract these x.509 certificates…
> Linus is really smart, but sometimes he makes a snap decision and then will perform whatever mental gymnastics are necessary to defend it to the death. Hmm, could it be argued that this is less a snap judgement and more one of strengthening the long-term political and technical health of the OS? Rather than take the easier short-term path, which may eventually put Linux's metaphorical balls into a Microsoft vice, h…
If that was the primary concern where was the criticism when his employer, The Linux Foundation, announced with great fanfare that they had released a microsoft ca signed boot loader to support linux uefi secure boot with the default oem trust setups.
If there is anyone that has a chance at providing a FOSS UEFI signing alternative to Microsoft it's the Linux Foundation. But they're unwilling or unable to do it. Redhat is unwilling to and has proven they have trouble securing their signing keys. Canonical tried and failed to sell vendors on including a ubuntu key, and they weren't even looking to sign for other companies.
There will soon be plenty of people running linux on their computers with secure boot enabled and relying on Microsoft's CA for a chain of trust. It's a done deal and no one is out there stepping up to provide a viable FOSS PKI alternative.
The only thing being debated here is if many of them will be running rather slow and buggy video drivers.
Re: Torvalds clarifies Linux's Windows 8 Secure Boot position
#137Earlier quoted context omitted.
Alternatively, Microsoft could sign x.509 certs. Why are they placing certificate data into Windows binaries in the first place? The Linux kernel is simply not the place to parse Windows binaries. It's not Linus's fault the de facto standard is a Windows binary, it's just another harmful side-effect of the Windows monopoly. Really SecureBoot should just die on the vine. But the monopolist wants to force it on their c…
Maybe Microsoft has patents on the PE format. And they're crossing their fingers and hoping Linus loses this argument, so they can become the next SCO and sue the entire Linux world.
Re: Torvalds clarifies Linux's Windows 8 Secure Boot position
#138Earlier quoted context omitted.
What exactly is illegal? Selling a machine with OS or not selling it without one? And as for the "this explains then why ThinkPads must come with Windows" - no. It doesn't explain it. Secure boot has to be present on Windows certified machine, not the other way around. Lenovo can sell whatever they want (but apparently it's beneficial for them economically to only sell Windows machines). Also, certified machine has t…
Responding from a French point of view, so that might not match Brazil (but does match Germany): you can not tie a material product with an immaterial one, if you do not also sell the material product as a stand alone. You cannot sell a car with an insurance if you don't sell the car alone. You cannot sell a phone with a plan if you don't sell the phone alone (see: iPhone 1 release in Europe). You cannot sell a compu…
Sure you can. I bought a very nice MacBook Air in Paris a couple of months back - and you most definitely can't buy a MacBook Air without OS X.
Re: Torvalds clarifies Linux's Windows 8 Secure Boot position
#139Having read through the entire thread instead of just the expletives, in my opinion it's a rare case of Linux and Greg being totally wrongheaded on the issue. The problem crops up because redhat submitted a pull request to enhance the existing in kernel live inclusion of additional trusted x.509 certificates. Note that this is 100% upstream and live. The pull was to add the ability to extract these x.509 certificates…
For the average linux user, key signing isn't really a big deal, imho. Running as a user and protecting root without running unnecessary services is your first step, after that it's all kind of iffy. Signing something from an untrusted source (Having dealt with having to revoke a bunch of Microsoft signed stuff not too long ago, I assure you Microsoft is not infallible) doesn't buy you a whole lot. If you build a dri…
It isn't a big deal to the average user because os internals aren't a big deal to the average user. Never the less, linux hasplenty of industry standard security measures like IOMMU support, DEP, ASLR, containers, RBAC, seccomp and so on.
You can't expect the average user to know what technical countermeasures they need anymore than you can expect them to know what garbage collection or interrupt coalescence strategy suits them best. It's important for folks with domain knowledge and pull requests to look out for them. The only problem in this case is the politicization rooted in hatred of a version of microsoft that differs considerably from the one that exists today.
Running as a user and protecting root without running unnecessary services is your first step, after that it's all kind of iffy.
That's advice from a different era. On the desktop (any flavor) the attack vectors are almost entirely malicious attachements, plugin exploits, browser and supporting library exploits, other random outbound clients and social engineering.
While linux isn't a popular target, it is at least as vulnerable to these attacks as the others. And due to design issues in X windows, once you can run client native code it is trivial to sniff credentials from the next elevation event.
While it's not infallibile, requiring the rootkit or bootkit to be signed by a CA raises the bar dramatically.