Live data from Hacker News

Secure Boot isn't the only problem facing Linux on Windows 8 hardware

mjg59.dreamwidth.org

61–70 of 178 posts

Re: Secure Boot isn't the only problem facing Linux on Windows 8 hardware

#61
post #22
post #19

Earlier quoted context omitted.

Additionally, as point (18) on the page you linked to states: Mandatory. Enable/Disable Secure Boot. On non-ARM systems, it is required to implement the ability to disable Secure Boot via firmware setup. A physically present user must be allowed to disable Secure Boot via firmware setup without possession of PKpriv. Doesn't this mean that (definitely on certified non-ARM systems, and possibly on some ARM systems) you…

As the article (clearly) says, since USB is not set up fast enough to recognize a keyboard before the bootloader has handed control to the OS, there's no way to interrupt boot to do so; Windows will let you reboot to another OS, but only after you click through a license agreement.

Surely a physically present user (mentioned by the requirement of point 18) can disconnect the boot device in order to prevent Windows from booting. The firmware then has ample time to set up USB and allow the user to enter firmware setup.

Alternatively, as a workaround, find someone who has already accepted said agreement elsewhere and have them accept it on your device, disable secure boot and wipe the boot device.

Re: Secure Boot isn't the only problem facing Linux on Windows 8 hardware

#62
post #61
post #22

Earlier quoted context omitted.

As the article (clearly) says, since USB is not set up fast enough to recognize a keyboard before the bootloader has handed control to the OS, there's no way to interrupt boot to do so; Windows will let you reboot to another OS, but only after you click through a license agreement.

Surely a physically present user (mentioned by the requirement of point 18) can disconnect the boot device in order to prevent Windows from booting. The firmware then has ample time to set up USB and allow the user to enter firmware setup. Alternatively, as a workaround, find someone who has already accepted said agreement elsewhere and have them accept it on your device, disable secure boot and wipe the boot device.

Not if the default is to boot from an SSD soldered onto the mainboard, or tucked away in a device that is not designed to be opened.

Re: Secure Boot isn't the only problem facing Linux on Windows 8 hardware

#63
post #19

Earlier quoted context omitted.

Additionally, as point (18) on the page you linked to states: Mandatory. Enable/Disable Secure Boot. On non-ARM systems, it is required to implement the ability to disable Secure Boot via firmware setup. A physically present user must be allowed to disable Secure Boot via firmware setup without possession of PKpriv. Doesn't this mean that (definitely on certified non-ARM systems, and possibly on some ARM systems) you…

This is idiotic. The requirement should be that the user can disable it entirely OR replace the private key. And it should require implementation of an optional password protection.

That is actually the case. Point 17 states:

    Mandatory. On non-ARM systems, the platform MUST implement 
    the ability for a physically present user to select
    between two Secure Boot modes in firmware setup: "Custom"
    and "Standard".

Re: Secure Boot isn't the only problem facing Linux on Windows 8 hardware

#64
post #19
post #16

It appears to me that both System.Fundamentals.Firmware.FirmwareSupportsUSBDevices System.Fundamentals.Firmware.FirmwareSupportsBootingFromDVDDevice are required for Windows Logo Certification for both Windows 7 and 8: http://msdn.microsoft.com/en-us/library/windows/hardware/jj1... Doesn't that directly contradict the hypothetical scenario presented in the article? Additionally, there's Windows 8 hardware out there a…

Additionally, as point (18) on the page you linked to states: Mandatory. Enable/Disable Secure Boot. On non-ARM systems, it is required to implement the ability to disable Secure Boot via firmware setup. A physically present user must be allowed to disable Secure Boot via firmware setup without possession of PKpriv. Doesn't this mean that (definitely on certified non-ARM systems, and possibly on some ARM systems) you…

> and possibly on some ARM systems

Disabling Secure Boot is forbidden on ARM systems. Point 18 ends with:

    Disabling Secure Boot must not be possible on ARM systems.

Re: Secure Boot isn't the only problem facing Linux on Windows 8 hardware

#65
I paid money (I don't know how much, but will be close to 50-100 dollars) for Windows 8 when I bought my Dell Inspiron Special Edition because it had good hardware, but Dell didn't provide an option to get it without the OS. It was the only affordable laptop available with 1080p screen. After a week of many annoyances, I decided to delete all the Windows partitions. After installing Ubuntu using Legacy boot, I tried to install a pirated Windows, but couldn't because there it couldn't be installed on a GPT partition. Installing an OS used to be easy.

Re: Secure Boot isn't the only problem facing Linux on Windows 8 hardware

#66
post #41

Earlier quoted context omitted.

If you agree to the EULA, then you can't get a refund for the Windows license that comes with the computer.

Fair. This is a legitimate concern. I guess I'm a fairly uninformed consumer, as I've never actually sought a refund for a Windows license (nor known this was a possibility).

With Windows 8 it no longer is.

Re: Secure Boot isn't the only problem facing Linux on Windows 8 hardware

#67
post #30

Earlier quoted context omitted.

Is it even that common to find hardware that will take a non-USB keyboard anymore? I've got some, but it's old .

Many desktop machines still do, and most of the modern motherboards in full or mid-tower size still have a PS/2 port or two, for laptops PS/2 support is almost non-existent.

I don't think that even thinkpad docking stations have PS/2 anymore. PS/2 support on modern laptops from non-obscure manufactures (leaving myself some wiggle room for whatever weird Chinese thing you might be able to buy on ebay) may very well be extinct.

Re: Secure Boot isn't the only problem facing Linux on Windows 8 hardware

#68
post #47
post #2

What's wrong with agreeing to the EULA?

Speaking of the EULA, couldn't I just lie to my tablet? Assume there's no communication back to Microsoft and no need for a license under copyright law. Couldn't I just click the "I agree" button while not actually accepting the EULA? Surely, the tablet itself can't be a party to a contract, right?

I do this all the time when I'm signing contracts, I just lie to the paper and sign my name even though I don't agree with it.

Right.

Re: Secure Boot isn't the only problem facing Linux on Windows 8 hardware

#69
post #44

What happens if you disagree with the EULA? (Does it have a disagree button?) What happens if you crtl-alt-del at the EULA prompt?

Or what if a 9 year old girl clicks through? She can not enter into any legal agreements (unless she is an emancipated youth). USA laws.
Post reply on HN