Live data from Hacker News

German government warns Windows 8 is a security risk

zeit.de

71–80 of 125 posts

Re: German government warns Windows 8 is a security risk

#71

So just don't install a TPM module if your getting paranoid and does any one know what powers the BND and the plethora of secret police have in Germany? This smells of poujadist knee jerk Anti Americanism

I'd be under the impression that TPM 2.0 modules come pre-installed and are probably surface mounted chips, the removal of which would void any warranty and possibly cause damage to the motherboard.

Re: German government warns Windows 8 is a security risk

#72

Earlier quoted context omitted.

Tell me where these mythical laptops are, other than the Dell XPS 13?

http://www.system76.com/ among others.

I hadn't heard of them, although buying such a thing internationally would be an expensive pain in the ass to return if there were an in-warranty defect!

Also, as an Ubuntu-user, as I really love the idea of these, but they're ugly and look really cheap: http://i.imgur.com/KGPznQz.jpg

Re: German government warns Windows 8 is a security risk

#73
post #35

Earlier quoted context omitted.

I have a Windows 8 notebook and for the first time in my life I have no control over my own general purpose computer: - I can't enter BIOS before entering OS. - Once I enter the BIOS from the OS I can't activate the hard disk password. - I can't install the Windows 8 OS clean. The MSFT has the deal with the computer producers that doesn't allow them to deliver the pure OS medium, you can only backup the already prese…

I had Windows 8 RTM installed on an old ThinkPad that I eventually wiped clean and put Ubuntu on. Granted its not a new laptop with Windows 8, but still, its not impossible to install Linux on a Win 8 laptop.

The notebook hardware made for Windows 8 behaves differently than all PC hardware before. It's irrelevant that the old ThinkPad works, it didn't magically change because the new software arrived.

Re: German government warns Windows 8 is a security risk

#74
post #67
post #53

Earlier quoted context omitted.

It's Acer, but I as far as I know almost nothing it Acer specific -- it's a Windows 8, all OEMs must accept what MSFT wants, plus the concept of third party additions, plus the Intel technologies. I'm surprised how little coverage there is on this all aspects. The discussions of kernel-level "giving up control" existed in Palladium and "technologies formerly known as Palladium ( http://en.wikipedia.org/wiki/Next-Gene…

It was Apple that implemented Palladium in on iPads and iPhones and many technical folks even cheered it on.

I like iPad and iPhone as they are. Apple devices don't come with random crud from the third parties preinstalled. Windows computers have problematic things even in BIOSes: different software from companies that claim to "protect" your computer but can even provide remote access for third parties.

Re: German government warns Windows 8 is a security risk

#75
post #65
post #33

Earlier quoted context omitted.

> The article is basically saying that, because the malware protection is not good enough (i.e. not securing against NSA malware), it's worse than no protection at all. No. If the OS is locked down so only MS-signed applications can run, it is impossible to run software that can detect malware that has been approved by MS. It is also impossible to run software that can remove such malware. If the OS makes it impossib…

First, Windows 8 allows you to run whatever desktop apps you want, including third party antivirus software of your choice that have full access to the system. Second, I haven't seen your argument made for iOS and Chromebooks which are much more locked down than Windows 8. Though one could argue that Chromebook doesn't need to have malware since everything is helpfully uploaded to the cloud.

If the third party antivirus software need to be approved by MS, then I can't run the software of my choice.

It might had been worth mentioned, I am not the first person to talk about liability issues regarding lockdown. I first heard it in a talk that described the iPhone.

Re: German government warns Windows 8 is a security risk

#76

So just don't install a TPM module if your getting paranoid and does any one know what powers the BND and the plethora of secret police have in Germany? This smells of poujadist knee jerk Anti Americanism

I'd be under the impression that TPM 2.0 modules come pre-installed and are probably surface mounted chips, the removal of which would void any warranty and possibly cause damage to the motherboard.

So and your point is? for example None of the consumer Ausus 8 series MB's (1150 Haswell) come with a pre installed TPM they just have the header.

Re: German government warns Windows 8 is a security risk

#77
post #41

Earlier quoted context omitted.

It is even worse. The attempt to escape into OSS/Linux is a step in the right direction. But as long as we are dependent on mass consumer hardware then there is always a risk of being spied through hardware backdoors. In this case it doesn't matter which software we use. Even encryption is useless. It is NOT enough to avoid Windows 8 because the real problem is modern hardware that uses Trusted Computing chips. Trust…

> silenced the mouth of the conspiracy mockers once and for all Before the Snowden leaks, you'd be hard pressed to find a technically-minded person arguing that the NSA doesn't have, at the least, the potential to have their fingers in every pie.

Before the recent leaks, the response was "OK, that's possible in theory buy surely they wouldn't." Now we know if they can, they do.

Re: German government warns Windows 8 is a security risk

#78

Earlier quoted context omitted.

I'd be under the impression that TPM 2.0 modules come pre-installed and are probably surface mounted chips, the removal of which would void any warranty and possibly cause damage to the motherboard.

So and your point is? for example None of the consumer Ausus 8 series MB's (1150 Haswell) come with a pre installed TPM they just have the header.

My point is TPM 2.0 appears to be a different beast. While it's optional today, it probably won't be tomorrow. Vendors are very keen to lock shit down and create walled app gardens in the name of increased security.

Re: German government warns Windows 8 is a security risk

#79
It is fairly amazing that any non-"Five Eyes" nation would use non-auditable and non-buildable software on systems they want to secure for quite a while now. I suppose the recent revelations have drained the last drop of credibility from the "we could but we wouldn't" argument.

Re: German government warns Windows 8 is a security risk

#80
TPMs can't be used to control which software you can install. All they can do is prove what software you're running, which means that a remote provider can choose whether or not to provide a service based on what you're running. Trusted Boot is about providing proof, not about enforcing local policies. Secure Boot can be used to restrict which software you can install, as demonstrated in Windows RT. But that has nothing to do with TPMs - iOS behaves in the same way without using any TPMs.

So I don't really understand the article. Placing trust in TPMs to maintain your secrets obviously depends on you trusting the TPM manufacturer not to hand over any of the secret keys, but having a TPM doesn't mean that you have to place trust in it.

Post reply on HN