Machines shipping with Windows 10 may see OEMs enforcing Secure Boot
21–30 of 80 posts
Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot
#22While some are saying it's only optional and up to the hardware vendors, isn't Microsoft giving Windows7 users a free upgrade? Is this the reason? A potential lock in?
Secure boot is part of the BIOS so nope.
Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot
#23Earlier quoted context omitted.
And who gets that $99? Microsoft. Some of us are not okay with one company charging a gatekeeper fee for access to hardware we already bought from a different company.
If you buy from an OEM that pre-installs Windows then you are already paying a fee for the Windows license. If you don't want to pay a fee for software then just buy a from a company that pre-installs Linux.
We currently pay our manufacturers to install our signing keys into UEFI; this is fantastically expensive. It's a damn shame that it is literally impossible to buy a consumer UEFI device without Microsoft's keys in the image unless you pay to have yours put in.
In short: it sucks that they are the default, and it sucks that Red Hat and Ubuntu rolled over on the issue and pay the (latest) Microsoft tax. I would have preferred a more flexible solution.
Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot
#24Ubuntu, Redhat, and other distros are compatible with secure boot. I understand the concern, but the flip side is that if secure boot makes my future Ubuntu laptops more secure that could be a good thing. Linux is here to stay. Relax.
Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot
#25That is really shitty. Though its only an OEM thing? If you build your own machine your still ok I guess.
Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot
#26Ubuntu, Redhat, and other distros are compatible with secure boot. I understand the concern, but the flip side is that if secure boot makes my future Ubuntu laptops more secure that could be a good thing. Linux is here to stay. Relax.
Serious question: how does Secure Boot make you more secure? How many times has a virus latched onto your computer by executing before your system booted up? I've never heard of this happening to anyone I've ever known. The only scenario I can imagine is having a PC set to auto-boot from peripherals, and a USB key having something bad execute before invoking your hard disk's boot loader. And that is obviously possibl…
So it is not entirely without precedent.
Then again, this did not touch the OS bootloader itself, strictly speaking and might not have been prevented by "Secure Boot". Also, once you're diddling with a devices firmware, you might as well tamper with "Secure Boot" as well and defang the checking of the bootloader or even make the firmware live-patch the bootloader...
So, while I am by no means a security expert, I have been wondering the same thing. The entire "Secure Boot" stuff just seems like a lame excuse to allow vendors control over what operating systems you can boot on their devices.
Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot
#27Earlier quoted context omitted.
> If you are able to set your own keys - then there is almost no problem Doesn't this make the feature useless from a security standpoint? If you're able to create your own keys then malware could create its own keys. Maybe if manufacturers could do it that would be handy.
I would assume that these UEFI machines have a built-in settings screen the same as BIOS-based machines do (and that screen would be where the setting we're discussing is found). If the only way to add keys is thru that screen, then you'd need physical access and malware adding keys wouldn't be an issue.
Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot
#28Earlier quoted context omitted.
> If you are able to set your own keys - then there is almost no problem Doesn't this make the feature useless from a security standpoint? If you're able to create your own keys then malware could create its own keys. Maybe if manufacturers could do it that would be handy.
I would assume that these UEFI machines have a built-in settings screen the same as BIOS-based machines do (and that screen would be where the setting we're discussing is found). If the only way to add keys is thru that screen, then you'd need physical access and malware adding keys wouldn't be an issue.
Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot
#29Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot
#30That is really shitty. Though its only an OEM thing? If you build your own machine your still ok I guess.
They're simply easing restrictions on their hardware partners especially since many enterprise customers only want signed software running on their machines.
This is really not a big deal.