Live data from Hacker News

Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

linuxveda.com

41–50 of 80 posts

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#41

I think the post pretty speculative, given the past and current efforts of Microsoft to get together with OSS and Linux community; using a single slide to come to a conclusion of "Microsoft stopped doing that or has been lying about it" is very speculative. I think we should give credit where it is due, MS is really trying to work with OSS community. Also, a lot of enterprise customer would want always on secure boot…

Is there any evidence that MS's recent OSS efforts are a reflection of anything other than the fact that Ballmer, who was ideologically against OSS, has left and so now MS can act rationally and use the OSS community the same way many other large companies do?

If working with the OSS community is in their own immediate self interest -- and I'm curious whether someone can point out something they've done that isn't -- I don't know how much light it sheds on an area such as OEMs where their self interest is best served by locking linux out.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#42

A few things. One possible direction the industry could go in (suggested by Win 8) is that the "laptop" as we know it could be replaced by tablets, and potentially these could be very low cost devices. The fly in that ointment is that vendors are not that excited about selling inexpensive machines. For instance, going with the "only a USB 3.1 port" approach would make a lot of sense for a cheap tablet but Apple did i…

The negative impact is not on the average Linux user who just runs a distro, but it will be bad for anyone who wants to compile and run their own kernels.

It will be bad for the average Linux user, because whoever has the signing keys can decide what Linux distributions a user can run and what versions not.

Let's not forget that e.g. Mint also started out as a distribution with a tiny user base. They are now big, because users could install and try Mint. In a UEFI world without unlockable boot loaders it's game over for OS competition, because parties can be excluded because they are too small, too competitive, or just because.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#44
https://technet.microsoft.com/en-us/windows/dn168167.aspx

"All Certified For Windows 8 PCs allow you to trust a noncertified bootloader by adding a signature to the UEFI database, allowing you to run any operating system, including homemade operating systems."

That's listed separately from disabling secure boot, which is what this article (and the previous Ars Technica article) are about.

Is there any reason to think that this part has changed?

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#45

Earlier quoted context omitted.

What if I prefer Debian over Ubuntu? Can I be upset then? I'm sure this will be possible to hack around, but we shouldn't have to hack our own computers to use them. A simple option to disable secure boot would solve all the problems. The vendors know this, so I'm curious why they would chose to not provide the option. Is there some belief that by even having the option, the system would be inherently more insecure?…

Doug, if you use a Linux distro that is not signed, then yes, it is an issue because you will have to track down laptops that allow allow disabling secure boot. BTW, I didn't intend to sound flippant in my original comment, it is just that as I get older (I turn 2^8 next month, yeah :-) I am more concerned with convenience, fun and productive development environments, etc.

So what if Microsoft decide to no longer allow Ubuntu or Redhat to get signed keys?

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#46

Earlier quoted context omitted.

What if I prefer Debian over Ubuntu? Can I be upset then? I'm sure this will be possible to hack around, but we shouldn't have to hack our own computers to use them. A simple option to disable secure boot would solve all the problems. The vendors know this, so I'm curious why they would chose to not provide the option. Is there some belief that by even having the option, the system would be inherently more insecure?…

Doug, if you use a Linux distro that is not signed, then yes, it is an issue because you will have to track down laptops that allow allow disabling secure boot. BTW, I didn't intend to sound flippant in my original comment, it is just that as I get older (I turn 2^8 next month, yeah :-) I am more concerned with convenience, fun and productive development environments, etc.

Thankfully, that's just about any x86 laptop at present.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#47
post #26
post #15

Earlier quoted context omitted.

Serious question: how does Secure Boot make you more secure? How many times has a virus latched onto your computer by executing before your system booted up? I've never heard of this happening to anyone I've ever known. The only scenario I can imagine is having a PC set to auto-boot from peripherals, and a USB key having something bad execute before invoking your hard disk's boot loader. And that is obviously possibl…

I read an article a couple of months back (like October-Novemberish 2014) about the NSA putting a virus into the firmware of a RAID controller on some Dell servers that would patch Windows Server 2003 (R2?) during startup. So it is not entirely without precedent. Then again, this did not touch the OS bootloader itself, strictly speaking and might not have been prevented by "Secure Boot". Also, once you're diddling wi…

> I read an article a couple of months back (like October-Novemberish 2014) about the NSA putting a virus into the firmware of a RAID controller on some Dell servers that would patch Windows Server 2003 (R2?) during startup.

The NSA and the PRC will get their payloads signed with the appropriate keys. Everyone else will do something cheaper and simpler, like reading their target's gmail accounts.

> So, while I am by no means a security expert, I have been wondering the same thing. The entire "Secure Boot" stuff just seems like a lame excuse to allow vendors control over what operating systems you can boot on their devices.

Yes: http://mjg59.dreamwidth.org/20187.html [1]

[1]: It's worth noting that mjg59 is a big secure boot fan, and did most/all of the Linux implementation.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#48
post #40

> If Microsoft’s stance on this issue is not reversed it’s possible we will see a spike in sales by manufacturers such as System76 and ZaReason who ship computers running Linux out of the box without any signs of Secure Boot at all. Come on. I prefer BSD based OSX and Linux myself, but to think that a large enough number of buyers care about Linux support to "spike" sellers is just silly. It's done well on servers, b…

Plus, you know, Dell will ship you a laptop with Ubuntu on it.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#49
post #45

Earlier quoted context omitted.

Doug, if you use a Linux distro that is not signed, then yes, it is an issue because you will have to track down laptops that allow allow disabling secure boot. BTW, I didn't intend to sound flippant in my original comment, it is just that as I get older (I turn 2^8 next month, yeah :-) I am more concerned with convenience, fun and productive development environments, etc.

So what if Microsoft decide to no longer allow Ubuntu or Redhat to get signed keys?

I would be more worried about other OS projects that are either too disorganized to meet whatever the signing qualifications are, or have ideological issues which prevent them from participating.
Post reply on HN