Live data from Hacker News

Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

linuxveda.com

71–80 of 80 posts

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#71

This whole discussion is misguided. It's not about Linux on 'windows machines', there are no such things as 'windows machines', there are only computers. Giving microsoft the ability to lock out their future competition (emphatically not linux) is where it goes wrong. Computers are universal machines, this idiocy makes all this hardware an extension of a single (software!) corporation that gets to decide after you bu…

Well it was apple that started it and now everybody is just following suit ...

If people demanded root on the original 2007 iPhone when realized what really were the capabilities of the device the walled garden model would have been DOA.

People are well trained by now with consoles, tablets, phones and thermostats that it is totally ok for someone else to tell you what to do with the hardware you own ... and only a couple of old (30+) farts like us that remember the wild west years of the internet and computing are kicking against the trend.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#72

I don't really understand the concern here. Microsoft is simply saying it's optional for its hardware partners to display the option to toggle it. I could see plenty of enterprise systems wanting to not allow users to change this setting. Microsoft isn't trying to block anything here. If you want to use linux simply vote with your dollar and go to the vendors that will let you install it (I imagine most will). That o…

My main concern is it will be a pain to actually find out whether or not a machine supports this option. Nobody will actually actively advertise its absence.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#73

Earlier quoted context omitted.

What if I prefer Debian over Ubuntu? Can I be upset then? I'm sure this will be possible to hack around, but we shouldn't have to hack our own computers to use them. A simple option to disable secure boot would solve all the problems. The vendors know this, so I'm curious why they would chose to not provide the option. Is there some belief that by even having the option, the system would be inherently more insecure?…

Doug, if you use a Linux distro that is not signed, then yes, it is an issue because you will have to track down laptops that allow allow disabling secure boot. BTW, I didn't intend to sound flippant in my original comment, it is just that as I get older (I turn 2^8 next month, yeah :-) I am more concerned with convenience, fun and productive development environments, etc.

> I turn 2^8 next month

256‽

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#74
post #73

Earlier quoted context omitted.

Doug, if you use a Linux distro that is not signed, then yes, it is an issue because you will have to track down laptops that allow allow disabling secure boot. BTW, I didn't intend to sound flippant in my original comment, it is just that as I get older (I turn 2^8 next month, yeah :-) I am more concerned with convenience, fun and productive development environments, etc.

> I turn 2^8 next month 256‽

Good catch. I meant 2^6

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#75

I think the post pretty speculative, given the past and current efforts of Microsoft to get together with OSS and Linux community; using a single slide to come to a conclusion of "Microsoft stopped doing that or has been lying about it" is very speculative. I think we should give credit where it is due, MS is really trying to work with OSS community. Also, a lot of enterprise customer would want always on secure boot…

Will this change block Qubes from running on Lenovo/Dell/HP computers? Qubes is arguably one of the most secure platforms in the market.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#76
I think the reason Microsoft are allowing OEMs to enforce Secure Boot is because Dell, HP et al are going to sell Windows 10 PCs that only run trusted code. [1]

> With Windows 10 Enterprise edition and specially configured OEM hardware, administrators will be able to completely lock down devices so that they're unable to run untrusted code.

> In this configuration, the only apps that will be allowed to run are those signed by a Microsoft-issued code-signing certificate. That includes any app from the Windows Store as well as desktop apps that have been submitted for approval through Microsoft. Enterprises with internal line of business apps can get their own key generator, which will allow those apps to run on their network but won't work outside the network.

[1] http://www.zdnet.com/article/microsoft-reveals-audacious-pla...

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#77
post #49
post #45

Earlier quoted context omitted.

So what if Microsoft decide to no longer allow Ubuntu or Redhat to get signed keys?

I would be more worried about other OS projects that are either too disorganized to meet whatever the signing qualifications are, or have ideological issues which prevent them from participating.

Canonical doesn't enforce signature checks for module loading (which is useful for DKMS based kernel modules, and is also a "freedom to tinker" matter). That may well lead to a revoked Secure Boot key at some point...

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#78
post #17

While some are saying it's only optional and up to the hardware vendors, isn't Microsoft giving Windows7 users a free upgrade? Is this the reason? A potential lock in?

> A potential lock in? Secure boot is part of the BIOS so nope.

I have no idea why people are downvoting you.This is about requirements for new PCs, not upgrades - nobody is going to get their ROM updated by upgrading to Windows 10.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#79
post #40

> If Microsoft’s stance on this issue is not reversed it’s possible we will see a spike in sales by manufacturers such as System76 and ZaReason who ship computers running Linux out of the box without any signs of Secure Boot at all. Come on. I prefer BSD based OSX and Linux myself, but to think that a large enough number of buyers care about Linux support to "spike" sellers is just silly. It's done well on servers, b…

Right, and those sellers are selling to that market almost exclusively. If buyers from that market then are forced into a situation where it's harder to buy the product they want from other suppliers of course the suppliers supplying it will see a spike. They're capturing a larger portion of a small market.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#80

Earlier quoted context omitted.

I would assume that these UEFI machines have a built-in settings screen the same as BIOS-based machines do (and that screen would be where the setting we're discussing is found). If the only way to add keys is thru that screen, then you'd need physical access and malware adding keys wouldn't be an issue.

But that's not how UEFI works. Unlike your traditional BIOS, the settings can be edited from a normal OS by command-line utilities and such, too. In fact, often the only way to do anything useful, given how broken many UEFI setup pages are, is to edit the settings directly.

You're not meant to be able to edit those settings from anywhere other than the setup page. In practice, that's as broken as everything else in modern UEFI implementations, and some allow userland processes within Windows to add signing keys.
Post reply on HN