Live data from Hacker News

Secure Boot is broken on 200 models from 5 big device makers

arstechnica.com

1–10 of 147 posts

Re: Secure Boot is broken on 200 models from 5 big device makers

#4
>In 2012, an industry-wide coalition of hardware and software makers adopted Secure Boot to protect against a long-looming security threat

This joke never gets stale, wait it is not a joke ?

I still believe the only reason for this to exist is to eventually turn general computing devices into a locked down Cell Phone Spying Device.

Re: Secure Boot is broken on 200 models from 5 big device makers

#5
It feels utterly absurd that devices typically have certain keys are baked in, cannot be removed. I believe there are still Microsoft keys on nearly every device?

It's unconscionable to tell users this is here to keep you safe, but that you have no control over it & if something goes wrong well then too bad, at best we might provide an update.

(Also that governments can probably force these root-of-trust companies to sign payloads to circumvent security is also pretty icky to me.)

Re: Secure Boot is broken on 200 models from 5 big device makers

#6
> To this day, key players in security—among them Microsoft and the US National Security Agency—regard Secure Boot as an important, if not essential, foundation of trust in securing devices in some of the most critical environments, including in industrial control and enterprise networks.

Am I correct that Secure Boot purely exists to prevent this attack vector: malware gets root on the OS, hardware allows updating firmware via OS now owned by malware, but Secure Boot means you have to wipe only the hard drive instead of the firmware to eliminate the malware.

It seems like it would be a lot simpler and more reliable to add a button to motherboards that resets the firmware to the factory version (on memory that can't be written by a malicious OS).

Re: Secure Boot is broken on 200 models from 5 big device makers

#7
post #6

> To this day, key players in security—among them Microsoft and the US National Security Agency—regard Secure Boot as an important, if not essential, foundation of trust in securing devices in some of the most critical environments, including in industrial control and enterprise networks. Am I correct that Secure Boot purely exists to prevent this attack vector: malware gets root on the OS, hardware allows updating f…

I'm having strange nostalgic flashbacks the '90s where I kept wondering why nobody offered a hard drive with a physical read-only toggle button. (Mounted to the front of the 5.25 inch bay in a tower chassis, as was the style of the time.)

Obviously you need some read+write storage elsewhere on the same computer, but you could reliably freeze large chunks of stuff in a way that would be impervious to viruses or hackers.

Re: Secure Boot is broken on 200 models from 5 big device makers

#8
Isn't that a vulnerability that still requires physical access to hardware?

Or is that just a protection against rootkits?

I still fail to understand what secure boot is protecting against: if a machine is compromised remotely, does secure boot prevents installing a rootkit that's invisible from virus scanners?

Re: Secure Boot is broken on 200 models from 5 big device makers

#9
post #6

> To this day, key players in security—among them Microsoft and the US National Security Agency—regard Secure Boot as an important, if not essential, foundation of trust in securing devices in some of the most critical environments, including in industrial control and enterprise networks. Am I correct that Secure Boot purely exists to prevent this attack vector: malware gets root on the OS, hardware allows updating f…

That sounds correct, but even the savviest of users might not be aware they have malware installed when they decide to re-install windows. If cleaning malware requires pressing a button on the MOBO then I can imagine only a single-digit percentage of users will actually click it.

Re: Secure Boot is broken on 200 models from 5 big device makers

#10
post #4

>In 2012, an industry-wide coalition of hardware and software makers adopted Secure Boot to protect against a long-looming security threat This joke never gets stale, wait it is not a joke ? I still believe the only reason for this to exist is to eventually turn general computing devices into a locked down Cell Phone Spying Device.

This has been my theory since Windows 11 required TPM. It's not to protect the consumer, it's to protect the IP-holder.

The PC is the lone outlier in the locked-down, walled-garden world of consoles, cell phones, tablets, smart TVs, EVs, etc. I think there's a concerted effort to change that.

Post reply on HN