Live data from Hacker News

Secure Boot is broken on 200 models from 5 big device makers

arstechnica.com

101–110 of 147 posts

Re: Secure Boot is broken on 200 models from 5 big device makers

#101

Earlier quoted context omitted.

> it can prevent ... switching a trusted kernel for a malicious, modified copy. Or a free OS.

Being able to enroll your own keys (or disable secure boot entirely) is a requirement for being a compliant implementation. So sign your own kernel with your own keys and enroll them to your UEFI and you have 0 problem with installing "a free OS" (it can also just be regular EFI binaries).

> Being able to enroll your own keys (or disable secure boot entirely) is a requirement for being a compliant implementation.

That may be true on x86, but on ARM, Microsoft specifically requires that you not be able to do either of those things:

> 13. On ARM platforms Secure Boot Custom Mode is not allowed. A physically present user cannot override Secure Boot authenticated variables (for example: PK, KEK, db, dbx).

> 18. Enable/Disable Secure Boot. On non-ARM systems, it is required to implement the ability to disable Secure Boot via firmware setup. A physically present user must be allowed to disable Secure Boot via firmware setup without possession of PKpriv. A Windows Server may also disable Secure Boot remotely using a strongly authenticated (preferably public-key based) out-of-band management connection, such as to a baseboard management controller or service processor. Programmatic disabling of Secure Boot either during Boot Services or after exiting EFI Boot Services MUST NOT be possible. Disabling Secure Boot must not be possible on ARM systems.

Re: Secure Boot is broken on 200 models from 5 big device makers

#102

Earlier quoted context omitted.

You can disable Secure Boot on x86 PCs, but nowhere else.

So how do people install openbsd on the thinkpad x13s?

Here's an article about the rule being made in the first place (IIRC, the rule got made at the same time Windows on ARM was itself first given to manufacturers): https://softwarefreedom.org/blog/2012/jan/12/microsoft-confi...

I'm not sure how it's working on those laptops, but I'd imagine the choices are either that Lenovo got given an exception, the rule as a whole got changed, or that Microsoft just hasn't noticed or is intentionally looking the other way.

Re: Secure Boot is broken on 200 models from 5 big device makers

#103

Earlier quoted context omitted.

Being able to enroll your own keys (or disable secure boot entirely) is a requirement for being a compliant implementation. So sign your own kernel with your own keys and enroll them to your UEFI and you have 0 problem with installing "a free OS" (it can also just be regular EFI binaries).

Making a non-microsoft product require manual key enrollment, while Microsoft products do not require such enrollment, sounds like abusing monopoly status to give new entrants a disadvantage. The 1990s antitrust people would have a field day with that one. Also, by the way, I am an ex Microsoft employee, bet you wouldn't guess that from these comments. I do personally consider secure boot and TPM to have been pushed…

> sounds like abusing monopoly status to give new entrants a disadvantage.

It is, and it isn't something I like, I'd prefer if no keys were enrolled by default.

> I am an ex Microsoft employee, bet you wouldn't guess that from these comments.

No I wouldn't have guessed, but MS is so big that just saying your were a MS employee could mean in any one of the thousands of departments not even remotely related to Windows. But that is neither here nor there as it doesn't change anything about my statement.

> I do personally consider secure boot and TPM to have been pushed in bad faith, not for serious security concerns.

Sure, but I still prefer to have this now that I can use it, even if its introduction was in bad faith (which it was consdering IIRC there were e-mail floating around talking about if they could get away with making it only work with Windows or maybe it was some other security mechanism).

Re: Secure Boot is broken on 200 models from 5 big device makers

#104

Earlier quoted context omitted.

Being able to enroll your own keys (or disable secure boot entirely) is a requirement for being a compliant implementation. So sign your own kernel with your own keys and enroll them to your UEFI and you have 0 problem with installing "a free OS" (it can also just be regular EFI binaries).

> Being able to enroll your own keys (or disable secure boot entirely) is a requirement for being a compliant implementation. That may be true on x86, but on ARM, Microsoft specifically requires that you not be able to do either of those things: > 13. On ARM platforms Secure Boot Custom Mode is not allowed. A physically present user cannot override Secure Boot authenticated variables (for example: PK, KEK, db, dbx).…

That is true, but I wasn't talking about those considering we are on a post about x86 MoBos (I guess I could have clarified that).

And until this requirement on ARM is changed (or there are options I can buy which allow it) I don't consider it a secure platform.

Re: Secure Boot is broken on 200 models from 5 big device makers

#105

Earlier quoted context omitted.

Making a non-microsoft product require manual key enrollment, while Microsoft products do not require such enrollment, sounds like abusing monopoly status to give new entrants a disadvantage. The 1990s antitrust people would have a field day with that one. Also, by the way, I am an ex Microsoft employee, bet you wouldn't guess that from these comments. I do personally consider secure boot and TPM to have been pushed…

> sounds like abusing monopoly status to give new entrants a disadvantage. It is, and it isn't something I like, I'd prefer if no keys were enrolled by default. > I am an ex Microsoft employee, bet you wouldn't guess that from these comments. No I wouldn't have guessed, but MS is so big that just saying your were a MS employee could mean in any one of the thousands of departments not even remotely related to Windows.…

> could mean in any one of the thousands of departments not even remotely related to Windows.

That's true. I was a dev in Windows though. I wasn't privy to any memorable internal discussions about secure boot.

Anyway, I'm just saying I'm not a kneejerk windows or ms hater, which I think I read as in discussions like this.

Re: Secure Boot is broken on 200 models from 5 big device makers

#107

Earlier quoted context omitted.

> sounds like abusing monopoly status to give new entrants a disadvantage. It is, and it isn't something I like, I'd prefer if no keys were enrolled by default. > I am an ex Microsoft employee, bet you wouldn't guess that from these comments. No I wouldn't have guessed, but MS is so big that just saying your were a MS employee could mean in any one of the thousands of departments not even remotely related to Windows.…

> could mean in any one of the thousands of departments not even remotely related to Windows. That's true. I was a dev in Windows though. I wasn't privy to any memorable internal discussions about secure boot. Anyway, I'm just saying I'm not a kneejerk windows or ms hater, which I think I read as in discussions like this.

I also am not a blind MS hater or supporter. I probably do often give MS too much leeway for a lot of things where more skeptical people would basically instantly dismiss it. I guess I just try to make the best out of what is given me.

> I wasn't privy to any memorable internal discussions about secure boot.

I think it was a leaked email from Bill Gates around when UEFI or Secure Boot was becoming a thing. I wasn't able to find it after searching for a while though.

Re: Secure Boot is broken on 200 models from 5 big device makers

#108
post #7
post #6

> To this day, key players in security—among them Microsoft and the US National Security Agency—regard Secure Boot as an important, if not essential, foundation of trust in securing devices in some of the most critical environments, including in industrial control and enterprise networks. Am I correct that Secure Boot purely exists to prevent this attack vector: malware gets root on the OS, hardware allows updating f…

I'm having strange nostalgic flashbacks the '90s where I kept wondering why nobody offered a hard drive with a physical read-only toggle button. (Mounted to the front of the 5.25 inch bay in a tower chassis, as was the style of the time.) Obviously you need some read+write storage elsewhere on the same computer, but you could reliably freeze large chunks of stuff in a way that would be impervious to viruses or hacker…

There were things like this, but it was more to prevent accidental writes. Some of the old 10" drives had a write enable toggle.

Re: Secure Boot is broken on 200 models from 5 big device makers

#109
post #6

> To this day, key players in security—among them Microsoft and the US National Security Agency—regard Secure Boot as an important, if not essential, foundation of trust in securing devices in some of the most critical environments, including in industrial control and enterprise networks. Am I correct that Secure Boot purely exists to prevent this attack vector: malware gets root on the OS, hardware allows updating f…

Immediately gets slapped over the head by the requirement: "preventing downgrade to a vulnerable version" (which would be just a matter of enough time passing)
Post reply on HN