Live data from Hacker News

Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

linuxveda.com

21–30 of 80 posts

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#22
post #17

While some are saying it's only optional and up to the hardware vendors, isn't Microsoft giving Windows7 users a free upgrade? Is this the reason? A potential lock in?

> A potential lock in?

Secure boot is part of the BIOS so nope.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#23
post #11

Earlier quoted context omitted.

And who gets that $99? Microsoft. Some of us are not okay with one company charging a gatekeeper fee for access to hardware we already bought from a different company.

If you buy from an OEM that pre-installs Windows then you are already paying a fee for the Windows license. If you don't want to pay a fee for software then just buy a from a company that pre-installs Linux.

My organization provides the disk images to the manufacturer for the computers we buy. This isn't about "paying a fee for software." It's about the fact that Microsoft has used its industry influence (and cozy relationship with Intel) to attach itself like a parasite to the process of bootloading in UEFI.

We currently pay our manufacturers to install our signing keys into UEFI; this is fantastically expensive. It's a damn shame that it is literally impossible to buy a consumer UEFI device without Microsoft's keys in the image unless you pay to have yours put in.

In short: it sucks that they are the default, and it sucks that Red Hat and Ubuntu rolled over on the issue and pay the (latest) Microsoft tax. I would have preferred a more flexible solution.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#24

Ubuntu, Redhat, and other distros are compatible with secure boot. I understand the concern, but the flip side is that if secure boot makes my future Ubuntu laptops more secure that could be a good thing. Linux is here to stay. Relax.

This is true today, but it ignores the realities of many secure boot implementations. Specifically, many UEFI firmware vendors don't include the ability for the hardware owner to update the public key used to verify a bootloader signature. This means that someone wanting to use a new bootloader on one of these platforms has to beg for permission from whoever owns the existing keys (Microsoft seems to be popular right now...) to get their software to boot. Right now, MS is willing to sign bootloaders for OSS, but this could change at any time. Do you really want MS to control the ability to boot your operating system of choice?

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#25

That is really shitty. Though its only an OEM thing? If you build your own machine your still ok I guess.

Motherboards bought in stores might omit the option as well. Not hugely likely, but certainly possible. It would probably be more of an oversight though, since it'd kill ~5-10% of their customer base over a menu option.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#26
post #15

Ubuntu, Redhat, and other distros are compatible with secure boot. I understand the concern, but the flip side is that if secure boot makes my future Ubuntu laptops more secure that could be a good thing. Linux is here to stay. Relax.

Serious question: how does Secure Boot make you more secure? How many times has a virus latched onto your computer by executing before your system booted up? I've never heard of this happening to anyone I've ever known. The only scenario I can imagine is having a PC set to auto-boot from peripherals, and a USB key having something bad execute before invoking your hard disk's boot loader. And that is obviously possibl…

I read an article a couple of months back (like October-Novemberish 2014) about the NSA putting a virus into the firmware of a RAID controller on some Dell servers that would patch Windows Server 2003 (R2?) during startup.

So it is not entirely without precedent.

Then again, this did not touch the OS bootloader itself, strictly speaking and might not have been prevented by "Secure Boot". Also, once you're diddling with a devices firmware, you might as well tamper with "Secure Boot" as well and defang the checking of the bootloader or even make the firmware live-patch the bootloader...

So, while I am by no means a security expert, I have been wondering the same thing. The entire "Secure Boot" stuff just seems like a lame excuse to allow vendors control over what operating systems you can boot on their devices.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#27

Earlier quoted context omitted.

> If you are able to set your own keys - then there is almost no problem Doesn't this make the feature useless from a security standpoint? If you're able to create your own keys then malware could create its own keys. Maybe if manufacturers could do it that would be handy.

I would assume that these UEFI machines have a built-in settings screen the same as BIOS-based machines do (and that screen would be where the setting we're discussing is found). If the only way to add keys is thru that screen, then you'd need physical access and malware adding keys wouldn't be an issue.

That would make sense; thanks!

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#28

Earlier quoted context omitted.

> If you are able to set your own keys - then there is almost no problem Doesn't this make the feature useless from a security standpoint? If you're able to create your own keys then malware could create its own keys. Maybe if manufacturers could do it that would be handy.

I would assume that these UEFI machines have a built-in settings screen the same as BIOS-based machines do (and that screen would be where the setting we're discussing is found). If the only way to add keys is thru that screen, then you'd need physical access and malware adding keys wouldn't be an issue.

If there's a way to add keys there's a way to add keys. I don't think I'd rely on a screen being the only way to pull it off.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#29
The headline is sensationalist to the point of being false. Microsoft is doing nothing to block Linux on Windows machines. Microsoft is allowing OEMs to ship devices that no longer have an option to disable SecureBoot. Given how they're positioning Windows 10 as a Run All The Things operating system, that's probably just catering to people making low-end IoT devices and tablets and whatever else. Dell and Lenovo have not been chomping at the bit to ban Linux from their laptops, and I doubt they will change anything they're doing now.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#30

That is really shitty. Though its only an OEM thing? If you build your own machine your still ok I guess.

> That is really shitty.

They're simply easing restrictions on their hardware partners especially since many enterprise customers only want signed software running on their machines.

This is really not a big deal.

Post reply on HN