Live data from Hacker News

What is an SBAT and why does everyone suddenly care

mjg59.dreamwidth.org

251–260 of 276 posts

Re: What is an SBAT and why does everyone suddenly care

#251
post #194

Earlier quoted context omitted.

> Who is Microsoft to decide what others do on their machines? That would be an amazing rant had it only ended with "Sent from my iPhone". Since the Blaster worm incident two decades ago, we're in a new era where security at scale becomes the forefront responsibility of the companies developing the product. That includes writing more secure code, having more verifications in place, adopting more secure technologies,…

The Blaster rworm did not in fact make the whole earth fall apart. Stop scaremongering. > When you have a billion devices running around the world This is exactly the point: Microsoft does NOT have those billions of devices, their users do. > CrowdStrike happened because one of the "user-empowering" features: ability to install kernel drivers on a machine. Crowdstrike happened because the corpration behind it had dir…

> The Blaster rworm did not in fact make the whole earth fall apart. Stop scaremongering.

Blaster was a wake-up call, caused DDoS on servers, and kickstarted similar variants like SQL Slammer, Sasser, Conficker that hindered many services around the world. Stop dismissing real threats because you haven't personally affected by them.

> This is exactly the point: Microsoft does NOT have those billions of devices, their users do.

Do you prefer a billion unpatched systems roaming around with all ports open and running all programs as admin? Why are you against as secure defaults?

> Because the demand for increased security never ands and can be used to justify any and all loss of freedom.

If you don't like secure defaults, just turn them off. If you don't like how Windows does something, use an alternative. What dystopia are you talking about?

Re: What is an SBAT and why does everyone suddenly care

#252

Earlier quoted context omitted.

There was nothing to be gained in this except ill will. Hanlon's Razor suggests they were in a hurry to fix a security issue and didn't dot their i's on checking for dual boot systems.

It's a trolley problem, and it's not in Microsoft's locus of control to keep dual boot systems dual booting. So they don't try. They have never, ever supported anything other than the Microsoft bootloader[s], and if you work around that for instance it's pretty trivial to blow up your data by hibernating Windows and booting into a different partition. Resuming hibernation loads the old MFT onto the modified partition…

>hibernating Windows and booting into a different partition.

Definitely to be avoided, along with a few other considerations.

But experienced multibooters can usually reboot so quick that they have not had any need for hibernation since forever. It's almost like a valid excuse to not fully reboot a sluggish machine, more so than an energy-saving success. But I don't blame them.

Re: What is an SBAT and why does everyone suddenly care

#253

Earlier quoted context omitted.

If your adversary is a nation state, you've already lost. Which gives me another opportunity to quote from my favourite Usenix paper: "In the real world, threat models are much simpler (see Figure 1). Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@ virus-basket.biz.…

> If your adversary is a nation state, you've already lost. Did you hear about Snowden?

Does that mean: If your adversary is a nation state, then you better move to a state adversary to your nation?

Re: What is an SBAT and why does everyone suddenly care

#254

Earlier quoted context omitted.

I guess in their defense the same attack can be used against any other OS so they're unintentionally protecting Linux as well, since they stated this was supposed to be a Windows-only system change. You can disable secure boot if you don't want to be secure. And, there is a way to disable the SBAT policy and keep secure boot if you want that, which is also insecure. Disable Secure Boot, login, sudo mokutil --set-sbat…

> I think understandably, everyone is concerned because it felt like an affront by MS against Linux. But, I don't think that was their thought process at all. Given Microsoft's history, it's hard to really be sure. It's been a quarter century since The Halloween Documents and Microsoft definitely gives the air of contributing to the open source ecosystem today, but giants like having a big moat to defend, and old hab…

>it's hard to really be sure.

Not that hard the more history there is.

Keep in mind that the default since the beginning of Linux is for someone who wants their PC to be completely Linux, never had a need for anything originating from Microsoft whatsoever. Something in firmware would really be the worst and it was immediately obvious when UEFI & GPT were foisted, with Microsoft SecureBoot to boot, that something was rotten somewhere.

A bigger threat than Linux was actually Windows 7, but with this exact hindsight now it can be seen how the knife was much further twisted for Linux well beyond the effective lifetime of W7. This was not just collateral damage, and it keeps on giving as if booby-trapped or time-bombed.

Also remember that until Windows Vista, motherboards and business machines from all major manufacturers were always common where there was no way to alter the BIOS itself in any way without physical access. Like a jumper on the board internal to the PC. Sometimes special key combinations on laptops accepted only from its built-in keyboard.

With BIOS settings only accessible to non-local users occasionally on specialized enterprise models according to options if present.

When you wanted to upgrade your BIOS, or "re-flash" it due to something like power line corruption, you always booted to the floppy containing the desired firmware after enabling the delicate flashing operation manually. By the time Vista arrived it was often a bootable CDROM, or a USB stick formatted FAT32 with DOS to substitute for a floppy. Whichever way you did it you wrote the same binary file into the BIOS chip, then with further access completely disabled after that, never need to worry about malicious firmware whatsoever as long as you used a clean binary.

The only possible way for a rootkit to infect your machine was to reside on your HDD. Usually in some of the spaces outside your filesystem that were so commonly unused it could lurk there and persist in spite of re-formatting.

But no rootkit or preboot contamination could withstand a complete HDD zeroing, or replacement HDD if needed under emergency conditions.

Well one day Microsoft must not have wanted people to ever boot DOS again, so they developed a need to access every BIOS from within Windows NT6, and manufacturers conformed. It only bricked machines significantly for a few years while the DOS way continued to be flawless for a while there.

It's a slippery slope, this got much worse once they forced UEFI on consumers, and malware can now reside in the preboot environment itself, which can often also access the web if connected.

Plus the motherboards have much more space for this kind of thing.

With Windows Servers and general Macs well-established beforehand at using EFI to restrict booting to only the exact OS that it was shipped with.

And everything on that Microsoft webpage introducing the advent of UEFI & GPT as a complete advantage in many ways, looking suspicious and turning out to be completely false without even waiting for the 20/20 hindsight there is now. The whole thing!

The cloak has now been further removed from this "false sense of security" system but surely not everybody wants to say out loud how sparsely-clad the emperor has become as he struts as if to demand the full respect once deserved.

So there hasn't been a physical way or available setting to prevent malicious access to sensitive PC firmware for quite some time, and who's most likely to blame for it?

No Windows "update" has ever made sense to change anybody's BIOS or UEFI firmware without being absolutely stupid as shinola, not like there was any question before this either.

This is also beyond most user recovery if you get malware in your UEFI.

Zeroing a HDD or SSD won't help you now like it would with BIOS.

You just can't fix shinola.

Re: What is an SBAT and why does everyone suddenly care

#255

Obviously people might screw up, but the spec included a way to revoke any signed components that turned out not to be trustworthy "trustworthy" according to who ? Remember that dystopia does not appear spontaneously, but steadily advances little-by-little. What's the summary? Microsoft (understandably) didn't want it to be possible to attack Windows by using a vulnerable version of grub that could be tricked into ex…

The full quote is:

"Those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety"

Is the ability to run an insecure bootloader on a system that has an installed OS with a security policy built around it not running insecure bootloaders an essential liberty? Let's say it is, for the sake of argument. Have you given up that freedom? Given that you can disable secure boot, or boot a live image and remove the SBAT entry, or boot an updated image and recover your existing install, I think it's hard to say that you've actually given it up. Is that security temporary? A well-maintained secure boot chain provides you long-term security against a variety of threats, so I don't think it's clearly temporary.

It's fine to disagree, but please don't do so by pretending that a misquote is meaningful.

Re: What is an SBAT and why does everyone suddenly care

#256
post #189

Earlier quoted context omitted.

I meant: - I'm only using a long password - but it would be optimal to require PCR values and password Note that in any case where you use PCR values you always should setup a secondary way to unlock the partition. Or else you will lose your data if some of your hardware measured into a PCR breaks. Requiring both is optimal as it 1. doesn't rely on TPM/PCRs but 2. prevent certain attack vectors possible with password…

Thanks for sharing your setup! Nit: It's useful to distinguish between passwords (checked against a hash for auth) and passphrases (used for decryption). It's an important practical distinction because a lost password can in general be bypassed out-of-band somehow while a backup strategy for passphrases is essential.

A more common definition of passphrase is a a password which is a phrase which makes it longer but also more predictable in it's structure.

Similar prompts for decryption will ask you for passwords in most cases as non technical users shouldn't need to understand the underlying technical differences (nor do they normally want to, or do).

Re: What is an SBAT and why does everyone suddenly care

#257
post #249

Earlier quoted context omitted.

Blaster was Microsoft's own incompetence. CrowdStrike was CrowdStrike's own incompetence. They are free to fix the problems of their own doing. But messing with software you do not own, on machines you do not own, crosses a line and should be considered an act of aggression. What if some Linux distro releases an update that deletes any installations of Windows it finds "because Windows is insecure" (according to them…

> Blaster was Microsoft's own incompetence. All security bugs are result of incompetence. Massive DoS incidents are result of scale. Use your magic wand, bring Linux to 90% desktop OS marketshare, and see how one malware destroys an order of magnitude more Linux devices than Windows. > They want to give more control to Microsoft No, they want secure defaults, not less control. > And crimes happen because people still…

> why do we have laws that limit people's freedom

Can you show me the law that deputizes Microsoft to be judge, jury and executioner on other people's private property?

> Not at the expense of harming others.

Isn't that exactly what Microsoft was doing here?

Re: What is an SBAT and why does everyone suddenly care

#258

Earlier quoted context omitted.

It was never designed to Empower the (end) User. This is vaguely the experience that should have been present in an Empowered User centric BIOS. First cold boot; BIOS verifies the hardware isn't broken, checks for a boot preference, finds none. Present the User with a set of choices: Check for BIOS Updates (manufacturer), Check for OS Choices (manufacturer), Begin installing an OS (options list). Locally cached (pres…

The best BIOS would be no BIOS, just find a drive, check for a boot sector, then boot from it. Have an internal USB slot that always gets boot priority for service and for advanced use cases. The point of personal computers is to make _personal_ computing easy. Everything else can just be an add on.

> find a drive, check for a boot sector, then boot from it

And how would you call the System code that does this? Would you want such a piece of code to be able to Output something to the screen in case it can't find such a boot sector? Should it be able to take user Input (e.g. in case multiple valid boot sectors are found)? These are quite Basic requirements for any early-boot phase.

Re: What is an SBAT and why does everyone suddenly care

#259

Earlier quoted context omitted.

> If your adversary is a nation state, you've already lost. Did you hear about Snowden?

Does that mean: If your adversary is a nation state, then you better move to a state adversary to your nation?

It means, Qubes OS saves you even if NSA is after you. He was collecting the data in the US first.

Re: What is an SBAT and why does everyone suddenly care

#260
post #250

Earlier quoted context omitted.

> When you have a billion devices running around the world, you can't say "hey we'll let this arbitrary group of billion people do what they think is best for them", because you then end up with Blaster worm, and the whole Earth falls apart. The bug is in the fact that billions of machines are running exactly the same proprietary software. Following the "virus" metaphor, having billions of identical organisms is how…

> The bug is in the fact that billions of machines are running exactly the same proprietary software. What's the alternative?

Running a diverse ecosystem of software, with varying builds of (potentially) identical source code. Preferably on a the variety of hardware.
Post reply on HN