Live data from Hacker News

Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

linuxveda.com

51–60 of 80 posts

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#52
post #11

It costs $99 to sign the software. I'm sure most of the distros can afford that (unless they take a die-hard stand, in which case, just don't buy a Windows pre-loaded PC from the OEM that disables the option to run Linux with).

And who gets that $99? Microsoft. Some of us are not okay with one company charging a gatekeeper fee for access to hardware we already bought from a different company.

I don't think you read the article. It says that Fedora paid VeriSign the $99 to sign the loader.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#53
post #40

> If Microsoft’s stance on this issue is not reversed it’s possible we will see a spike in sales by manufacturers such as System76 and ZaReason who ship computers running Linux out of the box without any signs of Secure Boot at all. Come on. I prefer BSD based OSX and Linux myself, but to think that a large enough number of buyers care about Linux support to "spike" sellers is just silly. It's done well on servers, b…

> I prefer BSD based OSX and Linux myself, but to think that a large enough number of buyers care about Linux support to "spike" sellers is just silly.

Hopeful rather than silly, I'd say.

Many people like you (who prefer BSD and Linux over MS) are still voting for MS with their wallets (dealing with majority MS manufacturers/sellers) and their discourse (the variations of how it all is "silly").

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#54
post #23

Earlier quoted context omitted.

If you buy from an OEM that pre-installs Windows then you are already paying a fee for the Windows license. If you don't want to pay a fee for software then just buy a from a company that pre-installs Linux.

My organization provides the disk images to the manufacturer for the computers we buy. This isn't about "paying a fee for software." It's about the fact that Microsoft has used its industry influence (and cozy relationship with Intel) to attach itself like a parasite to the process of bootloading in UEFI. We currently pay our manufacturers to install our signing keys into UEFI; this is fantastically expensive. It's a…

How much are we talking about?

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#55

Earlier quoted context omitted.

This is true today, but it ignores the realities of many secure boot implementations. Specifically, many UEFI firmware vendors don't include the ability for the hardware owner to update the public key used to verify a bootloader signature. This means that someone wanting to use a new bootloader on one of these platforms has to beg for permission from whoever owns the existing keys (Microsoft seems to be popular right…

Jeff, you mention valid concerns but there are two things that make me feel reasonably comfortable with this: there will be laptop manufacturers who will provide selective disabling because of market pressures, and, I think the 'new Microsoft' sees its future as providing productivity tools cross platform. I find the web based versions of Office 365 to be handy to have on my Linux laptops and I would be a little surp…

It's less about Linux for me than about the other things I want to boot (MS is unlikely to disable Linux bootloaders on certified Windows PCs for lots of reasons).

By way of example, the company where I work today produces a hypervisor for x86. We're nowhere near big enough to exert market pressure on someone the size of MS or the hardware manufacturers. When we recently added UEFI support to our product, we looked at support for UEFI secure boot as well. Some systems made key management easy (obvious bios options, etc.), but others made it impossible. Upon investigation, this mostly appears to be more due to apathy on the hardware vendors part than any conspiracy theory, but for an end user the distinction is unimportant. Today we can work-around this by using an MS-signed bootloader shim, but this reduces the security of the end solution (any ms-signed shim will boot, a third party owns the root keys). And, as I mentioned in my comment above, MS can change their policies at any time.

I haven't run into an x86 system yet that doesn't at least allow you to disable secure boot, but the trend towards more locked-down hardware in general (esp. in mobile) worries me due to the potential for anti-competitive behavior towards both commercial and open-source software from third parties.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#56

Earlier quoted context omitted.

> If you are able to set your own keys - then there is almost no problem Doesn't this make the feature useless from a security standpoint? If you're able to create your own keys then malware could create its own keys. Maybe if manufacturers could do it that would be handy.

I would assume that these UEFI machines have a built-in settings screen the same as BIOS-based machines do (and that screen would be where the setting we're discussing is found). If the only way to add keys is thru that screen, then you'd need physical access and malware adding keys wouldn't be an issue.

But that's not how UEFI works. Unlike your traditional BIOS, the settings can be edited from a normal OS by command-line utilities and such, too. In fact, often the only way to do anything useful, given how broken many UEFI setup pages are, is to edit the settings directly.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#57
post #28

Earlier quoted context omitted.

If there's a way to add keys there's a way to add keys. I don't think I'd rely on a screen being the only way to pull it off.

The keys are stored in a separate hardware module with a defined interface (which I'm sure is standardized somewhere). From what I understand, part of that interface would be a flag you can set to say "do not accept new keys until next reboot" (I assume there's also one for "do not accept new keys, ever again"). If the firmware sets that not-until-reboot flag before booting the OS, then going thru the firmware really…

Secure Boot can (and typically does) operate without a TPM, so no separate hardware module.

However, flash writing can be limited in hardware, so it would be possible to store Secure Boot keys in a special region of the flash that's locked down right after the opportunity to get to that setup screen passed.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#58
post #29

The headline is sensationalist to the point of being false. Microsoft is doing nothing to block Linux on Windows machines. Microsoft is allowing OEMs to ship devices that no longer have an option to disable SecureBoot. Given how they're positioning Windows 10 as a Run All The Things operating system, that's probably just catering to people making low-end IoT devices and tablets and whatever else. Dell and Lenovo have…

We updated the title to something more informative from the article.

Re: Machines shipping with Windows 10 may see OEMs enforcing Secure Boot

#59
Honest question: what's the defense that makes this not monopolistic behavior? This is MS going around trying to get all of the vendors for hardware to switch over to a system for which they are both the client AND the gatekeeper. The end goal is clearly to prevent anyone from entering the consumer operating system space without their express permission, giving them full monopoly over the consumer OS space. This would be like if in 98, they hadn't just been making it difficult to use other browsers, they had been asking all of the other OS vendors to add IE to their systems and disallow everything else that they don't like.
Post reply on HN