SovietRussia Posted March 26, 2013 Posted March 26, 2013 Looks like the Linux users are uprising against MS due to the fact that UEFI and Secure Boot is hard to turn off. Discuss! BBC News - Microsoft faces European open software probe
jamesfed Posted March 26, 2013 Posted March 26, 2013 A few clicks in the UEFI settings on most PCs? what on earth are they on about!
SovietRussia Posted March 26, 2013 Author Posted March 26, 2013 A few clicks in the UEFI settings on most PCs? what on earth are they on about! That's what we do when installing Win 7, turn UEFI to Legacy and turn off Secure Boot! 1
Michael Posted March 26, 2013 Posted March 26, 2013 You have to admit though, the first time I came across this I did have a head scratching moment... so I would agree, it does make it more difficult to downgrade Windows 8 or install a new OS altogether. Just think from a customer point of view - they buy a computer with Win 8, decide they don't like it and wish to downgrade. If instructions were provided it wouldn't be so bad - it's just UEFI is being kept very secret. I'm not entirely sure how or why UEFI makes computer users more secure as it's supposed to replace any standard BIOS. Although some BIOSes have been hacked or modified, it's generally pretty rare as the code is relatively simple.
jamesfed Posted March 26, 2013 Posted March 26, 2013 You have to admit though, the first time I came across this I did have a head scratching moment... so I would agree, it does make it more difficult to downgrade Windows 8 or install a new OS altogether. Just think from a customer point of view - they buy a computer with Win 8, decide they don't like it and wish to downgrade. If instructions were provided it wouldn't be so bad - it's just UEFI is being kept very secret. I'm not entirely sure how or why UEFI makes computer users more secure as it's supposed to replace any standard BIOS. Although some BIOSes have been hacked or modified, it's generally pretty rare as the code is relatively simple. You might expect though that users who know how to downgrade their OS to something else would be tech savvy enough to turn off something that's pretty easy in UEFI. Secure boot makes things safer by making sure that no malware interferes with the boot process.
jinnantonnixx Posted March 26, 2013 Posted March 26, 2013 (edited) Let's see what Linus himself has to say... So here's what I would suggest, and it is based on REAL SECURITY and on PUTTING THE USER FIRST instead of your continual "let's please microsoft by doing idiotic crap" approach. So instead of pleasing microsoft, try to see how we can add real security: - a distro should sign its own modules AND NOTHING ELSE by default. And it damn well shouldn't allow any other modules to be loaded at all by default, because why the **** should it? And what the hell should a microsoft signature have to do with *anything*? .... 'Re: [GIT PULL] Load keys from signed PE binaries' - MARC Edited March 26, 2013 by jinnantonnixx
Michael Posted March 26, 2013 Posted March 26, 2013 You might expect though that users who know how to downgrade their OS to something else would be tech savvy enough to turn off something that's pretty easy in UEFI. Secure boot makes things safer by making sure that no malware interferes with the boot process. The thing is, virus or malware writers don't wish to destroy or shutdown your PC. They want to harness its power and gullibility of the end user to part with their cash to 'fix' the problem. UEFI is pointless in my opinion and I have to agree with Linus's quote - why is a generic piece of hardware being controlled by a Microsoft signature?
jamesfed Posted March 26, 2013 Posted March 26, 2013 The thing is, virus or malware writers don't wish to destroy or shutdown your PC. They want to harness its power and gullibility of the end user to part with their cash to 'fix' the problem. UEFI is pointless in my opinion and I have to agree with Linus's quote - why is a generic piece of hardware being controlled by a Microsoft signature? All the same its an attack vector...might as well close off as many of the vectors as possible, just because its the boot process it doesn't mean that it can't be a route to turn your PC into part of a botnet. Either way the argument is null and void - just turn off secure boot
Geoff Posted March 27, 2013 Posted March 27, 2013 Yes but hardware manufacturers are incapable of writing a system bios that can't be bypassed like a Christmas tree because its full of holes. See Jailbroken iPhones, Chipped consoles, etc for example. The whole premise of secure boot is flawed and will not work as advertised.
CyberNerd Posted March 27, 2013 Posted March 27, 2013 Case in point being Samsungs implementation: AnandTech | Samsung Laptops Bricked by Booting Linux Using UEFI and some manufacturers don't even allow UEFI to be turned off .
SYNACK Posted March 27, 2013 Posted March 27, 2013 UEFI is pointless in my opinion and I have to agree with Linus's quote - why is a generic piece of hardware being controlled by a Microsoft signature? UEFI makes booting much quicker and more reliable (easier to diagnose faults) and secure boot does help prevent rootkits which are nasty and effect everything along with being stupidly difficult to detect and root out with virtualisation on. This is a step towards actually combating that and I would think that people would be happy with the faster boots and more secure end result. As to Linus, Wahhhh, waaahhhhhh, wahhhh. There is nothing stoping the individual distributions going to the motherbard vendors and getting certs and signing to implement this it is just that there are eleventymillion distributions and plenty of vendors so the overhead would be a nightmare. MS has offered (as the one pushing newer tech and better security to this hardware) to act as an intermediary so that linux can share in the benifits. For this they get wined at by the qunitisential angryman. If you don't like it don't use secureboot and be more vunrable to rootkits and add an extra few seconds to every boot. If the hardware does not support it (no secureboot off) then don't buy that hardware. Not every bit of hardware has to boot linux with full compatibility unless they are willing to do the work to make it work. Where is Linus's monologue on intel's new BGA chips, those are probably more of a threat to the universality of certain software, the new atom chips actually said something about not supporting linux too. EFI is better, it is not new either, Intel made it around a decade ago and apple has been using it for years. It has taken MS fully supporting it to push it into everything and get the vendors to move on. This is the same as SATA and all the wineing that went on about having to switch it off to use old stuff with the new tech without installing the propper drivers. If you want to use the new stuff work with a platform that can actually support it, If you have to jump through a few hoops to make it work that is because your platform of choice does not support it propperly. You choose the platform and so having to do the extra fighiting is your choice to degrade the technology. 2
Arthur Posted March 27, 2013 Posted March 27, 2013 Looks like the Linux users are uprising against MS due to the fact that UEFI and Secure Boot is hard to turn off. Have they not heard of the Verified Boot feature on Chrome OS devices? Oh wait, it's okay because Google designed it and not Microsoft. http://i.imgur.com/myEMhdO.png UEFI is pointless in my opinion UEFI is not the same thing as Secure Boot. My Sandy-Bridge-based PC has a UEFI BIOS, but the motherboard lacks the Secure Boot feature. UEFI is definitely a good thing. I have to agree with Linus's quote - why is a generic piece of hardware being controlled by a Microsoft signature? I wonder what Linus has to say about locked down iPad's, iPhones and Android smartphones/tablets with locked bootloaders that can't be unlocked? Are these fine because 99% of users generally don't install different operating systems on them? Is Richard Stallman the only person who cares? The thing is, virus or malware writers don't wish to destroy or shutdown your PC. Have you heard of the TDL-4 (Alureon) bootkit? This creates its own hidden partition on your hard drive so that it persists across OS re-installs. Ordinary users wouldn't have a clue how to use GParted to remove it. Also, what would you do if you came across a PC that had a rootkit hidden inside the BIOS? Throw the computer in the bin? Case in point being Samsungs implementation Samsung are awful at writing software. The Galaxy S3 bricks itself too. 1
Michael Posted March 27, 2013 Posted March 27, 2013 You're right UEFI replaces the BIOS, but Secure Boot is a protocol so they're sort of one and the same working together. If it was just UEFI then that wouldn't be so bad, however it's only later versions that have introduced Secure Boot requiring a digital signature. As I say, I still think it's something that's not really needed as virus or malware writers want to use your system as a host. It's only in extreme cases where someone wants to take an organisation down by targetting its servers. Any decent server setup also has managed firewalls and/or proxies in front of it. Why don't these have Secure Boot also? Clearly the idea of Secure Boot needs re-thinking as users should be able to install any OS of their choosing. If the only method is to switch it off then I'm afraid it completely defeats the purpose of Secure Boot. You could also argue the fact that it can be switched off is also a potential entry for malware or virus writers.
CyberNerd Posted March 27, 2013 Posted March 27, 2013 UEFI faster?? ever tried to boot an HS22 in a hurry?
Arthur Posted March 27, 2013 Posted March 27, 2013 I still think it's something that's not really needed as virus or malware writers want to use your system as a host. The following article is worth a read (it's on a RedHat developers blog)... Some things you may have heard about Secure Boot which aren't entirely true Clearly the idea of Secure Boot needs re-thinking as users should be able to install any OS of their choosing. You can already install Ubuntu with Secure Boot switched on. It's only a matter of time before others follow suit. Ubuntu 12.10 is the first Ubuntu release to support UEFI Secure Boot, a standard for controlling what software can be run on a computer. Supporting Secure Boot, a part of the Windows 8 certification requirements for client systems, ensures that Ubuntu will continue to provide an "it just works" experience on new hardware. Due to time pressures, only some flavors released with 12.10 will install and boot on Secure Boot hardware: Ubuntu desktop Ubuntu server Edubuntu We expect to enable all other flavors in 13.04. (Source)
Michael Posted March 27, 2013 Posted March 27, 2013 Question is, would Microsoft go to the effort of creating an updated ISO for Win 7 to support Secure Boot? It's going to become more and more of a problem as clearly Win 8 isn't making the impact Microsoft had hoped.
CyberNerd Posted March 27, 2013 Posted March 27, 2013 Real question is: Why are MS in charge of the keys?
Geoff Posted March 27, 2013 Posted March 27, 2013 Answer. EU antitrust lawsuit! Exclusive: Linux users file EU complaint against Microsoft | Reuters
SYNACK Posted March 29, 2013 Posted March 29, 2013 UEFI faster?? ever tried to boot an HS22 in a hurry? What is an HS22, we buy EliteBooks that have worked really well with UEFI for a long time because the vendor could program their way out of a paperbag unlike certain others... Google Nexus7, Samsung, HTC etc. Wait, looked it up, it's a server blade which you of course need to boot in seconds several times a day . Even with a BIOS server gear takes longer thanks to all the extra tech and more robust checks that it does. Your making unfair comparisons again.
jamesfed Posted March 29, 2013 Posted March 29, 2013 Question is, would Microsoft go to the effort of creating an updated ISO for Win 7 to support Secure Boot? It's going to become more and more of a problem as clearly Win 8 isn't making the impact Microsoft had hoped. I fail to see why it would be a problem? All you do is turn off secure boot in the UEFI setup....
CyberNerd Posted March 29, 2013 Posted March 29, 2013 Your making unfair comparisons again. The older HS21's with similar modules do a better job with BIOS. I don't think its faster at all, and if it is its a result of the hardware being faster and not that UEFI is intrinsically faster than BIOS.
SYNACK Posted March 29, 2013 Posted March 29, 2013 The older HS21's with similar modules do a better job with BIOS. I don't think its faster at all, and if it is its a result of the hardware being faster and not that UEFI is intrinsically faster than BIOS. Yes, the hardware is faster and the EFI boot lets you take advantage of that, the BIOS is what added that extra time. Oh and again, you can't blame the technology if the vendor can't implement it properly, besides, AGAIN, as a server it has a different set of requirements from EFI. Speed may not be their primary concern, perhaps they are running a bunch more checks at startup so that your server is more likely to run happily without issue for x months or years between full power downs.
markwilfan Posted March 29, 2013 Posted March 29, 2013 I fail to see why it would be a problem? All you do is turn off secure boot in the UEFI setup.... Fine if all manus stick to the spec... But.... We have an Acer w510 that you can turn off secure boot but not put it into legacy mode! Needless to say this upset me that we couldn't crack the admin password by booting Linux :'(
markwilfan Posted March 29, 2013 Posted March 29, 2013 It's on loan BTW but this and not being able to easily deploy an image to it make it a non starter for us
jamesfed Posted March 29, 2013 Posted March 29, 2013 It's on loan BTW but this and not being able to easily deploy an image to it make it a non starter for us USB Network adapter with the driver for it in your boot image does the trick in most cases with ultrabooks/tablets without a LAN port.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now