Jump to content

Windows 8 Secure boot - Blocking hardware and software like nobodies business


Recommended Posts

Posted
A new security measure introduced with Windows 8 requiring so-called secure boot keys could make it more difficult for consumers to load other operating systems including Linux on OEM Microsoft-certified machines pre-loaded with the software.

 

Depending on whom you talk to, this is a massive violation of consumer freedom that might (or should) draw anti-trust scrutiny from authorities such as the EU — or it is a desirable defense against malware that just so happens to coincidentally inconvenience a small, if vocal, group of power users.

 

::Source::

 

 

What say you, Edugeeks?

 

Anti-trust violation to ensure market monopoly?

Or necessary evil for system security?

 

 

Personally, I'm not impressed. But, unless a large number of their target market say something, it'll stay the same.

 

From that I saw last Microsoft have a ~90% market share, and it seems they want to keep it. Even if it means actively disabling free choice.

 

New graphics card? It isn't signed, you can't use it.

New HDD? Nope, can't use that either.

Don't agree with Microsoft's decision? Sucks to be you then, you can't change the OS.

Posted

Haven't you just described Apple there with their ring fenced hardware and software?

 

I'd prefer to wait and see when it eventually comes out. All these sites thrive on rumour, speculation and such.

Posted
Haven't you just described Apple there with their ring fenced hardware and software?

 

I'd prefer to wait and see when it eventually comes out. All these sites thrive on rumour, speculation and such.

 

 

It was purely unintentional, I assure you. I don't use Apple products all that often.

 

I agree on the "wait and see" approach, but from what I've seen confirmed by Microsoft isn't inspiring.

Posted
Does sound very apple-esque. But then Apple are doing very nicely at the moment, so perhap our good friends at Microsoft are thinking if it works for them....
Posted

From what I have read Microsoft require secure boot to be turned on in order to boot Windows 8. They have said it is up to the system manufacturers if they allow the end user to toggle it off.

 

As far as I see it what we as consumers need to do is refuse to buy machines from manufacturers who will not allow us to turn off secure boot.

 

oh and we dont want to pay extra to be able to turn it off, as that is unfairly loading an extra cost onto those people who choose not to run Windows 8

Posted
There wouldn't be anything to stop a consumer key being supplied with hardware that would allow someone to do what they wanted, but I wouldn't be surprised if manufacturers refused to manage and distribute the keys (and I imagine Microsoft will create incentives for this to be the case). If you built your own PC then you will have to be given a key, the real problem will be for mobile devices as you can't really buy the parts and make your own.
Posted
Keys as in, code signing with a public and private key pair. The private key of what you are installing (i.e. the bootloader) will have to match with a public key that is on the motherboard.
Posted

If Apple had not got away with this kind of game and been lorded for it by the sheeple and media there is no way that this would have been an issue. Everyone who decided that Apple were more secure because of hardware lockins has contributed to this. The same rings true for the 'only need a tablet' crowd who will force the price up on other forms of computer hardware and drive development into locking them down just like the tablets.

 

They are only giving the sheeple what they think they want.

 

I don't agree with it if hardware is not user unlockable but as shown by Apple consumers and a bunch of android/WP ones with bootlocked devices there is plenty of market for it.

  • Thanks 1
Posted
What happens when this secure boot only hardware makes it onto the second hand market?

 

You have to pay extra for signing.

 

Like what EA are doing with second hand games. But a bit more extreme.

Posted
Haven't you just described Apple there with their ring fenced hardware and software?

 

I'd prefer to wait and see when it eventually comes out. All these sites thrive on rumour, speculation and such.

 

Pretty much agree there, I totally don't blame Microsoft for doing this because other manufacturers are doing it. Surely if you want another OS why not buy their product? I can slightly understand why people had a hissy fit over the PS3 terms change but frankly sony should of said from day 1 "You can not install other OS's on the PS3". Why would anyone install anything else anyway? Oh wait..... cough...

Posted

Looks to em like a decision influenced by the mobile market. Phone rooting is a big headache for device and OS manufacturers and Windows 8 has clear indications that it will be intended run on such devices. UEFI's signed rooting will make it harder to root and power the device on in seconds.

 

Of course, for desktop computers the answer is to buy a UEFI motherboard capable of disabling secure boot. The question is how many cheap motherboards will come without such functionality.

 

Can't really leave the blame squarely in Microsoft's court though and eyes should fall on hardware manufacturers and how they handle non-secure boot support. If worst comes to worst and Linux distros are forced to release a signed version, we may see one signed version rise to the top and provide the stability Linux needs for developers to work with it (instead of one billion distros with their own quirks and changes).

Posted

Can't really leave the blame squarely in Microsoft's court though and eyes should fall on hardware manufacturers and how they handle non-secure boot support. If worst comes to worst and Linux distros are forced to release a signed version, we may see one signed version rise to the top and provide the stability Linux needs for developers to work with it (instead of one billion distros with their own quirks and changes).

 

The problem here is that if a key is released to a linux distribution, then to comply with the GPL it would have to be released to everyone, which null and voids the whole point of doing it.

 

We can still install Linux on Mac's, so I'm not sure where the idea that this is apple's fault comes from?

Posted

How will this affect the upgrade path from Windows 7 to Windows 8? Would this mean that you would need new hardware to support the new security? If so then I can hardly see companies and schools going out a buying all new kit just to install an upgrade. Doesn't make sense.

 

If indeed this is the case then MS should take this opportunity to eradicate support for old technology in their latest OS.

Posted
How will this affect the upgrade path from Windows 7 to Windows 8? Would this mean that you would need new hardware to support the new security? If so then I can hardly see companies and schools going out a buying all new kit just to install an upgrade. Doesn't make sense.

 

If indeed this is the case then MS should take this opportunity to eradicate support for old technology in their latest OS.

 

Old hardware should be okay, but the restriction is necessary for new hardware that will be marketed as Windows 8 Certified. I imagine if you are selling OEM Windows 8 licences you will only be able to do so on such hardware as part of the agreement.

Posted
Looks to em like a decision influenced by the mobile market. Phone rooting is a big headache for device and OS manufacturers and Windows 8 has clear indications that it will be intended run on such devices. UEFI's signed rooting will make it harder to root and power the device on in seconds.

 

Of course, for desktop computers the answer is to buy a UEFI motherboard capable of disabling secure boot. The question is how many cheap motherboards will come without such functionality.

 

Can't really leave the blame squarely in Microsoft's court though and eyes should fall on hardware manufacturers and how they handle non-secure boot support. If worst comes to worst and Linux distros are forced to release a signed version, we may see one signed version rise to the top and provide the stability Linux needs for developers to work with it (instead of one billion distros with their own quirks and changes).

 

Eh? Rooting phones is not a big issue for mobile phone providers (outside of MS and Apple enviro's) and in fact many see it as a way of selling more handsets. Look at Samsung who recently supplied Galaxy S2 handsets to the Cyanogen team so they could port CM7 to it, then look to HTC who confirmed they would unlock the boot loader on their new phones. Publically the phone manufacturers might not be seen to like phone ROM cooking (I avoid the use of the term hacking for the obvious negative connotations of the word) but certainly the Android suppliers like HTC and Samsung love it. It makes their device far more saleable to the people who don't like the idea of not being able to do what they want with it how they want and whilst Apple might publically moan about Jailbreaking it's massively helped with hardware sales. The only negative I can think of is for the app makers who rely on adverts for their free games when rooted you can use a custom HOSTS file and block all the adverts, apart from that I cannot think of a serious negative that would upset Google, HTC, Samsung and the like but I could easily be wrong...

 

You only have to look at Modaco and XDA to see how fast development is happening for these 3rd party ROMs far far faster than the OEM will ever commit to and in fact many of these ROMs make the device infinitely more usable - Proxy support Android i'm looking at you!

 

Whilst I am still running a stock ROM on my S2 I am running a custom kernel and rooted which allows me to do things I would not be otherwise able to do and makes the phone much better for "me".

 

Samsung and HTC at least recognise that and realise it helps with sales otherwise they would not do what they have done.

 

TBH this UEFI secure boot thing is nothing more than the latest shot across the bows and I wager it will come to nothing previous examples:

 

PIII unique processor serial numbers - Outcry and option to disable added to BIOS options

TPM platform - What happened to that?

 

MS need to look at all these secure platforms and see what's happened to them:

 

Xbox - hacked

Xbox360 - hacked

PS1/2/3 - hacked

Apple OS X hardware check - hacked

Blu-ray secure platform - hacked

HDCP - hacked

 

In short even if they do implement this and ram it down our throats (which won't happen due to Linux etc crowd fighting it) it'll be broken in very short order

Posted
MS need to look at all these secure platforms and see what's happened to them:

 

Xbox - hacked

Xbox360 - hacked

PS1/2/3 - hacked

Apple OS X hardware check - hacked

Blu-ray secure platform - hacked

HDCP - hacked

 

To be honest, is there anything that hasnt been hacked? If its's popular it's going to get ripped in to, some do it just for kicks or another challenge.

  • 1 month later...
Posted

It has been said by Dell and other OEMs that they will have a switch in the BIOS to turn it off, it will just be shipped with it on for security and compliance (like the developer switch in android) or like the virtualisation extentions for CPUs that are switched off by default because of threats like blue/red pill stuff.

 

This kind of restriction is not new and if you cant turn something off in the BIOS are you really skilled enough to be installing an OS anyway. Besides a twenty second youtube video will fix this and teach people how.

 

The one area where it may be a concern is in the ARM line of heavily consumer devices where this kind of lockin is already common (iPhone anyone).

Posted
To be honest, is there anything that hasnt been hacked?

I'm sure there are more examples, but the Cinavia audio watermarking tech found on DVDs and Blu-ray's, and Amazon's Topaz eBook format used on Kindle's have yet to be cracked.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...