7 ms·
As a developer my first question would be: Can I dual boot linux on it? If so it would be an extremely attractive developer machine and switch to Windows when y
by arel 11y ago
As a developer my first question would be: Can I dual boot linux on it? If so it would be an extremely attractive developer machine and switch to Windows when you need it. The hardware is the show stealer here.
- elipsey 11y agoThis. Is the bootloader locked? So far I have mixed feelings about tablets. I like the "tablet" part but not the "it is cryptographically sercured from doing anything that might upset a government, corporation, or business model" part.
- Someone1234 11y agoThe Surface Pro 3 you could. Just had to disable Secure Boot for setup, boot from a USB stick, and after installation you could re-enable it (assuming you had a Linux distribution that supports Secure Boot signing). Obviously nobody outside of Microsoft will know if that remains true with the Surface Pro 4.
- Arnavion 11y agoSecure Boot is always disable-able on x86. This has been true since Surface Pro 1.
- cmurf 11y agoThe Windows 10 hardware certification permits the OEM to make Secure Boot not disablable. But the way the major distros work, they get a pre-bootloader signed with the Microsoft key through Microsoft's signing service, and that pre-bootloader contains a key permitting the chaining of the real bootloader, the kernel, signed with the distro key. So it's not a big problem.
- Arnavion 11y agoUp till W8.1, the spec (https://msdn.microsoft.com/en-us/library/windows/hardware/jj128256 https://msdn.microsoft.com/en-us/library/windows/hardware/jj...) explicitly requires the ability to disable Secure Boot: On non-ARM systems, the platform MUST implement the ability for a physically present user to select between two Secure Boot modes in firmware setup: "Custom" and "Standard". Custom Mode allows for more flexibility as specified in the following: ... B.If the user ends up deleting the PK then, upon exiting the Custom Mode firmware setup, the system is operating in Setup Mode with SecureBoot turned off. ... Enable/Disable Secure Boot. On non-ARM systems, it is required to implement the ability to disable Secure Boot via firmware setup. A physically present user must be allowed to disable Secure Boot via firmware setup without possession of PKpriv. I can't find the doc for W10. Has the language changed? Can you link it? The closest thing I found is https://msdn.microsoft.com/en-us/library/windows/hardware/dn898540 https://msdn.microsoft.com/en-us/library/windows/hardware/dn... which isn't really a spec, but does say: For most PCs, you can disable Secure Boot through the PC’s firmware (BIOS) menus. For logo-certified Windows RT 8.1 and Windows RT PCs, Secure Boot is required to be configured so that it cannot be disabled. which seems to imply that it is no longer a hard requirement for x86 unlike before.
- cmurf 11y agoI'm not finding an actual Windows 10 hardware certification requirement document. Yet Windows 10 is out and shipping pre-installed on hardware, so how can there not be a document somewhere? "The precise final specs are not available yet, so all this is somewhat subject to change, but right now, Microsoft says that the switch to allow Secure Boot to be turned off is now optional. Hardware can be Designed for Windows 10 and can offer no way to opt out of the Secure Boot lock down." http://arstechnica.com/information-technology/2015/03/windows-10-to-make-the-secure-boot-alt-os-lock-out-a-reality/ http://arstechnica.com/information-technology/2015/03/window...
- deleted 11y ago[deleted]
- elif 11y agoyes. I run ubuntu on my surface pro. Everything works well, with reasonably good battery life (not as good as win10, obviously). it is a painful install process, but that should change completely with ubuntu 15.10
- elipsey 11y agoWhy painful? Can you desable secureboot, but UEFI on Ubuntu is still sucky?
- rickyc091 11y agoUbuntu 14 doesn't support a lot of the latest hardware at the moment. I had an Intel i7 NUC and installing ubuntu 14 on it was a nightmare... You fix one thing to move the installer, another thing breaks. It's trial and error. Ubuntu 15 was just straight forward, one click install.
- Aldo_MX 11y agoI have a Surface Pro 1, and installed Ubuntu and Linux Mint pretty easy... but I wouldn't use any Linux in a Surface honestly, the Desktop Environments are far from having decent HDPI support, and the touch experience is still far from feeling usable.
- mizzao 11y agoIt seems like running in a VM is a much more attractive option than dual booting these days. The performance hit is negligible (especially with 16GB RAM), you can use both OSes at the same time, and you can use all the native Windows touch/pen drivers and have them carry over to the VM.
- elipsey 11y agoGood point, but not ideal for everyone. Especially with IOMMU and an SSD, performance isn't so bad when it works. I haven't liked the overhead with this in the past though, plus no full disk encryption, (although I guess you could do it in the guest), and Windows security in general, and bad 3D drivers for the guest (compositing please), and anything that wants low level hardware access is out. So if you don't actually want to _use_ Windows it makes a pretty crummy hardware abstraction layer.
- suryon 11y agoWindows security in general is better than Linux security in general.Unless you are running Grsec/PaX but hey i do not believe you do that on desktop. Also you can still run EMET on Windows.
- komaromy 11y ago> Windows security in general is better than Linux security in general. Can you elaborate on this or provide some sources?
- RaleyField 11y agoTheo de Raadt of OpenBSD made a comment in this line recently. https://www.youtube.com/watch?v=OXS8ljif9b8&t=54 https://www.youtube.com/watch?v=OXS8ljif9b8&t=54
- RaleyField 11y ago> Windows security in general is better than Linux security in general. Maybe. Have they fixed UAC not being security boundary [1] if you are on a default administrator account? It's hard to take them seriously when most software for most users still runs effectively under 'root'. [1] http://www.pretentiousname.com/misc/win7_uac_whitelist2.html http://www.pretentiousname.com/misc/win7_uac_whitelist2.html