4 ms·
See also https://encrypted.google.com/search?q=DRM+writes+to+boot+sector https://encrypted.google.com/search?q=DRM+writes+to+boot+sec... This is a pretty nasty
by mtigas 16y ago
See also https://encrypted.google.com/search?q=DRM+writes+to+boot+sector https://encrypted.google.com/search?q=DRM+writes+to+boot+sec...
This is a pretty nasty thing that's largely coming to light just now because GRUB2 uses a significantly larger portion of the space between the MBR and first partition ("embedding area," 24KB vs 10KB).
What we have is separate applications (GRUB2 and whatever Windows application) trying to use off-spec storage (the "embedding area") at the same time. Seems to be a bad idea on everyone's part, not just the GRUB or rogue Windows app developers.
The "embedding area" is not guaranteed to exist, be a certain size, or be unused: https://encrypted.google.com/search?q=embedding+area+is+unusually+small https://encrypted.google.com/search?q=embedding+area+is+unus...
- jacquesm 16y agoI think the application is clearly at fault here. The boot loader doesn't have to make any assumptions about the disk (not even the presence of files or a filesystem), it sets up the info passed on to the operating system and both the operating system and any applications within that OS should stay outside of areas that were not explicitly allowed. The OS should never allow an application to do this.
- aw3c2 16y agoI do agree that the OS "should" not allow access but it has to because otherwise you would not be able to modify it.
- seabee 16y agoExactly - how else would you install Grub otherwise? :)
- jacquesm 16y agoAn installer or a program running at installation time as the super user has different permissions than just any old application. Think about it, if an application can write to the boot area then you've got a giant hole in your security.
- seabee 16y agoRight, but how do you do disk imaging (for example) if the OS doesn't give you access to the entire drive? The OS could say "OK, you can modify any drive's boot area but the one I'm on", but that doesn't help if you're booting from another drive and using chainloading. Hell, you can flash motherboards from an OS... writing to the boot area is just one example of many 'giant holes in your security'.
- woodall 16y agoThis gapping hole has actually been used to target TrueCrypt. http://www.stoned-bootkit.info/ http://www.stoned-bootkit.info/ http://www.h-online.com/security/news/item/Bootkit-bypasses-hard-disk-encryption-742721.html http://www.h-online.com/security/news/item/Bootkit-bypasses-... http://www.anti-forensics.com/modify-truecrypt-encryption-boot-loader-strings http://www.anti-forensics.com/modify-truecrypt-encryption-bo...
- rbanffy 16y agoNo OS can block users with administrative privileges from completely destroying their environments. That said, no application without a very high level of trust (perhaps above what an Administrator can do on Windows) should be able to write outside the filesystem. This should, at the very least, pop-up some "Program X is about to do something remarkably stupid. Allow or deny?" dialog.
- j_baker 16y agoI'd be suprised if windows didn't show such a dialog. The user probably just ignored it because they see such dialogs all the time.
- Raphael_Amiard 16y agoBe surprised then. This thing happened to me (on windows 7). I'm very wary about what kind of dialog i click on to, and never saw a warning which would seem related to that.
- __david__ 16y agoThe application shouldn't be doing what it's doing, but it still is kind of hypocritical to complain that someone else is doing exactly what grub is doing. There is no reason grub couldn't make a little partition for its data (except for inconvenience). It wouldn't even have to know how to parse a partition to get to its data, it would just be there to mark the area on the disk as its own. We've solved the problem of data contention on a disk a long time ago...
- jacquesm 16y agoGrub is not operating within the OS sandbox though.
- __david__ 16y agoWhy does that give it a free pass to write to places on the disk that are "reserved" or unallocated? Grub may not operating within an OS sandbox, but it is required to play nicely with the OSes it is booting. The way to do that is to wrap your data in a partition or a file.
- jacquesm 16y agoIt doesn't give it a free pass but there is no 'supervisor' to stop it.
- __david__ 16y agoWell, you're right that grub-the-bootloader doesn't have a supervisor to stop it from writing to random places on the disk (since it's not running under an OS), but grub-the-bootloader doesn't actually write to those sectors, so I'm not sure what your point is. grub-the-comman-line-utility writes to those sectors but it runs in linux userspace so it's really in the same position as the windows programs that also write to the reserved space...
- jacquesm 16y ago