3 ms·
MS is pushing this so-called "secure boot" purely to prevent boot loaders from functioning. There is no "security exposure" that this plugs, this is a "piracy e
by DayTrader 15y ago
MS is pushing this so-called "secure boot" purely to prevent boot loaders from functioning. There is no "security exposure" that this plugs, this is a "piracy exposure" fix.
The only people who install pirated versions of Windows are typically more technically inclined - Joe Plumber isn't installing his own pirated version. Neither is Joe Plumber setting his machine to dual-boot to Linux.
If vendors do not include a way to bypass the "Secure Boot" option, this will NOT affect Joe Plumber, it will only affect his technician buddy. And his technician buddy will have an alternative crack for Windows 8 if the boot loader doesn't work.
But when Joe Plumber asks his technician buddy which computer he should buy, do you think the technician will recommend a computer with a BIOS that doesn't allow you to bypass secure boot? I think not.
So computer vendors have every reason to include secure boot and turn it on by default (so they can get the Windows 8 logo), but they also have every reason to include an option to turn it off (which Microsoft allows).
So I believe this will be a non-issue at Windows 8 launch, or perhaps several months later.
- dpark 15y agoHas Microsoft indicated that they don't want it possible to disable Secure Boot? Have they stated that, or is there evidence that they've pressured OEMs in that direction? If not, it's not a piracy fix. Anyone willing to install some hacky boot loader should be able to turn off a setting in the BIOS. The fact that you don't see the security issue doesn't mean it's not present. There are known boot-time attacks that no OS or anti-malware can reliably fix. Thankfully none of these are widely exploited at present, but a security problem should not need to be exploited on a wide scale before a fix is put in place. Disclaimer: MSFT employee
- DayTrader 15y agoI didn't say I didn't see a security issue (minor though it may be). I said that security is not the reason for this "fix" - the effort required for secure boot is completely out of balance with the potential exposure this plugs. And if Microsoft is indeed pressuring vendors not to include an option to turn secure boot off, this is an ominous turn of events that would indeed force buyers to chooses carefully. But as I said, I believe that those people who ask their tech buddies which computer to buy will be steered towards computers that give the option, or have no secure boot at all. This will ultimately force the vendors to discontinue models that lock down secure boot.
- dpark 15y ago> I didn't say I didn't see a security issue Yeah, you did: There is no "security exposure" that this plugs > I said that security is not the reason for this "fix" - the effort required for secure boot is completely out of balance with the potential exposure this plugs. The potential risk is massive. Malware that injects a hypervisor beneath the OS could be undetectable without external scanning and nearly unfixable for the typical user. Imagine botnets built like this. The OS is healthy, anti-malware says everything's great. Meanwhile the machine is being remotely controlled and no one knows it except the guy who's using it to hammer away as part of a DDoS attack, or using it to host child pornography, or whatever. The effort required for secure boot actually seems quite small. The real effort is in making secure boot work for 3rd parties as well. That's a difficult problem because "I want to run some random crap in my bootloader" is in direct conflict with the "don't allow random crap to run in the bootloader" design goal. > And if Microsoft is indeed pressuring vendors not to include an option to turn secure boot off, this is an ominous turn of events that would indeed force buyers to chooses carefully. I seriously doubt that's happening. > But as I said, I believe that those people who ask their tech buddies which computer to buy will be steered towards computers that give the option, or have no secure boot at all. This will ultimately force the vendors to discontinue models that lock down secure boot. I agree. I think any vendor who sells a locked-down secure boot will see public backlash, and fix it in either future models or a firmware reflash.