46 ms·
Responsible stewardship of the UEFI Secure Boot ecosystem
- Harvesterify 4y agoPrevious discussion: https://news.ycombinator.com/item?id=32023868 https://news.ycombinator.com/item?id=32023868
- chr15p 4y agothat was a discussion of a previous blog post by the same author (Mathew Garrett). Its on the same subject but this one is much longer and goes into much more detail.
- rob_c 4y agoIt doesn’t add much other than a lack of open public docs of a new feature that’s not been widely adopted yet. I’m not panicking.
- Arnavion 4y agoNon-Cloudflare-captcha link: https://web.archive.org/web/20220712083007/https://mjg59.dreamwidth.org/60248.html https://web.archive.org/web/20220712083007/https://mjg59.dre... ("Please stand by, while we are checking your browser... Please turn JavaScript on and reload the page." No thanks.)
- skywal_l 4y agoTLDR: So essentially, if the Lenovo laptop does not allow to boot on linux (or anything that is not Microsoft sanctioned) by default without a modification of the boot options, this is not because of Lenovo but because, in order to be certified by Microsoft, Lenovo has to comply with a set of rules that are not public and as such, impossible to follow for non-Microsoft entities. Edit: So, as Arnavion commented right below, my TLDR is incorrect inasmuch the fact that Microsoft requirements are not public only prevent us to understand why this change was made.
- trasz 4y agoThis is a gross misrepresentation of what this article is about.
- Arnavion 4y ago>a set of rules that are not public and as such, impossible to follow for non-Microsoft entities. This is not correct, in that there's nothing for "non-Microsoft entities" to do in this situation regardless of whether the rules are public or not. The only CA that non-Microsoft bootloaders can be signed by is the UEFI CA, and that is not going to change. At least not in the sense that non-MS bootloaders could ask to be signed by the CA that signs Windows (the one that's still trusted by default), because it has obviously always been intentional that Windows was signed by a different CA than the common rabble. The only piece of information we're missing, and which having the docs become public would reveal, is why this change needed to be made, so that we can then either sulk about it or try to get it reverted or resolved in some way. Edit: Note that SB has had a revocation list concept built-in since the beginning, and this list is designed to be serviceable by regular OS updates (the OS can just modify the EFI vars, no manual firmware flashing required like it was with BIOS). So it was not a problem even if some bootloaders got signed that shouldn't have. That's why it's weird that such a drastic approach is being taken.
- Avamander 4y ago> The only piece of information we're missing, and which having the docs become public would reveal It has been documented for a while really: https://docs.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-requirements#2016-additional-security-qualifications-starting-with-windows-10-version-1607-and-windows-server-2016 https://docs.microsoft.com/en-us/windows/security/identity-p...
- deleted 4y ago[deleted]
- aosmith 4y agoI would feel better if this was spun off into a b-corp with a perpetual grant.
- yellowapple 4y agoI agree, and I don't know why anyone would disagree sufficiently strongly to downvote your comment for suggesting that. Microsoft being directly in control over what can boot by default on PCs was and still is a blatant conflict of interest, and transitioning that decisionmaking to an independent body with input/control from more than just Microsoft would alleviate that considerably.
- aosmith 4y agoYup, we did it with SSL a long time ago...
- usr1106 4y agohttps://en.m.wikipedia.org/wiki/Benefit_corporation https://en.m.wikipedia.org/wiki/Benefit_corporation for those not familiar with US terminology.
- justinclift 4y agoPossibly better not under US control? Though I kind of reckon it'd have to be some inter-governmental thing rather than "pick a better gov". ;)
- aosmith 4y agoSSL isn't under government control, the same thing could be applied for secure boot.
- Arnavion 4y agoAs shitty as it is, it's nice of Lenovo to at least make it easy to enable the second CA. I wonder if all OEMs will be as "nice", or if any will require you to boot into Windows just to edit the EFI variables to add the second CA. Edit: Also, I've read a few horror stories of systems no longer displaying anything after the UEFI CA was removed from the trusted CAs, because there was no iGPU and the discrete GPU required an OpROM. No display meant no way to boot into the UEFI firmware to revert that change or even disable SB. How is that not a problem now?
- jsiepkes 4y agoThere used to be a requirement by MS mandating secure boot to be disable-able. Though I think they scrapped that requirement later on. No idea if third party CA enabling also has such a requirement.
- deleted 4y ago[deleted]
- usr1106 4y agoDisabling secure boot is one thing you should be able to do with hardware you own. Of course that's not a good idea if you want to run a non-Windows OS in a secure manner. Installing your own CA cert should also be possible. That's what we do at work with current UEFI implementations.
- cesarb 4y ago> There used to be a requirement by MS mandating secure boot to be disable-able. Not always, in some situations there was a requirement by MS mandating secure boot NOT to be disable-able: https://softwarefreedom.org/blog/2012/jan/12/microsoft-confirms-UEFI-fears-locks-down-ARM/ https://softwarefreedom.org/blog/2012/jan/12/microsoft-confi... "Disabling Secure [Boot] MUST NOT be possible on ARM systems."
- AshamedCaptain 4y agoOn the early Surface Pros at least, you had to boot into Windows and run a PowerShell script to enable the MS UEFI CA certificate. These days it looks like they made it a option on the system firmware.
- Joel_Mckay 4y agoDigital-locks like UEFI signing have a singular flaw, in that it only truly offers security to the people holding the signing keys i.e. a firm that did not pay for the computer, shouldn’t be tying unsolicited services to other peoples businesses, and should be classified as an adversarial threat vector. If Libreboot wasn’t such a pain to install, it would have saved a lot of grief.
- jsiepkes 4y ago> in that it only truly offers security to the people holding the signing keys i.e. a firm that did not pay for the computer That's not true. Practically all servers and more high end motherboards (even my HP zbook allows it) allow you to install your own CA's. Allowing you to create your own trust chain from firmware to OS. By itself there is nothing wrong with wanting a chain of trust between firmware and OS.
- Joel_Mckay 4y agoSure.. if you can manage your own keys and still install a normal OS, than you have done 2 things most home PC users will never do… and others simply cannot with a crippled factory BIOS. Yet we are not talking about servers, as features like Backplane administrative subsystems and hot-swapping internal bus parts are not standard on most PCs. Also, the Intel management engine and Computrace decedent features are not always removable, include their own CVE, and companies like Toshiba and Sony would trip the permanent asset flag at the factory forcing end users to adopt features they never asked for. “chain of trust between firmware and OS” assumes physical security in logistics and co-locations is perfect, and given the number of unsolicited network appliances we would get from vendors in some places I worked... a CA no one ever checks is the least of peoples issues. We avoided HP after the quality dipped for their fragile laptops, and some server firmware would reject generic storage options. ;-)
- jsiepkes 4y ago> Intel management engine and Computrace decedent features are not always removable Intel ME and Computrace have nothing to do with UEFI secureboot. > “chain of trust between firmware and OS” assumes physical security in logistics and co-locations is perfect Secureboot isn't just about physical security. It also (probably even more important) ensures malware can't modify anything in the chain of trust. Meaning malware can't backdoor the bootloader and in turn also can't install a rootkit in the kernel. If you would modify the binary of the bootloader or kernel their signatures would be modified. The firmware (ie. UEFI) won't load the bootloader anymore (because the signature check fails) and the bootloader (which verifies the kernel signature) won't boot the kernel.
- jillesvangurp 4y agoSounds like the same anti competitive behavior that MS was punished for two decades ago. Making it a requirement to only boot software approved by them excludes a whole range of competitors from using the same hardware. Making that a condition for OEMs to even get a license is the problem here. Lenovo is otherwise known for supporting Linux on their laptops. And yes I know you can jump through hoops and fiddle with scary (for ordinary users) bios options to "fix" this. The point is that you shouldn't have to and this is a bit too convenient for MS to keep competitors off laptops. Basically, what is needed here is a neutral certificate authority not controlled by a single company with a reasonable process for independent operating systems to get a certificate. I recently ran into this trying to boot linux on my old imac. Ubuntu actually works but forget about arch, manjaro, and a whole lot of other distributions. Imacs have no off-switch for secure boot that I know off.
- Arnavion 4y ago>I recently ran into this trying to boot linux on my old imac. Ubuntu actually works but forget about arch, manjaro, and a whole lot of other distributions. Imacs have no off-switch for secure boot that I know off. Does it also not let you use your own keys? Because if it does, you don't have to turn SB off, just use your key to sign the UKI and a bootloader like systemd-boot. It should work with any distro, especially one that uses dracut to create the initramfs because it's a couple of lines of dracut config to generate a (signed) UKI instead.
- jillesvangurp 4y agoNot in a way that is obvious to me. I'm sure you can work around it but if you just want to boot a live image and run an installer, ubuntu works and not a whole lot of other distributions do (because their installers don't support secure boot). I assume this is because of how much of a PITA it is to get certified.
- Arnavion 4y ago>I assume this is because of how much of a PITA it is to get certified. Distros don't have to do anything distro-specific to get signed. Most distros use (Microsoft-signed) shim to chainload to something like grub. But yes, it might be that the live CDs don't do that; I don't know. My experience with SB on all my machines has been to start with SB disabled and then I enable it afterwards with my own keys. I know the gparted and OpenSUSE live CDs support SB because I've booted off them after enabling SB. You could boot the Ubuntu live CD (or something smaller like gparted), mount the other distro's live CD, chroot into it, and run the other distro's installer that way. Just be sure that you enable SB support so that the installation actually boots afterwards.
- lmm 4y agoAt what point will mjg59 be willing to write the whole thing off as the anti-Linux measure that most open source fans have realised it is for a decade or more?
- jsiepkes 4y agoSecureboot by itself is needed because otherwise you have no way of making a boot chain from firmware to OS which can be validated on x86. Meaning Linux (servers) also have a use case for it. I also highly doubt Microsoft sees the Linux desktop as a credible threat to Windows. ChromeOS is an actual threat to Windows. And this does nothing for ChromeOS. It's more likely it's just a poor, uninformed decision from a team at MS.
- FeepingCreature 4y agoHow big do you think Microsoft's threshold is to fuck a competitor over? It sounds like you're saying Microsoft is slow to rouse to malice; I don't think that's how they work. If they can head off a competitor early for little investment, I believe they will do so - are doing so.
- selfhoster11 4y agoYou don't need Secure Boot or PKI for that. Simple proposal: 1. The system includes a TPM. The TPM measures all relevant pre-bootloader firmwares. 2. On first boot, the system firmware hashes the bootloader and stores the hash. A bootloader upgrade may be initiated by the old bootloader at boot time, and will update the stored hash to the one for the new bootloader., 3. On subsequent boots, the system will refuse to boot unless the user overrides the boot device, the user resets the stored bootloader hash, or the bootloader hash matches. The boot process then proceeds. 4. The bootloader may choose to continue measuring the system and updating the TPM, or skip the process. This proposal is platform neutral (will work on every platform with a TPM and system firmware), extremely simple to implement, not user hostile, and will not require PKI nor be hostile to users by default.
- kmeisthax 4y ago
- AshamedCaptain 4y agoThe worst problem is that people are (even in the other discussion thread here on HN) still claiming that we are scaremongering. Back when all this Secure Boot was announced, we already said that its main purpose seemed to be to make booting of non-MS operating systems more complicated, rather than security enforcement. "But, you're scaremongering! See, I put this Debian USB pendrive and I can still boot it fine!" This was because Debian (and many other distros) went, at some point, through MS-enforced hoops in order to get their bootloader signed. Quite a perilous situation in which MS was this "steward" of the entire PC OS ecosystem; whether a Linux distribution booted or not on PCs was practically at the whim of MS. That was at least better than the alternative (no booting -- since MS got away with SecureBoot anyway) and we have to thank people like mjg59 for it. Now, your Debian pendrive will not boot on this Lenovo PC, even if MS-signed. "But, you're scaremongering! See, I put this Debian USB pendrive in, hit F1, hit cursor down three times, tab, down five times, space, F12, and I can still boot it fine!"
- bejelentkezni 4y agoDebian's images are not Secure Boot signed. You made that up.
- sgift 4y agoMy problem with the position of the "MS is bad" crowd here is that the security reasons are outright dismissed. It's even in the article: > The second is that this is predicated on the idea that removing the third-party bootloaders and drivers removes all the vulnerabilities. In fact, there's been rather a lot of vulnerabilities in the Windows bootloader. A broad enough vulnerability in the Windows bootloader is arguably a lot worse than a vulnerability in a third-party loader, since it won't change the PCR 7 measurements and the system will boot happily. Removing trust in the third-party CA does nothing to protect against this. Why is it 'all'? Why not 'some' vulnerabilities? Because then it's rather obvious that having one less bootloader allowed by default means less potential for vulnerabilities. And then the whole point breaks down.
- michaelt 4y ago> Given the association with the secured-core requirements, this is presumably a security decision of some kind. Unfortunately, we have no real idea what this security decision is intended to protect against. Isn't secure boot attempting to protect against 'evil maid' attacks? After all, the evil maid can come in on Day 1 and insert a bootable USB stick which boots a linux distro customised to look like the normal Windows boot and save your password when you enter it; then on Day 2 boot the computer normally and use that password. If you want to protect against that, you need password-protected BIOS settings to enable/disable booting third-party code. (Personally I see adopting the TPM as a fool's errand - I don't think it can ever deliver on its promises)
- phh 4y agoIf you can't modify victim's computer itself, just do that on another computer? The evil maid will need less time to replace the computer with another one that looks alike the original one, than to install a Linux distro
- dotancohen 4y agoThe maid could even install a USB keylogger, if the goal is compromising just the credentials.
- michaelt 4y agoThis is what I mean when I say adopting the TPM is a fool's errand; I think protection against evil maid attacks is impossible. Unless you're willing to go full iphone/xbox with no third-party hardware or OSes.
- phh 4y agoIn the case of the Xbox, you can replace the mainboard with like a rpi and still achieve it quite easily (I'd say budget ~ 100€). That's harder for a smartphone (I'd say budget ~ 2000€). Either way, the budget is still lower than the price of security flaws to circumvent secure boot.
- peter_retief 4y agoI do not want to ever use Microsoft software, why do I need a Microsoft certified key to use my own hardware? Big question is how do Microsoft get away with this bullying of hardware manufactures, probably the fear of losing business. What can we do to stop this?
- onli 4y agoThe moment systems like TPM and secureboot were added it stopped being our hardware. We said as much back then, sabotage like described here show that analysis was right. There is nothing that can be done as long as there is a processor duopoly that follows these ms requirements.
- jeroenhd 4y agoWhat's the problem with TPMs? Do you mean the Intel ME/AMD PSP or is there an anti hardware key movement out there that I don't know about?
- cesarb 4y agoAFAIK, the fears with TPM are mostly about remote attestation. That is, a remote system could certify that you are running Windows (and not something else like Linux) on the physical hardware (and not on a VM) before allowing access to some resource; and that "some resource" could in the future even include basic things like Internet access.
- jeroenhd 4y agoThat's a pretty terrible system, but I'm more afraid of the remote end of the system than the local one to be honest. We already have DRM and Intel providing features like SGX isn't the problem; the external parties choosing to restrict user freedom are. I don't think remote hardware attestation will be implemented anywhere but in enterprise environments where it makes sense to do so. Even on Android we see remote attestation being bypassed quite easily in most apps. Some banks and payment providers are harder to trick, but I don't think there's a version of the system that hasn't been bypassed yet.
- denton-scratch 4y agoThis seems to be MS's response to a rather serious mistake in GRUB2 - a howler, I'd say. I've never liked GRUB2 much. The configuration seems to freely mix executable code and data, which makes me tremble at the prospect of altering it. And I find it much harder to understand than GRUB Legacy (and that's saying something).
- password4321 4y agoI recently learned about EFISTUB thanks to https://news.ycombinator.com/item?id=31231968&p=2#31234648 https://news.ycombinator.com/item?id=31231968&p=2#31234648 > Load Linux directly as an EFI executable via the EFISTUB approach. > the "Using UEFI directly" section [...] https://wiki.archlinux.org/title/EFISTUB https://wiki.archlinux.org/title/EFISTUB
- ysnp 4y ago>But unfortunately the 2022 requirements don't seem to be publicly available, so it's difficult to know what's being asked for and why. Where can we find the full requirements for a device to be Secured-core?
- james-redwood 4y agoThe lack of transparency over the definition of 'secured-core' is disturbing.
- bitwize 4y agoWe're now at the final stage of conspiracy theory damage control with respect to the idea that Microsoft is trying to lock down the PC platform and prevent non-Windows operating systems from booting: 1. It's not happening, I don't know what you're talking about, anybody who believes that has been radicalized by Russian propaganda 2. Well, yeah, maybe it is happening here and there, but it's no big deal, and it's certainly not through a coordinated effort on our part 3. Yes, it's happening, it's been happening all this while, and here's why it's a good thing <-- we are here We all will have to reckon with the fact that general purpose computing is going bye-bye. The interests of OEMs and ISVs in delivering a safe, consumable experience to end users are aligned against allowing unsigned, unapproved software from running. And yes, the OEMs, ISVs, and probably most of the consumer market will believe that this is a good thing. The next big thing is remote attestation: the internet will simply stop working properly on your machine unless it can prove that it is running an approved OS and application stack.
- option_key 4y agoYou don't understand! Nadella's Microsoft open-sourced a few applications and created a popular text editor, which makes him basically the second coming of Christ in the eyes of a large portion of HN users. Their numerous anti-user and anti-privacy practices are unimportant. Nadella's Microsoft is "cool" and that's all that matters.
- fredgrott 4y agoDoes this reflect the same sort of issues in the browser password protection space, i.e. Since last year chrome by default links to google password protection in short words you have to do extra steps to link google accounts to non-google Chrome browsers. They say security but there is an underlying Elephant in the room concern that keeps rearing it's head.
- xenophonf 4y agoThe apparent secured-core requirement for 2022 is that [...] out of the box, these systems will not boot anything other than Windows. I don't see how anyone can look at the history of Microsoft and not immediately judge this as being completely anti-competitive in nature.
- sylware 4y agoAccute evil, what did you expect?
- NoGravitas 4y agoI'm shocked. Who could ever have foreseen Microsoft doing such a thing?
- nvr219 4y agoRe this website itself: Love seeing LiveJournal code base still in use.
- CaliforniaKarl 4y agoKindof off-topic, but… > whenever a signed object is booted by the firmware, the trusted certificate used to verify that object is measured into PCR 7 in the TPM. Is there a list somewhere of what each PCR is generally used for? I’ve had difficulty finding the information through Google searches.
- mjg59 4y agohttps://trustedcomputinggroup.org/resource/pc-client-specific-platform-firmware-profile-specification/ https://trustedcomputinggroup.org/resource/pc-client-specifi... is the spec for this on PCs.
- dang 4y agoRecent and related: Lenovo shipping new laptops that only boot Windows by default - https://news.ycombinator.com/item?id=32023868 https://news.ycombinator.com/item?id=32023868 - July 2022 (388 comments)
- zzo38computer 4y agoSecure boot is one problem with UEFI but it is not the only problem.
- rob_c 4y agoWhy is this being moaned about because of one bad machine _again_. As much as i love to lay into Microsoft I see little reason to yet, other than speculation and corporate bad practice brought on by massive corporate incompetence, no grand conspiracy…