17 ms·
MSI's (in)Secure Boot
- Gigachad 4y agoGreat writeup. The result is not particularly surprising. I suspect they did this to reduce customer support messages about things not working and decided just putting fake secure boot in makes things work most. Security would be not a major concern for gaming mobo makers.
- jabbany 4y agoTo me this makes a lot of sense, and really is the reason why most things are by default insecure. Most people who are building their own computer are not going to be an expert in UEFI and secure boot (some may have never even heard of these things). These people are almost guaranteed to need to install their own OS. So if they try, and it "doesn't work", they are going to need tech support or most likely return the motherboard as defective. Thus it makes more sense to make the default permissive. On the other hand, someone who does want to run secure boot securely is probably an expert, so they can probably figure out how to actually turn it on and harden their setup. As long as you can lock stuff down, having these people jump through a few more hoops seems like a reasonable trade-off. (Also FWIW, most pre-builts or integrated devices do have real secure boot enabled, since the expectation is that users of these will likely never need to install an OS that won't work with a strict secure boot enforcement policy.)
- toyg 4y agoTotally agree. MSI picked the right default for a PC component sold individually.
- gjsman-1000 4y agoThis doesn't actually make any sense to me. MSI's BIOS falsely reports to Windows that Secure Boot is enabled. This is very different from just shipping with Secure Boot disabled but available. That would be pretty normal (at least of a few years ago) - but shipping with a mode where it is "enabled," and Windows is convinced that it is "enabled," even though it is doing practically nothing - that's an inexcusable situation. Assuming that I interpreted this rather vague statement correctly, of course: > When we enter the menu, we can see the disappointing default settings. It's doing no verification. It's useless. It's just there to satisfy Windows 11 requirements. OS has no idea that Secure Boot is doing nothing, it just knows that it's "enabled". As he says, this would totally break UEFI Spec. Secure Boot being available but disabled is OK and common - Secure Boot being available and saying enabled while actually not checking is a violation. EDIT: Actually... the author may be wrong and, counter-intuitively, it may not break spec. https://news.ycombinator.com/item?id=34407911 https://news.ycombinator.com/item?id=34407911
- jeroenhd 4y agoWindows 11 requires secure boot to be enabled, at least during install. Perhaps it has something to do with that?
- gjsman-1000 4y agoNo, it does not, as far as I am aware. Windows 11 requires information from the BIOS that Secure Boot is available, not that it is enabled. EDIT: I stand corrected. Windows 11 is OK with Secure Boot capable if you are upgrading from Windows 10, but requires enabled for a fresh install, though Secure Boot can be disabled after installation. > While the requirement to upgrade a Windows 10 device to Windows 11 is only that the PC be Secure Boot capable by having UEFI/BIOS enabled, you may also consider enabling or turning Secure Boot on for better security. https://support.microsoft.com/en-us/windows/windows-11-and-secure-boot-a8ff1202-c0d9-42f5-940f-843abef64fad https://support.microsoft.com/en-us/windows/windows-11-and-s...
- jeroenhd 4y agoYup, this is the confusing thing about Windows 11. The requirements for upgrades and fresh installs are different so upgrading will work but installing from scratch on the same machine may fail. I think MS deliberately chose to let users upgrade from Win10 without secure boot because too many PCs have it disabled by default, and your average user cannot be expected to go into their UEFI security options to resolve that. The secure boot requirement is mostly intended for vendors AFAIK, requiring them to turn it on by default (and leaving it up to the user to disable it) so Windows 11 can make use of the additional security features out of the box.
- Gigachad 4y agoThe Windows installer does an awful job at guiding the user through this. If Secure Boot is turned off, it doesn't tell you this. It just says "Your computer is not compatible with Windows 11" I have a brand new desktop and Windows just flat out says you can't install it when I'm sure it just involves changing some settings.
- jeroenhd 4y agoMost people are going to install Windows and Windows works out of the box with secure boot enabled. Most other people will use a popular distribution like Ubuntu or Fedora which work out of the box with secure boot enabled. I doubt people installing their OS will run into this. Even still, the firmware contains the ability to prompt the user about secure boot failures, so if you're going to neuter it, at least pick that as the default option so people notice. Instead, my suspicion is that these policies are in place so non-OS firmware can run, such as firmware update tools for upgrading the BIOS itself or perhaps management chips/HDDs/SSDs/peripheral controllers. If I were to lock down my previous laptop with secure boot, HP's firmware updates would no longer be able to run without enrolling their signature keys.
- gjsman-1000 4y ago> If I were to lock down my previous laptop with secure boot, HP's firmware updates would no longer be able to run without enrolling their signature keys. Well that's... really dumb and shows why OEM's are terrible at security, as there isn't a reason I am aware of on why Secure Boot can't trust two keys simultaneously (one for OS and one for vendor). Heck, Microsoft themselves seems to do it with "Windows + 3rd Party UEFI CA."
- jeroenhd 4y agoI suppose I _could_ sign the extracted UEFI loader manually to make the updates work, but that pretty much breaks the automated process and requires me shuffling the boot order manually after the failed boot. Not a great solution and that assumes the UEFI image doesn't do something weird like its own signature. It makes sense to use UEFI programs to update the UEFI, but secure boot adds a layer of complexity on top of that which requires taking special notice.
- vladvasiliu 4y agoI'm not one to praise my HP machines, but this is one area where I've had zero issues with them. Are you by chance using "consumer" models? My "enterprise" level PCs, starting with models of the intel 6th gen era, up to 12th gen, have been smooth-sailing secure-boot wise. I didn't interact with any older model. I run Arch (which isn't signed by MS like Ubuntu / Fedora) and sign the bootloader with my own key that I've generated myself. On some computers where I need to dual-boot with Windows, I've signed MS's Windows key (not the third-party one) with my key. Everything has always worked fine, including automatically upgrading the UEFI over the network from the UEFI itself, installing Windows 11, etc. I never needed to disable Secure Boot (apart from initial Arch install) or sign any HP-specific key. The only thing that "breaks", but that's expected and HP warns you during the update, is that whatever relies on measuring the UEFI image will break. That's typically the case with BitLocker (mentioned specifically) and LUKS.
- gruez 4y ago>Most people who are building their own computer are not going to be an expert in UEFI and secure boot (some may have never even heard of these things). These people are almost guaranteed to need to install their own OS. So if they try, and it "doesn't work", they are going to need tech support or most likely return the motherboard as defective. Thus it makes more sense to make the default permissive. Not only that, a popular tool for creating windows USB installers[1] fails to boot if secureboot is enabled. I looked into it a few years ago and it was because it defaults to NTFS formatting if install.wim is greater than 4GB (because of FAT32 limitations), which is most windows ISOs. Most UEFI implementations don't support NTFS, so it installs a shim loader, which is unsigned and therefore fails to boot with secureboot enabled. [1] https://rufus.ie/en/ https://rufus.ie/en/
- scrlk 4y agoRufus 3.17 (released Oct 2021) onwards is secure boot signed. See: https://github.com/pbatard/rufus/releases/tag/v3.17 https://github.com/pbatard/rufus/releases/tag/v3.17
- Sakos 4y agoHuh, interesting. I know he'd been working on it for a while and wasn't getting anywhere because of Microsoft, but apparently he finally got it working. The only real issue is getting your bootloader signed by MS. There's no other way to pass Secure Boot verification. https://github.com/pbatard/uefi-ntfs https://github.com/pbatard/uefi-ntfs Edit: https://old.reddit.com/r/sysadmin/comments/pl2jqg/creating_bootable_usb_drives_with_rufus_requires/hcb9tw6/ https://old.reddit.com/r/sysadmin/comments/pl2jqg/creating_b... This is the last time I read anything about it from the Rufus dev (which was over a year ago)
- mook 4y agoBecause it was interesting, here's a summary: • Microsoft refuses to sign GPL3 code for secure boot, because the anti-Tivoization clause is specifically designed to prevent this (the system basically tries to achieve what Tivo did, only supporting boot authorized by people with a given key). • The Rufus developer did work to get the GPL2 ntfs-3g drivers usable in UEFI. • Microsoft appears to have no issues signing that.
- arsome 4y agoThis is actually a pretty nice pro-consumer feature as this makes it trivial to lie to Windows that secure boot is enabled while hooking things. Great for game cheat developers for example, who often want very deep hooks on the system to bypass anti-cheat tooling and with some modern games requiring secure boot to be enabled, this could provide an interesting alternative strategy.
- gjsman-1000 4y agoI am shocked that Windows isn't using a TPM Measurement for verification, as the TPM can be used to prove that Secure Boot was enabled. Instead... Windows just seems happy trusting the UEFI and letting any apps that want to ask the TPM. Which... why? I mean, I suppose it's a holdover from Windows 10 where Secure Boot existed without TPM but there's no reason in Windows 11 where both should be present.
- helloooooooo 4y agoWindows does do that, it’s called Secure Launch. It uses DRTM and SRTM for remote attestation to prove to remote machines that the OS booted in a well known state. The biggest problem is that there is such a modge podge of hardware and firmware to measure, that the only real use of it is in corporate environments where the hardware deployed is fairly homogenous.
- joerichey 4y agoI looked into this on my motherboard, and the issue is that MSI's firmware measures in the TPM events saying "Secure Boot is On", even when it is in this insecure mode. This means that even if Windows "checks" (via measured boot) that Secure Boot is on, they are still being lied to by the motherboard firmware.
- mjg59 4y agoPCR 7 doesn't just indicate whether secure boot was enabled, it also contains information about which certificates were used to boot. Obviously if you'll happily sign something unsigned the unsigned thing can just fake a measurement that contains the expected certificate, but I'd be interested to see what the event log looks like on one of these systems when it boots an unsigned binary.
- g_p 4y agoFor the 99% use-case, secure boot being enabled and enforcing by default shouldn't really be an issue in the last few years. Almost all major Linux distributions (i.e. the ones with an easy install disc image you write to a USB stick) use a signed bootloader, and shim or mok or another way to validate the boot chain - the installer will boot fine, and after install, the OS will boot fine, under secure boot. Windows since 8.0 (?) has also shipped signed - installer and resulting install will both work. Unless you're dealing with an edge case (i.e. you want to install a non-secure boot capable Linux OS, or BSD or something less common, which isn't using a signed loader), an end user should never really encounter secure boot issues in theory. That's not to say there shouldn't be an "off" switch; but that these days there are very few scenarios where an end user doing their own OS install will hit a secure boot failure.
- jabbany 4y agoHaving to handle 1 customer support ticket for every 100 board sales seems like an extremely serious problem well worth supporting! The failure rate of motherboards is only ~3%, imagine adding an extra 1% on top... (I know you're trying to make a point with the 1%, but _any_ reduction in support tickets by adjusting the secure boot default (which is essentially free) is going to be worth it to the manufacturer. )
- smileybarry 4y agoYou don’t have to know about UEFI or Secure Boot to properly install Windows. You download an EXE from Microsoft, make an installation USB, and it‘s fully configured for you. That’s what everyone does (especially in the desktop PC space) and it’s works with Secure Boot perfectly well. And it’s there to disable if you don’t want it.
- blueflow 4y agoAnother vendor quirk! Give it a decade and the UEFI/SecureBoot ecosystem will be as muddy as real mode/BIOS was when we replaced it with UEFI.
- gruez 4y agoShouldn't this be an non-issue in any sane setup (ie. secureboot + TPM + FDE)? If the TPM is doing its job, it should be measuring the signature of the bootloader, so whether it's signed or not is irrelevant. Even if you could get stuff to boot, it wouldn't do you any good because you can't access the decryption keys. On the off chance that you're using secureboot without TPM + FDE, you'd be screwed anyways, because a bad guy could easily disable secureboot inside bios settings, or use shim loader to bypass it.
- WhyNotHugo 4y ago> Shouldn't this be an non-issue in any sane setup (ie. secureboot + TPM + FDE)? A sane setup might not be using TPM because, e.g.: they don't need it. I don't use TPM for FDE, just a passphrase. Using TPM means that if my motherboard dies, I can no longer access my disk. Far from ideal. > a bad guy could easily disable secureboot inside bios settings Can this be usually reconfigured without the firmware passphrase? > use shim loader to bypass it. They'd need to get it signed with the key trusted by the local firmware.
- derkades 4y agoSo is there any reason for secure boot to exist, other than to make it harder to boot an operating system other than Windows? I am all for verified boot (like implemented on some smartphones like Pixels), but UEFI secure boot doesn't seem particularly useful to me.
- gruez 4y agoIn theory it would make bootkits (ie. malware that installs themselves as the bootloader, thereby being able to compromise/remain undetected for every subsequent step) harder to pull off. It's not part of my threat model though, because if malware made it onto my machine I'd be doing a full wipe. Also, this xkcd is pertinent: https://xkcd.com/1200/ https://xkcd.com/1200/
- tormeh 4y ago> Also, this xkcd is pertinent: https://xkcd.com/1200/ https://xkcd.com/1200/ Pretty much. The mainframe security model used by desktop OSes is fundamentally broken.
- derkades 4y ago> Is it mentioned in the changelog? Hah, nope. For a motherboard I updated a week ago (B350 PC Mate) I did notice the following item in the changelog: > - Change the default setting of Secure Boot. So it was mentioned in the changelog, just very vaguely.
- dawidpotocki 4y agoThis change is unrelated. E.g. 7C02v3F (2022-08-12) for B450 TOMAHAWK MAX had this line in the changelog, but 7C02v3C (2022-01-18) version also had this issue.
- zerocrates 4y agoI believe that change is to enable Secure Boot by default. Changes like this and enabling the CPU-integrated TPM by default have happened all across product lines in the past year or so due to Windows 11 requirements. I applied an update with that changelog line recently and it definitely now turns Secure Boot on (presumably in this "non-enforcing" state mentioned in the article) by default when it previously didn't.
- jasonhansel 4y agoSounds like a good thing, insofar as it allows you to bypass the Windows requirement that Secure Boot be enabled. This should be good news for people running obscure Linux distros or other operating systems. Might be better to disable it by default, though. Do other motherboards support this "feature"?
- Gigachad 4y agoMacBooks have a much better feature where you can run MacOS in full security mode while having separate bootable partitions which are in permissive mode. Much better than the all or nothing model of secure boot.
- zozbot234 4y agoTo be fair, the SecureBoot 'shim' loader is pretty much designed to do this, with user's consent.
- dawidpotocki 4y agoIt's not good news for Linux distros. This setting breaks GRUB's expectations of shim being available when Secure Boot is enabled. Because of this, it will decline booting and will show you an error message. IIRC EVGA and Gigabyte have "Audit mode" option in their firmware, which does only logging.
- micahdeath 4y agoMy Linux prefers this mode, but I use ELILO & LILO.
- userbinator 4y agoWhether it's intentional or not, I like that there are still companies which are willing to subvert the corporate authoritarianism of Big Tech. What's funny is that "Allow Execute" and "Query User" options are breaking UEFI specification They're giving the user freedom, which the specification is against. IMHO they chose the right path. Willful disobedience applies to software too. My opinion of MSI just got a little better.
- dawidpotocki 4y agoNo, the specification is not against user freedom. "Always Execute" is not against the spec. "Query User" is partially broken, so it's not even that useful. If you use a bootloader, you will only be able to confirm booting of the bootloader, you won’t be able to confirm the OS that it starts. You will get the dialog, but the input won’t work. MSI did not add any of these features, they are available in EDK II. https://github.com/tianocore/edk2/blob/9ce09870e721efacc41fa7ee684e9e299f120350/SecurityPkg/SecurityPkg.dec#L267-L278 https://github.com/tianocore/edk2/blob/9ce09870e721efacc41fa...
- Conan_Kudo 4y agoAt one point, I would have agreed with you. But Microsoft and Intel have been strong-arming implementations to reduce or eliminate user freedom over the past few years. It's been a sad state of affairs.
- Randor 4y agoThe modes "Allow Execution" at 0x2 and "Query User" at 0x5 are both documented in the UEFI security spec.
- drdaeman 4y agoI hope that they provide a visible warning that secure boot is subverted. So it's not that some evil maid could replace the boot chain and update the firmware settings to make it behave as if nothing happened. Just for those folks who use and want it. And maybe also introduce a TOFU model i.e. "allow execute" but ask when the hash changes, so booting the same unsigned binary is OK but updates aren't silently allowed and require a quick confirmation (possibly with a timer for unattended reboots). Won't help against physical attacker but should help against a malware that manages to get root and tries to install itself into the boot chain.
- getcrunk 4y agoThis reminds me of the time where I think Samsung drives would do “hardware encryption” when using bitlocker on windows. And the encryption literally actually did nothing.
- Gigachad 4y agoYou should never trust that anyway. Apple has a similar thing which presumably works using the T2 chip to transparently encrypt everything going to the SSD, but they still use filevault to then encrypt the user data again.
- WirelessGigabit 4y agoDo they? I recall that Apple recommends enabling FileVault to ensure you CAN erase data from the computer, as you cannot really erase an SSD.
- transpute 4y agoMSI Z690 has coreboot support, https://www.phoronix.com/news/MSI-Z690-A-DDR5-Coreboot https://www.phoronix.com/news/MSI-Z690-A-DDR5-Coreboot
- grawlinson 4y agoI have a Z97 board from ASUS that exhibits this behavior. It’s a bit ridiculous because there is no Secure Boot option in BIOS other than disable/enable.
- 4cao 4y agoThese defaults seem like a reasonable, pro-consumer choice. Great to know there's at least one vendor that helps to get around the restrictions Secure Boot creates for the user. Secure Boot has always been an anti-feature, at least from the user's point of view. It seems really strange to complain your device isn't locked down enough by default: the restrictions can always be enabled manually if that's your kink.
- charcircuit 4y agoBy that logic any security feature is an antifeature. The problem with that logic is that you can't ignore the potential harm that is being protected against.
- 4cao 4y agoSecurity from the user, not for the user, is an anti-feature from the user's point of view. Security features in general are not.
- charcircuit 4y agoOkay, but secure boot's purpose is protecting against malware.
- patientplatypus 4y ago[dead]
- simple-thoughts 4y agoI’ve never understood secure boot. If someone gains physical access to one of my devices, they can do any number of things to compromise it. I don’t really understand what threat model secure boot protects against, but I have spent so much time digging thru bios settings trying to figure out how to disable secure boot so I can install my preferred Linux distro that it seems the primary “threat” is users who don’t want to install Windows.
- pilif 4y agoSecure Boot is designed to help with malware compromising boot code that runs before the OS gets to run and thus has the ability to hide itself from OS and everything running on it while also able to intercept everything an OS is doing. Given that often physical access allows secure boot to be turned off, it’s clearly not made to protect against a physical attacker. Now, what’s left is a bit of a mixture of a political issue and developer laziness that makes secure boot a binary toggle of on=boots only microsoft-sanctioned OSes and off. Ideally there was a safe way for a user to get their own boot loader and OSes signed to allow them to safely boot their own OS while still being sure that it was the user‘s intention to boot that thing. Ironically, walled-garden Apple went exactly there with their secure boot implementation on their Apple Silicon macs (source: https://social.treehouse.systems/@marcan/109679905123512668 https://social.treehouse.systems/@marcan/109679905123512668)
- cesarb 4y ago> I’ve never understood secure boot. [...] I don’t really understand what threat model secure boot protects against It helps if you remember the context in which Secure Boot was created. Back then, boot sector viruses and similar malware were common. The way they operated was by hooking the operating system while it was being loaded. The operating system (or software running on top of it, like anti-virus and other anti-malware stuff) could protect itself against something which loaded after the kernel and device drivers, but not against something which loaded before the operating system kernel itself. That is: the main threat model Secure Boot protects against is boot sector viruses and similar. Even if some malware gets write access to the full raw disk, it still cannot inject itself before the kernel in the startup sequence.
- Nursie 4y agoInteresting, and I think a positive option, if an odd default. My guess is that this was a direct result of people saying "But I need to install windows 11!" but not wanting to actually default-activate secure-boot in case it screwed up other systems. I'd have preferred this to what happened on my MSI MEG X570 Unify motherboard when I recently updated the BIOS and installed a TPM module - grub was prevented from loading up my debian system because secure-boot got activated by default. I had to hunt around and de-activate to continue using the system.
- jgaa 4y agoUEFI and "Secure Boot" has always stuck me as a terrible idea. It adds lots of complexity to the boot process - which means that it adds vulnerabilities. Added complexity almost always leads to more vulnerabilities. It adds a DOS partition (!!!) to the disk, and prevents me from for example dual booting two versions of Debian on the same machine. The whole thing has a bad smell of Microsoft around it, which translates to hidden motives (make it hard to not run Microsoft on this hardware) and insecurity (because they don't do "secure". They never did). If you want "secure boot" - get hardware that support "legacy boot" and boot something else than Microsoft Windows ;)
- vetinari 4y ago> It adds a DOS partition (!!!) to the disk, It is a FAT32 partition; most DOS versions are unable to read it. > prevents me from for example dual booting two versions of Debian on the same machine. It doesn't; UEFI doesn't care what is the boot image, only that there is some. You can register as many boot targets as you want. Check efibootmgr in one of your debian instances, if your installer is not capable of doing that.
- deleted 4y ago[deleted]
- boring_twenties 4y ago> prevents me from for example dual booting two versions of Debian on the same machine. It absolutely does not.
- geocrasher 4y agoI have one of the affected motherboards, a B350 PC MATE: 7A34vALS. I'm glad. I just updated the CPU to a Ryzen 5 5500 (half the price of the 5600G, no "G", less L3, fine for my use case, and only $100 right now). It has TPM, so now I can upgrade to W11 (save it, don't want to hear the W11, don't care) but I need to turn on Secure Boot, which I haven't had a chance to examine yet. But now, I don't need to. MSI's implementation caters to people like me who don't need enterprise level security just to run an OS. Thanks, MSI.
- rogers18445 4y agoAn answer to security theater is a performance of your own it seems.
- Avamander 4y agoI've seen similar with EU power consumption legislation toggles. Default off, for no good reason.
- frankzander 4y agoI have a over 10 years old second hand computer. Works great. But from the comments ... is it nowadays not possible to work without secure boot if I buy a new motherboard?
- DiabloD3 4y agoNo, it's completely possible. You go into the BIOS and turn it off. Any BIOS that you can't turn it off is either defective, or it is meant for high security enterprise stuff (you have to pay extra for corporate laptops that only allow secure operation).
- mmis1000 4y agoI used to try to add ventoy's CA into the secure boot ca list. But due to one of the hard disks failed(the exact reason I use ventoy to boot an iso).The secure boot configuration just decided to hang every time I open it. In the end I just disabled the secure boot all along. It's just broken and didn't work.