22 ms·
If you really wanted to verify that secure boot was enabled, and that a user wasn't doing "funky things", you'd need to also check for a TPM attestation, as you
by g_p 4y ago
If you really wanted to verify that secure boot was enabled, and that a user wasn't doing "funky things", you'd need to also check for a TPM attestation, as you allude to - this isn't really simulating a whole lot from a security perspective.
You can fairly easily "spoof" secure boot being enabled on a non-secure-boot system, since effectively you are exposing a 1 instead of a 0 (and with secure boot off, can hook whatever you need to). Admittedly, having a button in the UEFI menu is more convenient for an end user though.
If you have a TPM attestation of the device state, PCR 7 is sealed around the secure boot state, and that would be more interesting for someone trying to lock someone in. As you say, if your TPM is then being used to attest that the system is unmodified, then that is pretty user hostile.
For a regular normal non-technical user though, having some "sane defaults" arguably makes sense - if we raise the bar on compromising a regular person's computer by a few notches (i.e. you can't just replace the bootloader with a keylogger and chain-load the regular bootloader), it can help with platform security. The problem is that, on top of that platform, end users run all kinds of (what we'd previously call) spyware/adware, which just sends their data off the system. When this "non-technical user protection" starts to get in the way of expert users, that's when it becomes more of a problem for being in control of your own system.
- raxxorraxor 4y agoI also would want to spoof the remote attestations. Let us be honest here, the features to expect is that Netflix doesn't work on your non-approved "secure" device. Not many other benefits to the user are provided. The most locked down systems are the ones that expose the most data. Granted, that is because of the type of the device in many cases, but that is the current reality.
- smileybarry 4y agoSome multiplayer games use Secure Boot and remote attestation as confirmation that the user can’t load cheats. Like any anti-cheating solution it’s not perfect, but it can lower the prevalence of cheats dramatically, and that’s one hell of a user benefit.
- Zuiii 4y ago> that’s one hell of a user benefit Not for every user. Besides, the protections this would offer would be easily and cheaply circumvented via a raspberry pi and usb peripheral emulation. The is no escaping the analog hole as you stated. I'm not willing to give up my control as an owner over my device for a reason as flimsy as this. Gamers who want to give up control for a slightly lower percentage of cheaters can get dedicated computing hardware (consoles) instead.
- smileybarry 4y ago> > that’s one hell of a user benefit > Not for every user. Not every feature has to benefit every single user. Otherwise let's just remove WSL because it's in use by <1% of Windows users. > I'm not willing to give up my control as an owner over my device for a reason as flimsy as this. Gamers who want to give up control for a slightly lower percentage of cheaters can get dedicated computing hardware (consoles) instead. Okay, then turn off Secure Boot. And just don't play these games. No one's saying all computers must have Secure Boot on and untoggleable. Secured Core is optional and it's very enterprise-focused, i.e.: businesses gating domain join to Secured Core PCs for extra perimeter control.