5 ms·
>like on surface systems. Surface Pro ships with an unlockable bootloader. You can even remove Microsoft's own key and install your own so that Windows can't b
by recoiledsnake 13y ago
>like on surface systems.
Surface Pro ships with an unlockable bootloader. You can even remove Microsoft's own key and install your own so that Windows can't boot.
>They can either change a requirement to have the ability to disable it be optional, or make the inability to disable it mandatory, like on surface systems.
No, they cannot. The antitrust govt lawyers will be all over them if they want to try something like that.
>The problem with supporting secure boot is it legitimizes microsoft's role as the gatekeeper to computing
Microsoft doesn't mandate that their key must be the only one to ship by default. The fact that Linux community can't get together to make a signing infrastructure while the OEMs are willing to add keys is not Microsoft's fault.
>I seriously do not understand why everybody has rolled over so hard on this issue
Simple, because the user is in real control of their PC and can add/remove keys as they wish. And Secure Boot prevents the vast majority of non-techy users from getting undetectable bootkits installed on their machine.
- throwaway2048 13y ago>Surface Pro ships with an unlockable bootloader. I was talking about surface systems, the arm ones with the locked boot loader, not surface pro, the similar naming only adds confusion to this issue. >The antitrust govt lawyers will be all over them if they want to try something like that. You totally ignored the point that now they can show antitrust lawyers all these linux distros and others that support secure boot! its not about maintaining a monopoly cough. > Microsoft doesn't mandate that their key must be the only one to ship by default. The fact that Linux community can't get together to make a signing infrastructure while the OEMs are willing to add keys is not Microsoft's fault. What about BSDs, what about haiku, what about the hacking project some guy wrote last week, should they all be held responsible "for not getting their act together" and getting OEMs to distribute their signing keys so Microsoft doesn't directly control their fate? The point is that this is a very intentional barrier to entry, its exactly the same tactic Microsoft has been using for decades to shut out competitors, but its totally sincere this time, and only about protecting users? Sorry i don't buy it. >Simple, because the user is in real control of their PC and can add/remove keys as they wish. For now, and a requirement that was only added after Microsoft went ahead with requiring secure boot when people complained. They already distribute fully locked down systems, is it such a stretch to believe they will permit, or even mandate it in the future for x86? Even if they never choose to lock down x86 systems entirely, why is this obvious conflict of interest being allowed to exist. >Secure Boot prevents the vast majority of non-techy users from getting undetectable bootkits installed on their machine. Anti-bootkit security does not imply UEFI Secure Boot where Microsoft controls the only key on every x86 PC of consequence.
- recoiledsnake 13y ago>surface systems, the arm ones with the locked boot loader, not surface pro, I guess you mean Surface RT. There is no "surface systems". >For now, and a requirement that was only added after Microsoft went ahead with requiring secure boot when people complained. They already distribute fully locked down systems, is it such a stretch to believe they will permit, or even mandate it in the future for x86? Sorry, but a thought crime is not a crime. That someone may or may not do something illegal in the future does not imply they should be prevented from doing something legal today. >Anti-bootkit security does not imply UEFI Secure Boot where Microsoft controls the only key on every x86 PC of consequence. Perhaps you have a better solution to prevent undetectable bootkits. My grandmom has a higher chance of getting a bad virus than wanting to install Haiku OS on her computer. I don't wish that her and hundreds of millions of other's PCs are left vulnerable to undetectable bootkits because a few people somewhere can't be bothered to uncheck a checkbox in order to install GNU/Hurd or because Microsoft may send thugs in the future to delete my Ubuntu install.
- throwaway2048 13y agoA murderer has murdered once, should we be wary about giving him the means and the ability to pull the trigger once again?
- drivebyacct2 13y agoWhat is your point/alternative/suggestion? I mean, what do you want to see happen? I don't think anyone loves the influence Microsoft has on OEMs but what can be done from a market or legal standpoint? Or even as I mentioned in my other post, what can even be done from a technical standpoint to properly mitigate this further?
- drivebyacct2 13y ago>Anti-bootkit security does not imply UEFI Secure Boot where Microsoft controls the only key on every x86 PC of consequence. So then, Microsoft releases Windows 9. It's signed with Microsoft's key. You go out and buy a Windows 9 laptop. But wait, they didn't pre-enroll the Microsoft SecureBoot key, now you're screwed and you can't even boot your brand new computer. That's the scenario if you don't pre-enroll the key. I'd love it if we could somehow guarantee they'll never change their mind and remove that requirement. In that absence of that, smarter solutions are needed- it's not as simple as people make it out to be.
- jejones3141 13y agoAlas, there's a long history of antitrust suits taking so long that the actions giving rise to them have had their intended effect and are no longer relevant.
- sounds 13y agoPlease review recoiledsnake's comment history. This discussion unfortunately has been had before.