5 ms·
What are the benefits of Secure Boot?
by raylu 13y ago
What are the benefits of Secure Boot?
- sliverstorm 13y ago[to] verify the integrity of the operating system and prevent unauthorized programs such as bootkits from infecting the device https://en.wikipedia.org/wiki/Windows_8#Secure_boot https://en.wikipedia.org/wiki/Windows_8#Secure_boot
- cookiecaper 13y agoSecure Boot is ostensibly a security feature, making it impossible to load kernel-level code that hasn't been signed by an authority recognized by the device's hardware. The idea is that this makes it harder for nefarious actors to do nefarious things to your system, because they'll be blocked from the most basic access to the system hardware and be forced through normal OS security channels. In practice, of course, it's just about solidifying lock-in with a cover story that's obviously weak to those with technical experience but is justifiable to politicians and regulators who would otherwise be all over MS for facilitating this kind of funny business.
- Zr40 13y agoSecure Boot isn't about lock-in, at least not on PCs. To qualify for the Windows Logo program, it must be possible to disable Secure Boot.
- rbanffy 13y agoAs TFA notes, this may involve repeated resets during boot, added hardware and a whole lot of steps my mother wouldn't take. She'd just be coerced to use Windows.
- Ayabashi 13y agoI find it hard to believe that there are a lot of people who are tech savvy enough to be able to install, partition disks and configure Linux and bootloader on a Windows 7 machine, but are suddenly unable to turn off one setting in the BIOS setup on a Windows 8 machine. And to enable them, we need to make every Windows PC insecure by default and leave hundreds of millions of people vulnerable to undetectable bootkit viruses?
- hackmiester 13y agoThere are lots of Linux distributions (for instance, Ubuntu) that makes all of that very simple. Some of them will even install inside of a Windows partition, or resize it for you.
- Ayabashi 13y agoEven in practice, it stops undetectable bootkits, for example, like this one. http://www.securelist.com/en/analysis/204792235/XPAJ_Reversing_a_Windows_x64_Bootkit http://www.securelist.com/en/analysis/204792235/XPAJ_Reversi...
- wmf 13y agoIt prevents you from using Windows Loader to pirate Windows. (That's a benefit... to Microsoft.)
- mjg59 13y agoNot really, since you can just disable Secure Boot and run a hacked copy of Windows Loader, or enrol the hash of said hacked Windows Loader and boot with Secure Boot enabled.
- dscrd 13y agoThey're absolutely out of their fucking minds if they think this is a good idea. People are already slowly oozing towards better operating systems, and if they actually manage to remove the possibility to run their shitty OS without any cost, they're totally screwed.
- rbanffy 13y ago> That's a benefit... to Microsoft That's debatable. For Microsoft, it's preferable you run a pirated Windows (and, hopefully, a pirated Office) than become part of a non-Microsoft ecosystem. Network effects apply and, as soon as too many people switch to non-Microsoft ecosystems, the value of using Microsoft decreases.
- deleted 13y ago[deleted]
- hackmiester 13y agoThis is not Secure Boot. Secure Boot is only one feature of EFI. You are describing EFI.
- wes-exp 13y agoTheoretically, secure boot could help prevent bootkits (e.g. the "evil maid" attack). Although I have no idea whether this works in practice.
- Filligree 13y agoIt does, if the stars align. The default setup of these computers (no full-disk encryption, easy to disable secure boot) typically means that it offers no such security. Look at Chromebook for an example of apparently doing it right.
- Ayabashi 13y agoThe Chromebook is doing it right? Really? It wipes your hard disk if you enable developer mode(which is a painful process in itself). And then at every single boot you either have to wait thirty seconds to go past a very scary warning or press Ctrl-D. Every single time you boot. If you switch back to ChromeOS, the hard disk is wiped again. I would love to see HN commenters' reactions if on disabling Secure Boot, the Windows 8 partition is wiped along with any documents and files you saved locally and if you wanted Windows 8 back, it wiped your Linux partition in the name of security.
- Filligree 13y agoWhere "doing it right" is defined as making the computer safe against maid attacks? Yes, this is how that looks. I'm not saying it's actually secure; I haven't analyzed it in that kind of detail, and I don't even own one.
- bookwormAT 13y ago"I would love to see HN commenters' reactions if on disabling Secure Boot, the Windows 8 partition is wiped along with any documents and files you saved locally" The equivalent to a Windows 8 partition on ChromeOS is cloud storage like Google Drive, Dropbox or Skydrive. This cloud storage is not being wiped when you switch to or from developer mode. The local storage is just a temporary storage for downloads and caching. Oh, and entering developer mode on my Pixel was as easy as holding 3 keys down at the same time.
- vacri 13y agoIt means you can have a crazy BIOS screen heavy with customised images that looks all 3li7e and stuff for the gamer crowd. My PC has one such thing, and it's garbage. I managed to find out how to put it into some sort of 'information' mode with less graphics and more info... but isn't a BIOS screen supposed to be a wholly info thing anyway?
- dillona 13y agoThat has absolutely nothing to do with Secure Boot. If anything, what you're talking about has more to do with EFI
- Qantourisc 13y agoYou sure there was any ? It's not even secure !