4 ms·
Additionally, as point (18) on the page you linked to states: Mandatory. Enable/Disable Secure Boot. On non-ARM systems, it is required to implement
by morpher 13y ago
Additionally, as point (18) on the page you linked to states:
Mandatory. Enable/Disable Secure Boot.
On non-ARM systems, it is required to implement the
ability to disable Secure Boot via firmware setup. A
physically present user must be allowed to disable
Secure Boot via firmware setup without possession of
PKpriv.
Doesn't this mean that (definitely on certified non-ARM systems, and possibly on some ARM systems) you can just enter the UEFI, disable secure boot, and boot your OS of choice?
- comex 13y agoAs the article (clearly) says, since USB is not set up fast enough to recognize a keyboard before the bootloader has handed control to the OS, there's no way to interrupt boot to do so; Windows will let you reboot to another OS, but only after you click through a license agreement.
- Zr40 13y agoSurely a physically present user (mentioned by the requirement of point 18) can disconnect the boot device in order to prevent Windows from booting. The firmware then has ample time to set up USB and allow the user to enter firmware setup. Alternatively, as a workaround, find someone who has already accepted said agreement elsewhere and have them accept it on your device, disable secure boot and wipe the boot device.
- asdfs 13y agoNot if the default is to boot from an SSD soldered onto the mainboard, or tucked away in a device that is not designed to be opened.
- rbanffy 13y ago> a physically present user (mentioned by the requirement of point 18) can disconnect the boot device in order to prevent Windows from booting. I believe that would void most warranties.
- mhurron 13y agoIn the case of a general purpose computer, I'm willing to bet you'd be wrong. We're not talking about a Surface tablet here.
- mjg59 13y agoHave you looked at an Ultrabook? Getting at the hard drive involves disassembling the entire machine, something that's almost impossible to do without either specialised tools or a willingness to inflict some amount of cosmetic damage.
- mhurron 13y agoHonestly, no I didn't think about that, but I would say that you might be starting to leave the realm of general there.
- mjg59 13y agoYes, as long as you can get into the firmware menu in the first place. Which, on some hardware, requires you to agree to the Windows EULA.
- krichman 13y agoThis is idiotic. The requirement should be that the user can disable it entirely OR replace the private key. And it should require implementation of an optional password protection.
- Zr40 13y ago> and possibly on some ARM systems Disabling Secure Boot is forbidden on ARM systems. Point 18 ends with: Disabling Secure Boot must not be possible on ARM systems.