LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 03-20-2015, 05:34 PM   #1
Pearlseattle
Member
 
Registered: Aug 2007
Location: Zurich, Switzerland
Distribution: Gentoo
Posts: 999

Rep: Reputation: 142Reputation: 142
Win2012 wants Secure Boot - damn?


Hi

I just saw here (slide 2 of 4) that Windows 2012 will require a UEFI bios and especially "Secure Boot" to be enabled.

I don't want to write right now the exact details - all I want to mention is that when I read that my first thoughts were "aaahhh, not again that s**t".

What are your thoughts?
 
Old 03-20-2015, 05:43 PM   #2
dugan
LQ Guru
 
Registered: Nov 2003
Location: Canada
Distribution: distro hopper
Posts: 11,235

Rep: Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320
Quote:
I just saw here (slide 2 of 4) that Windows 2012 will require a UEFI bios and especially "Secure Boot" to be enabled.
No, it doesn't. It no longer requires Secure Boot to be optional. OEMs will have the option of allowing Secure Boot to be turned off, whereas before they were required to allow it to be turned off.

My thought? Lame move on the part of MS.

Last edited by dugan; 03-20-2015 at 05:51 PM.
 
Old 03-20-2015, 07:05 PM   #3
Pearlseattle
Member
 
Registered: Aug 2007
Location: Zurich, Switzerland
Distribution: Gentoo
Posts: 999

Original Poster
Rep: Reputation: 142Reputation: 142
Quote:
It no longer requires Secure Boot to be optional.
Mmmhh, so "Secure Boot" will be mandatory?
 
Old 03-20-2015, 07:07 PM   #4
dugan
LQ Guru
 
Registered: Nov 2003
Location: Canada
Distribution: distro hopper
Posts: 11,235

Rep: Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320
Yes.

http://arstechnica.com/information-t...out-a-reality/

Uhm... that's what you said in the first place... AARRRGGH CORPORATE DOUBLESPEAK MY LOGIC CIRCUITS HURT

It will be mandatory to ship with Secure Boot enabled. It will be optional to allow the user to turn it off.

Last edited by dugan; 03-20-2015 at 07:10 PM.
 
Old 03-20-2015, 10:10 PM   #5
smeezekitty
Senior Member
 
Registered: Sep 2009
Location: Washington U.S.
Distribution: M$ Windows / Debian / Ubuntu / DSL / many others
Posts: 2,339

Rep: Reputation: 231Reputation: 231Reputation: 231
Quote:
It will be mandatory to ship with Secure Boot enabled. It will be optional to allow the user to turn it off.
Obviously it has nothing to do with security and everything to do with anti-competitive vendor lock-in. I knew this would happen
even those many didn't believe me.
 
Old 03-20-2015, 10:14 PM   #6
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,331
Blog Entries: 28

Rep: Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144Reputation: 6144
"Secure Boot" translates to "Secure Market Share."
 
Old 03-21-2015, 10:06 AM   #7
dugan
LQ Guru
 
Registered: Nov 2003
Location: Canada
Distribution: distro hopper
Posts: 11,235

Rep: Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320
Quote:
Originally Posted by smeezekitty View Post
Obviously it has nothing to do with security and everything to do with anti-competitive vendor lock-in. I knew this would happen even those many didn't believe me.
Quote:
Originally Posted by frankbell View Post
"Secure Boot" translates to "Secure Market Share."
Quite the refutation of the "companies don't care about the Linux desktop because it has 'only' 2 market share" argument, isn't it.

If Microsoft didn't care, they wouldn't do this.

Last edited by dugan; 03-21-2015 at 10:07 AM.
 
Old 03-21-2015, 10:22 AM   #8
Head_on_a_Stick
Senior Member
 
Registered: Dec 2014
Location: London, England
Distribution: Debian stable (and OpenBSD-current)
Posts: 1,187

Rep: Reputation: 285Reputation: 285Reputation: 285
Secure Boot is designed to prevent pre-boot malware.

It has nothing to do with "locking out" other operating systems -- Ubuntu, Fedora & OpenSUSE will all install a Secure Boot compliant system.

It is even possible to create your own keys, enrol them into the firmware (BIOS) and sign the kernel image & boot loader/manager to acheive a Secure Boot set up that is completely independent of the Microsoft licence.
http://kroah.com/log/blog/2013/09/02...d-linux-kernel
 
Old 03-21-2015, 10:39 AM   #9
273
LQ Addict
 
Registered: Dec 2011
Location: UK
Distribution: Debian Sid AMD64, Raspbian Wheezy, various VMs
Posts: 7,680

Rep: Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373
Quote:
Originally Posted by Head_on_a_Stick View Post
It is even possible to create your own keys, enrol them into the firmware (BIOS) and sign the kernel image & boot loader/manager to acheive a Secure Boot set up that is completely independent of the Microsoft licence.
http://kroah.com/log/blog/2013/09/02...d-linux-kernel
Not when Windows 10 machines are released. Well, to be more precise, it is not guaranteed that it will be possible to create one's own keys on a Windows 10 machine as M$ are removing that requirement for vendors to be able to mark their equipment Windows compatible.
I am sure some vendors will continue to play fair but some may be paid by M$ to lock down secure boot and some may find it cheaper to do so.
So, this isn't "the sky is falling" but it is a slightly worrying move.
 
Old 03-21-2015, 11:15 AM   #10
Hungry ghost
Senior Member
 
Registered: Dec 2004
Posts: 1,222

Rep: Reputation: 667Reputation: 667Reputation: 667Reputation: 667Reputation: 667Reputation: 667
I wonder if secure boot prevents computers to get infected with the Equation Group malware. Something tells me it doesn't
 
Old 03-21-2015, 11:56 AM   #11
TobiSGD
Moderator
 
Registered: Dec 2009
Location: Germany
Distribution: Whatever fits the task best
Posts: 17,148
Blog Entries: 2

Rep: Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886
Quote:
Originally Posted by odiseo77 View Post
I wonder if secure boot prevents computers to get infected with the Equation Group malware. Something tells me it doesn't
It depends on how that malware works. If it makes changes to the bootloader or kernel then it shouldn't work with Secure Boot enabled.
 
Old 03-21-2015, 12:16 PM   #12
Hungry ghost
Senior Member
 
Registered: Dec 2004
Posts: 1,222

Rep: Reputation: 667Reputation: 667Reputation: 667Reputation: 667Reputation: 667Reputation: 667
Well, according to Wikipedia, the Equation Group malware "infects the hard drive firmware, which in turn adds instructions to the disk's master boot record that causes the software to install each time the computer is booted up." So I guess this means secure boot should -- in theory -- prevent the malware from running. In any case, I wouldn't risk my neck for it

Last edited by Hungry ghost; 03-21-2015 at 02:19 PM.
 
Old 03-21-2015, 02:19 PM   #13
linux4everybody
LQ Newbie
 
Registered: Mar 2015
Posts: 5

Rep: Reputation: Disabled
If I bought a system that didn't allow me to disable secure boot, I'll complain to the customer/tech support people and tell them I don't like using windows and I only use linux. If they refuse, I'll just get my refund.

I believe if you plan to use inux only a system from system76 or zareason is best.

Last edited by linux4everybody; 03-21-2015 at 02:22 PM.
 
Old 03-21-2015, 02:24 PM   #14
smeezekitty
Senior Member
 
Registered: Sep 2009
Location: Washington U.S.
Distribution: M$ Windows / Debian / Ubuntu / DSL / many others
Posts: 2,339

Rep: Reputation: 231Reputation: 231Reputation: 231
Quote:
Originally Posted by linux4everybody View Post
If I bought a system that didn't allow me to disable secure boot, I'll complain to the customer/tech support people and tell them I don't like using windows and I only use linux. If they refuse, I'll just get my refund.

I believe if you plan to use inux only a system from system76 or zareason is best.
The problem is that it removes the possibility for non highly computer-savvy people to try alt OSes. Not even a live cd.
 
Old 03-21-2015, 02:28 PM   #15
Head_on_a_Stick
Senior Member
 
Registered: Dec 2014
Location: London, England
Distribution: Debian stable (and OpenBSD-current)
Posts: 1,187

Rep: Reputation: 285Reputation: 285Reputation: 285
Quote:
Originally Posted by smeezekitty View Post
The problem is that it removes the possibility for non highly computer-savvy people to try alt OSes. Not even a live cd.
Apart from Ubuntu, Fedora & OpenSUSE live CDs all of which will boot and install a working system with Secure Boot enabled...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Damn Small, damn annoying with d-link DWA-130 wireless N USB freezerburn666 Linux - Hardware 5 09-09-2008 05:28 PM
Secure while running Damn Small Linux from within XP?? Adamski960 Linux - Security 4 08-02-2008 02:51 PM
Can't get DSL (Damn Small Linux) to boot from CD with or without boot floppy!!! dude_56013 DamnSmallLinux 4 03-08-2008 08:21 AM
Booting Damn Small w/out CD Boot pteri498 Linux - Newbie 1 02-04-2007 07:05 PM
The damn thing won't boot bjojoi Linux - General 1 06-25-2003 01:15 PM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 09:05 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration