Results 1 to 5 of 5

Thread: More On Microsoft's SecureBoot Scheme303 days old

  1. #1
    The Stealth Mod
    ZemaTalon's Avatar
    Join Date
    Aug 2002
    Location
    Southern California
    Posts
    4,529
    Threads
    785

    Awards Showcase

    Real Name
    Steve
    Blog Entries
    1
    Local Date
    05-22-2013
    Local Time
    08:40 PM

    tablet More On Microsoft's SecureBoot Scheme

    asus-uefi.jpg

    Here's the problem: A Windows 8 PC must be locked down with the UEFI (Unified Extensible Firmware Interface) set with Microsoft's secure boot on. In turn, that means you won't be able to easily install Linux or any other operating system, such as Windows 7 or XP, on a Windows 8 system. Since the vast majority of desktop Linux installations start with a PC running Windows that's going to be a real headache. So, what can you do about it?

    Well, Fedora, Red Hat's community Linux distribution decided to co-operate with Microsoft's key signing service, Verisign. Thus, in the Fedora plan, Fedora will create its own Windows 8 system compatible UEFI secure boot key using Microsoft's own system.

    This made a lot of Linux fans unhappy. Matthew Garrett, a Red Hat developer, explained that “it's cheaper than any realistic alternative would have been. It ensures compatibility with as wide a range of hardware as possible and it avoids Fedora having any special privileges over other Linux distributions.” Linus Torvalds, Linux's founder and guiding light, take: was "I'm certainly not a huge UEFI fan, but at the same time I see why you might want to have signed bootup etc.”

    Canonical, Ubuntu Linux's parent company, came up with its own answer. Canonical's secure boot solution (PDF Link) is to “provide keys and signed boot images for use with secure boot functionality.” In short, Ubuntu will come up with its own independent key that's compatible with the “Windows 8 Hardware Certification Requirements [WIN8HCR]."

    Garrett complained that this is essentially Microsoft's same lock-in scheme “except with an Ubuntu key instead of a Microsoft one.” Mark Shuttleworth, Ubuntu's founder, responded, that he didn't think either plan was ideal, but “Secure Boot retains flaws in its design that will ultimately mandate that Microsoft's key is on every PC (because of core UEFI driver signing). That, and the inability of Secure Boot to support multiple signatures on critical elements means that options are limited but we continue to seek a better result.”
    Wait a moment there. Will the advent of Windows 8 really mean that Microsoft's secure boot lock-in will be on every PC? Cathy Malmrose, CEO of the Linux PC vendor ZaReason doesn't think it should.

    Malmrose told me “With UEFI's Secure Boot around the corner, we are hoping to raise awareness that Linux distributors don't need to sign with Microsoft [or use their secure boot. Computers that are rooted with open bootloader are available. That's what we ship.”

    She knows, “UEFI's Secure Boot is implemented at OEM (originial equipment manufacturer) level, all new PCs purchased (with the intent of loading your favorite distro) will have Secure Boot." This cripples them as far as Malmrose is concerned.

    “Yes, you can disable it. But 'disabling' something that's 'secure' makes you bad.” Besides as Malmose told me, “the keystroke(s) needed to get Linux to run on machines post-2012 will be simple at first, becoming increasingly complex at a non-shocking rate. It's a monumental shift at OEM level.” Malmrose fears that this will desktop Linux “too difficult to new users, [and this will cause] slow death by suffocation” for Linux.

    So what can Linux users do instead? Malmrose thinks we can avoid a "Greek Tragedy “ by recognizing that Linux needs hardware vendors, like ZaReason, “who can keep things open, [who keep our collective foot in the door at the factories.” Malmrose insists that it isn't about her particular company. “There is 0 profit.* If we ever did have profit, we would donate to support the EFF, FSF, Software Freedom Conservancy, LinuxFests, GNOME Foundation, various conferences, the works. Hopefully someday there will be but most months it's a stretch to make payroll.”
    From ZDNet.

  2. #2
    The Stealth Mod
    ZemaTalon's Avatar
    Join Date
    Aug 2002
    Location
    Southern California
    Posts
    4,529
    Threads
    785

    Awards Showcase

    Real Name
    Steve
    Blog Entries
    1
    Local Date
    05-22-2013
    Local Time
    08:40 PM

    I was listening to a discussion about this on the Mintcast, and they talked about the absurdity of calling it a "security feature" - from a company world renowned for being unsecure

  3. #3
    Posting Deity Bad Haircut's Avatar
    Join Date
    Nov 2009
    Location
    Deak Pistrict UK
    Posts
    2,924
    Threads
    227
    Real Name
    'kin neigh
    Local Date
    05-23-2013
    Local Time
    04:40 AM
    Chakra atm you set up your HDD for GPT and have 8mb unformatted space at start of partition table to boot with UEFI.

  4. #4
    Hell's Very Own Grogan's Avatar
    Join Date
    Sep 2002
    Location
    Ontario, Canada
    Posts
    23,099
    Threads
    2409

    Awards Showcase

    Real Name
    Hugh Jorgen
    Local Date
    05-22-2013
    Local Time
    11:40 PM
    The solution is to just not buy any hardware with that lock-in. Don't buy a Windows 8 ARM device... period. Anyone who does, is a mindless receiver of a chocolate coated kielbasa.

    No, Ubuntu's solution is not acceptable. I'll fight that.

  5. #5
    Bikini Peeker MSUredux's Avatar
    Join Date
    May 2007
    Location
    Jeannette, PA
    Posts
    3,935
    Threads
    144

    Awards Showcase

    Real Name
    Mark
    Local Date
    05-22-2013
    Local Time
    11:40 PM
    The only "security" that crap provides is security for Microsoft. Just another way to try and squeeze out any competition.
    My life is slipping away
    I'm aging every day
    But even when I'm grey
    I'll still be grey my way

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •