Also you can still run EMET on Windows.
Can you elaborate on this or provide some sources?
Maybe. Have they fixed UAC not being security boundary [1] if you are on a default administrator account? It's hard to take them seriously when most software for most users still runs effectively under 'root'.
[1] http://www.pretentiousname.com/misc/win7_uac_whitelist2.html
I feel like I know how to reduce the attack surface a bit more easily on linux client systems. Most OEM Windows installations are pretty bad, so I would want to install Windows myself, sans crapware, and with unneeded built in services, apps and hooks and so on removed. If the bootloader was locked, I'm not sure whether I could reinstall the Windows OS of my choosing. Maybe these products have less crap on them though, since the OS image comes directly from Microsoft.
I didn't mean to refer to situations other than personal clients used by me, and I don't really have an opinion about this in general, except maybe: It depends... :)
We, as users, have no way of verifying what BitLocker does, if it has backdoors, etc.
BitLocker is secure in that it keeps out the attackers. If it keeps out the NSA is a different story (one that is much harder to determine).
So far I have mixed feelings about tablets. I like the "tablet" part but not the "it is cryptographically sercured from doing anything that might upset a government, corporation, or business model" part.
Obviously nobody outside of Microsoft will know if that remains true with the Surface Pro 4.
On non-ARM systems, the platform MUST implement the ability for a physically present user to select between two Secure Boot modes in firmware setup: "Custom" and "Standard". Custom Mode allows for more flexibility as specified in the following:
...
B.If the user ends up deleting the PK then, upon exiting the Custom Mode firmware setup, the system is operating in Setup Mode with SecureBoot turned off.
...
Enable/Disable Secure Boot. On non-ARM systems, it is required to implement the ability to disable Secure Boot via firmware setup. A physically present user must be allowed to disable Secure Boot via firmware setup without possession of PKpriv.
I can't find the doc for W10. Has the language changed? Can you link it?The closest thing I found is https://msdn.microsoft.com/en-us/library/windows/hardware/dn... which isn't really a spec, but does say:
For most PCs, you can disable Secure Boot through the PC’s firmware (BIOS) menus. For logo-certified Windows RT 8.1 and Windows RT PCs, Secure Boot is required to be configured so that it cannot be disabled.
which seems to imply that it is no longer a hard requirement for x86 unlike before."The precise final specs are not available yet, so all this is somewhat subject to change, but right now, Microsoft says that the switch to allow Secure Boot to be turned off is now optional. Hardware can be Designed for Windows 10 and can offer no way to opt out of the Secure Boot lock down." http://arstechnica.com/information-technology/2015/03/window...
it is a painful install process, but that should change completely with ubuntu 15.10