Microsoft patched Windows RT, blocks dev Linux boot
theregister.co.uk
theregister.co.uk
As for physical access, somebody could install a new HDD or motherboard or computer - where do you stop?
Microsoft's justification of this "security feature" is borderline insanity.
They've been trying to do this with Windows-proper for the last 5 years, banking on the apathy of manufacturers to block other operating systems from running by not allowing other secure keys (or disabling the disabling of secure boot).
This is just the extension of that, except they control the hardware too.
Given open Linux distributions have a habit of making devices Just Work™ indefinitely —well that's what my 2008 desktop CPU, 2010 laptop tell me— I'm not surprised they want to make sure their hardware rots so people have to upgrade to a newer, stronger-walled garden.
2006 Conroe is still perfectly capable of running the latest Windows OS. And anecdotally I had to rescue an Ubuntu installation few days ago simply because the root partition got filled and system didn't boot. Go figure.
If a company is selling hardware, why should it matter what the purchaser does with it afterwards?
For the answer to that question, we might ask Apple.
Whatever the answer is, it is certainly not "for the security of the user" if the user explicitly wants to install their own choice of OS.
> An attacker who successfully exploited this vulnerability could disable code integrity checks, allowing test-signed executables and drivers to be loaded on a target device. In addition, an attacker could bypass the Secure Boot Integrity Validation for BitLocker and the Device Encryption security features.
Microsoft is patching the device, despite it being a dead product, to avoid screwing actual users of the product. Sorry to the ones of people using it with Linux, I guess, but being able to subvert BitLocker and device encryption is kind of bad, yeah?
Besides, AFAIK if a drive is encrypted then you would not be able to decrypt it without the correct key, unless they did something very un-crypto-like with BitLocker...
You're correct. So an attacker will now attempt obtaining the correct key, by targeting the pre-decryption stages and infecting any layer that has access to the decryption key. If the bootloader's the one that asks for the user for the disk decryption key, then the bootloader would be the prime target of infection. And so on, it's turtles all the way down, until the hardware; which is what gives Intel the excuse to ship locked down firmware with their processors and motherboards.
I'd say they weren't as anti-consumer back then as they are now. In particular, backwards compatibility was highly valued and I don't remember much in the way of forced "upgrades" or aggressive feature-removals/UI changes in the late 90s/early 2000s.
After all, what is a Surface RT except a large screen phone that doesn't make phone calls.
after all, it was only an old platform that only sold a few million units.
Surface RT tablets were sold as locked down devices from the start, just like many other tablets on the market today. You can't really apply EEE if the 'Embrace' part is missing.
> An attacker who successfully exploited this vulnerability could disable code integrity checks, allowing test-signed executables and drivers to be loaded on a target device. In addition, an attacker could bypass the Secure Boot Integrity Validation for BitLocker and the Device Encryption security features.
So if Microsoft didn't patch this, you could equally accuse them of leaving bad security flaws in Windows 8.1.
Damned if they do...
Users also had the choice to buy something different - like any of the other ARM tablets with broadly similar hardware specs that already run linux.
Especially within a hacker culture that has seen their right to hack their hardware as self-evident.
Now, locking the Windows RT bootloader was a bad practice to begin with, and it's a good thing Microsoft stopped doing that. Then again, it's hard to blame them, seeing that Apple keeps locking down everything they can lay their hands on with virtually no criticism outside the Slashdot crowd perhaps. Everyone just keeps nodding and saying "This is the right thing for protecting their users and ecosystem. Look at all the fragmentation and malware mess that Android suffers from".
And what is with that "Embrace, Extend and Extinguish"? It's 2016. Next thing, IBM will come selling their Watson SaaS and everyone would have to buy it because "nobody ever got fired for buying IBM "?
now, let me channel dang for a second here:
HN looks down on these types of posts filled with logical fallacy (ad hominem, appeal to ridicule, moving goalposts). You would have made your point with the first two sentences alone.
Also blocking the install of Linux...iPads and iPhones. Why is this a crisis but that's OK?
Why did you but this thing?
Given MS' security model* described in this thread ("vulnerable to attackers with administrative access") I wonder if RT tablets and similar hardware are actually still sold. Wouldn't it - from the company's POV - be easier to just sell a license?
*(MS is by far not the only one acting like this, but they somehow seem to draw the most attention when locking down things)