The implications of UEFI "Secure Boot" for Linux users
blog.canonical.com
blog.canonical.com
http://blogs.msdn.com/b/b8/archive/2011/09/22/protecting-the...
If you look at the diagram, it appears that Remote Attestation is being brought back. For those of you who weren't around, or weren't paying attention, during the first Trusted Computing War, that means something like the following:
- You try to log on to your bank's website - Your bank queries your TPM - Your TPM sends back a signed hash attesting that you're running an unmodified version of Windows 8 - The bank lets you on
Versus:
- You try to log on to your bank's website - Your bank queries your TPM - Your TPM sends back a signed hash attesting that you're running an unmodified version of RedHat Linux - The bank denies your login for violating the security policy - There is NOTHING you can do about it, short of taking an electron microscope to your TPM to extract the keys.
Of course, none of this is possible as long as there are a nontrivial number of people whose machines aren't capable of Remote Attestation. But it's likely that every machine you've bought in the last 5 years has a TPM with this capability, which means that as soon as Windows 8 and UEFI Secure Boot have critical mass, Remote Attestation will have critical mass too. And then it will start showing up in security requirements for banks and other secure applications. And then the Linux users will start to feel the heat...
Of course, even though the general scheme might be sound, there might still be a lot of possible attacks. I'm not saying it's unbreakable.
It's also amusing the Microsoft is so concerned with malware operating underneath the OS when most nuisance malware on Windows simply uses the features that are readily available within Windows itself.
That's what it does after it gets installed. It got installed by attacking Windows itself.
The same attack is technically possible in OS X and Linux but not in iOS or WP7. Go figure.
>I think parent was wondering whether Microsoft should be more concerned with why their system allowed the rootkit to install itself in the first place
Short of iOS style lockdown, how do they do that? Even OS X and Linux can be rootkitted.
Nothing recent about it; boot sector viruses have been around way longer than Windows. I remember getting one on my 386DX from a floppy I'd used to grab a shareware version of Commander Keen from our local public library. Pain in the ass to clean up.
Boot viruses were to major form of viruses back then, there was a fun one that reversed your mouse's y-axis after a while. There weren't many destructive ones though.
http://forums.mydigitallife.info/threads/24901-Windows-Loade...
If you run their installer and the first step is "reboot, press F12 (or F2, or DEL, or who knows what else) to enter the BIOS and turn off this security setting - that you have to find on your own - then reboot and run the installer again" instead of "click the Install button" that's a big step backwards. Not to mention the fear some users will have about turning of security, wondering if they're being had.
- Why would I care? I don't know anything about what's under the hood and I don't want to.
- Apple puts DRM on for the user's safety.
- The days when every software users was if not programmer then at least IT guy in some sense are long gone. That model no longer fits the world.
Take the Sony Playstation or their rootkits for example...
Or who need help to tell their BIOS to boot from USB before HD.
We can already see how willing handset makers are to pay them for Android related cross-licensing. That's extending into the realm of ChromeOS now too.
I hope the days of installing an alternate OS on garden variety hardware are not numbered, because I suspect the economic leverage Microsoft has vs. the economic incentive for OEMs to ship open hardware isn't enough. Hopefully, I'm totally wrong.
http://www.askforit.com/3993/all-computer-manufacturers-that...
Or even an open spec x64 motherboard with EFI that I can slam an x64 chip into.
There have been a lot of attempts in the past, but has anyone gotten anywhere?
I'm an open source person and I care for EFI :)
It looks like some Free Software people (along with the coreboot) guy don't care for EFI, due to IP issues.
However, Free Software hardware (and peripheries like coreboot) efforts rarely seem to gain the kind of sizable acceptance required for these kinds of endeavors.
It looks like the coreboot guy, Stefan, works for Google. So that may be a possible "in" (for example, future Chromebooks).