Windows 10 to make the Secure Boot alt-OS lock out a reality
arstechnica.com
arstechnica.com
You need Windows 2018? You'll have to buy a new computer...
Honestly I'm only very slightly unhappy about that. Unlike with the IBM-compatible PC, a historically open platform, this isn't closing off a historically open platforms. The other entries in the space, like Apple's iPad, are historically very closed. And the Windows platform doesn't have anywhere near the dominance in ARM that it does on x86.
Secure Boot is about protecting the kernel from modification (e.g. root kits, activation cracks, and so on). It may help protect data also when combined with full disk encryption (it will make tricking you into entering your decryption key(s) into a fake/altered OS harder).
It is a classic defence in depth system. I actually have nothing against Secure Boot, I just think it is too Microsoft controlled and getting a signing key too difficult (and for Microsoft to block competition too easy).
Yeah, I'd been thinking that if you were stuck with what was already installed, a thief wouldn't be able to get rid of any lojak / phone-home-and-brick-yourself monitors. But you're right, secure boot by itself wouldn't provide quite that level of lockdown.
:(
First, the slide shown in this article says "allow end user to turn off". It says nothing about "allow end user to add his own keys". If the end user can add his own keys, the end user can still bypass this mechanism; it's just a bit more complex and annoying.
Second, even if the firmware doesn't allow the user to add his own keys, there are bootloaders like SUSE's shim which are signed by Microsoft and allow the user to add his own keys for the next step (see https://www.suse.com/documentation/sles11/book_sle_admin/dat... for instance).
Of course, I wonder how long until shim doesn't work anymore (either by having its signature revoked or by Microsoft migrating to a new root key and not signing shim with it). Who knows, these Windows 10 requirements might already be using a new root key, instead of the one the shim bootloaders were signed with.
If end-users cannot disable secure boot (or add his own keys), they won't be affected at first, since the most popular Linux distributions have a signed bootloader. But when in secure mode, you can't boot your own self-compiled kernel, and often you can't even load unsigned drivers. This makes it harder to debug kernel issues (since you can't compile and install a modified kernel), and makes it hard to develop drivers for new hardware.
Keeping everything the way it is is great for them. It's a PITA for non-tech users to install the certificate to try out linux/any other OS, which means less users leaving windows. No need to push it and rish monopoly-related issues, etc.
I will say the whole way Secure Boot was done (essentially only having a single signing authority: Microsoft) was highly flawed from the get go. There was some talk about allowing the free software foundation to sign keys, what happened to that?