1. Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Windows 8 Secure Boot: Handy Malware Backdoor for Nosy Governments?

Discussion in 'News' started by qubit, Oct 29, 2011.

  1. newtekie1

    newtekie1 Semi-Retired Folder

    Joined:
    Nov 22, 2005
    Messages:
    21,002 (6.05/day)
    Thanks Received:
    6,989
    I like how every article that Qubit has posted about Secure Boot has had a negative tone to it, and he constantly calls it "Windows 8 secure boot feature". It isn't even a feature of Windows 8, it isn't like Microsoft just say "implement this" and it gets done. Microsoft is pushing for the technology to become mandatory, but it is up to the Unified EFI Forum to decide if it becomes mandatory as part of UEFI, not Windows 8. It is UEFI's Secure Boot feature, not Windows 8's.

    Also, even if it is implemented, it isn't up to Microsoft to decide what OS gets allowed on the machine. The option to disable the feature entirely is supposed to be included. However, the OEM manufacturer of the computer has the option to omit this option if they choose, but Microsoft has no real say in the matter. I can see where this might happen, because OEMs hate supporting hardware that isn't running the original OS.
     
    CyberDruid and Easy Rhino say thanks.
    Crunching for Team TPU More than 25k PPD
  2. Easy Rhino

    Easy Rhino Linux Advocate

    Joined:
    Nov 13, 2006
    Messages:
    13,749 (4.42/day)
    Thanks Received:
    3,571
    also, bringing up vPro is purely silliness. vPro is excellent for businesses that want to leverage agility over a large workforce. where i work, we have very similiar software that makes it much easier on the tech support guys to fix issues and control desktops. vpro is simply a creation of the marketplace, not some tin foil douche bags. of course, anyone who actually worked in the industry would know that.
     
  3. Fx

    Fx

    Joined:
    Oct 31, 2008
    Messages:
    530 (0.22/day)
    Thanks Received:
    100
    Location:
    Portland, OR
    well, concerning sinister governments- it appears that the vast majority of people would still prefer to cover their eyes and ears than question evidence to find truth. it doesnt take much research through readily available un-edited video to see that things arent as rosy as you would like to believe... to each their own

    back to the topic...

    I hope secure boot doesnt gain traction because it never turns out as well for consumers when companies impose restraints to the products that we use. for example: open source development has spread like wild-fire in recent years and has become a boon to innovation as we continue to collaborate- not limit ourselves...
     
    qubit says thanks.
  4. Liquid Cool

    Liquid Cool

    Joined:
    Mar 2, 2011
    Messages:
    466 (0.30/day)
    Thanks Received:
    283
    Location:
    Omaha, NE
    Ubuntu doesn't have this problem?

    :)

    I just love to say the word - Free.

    I don't know if I'm a 40 year old hippie, but I'm just loving 'stickin' it to the man' as of late.

    Screw Mafiasoft. I can play my Crysis2 in Steam under Ubuntu and I'm happy with it. The last tie to this company is now severed.

    Free-dom. Try some...

    Best Regards,

    Liquid Cool
     
  5. Frick

    Frick Fishfaced Nincompoop

    Joined:
    Feb 27, 2006
    Messages:
    11,255 (3.34/day)
    Thanks Received:
    2,697
    It's fine for some people but the majority of people will not be on Linux for some time.
     
  6. qubit

    qubit Overclocked quantum bit

    Joined:
    Dec 6, 2007
    Messages:
    10,655 (3.91/day)
    Thanks Received:
    4,067
    Location:
    Quantum well (UK)
    Of course it's a "Windows 8 secure boot feature" - Microsoft is the driving force behind getting it implemented in UEFI - you've just said it yourself. And do you really think that the UEFI Forum are gonna turn this down? That would be extremely naive to think so. Remember who's got the dollars here...

    And OEMs not supporting an off switch for it is mighty handy for Microsoft isn't it? They get that lock-in they so desire and can then claim it wasn't them. This really doesn't take much to see through the smokescreen.

    So yeah, you're damn right I'm negative about this technology and I'm going to keep writing news articles about it. Remember, governments and big corporations like nothing better than to restrict and control the population for their own gain and profits. The one thing they want is for developments like this to remain in the dark until it's all ready to go and too late to do anything about it. Therefore, the only way to beat it, or at least hold it back some, is to bring it out into the light and shout about it, so that everyone knows what's going on and the force of public pressure prevents it from happening. It doesn't always work unfortunately, but it's better than just sitting idle and taking whatever crap they spoonfeed you. In all aspects of life, public outcry/pressure does hold restrictive practices back and we'd have a much more autocratic and repressed world without it.

    As Thomas Jefferson himself said, "The condition upon which God hath given liberty to man is eternal vigilance". So true, one must never forget it.
     
    Last edited: Oct 30, 2011
  7. CyberDruid

    CyberDruid New Member

    Joined:
    Sep 23, 2007
    Messages:
    2,888 (1.03/day)
    Thanks Received:
    1,100
    Location:
    On top of a mountain
    There. I fixed it.:cry:
     
    Frick and newtekie1 say thanks.
  8. qubit

    qubit Overclocked quantum bit

    Joined:
    Dec 6, 2007
    Messages:
    10,655 (3.91/day)
    Thanks Received:
    4,067
    Location:
    Quantum well (UK)
    You made an error. That's ok, there's no need for you to cry about it. :laugh:
     
  9. newtekie1

    newtekie1 Semi-Retired Folder

    Joined:
    Nov 22, 2005
    Messages:
    21,002 (6.05/day)
    Thanks Received:
    6,989
    No, I said they are pushing for it. The industry is the main driving force behind it, to help close some of the security concerns caused by UEFI's network features. Secure boot was being talked about in the industry a long time before Microsoft picked it up and started pushing for it. Intel and IBM have been the big driving force behind secure boot up until recently when Microsoft stepped in too.

    Well when you consist of big players like Intel, AMD, Apple, HP, Dell, IBM, Lenovo... Yeah, Microsoft's money doesn't mean shit to them. I guess if you really remember who's got the dollars it is actually Apple, they are the biggest company currently sitting on the board of directors with the UEFI Forum...

    Also, the money argument doesn't really make sense when you are basically giving the power to shape the Industry at this point. UEFI is essential at this point moving forward in the industry. PCs are going to have to have UEFI, so Microsoft to say they want it all they want, the UEFI Forum has the power to do whatever they want, and we all just have to sit back and take it.

    Do I think they will turn this down? No, I never said they would. They would be stupid to as it addresses security holes that industry leaders have been complaining about in UEFI for a while now. But they aren't just going to pass it because Microsoft says so.

    Take the tin-foil hat off. I'm guessing your conspiracy doesn't really hold water once you realize the people making the decisions are bigger players than Microsoft. When is the last time you saw Apple just step down and accept what Microsoft wants?:rolleyes:

    See the problem seems to be that you haven't done proper research, because I'm guessing if you had you would have realized that the UEFI Forum is loaded with huge players in the industry, and not some small little broke individuals that will bend to Microsoft's will. You also would have realized that IBM and Intel were the big promoter of Secure Boot, not Microsoft.

    That is fine, but news, presented by a proper news reporter, should be presented without bias. And the reporter should be doing proper research before posting news articles, especially if they are going to be adding their own information to the article, they better make sure the information is actually correct. Calling Secure Boot a Microsoft invention is complete wrong information, and you should be ashamed for even suggesting it in a serious news article. If you are going to report on it, present the correct facts, not just BS that you pulled out of you ass because you think Microsoft is evil and want to bash them.
     
    Last edited: Oct 30, 2011
    TRWOV, qubit and Frick say thanks.
    Crunching for Team TPU More than 25k PPD
  10. Marv

    Marv New Member

    Joined:
    Jan 27, 2011
    Messages:
    36 (0.02/day)
    Thanks Received:
    4
    Location:
    Maidstone, UK
    I have to say I'm starting to lose faith in TPU with these articles. I have come here for ~3 years for unbiased reviews and news, often with a bit of cynicism thrown in to stay the tide of marketing dribble. Wizzard and btanrar both produce some of the best articles (news related) around, and this is dragging it down.

    I'd have to ask qubit, have you written articles for the Daily Mail? The tone very much feels like it, and the articles are far too opinionated to belong as news articles.

    Many reasoned arguments have already been posted combating this, but as you love the "big bad company" image so much you ignore those comments.

    Besides which, if someone is buying a bog-standard Windows 8 PC from Dell/HP et al, do you really think they're going to want to run Linux? Plus, I somehow doubt that the OS will be effectively locked to the hardware, as it does prevent Microsoft's upgrade path to an extent (have to buy a whole new PC for Windows 9, rather than upgrade).

    Also:
    I thought Apple have beaten them to that already?
     
  11. qubit

    qubit Overclocked quantum bit

    Joined:
    Dec 6, 2007
    Messages:
    10,655 (3.91/day)
    Thanks Received:
    4,067
    Location:
    Quantum well (UK)
    So, I bring news with some healthy commentary on the weekend for you to read and you complain that you're "losing faith"? :rolleyes:

    Let's see you contribute something useful to TPU instead of whinging in my news threads. :slap:
     
  12. Wile E

    Wile E Power User

    Joined:
    Oct 1, 2006
    Messages:
    24,324 (7.71/day)
    Thanks Received:
    3,778
    Ummm, any OS can use the feature. It's part of UEFI. Anything capable of using UEFI is capable of using this. How is this locking it to anything?

    MS backing the technology does not automatically make this a conspiracy.

    Yet again, mountain out of a molehill.
     
  13. newtekie1

    newtekie1 Semi-Retired Folder

    Joined:
    Nov 22, 2005
    Messages:
    21,002 (6.05/day)
    Thanks Received:
    6,989
    ftfy

    Microsoft didn't even come up with the technology. Intel and IBM pioneered it.

    So far, the only thing MS has really done is require that any PC sold with a Designed for Windows 8 Logo have the Secure Boot feature in the UEFI enabled by default, but they don't say it can't be disabled by the end user, that part will be up to the OEMs.
     
    Crunching for Team TPU More than 25k PPD
  14. Wile E

    Wile E Power User

    Joined:
    Oct 1, 2006
    Messages:
    24,324 (7.71/day)
    Thanks Received:
    3,778
    Good point. Editing it to backing.
     
  15. qubit

    qubit Overclocked quantum bit

    Joined:
    Dec 6, 2007
    Messages:
    10,655 (3.91/day)
    Thanks Received:
    4,067
    Location:
    Quantum well (UK)
    A grubby personal attack? That's a bit low coming from you, no? :slap:

    And what's with you idiotically messing up my quotes? :rolleyes:

    Life getting a little hard, perhaps? ;)

    ---------------

    How about a little less of the personal attacks people, ffs. :rolleyes:
     
  16. Wile E

    Wile E Power User

    Joined:
    Oct 1, 2006
    Messages:
    24,324 (7.71/day)
    Thanks Received:
    3,778
    Disagreeing with you is not a personal attack.
     
  17. qubit

    qubit Overclocked quantum bit

    Joined:
    Dec 6, 2007
    Messages:
    10,655 (3.91/day)
    Thanks Received:
    4,067
    Location:
    Quantum well (UK)
    There's disagreeing and there's disagreeing. Agreeing with someone who is making a personal attack on me, is also making a personal attack.

    Give me some coherent arguments why you think I'm wrong and you're right and I'll debate it with you.
     
  18. Kreij

    Kreij Senior Monkey Moderator Staff Member

    Joined:
    Feb 6, 2007
    Messages:
    13,881 (4.58/day)
    Thanks Received:
    5,623
    Location:
    Cheeseland (Wisconsin, USA)
    Keep it civil people.
     
    qubit says thanks.
  19. Wile E

    Wile E Power User

    Joined:
    Oct 1, 2006
    Messages:
    24,324 (7.71/day)
    Thanks Received:
    3,778
    I did.

    Recap:

    secure boot = UEFI feature

    Available for use by ANY OS.

    MS being involved =|= automatic conspiracy.

    Then capped off with my opinion on the matter:

    Mountain out of a molehill.

    That is not an attack.

    Neither is agreeing with some points another member made, even if they were attacking you. I agreed with the points, which are still valid. I didn't respond or add to any personal attacks.
     
  20. qubit

    qubit Overclocked quantum bit

    Joined:
    Dec 6, 2007
    Messages:
    10,655 (3.91/day)
    Thanks Received:
    4,067
    Location:
    Quantum well (UK)
    Yeah, so you did. :toast:

    Yes, it might have been set up by the UEFI Forum, but that doesn't mean it won't get abused to shut out the competition, especially considering the big names that are on it (thanks NT :)). Saying anyone can use it sounds fine in practice, but you know how these things are structured: there will be a big fat payment to make to obtain a signature, shutting out smaller players.

    I'm wondering, how will this affect even basic tasks like disc partitioning, adding removing discs etc? I suspect that it will make no difference, but I don't know.
     
  21. Easy Rhino

    Easy Rhino Linux Advocate

    Joined:
    Nov 13, 2006
    Messages:
    13,749 (4.42/day)
    Thanks Received:
    3,571
    see, you say that you don't know, yet in your "news" article you throw out a bunch of ideas that are in your head about the whole topic that lack any factual backing.

    if you don't know about a topic then you shouldn't interject your opinions into a news article or draw conspiratorial conclusions about the issue.
     
  22. Wile E

    Wile E Power User

    Joined:
    Oct 1, 2006
    Messages:
    24,324 (7.71/day)
    Thanks Received:
    3,778
    There are no licensing fees mentioned anywhere in the UEFI Forum's website and documentation that I can see. Just guidelines to follow to be able to use the UEFI logo and claim compliance. It's a non-profit.
     
  23. qubit

    qubit Overclocked quantum bit

    Joined:
    Dec 6, 2007
    Messages:
    10,655 (3.91/day)
    Thanks Received:
    4,067
    Location:
    Quantum well (UK)
    I don't lack factual backing, I based my story on what professor Anderson said.

    The fact that I don't know about how it will affect disc partitioning doesn't invalidate everything else I've said, either. I have no idea how you reached that conclusion. :confused:

    Well, they need money from somewhere to stay afloat, so we'll see what happens when it goes live. Perhaps the various companies that form this entity will just pay, but it seems reasonable to me that they would charge companies that use its services, one way or another.

    Think about it this way: the initiative claims to be about increasing security, right? Therefore, they need some kind of vetting process to check each application to make sure it's not malware or something else unsavoury. That costs money to do.

    Finally, back to the core point of Anderson's blog, that of dodgy governments. We've already seen how the SSL certificate authorities have been corrupted in certain countries (sorry, I don't have a handy link to any article at the moment) to mint a genuine cert for bad websites at the behest of those governments. So, what's to stop those same governments from leaning on the UEFI Forum and getting their dodgy snooping programs on people's computers?
     
  24. Easy Rhino

    Easy Rhino Linux Advocate

    Joined:
    Nov 13, 2006
    Messages:
    13,749 (4.42/day)
    Thanks Received:
    3,571
    qubit, you draw the conclusion, based on one guys worst case scenerio opinion, that microsoft is evil and uefi is going to take down entire nations. stick to the news, and stop with the opinions.
     
    TRWOV, Marv, newtekie1 and 2 others say thanks.
  25. newtekie1

    newtekie1 Semi-Retired Folder

    Joined:
    Nov 22, 2005
    Messages:
    21,002 (6.05/day)
    Thanks Received:
    6,989
    No, you see when an article has accurate non-bias information it is a news article. When an article has wrong information and is filled with bias and opinion from the reporter it is an editorial. Look up the definitions. What you wrote is an editorial not a news piece. If it has your opinion in it, which this does, it is an editorial. This isn't a personal attack, just the facts. But adding your own opinion to the article you made it an editorial. I'm sorry you can't take correction of your mis-information without viewing it as a personal attack.

    Correct, but the only people that can possibly abuse it would be hardware OEMs, but not including the option to disable Secure Boot in their UEFI setup, not Microsoft, and the hardware OEMs abusing it will not be to lock out competition. Microsoft has no say in it.

    Sure you did. You put opinions in the article based on the assumption that it was Microsoft the created and pushed this technology. You obviously had no clue that in fact it was huge industry leaders that developed it and are pushing for it long before Microsoft came into the picture.

    You also assumed that Microsoft was just throwing around their wallet to get their way, again not knowing the fact that the UEFI Forum is comprised of companies as big or bigger than Microsoft.


    I'm pretty sure the multi-billion dollar companies that make up the UEFI Forum can handle it being a non-profit and front the little bit of money it takes to maintain the standard.

    A relatively small amount for the Multi-Billion dollar companies that run it.
     
    qubit says thanks.
    Crunching for Team TPU More than 25k PPD

Currently Active Users Viewing This Thread: 1 (0 members and 1 guest)

Share This Page