VaultNetwork.netVault Network Boards
Author Topic: UEFI secure booting and why Windows 8 systems might not be able to boot Linux [Locked]
Aerlinthian  4 stars
Posts: 2,126
Registered: 2001-5-7 23:53:38
Interesting stuff that I guess I will have to keep an eye out for since I dual boot and am generally concerned about any artificial limitations put upon things I purchase. I did a tiny bit of research, Matthew Garrett is a Linux kernel developer according to ITWire that picked this story up.


mjg59@dreamwidth.org posted:

Sep. 20th, 2011 02:01 pm
Since there are probably going to be some questions about this in the near future:

The UEFI secure boot protocol is part of recent UEFI specification releases. It permits one or more signing keys to be installed into a system firmware. Once enabled, secure boot prevents executables or drivers from being loaded unless they're signed by one of these keys. Another set of keys (Pkek) permits communication between an OS and the firmware. An OS with a Pkek matching that installed in the firmware may add additional keys to the whitelist. Alternatively, it may add keys to a blacklist. Binaries signed with a blacklisted key will not load.

There is no centralised signing authority for these UEFI keys. If a vendor key is installed on a machine, the only way to get code signed with that key is to get the vendor to perform the signing. A machine may have several keys installed, but if you are unable to get any of them to sign your binary then it won't be installable.

This impacts both software and hardware vendors. An OS vendor cannot boot their software on a system unless it's signed with a key that's included in the system firmware. A hardware vendor cannot run their hardware inside the EFI environment unless their drivers are signed with a key that's included in the system firmware. If you install a new graphics card that either has unsigned drivers, or drivers that are signed with a key that's not in your system firmware, you'll get no graphics support in the firmware.

Report continues and includes forum commentary.
The_Korrigan  3 stars
Title: Scrub Buster
Posts: 955
Registered: 2001-7-17 03:51:32
Still doesn't stop me from putting a Linux install inside a Virtual VMWare machine so... *shrug*

 

-----signature-----
SWTOR: 50 Jedi Shadow (Tank), 50 Sith Marauder (Annihilation).
LOTRO: Lifetime account, playing very casually.
WoW: Both accounts canceled for now.
GW2: Future Warrior.
Speak-pkhq  1 star
Title: Sheep's bane
Posts: 113
Registered: 2002-7-7 21:32:14
"once enabled ..."

guess we all know what we won't be enabling

 

-----signature-----
Wailing HoHoHoMerryXmas Hero, daoc Kay
Bardog Mage, wow Thunderlord <Schizm>
http://7-zip.org/
trollop hunter
Locuus  1 star
Posts: 124
Registered: 2003-3-13 22:55:35
Won't there be user toggle in the BIOS where one could disable this security if it is unwanted?

 

-----signature-----
Men do not differ much about what things they will call evils; they differ enormously about what evils they will call excusable. ~ G. K. Chesterton
Karsus_the_Great  1 star
Title: This is a title.
Posts: 76
Registered: 2003-4-12 21:33:04
I have a feeling that windows 8 will be the next ME...

I am pretty sure that Windows 7 will be/is the next long haul OS for microsuck now that XP is slowly fading.

At this point, my laptop and all externals have FDE. After my last run through the airport security I am both really glad I do that, and have been debating doing this on my home computer as well.. It's really getting ridiculous.. Did you read the on star post and all the other crap like it?

 

-----signature-----
I know I'm going to hell, I'll bring marshmallows.
Caldari. The only race in Eve that does not fly it's own ships.
Karsus the Great - lvl 240+ Original BM(retired)

VaultNetwork.net is an independently operated community forum and is not affiliated with, endorsed by, or technically based on IGN, GameSpy, FilePlanet, GameStats, or the former IGN/GameSpy Vault Network.
References to VaultNetwork.net mean this site/domain. VNBoards-style presentation is a visual homage only. By using this site, you agree to the forum rules.