Skip to content
Firmware  Security

Firmware Security

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

  • Home
  • Disclaimers
  • Sponsored by PreOS Security

Tag: Windows OEMs

Microsoft increases use of Secure Boot as marketing tool

June 7, 2015 ~ hucktech ~ Leave a comment

Earlier this week, Sam Varghese wrote an article in iTWire about Windows 10 and UEFI. According to the article, Window 10 will not enable Secure Boot unless the system has a Windows 8-compliant logo. It appears from the article Microsoft is hesitant to answer further questions from the author.

“System BIOS detected a non-Windows 8 logo graphic card. There is no Graphic Output Protocol support detected in this card. Windows 8 feature settings in BIOS will be changed to disabled.”

This will likely not impact users of new systems, as OEMs will ensure their logos are complaint and pominently displayed.

This appears to imply that users upgrading to Windows 10 from Windows 8 may lose the ability to use Secure Boot, unless they buy a new video card or have a recent one.

It also may mean an attacker can simply swap video cards and bypass SecureBoot; so much for tamper resistance in TPM chips…

It seems very strange for an OS vendor to be enabling or disabling firmware features. It is worse to see security features being disabled in the name of marketing. If Microsoft disables Secure Boot on a system, this may mean that Secure Boot is also disabled for any other OS installed on that system, like Linux, via the Micorosoft-signed Shim. So this Windows marketing technique likely impacts non-Windows system security. I am not sure, maybe their change only impacts their own OS, and other OSes on that system will still continue to Securely Boot.

It is also bad that this vendor is default Certificate Authority representing the UEFI Forum. It is also disconcerting to see Microsoft adding additional restrictions to all UEFI pre-OS applications. The UEFI Forum and Intel is letting Microsoft bully Intel-based Windows OEMs. I was reading some ARM slides recently, sorry I don’t have the URL handy for exact quote, but it said something like “no bully in our playground telling us what to run”.  I wish Intel had the ability to stand up to the bully in their playground.

Ironically, Microsoft appears to have just learned to play Apple’s game better. Before Microsoft was playing UEFI-based games with systems, Apple was already using EFI to prevent non-Apple OSes on some of their systems. Since APPL and MSFT are OEMs as well as OS vendors, I expect their own systems would use UEFI as a form of “DRM” to keep their OS on their hardware. But Microsoft is now impacting all Windows OEMs, in addition to their own systems, each release of Windows makes more use of UEFI to restrict what OEMs and users can do and let Microsoft have more control over these systems. Chrome OEMs are looking better and better… 😦

More information:

http://www.itwire.com/opinion-and-analysis/open-sauce/68262-windows-10-no-secure-boot-unless-microsoft-tax-is-paid
https://msdn.microsoft.com/en-us/library/dn917885%28v=vs.85%29.aspx
https://msdn.microsoft.com/en-us/library/dn756793%28v=vs.85%29.aspx

Disclaimers

  • No guarantees, explicit or implied. BE CAREFUL WORKING WITH FIRMWARE.
  • Affiliate links in use.
  • Sponsored by PreOS Security.

Follow Us

  • Twitter
  • Twitter
  • Twitter
  • RSS Feed
  • RSS Feed
  • LinkedIn
  • GitHub

Search

Tags

ACPI AMD AMI Android Apple ARM ARM Ltd BIOS Canonical CHIPSEC Coreboot Debian EDK2 EFI event FreeBSD FWTS Google HP IBM Intel Intel AMT Intel ME Intel SGX IoT job-posting Lenovo Linaro Linux macOS Matthew Garrett Meltdown Microsoft Nikolaj Schlej qemu Redfish Red Hat RISC-V Rust Secure Boot SMM Spectre TianoCore TPM U-Boot UEFI UEFI Forum USB Vincent Zimmer Windows

Archives

Blogs I Follow (only shows first 50…)

  • Android
  • Android Developers Blog
  • Qt Blog
  • LLVM Project Blog
  • Chromium Blog
  • Broadcom ConnectedBroadcom Connected
  • w00tsec
  • sniablog.org
  • https://blogs.mcafee.com/home-page/feed
  • Malwarebytes Labs
  • Blog RSS
  • Blog – NVM Express
  • Schneier on Security
  • IBM Product Security Incident Response Team
  • Threatpost
  • Rapid7 Blog
  • blogs.technet.com/rss.aspx
  • Search Msdn
  • Cyber Trust Blog
  • Blog - Möbius Strip Reverse Engineering
  • Executive Platform - Cisco Blogs
  • Replicant
  • IoTivity blogs
  • Official PC-BSD Blog
  • Bootlin
  • FreeBSD Foundation
  • Planet FreeBSD
  • Ubuntu blog
  • FSF News
  • Oracle Blogs | Oracle Blogs
  • Oracle Blogs | Oracle Blogs
  • Xen Project Blog
  • Red Hat Blog
  • Planet openSUSE
  • Fedora People
  • Planet Debian
  • Blog
  • Tizen - An open source, standards-based software platform for multiple device categories.
  • iXsystems, Inc. – Enterprise Storage & Servers
  • Kali Linux
  • Linaro
  • InTelligence Blog
  • ASSET InterTech
  • Sage
  • coreboot developer blogs
  • blogs.phoenix.com/phoenix_technologies_bios/atom.xml
  • Lenovo Blog
  • System76 Blog RSS Feed
  • Purism
  • bunnie's blog

Blogroll

  • Discuss
  • Get Inspired
  • Get Polling
  • Get Support
  • Learn WordPress.com
  • Theme Showcase
  • WordPress Planet
  • WordPress.com News
Blog at WordPress.com.
Android

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Android Developers Blog

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Qt Blog

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

LLVM Project Blog

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Chromium Blog

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Broadcom ConnectedBroadcom Connected

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

w00tsec

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

sniablog.org

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Malwarebytes Labs

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Blog RSS

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Blog – NVM Express

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Schneier on Security

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

IBM Product Security Incident Response Team

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Threatpost

Rapid7 Blog

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Search Msdn

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Cyber Trust Blog

Blog - Möbius Strip Reverse Engineering

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Executive Platform - Cisco Blogs

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Replicant

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

IoTivity blogs

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Official PC-BSD Blog

Discover the Desktop

Bootlin

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

FreeBSD Foundation

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Planet FreeBSD

Ubuntu blog

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

FSF News

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Oracle Blogs | Oracle Blogs

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Oracle Blogs | Oracle Blogs

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Xen Project Blog

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Red Hat Blog

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Planet openSUSE

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Fedora People

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Planet Debian

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Blog

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Tizen - An open source, standards-based software platform for multiple device categories.

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

iXsystems, Inc. – Enterprise Storage & Servers

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Kali Linux

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Linaro

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

InTelligence Blog

ASSET InterTech

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Sage

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

coreboot developer blogs

News from coreboot world

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Lenovo Blog

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

System76 Blog RSS Feed

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

Purism

Just another WordPress.com site

bunnie's blog

Hastily-written news/info on the firmware security/development communities, sorry for the typos.

  • Follow Following
    • Firmware Security
    • Join 231 other followers
    • Already have a WordPress.com account? Log in now.
    • Firmware Security
    • Customize
    • Follow Following
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar