Click here to learn
about this Sponsor:
Home  |  News  |  Articles  |  Forum

  Home arrow News arrow Free Software Foundation: Windows 8 secure boot requirement could lock out Linux

Free Software Foundation: Windows 8 secure boot requirement could lock out Linux
By Jonathan Angel

Rate This Article: Add This Article To:

The Free Software Foundation (FSF) has launched a campaign claiming that Windows 8-certified PCs might prevent users from booting into Linux. The mandatory "secure boot" facility in the systems' Unified Extensible Firmware Interface (UEFI) might better be called "restricted boot," the organization claims.

Microsoft cheered Windows users in September when it demonstrated the upcoming Windows 8 operating system booting in eight seconds. Part of the technology behind the fast boots, however, could enable Microsoft and its PC vendor partners to block users from loading Linux on a Windows 8 PC, Matthew Garrett, a mobile Linux developer at Red Hat, wrote in a Sept. 20 blog post.


When secure boot is turned on, UEFI will only launch verified boot loaders
Source: Microsoft
(Click to enlarge)

To gain Windows 8 certification, PCs will be required to use the Unified Extensible Firmware Interface (UEFI) in revision 2.3.1 or later. This firmware includes a secure boot mode, intended to block malware such as rootkit infections. When this mode is turned on, the only boot loaders that will run are those whose signatures match those stored in a database within the firmware, according to Microsoft.

Garrett charged that this mechanism could not only keep users from installing alternative operating systems such as Linux, but also prevent them from using hardware -- a new graphics card, for example -- that didn't come with appropriately signed drivers. He further complained that there is no central signing authority for the keys employed in UEFI secure boot, effectively giving each PC vendor control over what software its products can load.

The Free Software Foundation enters the fray

More about Microsoft's response to the above, plus another riposte from Garrett, appears later in this story. Meanwhile, the FSF entered the fray Oct. 17, releasing a statement titled "Stand up for your freedom to install free software."

FSF Campaigns Manager Joshua Gay writes, "The FSF is concerned that Microsoft and hardware manufacturers will implement the system in a way that will prevent users from booting anything other than Windows. In this case, the FSF offers the more accurate name of Restricted Boot, explaining that such a requirement would be a severe restriction on computer users and, by giving only a remote third party control over what's authorized to run on their computers, not a security feature at all."

The complete statement, open for signing here, reads as follows:

"We, the undersigned, urge all computer makers implementing UEFI's so-called "Secure Boot" to do it in a way that allows free software operating systems to be installed. To respect user freedom and truly protect user security, manufacturers must either allow computer owners to disable the boot restrictions, or provide a sure-fire way for them to install and run a free software operating system of their choice. We commit that we will neither purchase nor recommend computers that strip users of this critical freedom, and we will actively urge people in our communities to avoid such jailed systems."

Microsoft response avoided the dreaded L-word

In a Sept. 22 posting on the Building Windows blog, Microsoft Program Manager Tony Mangefeste responded to Matthew Garrett's Sept. 20 complaint. He wrote, "At the end of the day, the customer is in control of their PC. The security that UEFI has to offer with secure boot means that most customers will have their systems protected against boot loader attacks. For the enthusiast who wants to run older operating systems, the option is there to allow you to make that decision."


The Windows 8 tablet given to BUILD attendees let secure boot be turned off
Source: Microsoft
(Click to enlarge)

Mangefeste pointed out that the Samsung tablet presented to developers at the recent BUILD conference included Microsoft-designed firmware (above) allowing secure boot to be disabled. "Microsoft does not mandate or control the settings on PC firmware that control or enable secured boot from any operating system other than Windows," he added.

In his posting, however, Mangafeste did appear to admit that a given OEM could make secure boot non-defeatable if it really wanted to. He also defends the lack of a central signing authority, as follows:

"Microsoft supports OEMs having the flexibility to decide who manages security certificates and how to allow customers to import and manage those certificates, and manage secure boot. We believe it is important to support this flexibility to the OEMs and to allow our customers to decide how they want to manage their systems."

Steve Sinofsky, president of Microsoft's Windows and Windows Live division, added the following comment to Mangafeste's blog posting, again avoiding the dreaded L-word: "How secure boot works with any other operating systems is obviously a question for those OS products :-) We focus our boot loader on Windows and there are a number of alternatives for people who wish to have other sets of functionality."

Garrett fought back in a Sept. 23 blog entry, as follows: "What's interesting is that at no point [did Microsoft] … contradict anything I've said. As things stand, Windows 8 certified systems will make it either more difficult or impossible to install alternative operating systems."

Microsoft's claim that the customer is in control of their PC is only true if by "customer" they mean "hardware manufacturer," Garrett charges. End users would not be guaranteed the ability to install extra signing keys to securely boot the operating system of their choice, and -- if secure boot is not defeatable -- might be unable to swap graphics cards, network cards, SATA controllers, or other hardware, he adds.

Whether a counterblast from Microsoft is in the offing, it's too early to say. But ZDNet blogger Ed Bott weighed in Oct. 18, charging that the FSF has "a longstanding reputation for hysterical reactions to everything Microsoft does." PC manufacturers will enable a secure boot toggle because they have "no economic incentive to mess with the microscopic percentage of the PC market that uses Linux," and the support calls that would otherwise result would eat up their razor-thin profit margins, he claims.

Bott also quotes AMI, one of the largest makers of UEFI firmware, as saying that secure boot will be defeatable whenever a particular OEM so decides. "I would imagine that many OEMs will keep this option open to their users in order to appeal to a wider cross-section of users," a spokesperson is said to have added.

Eric Brown contributed reporting to this story.


Related Stories:


Discuss Free Software Foundation: Windows 8 secure boot requirement could lock out Linux
 
Ed Bott has "a longstanding reputation of parroting everything Microsoft does."...
Boot viruses and rootkits that modify the boot process are extremely infrequent. The...
>>> Post your comment now!
 
 
 
>>> More News Articles          >>> More By Jonathan Angel
 



FUEL Database on MontaVista Linux
Whether building a mobile handset, a car navigation system, a package tracking device, or a home entertainment console, developers need capable software systems, including an operating system, development tools, and supporting libraries, to gain maximum benefit from their hardware platform and to meet aggressive time-to-market goals.

Breaking New Ground: The Evolution of Linux Clustering
With a platform comprising a complete Linux distribution, enhanced for clustering, and tailored for HPC, Penguin Computing¿s Scyld Software provides the building blocks for organizations from enterprises to workgroups to deploy, manage, and maintain Linux clusters, regardless of their size.

Data Monitoring with NightStar LX
Unlike ordinary debuggers, NightStar LX doesn¿t leave you stranded in the dark. It¿s more than just a debugger, it¿s a whole suite of integrated diagnostic tools designed for time-critical Linux applications to reduce test time, increase productivity and lower costs. You can debug, monitor, analyze and tune with minimal intrusion, so you see real execution behavior. And that¿s positively illuminating.

Virtualizing Service Provider Networks with Vyatta
This paper highlights Vyatta's unique ability to virtualize networking functions using Vyatta's secure routing software in service provider environments.

High Availability Messaging Solution Using AXIGEN, Heartbeat and DRBD
This white paper discusses a high-availability messaging solution relying on the AXIGEN Mail Server, Heartbeat and DRBD. Solution architecture and implementation, as well as benefits of using AXIGEN for this setup are all presented in detail.

Understanding the Financial Benefits of Open Source
Will open source pay off? Open source is becoming standard within enterprises, often because of cost savings. Find out how much of a financial impact it can have on your organization. Get this methodology and calculator now, compliments of JBoss.

Embedded Hardware and OS Technology Empower PC-Based Platforms
The modern embedded computer is the jack of all trades appearing in many forms.

Data Management for Real-Time Distributed Systems
This paper provides an overview of the network-centric computing model, data distribution services, and distributed data management. It then describes how the SkyBoard integration and synchronization service, coupled with an implementation of the OMG¿s Data Distribution Service (DDS) standard, can be used to create an efficient data distribution, storage, and retrieval system.

7 Advantages of D2D Backup
For decades, tape has been the backup medium of choice. But, now, disk-to-disk (D2D) backup is gaining in favor. Learn why you should make the move in this whitepaper.

Got a HOT tip?   please tell us!
Free weekly newsletter
Enter your email...
PLATINUM SPONSORS

 


ADVERTISEMENT


Check out the latest Linux powered...

Mobile phones!

MIDs, UMPCs
& tablets

Mobile devices

Other cool
gadgets

Resource Library

• Unix, Linux Uptime and Reliability Increase: Patch Management Woes Plague Windows Yankee Group survey finds IBM AIX Unix is highest in ...
• Scalable, Fault-Tolerant NAS for Oracle - The Next Generation For several years NAS has been evolving as a storage ...
• Managing Software Intellectual Property in an Open Source World This whitepaper draws on the experiences of the Black Duck ...
• Open Source Security Myths Dispelled Is it risky to trust mission-critical infrastructure to open source ...
• Bringing IT Operations Management to Open Source & Beyond Download this IDC analyst report to learn how open source ...




Most popular stories -- past 90 days:
· Linux boots in 2.97 seconds
· Tiniest Linux system, yet?
· Linux powers "cloud" gaming console
· Report: T-Mobile sells out first 1.5 million G1s
· Open set-top box ships
· E17 adapted to Linux devices, demo'd on Treo650
· Android debuts
· First ALP Linux smartphone?
· Cortex-A8 gaming handheld runs Linux
· Ubuntu announces ARM port


DesktopLinux headlines:
· Simulator runs Android apps on Ubuntu
· Hypervisor rev'd for higher reliability
· Pluggable NAS now supports Linux desktops
· Moblin v2 beta targets netbooks
· Linux-ready netbook touted as "Student rugged"
· USB display technology heading for Linux
· Ubuntu One takes baby step to the cloud
· Game over for Linux netbooks?
· Linux Foundation relaunches Linux web site
· Dell spins lower-cost netbook


Also visit our sister site:


Sign up for LinuxForDevices.com's...

news feed


Or, follow us on Twitter...