Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Additionally, as point (18) on the page you linked to states:

    Mandatory. Enable/Disable Secure Boot.
      On non-ARM systems, it is required to implement the
      ability to disable Secure Boot via firmware setup. A
      physically present user must be allowed to disable 
      Secure Boot via firmware setup without possession of 
      PKpriv.
Doesn't this mean that (definitely on certified non-ARM systems, and possibly on some ARM systems) you can just enter the UEFI, disable secure boot, and boot your OS of choice?


As the article (clearly) says, since USB is not set up fast enough to recognize a keyboard before the bootloader has handed control to the OS, there's no way to interrupt boot to do so; Windows will let you reboot to another OS, but only after you click through a license agreement.


Surely a physically present user (mentioned by the requirement of point 18) can disconnect the boot device in order to prevent Windows from booting. The firmware then has ample time to set up USB and allow the user to enter firmware setup.

Alternatively, as a workaround, find someone who has already accepted said agreement elsewhere and have them accept it on your device, disable secure boot and wipe the boot device.


Not if the default is to boot from an SSD soldered onto the mainboard, or tucked away in a device that is not designed to be opened.


> a physically present user (mentioned by the requirement of point 18) can disconnect the boot device in order to prevent Windows from booting.

I believe that would void most warranties.


In the case of a general purpose computer, I'm willing to bet you'd be wrong. We're not talking about a Surface tablet here.


Have you looked at an Ultrabook? Getting at the hard drive involves disassembling the entire machine, something that's almost impossible to do without either specialised tools or a willingness to inflict some amount of cosmetic damage.


Honestly, no I didn't think about that, but I would say that you might be starting to leave the realm of general there.


Yes, as long as you can get into the firmware menu in the first place. Which, on some hardware, requires you to agree to the Windows EULA.


> and possibly on some ARM systems

Disabling Secure Boot is forbidden on ARM systems. Point 18 ends with:

    Disabling Secure Boot must not be possible on ARM systems.


This is idiotic. The requirement should be that the user can disable it entirely OR replace the private key. And it should require implementation of an optional password protection.


That is actually the case. Point 17 states:

    Mandatory. On non-ARM systems, the platform MUST implement 
    the ability for a physically present user to select
    between two Secure Boot modes in firmware setup: "Custom"
    and "Standard".


My mistake. Carry on.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: