Linked by Thom Holwerda on Fri 23rd Sep 2011 22:22 UTC, submitted by kragil
Windows The story about how secure boot for Windows 8, part of UEFI, will hinder the use of non-signed binaries and operating systems, like Linux, has registered at Redmond as well. The company posted about it on the Building Windows 8 blog - but didn't take any of the worries away. In fact, Red Hat's Matthew Garrett, who originally broke this story, has some more information - worst of which is that Red Hat has received confirmation from hardware vendors that some of them will not allow you to disable secure boot.
Permalink for comment 490739
To read all comments associated with this story, please click here.
RE[2]: Bootloader anyone ?
by lemur2 on Sun 25th Sep 2011 23:51 UTC in reply to "RE: Bootloader anyone ?"
Member since:

DVDs on the other hand are not cryptographically sound because the encryption keys used must be accessible on the end user device (otherwise the DVD would not play).

Correct. Linux, for example, does not use DeCSS software to play DVDs, it uses libdvdcss.

DeCSS used a "stolen" player key, it was stolen from the Xing software player I believe. This strategy is arguably illegal.

libdvdcss does not use a stolen player key, but rather it reads information from the DVD it is attempting to play, and from that data it calculates a list of possible keys. All of the possible keys are tried until one which works for that DVD is found.

The situation with UEFI secure boot is that the keys will be stored in secure storage on the motherboard, and they will not be accessible to the boot loader.

In order to boot the boot loader must in effect know one of the signing keys, because no method similar to that used by libdvdcss will be possible. Any work-around will have to be similar to DeCSS, which is to say it must use "stolen" keys. This will probably be in violation of the DMCA, and therefore illegal.

Reply Parent Score: 2