Feeds

FSF takes Win 8 Secure Boot fight to OEMs

Punters urged to bombard PC makers

Secure remote control for conventional and virtual desktops

PC makers are being lobbied to install Windows 8 on machines in a way that will afford users the freedom to boot Linux or any other operating system.

The Free Software Foundation (FSF) is urging PC users to sign a statement demanding that OEMs which implement Windows 8's UEFI Secure Boot do so in a way that allows individuals to disable it, or that the PC makers provide a "sure-fire way" to install and run an operating system of the user's choice.

The statement says that giving this choice will protect users' rights and security.

The FSF has also hinted at a boycott on buying Windows 8 PCs. "We commit that we will neither purchase nor recommend computers that strip users of this critical freedom, and we will actively urge people in our communities to avoid such jailed systems," the FSF concludes.

Windows 8's Secure Boot was branded "Restricted Boot" by the FSF because "it would be a disastrous restriction on computer users and not a security feature at all".

The FSF's website became suddenly unavailable Tuesday morning due to "technical problems" once word of the campaign began to spread.

Secure Boot is a planned feature of Windows 8 intended to thwart a type of hack that targets the boot path; the idea is to ensure only signed "good code" will boot up.

Microsoft's system implements the Unified Extensible Firmware Interface (UEFI) firmware specification, only the system in Windows 8 would mean any Windows 8 PC that ships with only OEM and Microsoft keys will not boot a generic build of Linux.

The red flag was raised by Red Hat employee and tech blogger Matthew Garrett here and Professor Ross Anderson of Cambridge University here. Anderson said Secure Boot might violate EU competition law.

Microsoft, meanwhile, has shifted responsibility for Secure Boot to the PC manufacturers. In a blog response to the alarm, Microsoft ecosystem team member Tony Mangefeste wrote: "OEMs are free to choose how to enable this support and can further customize the parameters as described above in an effort to deliver unique value propositions to their customers."

However, it seems OEMs are not free to choose how to enable Secure Boot.

All About Microsoft's Mary-Jo Foley reports that at Microsoft's Build conference in California last month, Microsoft said support for UEFI Secure Boot is a Windows 8 certification requirement.

Meanwhile, on the Windows 8 blog in response to concern about UEFI, Mangefeste went on to claim: "At the end of the day, the customer is in control of their PC."

Responding to Mangefeste, Garrett called the rebuttal "entirely factually accurate", adding "but it's also misleading" – because the PC marker and Microsoft would maintain control over the keys needed to permit trusted code to boot on PCs.

"The truth is that Microsoft's move removes control from the end user and places it in the hands of Microsoft and the hardware vendors," Garrett wrote in response to Mangefeste here. ®

Beginner's guide to SSL certificates

More from The Register

next story
Xperia Z3: Crikey, Sony – ANOTHER flagship phondleslab?
The Fourth Amendment... and it IS better
Don't wait for that big iPad, order a NEXUS 9 instead, industry little bird says
Google said to debut next big slab, Android L ahead of Apple event
Microsoft to enter the STRUGGLE of the HUMAN WRIST
It's not just a thumb war, it's total digit war
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Netscape Navigator - the browser that started it all - turns 20
It was 20 years ago today, Marc Andreeesen taught the band to play
A drone of one's own: Reg buyers' guide for UAV fanciers
Hardware: Check. Software: Huh? Licence: Licence...?
The Apple launch AS IT HAPPENED: Totally SERIOUS coverage, not for haters
Fandroids, Windows Phone fringe-oids – you wouldn't understand
Apple SILENCES Bose, YANKS headphones from stores
The, er, Beats go on after noise-cancelling spat
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.