You are not registered yet. Please click here to register!
[Techpowerup.com] Windows 8 Secure Boot Feature: Not So Secure? - i4memory.com - different look at memory
Tags Register Blogs FAQ Members List Calendar Mark Forums Read

Notices

Reply
 
Thread Tools
Old 21-11-2011, 05:40 AM   #1
News
News Hound
News's PC Specs
 
Join Date: May 19 2008
Posts: 41,643
[Techpowerup.com] Windows 8 Secure Boot Feature: Not So Secure?

We have brought you the potential perils of the upcoming UEFI Forum-implemented - www.uefi.org - Windows 8 secure boot feature here, here and here. However, it appears that it may not be so 'secure' after all, since there appears to be a surefire way to circumvent it, at least for the moment, while it's in development.

Softpedia has scored an exclusive interview with security researcher Peter Kleissner, who has created various Windows (XP, Server 2003 etc) "bootkits", which allow OS infection at the highest privilege level, giving unrestricted access to the whole of the PC. His latest one, called Stoned Lite, shows how the Windows 8 secure boot process, still in development, can be subverted, as it stands. He is planning to release details of how the code works at the upcoming International Malware Conference (MalCon) - http://malcon.org - that will take place in India on November 25th. It appears that the real vulnerability exists in the legacy BIOS boot procedure, not in Microsoft's implementation of secure boot, as Kleissner said:
The problem with the legacy startup is that no one verifies the MBR, which makes it the vulnerable point. With UEFI and secure boot, all the boot applications and drivers have to be signed (otherwise they won't be loaded). You can compare it to TPM, although Arie van der Hoeven from Microsoft announced that the secure boot feature is mandatory for OEMs who want to be UEFI certified. It is a good message that security is not an option.
More...
News is offline   Reply With Quote
Reply

Bookmarks

Tags
boot, feature, secure, techpowerupcom, windows


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


Similar Threads for: [Techpowerup.com] Windows 8 Secure Boot Feature: Not So Secure?
Thread Thread Starter Forum Replies Last Post
[Techpowerup.com] Windows 8 Secure Boot: Handy Malware Backdoor for Nosy Governments? News Reviews & News Online 0 30-10-2011 01:31 AM
[Techpowerup.com] Controversial Windows 8 Secure Boot Feature: FSF Issues Rallying Cry News Reviews & News Online 0 26-10-2011 04:44 PM
[Techpowerup.com] Windows 8 Secure Boot: Designed to Lock Out Linux? News Reviews & News Online 0 22-09-2011 04:28 PM
Windows Vista/2008 SP2 Beta released eva2000 Operating systems 2 04-12-2008 10:33 PM


All times are GMT +11. The time now is 12:05 AM.

no new posts