|21-11-2011, 06:40 AM||#1|
Join Date: May 19 2008
[Techpowerup.com] Windows 8 Secure Boot Feature: Not So Secure?
We have brought you the potential perils of the upcoming UEFI Forum-implemented - www.uefi.org - Windows 8 secure boot feature here, here and here. However, it appears that it may not be so 'secure' after all, since there appears to be a surefire way to circumvent it, at least for the moment, while it's in development.
Softpedia has scored an exclusive interview with security researcher Peter Kleissner, who has created various Windows (XP, Server 2003 etc) "bootkits", which allow OS infection at the highest privilege level, giving unrestricted access to the whole of the PC. His latest one, called Stoned Lite, shows how the Windows 8 secure boot process, still in development, can be subverted, as it stands. He is planning to release details of how the code works at the upcoming International Malware Conference (MalCon) - http://malcon.org - that will take place in India on November 25th. It appears that the real vulnerability exists in the legacy BIOS boot procedure, not in Microsoft's implementation of secure boot, as Kleissner said:
The problem with the legacy startup is that no one verifies the MBR, which makes it the vulnerable point. With UEFI and secure boot, all the boot applications and drivers have to be signed (otherwise they won't be loaded). You can compare it to TPM, although Arie van der Hoeven from Microsoft announced that the secure boot feature is mandatory for OEMs who want to be UEFI certified. It is a good message that security is not an option.More...
|boot, feature, secure, techpowerupcom, windows|
|Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)|
|Similar Threads for: [Techpowerup.com] Windows 8 Secure Boot Feature: Not So Secure?|
|Thread||Thread Starter||Forum||Replies||Last Post|
|[Techpowerup.com] Windows 8 Secure Boot: Handy Malware Backdoor for Nosy Governments?||News||Reviews & News Online||0||30-10-2011 02:31 AM|
|[Techpowerup.com] Controversial Windows 8 Secure Boot Feature: FSF Issues Rallying Cry||News||Reviews & News Online||0||26-10-2011 05:44 PM|
|[Techpowerup.com] Windows 8 Secure Boot: Designed to Lock Out Linux?||News||Reviews & News Online||0||22-09-2011 05:28 PM|
|Windows Vista/2008 SP2 Beta released||eva2000||Operating systems||2||04-12-2008 11:33 PM|
All times are GMT +11. The time now is 08:18 AM.