Greg Kroah-Hartman Shows UEFI Booting Unsigned Kernel

The UEFI interface can enroll the hash of the Linux kernel to be booted securely and he has no need to sign anything…

see Discussion on Google Plus

Let’s hope that behaviour is widespread. One still has to find a way to get the kernel onto the hard drive. Perhaps one can install on one machine and copy/move to another or turn off “secure boot” temporarily. This is good news, at least for x86/amd64 systems. On a similar note, Intel now claims it is not abandoning socketed CPUs

- Robert Pogson

26 Responses to “Greg Kroah-Hartman Shows UEFI Booting Unsigned Kernel”


  1. 1 dougman Dec 7th, 2012 at 3:54 pm

    How to Circumvent UEFI Secure Boot
    http://www.osnews.com/comments/26591

    Eventually what will happen is that UEFI will become exploitable and malware will come out taking advantage of this, affecting everyone.

    M$ will revoke keys, and people will become screaming howler monkeys.

  2. 2 lpbbear Dec 7th, 2012 at 8:20 pm

    I would imagine the exploit for the so called secure boot is going to be pretty simple. Since as I understand it the method to make the boot secure involves a set of signing keys, one in the UEFI “Bios” and another in the actual Windows operating system, I would guess all it might take to make one of these supposedly secure Windows systems to crap out is infect the OS with something that trashes the half of the process, or key, that exists in Windows. Since that half is trashed the UEFI boot process has no paired key…..no more boot at all. End of game for Windows user.

    My guess is the whole scheme will fall a part in the near future and it will be because of some simple exploit or flaw in the idea.

  3. 3 Robert Pogson Dec 7th, 2012 at 10:11 pm

    lpbear wrote, “Since that half is trashed the UEFI boot process has no paired key…..no more boot at all. End of game for Windows user.”

    Ahhh, yet another route to unbootability. M$ relies on that to have suckersconsumers buy new machines because it’s cheaper than fixing them sometimes and with malware there’s no guarantee of putting everything right.

  4. 4 eug Dec 8th, 2012 at 4:48 am

    “UEFI secure boot” is nothing about malware afflicting users. It is ALL about preventing things like paradox and windows loader.

  5. 5 Adam King Dec 8th, 2012 at 5:31 am

    No, it’s about mafia$oft having one more way to extort customers.

  6. 6 eug Dec 8th, 2012 at 10:44 am

    Yes, it is!
    With or withou (U2!) UEFI windows malware will continue to have a happy life!

  7. 7 oiaohm Dec 8th, 2012 at 6:55 pm

    eug problem here is items like Windows Loader will be able to alter to chain load instead of a Linux kernel or even possible chain load from MS own loader.

    http://neosmart.net/blog/2012/announcing-easybcd-2-2-windows-8-dual-booting-and-more/

    So UEFI really is limited on how much help it is unless you lock users out from altering the system completely.

    If Ms goal is to prevent windows loader and paradox on x86 they have been wasting there.

    Now the Windows Arm RT device that is a different matter. Only way to prevent windows loader and paradox is prevent other OS’s from running end of story.

    Greg Kroah-Hartman focus is direct booting not chain loading from the MS boot loader.

  8. 8 Robert Pogson Dec 9th, 2012 at 6:17 am

    oiaohm wrote, “So UEFI really is limited on how much help it is unless you lock users out from altering the system completely.”

    True.

    Incidentally, I had a problem with the old BIOS recently. On one of our PCs, the BIOS was changed to “wait for F1 on error” (no idea how that happened). Of course it would not boot with our wireless keyboard. I had to bring Beast’s Fujitsu “aircraft carrier” keyboard to the machine to get in and root around. After looking and failing to find “halt on all errors” or something similar, I reasoned that F1 must be on the keyboard… It worked. I will bet UEFI and “secure boot” will launch no end of similar problems over the years as M$ struggles to survive. I can see M$ using “secure boot” to prevent old versions of that other OS running on new hardware. Nothing prevents M$ from “updating” “secure boot” or its “keys” to jerk around the markets indefinitely. I think all these work-arounds are just a stop-gap. What the world needs is a good lawsuit to put M$ in its place once and for all time. The world missed that chance in DOJ v M$.

  9. 9 eug Dec 14th, 2012 at 10:08 am
  10. 10 eug Jan 3rd, 2013 at 6:11 pm
  11. 11 eug Jan 5th, 2013 at 5:57 am

    More fun with Windows 8 UEFI, Secure Boot, Fedora and Ubuntu

    http://mrpogson.com/2012/12/07/greg-kroah-hartman-shows-uefi-booting-unsigned-kernel

  12. 12 eug Jan 30th, 2013 at 6:27 am

    The rEFInd boot loader for UEFI Systems: A life (and sanity) saver

    http://www.zdnet.com/the-refind-boot-loader-for-uefi-systems-7000010275/

  13. 13 eug Jan 31st, 2013 at 9:22 am
  14. 14 eug Feb 3rd, 2013 at 5:50 am
  15. 15 eug Feb 3rd, 2013 at 5:51 am

    The current state of UEFI and Linux

    http://mjg59.dreamwidth.org/22028.html

  16. 16 eug Feb 3rd, 2013 at 5:51 am
  17. 17 Der Balrog Feb 3rd, 2013 at 6:40 am

    Very good, eug. Your link finding skills are unprecedented. You’re almost like a dog.

  18. 18 eug Feb 6th, 2013 at 11:22 am
  19. 19 eug Feb 6th, 2013 at 11:22 am
  20. 20 eug Feb 12th, 2013 at 10:20 am
  21. 21 eug Feb 12th, 2013 at 10:20 am

    Linux acquitted in Samsung laptop UEFI deaths

    http://www.bit-tech.net/news/bits/2013/02/11/linux-samsung-deaths-2/1

  22. 22 eug Feb 21st, 2013 at 11:06 am

    Enough with the UEFI drama already

    http://www.dedoimedo.com/computers/uefi-drama.html

  23. 23 eug Feb 27th, 2013 at 11:51 am
  24. 24 eug Feb 28th, 2013 at 10:10 am

    Supporting third-party keys in a Secure Boot world

    http://mjg59.dreamwidth.org/23400.html

  25. 25 eug Apr 8th, 2013 at 12:03 pm
  26. 26 eug Apr 18th, 2013 at 11:09 am

Leave a Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>




Archives by Month

My Mission

My observations and opinions about IT are based on 40 years of use in science and technology and lately, in education. I like IT that is fast, cost-effective and reliable. I do not care whether my solution is the same as yours. I like to think for myself.

My first use of GNU/Linux in 2001 was so remarkably better than what I had been using, I feel it is important work to share GNU/Linux with the world. I have been blessed by working in schools where students and school systems have benefited by good, modular software easily installed in most systems.

I have shown GNU/Linux to thousands of students and hundreds of teachers over the years and will continue in some way doing that until I die in spite of the opposition.

Posts

December 2012
S M T W T F S
« Nov   Jan »
 1
2345678
9101112131415
16171819202122
23242526272829
3031  

    Writing

    3434 articles
    30679 comments

      Comments

      platforms
      linux 17509
      windows 12809
      macos 206
      sun 3
      wp 2

      browsers
      firefox 23964 
      safari 11881 
      chrome 11732 
      ie 4666 
      iceweasel 4281 
      opera 1644 
      konqueror 198 
      netnewswire 14 
      epiphany 2 
      flock 0 
      bonecho 0 
      lynx 0 

Bad Behavior has blocked 6300 access attempts in the last 7 days.