Microsoft Bans Linux/Android Dual-Booting on Windows 8 ARM Devices
January 16, 2012 11:39 AM
comment(s) - last by
Anti-Android crackdown would make Apple proud
Microsoft Corp.'s (
) UEFI Secure Boot technology -- the
long-awaited BIOS replacement
-- has some people concerned due to its digital rights management features, which can be used by OEMs to prevent dual-booting to other operating systems like Linux.
Microsoft Windows President Steven Sinofsky sought to assuage disgruntled Windows users,
There have been some comments about how Microsoft implemented secure boot and unfortunately these seemed to synthesize scenarios that are not the case so we are going to use this post as a chance to further describe how UEFI enables secure boot and the options available to PC manufacturers. The most important thing to understand is that we are introducing capabilities that provide a no-compromise approach to security to customers that seek this out while at the same time full and complete control over the PC continues to be available. Tony Mangefeste on our Ecosystem team authored this post. --Steven
UEFI allows firmware to implement a security policy
Secure boot is a UEFI protocol not a Windows 8 feature
UEFI secure boot is part of Windows 8 secured boot architecture
Windows 8 utilizes secure boot to ensure that the pre-OS environment is secure
Secure boot doesn’t “lock out” operating system loaders, but is a policy that allows firmware to validate authenticity of components
OEMs have the ability to customize their firmware to meet the needs of their customers by customizing the level of certificate and policy management on their platform
Microsoft does not mandate or control the settings on PC firmware that control or enable secured boot from any operating system other than Windows.
In other words, Microsoft isn't forcing laptop and desktop makers to ban Linux, though it's giving them the tools to do so.
That statement rebuked previously claims of a Red Hat, Inc. (
) Linux engineer who
Microsoft requires that machines conforming to the Windows 8 logo program and running a client version of Windows 8 ship with secure boot enabled. The two alternatives here are for Windows to be signed with a Microsoft key and for the public part of that key to be included with all systems, or alternatively for each OEM to include their own key and sign the pre-installed versions of Windows. The second approach would make it impossible to run boxed copies of Windows on Windows logo hardware, and also impossible to install new versions of Windows unless your OEM provided a new signed copy. The former seems more likely.
A system that ships with only OEM and Microsoft keys will not boot a generic copy of Linux.
Now, obviously, we could provide signed versions of Linux. This poses several problems. Firstly, we'd need a non-GPL bootloader. Grub 2 is released under the GPLv3, which explicitly requires that we provide the signing keys. Grub is under GPLv2 which lacks the explicit requirement for keys, but it could be argued that the requirement for the scripts used to control compilation includes that. It's a grey area, and exploiting it would be a pretty good show of bad faith. Secondly, in the near future the design of the kernel will mean that the kernel itself is part of the bootloader. This means that kernels will also have to be signed. Making it impossible for users or developers to build their own kernels is not practical. Finally, if we self-sign, it's still necessary to get our keys included by ever OEM.
Or does it?
's UK correspondent Glyn Moody dug up this interesting tidbit in Microsoft's ARM license. Writes Microsoft in "
Windows Hardware Certification Requirements
" for client and server systems, a document that regulates licensing (certification) (pg. 116):
MANDATORY: Enable/Disable Secure Boot. On non-ARM systems, it is required to implement the ability to disable Secure Boot via firmware setup. A physically present user must be allowed to disable Secure Boot via firmware setup without possession of Pkpriv. Programmatic disabling of Secure Boot either during Boot Services or after exiting EFI Boot Services MUST NOT be possible.
Disabling Secure MUST NOT be possible on ARM systems.
In other words dual-booting Linux on a standard x86 desktop should be no issue. But if you were hoping to load dual-booting Android and Windows kernels on a Windows 8 tablet (which will likely have an ARM) CPU or on
certain notebooks with ARM chips
, think again. Microsoft could soften its stance and/or users could find a way to break its DRM protections -- but there's no guarantee of either outcome.
ARM on Windows 8 -- don't you dare dual boot. [
In this regard Microsoft is very much "
Apple, Inc.'s (
) line". Apple has long prevented dual booting to Linux or the
installation of OS X on non-Apple computers
. Apple does
allow Windows installation via Boot Camp
, but only via a special understanding with Microsoft who cross licenses patents with Apple.
Windows 8 was a
star of the show
at the 2012 Consumer Electronics Show and is expected to
land in tablets and PCs this fall
Computer World UK
This article is over a month old, voting and posting comments is disabled
RE: Why do you say they're following in Apple's footsteps
1/17/2012 8:44:11 PM
>How is this any different from something like the nexus having its
There is a difference between a hardware vendor locking their own device and an OS vendor mandating locked devices. Both are anti-consumer, but the latter is anti-competitive. It's also different because we're not talking about phones, we're talking about general-purpose computing devices (we will probably be seeing ARM laptops in the near future as we already have ARM convertible tablets). We're talking about killing off Linux on ARM, for instance. It boggles my mind that the same people who are against Apple's lawsuit frenzy and SOPA are perfectly cool with general-purpose computing devices mandating what you can run on them.
>What about the various other phones, and devices like the asus
Ok, the first thing here is stop thinking phones. This isn't about toys and widgets. This is about future laptops and convertible tablets. The locking of the Transformer was anti-consumer, and the Linux and Android community raised so much fuss that within days ASUS agreed to unlock it. Meanwhile, MS had policy papers from two groups (including Red Hat) suggesting ways to implement secure boot without limiting user choice. They didn't acknowledge them, played word games, and then implemented this OEM policy anyway (as monopolies are wont to do). All of these things combined make this a heck of a lot more serious than one phone maker locking down a phone.
>windows 8 isn't even out yet and it's getting flak for adopting a
>security standard that it did not create
This statement is problematic on several fronts. First, those defending MS when the news first came out about secure boot advised waiting. Now that we've waited and ARM is locked down you're suggesting waiting again? If we sit down and shut up, it's too late. If Win8 ARM devices ship, the vendors will have already agreed to these OEM terms so the only hope to have MS reconsider them is long before Win 8 ARM ships.
Second, don't blame this on secure boot. It's INCREDIBLE how people are blaming everyone except Microsoft. My reply to you is the same I gave to someone else who told me "Microsoft didn't invent this" : Timothy McVeigh didn't invent explosives either. On top of that, Red Hat, like MS,
is part of the UEFI steering committee
. Red Hat told MS not to do this. In the article that announced the ARM restrictions, it was made clear that
secure boot is being used in a way it was never intended to be used
. It was
designed to prohibit end users from installing their own operating systems. Microsoft is
secure boot to block its competition (free OSes Android, WebOS and Linux) and prevent end users from trying them.
> and was not the first to adopt. makes no sense to me.
I'm sorry it doesn't make sense to you, but perhaps that's because you haven't read the relevant articles on the subject or are viewing this through partisan lenses. Microsoft
the first and only company to mandate to OEMs that end users not be able to disable secure boot. That is
part of the secure boot standard. There is nothing wrong with secure boot; there is something wrong with using it to keep consumers from installing their OS of choice.
"Nowadays, security guys break the Mac every single day. Every single day, they come out with a total exploit, your machine can be taken over totally. I dare anybody to do that once a month on the Windows machine." -- Bill Gates
CES 2012: Intel -- 2012 is the Year of the Ultrabook
January 9, 2012, 12:05 PM
Qualcomm to Lead ARM in War Against Intel With New Laptop Chips
January 3, 2012, 10:30 AM
Ballmer: Windows 8 Will Land in 2012, Pop up in Tablets
May 24, 2011, 2:49 PM
Say Bye to BIOS and Hello to PCs that Boot in Seconds With UEFI
October 4, 2010, 9:24 AM
Microsoft Exec: Windows Phone 7 is "Following in Apple’s Line", Won't Initially Support Multitasking or Memory Cards
April 12, 2010, 11:14 AM
BlackBerry Passport, Q5, and Z30 Go on Sale Till Dec. 30, Z30 is Nearly Sold Out
December 26, 2014, 4:04 PM
Despite Bump to $99/Year, Amazon Prime Attracts 10 Million New Customers
December 26, 2014, 3:08 PM
Qualcomm Snapdragon 810, New Gobi Modem Pass Cat. 9 LTE-A Test on UK's EE
December 25, 2014, 11:30 PM
Happy Holidays From DailyTech!!
December 24, 2014, 5:07 PM
Nokia's Sweet $250 Android Lollipop N1 Tablet is Rumored for Jan. 7 China Launch
December 24, 2014, 1:45 PM
Samsung Preps 4 GB LPDDR4 RAM to Power "4K" Smartphones in 2015
December 23, 2014, 10:38 AM
Most Popular Articles
Miyamoto: Nintendo is Prepping Successor to Troubled Wii U
December 22, 2014, 6:28 PM
Amazon's Kindle Fire HDX 8.9 Drops to $299 (30 Percent Off) for a Day
December 22, 2014, 10:57 AM
Airbus A350 XWB Passenger Jet Takes Off, First Unit Delivered to Qatar Airlines
December 22, 2014, 1:22 PM
Microsoft, Google Back The Interview, North Korea Vows Attacks on America
December 24, 2014, 4:25 PM
Nokia's Sweet $250 Android Lollipop N1 Tablet is Rumored for Jan. 7 China Launch
December 24, 2014, 1:45 PM
Latest Blog Posts
Sceptre Airs 27", 120 Hz. 1080p Monitor/HDTV w/ 5 ms Response Time for $220
Dec 3, 2014, 10:32 PM
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information