Pages

Showing posts with label Windows 8 versions. Show all posts
Showing posts with label Windows 8 versions. Show all posts

Monday, 5 November 2012

Why does Secure Boot need such draconian control?

Pros and cons of Secure Boot explored

 


There's a new unavoidable conundrum for free software, and it has a name that conjures up thoughts of either a totalitarian regime, or a decent way of ensuring that malevolent code doesn't slip in between the cracks in your BIOS and your operating system.
 It's called Secure Boot, and it's part of the Unified Extensible Firmware Interface specification (UEFI) developed for the next generation of PCs.
Secure Boot is designed to only allow signed code to boot your machine, and only entities that hold a valid key can sign the code that will allow your machine to boot. If the code can't be verified, it won't be able to run, in which case you'll probably be presented with an updated version of the message you used to get when you accidentally overwrote the master boot record.
It means that the USB version of Ubuntu 10.10 you've been relying on to undelete your Windows files and repair over-written master boot records will no longer work - at least not on a new machine that conforms to the specification. But then you probably won't have MBRs any more, either. Windows 8, and machines that are sold and certified to run it, will need to use Secure Boot. This is a good thing in some ways. For Microsoft and for Windows users, it will mean that one of the most glaring loopholes in PC security can finally be sealed. Trojans won't be able to hide, and Microsoft will be able to control the entire software stack from the boot to the desktop.
This will make it a lot harder for anything to usurp the operating system before it reaches sentience, and it's something Apple has been able to do for a long time.
It's part of the reason why iOS hardware hasn't yet been compromised and why, despite everyone owning one, Apple's devices seem to be retaining their integrity (though now that I've written this, there's probably some terrible malware infecting every iOS device on the planet).

The downside 

But in other ways, this isn't a good thing. Apple controls every line of code that goes through the CPU, whether that's the bootstrap or any one of the thousands of apps vetted and sandboxed to run on its devices.
It does this on an Apple TV, its music players, its tablets and its phones. Its PCs famously only run on authenticated hardware too, and Apple wants to take the sandbox approach used in iOS development to the desktop.
It will do this by making the OS X App store as popular and as integral to OS X as possible, and by forcing developers into the sandboxed environment it is creating.
There are similarities between the level of control in Secure Boot and the direction Apple is headed in when it comes to running software on your hardware, and while this development will be good for consumer confidence, I don't think it's a good thing for freedom or for security.
It stinks of an easy option being made because, surreptitiously, it's an idea that also works to give Microsoft more control. There should be a more imaginative solution to these problems, because it's unclear what this going to mean for Linux - and more importantly, what is it going to mean for choice.
Do you really want an operating system vendor to have this level of control over your hardware? Apple customers can be excused somewhat because they buy a device that's been 'Designed by Apple in California', and they know what they're not getting. But the PC market is completely different, and in a good way.
There's no official platform, hardware or vendor. There's massive variety, and whether you're buying a laptop or putting your PC together from components, you have a great deal of choice.

Removing choice 

Big Linux distributions like Fedora and Ubuntu are making their own arrangements for procuring the credentials to allow booting - the price isn't prohibitive, and it's a system managed by Verisign, not Microsoft. But it's causing a split, not just because people can't agree on the best approach, but because it's already creating friction.
The Free Software Foundation, for instance, criticised Ubuntu's plans use an Ubuntu-specific key for what the FSF calls Restrictive Boot, as well as Canonical's intention to drop the Grub bootloader over concerns that using it will break the terms of the GPL used to distribute.
But what about the smaller distributions, updates, unofficial re-spins and personal redistribution to friends? I don't understand why Secure Boot needs to have such draconian control over the PC. Why can't it be used only when booting Windows, for example, and who's naive enough to think that the keys won't be cracked or stolen, giving hackers an even softer back door into Windows than before?

Secure Boot isn't a solution, it's about control and it's removing choice from a platform that has always flourished because of it. Whether that was Microsoft capitalising on the rise of IBM-PC clones, or Linux undercutting UNIX when it appeared on x86. And to paraphrase Benjamin Franklin, those who sacrifice freedom for security deserve neither.

Friday, 2 November 2012

Early Windows 8 adoption '5X slower' than Windows 7

Only 0.45 per cent of all Windows machines 

 

Microsoft's new Windows 8 operating systme is only running on 45 out of every 10,000 PCs, according to new figures, putting adoption far below the initial Windows 7 uptake.
Data from the Net Applications company showed that, at the end of October, 0.45 per cent of total PCs were running Microsoft's latest OS.
That's compared to previous figures from the same company that showed 2.33 per cent of users had taken on Windows 7 following its launch at the end of October 2009.
However, the comparison is tempered by slightly differing launch dates. Windows 7 arrived on the Oct. 22 that year, while Windows 8 only went public on last Friday, Oct. 26.

Adoption anomaly

The four-day launch discrepancy aside, a rocket science doctorate isn't really necessary to produce a thesis on the anomaly, which suggests an early adoption rate five times lower than W8's predecessor.
It's been well documented that, when Windows 7 arrived in 2009, PC users were anxious to make the jump from the largely-disastrous Windows Vista or the ancient Window XP software.
However, it turns out people actually quite like Windows 7, are still enjoying it and may not be experiencing the same sense of urgency to upgrade.
There's also the newness of the Windows 8 experience to consider. Microsoft has "re-imagined" its operating system with the new Windows UI and potential upgraders may be experiencing trepidation at the prospect of learning new software.
However, Microsoft knows this is a marathon and not a sprint and will thus be blitzing televisions and web browsers with commercials in the run up to Christmas.

Wednesday, 24 October 2012

Windows 8 versions: which is right for you?

Explained The difference between Windows 8, Windows 8 Pro and Windows RT


With only two versions of Windows 8 to be available to consumers, plus one for ARM devices (pre-installed only), what you get ought to be straightforward.
But, as is usual with a new version of Windows, there's still room for confusion because what you get with each version overlaps slightly.

The three Windows 8 versions
Windows 8 (for x86, Intel/AMD)
Windows 8 Pro (for x86, Intel/AMD)
Windows RT (for ARM)

Windows 8

Windows 8 (yes, just Windows 8) is the home version for x86 Intel and AMD PCs. The features you do and don't get mostly make sense; joining a domain, encrypting your disk with BitLocker and being able to log into your PC remotely are business features.
You can connect to a PC at work from a Windows 8 system, with Remote Desktop or a VPN, you can combine multiple hard drives into one storage 'pool' that has multiple copies of your files and you can mount VHD and ISO images as if they were hard drives – but you can't boot from a VHD file.
And anyone who speaks more than one language or travels between countries will be delighted that you can switch not just the keyboard but the Windows interface from one language to another without paying extra.

Windows 8 Pro

What doesn't immediately make as much sense is that Media Center not included with Windows 8; it's "an economical media pack add-on" that's only available for Windows 8 Pro, which is otherwise for business users (or enthusiast users). Again, Windows 8 Pro is for for x86 Intel and AMD PCs.
Although Media Center has dedicated fans (around 50 of whom wrote to Windows head Steven Sinofsky to ask about the feature), only 6% of Windows 7 users ever launch it and only 25% of those use it for more than ten minutes at a time.
Microsoft has to pay licences for the codecs used in Media Centre, including Dolby technology. When the Developer Preview came out last September, Sinofsky commented that "the feedback about Media Center was predominantly "we will pay extra, just include it" based on the input directly to me," so it looks like Microsoft is taking users at their word.

Windows RT explained

All three versions of Windows 8 run Metro-style (also now known as Microsoft design style) applications written in WinRT, the new Windows RunTime programming framework, which is also what Windows RT is named for. Windows RT will come pre-installed on ARM devices like Microsoft Surface, you won't be able to install it yourself.
This is what was previously called Windows on ARM. It has both the Microsoft design style Start screen and the Windows desktop, with Task Manager and Explorer and support for multiple monitors (remember Windows RT devices won't be just tablets and they'll have connectors like HDMI).

But even though you get the desktop on Windows RT, you can't install desktop applications. It comes with ARM-specific versions of Office apps – but just Word, Excel, PowerPoint and OneNote, so if you want Outlook you need a PC with an Intel or AMD processor.

TOTAL VISITORS