Motherboards
  Home arrow Motherboards arrow Page 3 - Secure Startup: Microsoft in Your Moth...
Dev Hardware Forums 
Computer Cases  
Computer Processors  
Computer Systems  
Digital Cameras  
Flat Panels  
Gaming  
Hardware Guides  
Hardware News  
Input Devices  
Memory  
Mobile Devices  
Motherboards  
Networking Hardware  
Opinions  
PC Cooling  
PC Speakers  
Peripherals  
Power Supply Units  
Software  
Sound Cards  
Storage Devices  
Tech Interviews  
User Experiences  
Video Cards  
Mobile Linux 
APP Generation ROI 
IBM® developerWorks 
Weekly Newsletter
 
Developer Updates  
Free Website Content 
 RSS  Articles
 RSS  Forums
 RSS  All Feeds
Write For Us Get Paid 
Request Media Kit
Contact Us 
Site Map 
Privacy Policy 
Support 
 USERNAME
 
 PASSWORD
 
 
  >>> SIGN UP!  
  Lost Password? 
MOTHERBOARDS

Secure Startup: Microsoft in Your Motherboard
By: Developer Shed
  • Search For More Articles!
  • Disclaimer
  • Author Terms
  • Rating: 3 stars3 stars3 stars3 stars3 stars / 38
    2005-06-01

    Table of Contents:
  • Secure Startup: Microsoft in Your Motherboard
  • What Secure Startup Does
  • What Secure Startup Wrecks
  • What Microsoft Wants

  • Rate this Article: Poor Best 
      ADD THIS ARTICLE TO:
      Del.ici.ous Digg
      Blink Simpy
      Google Spurl
      Y! MyWeb Furl
    Email Me Similar Content When Posted
    Add Developer Shed Article Feed To Your Site
    Email Article To Friend
    Print Version Of Article
    PDF Version Of Article
     
     
    ADVERTISEMENT


    Secure Startup: Microsoft in Your Motherboard - What Secure Startup Wrecks


    (Page 3 of 4 )

    There are a lot of questions about what Secure Startup will allow and what it won't. Linux users are understandably wary of this technology. Would Microsoft and the other members of the Trusted Computing Group design a system that doesn't allow Linux to load since the hardware is looking for Windows? I'm sure Microsoft would smile at the idea, but it's not likely they would do this. Besides the legality of blocking competitors, Microsoft probably wants to stay on good terms with companies that use Windows desktops and open source servers.

    More concerning though is whether this feature will interfere with systems that dual-boot both Windows and Linux. This feature will not necessarily bother dual loading programs; the dual loader will be accessible as it is on the Linux partition, and the SYSKEY should not be necessary unless loading Windows. Linux should boot fine, but the Windows disk will be entirely inaccessible. If booting Windows, it will go through the authentication process with the TPM and probably gain the SYSKEY to unlock itself. The only thing that would stand in the way is whether or not the authentication would be denied for having a boot loader in the startup. If not, remember that Secure Startup can be turned off.

    Managing computers will become a bit more difficult to manage. Microsoft really had to make this feature optional; otherwise upgrading and troubleshooting computers would become nearly impossible. As it looks now, people who want the feature are going to need to remember to deactivate it before changing hardware around, especially hard drives and motherboards, and to reactivate it once the system is done changing. Pulling a drive out and putting into another computer for a virus scan or to move over files will require performing that extra step. Giving away a drive or installing a new one will require a little extra work too. Booting changed computer will fail if users forget to do this, which would force them to change all the hardware back to the original state and start over.

    The real problem areas arise from hardware failures. Motherboards die sometimes, or they can cause problems that prevent the operating system from loading or functioning stably. With Secure Startup activated, this could be devastating. Say the motherboard completely goes while the feature was activated. The only place that SYSKEY exists is in the unusable motherboard, so your Windows disk may be unbootable unless you wipe the drive clean and start all over. This would be devastating to anyone that has anything on their hard drive that they're attached to. And if Microsoft made a fix-it tool for extracting the SYSKEY from the TPM, it would negate the purpose of the entire Trustworthy Computing project. Anyone who would be vaguely troubled by losing all their data should consider opting out of this feature.

    For corporate networks, this may be a different issue though. Microsoft says, "Recovery passwords and keys can be stored in the Active Directory. Therefore, users can call their corporate helpdesk or administrator who has recovery key access for assistance with system reactivation." General computer or laptop users will not have this sort of helpdesk support as their keys and passwords will be stuck only in the TPM. This makes Secure Startup more reliable for large networks granted that they are using Microsoft's Active Directory, part of the Windows Server. If Active Directory is in fact the only option, this is one of the concerns that NGSCB opponents fear; users might be coerced into a less competitive market in order to run a system properly, since Microsoft will probably only allow a limited number of programs be trustworthy.

    More Motherboards Articles
    More By Developer Shed


       · SOunds like a boon to Admins, but at what cost? How much more, I wonder, will the...
       · Thanks for your interest in the article. My guess is that secure motherboards can't...
     

    MOTHERBOARDS ARTICLES

    - Intel Nehalem Boards Compared
    - ABIT Fatal1ty F-I90HD
    - Intel Media Series DG33TL
    - Biostar TA690G
    - EVGA 680i LT SLI
    - ASUS P5N-E SLI
    - Biostar TForce TF570 SLI
    - ABIT IP35-E
    - EPoX EP-AT690G Pro Motherboard Review
    - EPoX EP-8U1697-GLI Motherboard
    - EPoX EP-9U1697-GLi Motherboard Review
    - Foxconn 955X7AA, Intel LGA 775 Motherboard R...
    - PC Partner ATI Xpress 200 Review
    - Foxconn Winfast NF4SK8AA-8EKRS Motherboard R...
    - Epox 5LDA+GLI Motherboard Review






    © 2003-2010 by Developer Shed. All rights reserved. DS Cluster 6 Hosted by Hostway
    For more Enterprise Application Development news, visit eWeek