|
Visit Our E2 Forums |
Education |
Financial Services |
Government |
Healthcare |
Manufacturing |
Retail
New! Focus on: End User Computing
|
||||||
Prepping for Secure Boot in Windows 8Sara Peters, Editor in Chief | 12/20/2012 |
A rootkit is a right nasty piece of malware. You'd be wise to do whatever you can to keep rootkits out of your IT ecosystem.
Secure Boot, a security feature included in both Windows 8 and Windows Server 2012, can do an admirable job of finding, containing, and eliminating rootkits... but only if you keep it enabled. Unfortunately, there are a few reasons you might be tempted to disable it. During the boot process, Secure Boot will scan your machine for any kernel-mode drivers. If those drivers have not been signed by a trusted certificate authority, then the operating system will simply not allow those drivers to run. This is excellent news if one of those unsigned drivers is actually a rootkit -- a particularly invasive type of malware that gives the attacker root access to your machine, thereby allowing them to do pretty much anything they want. A rootkit might infect your machine via a common attack vector, such as a phishing message, nestling itself into your kernel without your having a clue. Or, it might come in the back end, being directly loaded onto the machine by a sinister individual who has physical access to the hardware. Regardless of how it makes its way onto the system, Secure Boot will stop that rootkit in its tracks during the boot process (assuming the rootkit hasn't falsely obtained a valid certificate, that is).
Window 8 and Windows Server 2012 Certficates One of the complaints against Secure Boot from the Linux user community is that it prevents a user from booting up Linux on a Windows 8 machine. The Linux Foundation has been waiting for Microsoft to hand over a validly signed pre-boot loader -- which would tell Windows 8 that it's safe to load up Linux. In the meantime, the Linux community developed a workaround, but it's a very clunky process.
Sure, you can disable Secure Boot. But you'd be missing out on a great security mechanism that:
These features give Secure Boot the potential to be pretty special. So, instead of disabling Secure Boot altogether, it's worth spending some time taking a close look at all your drivers before you decide to make the jump from one operating system to another. Identify all the drivers that access the kernel, and check to see if they've been signed by a trusted certificate authority. If the answer is no, then you might want to hold off on a migration until the answer is yes. The blogs and comments posted on EnterpriseEfficiency.com do not reflect the views of TechWeb, EnterpriseEfficiency.com, or its sponsors. EnterpriseEfficiency.com, TechWeb, and its sponsors do not assume responsibility for any comments, claims, or opinions made by authors and bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose. |
More Blogs from Sara Peters
Sara Peters 5/14/2013
Essay-grading software might be very useful... just maybe not for grading essays.
Sara Peters 5/8/2013
Cue Queen's "We Are the Champions." It is time to crown the winner of the E2 Tournament of IT Revolutionaries. The crown, the mantle, the scepter, the glory, and the responsibility go ...
Sara Peters 5/2/2013
Collaboration, creativity, and change were common themes throughout this week's mid-year conference of the National Association of State CIOs.
Sara Peters 5/1/2013
Two weeks ago, Michael Gliedman, CIO of the National Basketball Association (NBA), joined us for a live video discussion about the NBA's new big-data project. Gliedman explained why and ...
Sara Peters 4/26/2013
The controversy over House Resolution 624, the proposed Cyber Intelligence Sharing and Protection Act (CISPA), isn't entirely much ado about nothing, although it's close.
Latest Archived Broadcast
Data visualization can make complex data easier to grasp. Our expert guest will talk about the hows, whys, and whats of bringing the big picture to your enterprise.
On-demand Video with Chat
NBA CIO Michael Gliedman will tell us why the NBA decided to create NBA.com/stats
6/18/2013 -
Please join us for the "IT Convergence Strategies: Why, When and How " to learn more about:
• 5 truths about infrastructure convergence today that go beyond the hype
• How to exploit the 4 phases of convergence maximum efficiency and agility
• Key milestones to plan for on the convergence journey
• Why integrated management is a critical component of convergence plans
• The importance of an open, modular approach, such as Dell’s active infrastructure, to building a converged data center
E2 IT Migration Zones
Office 365 Finds Fans
Cutting Through the Modern App Confusion
Microsoft Hints at Changes to Windows 8
S’équiper ou non d’un logiciel anti-virus ?
Microsoft passe au facteur deux
Windows Azure Infrastructure Services est disponible !
Microsofts Surface Pro kommt nach Deutschland
Zum Schmunzeln: drei neue Werbeclips für Windows 8
Like Us on Facebook
Dell IT Insights
![]() ![]() Site Moderators Wanted
Enterprise Efficiency is looking for engaged readers to moderate the message boards on this site. Engage in high-IQ conversations with IT industry leaders; earn kudos and perks. Interested? E-mail:
moderators@enterpriseefficiency.com The major problem facing the CIO is how to measure the effectiveness of the IT department. Learn how Dell’s Efficiency Modeling Tool gives the CIO two clear, powerful numbers: Efficiency Quotient and Impact Quotient. These numbers can be transforma¬tive not only to the department, but to the entire enterprise. Read the full report Virtualization is a presence in nearly all enterprise data centers. But not all companies are using it to its best effect. Learn the common characteristics of success, what barriers companies face, and how to get the most from your efforts. Read the full report Cut through the VDI hype and get the full picture -- including ROI and the impact on your Data Center -- to make an informed decision about your virtual desktop infrastructure deployments. Read the full report SPONSORED BY DELL
BRIEFINGS
CASE STUDIES
EBOOKS
PUBLIC SECTOR RESOURCES
VIDEOS
WHITE PAPERS
A Video Case Study – Translational Genomics Research Institute e2 Video
|
|||||
|
|
||||||