Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Hack Windows RT to Run any Desktop App

microsoft-surface
The security mechanism preventing unauthorised software running on ARM-powered Windows RT tablets - such as Microsoft's Surface slabtops - can be easily defeated.

The Redmond giant wanted only cryptographically signed executables, ideally those obtained from the official Windows application store, to run on its hardware. But, we're told, by twiddling a byte of memory in the Windows kernel, it is possible to disable the protection system and allow any code to run on the system.

Taking full control of the device, effectively jail-breaking the computer to run any desktop or touch-driven ARM-compatible software, is an exercise left to the user.

A security researcher calling him or herself C. L. Rokr claims to have found an oversight in the Windows kernel to allow this to happen. According to Rokr, all you have to do is fire up the Windows Debugger software with Administrator-level permissions, connect it to the tablet and manipulate the device's kernel memory.

Specifically, one needs to inject a blob of ARM code into a safe spot of RAM and have the Windows RT kernel divert the processor momentarily to run these instructions. This code locates and alters a moderately hidden variable in the kernel to disable the executable signature check. On PCs the variable contains '0' allowing any program to run, whereas it is '8' on Windows RT devices to enforce the signature check.

Trivially overwriting this byte can therefore change the level of protection on the system and circumvent Microsoft's cryptographic keys.

You can read more about the hack along with a how-to guide here.

Windows RT, which is a straight-up ARM port of Windows 8 for portable computers, was built to only run apps that are signed using a Microsoft-issued certificate.

The hack is unlikely to be something most non-techie users could pull off as it requires knowledge of WinDbg. And modifying the operating system could fall foul of the device's secure boot protection, which refuses to start the OS if it has been altered.

It's also not clear which apps can be run, although as pointed out in this programming forum the software must be compiled for, or otherwise be compatible with, ARM-powered systems. Programs already built for Intel and AMD processors need not apply, therefore.

Windows RT can be found on Microsoft's Surface tablet and fondleslabs from companies including Asus and Samsung. So far it appears sales of Windows RT devices are low and below Microsoft's expectations. Redmond has quickly turned from only selling Surface itself online and in its stores to recruiting retail partners.

One reason for the lack of interest could be lack of apps. Windows RT has been deliberately locked down because, we're told, Microsoft wants to maintain a standard of performance and security, and to ensure apps conform to the design of the interface and input via touch. This means the number of Windows RT apps is far behind the number of apps that exists for Intel machines running the exact same operating system.

Devices using Windows RT come with some built-in apps including Office Home and Student 2013 RT Preview Edition and Mail, Messaging and SkyDrive, but the official way to obtain more is via Microsoft's Windows Store, which supplies suitably signed executables.

Microsoft Releases So.cl Network to the Public

so.cl-microsoft.PNG
Microsoft’s "experiment in open search", so.cl, is now open to anyone.

Launched back in May amidst very little fanfare, so.cl (pronounced "social") was initially offered only to students and billed as an experiment in learning.

Redmond has recanted those restrictions, today telling world+dog they’re free to pile in and enjoy the fun, as so.cl is now "a service where people connect over shared interests."

So.cl is rather unlike other social networks inasmuch as a post starts with a search. The results of that search can then be assembled into a post that brings together the user’s desired elements.

Many users post just a single image. Others take a more curatorial approach, collecting several images related to the same topic in a fashion not entirely unlike creating a Pinterest collection.

Redmond’s not building a walled garden, as Facebook is a permitted login mechanism and so.cl’s About page states it is not in competition with other social networks.

Socl — pronounced social — allows you to express and share your ideas through rich post collages comprised of images, links, captions and videos.
"Socl is a research project from Microsoft Research FUSE Labs and began as an experiment in social search targeted at students for the purpose of learning. Following the lead of the Socl community, Socl has since evolved to be a service where people connect over shared interests expressed through beautiful posts that take only seconds to create", says Microsoft.
Whether Redmond will be still be saying that if, or when, it embeds a so.cl tile in the default Windows 8 start screen remains to be seen.

Microsoft Surface Priced: 32GB For $499 Without Touch Cover, $599 With; 64GB For $699

Microsoft's Surface tablet pricing has been outed by the software giant.

Earlier today, Surface pricing was posted on the Microsoft Store online site. Not long after, the page was taken down, seemingly because the pricing information was put up on the site before it was supposed to go live.


Based on that screenshot, it appears Microsoft will sell its Surface with Windows RT for a starting price of $499 with 32GB of storage and a Touch Cover. Those who want a Touch Cover included in the order will need to set aside $599 for the device. Adding an additional 32GB of storage will push the Surface's price up to $699.

Microsoft unveiled its Surface tablet earlier this year. The RT version comes with a 10.6-inch screen and a 1,280 x 720 resolution. The device is expected to be Wi-Fi-only, and its Touch Cover add-on works as a screen protector, stand, and keyboard. Surface for Windows 8 Pro is expected to launch after the Windows RT version, and will come with a "full HD" 1080p screen resolution. That device will likely be more expensive than the Windows RT model.

Windows 8 is scheduled to launch on October 26. Windows RT, which will be running on the Surfaces leaked on the store site, will run on ARM processors. Microsoft will also sell Windows 8, Windows 8 Pro, and Windows 8 Enterprise versions. Those models are not compatible with ARM-based chips.

German Goverment Urges Everyone to Stop Using Internet Explorer

Following the recent bug  that was discovered in Internet Explorer 6, Internet Explorer 7, Internet Explorer 8 and Internet Explorer 9 which makes PC's vulnerable to attack by hackers, the German government advised the public on Tuesday to stop using the browser temporarily.


The security flaw, which affects hundreds of millions of Internet Explorer browser users around the globe, publicly surfaced over the weekend.

Microsoft had said on Monday that attackers can exploit the bug to infect the PC of somebody who visits a malicious website and then take control of the victim's computer.

The German government's Federal Office for Information Security, or BSI, said that it was aware was aware of targeted attacks and that all that was needed was to lure web surfers to a website where hackers had planted malicious software that exploited the bug in Internet Explorer to infect their PCs.

"A fast spreading of the code has to be feared," the German government said in its statement.

BSI advised all users of Internet Explorer to use an alternative browser until the manufacturer has released a security update.

Officials with Microsoft did not respond to a request for comment on the move by the German government.

The company late on Monday urged customers to install a piece of security software as an interim measure, buying it time to fix the bug and release a new, more secure version of Internet Explorer.

Microsoft did not say how long that will take, but several security researchers said they expect the update within a week.

The free security tool, which is known as the Enhanced Mitigation Experience Toolkit, or EMET, is available through an advisory on Microsoft's website: blogs.technet.com/b/msrc/

The EMET software must be downloaded, installed and then manually configured to protect computers from the newly discovered threat, according to the posting from Microsoft. The company also advised customers to adjust several Windows security settings to thwart potential attackers, but cautioned that doing so might impact the PC's usability.

Some security experts had said it would be too cumbersome for many PC users to implement the measures suggested by Microsoft. Instead they advised Windows users to temporarily switch from Internet Explorer to rival browsers such as Google Inc's Chrome, Mozilla's Firefox or Opera Software ASA's Opera.

Internet Explorer was the world's second-most widely used browser last month, with about 33 percent market share, according to StatCounter. It was close behind Chrome, which had 34 percent of the market.

Microsoft Secure Boot Firmware may Block Linux Booting

Windows-8-Linux
Computer scientists warn that proposed changes in firmware specifications may make it impossible to run “unauthorised” operating systems such as Linux and FreeBSD on PCs.

Proposed changes to the Unified Extensible Firmware Interface (UEFI) firmware specifications would mean PCs would only boot from a digitally signed image derived from a keychain rooted in keys built into the PC. Microsoft is pushing to make this mandatory in a move that could not be overridden by users and would effectively exclude alternative operating systems, according to Professor Ross Anderson of Cambridge University and other observers.

UEFI is a successor to the BIOS ROM firmware designed to shorten boot times and improve security. The framework, a key part of Windows 8, is designed to work on a variety of CPU architectures.

If the draft for UEFI is adopted without modification, then any system that ships with only OEM and Microsoft keys will not boot a generic copy of Linux. A signed version of Linux would work, but this poses problems, as tech blogger Matthew Garrett explains.

Garrett writes:

Firstly, we'd need a non-GPL bootloader. Grub 2 is released under the GPLv3, which explicitly requires that we provide the signing keys. Grub is under GPLv2 which lacks the explicit requirement for keys, but it could be argued that the requirement for the scripts used to control compilation includes that. It's a grey area, and exploiting it would be a pretty good show of bad faith.

Secondly, in the near future the design of the kernel will mean that the kernel itself is part of the bootloader. This means that kernels will also have to be signed. Making it impossible for users or developers to build their own kernels is not practical. Finally, if we self-sign, it's still necessary to get our keys included by ever OEM.

There's no indication that Microsoft will prevent vendors from providing firmware support for disabling this feature and running unsigned code. However, experience indicates that many firmware vendors and OEMs are interested in providing only the minimum of firmware functionality required for their market.

Garrett concluded that there is no need to panic just yet.

The upshot of the changes is that considerable roadblocks might be placed in the way of running alternative operating systems on PCs. Anderson describes this as a return to the rejected Trusted Computing architecture – which at that point involved force-feeding DRM copy-protection restrictions – which may be far worse than its predecessor.

The professor said:

These issues last arose in 2003, when we fought back with the Trusted Computing FAQ and economic analysis. That initiative petered out after widespread opposition. This time round the effects could be even worse, as 'unauthorised' operating systems like Linux and FreeBSD just won’t run at all. On an old-fashioned Trusted Computing platform you could at least run Linux – it just couldn’t get at the keys for Windows Media Player.

The extension of Microsoft’s OS monopoly to hardware would be a disaster, with increased lock-in, decreased consumer choice and lack of space to innovate.

Anderson concludes that the technology might violate EU competition law in a rallying call on Cambridge University's Light Blue Touchpaper blog here.