News: 1638940510

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft extends Secured-core concept to servers

(2021/12/08)


Microsoft has extended the Secured-core concept it applied to PCs in [1]2019 to servers, and to Windows Server and Azure Stack HCI.

Secured-core sees Microsoft work with hardware manufacturers to ensure that their products include TPM 2.0 modules, ship with Secure Boot enabled by default in BIOS, and use the Dynamic Root of Trust for Measurement tech that allows use of Intel's Trusted Execution Technology (TXT) and AMD's Secure Virtual Machine (SVM).

Once those elements are in place, Microsoft is confident hardware is harder to compromise with firmware-based attacks, and is less susceptible to running unverified code.

[2]Microsoft's Teams Essential tier seems designed to coax people on to Business Basic

[3]Cisco deprecates Microsoft management integrations for UCS servers

[4]Power management IC shortage holding cars, laptops, hostage

Redmond's [5]announcement of Secured-core servers explains that its approach buttresses defences against threats such as ransomware because it employs Hypervisor-Protected Code Integrity (HVCI) – a tech that only allows signed executables from known good sources to run.

The Mimikatz password-dumping tool – a favorite of attackers seeking to plant ransomware – fiddles with the Windows kernel as it works. Microsoft reckons a Secured-core server running HVCI will spot it at work and make ransomware scum's life harder. This is no bad thing.

[6]

Secured-core PCs are not hard to find. Just about [7]every leading vendor offers such a configuration.

[8]

At the time of writing, Microsoft lists [9]42 servers that meet the spec when running Windows Server, plus [10]four systems to run Azure Stack HCI.

Microsoft's post also indicates that Azure-certified IoT devices can use the Secured-core spec. ®

Get our [11]Tech Resources



[1] https://www.theregister.com/2019/10/22/microsoft_securecore_pcs/

[2] https://www.theregister.com/2021/12/01/teams_essentials/

[3] https://www.theregister.com/2021/10/27/ucs_intergration_deprecatoin/

[4] https://www.theregister.com/2021/12/07/car_ic_shortage/

[5] https://www.microsoft.com/security/blog/2021/12/07/new-Secured-core-servers-are-now-available-from-the-microsoft-ecosystem-to-help-secure-your-infrastructure/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YbCQXxthMGuddmMhevUNoAAAAFg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[7] https://www.microsoft.com/en-us/windows/business/devices?col=secured-core-pcs

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbCQXxthMGuddmMhevUNoAAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.windowsservercatalog.com/results.aspx?&bCatID=1333&cpID=0&avc=10&ava=0&avt=0&avq=140&OR=1&PGS=25&PG=1

[10] https://hcicatalog.azurewebsites.net/#/catalog?FeatureSupported=securedCoreServer

[11] https://whitepapers.theregister.com/



from known good sources....

Anonymous Coward

Bullshit. What it means is that malicious code will run when it has been signed by a pilfered code-signing certificate.

While that's true

Richard 12

It does raise the bar a little.

The real elephant is of course the certificate store.

Alumoi

So now we'll have only Microsoft approved software? Looking forward to it. Not.

phuzz

We already had Microsoft approved software, that's what's in the Windows Store, and clearly the bar is pretty low (it's mostly rip-offs of existing programs).

TFA is about Microsoft approved hardware .

Ever feel like life was a game and you had the wrong instruction book?