Sinistraverso
  • Communities
  • Multi-communities
  • Support Lemmy
  • Search
  • Login
  • Sign Up
Technology@lemmy.worldbybeep@piefed.world
20 days

Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

www.welivesecurity.com English

cross-posted from: https://piefed.world/c/tech/p/1263218/microsofts-secure-boot-has-been-broken-for-a-decade-and-no-one-noticed-until-now

7
    Forgotten UEFI shims undermining Secure Boot
    www.welivesecurity.com
    ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities.
    You must log in or register to comment.

    • Kongar@lemmy.dbzer0.comEnglish
      20 days

      Unpopular opinion but I’m dying on this hill. Secure boot creates more problems than it solves.

        • JiveTurkey@lemmy.worldEnglish
          20 days

          I’d argue this is actually a popular opinion. IMO secureboot has just become a way for Microsoft to leverage it’s position and keep a strangle hold on industries they have no business being in.

          The whole kernel level anti-cheat on win11 bullshit in the gaming industry is a good example. Essentially locking games to its platform and willing to sacrifice security to do so at our expense.

            • Default Username@lemmy.dbzer0.comEnglish
              20 days

              This is especially true on computers where it is impossible to change the signing keys. Smartphones, game consoles, many laptops, some desktops, smart TVs, IoT devices, modern cars, etc.

          • A_norny_mousse@piefed.zipEnglish
            20 days

            11 old and forgotten UEFI shim bootloaders at versions 0.9 and below that can be used to bypass UEFI Secure Boot on any UEFI-based machine that trusts Microsoft’s Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CA) certificate, regardless of the installed operating system (OS).

            This “Trust” is one of my pet peeves. It’s $$$.

              • naticus@lemmy.worldEnglish
                20 days

                I get why you’d dislike that wording, but this is also how all certificate stores work, regardless of whether we’re talking Secure Boot, Windows or Linux. Gotta trust the top level as providing legitimate certificates to then trust everything underlying as coming from the correct parties.

                Certificate are something I work with constantly at work and I fucking hate resolving issues with them lol.

              • CriticalMiss@lemmy.worldEnglish
                20 days

                Arch Wiki had pointed out for years that Secure Boot is a flawed mechanism.

                  • black0ut@pawb.socialEnglish
                    19 days

                    It’s not flawed at all. But its purpose isn’t actually to secure anything. Its purpose is to complicate the installation of alternative OS and to perpetuate vendor lock in, while sounding like it’s “for your security”. In that regard, it has succeeded.

                    There is also TPM and Microsoft Pluton, which serve the same purpose.

                  Technology@lemmy.world

                  technology@lemmy.world

                  Subscribe from remote instance

                  Create post

                  Report community

                  Modlog
                  You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

                  This is a most excellent place for technology news and articles.


                  Our Rules


                  1. Follow the lemmy.world rules.
                  2. Only tech related news or articles.
                  3. Be excellent to each other!
                  4. Mod approved content bots can post up to 10 articles per day.
                  5. Threads asking for personal tech support may be deleted.
                  6. Politics threads may be removed.
                  7. No memes allowed as posts, OK to post as comments.
                  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
                  9. Check for duplicates before posting, duplicates may be removed
                  10. Accounts 7 days and younger will have their posts automatically removed.

                  Approved Bots


                  • @L4s@lemmy.world
                  • @autotldr@lemmings.world
                  • @PipedLinkBot@feddit.rocks
                  • @wikibot@lemmy.world
                  Visibility: Public

                  This community is visible to everyone.

                  • Unknown language
                  • Italiano
                  • 650 users / Day
                  • 8.44K users / Week
                  • 11.3K users / Month
                  • 11.4K users / 6 months
                  • 1.01K posts
                  • 14.8K comments
                  • 1 local subscriber
                  • 86.8K subscribers
                  • Mods:
                  • L3s@lemmy.world
                  • UI: -nightly-2026-08-02
                  • BE: 1.0.0-nightly-2026-08-04
                  • Modlog
                  • Instances
                  • Docs
                  • Code
                  • join-lemmy.org