Bonum Certa Men Certa

“Wintel” “Secure” uEFI Firmware Used to Store Persistent Malware, and Security Theater Boot is Worthless

Guest post by Ryan, reprinted with permission from the original

Free space

PCMag now reports (And calls out Windows! Good!) that the situation where persistent rootkit malware that doesn’t really need anything except to run once, somehow, on a Windows machine, is now being installed into the system’s uEFI firmware, where it will survive what most Windows users end up doing every time their computer ends up acting weird….nuking Windows and re-installing from scratch.



It was already so much easier for Microsoft to include “Reset this PC” than it was to fix Windows that this has been a staple for the past decade. It sometimes works, unless something has also corrupted the WIM installer image on the recovery partition, which also takes up precious SSD space.



However, with the latest threat to Windows users, which uEFI made possible (as bootkits on legacy BIOS were unheard of), no matter how many times you re-install Windows, no matter whether or not TPM or Secure Boot are on and enforced, it won’t matter. The malware isn’t running in a part of your computer that is subjected to any sort of auditable behavior.



Therefore, the only way to prevent a foothold situation is to get rid of Windows now, while it may not be too late, and replace it with GNU/Linux.



Again, most people find that their “must have” Windows software works in Wine. Sometimes Wine even resurrects programs that Windows itself has been incompatible with or partially broke years ago.



Instead of fixing Windows, Microsoft spends billions in “shadow advertising” to pay “freelance” writers to make “Linux” sound like a security disaster too, so there’s this “false equivalence” in the user’s mind.




My dad used to do the same thing to my mother when she threatened to divorce him. “You know if you leave me, your cancer will come back and there won’t be anyone to help you with that. The kids won’t be able to come back and live with me because I won’t have them”.



Like, here’s the biggest dickhead in the world, right? And mom’s 64 now and she’s fine, and I’m pushing 40, will be 40 in a couple years and some change and I’m fine, right? Bullies always use threats which turn out to be puffery. They want you to think they’re all powerful. And their antics usually get worse as they lose power.



So we should see that Microsoft is acting from a position of weakness.



There’s this whole Truman Show thing going on right now they’re up in the tower panicking because he finally realizes everything around him is fake and he needs to leave, and he finally decides to escape the island.



So all of a sudden there’s a fake nuclear power plant meltdown, and actors getting in the way of his car, and a wind storm being generated on the lake to try to scare him into giving up and thinking he was crazy, and going back to the show. And up until that point, every time he started to question the nature of things, they could always increase his fear of the unknown to overcome his curiosity, or his need to grow. And that’s exactly how abusers operate.



The very act of porting Microsoft Pretender to “Linux” is a part of this psyop.



They fund nasty trolls to imply that there is a remote technical possibility of targeting GNU/Linux users. (Technically possible, but much, much more difficult and far less pay off.)



I have another post coming about that, very shortly.



Just using some back of the napkin math, however, Windows is more than 10 times bigger than GNU/Linux after a fresh install as measured by disk footprint.



Secunia wrote in 2014 that the defect density for open source code was 0.59 defects per 1,000 lines, and for proprietary it was 0.72.



(The bonus in their reports is that the one from the prior year showed that C++ projects tended to be a much bigger security mess than C. Linux the kernel is almost entirely C. Linus was right!)



So if you assume that there’s about 10 times as much source code in Windows (which is amazing, considering that the built-in apps are useless and you don’t get a free fully-featured operating system, only SKUs with various parts of the OS disabled, and most people will try to get a different web browser, LibreOffice, and VLC anyway), and you give Microsoft the benefit of the doubt and assume they’re not writing garbage that’s even worse than the proprietary software average (LOL), there’d still be well over 12 times as many bugs in the Windows operating system as in GNU/Linux, even though Windows doesn’t have good features and quality software included.



(It usually comes with a lot of crapware from the OEM though, and that’s a totally different story, and makes the situation worse.)



There absolutely is a security cost to leaving a ton of garbage laying around and no good security practices for software installation and package management (just a failed crApp Store with fake apps and junk), and Windows “users” (useds) are paying this price every day.



Wisdom comes by seeing bullshit, calling bullshit, and refusing to be a part of the bullshit. Software is getting to be so tertiary to what Microsoft even does to make money.



What they seem to do these days boils down to spawn camping “Linux” while they don’t even use Windows internally that much anymore, in favor of “Linux”, and suing Android OEMs -or- offering to cram pack your new phone with pestware that demands to connect to Microsoft. (Samsung)



I’m heartened that the “news” is starting to rebel against this disgusting spectacle that’s going on around Microsoft Edge lately and is no longer just calling Windows bugs a “PC problem” in every article. Hopefully, the more Microsoft tightens their grasp, the more things slip through their fingers.



Recent Techrights' Posts

Microsoft Windows Falls to All-Time Low of ~60% in Switzerland, GNU/Linux Among Top Gainers
What will it take for mainstream media (not just geeks' site) to cover it?
 
Culture of Harassment Inside Microsoft, Says Former Director at Microsoft
listen to Microsoft insiders
Drone Strikes on Amazon (GAFAM) Datacentres Highlight Azure's Miniscule Share
Azure is failing
SLAPP Censorship - Part 35 Out of 200: How to Make ~10,000 Pound Sterling (13,220.50 United States Dollars) by Copy-Pasting and Editing 10 Pages
Today it's Easter Sunday, so we'll keep this part relatively short
Gemini Links 05/04/2026: Artemis II Mission Tracker, Meditation on Copyright, Alhena 5.5.5, "Gemini as the Final Frontier of Human Cognition"
Links for the day
Mainstream Media on "Practical Survivalism"
Suffice to say, panic buying begets more panic and price surges
Cloud Computing as a Cloud of Smoke (Your Hosting Provider is a "Legitimate" Military Target)
When a French datacentre went up in flames people joked that the "cloud" meant a cloud of smoke
Andreas Tille Congratulates Sruthi Chandran Before the Election for Debian Project Leader (DPL) is Even Over
Andreas Tille, the current Debian Project Leader (DPL) who has been in this role for nearly 24 months
When You Try to Change the World for the Better and Somehow They Find a Way to Say You Are the Villain
Don't be a fool. Don't fall for inversions of narratives.
Slop Was a Flop and Energy Crisis Will be Slop's Final Blow
Today we see no slopfarms in Google News
Links 05/04/2026: "Taiwanese Airlines to Hike Fuel Surcharges 157%" and Openly Racist Voter Suppression Starts in the US
Links for the day
Gemini Links 05/04/2026: Playing with Hyprland and Migrating Antenna Filters
Links for the day
Links 05/04/2026: "Confidential Computing" as Proprietary Bundle of False Promises and "The Web Is an Antitrust Wedge"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, April 04, 2026
IRC logs for Saturday, April 04, 2026
SLAPP Censorship - Part 34 Out of 200: The Necessity of Transparency, Illuminating Garrett's and Graveley's 'Tag-Team' Act, Misusing the British Docket (From Far Away in America) in Efforts to Hide Bad Behaviour
Transparency is paramount
Red Tape at Red Hat (IBM)
Now the guiding principles are the whims and moods of people who peddle buzzwords to manipulate IBM's share prices
The So-called 'AI' (Slop) Companies Will Have the Plug Pulled
It can vastly accelerate this bubble's implosion
Dr. Andy Farnell on a "Technology Plan B"
based around Free software
Windows Lows Across the Mediterranean
Judging by this month's data from statCounter
The Future of the Net is 'in Space'
Gemini Protocol is growing and GemText remains the same, so it's made to endure
Linux Foundation Profits From Scams, Fraud, and Grifting
Don't be misled by the name "Linux Foundation"
Too Hard for IBM to Keep Everybody Silent About How the Company Has Gone South
IBM is busy trying to keep disgruntled or ex workers silent using NDAs
Microsoft Transmits Malware and Back Doors to GNU/Linux Servers, Media Points the Finger at Everyone But Microsoft's Servers
Is Microsoft too poor to vet and check what it hosts and transmits?
Gemini Links 04/04/2026: "Fuzz Guy", "Reusing Old Computers with Arch Linux and DWM", and Bubble v10.0 Released
Links for the day
Links 04/04/2026: eBay Scam, "Music Publishers’ X Copyright Lawsuit Officially on Pause"
Links for the day
Links 04/04/2026: Social Control Media Verdict and Bans, Whistleblower (Axel Rietschin) Explains How "Microsoft Vaporized a Trillion Dollars"
Links for the day
Reaching the End/Event Horizon of LLM Slop
Are we moving towards a post-LLMs world?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, April 03, 2026
IRC logs for Friday, April 03, 2026
Gemini Links 04/04/2026: STXGE and Computer Relationships
Links for the day
SLAPP Censorship - Part 33 Out of 200: Garrett Sued by My Wife and I, Then His Microsoft Acquaintance Files Another Lawsuit and Our Webhost Receives Legal Threats Too
Today we also show how our solicitor Mark Lewis responded to it
Good Friday, Leaving IBM for Good
Even on holidays
Links 03/04/2026: Rejection of More Software Patents and Social Control Media in Several Continents
Links for the day
Malware in Proprietary Software - Latest Additions by Rob Musial
Original published yesterday in gnu.org
Visual Evidence/Documentation of IBM Dying Like the Dinosaurs
IBM has many of these giant white elephants lying around, with some getting demolished
Links 03/04/2026: USPTO’s Latest Greenwashing and Internet Blackouts Impact Journalists in War Zones
Links for the day
SLAPP Censorship - Part 32 Out of 200: Garrett Made Spurious Requests (Later Withdrawn) the Same Week Someone He Later Spoke to by E-mail Sent Threats to Our Webhost
The "plot thickens" because there's a multi-party tag-team act, as confirmed by Garrett after he had sworn on the Bible
IBM is a Dying Company, Nowadays It Kills Red Hat With Slop
when your last day is a national holiday in IBM's country
"Independence Drives" and Community-Run Sites
Independence in reporting is a much-valued trait
When Charlatans Are Only Good at Losing Money and Storytelling (e.g. About Investment in Them)
Wait till a a barrel of oil costs $300
What Apple Fans Are Missing
Apple is a bad company
The "Pale Blue Dot" Moment Had Returned
To many people, the "bitter-sweet" observation of how small we are
Saudi Arabia Does Not Rely Much on Microsoft/Windows
Putting aside politics, this is good for Free software
Almost 12 Years of Exposing Corruption in Europe's Second-Largest Institution
The "unready" President is now an abandoned President
Easter Moon Mission and Its Reminder of IBM's Demise
A lot of NASA operations now rely on GNU/Linux
When Power is Scarce and GNU/Linux Has Power
In Cuba, GNU/Linux has long enjoyed high adoption rates
Don't Totally Dismiss the 'Survivalists'
'Survivalists' or similar terms are used to describe a particular mindset of people who prepare for some really awful scenarios
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 02, 2026
IRC logs for Thursday, April 02, 2026
A Much Better Use of Fuel Than Slop
Something positive for a change
Hoping for Peace
There are still many things to be enjoyed, including nature and kind people
Gemini Links 03/04/2026: "Slide Rule Triple Multiplication" and End of "Picture Pages"
Links for the day
Rumours of Microsoft Layoffs This Season
Just how much trouble is Microsoft in at this point?
GNU/Linux Measured at All-Time High in Sweden
Can 'influencers' have played a role