Bonum Certa Men Certa

“Wintel” “Secure” uEFI Firmware Used to Store Persistent Malware, and Security Theater Boot is Worthless

Guest post by Ryan, reprinted with permission from the original

Free space

PCMag now reports (And calls out Windows! Good!) that the situation where persistent rootkit malware that doesn’t really need anything except to run once, somehow, on a Windows machine, is now being installed into the system’s uEFI firmware, where it will survive what most Windows users end up doing every time their computer ends up acting weird….nuking Windows and re-installing from scratch.



It was already so much easier for Microsoft to include “Reset this PC” than it was to fix Windows that this has been a staple for the past decade. It sometimes works, unless something has also corrupted the WIM installer image on the recovery partition, which also takes up precious SSD space.



However, with the latest threat to Windows users, which uEFI made possible (as bootkits on legacy BIOS were unheard of), no matter how many times you re-install Windows, no matter whether or not TPM or Secure Boot are on and enforced, it won’t matter. The malware isn’t running in a part of your computer that is subjected to any sort of auditable behavior.



Therefore, the only way to prevent a foothold situation is to get rid of Windows now, while it may not be too late, and replace it with GNU/Linux.



Again, most people find that their “must have” Windows software works in Wine. Sometimes Wine even resurrects programs that Windows itself has been incompatible with or partially broke years ago.



Instead of fixing Windows, Microsoft spends billions in “shadow advertising” to pay “freelance” writers to make “Linux” sound like a security disaster too, so there’s this “false equivalence” in the user’s mind.




My dad used to do the same thing to my mother when she threatened to divorce him. “You know if you leave me, your cancer will come back and there won’t be anyone to help you with that. The kids won’t be able to come back and live with me because I won’t have them”.



Like, here’s the biggest dickhead in the world, right? And mom’s 64 now and she’s fine, and I’m pushing 40, will be 40 in a couple years and some change and I’m fine, right? Bullies always use threats which turn out to be puffery. They want you to think they’re all powerful. And their antics usually get worse as they lose power.



So we should see that Microsoft is acting from a position of weakness.



There’s this whole Truman Show thing going on right now they’re up in the tower panicking because he finally realizes everything around him is fake and he needs to leave, and he finally decides to escape the island.



So all of a sudden there’s a fake nuclear power plant meltdown, and actors getting in the way of his car, and a wind storm being generated on the lake to try to scare him into giving up and thinking he was crazy, and going back to the show. And up until that point, every time he started to question the nature of things, they could always increase his fear of the unknown to overcome his curiosity, or his need to grow. And that’s exactly how abusers operate.



The very act of porting Microsoft Pretender to “Linux” is a part of this psyop.



They fund nasty trolls to imply that there is a remote technical possibility of targeting GNU/Linux users. (Technically possible, but much, much more difficult and far less pay off.)



I have another post coming about that, very shortly.



Just using some back of the napkin math, however, Windows is more than 10 times bigger than GNU/Linux after a fresh install as measured by disk footprint.



Secunia wrote in 2014 that the defect density for open source code was 0.59 defects per 1,000 lines, and for proprietary it was 0.72.



(The bonus in their reports is that the one from the prior year showed that C++ projects tended to be a much bigger security mess than C. Linux the kernel is almost entirely C. Linus was right!)



So if you assume that there’s about 10 times as much source code in Windows (which is amazing, considering that the built-in apps are useless and you don’t get a free fully-featured operating system, only SKUs with various parts of the OS disabled, and most people will try to get a different web browser, LibreOffice, and VLC anyway), and you give Microsoft the benefit of the doubt and assume they’re not writing garbage that’s even worse than the proprietary software average (LOL), there’d still be well over 12 times as many bugs in the Windows operating system as in GNU/Linux, even though Windows doesn’t have good features and quality software included.



(It usually comes with a lot of crapware from the OEM though, and that’s a totally different story, and makes the situation worse.)



There absolutely is a security cost to leaving a ton of garbage laying around and no good security practices for software installation and package management (just a failed crApp Store with fake apps and junk), and Windows “users” (useds) are paying this price every day.



Wisdom comes by seeing bullshit, calling bullshit, and refusing to be a part of the bullshit. Software is getting to be so tertiary to what Microsoft even does to make money.



What they seem to do these days boils down to spawn camping “Linux” while they don’t even use Windows internally that much anymore, in favor of “Linux”, and suing Android OEMs -or- offering to cram pack your new phone with pestware that demands to connect to Microsoft. (Samsung)



I’m heartened that the “news” is starting to rebel against this disgusting spectacle that’s going on around Microsoft Edge lately and is no longer just calling Windows bugs a “PC problem” in every article. Hopefully, the more Microsoft tightens their grasp, the more things slip through their fingers.



Recent Techrights' Posts

Plot Twist: Microsoft MSN Relays Articles Hinting at or Pointing to Mass Layoffs Soon, Other Gossip
the narrative from Microsoft's "PR bunny" (Shaw) is showing mold already
'Vibe Coding' is Not "AI", It's a Sewer, It is Junk
Linus Torvalds was wrong. 'Vibe coding' isn't good for anything.
GNU/Linux May be Approaching 10% "Market Share" in Montenegro
The surge started around 2021
More IBM Layoffs in India
If IBM cannot afford to retain workers in India, then something is truly "out of control" at IBM
Dr. Richard Stallman Has Done No Harm to the GNU Project or the FSF (He Had Benefited Both, Always, Even After the Attacks on Him Began)
Some people try to prevent Dr. Stallman from speaking or having a platform where many people can hear him
Microsoft Isn't Denying the Mass Layoffs
Still silence from Microsoft
In Western Africa GNU/Linux Flirts With 5% Market Share
there's a gradual increase in GNU/Linux usage there
Gemini Links 09/01/2026: Pro1 X Repair and the Mercury Protocol
Links for the day
No, Microsoft Did Not Deny the Q1 Mass Layoffs (Microsoft Can Delay These)
Maybe they disperse or delay the layoffs (changing plans), but the layoffs are going to happen
EPO People Power - Part XXIX - Getting DER SPIEGEL, FAZ, Deutschlandfunk and Sueddeutsche Zeitung (SZ) to Cover EPO Scandals
We kindly ask our readers to contact their local media and urge it to cover the scandals
 
IBM is a Cancer That Attaches Itself to Everything
Red Hat should have remained an independent company
Links 09/01/2026: Google and Character.AI Implicitly Accept Chatbots Kill Kids and GLP-1 ‘Slimming Pens’ Turn Out to be a Lot Worse Than Advertised
Links for the day
At IBM, "Employee Reviews" (or Appraisals in the UK) Are a "Trojan Horse" for RAs (Mass Layoffs), a Waste of Time
comments from IBMer serve to suggest that appraisals can be precursors
Links 09/01/2026: Technical Blogging Lessons Learned and Google's Gmail Getting a Lot Worse
Links for the day
Escaping GAFAM Colonialism Requires Homegrown Free Software
GNU/Linux now measured at 3% in Zambia
GNU/Linux at 4% in Saudi Arabia, Says statCounter
Some years ago Windows fell to a "market share" of just 11% there
Links 09/01/2026: Cambodia and China Extradition, "NATO’s High-risk Patrols Near Ukraine"
Links for the day
Only One Person in Charge of Fedora is Not IBM Staff
This is not a community project, it's just a way for IBM to onboard unpaid volunteers
This Is Not a Drill, GNU/Linux is Really Going 'Mainstream' on Laptops (and Desktops)
It is important to explain to people software freedom
IBM Albany Layoffs
not only did many in the site lose their job; there's more to come "and likely another one in February" (weeks from now)
EPO Workers' Industrial Action to Include Many Strikes, to Last Several Months
In some ways, The Hague and Bavaria are becoming almost indistinguishable from Moscow
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, January 08, 2026
IRC logs for Thursday, January 08, 2026
Gemini Links 08/01/2026: "New Year, Old Plans" and Alex's "Butlerian Jihad"
Links for the day
LLM Slop About "Linux" Scarce and of Very Low Quality
At this rate, we reckon there may be one (or zero) per day by year's end
IBM's "Forever Layoffs" (to Bypass Warnings or Notices as Required by WARN Act)
There is a bunch of speculations about when the next "major round" of RAs will be
Attempts to Undermine This Site's Latest Series Using Intimidation, Threats, and Presumptuous Accusations
threatening language is less effective when everyone is an alibi
Links 08/01/2026: "Golden Smartphone" Scam and Riseup Account Issues
Links for the day
Links 08/01/2026: Possible "Collapse of NATO Over Greenland"; Journalistic Malpractice and "US Voters Hate Slop"
Links for the day
EPO People Power - Part XXVIII - A Sensitive Issue for Germany and The Netherlands
If Germans who read this series can communicate this to public officials or to their media, maybe they can strike a nerve and get the ball rolling
Age Discrimination at IBM Discussed Amid Mass Layoffs (Especially in the United States)
Workers are anxious. Are they next to face the axe?
Gemini Links 08/01/2026: Potentiometer Calculator, Power Outages, Why You Should Abandon Discord for IRC (e.g. Ergo), and Formatting Gopher Posts
Links for the day
Links 08/01/2026: More Software Patents Squashed, White House Repeats Misinformation From the Kremlin
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, January 07, 2026
IRC logs for Wednesday, January 07, 2026
The Free Software Foundation (FSF) Looking to Add Associate Members
"Celebrate '26 by helping us reach our New Year's goal before Jan. 16: join as an associate member today. You will help the FSF remain strong and independent to empower technology users everywhere. Join us today and help us reach our goal of 100 new associate members!"
Only Google is Still Spreading Lots of Slopfarms' Fake News and Plagiarism About Linux
2 days' worth of Google News spewing crap out about "Linux"
Georgia Institute of Technology (Georgia Tech) Formally Announces Upcoming Richard Stallman Talk
Room 100, Scheller College of Business
Links 07/01/2026: Europe's 'Binding Commitments' on Ukraine's Security, "Venezuelan Leaders Project Independence"
Links for the day
Gemini Links 07/01/2026: Smart Toaster and Social Control Media Fatigue
Links for the day
Projection Tactics - Part II: Causing "Serious Harm" to Many People (Even Animals)
Narcissists and sociopaths are like that
Even Microsofters Now Speak About Microsoft Reportedly Planning to Sack 10% of Its Staff (as Early as This Month, or 2 Weeks From Now) as Real Income Falls
Microsoft buying from Microsoft isn't real income, it is accounting fraud
The four freedoms and GNU/Linux naming controversy, by Akira Urushibata
Social control media owned and run by 'broligarchs' keeps attacking RMS for insisting on names that include GNU
Crans-Montana, Le Constellation: journalists, victims' families, ProtonMail users at risk, police raids
Reprinted with permission from Daniel Pocock
GNU/Linux Reaches All-Time High in Tanzania
This month (and year) GNU/Linux is measured at an all-time high there, based on the data that statCounter can see
Open Source Initiative (OSI) Not Doing Its Job, Instead It's Promoting Microsoft Ponzi Schemes
it participates in Microsoft's Ponzi scheme, which helps Microsoft distract from or excuse the mass layoffs
Links 07/01/2026: Microsoft ChatGPT Killing People and Microsoft "Github monopoly is destroying the open source ecosystem"
Links for the day
The Register MS: Installing Free Software on Your Device is 'Sideloading'
This is a form of propaganda
Mass Layoffs in Microsoft's XBox Soon, Just Like We've Said for Months
IBM and Microsoft are heading in a similar trajectory and are hiding how bad things are using similar tactics
Mozilla's Assisted Suicide, Assisted by GNOME
Firefox is meant to get better all the time, but instead it gets worse
Now It's a Mainstream Media (MSM) Story: Microsoft Layoffs Coming, They'll be Vast (and They Blame "AI", As Usual!)
the books were cooked (accounting fraud) to hide what really went on
Frankly Getting Sick of Slop About "AI" (Slop)
Calling everything out there "AI" serves nobody and nothing but the Ponzi scheme
Stick to the Science, the Facts, the Observable Reality
Science is at the heart of this site
Africa's Search Market Has Been Unfavourable to Microsoft
In Africa, as we've just noticed, Bing is moving down, even more sharply this year
Slideshare is Slop
Be sure fools will rewrite history online
Gemini Links 07/01/2026: Looking at 2026, Linux Anti-Minimalism, Diode Function Generators, and Inkscape
Links for the day
Projection Tactics - Part I: What is "Serious Harm"? Or Whose?
the most serious harm was done to us
Links 07/01/2026: More Signs XBox the Console is Dead/Dying, Convicted Felon Repeats Threats of Greenland Annexation
Links for the day
EPO People Power - Part XXVII - Science- and Principles-First Journalism About Issues That Matter
journalism became so shallow that nowadays it can be replaced by bots
Media Gaslighting Dooms the Media
this "AI" gaslighting is done because publishers get paid to do so
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, January 06, 2026
IRC logs for Tuesday, January 06, 2026