Bonum Certa Men Certa

“Wintel” “Secure” uEFI Firmware Used to Store Persistent Malware, and Security Theater Boot is Worthless

Guest post by Ryan, reprinted with permission from the original

Free space

PCMag now reports (And calls out Windows! Good!) that the situation where persistent rootkit malware that doesn’t really need anything except to run once, somehow, on a Windows machine, is now being installed into the system’s uEFI firmware, where it will survive what most Windows users end up doing every time their computer ends up acting weird….nuking Windows and re-installing from scratch.



It was already so much easier for Microsoft to include “Reset this PC” than it was to fix Windows that this has been a staple for the past decade. It sometimes works, unless something has also corrupted the WIM installer image on the recovery partition, which also takes up precious SSD space.



However, with the latest threat to Windows users, which uEFI made possible (as bootkits on legacy BIOS were unheard of), no matter how many times you re-install Windows, no matter whether or not TPM or Secure Boot are on and enforced, it won’t matter. The malware isn’t running in a part of your computer that is subjected to any sort of auditable behavior.



Therefore, the only way to prevent a foothold situation is to get rid of Windows now, while it may not be too late, and replace it with GNU/Linux.



Again, most people find that their “must have” Windows software works in Wine. Sometimes Wine even resurrects programs that Windows itself has been incompatible with or partially broke years ago.



Instead of fixing Windows, Microsoft spends billions in “shadow advertising” to pay “freelance” writers to make “Linux” sound like a security disaster too, so there’s this “false equivalence” in the user’s mind.




My dad used to do the same thing to my mother when she threatened to divorce him. “You know if you leave me, your cancer will come back and there won’t be anyone to help you with that. The kids won’t be able to come back and live with me because I won’t have them”.



Like, here’s the biggest dickhead in the world, right? And mom’s 64 now and she’s fine, and I’m pushing 40, will be 40 in a couple years and some change and I’m fine, right? Bullies always use threats which turn out to be puffery. They want you to think they’re all powerful. And their antics usually get worse as they lose power.



So we should see that Microsoft is acting from a position of weakness.



There’s this whole Truman Show thing going on right now they’re up in the tower panicking because he finally realizes everything around him is fake and he needs to leave, and he finally decides to escape the island.



So all of a sudden there’s a fake nuclear power plant meltdown, and actors getting in the way of his car, and a wind storm being generated on the lake to try to scare him into giving up and thinking he was crazy, and going back to the show. And up until that point, every time he started to question the nature of things, they could always increase his fear of the unknown to overcome his curiosity, or his need to grow. And that’s exactly how abusers operate.



The very act of porting Microsoft Pretender to “Linux” is a part of this psyop.



They fund nasty trolls to imply that there is a remote technical possibility of targeting GNU/Linux users. (Technically possible, but much, much more difficult and far less pay off.)



I have another post coming about that, very shortly.



Just using some back of the napkin math, however, Windows is more than 10 times bigger than GNU/Linux after a fresh install as measured by disk footprint.



Secunia wrote in 2014 that the defect density for open source code was 0.59 defects per 1,000 lines, and for proprietary it was 0.72.



(The bonus in their reports is that the one from the prior year showed that C++ projects tended to be a much bigger security mess than C. Linux the kernel is almost entirely C. Linus was right!)



So if you assume that there’s about 10 times as much source code in Windows (which is amazing, considering that the built-in apps are useless and you don’t get a free fully-featured operating system, only SKUs with various parts of the OS disabled, and most people will try to get a different web browser, LibreOffice, and VLC anyway), and you give Microsoft the benefit of the doubt and assume they’re not writing garbage that’s even worse than the proprietary software average (LOL), there’d still be well over 12 times as many bugs in the Windows operating system as in GNU/Linux, even though Windows doesn’t have good features and quality software included.



(It usually comes with a lot of crapware from the OEM though, and that’s a totally different story, and makes the situation worse.)



There absolutely is a security cost to leaving a ton of garbage laying around and no good security practices for software installation and package management (just a failed crApp Store with fake apps and junk), and Windows “users” (useds) are paying this price every day.



Wisdom comes by seeing bullshit, calling bullshit, and refusing to be a part of the bullshit. Software is getting to be so tertiary to what Microsoft even does to make money.



What they seem to do these days boils down to spawn camping “Linux” while they don’t even use Windows internally that much anymore, in favor of “Linux”, and suing Android OEMs -or- offering to cram pack your new phone with pestware that demands to connect to Microsoft. (Samsung)



I’m heartened that the “news” is starting to rebel against this disgusting spectacle that’s going on around Microsoft Edge lately and is no longer just calling Windows bugs a “PC problem” in every article. Hopefully, the more Microsoft tightens their grasp, the more things slip through their fingers.



Recent Techrights' Posts

"systemd is essentially a corporate IBM/Redhat project and corporations of course will comply"
Microsoft and IBM care about users' freedom like Cheeto Lump cares about the US Constitution
Gemini Links 20/03/2026: Digital Identity Bifurcation and a "Return to Gemini"
Links for the day
 
Even Uganda Understands That Journalists Never Belong in Prison
"Ugandan authorities must respect the spirit of this ruling and abandon any measures that seek to jail Ugandans for the free flow of ideas."
Inaction Helps Your Enemies
Without freedom, there's nothing else left
Windows Down From 99% to ~50% in Republic of Seychelles (République des Seychelles)
Windows fell by a lot
Confluent Insiders: IBM Laid Over Over 800 at Confluent, Not Just 800
For the record, the layoffs at Confluent won't be over. After the bluewashing there will be "IBM RAs" impacting Confluent folks, aside from PIPs
The Layoffs at IBM Carry on (Shades of Enron)
Is IBM another Enron?
"IBM boss Arvind Krishna... financial package valued at $38 million in calendar 2025 - equivalent to the average collective pay of 765 Big Blue workers."
continues to ruin the company to enrich himself while pretending he has a strategy
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, March 19, 2026
IRC logs for Thursday, March 19, 2026
SLAPP Censorship - Part 16 Out of 200: Detailing the Actors and Explaining Techrights' Own Internet Relay Chat (IRC) Network
For those who have not followed our story
Microsoft "hiding behind bigger news of war, Epstein, other companies' layoffs"
They know what's coming, they just don't know when
Joerg Jaspert (Debian Account Manager/DAM) personally approved Raphael Hertzog's wife Sophie Brun
Reprinted with permission from Daniel Pocock
Letter 'A' prohibited by Code of Conduct extremism
Reprinted with permission from Daniel Pocock
Spoiler: Diversity & Debian means different things to different people
Reprinted with permission from Daniel Pocock
Solicitors Regulation Authority (SRA) Admits Failures and Criticism of Inaction on SLAPPs
many if not all solicitors and solicitor firms in the UK are in effect unregulated
Archiving or Preserving Pages About IBM Layoffs
Layoffs at IBM and the media does not talk about these
ABC, the American National Broadcaster, "Now Publishes Slop"
If the "big media" absorbs slop, it'll no longer be trusted and therefore not read/watched by the public
Links 19/03/2026: Culling Deepfakes of Artists’ Music and "Age Verification Isn’t the Answer"
Links for the day
Gemini Links 19/03/2026: "Aktion GPT-4" and "Kill All Descendants"
Links for the day
"AI" 15 Times in Short 'Article' From The Register MS. And The Register MS Got Paid to Publish It.
gets paid to do this
People Who Decided to Boycott Novell Over Its Microsoft Alliance Should Also Boycott Canonical
As an associate put it, "selling out further, due to Microsoft moles inside Canonical"
Links 19/03/2026: "AI Glasses" as Euphemism for Mass Surveillance and ABC (US) Has Begun Publishing Slop as 'News'
Links for the day
The European Patent Office, Europe's Second-Largest Institution, is on Strike Today
Lots more to come
What People Impacted by the Bluewashing Layoffs at IBM Confluent Say (While the Media Says Nothing at All, in Effect Burying the News)
Worse yet, the mainstream media spreads lies about it right now
IBM Has Turned Red Hat and Fedora Into Slop
This is IBM policy
IBM is Being Robbed, Companies and Jobs Are Destroyed
Companies taken over by IBM will be exploited and destroyed to keep a bubble inflated for a little while longer
In Confluent Layoffs, IBM Vapourises a Quarter of Its Workforce (IBM Buys Something That It Destroys Already)
In the past, such things were typically referred to as "media blackout"; now it's just "the norm".
IBM Effect at Confluent: Mass Layoffs and IBM's Business Conduct Guidelines (BCGs) Said to be Violated
For Confluent employees who survived the layoffs there will be "culture chock"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, March 18, 2026
IRC logs for Wednesday, March 18, 2026
Links 19/03/2026: LLM Fatigue (It Doesn't Work as Advertised), "Small Web Feeds"
Links for the day
SLAPP Censorship - Part 15 Out of 200: Background and Particulars of Truth Regarding Techrights and Tux Machines
the basic facts (this has aged well, except the times/ages/numbers)
A Slopfarms Survey for Today (linuxteck.com, linuxsecurity.com, linuxjournal.com)
Not only did Google news link to a slopfarm; it linked to three run by the same team!
Links 18/03/2026: "Venture Capitalist Warns That It’s All About to Come Crashing Down" Due to Slop Bubble, "Birdwatching for Fun and no Profit"
Links for the day
IBM Red Hat is Still Promoting Restricted Boot Which Restricts Users' Control Over Their Computers
Red Hat under IBM is a total catastrophe
Arvind Says... Something Something "Hey Hi" (the State of Today's Media)
Look for news about IBM and most likely it'll boil down to some sound bites from an executive and nothing else
New Post Has Just Explained How IBM Gets Robbed by the People Who Fail IBM
Their plan for IBM is a personal plan
Slop-Spewing GAFAM LLM That Knows Nothing and Understands Nothing, It's a Stochastic Parrot That Cannot Even Figure Out Tux Machines is a Community That Started in Tennessee 22 Years Ago
RMS rightly calls those things "bullshit generators"
Cusdeb Makes New Presentation About Where GNU Hurd (Still a Possible Linux Replacement) Stands in 2026
coming from a generally RMS-friendly account
Gemini Links 18/03/2026: Librarians, Phone Anxiety, Growing 'Small' Net, and Slop Versus Software Engineering
Links for the day
Estimates That IBM to Lay Off Close to 10,000 Workers in 2026 (Not Counting People Pushed Out)
There's still chatter about Confluent mass layoffs
Smug Threat by Garrett to Put My Family and I in Prison Doesn't Prove We Did Anything Wrong, It Only Proves He's Truly Desperate to Stop Further Publications That Embarrass Him
his reputation is poor in the United States
systemd Increasingly Microsoft Project, Controlled by Microsoft and Slopware
Cannot allow choice
What IBM Meant to Red Hat: "Proprietary Bundling, Restricted Source Access"
Anyone or anything that joins IBM likely shortens its lifespan
IBM Thrashing Confluent Upon Arrival, Based on Rumours
We deem it a bigger issue that investigative journalism perished, not that one must rely on hearsay online or mere "rumours"
Slop Is Plagiarism, Not (Vibe) Coding, and It's Not Automated, It Doesn't Save Money
Reject misnomers, explain what's actually happening
UPC is Still Illegal and Unconstitutional (Kangaroo Court for Patents, Manned by Corporate Staff), Federal Court of Justice of Germany Receives Belated Complaint About It
What is happening to Europe???
EPO Demonstration Happening Right Now, Later This Week Things Will Only Escalate Further
The SUEPO The Hague Committee wrote to staff this morning
Sophie Brun, Raphael Hertzog & Debian sexual conflicts of interest
Reprinted with permission from Daniel Pocock
Links 18/03/2026: Commodore's Hedley Davis Dies, Apple Not Good Enough, Cheeto "Floats Treason Charges for Iran War Coverage"
Links for the day
A Step Close to Shutting Down the European Patent Office (EPO)
Not going to work all month long
EPO Staff Demonstration Today
The demonstration will be live-streamed for those thousands of colleagues who don't live in Munich
Gemini Links 18/03/2026: Brazilian SYN Attacks and BGP
Links for the day
LibreLocal Also Coming to Jordan, Kenya, Mexico, New Zealand, and Spain
It helps raise awareness of Software Freedom
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, March 17, 2026
IRC logs for Tuesday, March 17, 2026