12.06.21

Gemini version available ♊︎

“Wintel” “Secure” uEFI Firmware Used to Store Persistent Malware, and Security Theater Boot is Worthless

Posted in Hardware, Microsoft, Security at 1:06 pm by Guest Editorial Team

Guest post by Ryan, reprinted with permission from the original

Free space

PCMag now reports (And calls out Windows! Good!) that the situation where persistent rootkit malware that doesn’t really need anything except to run once, somehow, on a Windows machine, is now being installed into the system’s uEFI firmware, where it will survive what most Windows users end up doing every time their computer ends up acting weird….nuking Windows and re-installing from scratch.

It was already so much easier for Microsoft to include “Reset this PC” than it was to fix Windows that this has been a staple for the past decade. It sometimes works, unless something has also corrupted the WIM installer image on the recovery partition, which also takes up precious SSD space.

However, with the latest threat to Windows users, which uEFI made possible (as bootkits on legacy BIOS were unheard of), no matter how many times you re-install Windows, no matter whether or not TPM or Secure Boot are on and enforced, it won’t matter. The malware isn’t running in a part of your computer that is subjected to any sort of auditable behavior.

Therefore, the only way to prevent a foothold situation is to get rid of Windows now, while it may not be too late, and replace it with GNU/Linux.

Again, most people find that their “must have” Windows software works in Wine. Sometimes Wine even resurrects programs that Windows itself has been incompatible with or partially broke years ago.

Instead of fixing Windows, Microsoft spends billions in “shadow advertising” to pay “freelance” writers to make “Linux” sound like a security disaster too, so there’s this “false equivalence” in the user’s mind.

My dad used to do the same thing to my mother when she threatened to divorce him. “You know if you leave me, your cancer will come back and there won’t be anyone to help you with that. The kids won’t be able to come back and live with me because I won’t have them”.

Like, here’s the biggest dickhead in the world, right? And mom’s 64 now and she’s fine, and I’m pushing 40, will be 40 in a couple years and some change and I’m fine, right? Bullies always use threats which turn out to be puffery. They want you to think they’re all powerful. And their antics usually get worse as they lose power.

So we should see that Microsoft is acting from a position of weakness.

There’s this whole Truman Show thing going on right now they’re up in the tower panicking because he finally realizes everything around him is fake and he needs to leave, and he finally decides to escape the island.

So all of a sudden there’s a fake nuclear power plant meltdown, and actors getting in the way of his car, and a wind storm being generated on the lake to try to scare him into giving up and thinking he was crazy, and going back to the show. And up until that point, every time he started to question the nature of things, they could always increase his fear of the unknown to overcome his curiosity, or his need to grow. And that’s exactly how abusers operate.

The very act of porting Microsoft Pretender to “Linux” is a part of this psyop.

They fund nasty trolls to imply that there is a remote technical possibility of targeting GNU/Linux users. (Technically possible, but much, much more difficult and far less pay off.)

I have another post coming about that, very shortly.

Just using some back of the napkin math, however, Windows is more than 10 times bigger than GNU/Linux after a fresh install as measured by disk footprint.

Secunia wrote in 2014 that the defect density for open source code was 0.59 defects per 1,000 lines, and for proprietary it was 0.72.

(The bonus in their reports is that the one from the prior year showed that C++ projects tended to be a much bigger security mess than C. Linux the kernel is almost entirely C. Linus was right!)

So if you assume that there’s about 10 times as much source code in Windows (which is amazing, considering that the built-in apps are useless and you don’t get a free fully-featured operating system, only SKUs with various parts of the OS disabled, and most people will try to get a different web browser, LibreOffice, and VLC anyway), and you give Microsoft the benefit of the doubt and assume they’re not writing garbage that’s even worse than the proprietary software average (LOL), there’d still be well over 12 times as many bugs in the Windows operating system as in GNU/Linux, even though Windows doesn’t have good features and quality software included.

(It usually comes with a lot of crapware from the OEM though, and that’s a totally different story, and makes the situation worse.)

There absolutely is a security cost to leaving a ton of garbage laying around and no good security practices for software installation and package management (just a failed crApp Store with fake apps and junk), and Windows “users” (useds) are paying this price every day.

Wisdom comes by seeing bullshit, calling bullshit, and refusing to be a part of the bullshit. Software is getting to be so tertiary to what Microsoft even does to make money.

What they seem to do these days boils down to spawn camping “Linux” while they don’t even use Windows internally that much anymore, in favor of “Linux”, and suing Android OEMs -or- offering to cram pack your new phone with pestware that demands to connect to Microsoft. (Samsung)

I’m heartened that the “news” is starting to rebel against this disgusting spectacle that’s going on around Microsoft Edge lately and is no longer just calling Windows bugs a “PC problem” in every article. Hopefully, the more Microsoft tightens their grasp, the more things slip through their fingers.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

DecorWhat Else is New


  1. [Meme] EPO: Pursuing an Eastern and Western District of Europe (for Patent Trolls and Software Patents)

    With the EPO so flagrantly lying and paying for misinformation maybe we should expect Benoît Battistelli and António Campinos to have delusions of grandeur… such as presiding over the Eastern and Western District of Europe, just like Mr. Gilstrap and Mr. Albright (political appointment by Donald Trump, ushering in “the swamp”)



  2. Gemini at 2,000: 86% of Capsules Use Self-Signed Certificate, Just Like the Techrights Web Site (WWW)

    As shown in the charts above (updated an hour ago), the relative share of ‘Linux’ Foundation (LE/LF; same thing, same office) in the capsules’ certificates has decreased over time; more and more (in terms of proportion) capsules choose to sign their own certificate/s; the concept of ‘fake security’ (centralisation and consolidation) should be rejected universally because it leaves nobody safe except plutocrats



  3. [Meme] UPC: Many Lies as Headlines, Almost Exclusively in Publishers Sponsored by EPO and Team UPC to Produce Fake News (Lobbying Through Misinformation)

    Lest we forget that EPO dictators, like Pinky and the Brainless Benoît Battistelli and António Campinos, have long littered the EPO's official Web site as well as publishers not directly connected to the EPO (but funded by it) with disinformation about the UPC



  4. EPO as the 'Ministry of Truth' of Team UPC and Special Interests

    The 'Ministry of Truth' of the patent world is turning the EPO's Web site into a propaganda mill, a misinformation farm, and a laughing stock with stock photography



  5. Microsoft 'Delighted' by Windows 11 (Vista 11) Usage, Which is Only 1% Three Months After Official Launch and Six Months After Release Online

    Microsoft boosters such as Bogdan Popa and Mark Hachman work overtime on distraction from the failure Vista 11 has been (the share of Windows continues to fall relative to other platforms)



  6. Links 27/1/2022: Preinstalled GNU/Linux (Ubuntu) and Arch Linux-Powered Steam Deck 30 Days Away

    Links for the day



  7. Don't Fall for Microsoft's Spin That Says Everything is Not Secure and Cannot be Secured

    Microsoft keeps promoting the utterly false concept that everything is not secure and there's nothing that can be done about it (hence, might as well stay with Windows, whose insecurity is even intentional)



  8. At Long Last: 2,000 Known Gemini Capsules!

    The corporate media, looking to appease its major sponsors (such as Web/advertising giants), won't tell you that Gemini Protocol is rising very rapidly; its userbase and the tools available for users are rapidly improving while more and more groups, institutions and individuals set up their own capsule (equivalent of a Web site)



  9. Links 26/1/2022: Gamebuntu 1.0, PiGear Nano, and Much More

    Links for the day



  10. IRC Proceedings: Tuesday, January 25, 2022

    IRC logs for Tuesday, January 25, 2022



  11. Links 26/1/2022: No ARM for Nvidia, End of EasyArch, and WordPress 5.9 is Out

    Links for the day



  12. Why the Unified Patent Court (UPC) is Still Just a Fantasy and the UPC's Fake News Mill Merely Discredits the Whole Patent 'Profession'

    Patents and science used to be connected; but now that the patent litigation 'sector' is hijacking patent offices (and even courts in places like Texas) it's trying to shove a Unified Patent Court (UPC) down the EU's throat under the disingenuous cover of "community" or "unity"



  13. Links 25/1/2022: Vulkan 1.3 Released, Kiwi TCMS 11.0, and antiX 19.5

    Links for the day



  14. Gemini Milestones and Growth (Almost 2,000 Known Gemini Servers Now, 39,000 Pages in Ours)

    The diaspora to Gemini Protocol or the transition to alternative 'webs' is underway; a linearly growing curve suggests that inertia/momentum is still there and we reap the benefits of early adoption of Gemini



  15. [Meme] Get Ready for Unified Patent Court (UPC) to be Taken to Court

    The Unified Patent Court (UPC) and Unitary Patent system that’s crafted to empower EPO thugs isn’t legal and isn’t constitutional either; even a thousand fake news 'articles' (deliberate misinformation or disinformation) cannot change the simple facts because CJEU isn’t “trial by media”



  16. The EPO Needs High-Calibre Examiners, Not Politicians Who Pretend to Understand Patents and Science

    Examiners are meant to obstruct fake patents or reject meritless patent applications; why is it that working conditions deteriorate for those who are intellectually equipped to do the job?



  17. Free Software is Greener

    Software Freedom is the only way to properly tackle environmental perils through reuse and recycling; the mainstream media never talks about it because it wants people to "consume" more and more products



  18. Links 25/1/2022: Git 2.35 and New openSUSE Hardware

    Links for the day



  19. IRC Proceedings: Monday, January 24, 2022

    IRC logs for Monday, January 24, 2022



  20. Links 25/1/2022: GPL Settlement With Patrick McHardy, Godot 4.0 Alpha 1, and DXVK 1.9.4 Released

    Links for the day



  21. Proprietary Software is Pollution

    "My daughter asked me about why are we throwing away some bits of technology," Dr. Andy Farnell says. "This is my attempt to put into words for "ordinary" people what I tried to explain to a 6 year old."



  22. Microsoft GitHub Exposé — Part XV — Cover-Up and Defamation

    Defamation of one’s victims might be another offence to add to the long list of offences committed by Microsoft’s Chief Architect of GitHub Copilot, Balabhadra (Alex) Graveley; attempting to discredit the police report is a new low and can get Mr. Graveley even deeper in trouble (Microsoft protecting him only makes matters worse)



  23. [Meme] Alexander Ramsay and Team UPC Inciting Politicians to Break the Law and Violate Constitutions, Based on Misinformation, Fake News, and Deliberate Lies Wrapped up as 'Studies'

    The EPO‘s law-breaking leadership (Benoît Battistelli, António Campinos and their corrupt cronies), helped by liars who don't enjoy diplomatic immunity, are cooperating to undermine courts across the EU, in effect replacing them with EPO puppets who are patent maximalists (Europe’s equivalents of James Rodney Gilstrap and Alan D Albright, a Donald Trump appointee, in the Eastern and Western Districts of Texas, respectively)



  24. Has the Administrative Council Belatedly Realised What Its Job in the European Patent Organisation Really Is?

    The "Mafia" which took over the EPO (the EPO's own workers call it "Mafia") isn't getting its way with a proposal, so it's preventing the states from even voting on it!



  25. [Meme] Team UPC is Celebrating a Pyrrhic Victory

    Pyrrhic victory best describes what's happening at the moment (it’s a lobbying tactic, faking/staging things to help false prophecies be fulfilled, based on hopes and wishes alone), for faking something without bothering to explain the legal basis is going to lead to further escalations and complaints (already impending)



  26. Links 24/1/2022: Scribus 1.5.8 and LXLE Reviewed

    Links for the day



  27. IRC Proceedings: Sunday, January 23, 2022

    IRC logs for Sunday, January 23, 2022



  28. [Meme] Team UPC Congratulating Itself

    The barrage of fake news and misinformation about the UPC deliberately leaves out all the obvious and very important facts; even the EPO‘s António Campinos and Breton (Benoît Battistelli‘s buddy) participated in the lying



  29. Links 24/1/2022: pgBadger 11.7 Released, Catch-up With Patents

    Links for the day



  30. The Demonisation and Stereotyping of Coders Not Working for Big Corporations (or 'The System')

    The war on encrypted communication (or secure communications) carries on despite a lack of evidence that encryption stands in the way of crime investigations (most criminals use none of it)


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts