Bonum Certa Men Certa

[Video] UEFI Insecure Boot: Another Nail in the Coffin

posted by Roy Schestowitz on Jul 29, 2024

Video download link | md5sum dd9c634b1416f67902406317d73b9009
Insecure Boot Strikes Again
Creative Commons Attribution-No Derivative Works 4.0

Preview for Insecure Boot Strikes Again

THE small bunch (borderline fringe) of 'Secure Boot' Microsofters are not talking about the latest blunder. They just have nothing to say in their defence. They've been proven wrong. So let's discuss the matter. We don't just let it pass.

12 years ago they told us adoption of 'bootlocks' is fine and that this is perfectly OK. To oppose this would be to oppose security. Well, patience is a virtue here because over the past 12 years we've repeatedly been proven right and we can howl from rooftops now. The lesson is, do not believe anything Microsofters say. As an associate put it recently, there will "be a few long-form series later on in the indefinite future on the details."

The time seems right to respond to over a decade of mindless propaganda from Microsofters. They're hired professional censors in an effort to suppress information and intimidate women.

Some have dubbed this latest scandal "InSecure Boot" and security gurus are deeply concerned ("This isn’t good"). IDG said:

Security research firm Binarly reports that leaked cryptographic keys have compromised hardware from several major vendors in the PC industry, including Dell, Acer, Gigabyte, Supermicro, and even Intel. Eight percent of firmware images released in the last four years are compromised, with 22 untrusted keys discovered immediately.

This is also discussed in some GNU/Linux forums. One commenter said: "It's security done by Microsoft... that's all that needs to be said, eh?" Another one said: "Yeah, enough said. I'm grateful that I was able to switch off secure boot on my new T14 Thinkpad to install Linux. I'm glad that Windows isn't on my home LAN."

This additional report says "Secure Boot key compromised in 2022 is still in use in over 200 models — an additional 300 more use keys are marked ‘DO NOT TRUST’". To quote from the summary:

>Software security firm Binarly discovered that over 200 device models used a compromised security key, while an additional 300 more used default test keys shared with nearly all of AMI's customers.

Finally, for the time being, this one mentions another "brand name" for this issue:

A vulnerability dubbed PKfail can allow attackers to run malicious code during the boot process, which can be used to deliver UEFI bootkits.

No matter what one calls it - e.g. "PKfail" or "InSecure Boot" - this is a black eye to Microsofters.

Iris Flower Art Vintage

We already added some of these stories to Daily Links or had them linked to the originals in the sister site, but on Saturday we did a video about it. The first piece that everyone linked to (also in IRC) was Ars Technica's and it sort of speaks for itself. An associate called for "a Tomi Ahonen style "I told you so" article," arguing that "even short series is warranted because the public had been warned in detail in advance of just these kinds of problems."

We've repeatedly written about this since 2012.

"There are other problems too which have manifested," the associate said, "this is not the first."

There are also more serious warnings (warranting further precautions) which have not yet come to pass, so the other shoe has yet to drop - so to speak - on UEFI.

The politics which the UEFI patches and shim allowed Microsoft can be re-examined in this context.

Microsoft is meanwhile pushing the media to pretend no option exists other than Windows (and Office) for new laptops and desktops. What is this, 2004? Citing this as an example, the associate said "Microsoft pursues trapping people into a the sunk cost fallacy to prevent upgrading the OS to Linux or, worse from their perspective, using open formats for documents."

The way Microsoft sees things, anything other than Windows is not trustworthy or is "piracy". People who object to Windows are being bullied and vilified, even if the facts are on their side all the time.

Other Recent Techrights' Posts

Fight Less, Collaborate More
Competition is OK, committing crimes is not OK
Defining Pseudo-journalists
Three days ago WikiLeaks shared the image
Truth and Microsoft Aren't Compatible
It's very much possible that Microsoft as a whole operates at a loss
Guest Post on the Cost of Debian Taking Bribes From Microsoft (and Letting Microsoft Vote Inside Debian!)
Guest post: DebConf24 welcomes its sponsors!
 
Gemini Links 31/07/2024: Combating Malaise, Modifying Gemini Network Transport Protocol Specification
Links for the day
Headline Change: "Jeffrey Epstein Called Bill Gates His 'Brightest' Star: New Book"
Seems like censorship by Gates (as usual)
EPO Workers Blow the Whistle on Extremely Worrying Discontinuation of the CFS, a Central File Store (Which Means Examination Will Be Hard to Do)
And, by default, patents will just be granted without sufficient scrutiny
[Meme] The Only File You Need is the Patent
Monopoly. Monopolies everywhere! Monopoly for everyone!
Links 30/07/2024: Atrocities in Sudan, Escalations Near Lebanon
Links for the day
Gemini Links 30/07/2024: Burnout and Plan 9
Links for the day
Links 30/07/2024: Microsoft Admits Lying About ClownStrike/Windows Outages to Save Face and Shared Email Addresses
Links for the day
Offending Accounts Removed, Even Without Help From the Police
The community must identify and properly deal with such militants, who disguise themselves as "diversity"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, July 29, 2024
IRC logs for Monday, July 29, 2024
[Meme] Microsoft Pundits 'Reporting' the 'Results'
every product became 'AI' and thus there is 'growth'
August Will be Productive, the Future Bears Much Promise
It's constant struggle and we need to ensure we have more people on our side than the likes of Microsoft have on theirs
Microsoft Lost Taiwan a Long Time Ago, About a Decade Ago
GNU/Linux adoption has been high in Taiwan
Genuinely Worried About Taiwan, a Tech Powerhouse That Gave Us EEE PC
Taiwan is an avid adopter of GNU/Linux and home of the EEE PC, the first netbook of its kind, which also shipped GNU/Linux by default (out of the box)
Gemini Links 29/07/2024: Automation vs Scarcity and Understanding Gemini
Links for the day
Windows Kills Even When There's No War
Russians or no Russians, war or no war, Microsoft kills. It's time to get rid of it.
Something Went Horribly Wrong For Microsoft in Finland
In the past 2 years Vista 11 hardly grew among versions of Windows
Addictive Behaviour Leads to a False Measure of Productivity
Ensure the metrics to strive for actually make sense, rather than release endorphins
Something for GNU/Linux Aficionados to Celebrate and Take Note of, Fake Microsoft 'Results' Coming Tomorrow
Be very sceptical but what Microsoft's media operatives already draft for tomorrow
[Meme] When It Gets Harder to Make Ends Meet in a Family (Without Promotions)
EPO salaries decreasing, working hours/stress increase every year, so what might this lead to?
Central Staff Committee of the European Patent Office (EPO) Reports Growing Secrecy at the EPO
"the first bonus round of 2024 ... been notably missing any statistics at all"
[Meme] Engaging With Women
"You hurt my feelings."
Anti-Free Software Militants Reported to the Police for Second Time This Month
They have resorted to criminal activities against not only yours truly but also relatives
Links 29/07/2024: Persistent Microsoft Layoffs Cause More Unions to Form
Links for the day
Poul-Henning Kamp (phk) Explains Insecure Boot
Monopolies always abuse their power
[Video] Software Freedom Starts With Code and Needs Coders, Not Microsofters and Pseudo-Politicians in Charge
Geeks get replaced by wannabe politicians who cannot and do not code
Mozilla Firefox Used to Dominate Cuba, Now It's Chrome
Firefox also 4 times bigger than Microsoft
Gemini Links 29/07/2024: Starting Chess and Why Automation is Not a Panacea
Links for the day
Responding to Us In Mastodon
Because many of those people who claim to have issues with us actually have personal issues
In Thailand, Microsoft and Mozilla Now Have the Same Share (Roughly)
Perhaps one day the share of GNU/Linux in Thailand will be similar to India's
[Meme] ZDNet's Downfall Will be the SPAM (the Editor Moved From CNET to ZDNet, the Strategy Moved Also)
Jason Hiner, ZDNet Editor In Chief
ZDNet Has Become a Shopping Spam Site, Just Like the Sister Site CNET
In many ways the site has become an SEO farm and is practically dead as a news source
[Meme] Microsoft's Concept of a 'Secure' Boot
"Linux is communism, I refuse to let you use it"
[Video] UEFI Insecure Boot: Another Nail in the Coffin
let's discuss the matter
Lessened Accountability Because Technology Replaces Humans for Many Tasks
It's a big problem when machines cannot be held accountable but at the same time inherit tasks where accountability is legally essential
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, July 28, 2024
IRC logs for Sunday, July 28, 2024
The Politics of Calls for Assassination
wanting to assassinate people is wrong and calling for assassinations is also wrong
China and India: High-Impact Nations in the Future of Computing
In India, GNU/Linux rose to 16.2% today
A Month of Mass Layoffs at Microsoft
Microsoft isn't doing well and in the coming days one must look carefully or watch out for what Microsoft hides from the public (and shareholders)