Bonum Certa Men Certa

[Video] UEFI Insecure Boot: Another Nail in the Coffin

posted by Roy Schestowitz on Jul 29, 2024

Video download link | md5sum dd9c634b1416f67902406317d73b9009
Insecure Boot Strikes Again
Creative Commons Attribution-No Derivative Works 4.0

Preview for Insecure Boot Strikes Again

THE small bunch (borderline fringe) of 'Secure Boot' Microsofters are not talking about the latest blunder. They just have nothing to say in their defence. They've been proven wrong. So let's discuss the matter. We don't just let it pass.

12 years ago they told us adoption of 'bootlocks' is fine and that this is perfectly OK. To oppose this would be to oppose security. Well, patience is a virtue here because over the past 12 years we've repeatedly been proven right and we can howl from rooftops now. The lesson is, do not believe anything Microsofters say. As an associate put it recently, there will "be a few long-form series later on in the indefinite future on the details."

The time seems right to respond to over a decade of mindless propaganda from Microsofters. They're hired professional censors in an effort to suppress information and intimidate women.

Some have dubbed this latest scandal "InSecure Boot" and security gurus are deeply concerned ("This isn’t good"). IDG said:

Security research firm Binarly reports that leaked cryptographic keys have compromised hardware from several major vendors in the PC industry, including Dell, Acer, Gigabyte, Supermicro, and even Intel. Eight percent of firmware images released in the last four years are compromised, with 22 untrusted keys discovered immediately.

This is also discussed in some GNU/Linux forums. One commenter said: "It's security done by Microsoft... that's all that needs to be said, eh?" Another one said: "Yeah, enough said. I'm grateful that I was able to switch off secure boot on my new T14 Thinkpad to install Linux. I'm glad that Windows isn't on my home LAN."

This additional report says "Secure Boot key compromised in 2022 is still in use in over 200 models — an additional 300 more use keys are marked ‘DO NOT TRUST’". To quote from the summary:

>Software security firm Binarly discovered that over 200 device models used a compromised security key, while an additional 300 more used default test keys shared with nearly all of AMI's customers.

Finally, for the time being, this one mentions another "brand name" for this issue:

A vulnerability dubbed PKfail can allow attackers to run malicious code during the boot process, which can be used to deliver UEFI bootkits.

No matter what one calls it - e.g. "PKfail" or "InSecure Boot" - this is a black eye to Microsofters.

Iris Flower Art Vintage

We already added some of these stories to Daily Links or had them linked to the originals in the sister site, but on Saturday we did a video about it. The first piece that everyone linked to (also in IRC) was Ars Technica's and it sort of speaks for itself. An associate called for "a Tomi Ahonen style "I told you so" article," arguing that "even short series is warranted because the public had been warned in detail in advance of just these kinds of problems."

We've repeatedly written about this since 2012.

"There are other problems too which have manifested," the associate said, "this is not the first."

There are also more serious warnings (warranting further precautions) which have not yet come to pass, so the other shoe has yet to drop - so to speak - on UEFI.

The politics which the UEFI patches and shim allowed Microsoft can be re-examined in this context.

Microsoft is meanwhile pushing the media to pretend no option exists other than Windows (and Office) for new laptops and desktops. What is this, 2004? Citing this as an example, the associate said "Microsoft pursues trapping people into a the sunk cost fallacy to prevent upgrading the OS to Linux or, worse from their perspective, using open formats for documents."

The way Microsoft sees things, anything other than Windows is not trustworthy or is "piracy". People who object to Windows are being bullied and vilified, even if the facts are on their side all the time.

Other Recent Techrights' Posts

(Live-)Stream of Richard Stallman's Latest Talk in Europe (No Longer Live)
The latest public talk and Live-Streamed schedule were announced early on for the public to know about
Richard Stallman is Already in India, Giving Talks About Microsoft Chaffbots and More
he's already giving some talks in India
Drunk on Chatbots, LinuxSecurity.com Spews Out More LLM Slop About "Wine"
They just keep googlebombing "Linux" and "Security" using slop
Gemini Links 24/01/2025: The "Hey Hi" Hype Continues Fading, Tesla/X/Twitter/SpaceX Associate With Nazism
Links for the day
Robbery at the European Patent Office (EPO), Office Staff as 'Prisoners'
publication from the Central Staff Committee, dated yesterday
Techrights in 0.036 Seconds
Combining Gemini and HTTP/S, yesterday we served an impressive number of requests
BetaNews Run by Plagiarism Bots That Googlebomb (for SEO) "Linux"
Google rewards and thus encourages plagiarism
IBM Titles Considered Worthless and Many IBM 'Fellows' Are Vanishing (Also: IBM Staff Inside Linux Attacks the Rights of Computer Users for Recognition or Rewards Like "Distinguished Engineer")
James Bottomley is still "a Distinguished Engineer at IBM"
 
Rumour of IBM 'Bloodbath' in Clown Computing
Performance Improvement Plans mean one step ahead or before layoffs
Dr. Andy Farnell: "Richard Stallman Chose to Stand For the Rights of People to Use Technology as They Wish. He Chose Freedom Instead of Riches."
Keeping busy in public transport
Gemini Links 24/01/2025: Drehgriffel, Computer Science and Capitalism
Links for the day
Microsoft Lost a Ton of Market Share in Web Servers Last Month (the Last Month of 2024) and Massive Losses Continue in 2025, Shows New Report
Microsoft down sharply
Microsoft (Nick Vidal) and Co-opting "Open Future" With Microsoft-led "Open Source AI Definition" (Openwashing LLM Slop and GPL Violations)
Microsoft is tainting all sorts of groups via the OSI
Microsoft, IBM, and Front Groups That Advance Racism for Profit
IBM has profited a lot from racism and it still does
FOSDEM and 'No Nazis'
the issue isn't wealth but principles
Gemini Links 24/01/2025: "Social" Control Media is Unsatisfying; An Old Call for a Gemini Without TLS
Links for the day
[Meme] Levels of Outrage
Apparently it's hip for criminals to leverage "the law" to silence their exposers
Links 24/01/2025: Earthquake, Landslide, and Official Implicated in Airplane With Landing Gear Issues (Boeing Plane) "Found Dead"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, January 23, 2025
IRC logs for Thursday, January 23, 2025
CDN Giant: Microsoft Bing and Skype Collapsed Since the LLM Hype, Same as Other Metrics Show
No wonder Microsoft managers suffer anxiety and there are several waves of layoffs even on the same month
Gemini Links 23/01/2025: Experience With Outer Wilds and Gifting a Site
Links for the day
Slopwatch: Fake 'Articles' About Linux by Brian Fagioli and by Brittany Day in BetaNews and linuxsecurity.com (LLM Slop Sites That Are Online Leeches or SEO Operations Working Against Free Software Journalism)
Two new examples for today
Links 23/01/2025: More Overt Constitutional Violations and "TikTok Executive Order" (White Flag to CCP)
Links for the day
Status of New Year's Resolutions
3 weeks later
"The AI Bubble is Popping", Now It's Bailout Time
The hype will quietly fizzle, just like "blockchains"
[Meme] When the Government of the Netherlands Participates in Your Crimes It Lacks an Incentive to Hold You Accountable for Crimes
the EPO's corrupt management boasted (on television) that it would ignore rulings against it even if issued by the highest Dutch court
Links 23/01/2025: US Constitution Already Besieged (Impeachable Offences Pile Up), Arrest Warrant for Assad
Links for the day
Microsoft's Head of Business Development Quits (Days After Two Large Waves of Mass Layoffs)
We recently learned that people close to the management are very stressed this month
[Meme] Reliable Sources
Sooner or later LLMs swallow up their own lies (that they generated), which means that over time those things will only deteriorate further, exacerbating an already-large misinformation pandemic
BetaNews Plagiarising Work in the Linux Space
The originals won't even be listed
Gemini Links 23/01/2025: US Politics and DevOps Career
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, January 22, 2025
IRC logs for Wednesday, January 22, 2025
Links 22/01/2025: Jeju Air Blame-Shifting (Talk to the Wall), Copyright Maximalism Rebounds
Links for the day
[Meme] The 'Garbage in, Garbage Out' Patent Office
"law of the buzzword"
Clueless and Nontechnical EPO Management Uses the 'Great Scam' (Hey Hi Hype) to Justify Automation Where It's Both Detrimental and Illegal
The EPC has been practically set aflame; thus, the EPO has no legitimacy or reason to exist anymore
Links 22/01/2025: Democratising Tech Initiative and "Bye Bye Meta"
Links for the day
The Japanese translation of the term "free software"
by Akira Urushibata
Links 22/01/2025: "The AI Bubble Is Bursting" and Microsoft's Scam Altman is Already Looking for De Facto Bailout From the Insurrectionist
Links for the day
Dr. Andy Farnell's Latest Article About Software Freedom and Richard Stallman
why Dr. Stallman is being picked on
Geminispace (Gemini Protocol) Offers an Escape From Social Control Networks Owned by Oligarchs and Governments
Gemini capsules that promote fascism and retreat to feudalism are rare and scarce
The Free Software Foundation (FSF) Has Formally Added an Outreach and Communications Coordinator
Maybe the addition happened last year (we mentioned it in passing), but now it's in the "rota"
Electronic Frontier Foundation: Fighting 'for the Poor and Powerless' While Taking Home $336,000 in Annual Salary
nowadays works for or serves not the interests of the masses
Of Note: The Misguided, Infiltrated, Weakened Electronic Frontier Foundation (EFF) Now Operating at a Loss of Over a Million Dollars
Worst since the COVID-19 lockdowns
Free Software Foundation's Miriam Bastian: We Surpassed Our Year-end Goal of $400,000 USD Thanks to You!
Miriam Bastian: We surpassed our year-end goal of $400,000 USD!
[Meme] Omit Microsoft When It's a Scandal or a Breach, Whereupon It Becomes Just an 'IT Company'
Microsoft is like a cult. Members of this cult promote the opposite of security, expecting to be financially rewarded for it.
Calling Out Windows (TCO) is Apparently Impermissible in Some News Sites
The online news sites are failing us (and corporate sponsors play a role)
Richard Stallman's Remarks on His Pain
Published two days ago
Focusing on the Issues
we'll do our best to find the news and not talk about "Mr. T"
Only About 3.6% of Web Users in Pakistan Use Vista 11, According to statCounter
It's not hard to see why so far in 2025 Microsoft has already had several waves of mass layoffs - more than any other company
Rumour: In IBM, Impending "25% Reduction in Finance Roles"
25% to be laid off?
[Meme] Fake Articles From linuxsecurity.com (Just Googlebombing "Linux" With LLM Slop)
Google should really just entirely delist that site
RedHat.com Written by Microsoft Staff, Promoting Microsoft' Proprietary Software That Does Not Even Run on Linux!
This is RedHat.com this week...
Links 22/01/2025: Mass Layoffs at Stripe, Microsoft's Illegal Accounting Practices Under Scrutiny
Links for the day
Fake 'Article' by Brittany Day (Guardian Digital, Inc) About Linux Mint 22.1 'Xia'
Apparently they've convinced themselves that this is OK
Red Hat Dumps "Inclusive Language", Puts "Master" In Official Communications and Headlines
Red Hat: you CANNOT say "master" (because it is racist). Also Red Hat: we put in it our headlines.
Red Hat Offers DRM, TPM, and Backed Doored 'Confidential' Containers (CoCo) for Microsoft (Proprietary Spyware)
No kidding!
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, January 21, 2025
IRC logs for Tuesday, January 21, 2025