Cybersecurity Does Not Mean Asking Microsoft for Permission to Boot
15 years ago Techrights began writing about (and constantly, consistently against) UEFI 'secure' (nope!) boot. There were very good and timely reasons to speak about the matter, including impending antitrust complaints against Microsoft - complaints later refused by Microsoft apologists and village fools on the payroll of Microsoft's business partners. They actively collaborated with Microsoft staff while consuming alcohol. That's how "professional" they were.
After all this time, as predicted all along, there are complaints about expiries of series of bytes - the not-so-magical sequences of 1s and 0s that we are being lied about. We're supposed to think they're (mere bits) somehow going to protect us from real threats to real security.
Having mentioned this in passing yesterday, now "would be a good opportunity to link to this one again," said a reader, linking to "Why We Can't Teach Cybersecurity" by Dr. Andy Farnell (an actual security expert, not someone who pretends to be one and crafts fake Wikipedia pages, marketing/vanity entries that clog up Wikipedia).
The above article has aged well ("or a follow[up] post if he has one," the reader said; he revisited the subject many times in years to come). It basically explains that in today's universities real computer security is frowned upon. See this article about Rossfest. Ross died. His ideas did not.
Going back to the delusion that some 0s and 1s will protect our security, recall how several years ago many 'old' computers (that cannot be updated) stopped having access to Web sites because some root certificate connected to the Linux Foundation just simply expired (a man-made crisis). How does it improve security when an 'old' TV can no longer access the Web?
Now we're heading towards a similar cutoff; The Microsoft Windows perspective is less alarming because Microsoft controls Microsoft and as a Microsoft marketing site put it very recently, "a portion of the Windows install base is running on hardware where that automatic update will never arrive" (so buy a new PC?).
At ZDNet they spoke of Linux and decided to cite a fake security 'expert' (faking it, his spouse agrees) and then say: "But certificates, unlike compromises, have expiration dates."
And what for? What use are these? The notion of (long-term) "dead man switch" is related to this. It's like saying, if this laptop wasn't powered up for a long time, then it's unsafe. Or if some site isn't actively rotating from one certificate to the next, do not dare enter it or you'll be set on fire. It's not about security, it is about control; it's about a remote third party controlling you, the user and owner of a computer. It's about constantly asking some third party for permission. It's akin to DRM; it facilitates kill switching.
As the slopfarm of Bobby 'vibed' a week ago: "The main risk lie in the transition period. New Linux installation images, updated shim packages, rescue media, older hardware, dual-boot systems, and machines with outdated Secure Boot databases may run into issues if they do not recognize the newer 2023 Microsoft UEFI CA. Removing the old 2011 key prematurely can also cause boot problems."
How did it ever improve security? It did not. It just let Microsoft - and by extension the US government - remotely control billions of machines. It takes a real fool with no qualifications in computer programming (or Computer Science/security) to insist outsourcing "trust" to Microsoft somehow means better security. If that's not enough, you send bullying communications and threaten critics with prison (to avoid any misunderstandings, if you send letters like these, very soon followed by threats from burner accounts, there may be a breach of law). This is the mindset of someone desperate to hide something (about oneself). By extension, it's the mindset of somehow who constantly advocates back doors like BitLocker's [1, 2]. Society needs computer security, but not every company (especially in the US) agrees on it. Many companies lies about this. People on their payroll side with the latter because their livelihood (paycheck) depends on it. █
Image source: Rossfest
