UEFI 'Secure Boot' Still Not Secure in 2026, New Holes (or Bypasses) Still Being Found
We have criticised restricted boot for nearly 15 years already and did interviews about it with Intel managers, RMS, and all sorts of luminaries. In some sense, we're probably the foremost critic of restricted boot because we have a good enough grasp of technology. We can explain why restricted boot is a scam, it is not security. This week we see new reports about the restricted boot scam, e.g. "11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot" with a video illustrating the bypass.

Some security, eh? As usual, restricted boot is a sham or a scam that typically worsens security (increases the attack surface too), it does not improve anything at all!
Mirko Zorz, Director of Content at Help Net Security, has said: "The vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and assorted boot tools can run with Secure Boot on. Eleven of those signed shims turned out to be old enough to undo the protection they were meant to support. ESET researchers found the vulnerable versions, all at 0.9 or below, and Microsoft revoked them in its June 9, 2026 Patch Tuesday update."
In 2026 there are still many people who call it "secure" and pretend to themselves that it is about security. It's not. It never was. Its loudest proponents are not even security experts, they try to intimidate or silence those who are. █
