Bonum Certa Men Certa

UEFI Restricted Boot No Longer Valid for Security, Keys Leaked

As much about security as multimedia DRM

Drip



Summary: Antitrust offences with UEFI restricted boot can no longer be defended as an act of enhancing security because keys are leaking

A Fedora developer was the first to embrace Microsoft's restricted boot, so Fedora was usually ahead of the curve when it comes to it and it shows.



Torvalds criticised Red Hat for complicity with Microsoft [1, 2] after he had slammed restricted boot as something that would not improve security. He was right. Keys were inevitably leaked, leaving UEFI restricted boot (which former Novell/SUSE developers too helped promote) in a position where it is only an antitrust issue and nothing to do with computer security, just protectionism. As one new article puts it, the "Linux Lawsuit Shines Uncomfortable Light on UEFI Standard" and a Restricted Boot proponent leads with this news about UEFI signing keys getting leaked:

A hardware vendor apparently had a copy of an AMI private key on a public FTP site. This is concerning, but it's not immediately obvious how dangerous this is for a few reasons. The first is that this is apparently the firmware signing key, not any of the Secure Boot keys. That means it can't be used to sign a UEFI executable or bootloader, so can't be used to sidestep Secure Boot directly. The second is that it's AMI's key, not a board vendor - we don't (yet) know if this key is used to sign any actual shipping firmware images, or whether it's effectively a reference key. And, thirdly, the code apparently dates from early 2012 - even if it was an actual signing key, it may have been replaced before any firmware based on this code shipped.

But there's still the worst case scenario that this key is used to sign most (or all) AMI-based vendor firmware. Can this be used to subvert Secure Boot? Plausibly. The attack would involve producing a new, signed firmware image with Secure Boot either disabled or with an additional key installed, and then to reflash that firmware. Firmware images are very board-specific, so unless you're engaging in a very targeted attack you either need a large repository of firmware for every board you want to attack, or you need to perform in-place modification.


Now we know that UEFI restrictions had nothing to do with security and eventually became just a competition barrier. Rather than cracking we are seeing leaking as the end of UEFI restricted boot's (or 'secure' boot's) reputation.

Recent Techrights' Posts

"AGI" is Decades Old and It Never Found a Viable Business Model or Real, Actually Useful Use Cases
I keep reminding people of local firms (right here in Manchester) doing the same thing the media now calls "AGI"...
SLAPP Censorship - Part 158 Out of 200: Making Alliances With Men Arrested for Strangling Women Was Always a Terrible Strategy
They work for American slop companies
 
Links 23/08/2026: Slop "Children's Stories Contain Bizarre Patterns" and "Butterflies at the One Garden"
Links for the day
SLAPP Censorship - Part 159 Out of 200: Telling Courts False Information and Spoon-feeding Them Insults, Hoping or Expecting Them to Repeat These Insults
When lawyers trick courts into repeating something false
Microsoft is in Double Trouble in Singapore
Android+GNU/Linux+ChromeOS are near 20%
The Slop Industry Bribed the Media to Pretend It Has Something New and Revolutionary. Now It Bribes Politicians Too. Anything to Avoid Scrutiny and Regulation.
borrowed money has long been used to bribe the media
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 22, 2026
IRC logs for Saturday, August 22, 2026
Microsoft to Its Workers in April-May: You're Too Old, Go Away. Microsoft in August: Young People, Go Away.
What does this company even sell anymore?
Clownflare Data US-Centric
We are assuming that for national security reasons not many sites in Chinese (or based in China) outsource their traffic to Clownflare
Gemini Links 22/08/2026: Broken Car, Devuan, and Thundermail
Links for the day
Links 22/08/2026: Prince Harry, Elton John and Others Pay High Price for Frivolous Litigation in the UK
Links for the day
'Voluntary' Mass Layoffs at IBM/Red Hat
IBM does not want people to notice what truly goes on there
Another Round of GAFAM Layoffs, This Time Apple
Now Apple "is shutting down an entire Vision Pro team focused on developing gaming features for the mixed-reality headset."
Gemini Links 22/08/2026: The Bodyguard (1992), Minimalism, Backups, and IPFS
Links for the day
Links 22/08/2026: TikTok Settles With Feds, Harms Caused by Social Control Media Gaining Attention
Links for the day
New Data Shows Microsoft's XBox is Really Dying
XBox is a "burning platform"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 21, 2026
IRC logs for Friday, August 21, 2026
Sources-First Publication
Thank you for keeping us on track
Ubuntu is Not Linux
I was one of the first users of Ubuntu
Links 21/08/2026: Outrage Over Politicians Who Support Slop-Feeding Data Centres, "America Is About to Get More Expensive"
Links for the day
Gemini Links 21/08/2026: Rain Coming Back and "Small Internet"
Links for the day
Mass Layoffs at IBM, But Mostly in Secret (PIPs and 'Voluntary' Redundancies)
Gerstner laid off a record number of people; Krishna tries to find 'innovative' new ways to cause workers to leave
Slop-ware: Nobody Knows What Code Goes Into Linux and Most Developers Cannot Understand the Rust Code (Even If They Tried)
So nobody is in charge
The Slop Pyramid Scheme (Not Boon!) Isn't Good for GNU/Linux, Even If the Plagiarism Engines (Framed as "Training" or "Intelligence") Almost Always Run GNU/Linux
We need the slop pop - we need the bubble to pop
North America: GNU/Linux Measured at 13%-15% Every Night
many (north) Americans use GNU/Linux at home and are using it to access the Web in the small hours of the morning
Links 21/08/2026: "Silicon Valley’s Billionaire Cults Are Coming for Democracy" and "Who’s Raking it in as the National Debt Explodes?"
Links for the day
SLAPP Censorship - Part 157 Out of 200: What is a 'Defamation Troll'?
"Defamation Mill" also
Northern Europe Leads the Pack in Abandoning Windows After Threats Made to Greenland (Says Clownflare Data)
Clownflare has a vast trove of data, so it cannot be easily dismissed as pure nonsense
Clownflare: In Past 12 Months Microsoft Windows Fell From ~80% to ~75% on Desktops/Laptops in Asia
Microsoft is deep in debt
Secret Layoffs at Microsoft, Apparently More Sites Will Shut Down Entirely
vindicates us and serves to affirm what we've said for over a month
The State of Slopfarms About "Linux" in August 2026
The Web needs serious cleanup, which curation can help deliver
IBM Offers Workers Some Money to Fire Themselves, It's Called "Next Step" and It's Allegedly 'Extended' (Not Enough Fools Have Fired Themselves)
Will IBM executives - including the CEO - ever be held accountable?
£5 Million Unsolicited/Undisclosed Bribes and What That Means to British Politics
It still remains unknown (disclosure denied) who helps fund the £1 million lawfare against us
[Satire] Pocock, Binface & nobodies vs Farage: defamation before UK High Court
Reprinted with permission from Daniel Pocock
The IBM Censorship Team, PIPs (Silent Layoffs) in IBM Europe
There seem to be many de facto layoffs going on at IBM right there
SLAPP Censorship - Part 156 Out of 200: Brett Wilson LLP Becoming Wilson FC
Now acting almost like one-person shop (lots of staff has fled this past year)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, August 20, 2026
IRC logs for Thursday, August 20, 2026
Gemini Links 21/08/2026: "Ensmallening the BigWeb", "Rust Dependencies"
Links for the day