Bonum Certa Men Certa

“Wintel” “Secure” uEFI Firmware Used to Store Persistent Malware, and Security Theater Boot is Worthless

Guest post by Ryan, reprinted with permission from the original

Free space

PCMag now reports (And calls out Windows! Good!) that the situation where persistent rootkit malware that doesn’t really need anything except to run once, somehow, on a Windows machine, is now being installed into the system’s uEFI firmware, where it will survive what most Windows users end up doing every time their computer ends up acting weird….nuking Windows and re-installing from scratch.



It was already so much easier for Microsoft to include “Reset this PC” than it was to fix Windows that this has been a staple for the past decade. It sometimes works, unless something has also corrupted the WIM installer image on the recovery partition, which also takes up precious SSD space.



However, with the latest threat to Windows users, which uEFI made possible (as bootkits on legacy BIOS were unheard of), no matter how many times you re-install Windows, no matter whether or not TPM or Secure Boot are on and enforced, it won’t matter. The malware isn’t running in a part of your computer that is subjected to any sort of auditable behavior.



Therefore, the only way to prevent a foothold situation is to get rid of Windows now, while it may not be too late, and replace it with GNU/Linux.



Again, most people find that their “must have” Windows software works in Wine. Sometimes Wine even resurrects programs that Windows itself has been incompatible with or partially broke years ago.



Instead of fixing Windows, Microsoft spends billions in “shadow advertising” to pay “freelance” writers to make “Linux” sound like a security disaster too, so there’s this “false equivalence” in the user’s mind.




My dad used to do the same thing to my mother when she threatened to divorce him. “You know if you leave me, your cancer will come back and there won’t be anyone to help you with that. The kids won’t be able to come back and live with me because I won’t have them”.



Like, here’s the biggest dickhead in the world, right? And mom’s 64 now and she’s fine, and I’m pushing 40, will be 40 in a couple years and some change and I’m fine, right? Bullies always use threats which turn out to be puffery. They want you to think they’re all powerful. And their antics usually get worse as they lose power.



So we should see that Microsoft is acting from a position of weakness.



There’s this whole Truman Show thing going on right now they’re up in the tower panicking because he finally realizes everything around him is fake and he needs to leave, and he finally decides to escape the island.



So all of a sudden there’s a fake nuclear power plant meltdown, and actors getting in the way of his car, and a wind storm being generated on the lake to try to scare him into giving up and thinking he was crazy, and going back to the show. And up until that point, every time he started to question the nature of things, they could always increase his fear of the unknown to overcome his curiosity, or his need to grow. And that’s exactly how abusers operate.



The very act of porting Microsoft Pretender to “Linux” is a part of this psyop.



They fund nasty trolls to imply that there is a remote technical possibility of targeting GNU/Linux users. (Technically possible, but much, much more difficult and far less pay off.)



I have another post coming about that, very shortly.



Just using some back of the napkin math, however, Windows is more than 10 times bigger than GNU/Linux after a fresh install as measured by disk footprint.



Secunia wrote in 2014 that the defect density for open source code was 0.59 defects per 1,000 lines, and for proprietary it was 0.72.



(The bonus in their reports is that the one from the prior year showed that C++ projects tended to be a much bigger security mess than C. Linux the kernel is almost entirely C. Linus was right!)



So if you assume that there’s about 10 times as much source code in Windows (which is amazing, considering that the built-in apps are useless and you don’t get a free fully-featured operating system, only SKUs with various parts of the OS disabled, and most people will try to get a different web browser, LibreOffice, and VLC anyway), and you give Microsoft the benefit of the doubt and assume they’re not writing garbage that’s even worse than the proprietary software average (LOL), there’d still be well over 12 times as many bugs in the Windows operating system as in GNU/Linux, even though Windows doesn’t have good features and quality software included.



(It usually comes with a lot of crapware from the OEM though, and that’s a totally different story, and makes the situation worse.)



There absolutely is a security cost to leaving a ton of garbage laying around and no good security practices for software installation and package management (just a failed crApp Store with fake apps and junk), and Windows “users” (useds) are paying this price every day.



Wisdom comes by seeing bullshit, calling bullshit, and refusing to be a part of the bullshit. Software is getting to be so tertiary to what Microsoft even does to make money.



What they seem to do these days boils down to spawn camping “Linux” while they don’t even use Windows internally that much anymore, in favor of “Linux”, and suing Android OEMs -or- offering to cram pack your new phone with pestware that demands to connect to Microsoft. (Samsung)



I’m heartened that the “news” is starting to rebel against this disgusting spectacle that’s going on around Microsoft Edge lately and is no longer just calling Windows bugs a “PC problem” in every article. Hopefully, the more Microsoft tightens their grasp, the more things slip through their fingers.



Recent Techrights' Posts

Hopefully Slopwatch is Dying
Some of the offending sites we used to keep abreast of descended into a lull
 
IBM's Mass Layoffs Will Continue Until Morale Improves
From recent hours
Links 07/12/2025: Political Catchup, Conflicts, Environmentalism
Links for the day
Gemini Links 07/12/2025: "Lazy Saturday" and Kubernetes With FreeBSD
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, December 06, 2025
IRC logs for Saturday, December 06, 2025
Links 06/12/2025: Science, Hardware, and Slop Fatigue
Links for the day
Contact Your National Representatives (Delegates) at the EPO, Here Are All the E-mail Addresses
We'll say more about this next week
Links 06/12/2025: Panic in the Slop (Chatbots) Industry and Perplexity Sued by New York Times for Plagiarising Articles Under Guise of "AI"
Links for the day
European Patent Office Issues: Points to Raise or Factoids to Share With Delegates of the EPO's Administrative Council
use their native language/tongue
European Readers, Get Ready to Contact Your National Representatives (Delegates) in the EPO's Administrative Council
Perfect timing might be Sunday or Monday
Why We'll Continue Our IBM/Red Hat Focus in 2026
There will be many more departures not only later this month but also next month
Links 06/12/2025: Slop's "Jeopardy Phenomenon" and RAM Shortage
Links for the day
Gemini Links 06/12/2025: Memories, "Sweetness and Burn", and Hope
Links for the day
Every Site That Uses Clownflare Had Worse Downtime/Uptime Record Than Ours
And the same goes for Azure and AWS
Software Freedom Conservancy (SFC) Does Not Work for Freedom, It Works to Secure the Massive Salary of Its President And Executive Director
We must be very effective then
Why (and When) I Become an 'Activist' Against Corruption and Abuse
The dictatorship bans criticism of the dictatorship. That's when there's a deadlock.
EPO Call for Action: Get Ready to Contact Your National Delegates, We Need to Remind Them That They Represent People
Today or tomorrow we'll publish contact details for national representatives in nearly 50 European nations
Links 05/12/2025: More Restrictions on Social Control Media and Slop, "Hype Can Turn to Backlash"
Links for the day
Like With Red Hat and Other IBM Acquisitions, the RAs (Layoffs) Seem to Already Extend to HashiCorp
Of course it is possible that HashiCorp staff just got PIP'ed or saw the writings on the wall and left [...] IBM is just a dying giant
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, December 05, 2025
IRC logs for Friday, December 05, 2025
Massachusetts Institute of Theft (MIT) Nowadays in the Business of Selling SPAM to Prop Up Fashionable Pyramid Schemes
There is nothing benign about it, more so when they misuse the MIT brand to lend credibility to elaborate schemes or scams
Many IBM Departures Today (Last Friday)
Way to go, IBM leadership
The Administrative Council of the European Patent Organisation Has More Reasons Than Cocainegate to Vote for Real Change in the European Patent Office
This is about democracy and accountability in Europe
Gemini Links 05/12/2025: Need for Simpler Systems, Molecular Dynamics, and More
Links for the day
Slopwatch: Not Much Today, Same as in Recent Weeks
Google News got 'conned' (maybe willingly) by one operator of several (at least 3) slopfarms that trash "Linux"
On IBM: "More Layoffs in Minnesota Are Coming" (Unverified Hearsay, for Now)
IBM is having loads of layoffs before the holidays
Links 05/12/2025: Openwashing by Microsoft's 'Open Source' Initiative, Unauthorised War Without Boundaries/Borders Waged by US
Links for the day
Finnish Politician Aura Salla Says Finland Must Dump Microsoft, Citing Security and Control Reasons, Not Costs
She says Finland should quit using Microsoft
Does This Pass the NDA "Sniff Test" at IBM?
In many companies, those who suck up to management get ahead
Links 05/12/2025: Slop Harming Democracy/Elections, More Bans Around the World on Kids' Use of Social Control Media
Links for the day
IBM Has No Layoffs, According to IBM, and According to the Media Parroting IBM
Another day of parrots (losers) who call themselves "journalists"
IBM Will Make You Unemployed On Christmas Eve
lists of people to cull
Within Weeks, Clownflare Has Collapsed Again, Time to Dump Clownflare
It's run by amateurs who, even if you maintain your site perfectly well, will render it inaccessible without prior notice
Cars Getting Worse and More Lethal
Who will be held accountable?
To "Take Back Control" Start With Actions Against 'Tech' (Mass Surveillance, Mass Censorship, Mass Control) Monopolies
collusion, price-fixing, a "cartel" of sorts
Beyond the Hype: Almost Nobody Uses Chatbots, Not Even 1% of Activity Online
3 years ago when Scam Altman (Microsoft) acted as if Google (search) was doomed a lot of the press got paid to pretend this was true
Rumour That Another IBM Round of Mass Layoffs (RAs) in Preparation Before the Current One is Even Completed
IBM still has strong brand recognition (because of its age and past might), but that won't last forever
Techrights Publication Pace to Increase Next Year
one is encouraged to stay indoors
Upgrading the Site
Debugging might be needed, so feedback helps
Why Microsoft is Panicking
Keep advocating (or "marketing") GNU/Linux to Vista 10 (or Vista 7) users... there are still over a billion of them "out there".
Web Developers in the US Can Already Disregard Mozilla, Firefox, and Firefox Users
"Last month, Firefox turned 21"
The Fate of "Blockchains" and "Metaverse" as a Sign of Things to Come for Slop ("AI")
Doesn't that tell us a lot about the modus operandi of these companies?
A Year After the Owner of X (Twitter) Performed Several Nazi Salutes on Stage the Germany-Based and Microsoft-Funded 'FSFE' Decides to Exit X (Twitter)
Will the real Free Software Foundation (FSF) follow suit?
EPO: What Comes Next
European media seems to have been sedated by soft bribes from cocaine addicts
Slopwatch: The Volume of Slop Has Certainly Gone Down a Lot Lately, Slop Image Providers Abandoned/Changed
It's a big improvement compared to past months
Thousands Laid Off at IBM, "Last Day" Yesterday
IBM is a dying company. This is a problem for Red Hat.
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, December 04, 2025
IRC logs for Thursday, December 04, 2025
Gemini Links 05/12/2025: Espressif ESP32-C5 UEXT Module, Pixelfed, and the Web Getting Much Worse
Links for the day