Bonum Certa Men Certa

With UEFI, TPM, Pluton Etc. Microsoft and Intel/AMD Trashed an Entire Generation of Computers, Made Security a Lot Worse in Order to Curtail GNU/Linux and BSD Adoption



Reprinted with permission from Ryan Farmer.

UEFI is Trash: Part 2 “Destroy the Computer to Continue Using Windows 11!”



This is a follow-up to my last post about System76 getting rid of UEFI and putting in Coreboot for their laptops.



UEFI is a security disaster.



Lenovo has patched my UEFI over 30 times and there are still releases like this month’s.



Modified:
1.  Enhancement to address security vulnerability CVE-2022-44611, CVE-2023-22616, CVE-2023-22615, CVE-2023-22612, CVE-2021-38578,
                                                  CVE-2022-24350, CVE-2023-22613, CVE-2021-38575
2.  Enhancement to address security vulnerability CVE-2022-46897, CVE-2023-27373, CVE-2023-26090, CVE-2023-27471, CVE-2022-24351,
                                                  CVE-2023-0286, CVE-2022-4304, CVE-2023-0215, CVE-2022-4450, CVE-2023-28468
3.  Enhancement to address security vulnerability CVE-2022-40982
4.  Enhancement to address security vulnerability CVE-2022-36392, CVE-2022-38102, CVE-2022-29871

-Lenovo


That’s TWENTY-TWO security vulnerabilities with a CVE that they’ve patched in one update (out of over thirty since this laptop was released in November 2020).



They’ve all been about like this.



“Security Expert” Matthew Garrett shows up to many debates about firmware, talking UEFI up as if it were possible to secure, if they even knew what they were doing with it.



Which they obviously, demonstrably, do not.



The recent Windows 11 “Unsupported Processor” error, had Microsoft say they were “working with OEMs” to provide “firmware updates”.



You’d need Windows to install the update, and Windows is already hosed if you got the update this month (you are making backups, right?), because it caused the system to Blue Screen of Death before the desktop is available to run any programs.



And even if you do install UEFI updates, which most users do not ever do, even once, you run the risk of bricking the entire computer to get Windows to behave itself enough to even do anything after you install the August Update.



(That’s if it doesn’t install the August Update and try to reboot itself while you’re trying to update the firmware. Does it still do things like this? Windows 10 was forcibly restarting for updates while people were live streaming games and had Microsoft Office open.)



Every time you update your firmware, any one of a million things can go wrong and leave the computer’s main board (which in a laptop has the CPU, RAM, and SSD soldered in sometimes, so kiss everything goodbye) utterly ruined.



That could be a Windows program (or virus) messing up the update process, Windows itself malfunctioning and freezing the computer before the update goes all the way in, the power going out, etc.



Of course you’re going to play Russian Roulette with your Lenovo laptop three dozen times, right? Right?



And even if it appears to update the UEFI, I have actually lost a motherboard (from Acer) while updating the correct firmware revision, and then had Acer refuse to do anything about it, so I had to find another motherboard that fit the case, and rebuild the entire desktop computer. (Which I’m sure all of you know how to do.)



So if you’re affected by Windows refusing to let you continue until you update the UEFI, it’s safer to just remove Windows and install Linux instead, because Linux doesn’t have fake errors like this.



It’s also worth mentioning that when I started tinkering with Windows 98 as a child and gutting the operating system of Internet Explorer, the Trident engine, the Windows 98 Shell Update (installing the Windows 95 B Shell), Outlook Express, and the several dozen useless components of Windows, using RoM II, I rebooted.



I said, “This is cool! Without all that Internet Explorer junk around, my games run 10% faster!”.



It was like a free graphics card, RAM, CPU, and hard disk update!



Even back then things were, relatively speaking, as bad as they are now, with the bloat.



You had a 4 GB hard disk and here comes Microsoft to spew at least 300 MB of useless trash all over it, you had a PC that came from the factory with 32 MB of RAM, or 64 if you were lucky, uh oh, here’s a bloated shell with IE stuff in it that takes up 11 MB more than it should!



They’ve always considered everything in your PC pretty much theirs to waste. You have an expensive PC? They’re wasting it on things you don’t even want to run.



But today, 25 years later, I say, “Let’s remove all this Windows junk so my games can go wheeeeeeee!”.



But for the adult in you, the average Linux distribution includes tons of Free and Open Source Software (as in freedom and price), including an entire Microsoft-compatible office suite that doesn’t go into “read-only” mode if your subscription to “Microsoft 365” lapses, saying “Pay Up, Chump!”.



Windows 11 treats its users like they’re running some kind of awful browser game with in-app purchases.



It’s not even really an operating system.



And you’re supposed to risk damaging a $1,500 laptop to continue running it because Microsoft is too incompetent to fix bugs?



Recent Techrights' Posts

Links 16/05/2026: Climate Issues, Free Speech, and Monopolies/Monopsonies
Links for the day
 
Links 16/05/2026: Cuba Plunges Into Darkness (Energy Wasted by Nonsense), Googlebooks as Slop Nonsense (Energy Waste and Time Wasted)
Links for the day
Gemini Links 16/05/2026: Retreat and Devuan Manuals
Links for the day
SLAPP Censorship - Part 78 Out of 200: Slandering Me for Saying the Truth About Graveley and Garrett's Abuse of Processes, Stacking Dockets
These are the sorts of things British taxpayers ought to talk about
"AI" Became a New Name or Placeholder for Debt
Because they will only ever lose money for this thing with "tokens" or "potential"
"Microsoft Goodwill and Intangible Assets" Down Two Years in a Row, According to Microsoft
Microsoft cannot sell these, so what is their real relevance?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 15, 2026
IRC logs for Friday, May 15, 2026
IBM: Shares Down 30%, Mass Layoffs, IBM Says "Goodwill" Grew by 10% to Over a Third of the Company's Total "Worth"
According to IBM
Microsoft LinkedIn Layoffs "Very Likely Higher" Than 1,000 People
Microsoft is bleeding
The Corrupt Lecture the Non-Corrupt - Part XXIV - Luis Berenguer Giménez at the EPO (European Patent Office) Became the Punchline of EPO Staff
"the fact that Luis was caught with cocaine causes laughter. The use of cocaine in itself is not the real shocking bit."
IBM Keeps Culling Essential Linux, Fedora, GNOME, and GTK Staff
Over a month ago IBM laid off over 400 Red Hat engineers
Cisco Cuts Nearly 4,000 Jobs Because of Debt, Nothing to Do With Slop
The media keeps talking about revenue, not profits
Gemini Links 15/05/2026: UDP Game Forwarding Over SSH, Avoiding LLMs, and Alhena 5.5.9
Links for the day
Links 15/05/2026: Electric Company Shuns Entire Town to Prioritise Only Data Centres, Saudi Arabia and U.A.E. Carried Out Secret Attacks in Iran
Links for the day
LLM Slop is Not Reliable, Constitutes No Process of 'Thinking'; There's No Thought Process at All, No Grasp or Understanding, Let Alone Context
Lies have become the "business model" [...] More people ought to talk about it and explain to other people what LLMs really are
Not a Security Expert If You Cannot Manage to Keep Online a Simple Two-User Mastodon Instance Somebody Else Built
From uptime of ~99% to maybe 80%
Microsoft Has All the Symptoms of a Dying Company (Mass Layoffs of the People Who Built the Company)
the company's debt is going through the ceiling
Focus is Important, Focus is Everything
We are still running 6 multi-part series in tandem
For Effective 'Finlandisation' (Not Digital Sovereignty) to Be Replaced by Autonomy Finland Needs to Think Like GNU (Software Freedom), Not Linux (Openwashing Source, Plus LLM Slop and Killswitches)
What is 'Finlandisation'?
Guest Post on False Marketing and PR Blitzes by Anthropic
A lot of people my age are just tired of the nonsense
Links 15/05/2026: UK antitrust regulator is officially investigating Microsoft Office, Anthropic’s Fraudulent Lies About Mythoslop Don't Withstand Scrutiny
Links for the day
IBM's Kyndryl in Trouble: Mass Layoffs, Payroll Problems, Buybacks (in Company Whose Debt is Almost Twice Its Total Value), and Soon $9 Per Share (Down Over 80%)
Kyndryl is done. Stick a fork in it.
ICYMI: GNU/Linux Did Not Start in Finland
If we're honest/true to ourselves, we need to recognise history for what it is, not what some corporations (like GAFAM) want it to be
IBM is Googlebombing the Media With Fake Numbers to Promote Fake Technology
a classic example of why much of today's media cannot be trusted (anymore)
Up to 10,000 Microsoft Layoffs in a Couple of Months
Many ways to skin a cat
Truth Hurts. People Hurt by Truth Aren't Entitled to Compensation.
Family members aren't exempt
SLAPP Censorship - Part 77 Out of 200: They Never Knew How to Handle Women (Except to Attack Them)
The case against us was really quite simple
Update on Sirius Open Source in 2026 (When Your Former Employer Commits Crimes and Nobody is Held Accountable)
I did not envision myself spending several years (even 4 years after leaving that company) challenging the system for tolerating and even covering up corruption
Codecs and Software Patents - Part VII - Entering Phase II, the Battle Against Companies That Normalise Taxed (by Patents on Mathematics) Codecs
In the next few part we'll deal with the impact on Free software, including the GNU Project
The Corrupt Lecture the Non-Corrupt - Part XXIII - Cocaine Use at the EPO's Top-Level Management "Adds Up" and Worsens Things "Over Time"
"cocaine use knocks the IQ down permanently a tiny bit with each use. Over time that adds up."
Gemini Links 15/05/2026: Slop Fatigue and Banning LLM Use
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, May 14, 2026
IRC logs for Thursday, May 14, 2026
Links 14/05/2026: Health Science, Cheeto Meets Pooh, and Facebook Staff Loathing the CEO
Links for the day
Gemini Links 14/05/2026: Early Morning Practice and Number to Roman Numeral Converter
Links for the day
FSF Advertises the Father of Software Freedom Giving a Talk in Germany (a Digital Sovereignty Interest Hub, Sponsor of Free Software)
Free Software vs malware and the need for reverse engineering
Cybershow (UK) Shaping Up to be a Neat and Very Large Gemini Capsule
If only more platforms did the same, plenty of energy would be spared, "old" machines would be totally suitable (even with 20 tabs open), as we'd focus on substance, not bells and whistles
SLAPP Censorship - Part 76 Out of 200: The Problem With the United Kingdom Allowing Americans to File Lawsuits by Proxy (Relayed by "Hired Guns")
Solicitors in UK warned not to act as ‘hired guns’ to silence critics of super-rich
When Microsoft's LinkedIn Goes Offline All Your Fake Friends/Connections and Manufactured 'Status' Will be Gone
Many people quit social control media because they recognise it for what it truly is
Major Setback for IBM in the Courtroom, the Demolition of IBM is Proving Costly
Kyndryl is a sign of how IBM ("mother ship") is run and where IBM is heading
Links 14/05/2026: Willful Ignorance and Mass Layoffs at Microsoft
Links for the day
Gemini Links 14/05/2026: Rewatching V for Vendetta, JPEG XL, and Platform Migrations
Links for the day
The Corrupt Lecture the Non-Corrupt - Part XXII - What the Science Says About Cocaine in the Workplace (EPO President, Mr. Campinos, Please Take Note)
What the science says
European Patent Office (EPO) President, Mr. Campinos, Ignoring Its Staff While Protecting His Friends
the President is covering up cocaine use while ignoring his own workers
Slop Cannot Replace Everybody (the Story of Perl and Universities)
Quantity where abundance exists is without merit; quality is what people opt for as they have limited time and patience
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, May 13, 2026
IRC logs for Wednesday, May 13, 2026