Bonum Certa Men Certa

Microsoft and Its Boosters Worsen Linux Security

posted by Roy Schestowitz on Dec 01, 2023

The circus goes on and on. Latest:

UEFI flaws allow bootkits to pwn potentially hundreds of devices using images: Secure? But whose standards?

Hundreds of consumer and enterprise devices are potentially vulnerable to bootkit exploits through unsecured BIOS image parsers.

Security researchers have identified vulnerabilities in UEFI system firmware from major vendors which they say could allow attackers to hijack poorly maintained image libraries to quietly deliver malicious payloads that bypass Secure Boot, Intel Boot Guard, AMD Hardware-Validated Boot, and others.

Dubbed "LogoFail," we're told the set of vulnerabilities allows attackers to use malicious image files that are loaded by the firmware during the boot phase as a means of quietly delivering payloads such as bootkits.

The vulnerabilities affect the image parsing libraries used by various firmware vendors, most of which are exposed to the flaws, according to the researchers at Binarly.

Image parsers are firmware components responsible for loading logos of vendors, or workplaces in cases where work-issued machines are configured to do so, flashing them on the display as the machine boots.

THE article above was shared just moments ago in IRC (by Sompi). It's yet another one of many such revelations and incidents. It's important to distinguish real, inherent security (auditable, reproducible, small and simple enough to exhaustively traverse and learn) from marketing junk and junk science. One need not go far back in time (just over a week) to grasp perils of Windows and shortcomings of fingerprint biometrics - i.e. quasi-futuristic security theatrics and gimmicks.

Where does this end? What happened to proper engineering?

The Microsofters like to break things and block Linux from booting and installing. Of course they call this whole charade "security" and anyone who questions their motives is "against security" or "homophobic" or something to that effect... so do not ever criticise what they do. Questioning Microsoft is an act of intolerance and disregard for the supposed needs of "Big Users" of Linux...

It should be noted that Microsoft's Poettering is pushing similar things and worse via systemd (even TPM). We covered this before. It'll get worse over time. As one reader put it some hours ago: "The Poettering-driven merge of /usr/bin and /bin is going to cause a tremendous amount of further damage to both the technological base as well as the community and add a lot of unnecessary effort."

This reader moreover cited "The collapse of Debian" - an ongoing discussion that relates to the above. And "there is a good three-point summary further down on the first page," this reader said, though to quote the top part: "Fedora and Ubuntu has nothing on what Debian was, and Debian is no longer what it was. We no longer have in our midst that which we used to have, and now more than ever need."

Almost all my machines run Debian and I heard that Debian 12 can be tough on some desktops/laptops. Heck, this site's server runs Debian 12, but so far no major issue. 4 Debian Developers have been added in 2 months, so one can hope the project can survive and thrive in an age when both IBM and Canonical push Microsoft agenda.

While GNU/Linux usage sure is increasing [1, 2], both in homes and businesses, the freedom of it is being compromised and security intentionally sabotaged (hence, many consider or move to BSD). It's rapidly becoming yet another back-doored platform that is vulnerable enough to be deemed "enterprise-ready" by the likes of the NSA.

Other Recent Techrights' Posts

Debt as the New Currency?
Rich people get richer because they take money from the rest of us, if not directly then by compelling us (collectively) to borrow money at a national level, then "invest" in them
EPO People Power - Part XIX - "Berenguer Has Known of Campinos' Substance Abuse First Hand For a Long Time"
"You rightfully claimed that Berenguer is Campinos' protegee"
Slopfarms About the "Linux CEO" Linus Torvaldos [sic]
nowadays NVIDIA builds and helps build a giant Ponzi scheme
IBM Layoffs in India, More Coming Soon, Say Apparent Insiders
Threads regarding IBM layoffs
 
Reality Check About IBM's Louis Grestner, Slopfarms Say He Was IBM CEO for 30 Years!
It is "hallucinating" (lying)
Gemini Links 30/12/2025: Quitting Coffee, Apartment by the Beach, and Strange Retail Ethics
Links for the day
Nintendo and Sony Outsold Microsoft XBox by 15:1!
The mass layoffs indicate Microsoft is aware of this
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, December 29, 2025
IRC logs for Monday, December 29, 2025
Slopfarm: Firing 35,000 Employee is "Saving the Company"
"Big Blue" is getting smaller all the time
Vista 11 is "10" (Ten Percent)
Some months ago Microsoft openly admitted that it had lost (shed off) hundreds of millions of Windows users
Dealing With Online Pogroms
lawfare funded by third parties
The Year Apple Would Rather Forget
We await further stumbles and falls from Apple (in 2026)
"EU's reform agenda threatens to erase a decade of digital rights"
This is really sad for those of us who spent decades promoting and boosting/advocating the EU
Gemini Links 29/12/2025: Earlier "Happy New Year 2026" and "Dead Archivist Society"
Links for the day
Links 29/12/2025: Putin Critic Sergei Udaltsov Imprisoned, Cloudflare’s Outages Discussed
Links for the day
LLMs Are Inherently Parasitic, We Need to Treat Them Accordingly
a maintenance burden for those who possess actual intelligence
Links 29/12/2025: Bottled Water Considered Harmful, Cheetos Promoting Nazis in Europe
Links for the day
EPO People Power - Part XVIII - European Patent Office "Paints Itself as Progressive While Literally Being Represented by Cokeheads"
To what length/s will German authorities and media (not just in Germany) go to protect the EPO's "precious image"?
What IBM Will Do to Red Hat in the Coming Year or Years
This won't end up well for GNU/Linux as a whole
Not Turning in His Grave: When People Die, Their Corporate Destruction Becomes a "Turnaround"
All he did was mass layoffs - a tradition that has not ended since then
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, December 28, 2025
IRC logs for Sunday, December 28, 2025
Louis Gerstner Has Died, His Legacy of Mass Layoffs at IBM Hasn't
Hagiographies will follow. They will say he "saved" IBM.
Links 29/12/2025: The Sunday Routine, Limits of Memory, and Gemini Vocabulary
Links for the day
Doxing is Illegal in the UK (Even If You're Based in the US)
Somebody has just added my identity (name, mugshot etc.) to a "hitlist" site of a political nature, pandering to violent people
Misunderstood Weapons of Censorship
It's cruel world out there. One needs to be aware of these shady activities, including "censorship-as-a-service".
Google Confidently Wrong, Nowadays Defaming People Too
I can relate as people did this to me and to my wife
What Happens When Americans Are Out of Office (Away From Work) for a Week? Vista 11 "Share" Falls to Just 10%.
How's that for slow adoption?
2026 Will Have EPO Focus, People Will See What the EPO is Trying to Hide
We certainly hope people will be held accountable
EPO People Power - Part XVII - Drugged, Stoned, and Drunk at the Office During Working Hours (Campinos Friend and Propaganda Chief Has Long Done This)
It's a total disgrace that press all over Europe is still trying to cover this up!
Gemini Links 28/12/2025: Health Ordeals and Discontinued Pedals
Links for the day
Slop About "Linux" Came Only From One Slopfarm This Weekend
Another day has passed with no LLM slop found in our RSS feeds
Links 28/12/2025: 'Digital Detox' and Slop "Backlash Grew Massively in 2025"
Links for the day
Links 28/12/2025: "Mass Quitting Apple" and "Generative AI Industry is Fraudulent, Immoral and Dangerous"
Links for the day
Links 28/12/2025: Fascination, Holidays, and Mormonism
Links for the day
Microsoft's Weapon Against the Reality of XBox (the Console) Dying Seems to be LLM Slop
XBox is dead/dying
Raffles for the Immaterial: Unauthorised Bingo for Red Hat "Vouchers"
This is IBM and some slop images
Andy Farnell on Standing Up Against Technological Oppression
some portions from it
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, December 27, 2025
IRC logs for Saturday, December 27, 2025