Bonum Certa Men Certa

Microsoft and Its Boosters Worsen Linux Security

posted by Roy Schestowitz on Dec 01, 2023

The circus goes on and on. Latest:

UEFI flaws allow bootkits to pwn potentially hundreds of devices using images: Secure? But whose standards?

Hundreds of consumer and enterprise devices are potentially vulnerable to bootkit exploits through unsecured BIOS image parsers.

Security researchers have identified vulnerabilities in UEFI system firmware from major vendors which they say could allow attackers to hijack poorly maintained image libraries to quietly deliver malicious payloads that bypass Secure Boot, Intel Boot Guard, AMD Hardware-Validated Boot, and others.

Dubbed "LogoFail," we're told the set of vulnerabilities allows attackers to use malicious image files that are loaded by the firmware during the boot phase as a means of quietly delivering payloads such as bootkits.

The vulnerabilities affect the image parsing libraries used by various firmware vendors, most of which are exposed to the flaws, according to the researchers at Binarly.

Image parsers are firmware components responsible for loading logos of vendors, or workplaces in cases where work-issued machines are configured to do so, flashing them on the display as the machine boots.

THE article above was shared just moments ago in IRC (by Sompi). It's yet another one of many such revelations and incidents. It's important to distinguish real, inherent security (auditable, reproducible, small and simple enough to exhaustively traverse and learn) from marketing junk and junk science. One need not go far back in time (just over a week) to grasp perils of Windows and shortcomings of fingerprint biometrics - i.e. quasi-futuristic security theatrics and gimmicks.

Where does this end? What happened to proper engineering?

The Microsofters like to break things and block Linux from booting and installing. Of course they call this whole charade "security" and anyone who questions their motives is "against security" or "homophobic" or something to that effect... so do not ever criticise what they do. Questioning Microsoft is an act of intolerance and disregard for the supposed needs of "Big Users" of Linux...

It should be noted that Microsoft's Poettering is pushing similar things and worse via systemd (even TPM). We covered this before. It'll get worse over time. As one reader put it some hours ago: "The Poettering-driven merge of /usr/bin and /bin is going to cause a tremendous amount of further damage to both the technological base as well as the community and add a lot of unnecessary effort."

This reader moreover cited "The collapse of Debian" - an ongoing discussion that relates to the above. And "there is a good three-point summary further down on the first page," this reader said, though to quote the top part: "Fedora and Ubuntu has nothing on what Debian was, and Debian is no longer what it was. We no longer have in our midst that which we used to have, and now more than ever need."

Almost all my machines run Debian and I heard that Debian 12 can be tough on some desktops/laptops. Heck, this site's server runs Debian 12, but so far no major issue. 4 Debian Developers have been added in 2 months, so one can hope the project can survive and thrive in an age when both IBM and Canonical push Microsoft agenda.

While GNU/Linux usage sure is increasing [1, 2], both in homes and businesses, the freedom of it is being compromised and security intentionally sabotaged (hence, many consider or move to BSD). It's rapidly becoming yet another back-doored platform that is vulnerable enough to be deemed "enterprise-ready" by the likes of the NSA. â–ˆ

Other Recent Techrights' Posts

Microsoft-Sponsored Xenophobia and Nationalism
IBM is very similar in this regard
Tentative Summary of Things to Publish in Project 2030
I'll still be in my forties by then
 
Links 21/09/2025: "Hey Hi" (Hype) Under Fire, Fakes Identified; Tesla Burns Family
Links for the day
Google's Software is Malware and Malware in Mobile Devices
Originally posted by Rob Musial
Links 20/09/2025: Hegemony Coming to a Close, Luigi Mangione Ruled Not Terrorist
Links for the day
Gemini Links 21/09/2025: "Charlie Kirk Was a Hateful Piece of Shit" and Slop Code Attempted by Microsofter
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 20, 2025
IRC logs for Saturday, September 20, 2025
Gemini Links 20/09/2025: Snowy Photos and utism is a Spectrum
Links for the day
Vintage is Sometimes Better
Why can't we get back to "simple" if (or where) "simple" means better?
Climate Breakdown Means We'll be Publishing More, Not Less
Press freedom will be a common, recurring theme
Our 5-Year Geminispace Anniversary is Coming Up
I still remember when Gemini Protocol was quite new
It's Right to Point Out Violence From the Right
Violence is a recurring theme
Web Browsers That "Do Hey Hi" (AI)
State-of-the-art plagiarism or "autocomplete on steroids" (not coined by us, nevertheless a nice description) don't have much/any prospect
Links 20/09/2025: Hardware Projects in View, Some Independent Publishers About Russia Prosper After Cheeto Cuts Funding
Links for the day
Gemini Links 20/09/2025: Options and TV Time Machine
Links for the day
Links 20/09/2025: Retrocomputer, Antique Phone Experience, and More
Links for the day
Links 20/09/2025: Internet Shutdowns, Media Censorship, and Climate Worries
Links for the day
About 700 New Gemini Capsules in 13 Months (or 54 Per Month)
4.8K would represent a 20% increase
Rust People: Drain the Swap, You're Holding It Wrong
Does Rust make sense?
Techrights the Name Turns 15
About 6 weeks from now we turn 19
Microsoft is Running Out of Time and Floating Fake Figures, Fake Projects, Fake Narratives, Fake Excuses
Also, a lot of Microsoft's "revenue" claims are circular financing (i.e. Microsoft buying from itself, which means Ponzi-like fraud)
Slopwatch: LinuxSecurity, linuxconfig.org, and Plagiarised Phoronix
Many articles out there are nowadays fake
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, September 19, 2025
IRC logs for Friday, September 19, 2025
Gemini Links 20/09/2025: Navigating the Pressures of Modern Life and SpellBinding Accidentally Wrote Another Gemini Server
Links for the day
Links 19/09/2025: Press Freedom Dying in US, Anti-Austerity Strikes in France, and Alan Rusbridger to Leave 'Prospect'
Links for the day
European Patent Office Illegally Gutting and Outsourcing Its Functions, Acting Like an Above-the-Law Commercial Business (It Won't Stop at Formalities Officers (FOs) and Classification Slop at the EPO)
breaking/violating laws and conventions
Offloading to the Sister Site
In the interest of not overwhelming readers
Links 19/09/2025: Coffee Club and "SpellBinding is Now Absurdly Fast"
Links for the day
Links 19/09/2025: Lobbyist of American GAFAM Becomes Data Protection Commissioner in Europe
Links for the day
Links 19/09/2025: Media Freedom Ceases to Exist in US, "Consider Dropping Twitter/X"
Links for the day
Gemini Links 19/09/2025: Thinking and Insect Bites
Links for the day
Microsoft E.E.E.: Git Will Now (or Very Soon) Fully Depend on Rust, Which is Controlled by Microsoft
Microsoft now makes Git dependent on Rust, or making Git dependent on GitHub, which is proprietary
The Right to Punch People (Apparently)
At Brett Wilson, Brett's job title is "Head of Crime" and Wilson normalises calls for violence
Slop or Fake Articles Have Turned Linux Journal From a Pioneering/Trailblazing "Linux" Magazine Into a Nuisance
some sites with former reputation - good reputation - turn into cesspools
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 18, 2025
IRC logs for Thursday, September 18, 2025