Bonum Certa Men Certa

The UEFI 9/11 - Part VII - This Coming Week Many PCs Will Refuse to Boot "Linux" (Because of Microsoft's Expired Certificate)

posted by Roy Schestowitz on Sep 06, 2025

A simple time bomb: Fake Security, Microsoft, UEFI, 9/11 vs Your O/S

Love it or hate it, more and more people are moving to GNU/Linux and many PCs ship with UEFI. Many existing PCs already have it and have had it for years. Many are configured, by default, to use "secure boot". Many won't be able to cope with certificate rotation (the proprietary firmware blobs are notoriously buggy) and even if updates become available - which is far from a certainty - installing them is super-risky (in part because those are barely tested and are notoriously buggy; a lot can go wrong and if it goes wrong, undoing the harm is almost infeasible for an ordinary person; it's worse than Windows breaking things because this is done closer to the hardware - rendering this a chicken-and-egg problem a la locking oneself out).

This is why throughout the week we'll keep reminding people (here and in the sister site) to turn off "secure boot" or "SecureBoot". It's imperative for people who value reliability and resiliency, uptime, data security etc. Being locked out of one's own machine is a really bad outcome. We saw how it played out before, e.g. in 2020 [1, 2]. This is not security, this is just sheer madness.

Updating firmware is not a good option at this time (or any time). Quoting thelayoff.com on IBM (from yesterday): "Yes, your Lenovo laptop is spying on you and sending your information to China. After all, when you install BIOS updates, who knows what those BIOS updates really do. Do you ? Same as your "Made In China" cell phone and the wireless access points updates. Big Brother is China, not Trump. LOL."

It is not security when some opaque, proprietary blob from China gets put inside your system at a very low level, with access to pretty much everything including external peripherals like backup drives. Having a program running as "root" and allowing remote modifications of firmware is not security either. It's insanity! It is promoted by the same people who advocate Microsoft-controlled 'secure boot'.

Today we'd like to debate some more details and refrain from getting too technical; on Monday and Wednesday we'll be concluding ahead of the actual "9/11" of this monstrosity. When we say "9/11" we refer to Chile's 9/11 moment [1, 2]. We explained several analogies/parallels/parables in prior parts. We won't get political about this. It is about commercial ambitions, not political ideology.

In Part I we introduced the issues in simple terms, in Part II we focused on the attacks on people who merely talked about these issues, Part III primarily tied things together, Part IV named some of the culprits, and Part V advised people to turn off "SecureBoot" (also in the sister site now that we're in September; live and learn). Part VI spoke of the "Serious Harm" that will be caused to many ordinary computer users; many will not even understand what the heck is going on; they're too busy to keep abreast of "Linux news" online and they don't have an LWN subscription. Most of them lack a backup option such as a second PC and never in their lifetime saw a boot menu (they might not know that such a thing exists or how to enter/activate it). Heck, some OEMs already make PCS would not let the users disable "secure boot" or "SecureBoot"; some of them refuse to boot anything but Windows (we're looking at you, Lenovo). The issues are very serious - to the point where those responsible for the monopolistic abuse started attacking my wife [1, 2] and when attacking my wife wasn't enough they joined forces with a dangerously violent Serial Strangler from Microsoft. This is what I get for merely talking about those things.

So we should be talking more about those things.

What is it that's happening to the system? Well, UEFI will be checking the time on the system (there's a system clock) and the firmware can then decide whether to boot or not (or what to boot). Although there are few super-geeks out there who take it a step further (e.g. installing one's own keys), way more than 99% of PCs out there don't have the skills nor the setup. The users don't know how to modify these things. Almost nobody would do that also because it is risky (cannot change the firmware, that's for sure). Consider what happened in Red Hat. Even Red Hat with all its Linux engineers couldn't get this right. It's very risky (you can brick or break your system, so either you get kicked out by UEFI or you break your own system while trying to mitigate).

Don't tell people to open their PCs and remove the clock's battery; it would not work and almost nobody would open a laptop (the modern ones require special screwdrivers).

It is a basically a giant risk. Very much so. Don't try. And you should not have this risk to begin with; this not security but a lie. It was always a lie.

The real solution is, disable "secure boot" or "SecureBoot" while it's still possible. Microsoft and OEMs will try to make it infeasible, at risk of angering people (expected PR toll).

Just like submarine patents, a lot of this problem was "hibernating" for a while, in effect artificially contrived right from the beginning in 2011. And it's not a matter of whether it's coming; it's a question of when.

In collusion with Red Hat and Canonical and enabled by terrible people with their online mob ('cancel brigade'), Microsoft promoted this 'inevitable' outcome. This collusion got the courts off of Microsoft's back with no further investigation after that (saying that shim was somehow a solution). We can still recall a complaint started in Spain but not limited to Spain; the European Commission or European authorities were meant to look into it, but then the Microsofters stepped in, plus they were libelling everyone who did not agree with them. Matthew J. Garrett did this nonstop. He cannot even keep his Web site online (why trust him with your PC?).

Now he openly admits that someone pays him to attack me. He might end up causing serious harm to his sponsors. Judges are beginning to realise both cases - his and the Serial Strangler's - are conjoined and classic abuse of process done from another continent for a large company to gain. Are Free software community folks and Techrights readers up to the task of finishing this job and getting costs ordered against them and maybe the two Directors of the LLP, who facilitated and coordinated this abuse? It's hardly infeasible, based on my research as LIP. This matter will be covered separately some other day.

Other Recent Techrights' Posts

Evri (HermesUK) is Now Run by Bots and Hallucinating Scammers
Years ago they virtually removed support and tried chatbots instead
Clown Storage Without Backups
Setting up several reliable copies of the data, plus several off-site backups (this data is nowhere as sensitive as medical data), should only cost a few grand
FreeCAD is Becoming Slop-ware, Use LibreCAD Instead
It has regular releases and "Qt5 is mandatory" now [...] they at least audit what they add
 
GNU/Linux in Ecuador and Colombia: Growing, Still Below International Average
locals turn away from Windows and try GNU/Linux instead
IBM is Dead or Dying. Now It Asks Workers to 'Resign' Voluntarily.
To save face, to pretend no layoffs are happening (as it might alarm shareholders) [...] We keep hearing more and more stories like that
Links 18/08/2026: Sergey Brin Controlling State Policies, "Dario Amodei's (Anthropic) Wife Is Closely Linked to Jeffrey Epstein"
Links for the day
SBS News Interviews Daniel Pocock
The locals say this PR stunt (by the bigot, Farage) was a waste of money
Clownflare Sees One in 7 Web Requests in Libya Originating From GNU/Linux
GNU/Linux has taken a (foot)hold there
Openwashing and Manifestos Composed in Private by Dictators With Deliberately Addictive (and Subsidised, Bundled) 'Tech'
It's long, so make a cuppa first
SLAPP Censorship - Part 153 Out of 200: Decades of Debt, Weaponising Borrowed Money to Try to Put Their Critics in Debt
they've always had a financial report by now
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, August 17, 2026
IRC logs for Monday, August 17, 2026
Gemini Links 18/08/2026: Solar Power, Kipple and Impermanence, Catastrophe Ethics
Links for the day
Less Technology, More Life
Technology is being associated (sometimes rightly) with physical and mental problems
Google Search Has Gotten Worse (a Lot Worse)
getting worse
Birthday in 80 Days
we'll start decorating and party online with our community
Loans and Massive Debt at Microsoft, This Won't End Well.
Microsoft running out of money to pay salaries (to the point of paying people for 'voluntary' layoffs) is a positive sign?
Gemini Links 17/08/2026: Life in Plain Text, Mimicking KARL, Release of Jugulans, Avoiding Slop
Links for the day
Cuba and Venezuela High in Adoption of GNU/Linux
some of the "communist" nations
Links 17/08/2026: Myanmar’s Cholera Outbreak, China Sends Commercial Vessels Through Arctic
Links for the day
GAFAM Loyalty Has Come to an End, Morale Low, People Whose Future is Uncertain Choose to Become "Lifers"
morale is low and there's no loyalty anymore
SLAPP Censorship - Part 152 Out of 200: Injunctions Do Not Cover Criticism, They Have Scope
self-incriminating communications
Clownflare Sees About Quarter of Web Requests in Ireland Coming From GNU/Linux
Well, in Ireland it seems like many people adopted GNU/Linux
Clownflare: In Australia and New Zealand GNU/Linux Peaks at Over 10% During Working Hours
That right there is interesting in its own right
Slowing Down by Intention
At the moment we have 6 or 7 ongoing series
Gemini Links 17/08/2026: Chamboree, Partial Solar Eclipse, Lady Macbeth
Links for the day
Links 17/08/2026: "Bluesky Is Down Again!" and "Anti-Social Media"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 16, 2026
IRC logs for Sunday, August 16, 2026
A Vortex of Beacons (or "Bluetooth Everywhere" Vision)
If someone (or someones) calls you paranoid for taking about "beacon"-like functionality, there will be no lack of authoritative citations (e.g. Web links) they can be provided to prove them wrong
Falkland Islands: GNU/Linux Elevated to 6%
GNU/Linux usage seems to have increased a lot there
Links 16/08/2026: Reading Outside, Going Offline More, and Art of Computer Programming
Links for the day
The Question of Patience
Is there a lesson here somewhere?
IBM May be Sued for Mass Layoffs Via PIPs
Some whole threads (with all the long comments in them) recently got nuked by thelayoff.com
Links 16/08/2026: Ceuta Reports Social Control Media Used as a Weapon
Links for the day
Links 16/08/2026: Europe in Crisis of Droughts While Energy- and Water-Consuming, Pollution-Emitting Chatbots Are Spread by GAFAM (US) to Keep a Ponzi Scheme Going
Links for the day
GNU/Linux is a Platform for Work (Usage Surges in Daytime)
GNU/Linux 15% in daytime
We Need Rain, Not Chatbots
There's no "anti-AI" (it's not even AI), there's opposition to fraud, to plagiarism, and to companies that profit more when there's global warning (caused in part by their business activities)
SLAPP Censorship - Part 151 Out of 200: Dealing With Sleazy People and Companies That Steal (While Employing These Sleazy People)
we offer a quick summary and we're reflecting
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 15, 2026
IRC logs for Saturday, August 15, 2026
Gemini Links 16/08/2026: Sterrenkijker Releases, Solar Gemini Server
Links for the day