• pelya@lemmy.world
    link
    fedilink
    English
    arrow-up
    22
    ·
    9 days ago

    You simply sign a corporate contract and pay a corporate fee, and MICROS~1 will sign any shitty broken and backdoored bootloader that you send to them with zero quality control, and it was like that with Windows drivers for years.

  • friend_of_satan@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    9 days ago

    “Complexity is the enemy” is a great quote. Definitely keeping that in my pocket for a future design doc review.

  • cley_faye@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    8 days ago

    That title is misleading. Maybe people didn’t notice that way Secure Boot was broken. But people certainly knows many other ways secure boot is broken.

  • LaunchesKayaks@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    2
    ·
    8 days ago

    The only thing I like about Microsoft is that their shit products give me job security.

    I get to do an extensive Microsoft Teams training for some middle-aged dudes next week. One of the men doesn’t recognize me as someone who can fix his shit. He straight up says, “Have one of your techs, your guys, give me a call” and I always tell him I am a technician and can handle his problem so he doesn’t have to wait. I use my kindest, sweetest customer service voice to talk to him and he has never once called me by my name despite it showing on his computer when I connect to it. He calls me honey and dear a lot and not in the endearing old person way.

    But dealing with him pays the bills so

  • ms.lane@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    edit-2
    9 days ago

    no one noticed

    Did that get Berenstained? I distinctly remember it being broken a decade a ago…

    • 9tr6gyp3@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      9 days ago

      Its been broken multiple times, which is why its important to update your BIOS firmware if your motherboard manufacturer says they have patched security issues.

      • cecilkorik@lemmy.ca
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        9 days ago

        Yes it’s important to always update to make sure you also have the newest security holes in addition to the old ones that nobody’s noticed. /s

    • terabyterex@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      8 days ago

      this paticular fix was never found. this last patch tuesday fixed over 500 vulnerabilities. they ran the kernel through mythos. you will be seeing a loy of companies with big patches comong up.

  • ragas@lemmy.ml
    link
    fedilink
    English
    arrow-up
    3
    ·
    8 days ago

    Wasn’t there this scandal with Gigabyte motherboards, where Secure Boot showed as enabled, but the motherboards still just booted any unsigned bootcode?!

  • spaghettiwestern@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    2
    ·
    9 days ago

    The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them.

  • SaharaMaleikuhm@feddit.org
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    2
    ·
    9 days ago

    No problem, I turned it off the day I bought this motherboard. It just gets in the way of me running linux

    • ragas@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      8 days ago

      For linux by now it is just incredibly easy to automatically self-sign new boot shims. But why would I add that complexity for no gain at all?