If it says Microslop on it, it’s broken.
BY DESIGN
tldr: Either use your own keys or don’t trust secure boot.
You simply sign a corporate contract and pay a corporate fee, and MICROS~1 will sign any shitty broken and backdoored bootloader that you send to them with zero quality control, and it was like that with Windows drivers for years.
No wonder no three letter agency has ever complained about it
“Complexity is the enemy” is a great quote. Definitely keeping that in my pocket for a future design doc review.
That title is misleading. Maybe people didn’t notice that way Secure Boot was broken. But people certainly knows many other ways secure boot is broken.
Or, like me, they never trusted it to begin with.
The only thing I like about Microsoft is that their shit products give me job security.
I get to do an extensive Microsoft Teams training for some middle-aged dudes next week. One of the men doesn’t recognize me as someone who can fix his shit. He straight up says, “Have one of your techs, your guys, give me a call” and I always tell him I am a technician and can handle his problem so he doesn’t have to wait. I use my kindest, sweetest customer service voice to talk to him and he has never once called me by my name despite it showing on his computer when I connect to it. He calls me honey and dear a lot and not in the endearing old person way.
But dealing with him pays the bills so
Make him pay extra for that.
I don’t make the prices. I’m just a grunt in the IT trenches. 🥲
Which is why you launch kayaks.
They do go far with trebuchets
no one noticed
Did that get Berenstained? I distinctly remember it being broken a decade a ago…
Its been broken multiple times, which is why its important to update your BIOS firmware if your motherboard manufacturer says they have patched security issues.
Yes it’s important to always update to make sure you also have the newest security holes in addition to the old ones that nobody’s noticed. /s
this paticular fix was never found. this last patch tuesday fixed over 500 vulnerabilities. they ran the kernel through mythos. you will be seeing a loy of companies with big patches comong up.
Wasn’t there this scandal with Gigabyte motherboards, where Secure Boot showed as enabled, but the motherboards still just booted any unsigned bootcode?!
The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them.
No problem, I turned it off the day I bought this motherboard. It just gets in the way of me running linux
For linux by now it is just incredibly easy to automatically self-sign new boot shims. But why would I add that complexity for no gain at all?








