this post was submitted on 17 Jul 2026
382 points (98.2% liked)

Technology

88390 readers
3058 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
top 34 comments
sorted by: hot top controversial new old
[–] Reygle@lemmy.world 102 points 2 months ago* (last edited 2 months ago) (1 children)

If it says Microslop on it, it's broken.

BY DESIGN

[–] heartSagan5@lemmy.zip 4 points 2 months ago

Gotta offer businesses and security firms job security somehow, and then, they’ll recommend Microslop.

[–] InnerScientist@lemmy.world 92 points 2 months ago (1 children)

tldr: Either use your own keys or don't trust secure boot.

[–] BladeFederation@piefed.social 19 points 2 months ago (1 children)

I am not a hacker, but what I gathered from the article is that this is due to shims with vulnerabilities being left as trusted instead of being revoked. If that's the case, wouldn't the hacker be using a modified version of a compromised shim? It shouldn't have to be a shim that you actually use right? Or does the signed shim have to correspond to thr correct OS that signed it?

[–] InnerScientist@lemmy.world 30 points 2 months ago* (last edited 2 months ago) (1 children)

There exists shims that are signed by Microsoft and were not revoked. Normally this would be fine but these shims had weaknesses that allowes hackers to load any code using them. Normally the shims should only run other signed/trusted code. These vulnerable shims can be used to bypass secure boot by replacing your existing bootloader with the shim and then running rootkits/hackerOS/whatever and bypass bitlocker using TPM or just running a level 0 virus that can't be detected by the OS on any PC which trusts Microsoft's keys (99% of all PCs)

To prevent this you'd have to not trust the vulnerable shims by either adding them manually to the exclusions list or using your own secure boot keys which would only trust the few bootloader files your pc uses and no other files.

Worst case: it behaves as if secure boot wasn't on. Without secure boot you wouldn't need this exploit cause then you can replace the bootloader with whatever you want anyways. With or without secure boot you need administrative permission to replace the bootloader so this is only an issue after your PC is already compromised or if someone had physical access to your PC.

[–] 0x0@infosec.pub 11 points 2 months ago* (last edited 2 months ago)

For anyone that hate microslop more than themself and enjoy pain i will provide this to aide in making your own pki, with blackjack and hookers:

https://www.rodsbooks.com/efi-bootloaders/controlling-sb.html#creatingkeys

https://blastrock.github.io/posts/fde-tpm-sb-ng/

[–] EnsignWashout@startrek.website 65 points 2 months ago* (last edited 2 months ago) (2 children)

Microsoft has yet to explain how or why the lapse occurred.

Highly skilled technical staff are expensive, and it turns out that some people still use Windows when Microsoft doesn't hire the talent necessary to keep Windows working.

Edit: Also, bribes from three letter government agencies are probably pretty nice.

[–] atomicbocks@sh.itjust.works 31 points 2 months ago (2 children)

The number of times I’ve seen a fix not get pushed because somebody got laid off is a lot higher than you might think.

[–] GreenBeard@lemmy.ca 14 points 2 months ago

Holy hell yes. It's actually alarming how many security holes are out there simply because management had no clue what people did and canned the last guy responsible for maintaining something. Zombie functions that are holding up the whole stack, but no one has had a clue what they did in 15 years, and we all just look away and hope they keep holding until they're someone else's problem.

[–] iknewitwhenisawit@fedinsfw.app 9 points 2 months ago

I cannot make certain teams at my work give a shit about known security vulnerabilities in libraries they use, since they don't trip our internal scanners. People have their own priorities. ¯\_(ツ)_/¯

[–] SpaceCowboy@lemmy.ca 4 points 2 months ago

It used to be Microsoft would hire the best and brightest people straight out of university. Most of those people went in thinking they were going to fix the problems. Usually management would grind them down and they'd give up and go work elsewhere. But they did have some talented people and occasionally those people would be able to make improvements.

Microsoft always sucked, but occasionally they could put out something good. There was a lot of inertia and a lot of half steps backwards for every step forward kind of thing going on. Mostly treading water, occasionally improving.

But now they've gotten rid of a lot of people so they can throw more money into the AI money pit. Microsoft is in a constant decline now. The people that worked there that would fight the good fight to improve things (and every now and then win a fight) probably aren't there any more.

[–] wrinkle2409@lemmy.cafe 58 points 2 months ago (1 children)

I thought the point of secure boot was to make it harder to install linux

[–] boonhet@sopuli.xyz 13 points 2 months ago
[–] pelya@lemmy.world 39 points 2 months ago

You simply sign a corporate contract and pay a corporate fee, and MICROS~1 will sign any shitty broken and backdoored bootloader that you send to them with zero quality control, and it was like that with Windows drivers for years.

[–] sfxrlz@lemmy.world 36 points 2 months ago

No wonder no three letter agency has ever complained about it

[–] friend_of_satan@lemmy.world 25 points 2 months ago (1 children)

"Complexity is the enemy" is a great quote. Definitely keeping that in my pocket for a future design doc review.

[–] 0x0@lemmy.dbzer0.com 9 points 2 months ago* (last edited 2 months ago)

The Eternal Enemy: Complexity

apex predator of grug is complexity

complexity bad

say again:

complexity very bad

you say now:

complexity very, very bad

https://grugbrain.dev/

[–] cley_faye@lemmy.world 17 points 2 months ago

That title is misleading. Maybe people didn't notice that way Secure Boot was broken. But people certainly knows many other ways secure boot is broken.

[–] dan1101@lemmy.world 15 points 2 months ago

Or, like me, they never trusted it to begin with.

[–] ms_lane@lemmy.world 9 points 2 months ago* (last edited 2 months ago) (2 children)

no one noticed

Did that get Berenstained? I distinctly remember it being broken a decade a ago...

[–] 9tr6gyp3@lemmy.world 3 points 2 months ago* (last edited 2 months ago) (1 children)

Its been broken multiple times, which is why its important to update your BIOS firmware if your motherboard manufacturer says they have patched security issues.

[–] cecilkorik@lemmy.ca 8 points 2 months ago

Yes it's important to always update to make sure you also have the newest security holes in addition to the old ones that nobody's noticed. /s

[–] terabyterex@lemmy.world 3 points 2 months ago

this paticular fix was never found. this last patch tuesday fixed over 500 vulnerabilities. they ran the kernel through mythos. you will be seeing a loy of companies with big patches comong up.

[–] LaunchesKayaks@lemmy.world 9 points 2 months ago (1 children)

The only thing I like about Microsoft is that their shit products give me job security.

I get to do an extensive Microsoft Teams training for some middle-aged dudes next week. One of the men doesn't recognize me as someone who can fix his shit. He straight up says, "Have one of your techs, your guys, give me a call" and I always tell him I am a technician and can handle his problem so he doesn't have to wait. I use my kindest, sweetest customer service voice to talk to him and he has never once called me by my name despite it showing on his computer when I connect to it. He calls me honey and dear a lot and not in the endearing old person way.

But dealing with him pays the bills so

[–] anon_8675309@lemmy.world 2 points 2 months ago (1 children)

Make him pay extra for that.

[–] LaunchesKayaks@lemmy.world 5 points 2 months ago (1 children)

I don't make the prices. I'm just a grunt in the IT trenches. 🥲

[–] undrwater@lemmy.world 4 points 2 months ago (1 children)

Which is why you launch kayaks.

[–] LaunchesKayaks@lemmy.world 1 points 2 months ago

They do go far with trebuchets

[–] ragas@lemmy.ml 7 points 2 months ago (1 children)

Wasn't there this scandal with Gigabyte motherboards, where Secure Boot showed as enabled, but the motherboards still just booted any unsigned bootcode?!

[–] ryannathans@aussie.zone 3 points 2 months ago

Same bug on my MSI board too

[–] spaghettiwestern@sh.itjust.works 6 points 2 months ago

The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them.

[–] SaharaMaleikuhm@feddit.org 6 points 2 months ago (1 children)

No problem, I turned it off the day I bought this motherboard. It just gets in the way of me running linux

[–] ragas@lemmy.ml 1 points 2 months ago

For linux by now it is just incredibly easy to automatically self-sign new boot shims. But why would I add that complexity for no gain at all?

[–] technocrit@lemmy.dbzer0.com 1 points 2 months ago* (last edited 2 months ago)

OFC. It's probably on purpose.

If you're using Microsoft products, then you care about security theater, legal liability, etc... but not security.