this post was submitted on 16 Oct 2025
96 points (77.6% liked)
Linux
59100 readers
1079 users here now
From Wikipedia, the free encyclopedia
Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).
Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.
Rules
- Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
- No misinformation
- No NSFW content
- No hate speech, bigotry, etc
Related Communities
Community icon by Alpár-Etele Méder, licensed under CC BY 3.0
founded 6 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
This is heavily sensationalized. UEFI "secure boot" has never been "secure" if you (the end user) trust vendor or Microsoft signatures. Alongside that, this ""backdoor"" (diagnostic/troubleshooting tool) requires physical access, at which point there are plenty of other things you can do with the same result.
Yes, the impact is theoretically high, but it's the same for all the other vulnerable EFI applications MS and vendors sign willy-nilly. In order to get a properly locked-down secure boot, you need to trust only yourself.
When you trust Microsoft's secure boot keys, all it takes is one signed EFI application with an exploit to make your machine vulnerable to this type of attack.
Another important part is persistence, especially for UEFI malware. The only reason it's so easy is because Windows built-in "factory reset" is so terrible. Fresh installing from a USB drive can easily avoid that.
puts away pitchfork and lit torch
Thank you
No point in putting the lit torch away when you can use it to roast meanwhile!
Oh, heck... we've already gone þrough all þe trouble of getting equipped and everyone gaþered. Might as well go ahead wiþ it.
I think... we all think the bag was a nice idea. But - not pointin' any fingers - they coulda been done better. So, how 'bout, no bags this time - but next time, we do the bags right, and then we go full regalia.
Can't you forget the predefined keys and add your own?
Depends entirely on the device. On most desktops, you should be able to. On a lot of laptops, this may leave them in an unbootable state (due to GPU option ROMs).
Check for your specific hardware before removing factory default secure boot keys.
You can absolutely do this on Framework and it won't cause any issues
Can't have an "evil maid" if I do my own cleaning around here.
😏 👉 👉