Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them.
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Old and forgotten "shims" Microsoft failed to revoke have made Secure Boot bypasses simple.Dan Goodin (Ars Technica)
like this

Midnitte
in reply to Midnitte • • •like this
qupada and Lippy like this.
lemmyvore
in reply to Midnitte • • •I mean, UEFI was broken by design from the get-go. It was entirely designed around Windows and shims were an afterthought once the rest of the industry figured out they'd be fucked if they allowed Microsoft complete control. But they didn't fight for an overhaul because Microsoft got all its OEM and BIOS makers on board.
So shims are the best next thing, and they aren't just about Linux, they're a second PKI layer that allows other entities (than Microsoft) to sign shims. Those entities can be Linux distros but also other OS, software or hardware makers.
Microsoft forgetting to revoke signatures for old shims is orthogonal to the design, but it's also true that it's not a very good design. Again, because it was originally made to only deal with Windows and does not deal well with other stuff. The article goes into some detail about workarounds on top of workarounds.
company
Contributors to Wikimedia projects (Wikimedia Foundation, Inc.)like this
Lippy likes this.
Em Adespoton
in reply to Midnitte • • •quick_snail
in reply to Midnitte • • •jay2
in reply to Midnitte • • •