• @cley_faye@lemmy.world
    link
    fedilink
    English
    173 days ago

    That title is misleading. Maybe people didn’t notice that way Secure Boot was broken. But people certainly knows many other ways secure boot is broken.

    • @heartSagan5@lemmy.zip
      link
      fedilink
      English
      43 days ago

      Gotta offer businesses and security firms job security somehow, and then, they’ll recommend Microslop.

    • BladeFederation
      link
      fedilink
      English
      194 days ago

      I am not a hacker, but what I gathered from the article is that this is due to shims with vulnerabilities being left as trusted instead of being revoked. If that’s the case, wouldn’t the hacker be using a modified version of a compromised shim? It shouldn’t have to be a shim that you actually use right? Or does the signed shim have to correspond to thr correct OS that signed it?

      • @InnerScientist@lemmy.world
        link
        fedilink
        English
        30
        edit-2
        4 days ago

        There exists shims that are signed by Microsoft and were not revoked. Normally this would be fine but these shims had weaknesses that allowes hackers to load any code using them. Normally the shims should only run other signed/trusted code. These vulnerable shims can be used to bypass secure boot by replacing your existing bootloader with the shim and then running rootkits/hackerOS/whatever and bypass bitlocker using TPM or just running a level 0 virus that can’t be detected by the OS on any PC which trusts Microsoft’s keys (99% of all PCs)

        To prevent this you’d have to not trust the vulnerable shims by either adding them manually to the exclusions list or using your own secure boot keys which would only trust the few bootloader files your pc uses and no other files.

        Worst case: it behaves as if secure boot wasn’t on. Without secure boot you wouldn’t need this exploit cause then you can replace the bootloader with whatever you want anyways. With or without secure boot you need administrative permission to replace the bootloader so this is only an issue after your PC is already compromised or if someone had physical access to your PC.

  • @EnsignWashout@startrek.website
    link
    fedilink
    English
    65
    edit-2
    4 days ago

    Microsoft has yet to explain how or why the lapse occurred.

    Highly skilled technical staff are expensive, and it turns out that some people still use Windows when Microsoft doesn’t hire the talent necessary to keep Windows working.

    Edit: Also, bribes from three letter government agencies are probably pretty nice.

      • GreenBeard
        link
        fedilink
        English
        144 days ago

        Holy hell yes. It’s actually alarming how many security holes are out there simply because management had no clue what people did and canned the last guy responsible for maintaining something. Zombie functions that are holding up the whole stack, but no one has had a clue what they did in 15 years, and we all just look away and hope they keep holding until they’re someone else’s problem.

      • iknewitwhenisawit
        link
        fedilink
        English
        84 days ago

        I cannot make certain teams at my work give a shit about known security vulnerabilities in libraries they use, since they don’t trip our internal scanners. People have their own priorities. ¯\_(ツ)_/¯

    • @SpaceCowboy@lemmy.ca
      link
      fedilink
      English
      43 days ago

      It used to be Microsoft would hire the best and brightest people straight out of university. Most of those people went in thinking they were going to fix the problems. Usually management would grind them down and they’d give up and go work elsewhere. But they did have some talented people and occasionally those people would be able to make improvements.

      Microsoft always sucked, but occasionally they could put out something good. There was a lot of inertia and a lot of half steps backwards for every step forward kind of thing going on. Mostly treading water, occasionally improving.

      But now they’ve gotten rid of a lot of people so they can throw more money into the AI money pit. Microsoft is in a constant decline now. The people that worked there that would fight the good fight to improve things (and every now and then win a fight) probably aren’t there any more.

  • pelya
    link
    fedilink
    English
    384 days ago

    You simply sign a corporate contract and pay a corporate fee, and MICROS~1 will sign any shitty broken and backdoored bootloader that you send to them with zero quality control, and it was like that with Windows drivers for years.

    • T. Hex
      link
      fedilink
      English
      9
      edit-2
      4 days ago

      The Eternal Enemy: Complexity

      apex predator of grug is complexity

      complexity bad

      say again:

      complexity very bad

      you say now:

      complexity veryvery bad

      https://grugbrain.dev/

  • @LaunchesKayaks@lemmy.world
    link
    fedilink
    English
    93 days ago

    The only thing I like about Microsoft is that their shit products give me job security.

    I get to do an extensive Microsoft Teams training for some middle-aged dudes next week. One of the men doesn’t recognize me as someone who can fix his shit. He straight up says, “Have one of your techs, your guys, give me a call” and I always tell him I am a technician and can handle his problem so he doesn’t have to wait. I use my kindest, sweetest customer service voice to talk to him and he has never once called me by my name despite it showing on his computer when I connect to it. He calls me honey and dear a lot and not in the endearing old person way.

    But dealing with him pays the bills so

  • @ragas@lemmy.ml
    link
    fedilink
    English
    73 days ago

    Wasn’t there this scandal with Gigabyte motherboards, where Secure Boot showed as enabled, but the motherboards still just booted any unsigned bootcode?!

  • ms.lane
    link
    fedilink
    English
    9
    edit-2
    4 days ago

    no one noticed

    Did that get Berenstained? I distinctly remember it being broken a decade a ago…

    • @terabyterex@lemmy.world
      link
      fedilink
      English
      33 days ago

      this paticular fix was never found. this last patch tuesday fixed over 500 vulnerabilities. they ran the kernel through mythos. you will be seeing a loy of companies with big patches comong up.

    • @9tr6gyp3@lemmy.world
      link
      fedilink
      English
      3
      edit-2
      4 days ago

      Its been broken multiple times, which is why its important to update your BIOS firmware if your motherboard manufacturer says they have patched security issues.

      • @cecilkorik@lemmy.ca
        link
        fedilink
        English
        74 days ago

        Yes it’s important to always update to make sure you also have the newest security holes in addition to the old ones that nobody’s noticed. /s

    • @ragas@lemmy.ml
      link
      fedilink
      English
      13 days ago

      For linux by now it is just incredibly easy to automatically self-sign new boot shims. But why would I add that complexity for no gain at all?

  • @spaghettiwestern@sh.itjust.works
    link
    fedilink
    English
    64 days ago

    The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them.

  • @technocrit@lemmy.dbzer0.com
    link
    fedilink
    English
    1
    edit-2
    3 days ago

    OFC. It’s probably on purpose.

    If you’re using Microsoft products, then you care about security theater, legal liability, etc… but not security.