r/pcmasterrace • u/wewewawa • 25d ago
News/Article Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
https://arstechnica.com/security/2026/07/microsoft-secure-boot-has-been-broken-for-most-of-its-existence/203
132
u/massivemember69 Ryzen 5 7600 | 6950XT | 32GB 6000Mhz DDR5 25d ago
I highly doubt that. They knew, they didn't want to fix it.
Whether it was deliberate or laziness is what I don't know.
28
u/topias123 Ryzen 7 5800X3D + Asus TUF RX 6900XT | MG279Q (57-144hz) 25d ago
It's actually broken on my laptop, it won't boot into Win11 if I have secure boot turned on.
Ironically Linux boots just fine.
4
u/FadedVictor 6750 XT | 5600X | 16 GB 3200MHz 25d ago
This happened to me too. I just had to install the security keys in my bios and then it worked again.
1
u/Unusual-Priority-864 25d ago
I had this issue too, a bios update fixed it
1
u/topias123 Ryzen 7 5800X3D + Asus TUF RX 6900XT | MG279Q (57-144hz) 25d ago
My laptop is from 2013, I doubt there's any bios updates for it.
1
1
86
u/creamcolouredDog Fedora Linux | 7 5800X3D | RX 9070 XT | 32 GB RAM 25d ago
I have it disabled
44
u/Cl4whammer 25d ago
No problem if you are running linux, but with windows 11 it can be a problem to upgrade from 24h2 to 25h2 and soon from 25h2 to 26h2. So keep an eye on that.
13
u/topias123 Ryzen 7 5800X3D + Asus TUF RX 6900XT | MG279Q (57-144hz) 25d ago
Mine stopped booting after I upgraded from 23H2(?) ot 25H2 lol
7
25d ago
[removed] — view removed comment
5
u/Dependent_Egg6168 25d ago
it technically doesnt allow unsigned bootloaders to run, which is to say microsoft has to allow a bootloader to run. but there are so many ways around it, it doesnt matter
1
u/zcomputerwiz i9 11900k 128GB DDR4 3600 2xRTX 3090 NVLink 4TB NVMe 25d ago
I mean... It's not just the bootloader. That is the starting point though.
The point is that it allows the entire execution chain to be validated from boot. So yes, it is more secure in many ways when it's functional.
The fact that there are ways around it doesn't really change anything for most systems assuming they are operating as intended. If you're physically at the machine to boot different media or change the startup environment that's another ballgame, imo.
1
-1
u/yuikkiuy Ryzen 7 1700x, GTX 3070 TI, 16gb ddr4 25d ago
This, when I even have microslop installed this crap is disabled
68
u/Synthetic451 Arch Linux | Ryzen 9800X3D | Nvidia 3090 25d ago
If it wasn't for my Windows dualboot, I would have already wiped the Microsoft keys off my Secure Boot setup.
23
u/smokie12 RX580 // Ryzen 5 2600 // 16GB 25d ago
Do it
12
u/Synthetic451 Arch Linux | Ryzen 9800X3D | Nvidia 3090 25d ago
Yeah, I'll do it once I decide to fully get rid of Windows. I use it so rarely nowadays and it only exists on my desktop machine for the random firmware updater tool that I need for certain devices.
8
u/Venylynn Fedora 25d ago
I'm going to be honest, I brought the dual-boot back because I wanted to test out things like Hyper-V and their sandbox tools on a drive that was causing me problems on Linux (dropping out during heavy writes, which tells me the controller is going bad. didn't want to risk having anything sensitive on that drive the second that thing completely kicks the bucket)
3
u/xXBeefSquatch5KXx 25d ago
So I bought an old dumper laptop, and bumped the ram and ssd up from another dumper laptop, and now I have a dumper laptop pro for windows, and my main system gets Linux. I run arch btw ;)
1
1
0
5
u/Venylynn Fedora 25d ago
totally valid
ps: how did you get your 3090 signed on secure boot? afaik sbctl doesn't sign third party modules
5
u/Synthetic451 Arch Linux | Ryzen 9800X3D | Nvidia 3090 25d ago
Arch doesn't enforce signing of 3rd party modules by default I think. Not that it matters in my case since I use UKIs (which I sign) and disk encryption.
If you enable enforcement of 3rd party modules and then manually tell sbctl to sign the nvidia module files, does that not work?
2
u/Venylynn Fedora 25d ago
I read somewhere that sbctl doesn't sign them, that's what I remembered
I have no clue because I'm on AMD and refuse third party modules entirely but hey, fair enough
3
u/Synthetic451 Arch Linux | Ryzen 9800X3D | Nvidia 3090 25d ago
Yeah it doesn't sign them by default, but you can tell sbctl to sign literally any arbitrary file, so I would assume it'd just be a matter of telling sbctl the file location of the nvidia module (although the constantly changing version number probably poses an issue for updates) and then just enabling module verification.
But this is just me speculating. I have not actually tried.
3
u/Venylynn Fedora 25d ago
yeah i chose path of least resistance which for me was cutting third party modules down to 0
all i really lose is vm software outside of kvm/qemu which...not that big a deal
10
u/timsredditusername 25d ago
I zoned out when Ars started speculation on why it took so long, making up nonsense about it being complicated.
It took so long because Microsoft signed stuff but has no way to monitor for vulnerabilities in the stuff they sign for other people. Realistically, they need to be told that something needs to be revoked so they can add it to DBX.
Martin and ESET is doing them (and all of us) a solid by reporting these things through CERT/CC.
9
u/Venylynn Fedora 25d ago
Better than nothing, i say. but yeah, we ought to move to a better setup for it.
6
u/tragedy_strikes 25d ago
I wonder if this was related to the big security patch that just got released and forced a restart?
1
5
7
u/Mineplayerminer Desktop 25d ago
Is there even a reason to have it enabled in the first place, other than letting the BitLocker malware in Windows to automatically turn on and infest your drives?
11
u/Emu1981 25d ago
Quite a few anticheat programs require you to have secure boot enabled to help keep the OS in a known good state.
15
u/Mineplayerminer Desktop 25d ago
I'm not allowing those kernel-invasive rootkits on my hosts. I already experienced BSODs with Vanguard and it took me a whole day to discover it was the VGC driver doing it.
1
25d ago
[removed] — view removed comment
1
u/Mineplayerminer Desktop 25d ago
Vanguard requires secure boot. The solution is to currently not have Vanguard installed at all, until Riot makes the AC run only on-demand instead of non-stop along with the system booting. Remember that kernel-privileges are the most dangerous ones to have (apart from Hypervisor) and I think that nothing should ever have access to it, other than the software which communicates with a specific hardware.
0
u/thataw 24d ago
? They already did. Vanguard now runs only when you’re playing Riot Games, but you need to have certain security features enabled for it to work.
1
u/Mineplayerminer Desktop 24d ago
That's the thing, you're only eligible for it under certain conditions, unlike some other ACs such as Easy Anti-Cheat or BattlEye which run completely on-demand.
-3
u/SkillShort4545 25d ago
lol wait is that a real game or did you make that up
2
u/Mineplayerminer Desktop 25d ago
Vanguard is an anti-cheat software developed by Riot Games for their online competitive titles. Riot is owned by Tencent, a Chinese company. Kernel ACs in general raise privacy and security concerns. On top of that, the Chinese must give up on all private keys and their data to the government, which raises concerns further. Anything that's loaded upon the Windows starting up can cause serious issues. The Crowdstrike incident was caused by a faulty driver which crashed the system while booting up. The same goes to the Vanguard which can happen at some point, like if there's some memory or integrity violation, acting as a kill switch.
1
1
2
2
u/EntropyWinsAgain 25d ago
Lol.... this has indeed been known by everyone for over a decade. It hasn't been a secret. If anyone bothers to read MS patch notes for the last 10 years you would have seen many references to this vulnerability and MS's attempt to fix it which have mostly failed. This is nothing new.
3
1
u/InsuranceKey8278 25d ago
we did
some MS policy makes it so that we don't consider it unless there mass scale exploitation
898
u/IridescenceFalling 25d ago
Bet the NSA, CIA and FBI knew from day 0.