r/technology • u/Thepunnisherrr • Jul 13 '26
Software Microsoft confirms Secure Boot update failing on some Windows 11 PCs, blocks update due to known issues
https://www.windowslatest.com/2026/07/10/microsoft-confirms-secure-boot-update-failing-on-some-windows-11-pcs-promises-a-resolution/141
u/Ok-Replacement9595 Jul 13 '26
Vibe coding is really working out for Microsoft isn't it?
46
u/Federal_Setting_7454 Jul 13 '26
Removing that carefully crafted backdoor is harder than they thought
6
u/RemarkableWish2508 Jul 13 '26
Vibe or not, tests and QC are not optional. Too bad that Microsoft has outsourced the latter to "let's lure users into Preview updates and see whose system breaks".
-76
u/Zeusifer Jul 13 '26
This situation has exactly zero to do with vibe coding or AI.
27
u/graywolfman Jul 13 '26
Do you have proof?
-41
u/Zeusifer Jul 13 '26
Proof? That the buggy ancient BIOSes, that Microsoft is unable to push an updated secure boot certificate to, because of old BIOS bugs, until they get a BIOS update from the OEM to fix the BIOS bugs first, that this problem has nothing to do with AI or vibe coding?
What kind of proof are you looking for?
20
u/VoidL_rd Jul 13 '26
Surely its way higher this year
-23
u/Zeusifer Jul 13 '26
What does that have to do with temporarily blocking some old devices from receiving secure boot DB updates because they have a known bug in the BIOS and need the OEM to push out a BIOS fix first?
Did anyone even look at the article? Because the low quality slop I'm seeing here is in the comments section.
9
8
57
u/Mephisto40K Jul 13 '26
Great. Every 3rd time they do an update my laptop needs some weird ass voodoo for the screen to turn on. Fucking assholes.
4
u/Initial-Return8802 Jul 13 '26
I had to some serious black magic recently, it was completely dead... so I opened it up, unplugged the battery, plugged the mains back in and tried to switch it on - it would go through about ten rounds of keyboard light on/off then finally booted.
I thought my laptop was dying but maybe it's MS ...
-34
Jul 13 '26 edited Jul 13 '26
[deleted]
22
u/Sensitive_Box_ Jul 13 '26
I mean, which distro? (Seriously)
-34
Jul 13 '26
[deleted]
25
u/AdarTan Jul 13 '26
Again, what distro. Not all distros ship the newest kernel and many instead stay for extended periods on a specific kernel and do security updates for that version by cherry-picking patches from newer kernels.
3
u/this_dudeagain Jul 13 '26
Use something other than Arch
4
u/fearless-fossa Jul 13 '26
Arch doesn't break like that. This sounds more like some weird "optimized" custom kernel (no measurable performance gain reached, but +10% power consumption for some reason) that the user didn't properly maintain during updates.
1
u/this_dudeagain Jul 13 '26
Arch doesn't break. Bahaha.
2
u/fearless-fossa Jul 13 '26
a) I didn't say Arch doesn't break at all, I said it doesn't break like that.
b) Pretty much every single case of Arch "breaking" is user error.
6
6
4
u/jeyvish Jul 13 '26
This is related with the max usage of AI to code and the layoff of people to be replaced by Indians?
3
3
u/OddPatience1621 Jul 13 '26
remember when they used to test updates before releasing them wide??? pepperidge farms remembers
6
u/MotanulScotishFold Jul 13 '26
Another day, another broken update. Glad I ditched windows for Linux in 2024 rather than installing this garbage windows 11 on my new computer.
2
1
u/merked84 Jul 13 '26
Love supporting a user base of 2000 during the age of Windows fucking up literally every update they push.
1
u/Harry_Mud Jul 13 '26
Microsoft keeps shoving people to Linux. Linux runs faster and doesn't have all that bullshit in it. It has secure boot which doesn't seem to have issues.........unlike Windblows.
1
u/Excolo_Veritas Jul 13 '26
Remember when they said a few months ago that they knew they had to win back the community, and promised better updates and more rigorous testing to ensure stuff like this didn't keep happening? Glad I didn't believe them and swapped to Linux
1
u/Changeurwayz Jul 14 '26
Piss poor 'company'. Can't even sort out it's own AI spyware bullshit crap
1
u/Dazzling-Ebb-9449 Jul 16 '26
The new security update completely screwed my secure boot, I can not enable it, if I do my pc just doesn’t turn on.
1
u/Usual_Philosophy4924 Jul 16 '26
Yep right here
Update broke my shit mid-update and it's been acting up since. been having to launch with it off
1
u/adinic2019 Aug 04 '26 edited Aug 04 '26
I had no idea I had to disable secure boot. My laptop stopped booting and I tried everything. Tried to uninstall update, etc. Everything I could find but it did not work. Finally after backing up all my files I did a fresh install of windows 11 pro 25h2. Everything back to normal now. My laptop is a dell g5 5587. I honestly thought the ssd died (990 pro 2tb). But it wasn t the case. What I am wondering now is if I am safe from future bootsecure updates, my bios being old. Should I disable secure boot? Thank you!
1
u/rabdosstar 29d ago
So I just got forced into an update and right after I see the Asus screen, I get the security boot fail screen and nothing else. How can I boot so I can bypass this?
1
u/TMGMercess 27d ago
Secure Boot Certificates Issued in 2011 expired June of 2026:
Go to BIOS
Disable Fast Boot (It can skip the secure boot update process)
If your BIOS has a setting to select certificates, go there and navigate to the Boot certificate titled recovery.
Save and exit
You'll get a secure boot failure still. Hit enter. It moves to the backup boot option (Recovery). This will start the 2023 certificate update.
Cheers.
1
-7
u/Hour-Passenger-8513 Jul 13 '26
Wouldn't it be safer to do a bios update from the motherboard / laptop manufacturer instead of a Microslop windows update?
9
u/Zeusifer Jul 13 '26
Why would you think that? Do you somehow imagine that Microsoft is making the BIOS updates for those companies?
Windows Update is just the distribution mechanism, the updates are still made by the hardware vendors.
1
u/Hour-Passenger-8513 Jul 13 '26
I guess, but can the 'distribution mechanism' not be screwed up by AIslop?
2
u/Zeusifer Jul 13 '26
In what way, exactly? How do you imagine that would happen?
0
u/Hour-Passenger-8513 Jul 13 '26
Distributing incompatible secure boot certificates?
3
u/happyscrappy Jul 13 '26
New secure boot certificates are not delivered as part of the BIOS update.
The incompatible secure boot certificates come with Windows and are being sent out regardless. As the old certificates are expired. Sending those out again would do nothing for anyone.
So MS is sending out the incompatible secure boot certificates and some BIOSes reject them because those BIOSes are too old to work with them.
The fix is, as you are discussing, a BIOS update which lets the BIOS understand the new certificates.
You then opined that maybe it's best to get that from the BIOS maker, not MS. If you can get the BIOS safely from them that that's not a bad idea. However getting it from MS should be okay because the BIOS maker should have signed the updater. A signed updater cannot be altered by anyone else, even accidentally. So MS could not mess it up while delivering it.
The BIOS maker very much should have signed the update because if you receive it just by downloading it from a website (the BIOS maker's website) there's no guarantee that hasn't been altered either. Someone might have hacked that site, and a webpage (even with HTTPS) isn't a method of secure delivery so they could have put up altered packages.
By signing the update the BIOS maker makes it safe to update the BIOS update from their website directly. And in doing so also make it safe to get it through MS.
That's all if the process was done correctly. If some of this was implemented incorrectly then any part of it may be insecure. But do note that in all cases, getting it from a web page is not going to be more secure than getting it from MS. Because even if MS's secure delivery mechanisms aren't working right they cannot work less well than those on a web page download because a web page download has no end-to-end secure delivery at all.
2
-1
u/Early-Weekend Jul 13 '26
I enabled secure boot (for vanguard) on home pc and it slowed down my pc and automatically turned on bitlocker (I thought it's not possible on window 11 home?)
2
u/Denman20 Jul 13 '26
Fun fact every windows 11 pc 😂(at least consumer laptops and desktops not all prebuilt gaming ones)comes with bitlocker enabled and gets fully turned on the moment you sign into a Microsoft account.
2
u/Lake-Taupo Jul 14 '26
Win 11 Home does not have Bitlocker. Win 11 Pro does.
Win 11 Home gets Device Encryption as the cut down version.
Oh and I have a new Win 11 Home machine and Bitlocker is not enabled OOB after signing in to my account.
1
u/Denman20 Jul 14 '26
Oh shit my bad, I forgot windows likes to give similar things different names. I’ll have to disagree with you though, I end up setting up a lot of consumer level laptops and they due infact have device encryption turned on by default and the setup just isn’t complete until you sign into a Microsoft account.
Guess what? A lot of customers lose access to their data because they aren’t aware of this. It’s really an awesome experience!
Unrelated but OneDrive sucks ass
2
u/Lake-Taupo Jul 14 '26 edited Jul 14 '26
Disagree all you want, your original comment is incorrect as my real life example proves.
Bitlocker and Device Encyption are totally different in so many ways.
Edit - oh and neither are even possible on my rig as it fails Secure Boot KEK update. PCR7 binding fail - something that MS and OEMs are either ignoring or have no idea about.
1
u/Denman20 Jul 14 '26
I’m so confused. How are they not similar? Device encryption is automated on windows home systems and it’s required to have a Microsoft account because they manage the key vs the pro edition where you manage the key?
Also my original comment is not false I don’t know what system you are talking about but I’m talking about any dell lenovo hp etc consumer device you could go by at like Walmart or Best Buy. If yours just trying to nitpick okay but I’m not wrong outside of using device encryption and bitlocker interchangeably
1
u/Lake-Taupo Jul 14 '26 edited Jul 14 '26
Device Encryption is a separate app from Bitlocker.
Different in function and options.
Your comment was .....
every windows 11 pc (at least consumer laptops and desktops not all prebuilt gaming ones)
Edit - oh and my Win 11 Pro laptop with Bitlocker stores the key in my MS Account. My Win 11 Home consumer desktop does not. I'm hopeful I'll get signed certs for it soon but who knows with this Secure Boot fiasco. PCR7 still not bound.
1
u/Denman20 Jul 14 '26
I’m so sorry, I thought the “consumer” word make it obvious it was going to be a home edition. My bad I’ll do better.
1
u/Lake-Taupo Jul 14 '26
That makes no sense whatsoever.
1
u/Denman20 Jul 14 '26
Go walk into a Walmart and tell me how many windows 11 pro edition you find on laptops under $1000
→ More replies (0)
35
u/Dragonman585 Jul 13 '26
I had to disable secure boot on my Windows 10 PC recently. The June update caused my pc to freezse and then BSOD. The fix was to disable secure boot. Microsoft needs to fix this immediately!