ky331

updated

2 years ago

K

ky331

5 Journeyman

15623 Posts

45050 Points

2

2106

July 26th, 2024 10:43

SecureBoot broken on many popular computers

The following was excerpted from Secure Boot is completely broken on 200+ models from 5 big device makers | Ars Technica

In 2012, an industry-wide coalition of hardware and software makers adopted Secure Boot to protect against a long-looming malware security threat that could infect the BIOS firmware that loaded the operating system each time a computer booted up.  Built into UEFI, Secure Boot used public-key cryptography to block the loading of any code that wasn’t signed with a pre-approved digital signature.

On Thursday, researchers from security firm Binarly revealed that Secure Boot is completely compromised on more than 200 device models sold by Acer, Dell, Gigabyte, Intel, and Supermicro. The cause: a cryptographic key underpinning Secure Boot on those models that was compromised in 2022.

See the article (link above) for a list of affected models.

----------------------------------

See also:  PKfail Secure Boot bypass lets attackers install UEFI malware (bleepingcomputer.com)

(edited)