frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Microsoft SecureBoot time-bomb ticks at its own pace

https://support.microsoft.com/en-us/topic/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e
2•fuzzfactor•2h ago

Comments

fuzzfactor•2h ago
>Windows Secure Boot certificates expiring in 2026

>Important When the 2011 CAs expire, Windows devices that do not have new 2023 certificates can no longer receive security fixes for pre-boot components compromising Windows boot security.

>Windows devices for businesses:

>https://support.microsoft.com/en-us/topic/windows-devices-fo...

>This article is targeted at organizations that do not share diagnostic data with Microsoft and have dedicated IT professionals who manage updates to their environment. Currently, there is insufficient information for Microsoft to fully support rolling out the Secure Boot certificates on these devices, especially those with diagnostic data disabled.

Hmm, so far the only proven technique for reliably updating the certificates is for regular consumer Windows users relying on full-auto Windows Update and deep integration with Microsoft servers at all times, not independent enterprises. Either way the motherboards' original UEFI firmware certificates aren't going to be truly updated at this point anyway. So the best fix is not even intended to be permanent. And this is by design? Where every device has a looming Microsoft defect under UEFI, nothing like a BIOS motherboard ever had. And it's a security defect? In the name of security?

"IMPORTANT

The Secure Boot certificate updates offered by Microsoft through Windows Update (WU) are applied to the active Secure Boot certificate variables; these updates are not persistent. If the Secure Boot state on a device is toggled from On to Off, the updates might be removed, as the active variables are reset. Consequently, even if Secure Boot is later re-enabled, the device will no longer retain the 2023 Secure Boot certificate updates that were previously installed through WU. This is because the updates from Microsoft are to the active variables of the Secure Boot certificates and not its default variables."

IOW in a dozen years nobody has come up with a way for millions of computers to remain as secure as they were when originally issued, just because of UEFI & SecureBoot which they are supposed to be experts at?

To be less generous, from another standpoint there are millions of computers happily running Windows 11 right now, where the electronics is in perfect condition and everything SecureBoots just great. In about a year the time will come when the fragility of the feature rears its ugly head and the system can then easily become incapable of booting as securely as it was this year, even though the PC's are still in the same exact top electronic condition.

And that will last forever since it will be incapable of updating the inbuilt certificates by then.

To be even less generous you could say it was just the kind of stupid that you can't fix. Which was obvious about UEFI & Microsoft SecureBoot from the beginning without even knowing about this time bomb.

Root cause has to be a pure defect in something about Microsoft when there is no change in electronics whatsoever.

Talk about design for landfill, if that's not enough you've got to have a scheduled doomsday "to boot".

leakycap•2h ago
Thanks for bringing this to my attention; feels like the kind of thing an airgapped single-use server in a corner somewhere could become afflicted with. Worse, if you have a twin backup unit, it may have the same issue.

I've wondered what will happen to T2 Apple devices that cannot boot to anything except macOS & require online activation for first boot after reinstall, even years after purchase. When Apple eventually shuts down the T2 activation servers, do all these Macs become paperweights upon reset?

It should be mentioned Apple still provides SW Update for 10.4.x which was released in the G4 era, so this isn't a looming issue like the 2026 MS Certificate.

You Can't Outsource Accountability

https://www.m365princess.com/blogs/accountability/
1•speckx•53s ago•0 comments

License plate readers coming to West LA's Cheviot Hills amid privacy concerns

https://laist.com/news/transportation/license-plate-readers-coming-to-west-las-cheviot-hills-amid-privacy-and-immigration-concerns
1•rbanffy•54s ago•0 comments

Red Bull team principal Christian Horner fired after 20 years with team

https://www.cnn.com/2025/07/09/sport/christian-horner-sacked-red-bull-spt
1•alien13•1m ago•0 comments

Claude Code vs. Gemini CLI – head to head comparison

https://milvus.io/blog/claude-code-vs-gemini-cli-which-ones-the-real-dev-co-pilot.md
1•Fendy•1m ago•0 comments

Windows SPNEGO Nightmare: Critical RCE Vulnerability

https://zeropath.com/blog/windows-spnego-cve-2025-47981-rce
1•tatersolid•1m ago•1 comments

Jeff Bezos sells $666M in Amazon stock

https://www.cnbc.com/2025/07/08/jeff-bezos-amazon-stock-sale.html
1•samaysharma•2m ago•0 comments

Gibberella zeae

https://en.wikipedia.org/wiki/Gibberella_zeae
1•sandwichsphinx•2m ago•0 comments

U.S. measles cases are the highest in 33 years, the CDC reports

https://www.npr.org/sections/shots-health-news/2025/07/09/nx-s1-5461155/measles-outbreak-cdc-vaccination-health
2•rbanffy•5m ago•1 comments

Arrayground – A mobile app for K and BQN

https://apps.apple.com/hk/app/arrayground/id6453522556
1•ngcc_hk•5m ago•0 comments

Douglass Mackey's "Meme" Conviction Reversed by US Court of Appeals [pdf]

https://ww3.ca2.uscourts.gov/decisions/isysquery/130b34d9-4f2e-4a63-9a7a-f15a10f0b64c/2/doc/23-7577_opn.pdf
1•Amezarak•6m ago•0 comments

Nvidia Becomes First Company to Hit $4T Market Value

https://www.chicagotribune.com/2025/07/09/chipmaker-nvidia/
2•thm•7m ago•0 comments

Anthropic Courses

https://anthropic.skilljar.com/
2•tortilla•7m ago•0 comments

Letta

https://www.letta.com/
1•handfuloflight•7m ago•0 comments

Show HN: Social Media and Ad Specs Tool – Filter, Share and Download Templates

2•rahulbstomar•8m ago•1 comments

PHP 8.5 Alpha 1 Released with New Features

https://www.phoronix.com/news/PHP-8.5-Alpha-1
1•Bender•10m ago•0 comments

Red Hat Announces No-Cost RHEL for Business Developers

https://www.phoronix.com/news/Red-Hat-RHEL-Business-Devs
2•Bender•10m ago•0 comments

Microsoft Patch Tuesday, July 2025 Edition

https://krebsonsecurity.com/2025/07/microsoft-patch-tuesday-july-2025-edition/
1•Bender•11m ago•0 comments

Ask HN: Is automatic time tracking a solved problem?

1•MoritzWall•13m ago•0 comments

The Largest Camera Captures 10⁷ Galaxies, Discovers 2,104 Asteroids

https://petapixel.com/2025/06/23/the-worlds-largest-camera-captures-10-million-galaxies-discovers-2104-asteroids-in-first-photos/
3•PaulHoule•13m ago•0 comments

Hit 1k signups with HypeDesk – and now I'm changing direction. Here's why

2•coursecrumbs•13m ago•0 comments

Barbie launches first doll with Type 1 diabetes

https://www.cbs8.com/article/news/nation-world/barbie-first-doll-type-1-diabetes/507-58500e51-92ae-42b9-8ee6-dac317a091b4
1•ohjeez•15m ago•0 comments

Stress is wrecking your health: how can science help?

https://www.nature.com/articles/d41586-025-02066-z
1•rbanffy•15m ago•0 comments

What Air Canada Lost in 'Remarkable' Lying AI Chatbot Case

https://www.forbes.com/sites/marisagarcia/2024/02/19/what-air-canada-lost-in-remarkable-lying-ai-chatbot-case/
1•samaysharma•15m ago•0 comments

Show HN: Blunderless, a chess board vision trainer

https://blunderless.com
1•evanletz•16m ago•0 comments

Show HN: I made simple components to get your coding journey started easily

https://www.webuildlite.com/
1•KreshSiva•17m ago•0 comments

Show HN: Publish IPFS webapps which require user consent to update

https://github.com/rhodey/IPFS-boot
1•rhodey•17m ago•0 comments

'Space Ice' is less like water than we thought

https://www.ucl.ac.uk/news/2025/jul/space-ice-less-water-we-thought
1•noleary•18m ago•1 comments

Google behind proposed Indianapolis data center revealed in new documents

https://mirrorindy.org/google-behind-proposed-indianapolis-data-center-franklin-township/
1•toomuchtodo•18m ago•1 comments

Speclinter MCP

https://github.com/orangebread/speclinter-mcp
1•orangebread•18m ago•1 comments

Show HN: Cool Symbols

https://copysymbol.cc/
2•artiomyak•20m ago•0 comments