frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Microsoft SecureBoot time-bomb ticks at its own pace

https://support.microsoft.com/en-us/topic/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e
3•fuzzfactor•7mo ago

Comments

fuzzfactor•7mo ago
>Windows Secure Boot certificates expiring in 2026

>Important When the 2011 CAs expire, Windows devices that do not have new 2023 certificates can no longer receive security fixes for pre-boot components compromising Windows boot security.

>Windows devices for businesses:

>https://support.microsoft.com/en-us/topic/windows-devices-fo...

>This article is targeted at organizations that do not share diagnostic data with Microsoft and have dedicated IT professionals who manage updates to their environment. Currently, there is insufficient information for Microsoft to fully support rolling out the Secure Boot certificates on these devices, especially those with diagnostic data disabled.

Hmm, so far the only proven technique for reliably updating the certificates is for regular consumer Windows users relying on full-auto Windows Update and deep integration with Microsoft servers at all times, not independent enterprises. Either way the motherboards' original UEFI firmware certificates aren't going to be truly updated at this point anyway. So the best fix is not even intended to be permanent. And this is by design? Where every device has a looming Microsoft defect under UEFI, nothing like a BIOS motherboard ever had. And it's a security defect? In the name of security?

"IMPORTANT

The Secure Boot certificate updates offered by Microsoft through Windows Update (WU) are applied to the active Secure Boot certificate variables; these updates are not persistent. If the Secure Boot state on a device is toggled from On to Off, the updates might be removed, as the active variables are reset. Consequently, even if Secure Boot is later re-enabled, the device will no longer retain the 2023 Secure Boot certificate updates that were previously installed through WU. This is because the updates from Microsoft are to the active variables of the Secure Boot certificates and not its default variables."

IOW in a dozen years nobody has come up with a way for millions of computers to remain as secure as they were when originally issued, just because of UEFI & SecureBoot which they are supposed to be experts at?

To be less generous, from another standpoint there are millions of computers happily running Windows 11 right now, where the electronics is in perfect condition and everything SecureBoots just great. In about a year the time will come when the fragility of the feature rears its ugly head and the system can then easily become incapable of booting as securely as it was this year, even though the PC's are still in the same exact top electronic condition.

And that will last forever since it will be incapable of updating the inbuilt certificates by then.

To be even less generous you could say it was just the kind of stupid that you can't fix. Which was obvious about UEFI & Microsoft SecureBoot from the beginning without even knowing about this time bomb.

Root cause has to be a pure defect in something about Microsoft when there is no change in electronics whatsoever.

Talk about design for landfill, if that's not enough you've got to have a scheduled doomsday "to boot".

leakycap•7mo ago
Thanks for bringing this to my attention; feels like the kind of thing an airgapped single-use server in a corner somewhere could become afflicted with. Worse, if you have a twin backup unit, it may have the same issue.

I've wondered what will happen to T2 Apple devices that cannot boot to anything except macOS & require online activation for first boot after reinstall, even years after purchase. When Apple eventually shuts down the T2 activation servers, do all these Macs become paperweights upon reset?

It should be mentioned Apple still provides SW Update for 10.4.x which was released in the G4 era, so this isn't a looming issue like the 2026 MS Certificate.

Show HN: Grovia – Long-Range Greenhouse Monitoring System

https://github.com/benb0jangles/Remote-greenhouse-monitor
1•benbojangles•4m ago•0 comments

Ask HN: The Coming Class War

1•fud101•4m ago•0 comments

Mind the GAAP Again

https://blog.dshr.org/2026/02/mind-gaap-again.html
1•gmays•6m ago•0 comments

The Yardbirds, Dazed and Confused (1968)

https://archive.org/details/the-yardbirds_dazed-and-confused_9-march-1968
1•petethomas•7m ago•0 comments

Agent News Chat – AI agents talk to each other about the news

https://www.agentnewschat.com/
1•kiddz•7m ago•0 comments

Do you have a mathematically attractive face?

https://www.doimog.com
1•a_n•11m ago•1 comments

Code only says what it does

https://brooker.co.za/blog/2020/06/23/code.html
1•logicprog•17m ago•0 comments

The success of 'natural language programming'

https://brooker.co.za/blog/2025/12/16/natural-language.html
1•logicprog•17m ago•0 comments

The Scriptovision Super Micro Script video titler is almost a home computer

http://oldvcr.blogspot.com/2026/02/the-scriptovision-super-micro-script.html
3•todsacerdoti•17m ago•0 comments

Discovering the "original" iPhone from 1995 [video]

https://www.youtube.com/watch?v=7cip9w-UxIc
1•fortran77•19m ago•0 comments

Psychometric Comparability of LLM-Based Digital Twins

https://arxiv.org/abs/2601.14264
1•PaulHoule•20m ago•0 comments

SidePop – track revenue, costs, and overall business health in one place

https://www.sidepop.io
1•ecaglar•23m ago•1 comments

The Other Markov's Inequality

https://www.ethanepperly.com/index.php/2026/01/16/the-other-markovs-inequality/
2•tzury•24m ago•0 comments

The Cascading Effects of Repackaged APIs [pdf]

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6055034
1•Tejas_dmg•26m ago•0 comments

Lightweight and extensible compatibility layer between dataframe libraries

https://narwhals-dev.github.io/narwhals/
1•kermatt•29m ago•0 comments

Haskell for all: Beyond agentic coding

https://haskellforall.com/2026/02/beyond-agentic-coding
2•RebelPotato•33m ago•0 comments

Dorsey's Block cutting up to 10% of staff

https://www.reuters.com/business/dorseys-block-cutting-up-10-staff-bloomberg-news-reports-2026-02...
2•dev_tty01•35m ago•0 comments

Show HN: Freenet Lives – Real-Time Decentralized Apps at Scale [video]

https://www.youtube.com/watch?v=3SxNBz1VTE0
1•sanity•37m ago•1 comments

In the AI age, 'slow and steady' doesn't win

https://www.semafor.com/article/01/30/2026/in-the-ai-age-slow-and-steady-is-on-the-outs
1•mooreds•44m ago•1 comments

Administration won't let student deported to Honduras return

https://www.reuters.com/world/us/trump-administration-wont-let-student-deported-honduras-return-2...
1•petethomas•44m ago•0 comments

How were the NIST ECDSA curve parameters generated? (2023)

https://saweis.net/posts/nist-curve-seed-origins.html
2•mooreds•45m ago•0 comments

AI, networks and Mechanical Turks (2025)

https://www.ben-evans.com/benedictevans/2025/11/23/ai-networks-and-mechanical-turks
1•mooreds•45m ago•0 comments

Goto Considered Awesome [video]

https://www.youtube.com/watch?v=1UKVEUGEk6Y
1•linkdd•48m ago•0 comments

Show HN: I Built a Free AI LinkedIn Carousel Generator

https://carousel-ai.intellisell.ai/
1•troyethaniel•49m ago•0 comments

Implementing Auto Tiling with Just 5 Tiles

https://www.kyledunbar.dev/2026/02/05/Implementing-auto-tiling-with-just-5-tiles.html
2•todsacerdoti•50m ago•0 comments

Open Challange (Get all Universities involved

https://x.com/i/grok/share/3513b9001b8445e49e4795c93bcb1855
1•rwilliamspbgops•51m ago•0 comments

Apple Tried to Tamper Proof AirTag 2 Speakers – I Broke It [video]

https://www.youtube.com/watch?v=QLK6ixQpQsQ
2•gnabgib•53m ago•0 comments

Show HN: Isolating AI-generated code from human code | Vibe as a Code

https://www.npmjs.com/package/@gace/vaac
1•bstrama•54m ago•0 comments

Show HN: More beautiful and usable Hacker News

https://twitter.com/shivamhwp/status/2020125417995436090
3•shivamhwp•55m ago•0 comments

Toledo Derailment Rescue [video]

https://www.youtube.com/watch?v=wPHh5yHxkfU
1•samsolomon•57m ago•0 comments