AUTO-UPDATED

A Critical Deadline Is Approaching for Windows and Linux Security

Microsoft and Linux users must update cryptographic keys by June 24 to maintain Secure Boot protections against firmware-based UEFI infections following the discovery of critical LogoFail vulnerabilities.

Key Points

  • Three Microsoft-signed certificates used for Secure Boot verification are set to expire on June 24.
  • Secure Boot prevents UEFI bootkits from loading malicious firmware before the operating system starts.
  • The update replaces 2011-era cryptographic signatures with new 2023 versions to mitigate risks like the LogoFail vulnerability.
  • Windows 10 and 11 users can verify their status via the Device Security settings menu.
  • Linux distributors are currently releasing updated "shims" to bridge Secure Boot keys with their bootloaders.

Why it Matters

Failure to update these keys leaves systems vulnerable to persistent malware that can survive operating system reinstalls and bypass traditional security software. Maintaining an updated chain of trust is essential for preventing attackers from compromising the foundational firmware of modern computing devices.
Wired Published by Dan Goodin, Ars Technica
Read original