tech

Windows and Linux users: The deadline to update Secure Boot keys is near

What you need to know about the expiration of keys securing your machine’s boot sequence.

Windows and Linux users: The deadline to update Secure Boot keys is near

TL;DR

  • Three Microsoft-signed certificates crucial for Secure Boot expire on June 24th.
  • Secure Boot uses these certificates to verify firmware and software signatures during system startup, preventing UEFI bootkits.
  • UEFI bootkits are difficult to detect and can reinfect systems even after OS reinstallation.
  • The LogoFail vulnerability discovered in 2023 necessitated the replacement of older signatures with new ones.
  • Windows 10 and 11 machines are being updated automatically or may require manual intervention.
  • Linux distributors are updating 'shims' to bridge Secure Boot keys and the Linux bootloader.
  • Failure to update will render systems vulnerable to UEFI threats.
  • Users are advised to check their Secure Boot status and potentially delay motherboard firmware updates until new certificates are in place.