tech
Windows and Linux users: The deadline to update Secure Boot keys is near
What you need to know about the expiration of keys securing your machine’s boot sequence.

TL;DR
- Three Microsoft-signed certificates crucial for Secure Boot expire on June 24th.
- Secure Boot uses these certificates to verify firmware and software signatures during system startup, preventing UEFI bootkits.
- UEFI bootkits are difficult to detect and can reinfect systems even after OS reinstallation.
- The LogoFail vulnerability discovered in 2023 necessitated the replacement of older signatures with new ones.
- Windows 10 and 11 machines are being updated automatically or may require manual intervention.
- Linux distributors are updating 'shims' to bridge Secure Boot keys and the Linux bootloader.
- Failure to update will render systems vulnerable to UEFI threats.
- Users are advised to check their Secure Boot status and potentially delay motherboard firmware updates until new certificates are in place.