PKfail Vulnerability Allows Secure Boot Bypass on Hundreds of Computer Models 

A vulnerability dubbed PKfail can allow attackers to run malicious code during the boot process, which can be used to deliver UEFI bootkits.
The post PKfail Vulnerability Allows Secure Boot Bypass on Hundreds of Computer Models  appeared first on Secur… Continue reading PKfail Vulnerability Allows Secure Boot Bypass on Hundreds of Computer Models 

Is the ability to use Machine Owner Keys effectively a bypass of SecureBoot security?

SecureBoot uses a PKI path to verify particular signed bootloader binaries before it runs these binaries. This PKI, as far as I understand, is basically owned by Microsoft, meaning that only Microsoft can sign binaries that will run on Sec… Continue reading Is the ability to use Machine Owner Keys effectively a bypass of SecureBoot security?

Are there any motherboards / UEFI that support hardware encryption on SED?

I found that Thinkpads have hdd password support, which in terms uses some bizarre password hashing and ends up with 90 bits of entropy, which is again used as ATA security password to SED, which in terms encrypts the HDD:s own build-in al… Continue reading Are there any motherboards / UEFI that support hardware encryption on SED?

Are there any motherboards / UEFI that support hardware encryption on SED?

I found that Thinkpads have hdd password support, which in terms uses some bizarre password hashing and ends up with 90 bits of entropy, which is again used as ATA security password to SED, which in terms encrypts the HDD:s own build-in al… Continue reading Are there any motherboards / UEFI that support hardware encryption on SED?

Hundreds of PC, Server Models Possibly Affected by Serious Phoenix UEFI Vulnerability

Hundreds of PC and server models may be affected by CVE-2024-0762, a privilege escalation and code execution flaw in Phoenix SecureCore UEFI firmware.
The post Hundreds of PC, Server Models Possibly Affected by Serious Phoenix UEFI Vulnerability appear… Continue reading Hundreds of PC, Server Models Possibly Affected by Serious Phoenix UEFI Vulnerability

Microsoft Collaborates with OEMs to Update Windows Secure Boot Keys

Microsoft has announced its plans to update Secure Boot on Windows Unified Extensible Firmware Interface (UEFI) PCs. The company is collaborating with its equipment manufacturer (OEM) partners to issue new Secure Boot keys starting this year. Secure Boot is a security feature that was first implemented in Windows 8 machines, particularly those running on the…

The post Microsoft Collaborates with OEMs to Update Windows Secure Boot Keys appeared first on Petri IT Knowledgebase.

Continue reading Microsoft Collaborates with OEMs to Update Windows Secure Boot Keys