Tag
bootai is an open-source UEFI application that boots directly into an AI chat/code REPL, running Qwen2.5 and SmolLM model inference on bare metal without an OS, with hand-written network drivers and a TCP/IP stack.
Researchers at ESET discovered that Microsoft's Secure Boot has been vulnerable to trivial bypass for 13 years due to unrevoked signed shims, allowing attackers to install persistent firmware malware on both Windows and Linux devices.
A terminal installer written in Rust + ratatui with a Ukrainian/English bilingual interface, dedicated to system installation of Artix Linux with dinit. Supports LUKS encryption, Btrfs snapshots, EFISTUB booting, and other features.
The old Microsoft UEFI CA from 2011 has expired, but thanks to coordinated efforts by Debian and other distributions, new dual-signed shim binaries are being deployed to prevent boot failures.
The article covers the upcoming expiration of a Microsoft Secure Boot certificate that Linux distributions rely on for booting via shim, and the complexities involved in updating system firmware to accommodate the replacement key.
A critical deadline is approaching for Windows and Linux users to update cryptographic keys that protect against UEFI bootkits, as three Microsoft-signed certificates for Secure Boot will expire on June 24.
An upcoming deadline requires Windows and Linux users to update Secure Boot keys to protect against UEFI-based bootkits. The expiration of Microsoft-signed certificates on June 24 could leave systems vulnerable if not updated.
This article provides a tutorial on setting up UEFI HTTP and HTTPS boot using QEMU and OVMF, highlighting the need for a random number generator device and demonstrating a minimal configuration.
This article alerts Linux distributions about the upcoming expiration of Microsoft's UEFI CA certificates used for Secure Boot, detailing new certificates and potential boot issues on newer hardware that lacks the old ones.
A novel software-based attack misconfigures the Infinity Fabric to break AMD SEV-SNP security guarantees, allowing a malicious hypervisor arbitrary read/write access to confidential virtual machines.
This article introduces Lanzaboote, a UEFI UKI stub written in Rust that enables Secure Boot support for NixOS. It solves NixOS-specific boot challenges by deferring signature checking to UEFI while keeping kernels and initrds separate from the UKI binary.
A systems administrator explains blocking old browser user-agents to deter LLM-training crawlers, and gives tips for affected users.