MICROSOFT IS “IN DENIAL” about a selfinflicted security flaw that could let hackers take control of Windows systems, the hackers who discovered the flaw have told PC Pro.
Microsoft released a so-called “golden key” that allows users, and also potentially hackers, to alter Secure Boot, which is part of the Unified Extensible Firmware Interface (UEFI) – see p40. Secure Boot ensures only certified operating systems can run on the device, and is initiated very early in the UEFI process, but the researchers found a way to deactivate the security measures.
Although Secure Boot is a key security feature, Microsoft needed a way to switch it off or modify it for development, engineering or refurbishment, for example. The so-called “golden key” was never supposed to be made public. “A backdoor, which…