'Secure Boot'-Enabled Windows Devices May Be Permanently Vulnerable Due To 'Golden Key' Backdoor, Say Researchers (Updated)

Updated, 9/11/2016, 11:20am PT: Microsoft sent us a statement shortly after we published this article. The statement is below, and we've adjusted the article copy to reflect the new information.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • Jeff Fx
    So we're back to where we were with totally open PCs. Is this supposed to be bad?
    Reply
  • captaincharisma
    still better than a mac
    Reply
  • JakeWearingKhakis
    Umm the update is from the future!!!!!!

    "Updated 9/11/2016
    Reply
  • Rhinofart
    Just wondering, how is that better than a Mac? They are all about the same these days. Mac, Win, *nix same as Ford, Dodge, Chevy.
    Reply
  • abbadon_34
    ""A backdoor, which MS put in to Secure Boot because they decided to not let the user turn it off in certain devices, allows for Secure Boot to be disabled everywhere!""

    So does mean we can truely disable all the datamining and spyware in Win 10 ? Maybe it is finally safe to upgrade. Just waiting on a nice open source utility.
    Reply
  • Darkk
    JAKEWEARINGKHAKIS Aug 11, 2016, 3:34 PM
    Umm the update is from the future!!!!!!

    "Updated 9/11/2016"

    TIME WARP!!!
    Reply
  • memadmax
    Friends don't let friends run Win8/10...

    No, I don't care that MS came out and said it doesn't apply to desktop machines...

    My trust meter with MS is at: -3
    Reply
  • virtualban
    one key feature (not bug) shown, 99 still remaining
    (and, why am I having trouble posting here? had to logout relogin and still brings me to the next article, witcher3 when clicking comments on the same tab)
    Reply
  • kungpaoshizi
    Are you using Chrome Virtualban? I'm using IE (because my work is stupid and won't use Edge) and I have no issues.
    Otherwise this really isn't news. They would say the same thing about a POS system that has no ports and it would qualify because you could break it open and connect to jumpers inside.. There's not a single machine that has un-exploitable setup, in existence, when it comes to physical access.
    Reply
  • godmodder
    If the attacker has physical access, then all bets are off anyway.
    Reply