Hard to believe but Secure Boot BIOS security has been compromised on hundreds of PC models from big brands because firmware engineers used four-letter passwords

PC detail
(Image credit: Future)

Now, I'll admit my own password hygiene isn't always the best, though I have graduated from the days when I used "xxxxxx" for a few non-critical accounts under the reverse psychology assumption that it's so obviously insecure, nobody would bother trying it. Genius, I know. But even I realise a four-character password is a big no-no.

And yet that's exactly what was used to protect an encrypted file that was critical to the fundamental integrity of the Secure Boot, a UEFI BIOS security layer designed to ensure that a device boots using only the software that is trusted by the PC maker itself.

Ars Technica reports that, "researchers from security firm Binarly revealed that Secure Boot is completely compromised on more than 200 device models sold by Acer, Dell, Gigabyte, HP, Intel, Lenovo, Supermicro and others. The cause: a cryptographic key underpinning Secure Boot on those models that was compromised in 2022." Ouch.

Apparently, a critical cryptographic key for Secure Boot that forms the root-of-trust anchor between the hardware device and the UEFI firmware that runs on it and is used by multiple hardware manufacturers was published online, protected only by a four-character password. Security outfit Binarly spotted the leak in early 2023 and has now published a full report outlining the timeline and development of the problem.

Part of the problem, as we understand it, is device makers basically using the same old keys over and over again. To quote Binarly, the security failure involves, "no rotation of the platform security cryptographic keys per product line. For example, the same cryptographic keys were confirmed on client and server-related products. Similar behavior was detected with Intel Boot Guard reference code key leakage. The same OEM used the same platform security-related cryptographic keys for firmware produced for different device manufactures. Similar behavior was detected with Intel Boot Guard reference code key leakage."

The report includes a list of hundreds of machines from the brands mentioned above that have all been compromised by the leak. For the record, some of those systems include Alienware gaming desktops and laptops. Security experts say that for those devices that use the compromised key, it represents an unlimited Secure Boot bypass allowing malware to be executed during system boot. Only a direct firmware update for each device can secured affected devices.

Your next machine

Gaming PC group shot

(Image credit: Future)

Best gaming PC: The top pre-built machines.
Best gaming laptop: Great devices for mobile gaming.

All that said, Ars Technica quotes many of the brands involved essentially claiming that all of the relevant systems have now either been patched or taken out of service, which is presumably why Binarly is now publishing details of the security breach that would allow bad actors to take advantage of it.

That all seems to indicate that this is now a historical problem rather than a live security risk. But it also underlines how easily even well-conceived security features can be undermined if not implemented properly. As one security expert interviewed by Ars said, "the story is that the whole UEFI supply chain is a hot mess and hasn't improved much since 2016."

Anyway, if you have any concerns, hit up the full report and have a looksee if any of your devices appear. If they do, a BIOS update is very likely in order.

Jeremy Laird
Hardware writer

Jeremy has been writing about technology and PCs since the 90nm Netburst era (Google it!) and enjoys nothing more than a serious dissertation on the finer points of monitor input lag and overshoot followed by a forensic examination of advanced lithography. Or maybe he just likes machines that go “ping!” He also has a thing for tennis and cars.

Read more
Pipboy holds up an open padlock.
A BIOS update could be all that's stopping you or someone else from jailbreaking your old AMD CPU
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Microsoft Windows 11
If you installed Windows 11 with certain security updates and a USB stick, you may not get any more security updates warns Microsoft
Retro 1990s style beige desktop PC computer and monitor screen and keyboard. 3D illustration.
Microsoft nixes details of its Windows 11 TPM 2.0 security bypass though there are still other ways of getting the latest OS on 'unsupported' hardware
ASRock X870 Steel Legend WiFi motherboard
Reddit reports of 9800X3D CPUs dying in ASRock motherboards are racking up fast, but a new BIOS update seemingly only addresses boot problems
Latest in Hardware
MSI RTX 5070 Ti Gaming Trio OC Plus graphics card under a red light
This MSI Afterburner file unlocks 36 Gbps RTX 50-series memory overclocks for, y'know, the few people that actually own a card
A Steam Deck with SteamOS running in desktop mode.
A new and improved desktop experience just landed on Steam Deck and SteamOS is readying 'support for non-Steam Deck handhelds'
The Cherry Xtrfy K4V2 TKL gaming keyboard on top of a mouse pad depicting a nebula. The keyboard is grey with red accent keys, a grey braided wire, and the bright RGB lights switched on.
Cherry Xtrfy K4V2 TKL review
A "sensor-actuator–coupled gustatory interface chemically connecting virtual and real environments for remote tasting," or essentially a virtual reality tongue in an artificial mouth
Would you like to taste fish soup in VR? Me neither, but this electronic tongue does it anyway
Razer DeathAdder V3 Pro gaming mouse on a blue background
The DeathAdder V3 Pro is currently so cheap it's put the usually more affordable HyperSpeed version out of a job
MSI RTX 5090 Suprim SOC graphics card on a grey background with a gradient
MSI RTX 5090 Suprim SOC review
Latest in News
Three sheep with big guns in Palworld.
It was 'super popular to hate Palworld' after launch, says community manager: 'A lot of companies might crumble under the threats, under the pressure'
Palworld Ancient Civilization Parts - Grizzbolt with a minigun
'It was a very depressing day': Palworld community manager reveals studio's reaction to Nintendo lawsuit
CS 1.6 remade in CS: Legacy.
A gorgeous ground-up remake of Counter-Strike 1.6 is on its way to Steam, and one of the game's original creators says 'it really gives me old vibes'
Portal P3 pinball table
There's a new Portal game and it costs $12,500
MrBeast posing in front of a stack of cashing, promoting Beast Games season 2
Beast Games opens casting for season 2: MrBeast lost a ton of money on season 1 but apparently not enough that he won't do it again
Ark: Lost Colony teaser still.
Ark 2 is still on: The next Ark expansion 'leads into the events of Ark 2,' says Studio Wildcard