Mickey Shkatov and Jesse Michael: One Bootloader to Rule Them All — Bypassing Secure Boot
A DEF CON 30 talk examining weaknesses in Secure Boot — the foundational trusted boot mechanism used in UEFI systems. Despite strict code-signing policies and OEM controls (Microsoft, Lenovo, Dell, and others), the security of the boot chain ultimately depends on the correctness of the bootloaders themselves.
The speakers analyze real-world vulnerabilities in legitimate bootloaders, demonstrate how built-in features can be abused to bypass Secure Boot, and explain techniques for evading TPM measurements used by BitLocker and remote attestation mechanisms.
The speakers analyze real-world vulnerabilities in legitimate bootloaders, demonstrate how built-in features can be abused to bypass Secure Boot, and explain techniques for evading TPM measurements used by BitLocker and remote attestation mechanisms.