UEFI Secure Boot Forbidden Signature Boot dbx

I am on a dual boot Debian 12 / Win11 and I get a firmware upgrade in debian with this text:

_Some of the platform secrets may be invalidated when updating this firmware. Please ensure you have the volume recovery key before continuing.

This updates the list of forbidden signatures (the "dbx") to the latest release from Microsoft.

Some insecure bootloaders were added, due to security vulnerabilities that allowed an attacker to bypass UEFI Secure Boot. The additional entries were from: • Baramanudi Management Suite • EAZ EasyFix • Finland Matriculation Examination Board • NTC IT ROSA Linux • PC-Doctor • Spyrus WTGCreator • WhiteCanyon blancco • Some ancient shim releases for OpenSUSE, Oracle and Red Hat_

My questions are:

  • Does dual boot have extra riscs?
  • The volume recovery key: is that the luks encryption key?
  • Any tips how to get it?

Any help much appreciated.

7 points · 7 comments · view on lemmy.world

7 Comments

anamethatisnt@sopuli.xyz · 3 pts · 13d (1 reply)

The volume recovery key refer to LUKS(linux)/Bitlocker(windows).
You got the recovery key when setting up your encryption, if you don't have it saved I think it's lost.

Your first steps before updating the firmware should be to backup your data and update your OS.

joeldebruijn@lemmy.ml · 1 pts · 13d

Thanks, will do and take a deep breath!

libewa@feddit.org · 3 pts · 13d (3 replies)

The volume recovery key for Linux is the LUKS key, yes. You should have that stored somewhere, you can't view it iirc. The volume key for Windows is the BitLocker Recovery Key. If you've signed in with a Microsoft account, it's stored in the cloud, otherwise you should have that printed out, too.

joeldebruijn@lemmy.ml · 1 pts · 13d (2 replies)

Thanks, I keep my Bitlocker key in Bitwarden, need it often after Windows uodates ...

The luks key ... wasnt so clever of me.

I am going to backup extra and see how it goes.

libewa@feddit.org · 2 pts · 13d (1 reply)

It should be fine, as long as you're not using one of these ancient bootloaders.

joeldebruijn@lemmy.ml · 2 pts · 13d

Ah ok, GRUB shipped with Debian 12 means low risc then ...

joeldebruijn@lemmy.ml · 2 pts · 13d

I am stupid ... my LUKS encryption key is the one I always have to type (between Grub and Gnome desktop). ... 🙈