Microsoft's Secure Boot, an industry-standard security measure, has been compromised for over a decade, and the tech giant's failure to revoke old and forgotten 'shims' is to blame. This oversight has allowed novice hackers to bypass the security feature, which is designed to protect Windows and Linux devices from firmware infections. The vulnerability affects both operating systems, as the shim can be installed on devices running either OS, enabling attackers to install malicious firmware that persists after OS reinstallation or hard drive replacement. The issue lies in Microsoft's oversight of the shim signing process, where the company failed to revoke publicly available images with known vulnerabilities. This lapse has been exploited by attackers, who can use simple scripts to bypass Secure Boot, highlighting a critical flaw in the security model. The complexity of Secure Boot's revocation process, which relies on databases and version-based mechanisms, has contributed to this problem. The discovery by ESET researchers underscores the need for a more robust and transparent approach to security, as the current system leaves devices vulnerable to exploitation. This incident serves as a stark reminder of the importance of regular security audits and the need for a more user-friendly and secure boot process.