Microsoft's Secure Boot, an industry-wide standard designed to protect Windows and Linux devices from firmware infections, has been vulnerable to bypasses for over a decade. This critical flaw, recently uncovered by researchers at ESET, highlights the complexity and potential weaknesses of the Secure Boot model. The issue stems from the existence of 'shims' - secondary trust anchors signed by Microsoft that authorize subsequent software loading during the boot process. These shims, which were introduced to extend Secure Boot to Linux devices and utility software, have been left unsigned and unrevoked by Microsoft, despite known vulnerabilities. This lapse has allowed attackers to bypass Secure Boot with relative ease, using simple scripts and basic knowledge of UEFI shims. The threat is particularly concerning as these vulnerable shims can be used against both Windows and Linux machines, although likely not Windows 11 Secured-core PCs in their default state. The complexity of the Secure Boot process, which involves multiple databases and revocation methods, has contributed to the difficulty in identifying and addressing these vulnerabilities. This debacle serves as a solid rebuke of the secure boot model, with experts like HD Moore calling for a reboot of the entire ecosystem. The incident underscores the importance of regular updates and the need for a more robust and scalable security model, one that can adapt to the evolving landscape of cyber threats.