- Secure Boot is a feature of your PC’s UEFI that only allows approved operating systems to boot up.
- It’s a security tool that prevents malware from taking over your PC at boot time.
- While it’s not recommended to disable Secure Boot, you can customize the certificates it uses to authenticate which operating systems are approved on your PC.
- Visit Insider’s Tech Reference library for more stories.
Secure Boot is a feature found in the startup software for your computer that’s designed to ensure your computer starts safely and securely by preventing unauthorized software like malware from taking control of your PC at boot-up.
If you’re using Windows 10 and a modern PC with UEFI (Unified Extensible Firmware Interface, the low-level software that enables your computer to boot), then you’re automatically afforded protection from illicit software attempting to take control of your computer when it starts up.
How Secure Boot works
Before Secure Boot, the computer’s BIOS (Basic Input/Output System) would hand off control of the PC to any bootloader that was located in the right location on the hard drive. There was no way for the BIOS to validate or authenticate the software, so anything could boot the PC – Windows, other operating systems like Linux, and even malware.
That’s no longer the case. Secure Boot is a feature in UEFI, which has replaced the BIOS on the vast majority of PCs in use today. While the BIOS was commonly used in computers from the first PC until the 2000s, today virtually all PCs use UEFI. You may have seen the UEFI interface if you had to access the startup menu by pressing a keyboard shortcut (usually F1 or F2) when the computer is first turned on.
Secure Boot establishes what programmers refer to as a “trust relationship” between the UEFI and the operating system that it launches at boot time. To do this, the launch software is signed with pairs of public/private security keys. The operating system’s private key is “whitelisted” by UEFI. If UEFI has approved the key, the software (like Windows 10) can launch.
Windows 10 ships with a certificate that’s stored in UEFI; this serves as the key that allows it to boot. Likewise, other reputable operating systems (like Linux) can also acquire a key and register with UEFI, allowing them to boot securely as well.
Conversely, if malware tries to install a bootloader on your PC to take over at startup, it will not have a signed key, and UEFI will not allow it to launch.