Skip to main content

Posts

Showing posts from August, 2026

What Does Windows Security Mean by an Older Boot Trust Configuration?

A Windows 10 or Windows 11 PC can pass every Secure Boot check its owner knows how to run and still be trusting certificates that expired in June 2026. msinfo32 reports Secure Boot State: On . Nothing fails to start. And Windows Security, under Device security → Secure Boot , shows a yellow badge whose sentence opens with those same two words. In the ordinary case the fix is one line: install the latest Windows updates and restart. What makes it worth more is that six status messages can appear in that spot, all six begin “Secure Boot is on”, and only one is fixed by patching. Two mean do nothing. Two point to Microsoft's guidance rather than anything the update screen can do. One is not a software problem. The badge colour does not separate those cases: four of the six carry the same yellow warning. The text after the comma is what distinguishes them. Start Here: Read the Sentence, Not the Badge Open Windows Security → Device security → Secure B...

Four KB Numbers, One FileFormatException: WPF Printing and PDF Export Since August 11

A document that printed without complaint in July stops printing in late August. Depending on the application, the print dialog closes and nothing reaches the queue, the export writes a file that will not open, or an error surfaces carrying the text System.IO.FileFormatException . The printer is not the thing that broke: the same printer, on the same machine, answers immediately from a different program. Microsoft has published this as a known issue against the .NET Framework cumulative updates released on August 11, 2026. The published wording is narrow, and the narrowness is the part worth reading closely: "After installing the August 2026 .NET Framework cumulative update, some WPF applications may fail with a System.IO.FileFormatException when printing or generating PDF/XPS content that uses certain fonts, including Calibri." Some applications, not every application. Certain fonts, of which Calibri is the only one named; the rest of that set has not been published. The ...

A Fourth DNS Server Is Not a Backup. Windows Reaches It Four Seconds In.

A name lookup fails and the application reports the failure after roughly ten seconds. The wait is the same whether two DNS servers are configured or six. Adding another server to the list does not shorten the wait, and the fourth one appears never to be used at all. None of that is a fault. Both numbers — the ten seconds, and the point at which later servers first get a question — are published defaults, and they are documented precisely enough to be read off a timeline. What follows is where the time goes, why the length of the server list stops mattering after the third entry, and the one place where the client and the server disagree about whether the lookup is over. What to Change First Before any of the mechanism below, three changes account for most real improvement. Put the server that answers fastest first. The first entry is queried alone at 0 s . Every other entry costs at least one full second of waiting before it is consulted. Stop at three entries on a client. ...

Every Authenticator Code Rejected After a Device Clock Drifts a Few Minutes

When an authenticator app produces a six-digit code and the site rejects it every time — three codes in a row, each typed within two seconds, same result — the password is almost never the problem. The usual cause is that the clock on the device generating the code has drifted away from the clock on the server checking it. A time-based one-time password is computed from the current time, so if the two clocks disagree by more than the verifier tolerates, the code is arithmetically correct and still refused. Stop entering codes and measure the offset first. Open time.gov in a browser on the device that runs the authenticator app. Operated by the NIST Time and Frequency Division and the United States Naval Observatory, it shows a line reading "Your clock is off by: ___ s" , noting that "Clocks are corrected for network delay." Read that number against the two tolerances quoted below — about 89 seconds in RFC 6238's worked example, and plus or minus one minute in...