My understanding after reading about BIOS + UEFI bootloaders is that clearing out the MBR for legacy BIOS drives is enough to make them non-bootable drives, even in a UEFI computer. For testing purposes, I tried to zero out my entire 8 GB USB drive and see if it stops showing up in the BIOS boot menu, just to confirm my understanding. Yet, every time I reboot, my (UEFI) computer still shows the drive in the boot menu (which I take to mean that it is still marked as bootable).
Why doesn’t zero-ing out my USB drive remove it from the boot menu?
Steps to reproduce:
First, I zeroed out the entire drive by running:
sudo dd if=/dev/zero of=/dev/sde count=8G status progress
Next, I verified that the first 512 bytes (which should be the MBR) were zeroed out:
$ sudo xxd /dev/sde | head -n 33
00000000: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000010: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000020: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000030: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000040: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000050: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000060: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000070: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000080: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000090: 0000 0000 0000 0000 0000 0000 0000 0000 ................
000000a0: 0000 0000 0000 0000 0000 0000 0000 0000 ................
000000b0: 0000 0000 0000 0000 0000 0000 0000 0000 ................
000000c0: 0000 0000 0000 0000 0000 0000 0000 0000 ................
000000d0: 0000 0000 0000 0000 0000 0000 0000 0000 ................
000000e0: 0000 0000 0000 0000 0000 0000 0000 0000 ................
000000f0: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000100: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000110: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000120: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000130: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000140: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000150: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000160: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000170: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000180: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000190: 0000 0000 0000 0000 0000 0000 0000 0000 ................
000001a0: 0000 0000 0000 0000 0000 0000 0000 0000 ................
000001b0: 0000 0000 0000 0000 0000 0000 0000 0000 ................
000001c0: 0000 0000 0000 0000 0000 0000 0000 0000 ................
000001d0: 0000 0000 0000 0000 0000 0000 0000 0000 ................
000001e0: 0000 0000 0000 0000 0000 0000 0000 0000 ................
000001f0: 0000 0000 0000 0000 0000 0000 0000 0000 ................
00000200: 0000 0000 0000 0000 0000 0000 0000 0000 ................
Finally, to get my computer to stop showing the drive as being bootable, I tried 1) shutting down instead of rebooting, 2) plugging and unplugging USB drive between reboots, and 3) removing the USB drive from the EFI NVRAM by running:
$ sudo efibootmgr
BootCurrent: 000A
Timeout: 1 seconds
BootOrder: 000A,0009,000D,000C
Boot0009* Hard Drive
Boot000A* ubuntu
Boot000C ubuntu
Boot000D* USB Floppy
$ sudo efibootmgr -b 000D -B
$ sudo efibootmgr
BootCurrent: 000A
Timeout: 1 seconds
BootOrder: 000A,0009,000C
Boot0009* Hard Drive
Boot000A* ubuntu
Boot000C ubuntu
I also tried plugging in my USB on another UEFI computer, which also shows the USB as an option in the boot menu.