Telemetry aside, can anyone comment on this?
Telemetry aside, can anyone comment on this?
* BitLocker: Hard-drive encryption backed by TPM & Secure Boot
With the above two and DMA protection, physical access attacks become very difficult.
* Virtual Secure Mode (VSM) - separate OS running on the hypervisor that can perform sensitive operations. Which enables:
1. Device Guard - Runs code integrity protection, i.e. only allowing signed code to run, from within the VSM.
2. Credential Guard - Runs user-mode security subsystem (LSA) inside VSM.
If that's the secret sauce that makes Win10 so much better, color me unimpressed. And neither of those features offer additional protection against zero-days (neither does VSM), which are what the TFA discusses.
Physical attacks aren't part of my threat model on a desktop PC. Indeed these protections feel more like DRM - trying to protect the computer from the (legitimate) user.
iOS being totally locked down in this way is no small part of why exploits for that platform sell for so much more money than exploits for other platforms. Of course, it is also used for DRM on that platform.
And without Secure Boot and/or TPM-backed key management, hard disk encryption becomes vulnerable to someone planting a modified boot loader or firmware on your system.
A lot of security features found in the previously stand-alone EMET are slowly being ported over natively to Win10, for example. It comes with a built-in AV which is pretty good. Smartscreen is unusually good at warning about suspicious executables and I've seen it stop ransomware attacks. VBS makes it harder for hackers to modify system or protected files. Secureboot and bitlocker support are useful in some scenarios. Device guard is supposed to helpful but I'm not sure how it works. Windows hello can replace the traditional password with camera or fingerprint auth cooked-in, which is probably a step in the right direction, although I'd rather see passphrases become more common. Cameras and fingerprints seem gimmmicky and not all my computers have those things.
But for an RMS-level of paranoia, I might have to go with RTEMS on a FPGA acting as a J-Core (SuperH-2) CPU.
Absent evidence to the contrary, I presume that OpenBSD is more secure than any Windows, even Windows 10, but has considerably fewer features. Do you know of actual evidence?