Microsoft leak reveals new Windows 10 Workstation edition for power users
theverge.com
theverge.com
At this point, it's like she's just trying to justify her position.
"Maybe if I invent more Windows editions my salary will also increase because of the increase in responsibility as well as the higher revenue from the nickle and diming customers?"
I imagine that would be her line of thought.
This product is a another way to devalue the old SKUs by introducing yet another premium priced product.
Cant reply below so adding my comment here:
That path doesn't exist for volume. There is no OEM to Volume path and guess what every business uses: Volume.
> Dell and Lenovo and HP have standard agreements to put Home on every PC, youre not paying for an individual OEM license.
The cost per OEM license of windows was reported to be $40-$80 depending on edition. That is baked into the cost of the computer you buy from them. You're not getting it for 'free' the same way you aren't getting leather seats for free because you bought the LT model of a car. You're paying for that too.
there is an upgrade path in that you can type in a key to transition from pro to enterprise.
>So you're paying for Windows twice, once via the OEM Pro license you'll never use Buy the computer with home. You cant buy most computers without Home anyway, so unless you are going to buy from a very slim line of linux laptops or become a laptop manufacturer, its not really paying twice. Dell and Lenovo and HP have standard agreements to put Home on every PC, youre not paying for an individual OEM license.
I remember (back in the day) Windows NT came in "desktop" and "server" editions. Someone did some digging, and it turned out the difference was 2 registry keys, whose settings were checked at boot time, and depending on the settings, the "server" or "desktop" editions were created.
Times have changed; Microsoft needs to change too.
I just want an OS that works. So I use OSX and I use Linux. Where I don't have to care much about what I'm running. At most I have to occasionally care about the revision I'm running being a bit old. But there's no nonsense with different editions that I need to waste time on.
MS does this to windows since... I'd say since Windows was a thing, but I don't know how they sold versions 1 and 2. So, since Windows 3.
Yet, if you segment your market too much, people stop knowing the segment they belong, and stop playing the game.
I destroyed the OS on that computer at least twice by doing stupid things like deleting DLL's in the windows folder because 8 year old me decided he "didn't need them" and bypassed the system file protection, but apparently that's part of learning to use and understand computers. Certainly it taught me how to install a new OS, which opened up a world of new OS's to me, which brought me to VM's, which inexorably lead to experimenting with hosting services, which lead to sysadmin skills, and so on.
Considering Microsoft is operating in and even leading an industry that alleges it is slowly starving to death from lack of new talent, creating versions of the OS with anything less than 100% control seems like a really stupid long term move. How are people supposed to form an intuitive grasp of the potential of general purpose computers if they grow up with machines that say "I'm sorry Dave, I'm afraid I can't do that"?
Basic thing is that power users and "security" do not mix. And yes, there is a small aspect of protection from external threats in there. But just as much it is about paternalism, and, in the case of Microsoft, about shoring up revenue streams.
Still don't care about W10.
It is such a big problem that Valve had to build in detection into their game where they warn you about it.
And in order to turn it off, you either have to login to their Xbox App, or play around with regedit, Valve have documented it here: https://support.steampowered.com/kb_article.php?ref=6239-DZC...
And it seems like updates are enabling it again automatically, because I have had to do it twice.
All of this can potentially be inspected by Google if you use their platforms or services.
There's really no difference here. Condemn Microsoft, condemn Google. Be upset both have defined your privacy as unimportant.
Oh god I'm giving them ideas...
https://www.reddit.com/r/TronScript/
Personally I just boot into Linux unless I'm streaming (Netflix 720p on Linux, boo), playing Civilization or doing my taxes.
Also, it should have a telemetry manager that applications have to use for sending telemetry data to Microsoft. It should have UI and PowerShell cmdlets that help people see the data that's being collected. It should have a global off switch for people that are concerned about it.
I tend to think that things like telemetry or "swarm" downloading of updates and patches are good things. I know that's not popular. I think that they need to be far more transparent about that stuff to make privacy concerned people happy.
Also, there are some people that are never going to like Microsoft, Windows, or anything that they do. I kind of wish those people were less involved in the conversation. If you aren't going to use their stuff, why should they listen to your feedback?
[1] https://www.forbes.com/sites/antonyleather/2017/05/17/amd-an...
it might help them wring more cash out of already-windows-users who need these new features. but those users will be glancing to the side and noticing all the features packed in for free by OSX and linux, and without a malignant upgrade process.
Shouldn't reliability always be as high as possible? Why would workstation users get more reliable operation than anyone else?
But probably this was written by some marketing guy with only half a clue.
Win10 Pro supports 2 CPU sockets and all cores within them. Expanding this up to 4 sockets seems to undercut their server market as past 2 sockets Win10 Server charges per socket.
I feel tricked into using the worlds worst OS.
MS is really outdoing themself lately.
I think at this point they'll have to do more than get rid of ads and telemetry to get me (and others) to switch back. Linux turned out to be much more stable than Windows for me, and after experiencing package management and sane update policies I can't go back to an OS that won't even let me use it while it's installing updates.
When I sit and try to make a list of reasons to use Windows it seems to come down to program compatibility and not operating system quality. Instead of trapping people on an OS because of vendor lock-in, try improving core parts of the OS to make it worth using.
https://en.wikipedia.org/wiki/Windows_Error_Reporting#Privac...
- You can't disable telemetry completey. Some people want it, some don't. Let the user decide.
- Microsoft does collect an insane amount of data.
https://docs.microsoft.com/en-us/windows/configuration/basic...
I would be curious how many users want telemetry sent to Microsoft. It seems the two largest buckets, by far, would be those who don't care and those who don't want it.
The problem with opt in is that most people, where most crashes occur, would never read what the prompt says asking them to send the data, they would just press the x in the corner because a dialog box popped up they didnt ask for. "What did that box say. I dont know. Why did you close it. Because I didnt want it."
You're describing a UX issue with the worst possible way this could be implemented. What chafes me is not that I'm not asked for permission for every crash report, but that I don't have the option to disable crash reports at all.
That's right, because all these unsolicited prompts and notifications are a waste of people's valuable time. A well-designed OS should aggressively keep quiet, stay out of the way, and err on the side of user privacy.
Your Windows crashing is an issue strictly between you, Microsoft, and the makers of whatever software and hardware you were using when the crash occurred. Absolutely nothing to do with anybody else.
I want your data sent to Microsoft too, for the same reason. I don't want my data sent to Microsoft, though.
As long as you're clearly informed about what kind of information it's collecting and you can turn it off (and ideally tune it) it's fine with me.
The opt in piece is important because you need large amounts of data to detect emerging issues. It lets you distinguish between flukes and trends. This enables the quality of service that the user expects.
It is simple, data is becoming worth something because you now have the ability to analyze all the data you could ever collect. And so, everybody naturally jumps on the wagon because of the inherent profit motive.
If a computer was an appliance, you would buy it and it would never need to phone home. Now we both know that there is some need for updates and it might therefore be a good idea to classify computers as something other than appliances.
Telemetry can be done right by letting end-user to see an example of the data that's going to be sent and then also audit the actual reports that were sent. Transcribed into a human-readable format with some comments about what the values mean - I can see the binary data myself, thanks. And a way to opt out if the data is found to be actually sensitive.
Basically, an opt-out switch and "sure, but give me a full transparency report" mode that a "power user" can optionally access if they happen to care. This is rarely the case, and not the case with Windows.
I agree with the desire for complete transparency in data shared, but eventually this will run afoul of a number of practices which rely on cat-and-mouse games where one side doesn't have complete information (an obvious example being precisely what sorts of data Windows Defender uses/sends for malware found by heuristic, presuming it doesn't just ship the entire binary off), to say nothing of the conspiracy theories that would arise every time they ever added some kind of data collection.
I don't have a good answer for this friction in general - complete transparency would only fly until a piece of malware that circumvented every heuristic and strict rule caused a major incident, whereas nearly complete opacity is where we are now.
(There's also the conflict of their lack of recurring revenue for Windows 10, which is why I'd anticipate them eventually at least floating the option to disable the "end user data as payment" harvesting for an annual fee, but...)
https://www.microsoft.com/investor/reports/ar16/index.html
https://www.fastcompany.com/3064030/satya-nadella-on-microso...
I couldn't find the older articles about how Ballmer was complaining that they were missing out on the personal data gold rush that Google and Facebook were experiencing.
Google's entire business is built around selling the presentation of unwanted information around the organic content you want. That works great in a visual medium where the extra information requires no more of your time and only minimally more of your attention. Alexa and Cortana and Siri shift that interaction to audio where it becomes incredibly difficult to insert even a tiny fraction of the surrounding ad content search engines used to deliver visually. Alexa and Cortana and Siri break google's business model because they break the ability to spam customers with ancillary information, and they can do that because neither Amazon nor Apple nor Microsoft derive the bulk of their revenues from ad sales. This is a battle of business models, not a quest for the other guy's business model.
So yes, Microsoft is building Cortana, and no, Cortana isn't about becoming an advertising powerhouse it's about blocking their two ad-fueled competitors (the best discussion I'm aware of of google's efforts to fight back against this agent-driven threat to their ad-based business model is [0] )
[0] https://stratechery.com/2016/google-and-the-limits-of-strate...
Is there an article where I can read more about that?
There were earlier articles that talked about the frequency of audio dumps (every 30 minutes) but I wouldn't call them as reliable sources as Ars or Microsoft.
Developed capacity may not equal intent, but if you can be ordered to do secret work and make it so anyway, the distinction is irrelevant.
It is entirely unclear if they did.
While the name of big companies (Google, Apple, Yahoo!, Microsoft, Dropbox, etc) got dragged through the mud, it only appears that these companies were responding to court orders and that "directly" in this context meant with cooperation of these companies and the courts. Companies are legally obligated to respond to valid court orders, issued from a normal court or secret court. See this slide[0], the fact that all data from those companies was going through the FBI instead of an NSA codename project, should tell you everything you need to know about the mechanism (i.e. legal, not technological).
The PRISM program seems to primarily be about hooking into telecommunication infrastructure (both in the US and abroad). Telecommunications companies were definitely complicit.
[0] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)#/...
The inverse of that is that all I need Windows for is Adobe stuff and Outlook (we use Exchange for mail, meeting scheduling, tasks etc.), which all run perfectly fine in a Windows VM with minimal resources. The only real extra setup involved there is running the Windows installer, which takes like 20 minutes tops.
So what's left to compel me to use Windows? The UI? Admittedly, I feel a bit more zippy in Windows than I do Linux, but Kubuntu feels pretty damn close and I kind of prefer its UI over Windows' at this point.
However, OS X gets excluded because it immediately constrains my hardware purchases.
Man how often do I hear "I don't want ads on my desktop" or "I want higher quality hardware" or "I'd pay more for a system that X" and then in the same breath someone says something ridiculous like "the apple tax".
It's like in cell phones. People bemoan how expensive iPhones are and brag about how cheap you can get an Android phone. An iPhone is $600 but you can get an Android phone for $100! Then I ask which Android phone I should get and I'm told "Samsung Galaxy S8", which is the same price as an iPhone!
I'm told Apple laptops are too expensive, so I ask which Windows laptop I should get and I'm told a Surface, a Thinkpad X1 Carbon, an XPS 13... all of which are exactly comparable in price with a Macbook.
It's almost like "the apple tax" doesn't exist and people are just mad that Apple doesn't make cheap low quality products that the person complaining would never buy anyway.
If you want equivalent specs then sure, the prices are going to be similar but that's the whole point, with Android (and a PC) you've got a wide range of _choices_ on many parts of the specifications/price spectrum. With Apple you've got far fewer.
The same goes for laptops where you listed three different manufacturers.
That is literally exactly what I said. If a Galaxy S8 and an iPhone with the same hardware costs the same price, there is no such thing as "the apple tax". None. Can't happen. They cost the same. The only difference is that Apple doesn't make anything cheaper, but google "best laptops 2017" and guess what? They all cost the same as a Macbook.
So as it turns out, Apple's prices are comparable with their direct competitors. Ergo, the Apple tax doesn't exist.
If your needs are met by the low end, you're forced to pay a premium.
You replied "Not sure I agree on the cell phones at all."
Your justification for that was "Apple's prices are comparable with their direct competitors for similar specifications but they just don't provide a low end."
It is a complete non-sequitur to say they're charging you a premium to buy a high-end device if you want a low-end one. They charge exactly the same for exactly the same. Not a tax.
Fact: Apple's prices are competitive with comparable devices.
Fact: Apple only competes in the high end market.
Not fact: Apple forces you to buy their products even if you can't afford it.
Laptops are an second pc for work station users sorry a MacBook "pro" is marketing speak.
OS X has plenty of ads and nags for iCloud and Apple Music FYI.
Fill up your iCloud space and it will ask you to buy more on every boot.
Siri on OS X was artificially limited to only play music from Apple Music but not your iTunes library when even the iPhone 4 could play music stored in its internal app.
I want a car that doesn't come with advertising built in. Every time I'm low on gas it starts dinging and flashing lights at me, and - can you believe this, people - if I refuse to buy any more, the car won't even start! And don't get me started on what happens every 10,000 miles... demanding I change the oil! I'm not a sucker, I won't fall for their advertising!
Also low space notifications for a service I am already using would be different than advertisements for a service I am not using at all.
The edge notifications look like a system alert and trigger constantly.
It's an ad because they are advertising the iCloud service to you. It's not just that they say "Your iCloud is running out of free space", it's that they say "Your iCloud is running out of free space, buy more space here!"
It's an install option for OSX and you can trivially disable it as well. OSX runs just fine without it.
That's not an advertisement. That's a critical notification about a service you've chosen to use. It's not any different just because they offered a free trial.
No, I expect it not to try to sell me something at all. If I'm close to my capacity limit, it just means I need to clean some of the crud out.
It's not that they say "Your iCloud is running out of free space." or "Your iCloud is running out of free space, buy more space here!" it's that they say "sign up for iCloud and store your X!". The first two are status updates for a service that's already being used. The last is an ad.
Very strange.
No one chooses to use iTunes, given reasonable alternatives. It is the only way to interact with some iDevices.
I know your being facetious, but the easy answer to that question is the Moto G5 Plus, which you can pick up for $230 in most any Best Buy or Costco in the US.
There are many other good choices there too.
> I'm told Apple laptops are too expensive, so I ask which Windows laptop I should get and I'm told a Surface, a Thinkpad X1 Carbon, an XPS 13... all of which are exactly comparable in price with a Macbook.
I don't think that's true. Apple store is down for WWDC today, but as of yesterday a 13' MacBook Pro is $1,300. The closest matching Dell XPS 13 is only $1,000. It has a lower resolution screen, but a newer gen processor and 10% more battery.
----
Fundamentally, Apple products carry a premium price. Some non-Apple products also carry a premium price (see the Surface Book as a good example). But that doesn't mean the "Apple Tax" (higher margins) aren't real, or that there aren't comparable products without it.
Again, the lineup is being refreshed today, so this may all change. But the Mac Pro is the typical perfect example of this -- you can build or buy a more powerful, smaller, faster PC including licensed Windows 10 Pro for much cheaper than a Mac, literally just a small fraction of the Mac Pro's current price.
My ThinkPad is easy to repair (already did a small repair myself), has support for a docking station (currently I don't need it, but a friend loves it), has an ethernet port (I won't buy a laptop that has no ethernet ports), allows one to buy a battery (or even buy a larger battery if I prefer one), allows me to add additional RAM myself if I conclude that I need more, ...
Does HFS+ really count as "native Unix"? (I'm not entirely sure what that would mean, so it's hard to argue, but it doesn't feel right.)
When you sandbox test your changes in your local dev you also quickly learn which pieces of your code are non-portable or non-standard.
I have worked at places were the dev test and prod systems where brought from the same sun production run so that the systems where identical down the rev of the motherboards, our networks and sysadmin said he would have liked to buy all the Disks (DASD) from the same production run as well.
That you write and test the code before moving to the "proper" development environment running Linux gives you a chance to ensure you're not writing Linux-specific code in cases where portability at least a passing concern (read: unless you're developing platform specific firmware).
Windows is not UNIX and that's its strength. Don't try to coerce it into doing Linux things; learn Powershell and Windows concepts instead. I've recently switched development from Linux to Windows and couldn't be happier.
Yes, it's a lot to learn at start, but Powershell is rather user-friendly, so it helps. Yes, I work slower now than in Linux, but I'm quickly picking up the pace and it's paying off. Plus, there are many hands-on howtos for specific tasks I need to accomplish.
Also change to IIS web server, because it's better.
Microsoft seems to disagree, which is why they felt compelled to include a Linux sub-system in Windows.
Random link that mentions the OS/2 subsystem.
https://brianreiter.org/2010/08/24/the-sad-history-of-the-mi...
The best thing Git did was to distribute Git Bash by default.
The only credible complaint I've heard against PowerShell terminal is path completion. I call it credible, because it's an actual behavioral difference with meaningful impact. Myself, I actually prefer the Windows path completion, where it fills the entire path and hitting tab again will cycle through the available options. Nothing drives me crazier than going into a directory generally knowing what I want, typing in a few letters, hit tab, get a subset of the path completed, think about what's there and where I want to go, figure out the next letter I need to type, hit tab again and hope for the best. When in reality there's only a few options that match my original text, and just hitting tab to cycle between them is pretty ergonomic. And shift-tab even cycles in the other direction, for those rare times when there actually is a huge list and you hit tab a little too quickly.
But for those who prefer the other way for some reason, there are projects like PSReadLine:
https://github.com/lzybkr/PSReadLine
EDIT: Found the previous discussion.
The most annoying issue I have run into - try to delete a node_modules folder with powershell. It's painful.
Completely agree. PowerShell is an object pipeline, which means that its axioms are different than a text pipeline. If you come in trying to treat it like a text pipeline, you're not going to find the tools you expect.
> The most annoying issue I have run into - try to delete a node_modules folder with powershell. It's painful.
I was curious, so I just did the following in PowerShell v5:
* Create a new, empty directory.
* Retrieve NPM modules (`npm install browserify gulp`).
* Ran `rm .\node_modules -Recurse`.
* Directory is gone.
What has your experience been?
zstyle ':completion:*' completer _complete _match
autoload -Uz compinit
compinit
There are many other options available with 'compinstall', but I set this up years ago and don't remember what I needed to choose. It's probably also available in Bash nowadays.The best approach I've seen isn't to change defaults, but rather to make porting customization painless. And that's definitely something that can almost always be improved. I've actually been recently impressed by Samsung in this regard with their "Smart Switch" phone app. Super simple to transfer a lot of the stuff you care about from one phone to another, including sourcing from iOS and even Windows Mobile!
Both use console host. Before it was horrible, but they've improved it recently: https://technet.microsoft.com/en-us/library/mt427362(v=ws.11...
And how does one exactly do that? Because I once tried to learn what a "home group" was and to my surprise it wasn't defined in precise terms anywhere. Not to mention lower-level stuff such as the init system.
The init system on Windows is robust enough that 99.999% of users never have to consider it. There is a UI to control what runs at startup, and that suffices for most things.
Windows has services of course, and there is a dependency graph built up of how they initialize, and for a huge % of people developing services, this also doesn't matter. Set what dependencies you have, if your service can be loaded on demand or if it has to be always on, and have at it.
More complicated services do require work, at which point documentation can be dug into.
> Because I once tried to learn what a "home group" was
Bing actually provides a great answer box on this. (search term: windows home group) tl;dr a group of PCs on a LAN that share out file folders (video, music, etc) and printers. Each computer can choose what to share. A PW is requested upon joining a home group. The first non-ad result on Google also explains it pretty well. :)
A protocol spec is also available: https://msdn.microsoft.com/en-us/library/ff362232.aspx
(found by searching home group msdn)
GNU's not Unix either, come to think of it. :p
This claim needs explainatory details, citations, and maybe even context.
For example. Create a new VM, and just have it create a dummy LV that you can throw away later (I actually keep a 4MiB one around just for the purpose of having something virt-manager will see and select).
Create the virtual size LV:
sudo lvcreate -V 50G -T thintastic/vg -n windows
Then 'virsh edit daisy' and find the disk section. <disk type='block' device='disk'>
<driver name='qemu' type='raw' cache='unsafe' io='threads'/>
<source dev='/dev/vg/dummy'/>
<target dev='vda' bus='virtio'/>
<boot order='1'/>
<address type='pci' domain='0x0000' bus='0x00' slot='0x07' function='0x0'/>
</disk>
Change the path from /dev/vg/dummy to /dev/vg/windows, save it. Now start the VM normally, and it'll use that thinp LV just fine. So the neat thing about that is, you give 50G to Windows, but it's only going to suck up from the VG what's actually being written to disk from Windows; i.e. an installation involves about 15G of writing, so it will only take up 15G of the VG pool's extents. The other 35G are still in the VG pool.You could make the virtual size LV 500G and Windows will see it as 500G, even if it's only backed by 75G of VG. Obviously if you hit 75G of writes, the virtual block device spits out ENOSPC and then presumably Windows gets pissed that it doesn't in fact have 500G to play with. But what this means is you make the LV as big as you would practically ever want it to be, without having to second guess and go "well if I give all that space over to Windows, now I can't ever use it for anything else without it being a hassle of fs resizing and repartitioning".
Also fstrim commands on NTFS will cause previously deallocated space (file deletions) in the LV to be returned to the VG for other use. It's actually more efficient doing this than fs resize.
I find NTFS on either qcow2 or raw disk on top of a file system means a bigger performance impact than just handing the VM its own virtual block device in the form of an LVM LV. It is easier to move file backed VM's around, like if you have to do a backup-restore. But so far I just backup the user data onto my NAS or cloud, and expect if I have a hardware failure I'm rebuilding the VM from scratch.
Apple still provides the closest thing, at least on Mac. (iOS is another story.) Their telemetry is more minimal than Microsoft's, and it's possible to disable it in a way that hasn't changed much in some time. There's not much evidence Apple cares if you do so. I also trust Apple's security far more than Microsoft's.
For a software developer, "core parts" of the OS are way more advanced and have much more to offer than Linux. If you don't believe me, start browsing here: https://msdn.microsoft.com/library/windows/desktop/bg126469....
Every functionality for which you would use a (one of many) 3rd party libraries on Linux, is included in the core OS on Windows.
Moreover, it's being bloated without choice because most people just use the included version so alternatives don't get to thrive.
First, they're not "replacing" anything. Printing, image acquisition, font rendering, advanced tracing (ETW), authentication and directory (Kerberos), remote access, internationalization, etc. are core OS services. Second, I recently installed Win10 on a machine intended for embedded use. All this "bloat" took ~10GB of disk space, compared to the most plain, cheapest OVH installation which used 2.5GB of disk space and doesn't deliver nearly 1/4 of the features that Windows does.
So which "bloat" are we talking about?
> Moreover, it's being bloated without choice because most people just use the included version so alternatives don't get to thrive.
If the OS-provided version is well thought-out [1] (APIs since Vista seem to be), why would I want an "alternative" that, even if it provides exactly the same functionality, isn't integrated with the rest of the system? (Thankfully, systemd is attacking the integration aspect.) Linux is full of "almost does the job" alternatives, as exemplified in [2]. Thank you, but I'll choose the OS-provided facility, not the least because it vastly simplifies deployment.
[1] EDIT: "Well though-out" is not the same as "easy to use". My impression is that C-level APIs are designed for performance and flexibility first, ease of use comes second.
[2] https://github.com/dotnet/coreclr/blob/master/Documentation/...
So is Windows. For example, you mentioned Kerberos. Only the Windows implementation is so limited, that you can authenticate against one realm only. What if you need tickets from more realms? In Windows, tough luck.
And no, you cannot replace the Windows Kerberos implementation with another security provider.
ha. They did that even for enterprise. But in truth they did that following Apple's footsteps. There are several projects documenting all that new versions of osx phone home data leaks. It's a ton of data and every single start up is just fine giving macbooks like it's candy for the employees.
MS is making it quite hard to just cleanly remove the crap / adware / telemetry they build in.
If you have a script that works well would you please mind sharing it with the rest of us.
The only place I have Windows 10 is on my Intel Compute keys for the media center running Kodi. One of these days I will get around to trying to get Linux to run on those devices.
Yes, you need a different script for 7 than 10
>some of the commands in the 1st PS script I found do not work anymore
use an updated script
>here are reports of some the "features" coming back after updates
That was once, it has been patched
>OneDrive is still in your face on most systems
Yes, my script (and most clones of it) remove it
>MS is making it quite hard to just cleanly remove the crap / adware / telemetry they build in
No, it's quite easy, I run one script once at install. That's the point.
>If you have a script that works well would you please mind sharing it with the rest of us.
Tron is probably the most comprehensive, personally I just use a modified version of Debloat: https://github.com/W4RH4WK/Debloat-Windows-10
Windows is pretty much the only OS left that doesn't support encryption by default.
From an end-user perspective it seems to behave very transparent as well. In what way does it come up short?
[1] https://technet.microsoft.com/en-us/library/hh831627(v=ws.11...
[2]https://helgeklein.com/blog/2015/01/how-to-enable-bitlocker-...
By forcing an escrow key linked to Microsoft and whomever owns the TPM on your computer.
By definition, backdoor keys and hidden users who can access encrypted content is just absolutely, horribly wrong. And there's no way to turn it off... Well, I'm sure someone will say there's 10 regkeys to change that might fix it on a specific version.
Still does nothing regarding the "trust" with the TPM.
That's why the whole excercise is meaningless if you leave the keys on the device, and why you should put them on external hardware TPMs or key vaults. Even a YubiKey is better.
Now you just need a system that supports reading keys from such a device during boot.
The TPM is a PKI device, nothing more. It cannot take over your computer.
Their encryption by definition, is already backdoored to MS. Game over.
And that's nothing about the stupidity of the TPM itself.
This statement is misleading. When setting up bitlocker, you have the option of saving your recovery key to onedrive. It's not mandatory or even the default choice.