Microsoft launches Windows 10 on ARM
anandtech.com
anandtech.com
> The firmware setup shall indicate if Secure Boot is turned on, and if it is operated in Standard or Custom Mode. The firmware setup must provide an option to return from Custom to Standard Mode which restores the factory defaults. On an ARM system, it is forbidden to enable Custom Mode. Only Standard Mode may be enabled.
[0]: https://docs.microsoft.com/en-us/windows-hardware/design/com...
The issue here is that Windows at first was asking not to provide a way to disable it back on x86, we got a compromise (we can disable it, and big distros could get signed).
Now Microsoft is trying the same over ARM, so the fight starts again. Microsoft holds over ARM is mostly nothing though they're newcomers here and there are far manufacturers, so I'm sure they will end up losing their bet again.
Running a closed-source bootloader on a platform with firmware enforcement of signed bootloaders is not good. But the problem is not the signature requirement, the problem is the closed-source bootloader. The signature requirement is only a problem in the case where (as on Windows-logo machines running ARM) it requires you to run a closed-source bootloader, or even an open-source one that you do not have the ability to make changes to. If you want to ensure your computing freedom, the best thing to do is to have your firmware ensure that you and you alone, or someone you trust and them alone (e.g. a vendor of a free OS that you think is reputable), can boot code on your computer.
But in the windows kernel rooting exploit were really everywhere before that started being deployed.
We can blame "everyone runs root all the time" and "disabling uac is a common tip on all windows site because users are used to be super administrator", and they all come back to Windows security model and default being complete shit until Windows 8 ((7 was still super admin as default user right?)), but I certainly won't blame Microsoft for finally cleaning that mess.
Go back less than a decade back and most windows system of everyday users would have some kind of crap running as super root, that was terrible.
Apple and Google, and perhaps the telcos those are the companies that need convincing.
It's not really surprising that it gets some consideration.
From the brands people buy from in Europe, only Sony allows it officially, by providing tools on their dev site.
Huawei, Xiaomi and HTC allow for unlocking via their webpages.
So I would say, that the biggest vendors are covered.
Having UEFI/ARM devices would be a huge game changer in the Linux world right now.
Yeah. Unfortunately Google (ChromeBooks) won the space, with virtually the same tactic, with the slight added advantage that they give you a hardware "break your warranty to unweld this hood" switch on most of the devices.
I miss the hell out of being able to be in control of the software on all my computers...
If so, sorry MS - this is a great step, but no sale yet.
Also, if they're signing any Linux distro's shim loader, shim allows a physically present user to enroll their own key or disable secure boot. See method 3 at https://wiki.ubuntu.com/UEFI/SecureBoot/DKMS .
(I don't actually know if they are signing any Linux shim for ARM - https://wiki.ubuntu.com/UEFI/SecureBoot/Testing#UEFI.2FSecur... implies no. Which means you can't use any version of Linux on it, unless they change their policy.)
The rest involve changing EFI variables, yes, but my impression is that "Custom Mode" refers to a UI in the BIOS which permits you to change the variables, and those variables are always writable by code running in boot services. The requirements say, "On non-ARM systems, the platform MUST implement the ability for a physically present user to select between two Secure Boot modes in firmware setup: 'Custom' and 'Standard'." Nothing I'm suggesting involves going to firmware setup.
I've got the full disk encryption working with luks/grub (you do have to unlock the device twice, one for grub to read its stage2 and one in the initrd for the kernel), I just haven't gotten around to trying to re-enable secure boot.
Otherwise, why have the antitrust laws at all? The dominant market players provide useful services, why should we care about the minor players? (Not only in operating systems, but in general).
The solution is to attach a SPI programmer (eg a RasPi) and flush the UEFI variable store. UEFI will reset to factory defaults, incl Secure Boot.
The complicated part of that is opening the device.
I don't see why it's not actual security.
And fair's fair, Microsoft was the one that pushed UEFI so hard.
> Windows 10 for desktop editions (Home, Pro, Enterprise, and Education) x64
> Windows 10 for desktop editions (Home, Pro, Enterprise, and Education) x86
> Windows 10 Mobile ARM
> Windows 10 Mobile x86
> Windows Server 2016 x64
It's not clear to me that this document has been updated to reflect this release. Windows 10 Mobile is the successor to Windows Phone 8.1, while the article suggests that this product might better described as "Windows 10 for desktop editions ARM".
From The Verge: "HP and Asus' devices will include Windows 10 S, designed to only run apps from the Windows Store, but users will be able to upgrade to Windows 10 Pro free of charge (for now) to get access to the full desktop apps." https://www.theverge.com/2017/12/5/16737288/microsoft-window...
What's worse than a computer with preinstalled spyware? A computer with preinstalled spyware you can't remove.
When the Lenovo/Superfish thing happened, I commented at the time that it was at least something you could remove by reformatting and installing your choice of OS. Ideally we'd all buy computers with our own choice of software already, but if forced to choose, I'd rather buy one with preinstalled spyware I know I can remove, than one which claims to not have such software and be "more secure".
https://en.m.wikipedia.org/wiki/United_States_v._Microsoft_C....
> Microsoft's obligations under the settlement, as originally drafted, expired on November 12, 2007. However, Microsoft later "agreed to consent to a two-year extension of part of the Final Judgments" dealing with communications protocol licensing.
Why don't people take Apple to task for doing the same thing? You can't take an iPad and install Linux on it, or Windows for ARM. You're locked into running iOS. Apple doesn't even allow downgrading iOS.
Same with Android devices that come with a locked bootloader. You can't install anything other OS version/flavour than what the manufacturer dictates.
Yes, it's unfortunate that Microsoft has this policy, but why is it that people only complain loudly about locked bootloaders when it comes to Microsoft products?
Apply the same standard to Apple and Android products with locked bootloaders. Microsoft isn't the first one to do this, and they won't ship nearly as many devices as other manufacturers who lock down the boot process.
The big _practical_'distinction' nowadays between a 'proper computer' and a 'tablet/phone/etc' is between being open for modification, creation and alteration by the user, or to be a walled garden where only the manufacturer chooses what can be done and installed.
The Ipad Pro may be powerful as a computer, but we think about it as a tablet because it uses IOS and its walled garden.
The OP is complaining that MS is trying to push its new product into the computer space even tough it's locked down via Windows 10S. It's not true that nobody 'takes on Apple about this' - it's simply that Apple does NOT do that on its COMPUTERS (i.e. the Mac line).
For most of it's life Microsoft has never put such restrictions on their Windows OS.
But I guess they have now realised, when it comes to making money, that Apple model is a much better way to go.
I appreciate things are different now in 2017 with x86 emulation (or dynamic translation) and the ability for most Win32 programs to be repackaged as *.appx - but Microsoft misses the implication to consumers again: users expect the freedom to install and download software from wherever - just like their x86 desktop machines. No-one is asking for an iOS style App Store for Windows and it's starkly visible by how poorly the Windows App Store is still doing.
Cynically, I suspect everyone at MSFT is well-aware of this and they fully expect Windows 10-for-ARM to sink for these exact reasons, they're just doing this as a repeat of their protest moves to remind Intel not to take their x86 monopoly for granted, and the addition of x86 support is a particularly bloody (but ultimately harmless) fist to the nose.
I'll point out that there is a very obvious use-case for Windows-on-ARM: low-power rackmountable/high-density server hardware for applications like web-servers and IO (not CPU)-bound database servers. No need for a 300W Intel Xeon box, or even a 150W Intel Core i7 - a 20W ARM chip will do. If Microsoft announced a no-shit, just-like-x86 SKU of Windows Server with no artificial restrictions with the same 10 year support period then I guarantee that Dell and SuperMicro would jump at building and shipping ARM servers - but this hasn't happened, instead we got a ridiculously impractical "Windows IOT" SKU which feels more like a toy than the basis for business critical infrastructure.
Server applications are much easier to port to ARM than desktop applications, given their lack of dependence on hardware associated with x86, like 3D graphics acceleration - or just users' expectation that a single executable binary should work everywhere. Servers are operated by businesses with professional sysadmins who know how to rebuild open-source applications for their machines or at least know the difference between downloading a program lablled "Thumb-2" vs "x64". Furthermore probably most server applications run on Java or .NET and can be trivially ported over to ARM.
The fact we haven't seen a true Windows Server ARM means that we can immediately dismiss consumer-level releases of desktop Windows for ARM for now.
...but why is this better than linux-on-arm? Windows server hasn't been generally very successful.
This is the norm for ARM, as much as we don’t like it and it will be the same when Apple eventually ships an arm laptop.
Looks like we need another golden key:
> https://web.archive.org/web/20170306015239/https://rol.im/se...
Yeah, even if they could be sued, they could settle for a couple years damages max, or quite possibly win, since they're doing DBT (no different from QEMU or loads of other x86 + SSE2 emulators).
[1] https://arstechnica.com/gadgets/2017/12/hp-asus-announce-fir...
I assume any kernel drivers will need to be compiled for ARM64 though. This might not help corporate adoption--VPN client, 3rd party anti-virus/full disk encryption, etc.
Also one thing that is x86-64 only is WSL, the Windows Subsystem for Linux.
Intel seemed to indicate at the time that it was really interested in any licensing around the x86 ISA.
Obviously, they wouldn't say that - the way to market that is to release 'Windows Gamers edition', which costs way more and 'unlocks' the power in the latest CPU's. When in fact, non 'game edition' windows versions simply leave some cores disabled or sleep some of the time when they detect a 'too fast' CPU and a fullscreen game running...
Then I remember people pay tons of cash for their rigs that are obsolete within two years anyway.
Seems like a lucrative practice for Microsoft and one they should embrace, extend and extinguish.
Expensive gaming rigs - a bit less so than PC, but for equivalent hardware, about $400 cheaper at introduction, about equal once 1-2 years pass.
Obsolete in 2 years - check
Expensive software - much more so for consoles.
So right now the situation is that if you go for PC gaming instead of console, you'll have about the same expense, but 100 games for PC (and a powerful general purpose computer), and maybe 5-10 on console.
I wish I could. The games I like aren't released anywhere else.
> Then I remember people pay tons of cash for their rigs that are obsolete within two years anyway.
This is false. A moderate gaming PC can last longer than a console. I used my previous rig for 4 years and now my wife is using it perfectly fine. It still has better visual fidelity than a console.
It actually works quite well.
http://www.techradar.com/news/a-closer-look-at-windows-10-s-...
In fact weren’t the IBM compatible PCs in the 80s doing exactly that?
Still sounds like emulation to me. It's a pretty fine line.
That said, people may not care. ARM can be very fast. My iPad is faster than many low end laptops.
So you get in the situation where a low cost laptop with ARM may be as fast or faster going through emulation than a low end Intel chip from 4-6 years ago while providing WAY more battery life.
People may be willing to make that trade.
I’m guessing it’s not 20% speed on most tasks. Probably 80%+, depending on the age and power of the Intel chip.
However, most people run a small selection of programs most of the time (web browser, word, excel, outlook), which will likely have an ARM native version sooner than later, and the long tail of programs they must have are often not compute intensive, and spend 85% of their time in the OS doing graphics/io which are native. So overall, even if the CPU emulation is 20% speed, the overall feel is likely going to be 80% or better for most people.
Gamers shouldn't hold their breath though.
I still can't believe they did that. Discontinuing software is one thing--you can find replacements. But discontinuing Surface RT tablets OS right after selling them is insulting and I will not be recommending them to my clients until Microsoft proves it will actually provide a long-term platform.
And their health watch.
And...
The really interesting bit however is whether or not ARM notebook computers can become a 'thing' for real. There have been a couple of runs at it by people without the resources to do something competitive with the thin and light laptops of today, doing it "for real" has always seemed a bit out of reach.
It becomes more and more clear to me that something like a Chromebook type OS and a walled garden app store is a really attractive proposition for people who don't do development on their machines.
But the interesting thing for me are the two approaches to window dynamics. The Surface Pro is difficult to operate with a finger, ok with the stylus.
Surface is 2.5x heavier, it's the 'I must remember to, and want to, take a full computer with'.
I think iPad Pro, with iOS 11 has shown what tablet is really capable of. And we are only just getting started.
Hence why I wish Apple will just leave the Mac as a PC. A PC with macOS. Stop dumping it into Appliance, give more choice and better flexiblity, heck even iPhone has more choices and model then the Mac.
First time Microsoft seems to be more focused than Apple (which works on semi-innovations like touchbars).
Remember when you had to reinstall windows XP every few months? Yeah, i haven't reinstalled my windows since windows 8 came out. I've done upgrade to 8.1, 10, 10 CU without re-installation or "refresh".
Before that, I did it once a year going back to NT3.51
XPs big problem was IE and malware infections, other than that it was as reliable as any current version of Windows today. Once you have to manage 3500 PCs and you see the same stupid issues coming up over and over, you realize it's not really any better. Computer stores may not be as busy cleaning malware from desktops and laptops, but my team is every bit as busy cleaning up bad updates, fixing BSODs and trying to find documentation that doesn't exist for whatever feature was released last week.
I'll have to disagree:
https://spectrum.ieee.org/tech-history/dawn-of-electronics/t...
Matching the perfomance of 91W-class i7's found in iMacs would take a lot of ARM. 45W-class i7's in Macbook Pro's are quite powerful, too.
Why the specific ISA desire?
(Hate UEFI all you want, but standardizing on something is much better than the Android world where every SoC requires a custom bootloader and if the manufacturer doesn't support the kernel you want to run, tough. Having a standardized platform to run on means you can have a Linux distribution that supports running on any device that supports the standard.)
But I do use it as a production machine.
Traditionally, one of the ways people got into Linux was inheriting an old box and sticking Linux on it. You won't be able to do this anymore.
And as Intel will become more and more niche, it will get more expensive.
The mail.app vs outlook is a great example of useful and useless UI. Both app does the same.
- If you do mostly web stuff, Linux fits all the bills.
- If you NEED compatibility (Office/Photoshop/whatever), you can often still run many programs with "Wine" in Linux.
I really recommend trying it by downloading a "to go"/"live" version to a USB drive. Ubuntu (the most popular user flavor of Linux) is really user friendly out-of-the-box. Being on a USB drive it'll be a little slower to load, but yeah. I use it every day on a Chromebook converted to Linux.
Monetization. Linux distributions can be produced at very low cost and don't need to make a profit, but a version of Windows has to make money to be worthwhile for Microsoft, so features that are effectively adverts or tie-ins for other products and services are inevitable.
But the mail/outlook comparison doesn't work: outlook is an old and enormous enterprise piece of calendar/mail thingy. Not a mail application. Even though many use it for just email, that's not what it is - and they can't change that.
This isn't an OS difference between Mac and windows. Windows has a simple/clean mail app, just like Mail.app. http://uk.pcmag.com/windows-10-preview-release-date-news-fea...
Also, seems Outlook will get a makeover to be more like Mail. https://www.theverge.com/2017/10/16/16481190/microsoft-outlo...
On Mac, I rediscovered Mail.app, and on Windows the Mail application. Both look very different, but fullfil the same function: You can manage multiple accounts from one place, they support conversations and archiving flawlessly, the interface is clean and efficient. Thanks to those two, I use desktop clients instead of webmail again.
Unfortunately, it seems like Microsoft has given up on Windows Phone already.
[1] http://www.zdnet.com/article/microsofts-x86-on-arm64-emulati...
Beyond that, rumor has it that Microsoft hopes selling tablets/laptops with ARM will open the Windows ARM space enough in the meantime while the Windows team is finishing the next version of key Windows shell components (nicknamed the "Composable Shell" or CShell), which would be make the Continuum experience for say Phones stronger because instead of switching entirely different shell applications (start menu, taskbar, et al) between form factors, the same applications responsively adapt themselves.
https://www.theverge.com/2016/12/7/13866936/microsoft-window...
Basically a Windows 10 phone-sized full computer that has docking features that make it conceivably the singular computing device in your life that covers all mobile and desktop contexts.
[1] https://www.windowscentral.com/microsoft-bring-back-courier-...
I would love something as light as the Galaxy Tab S2 (Less then 400g!!) that I can use with Linux and a type cover.
I would be able to work everywhere I go. Because carrying around 400g with me all the time would be worth it.
You will be forbidden by DRM from running linux on it. Their policy is clear on only permitting Microsoft signed OS to boot and forbidding the device manufacturer from permitting you to run an OS not crytographically blessed by Microsoft.
Should someone generously share some articles, I’d really appreciate that help.
So QCOM is being sued right and left (Apple, Intel, and governments all over the world)?
For what it's worth, if you do competitive business like Qualcomm does, there will most likely be at least one pending lawsuit against you at any given time.
I guess it could be up to the device manufacturers.
I wouldn't expect these very first devices target that market, though, possibly because Qualcomm wants to be associated with more premium devices, but I think we'll see these chips in lower-end cost-competitive devices, too.
Nothing about Windows RT was done in a way that indicated that they were serious about pushing it. How could you possibly sell people on a version of Windows that does virtually nothing that people would want to buy Windows instead of Android or iOS for?
Given Qualcomm's just-announced partnership with AMD [1], Qualcomm is clearly pursuing multiple strategies to compete with Intel, but they can leverage AMD to cover their weaknesses, instead of trying to outpace Apple's A-series in places where the market seems fine with the current Snapdragons.
Possibly. Although I don't doubt Apple may have superior expertise in designing ARM chips (which sounds strange when comparing to the #1 ARM chip maker), I think one of the main reasons Qualcomm hasn't been able to match Apple is that Qualcomm has to optimize its chip for a variety of OEM needs.
Apple on the other hand, could even push the TDP by 20% on its chip, if it know that it can make up for that loss of efficiency with more optimized software that's developed specifically for that chip.
The AMD partnership is very interesting. I hope they double down on that.
Fun fact: Qualcomm wanted to buy AMD in 2015, but because of some terrible management and engineering choices with the Snapdragon 810, which led to a sales slump that year, the board was so furious that i wanted to sell Qualcomm's chip business! (and sell just modems).
Of course, that would have been a terrible idea, business-wise, which is why if Broadcom buys Qualcomm I hope it does get rid of that board and Qualcomm's CEO from day one.
Another fun fact: Qualcomm's Adreno GPU is AMD's old Mobile Radeon GPU division, and Adreno is an anagram of Radeon.
I've been hoping someone like Qualcomm or Samsung buys AMD. Perhaps it may actually do that eventually, with or without Broadcom's help. Then we can see some real competition against Intel, and AMD alone simply lacks the funds to compete head-on with Intel in many areas.
Also, now I'm starting to wonder if Broadcom knew about this deal and it's why it wanted to buy Qualcomm now.
This just makes no sense at all. So you are saying some OEM's want slow chips? No, of course not. Or are you saying that Samsung S8 has different needs to LG V30 or to the Google Pixel? No, of course not. There needs are all the same.
a11: https://browser.geekbench.com/v4/cpu/5286336
i7 (rmbp): https://browser.geekbench.com/v4/cpu/5285899
4.1k vs. 4.8k
The A11 is way too overpowered for a phone or tablet. Apple is clearly in the awkward phase where they've almost gotten the right CPU to put in their laptops. The A12 will be a no-brainer. Same performance as i7, way better battery life, way cheaper to produce.
Raw performance is nowhere near intel chips.
https://www.pcworld.com/article/3006268/tablets/tested-why-t...
Apple's A11 (single thread) 4217 (multi) 10164 https://browser.geekbench.com/ios-benchmarks
Intel i7 8700k (single thread) 6089 (multi) 26654 https://browser.geekbench.com/processor-benchmarks
The A11 is running at 2.4Ghz. The i7 in the single-thread test at 3.1Ghz (actually up to 4.1Ghz). Cycle for cycle the A11 is faster than the fattest Intel chip.
Which is insane. I am no Apple booster, but this is quite an incredible switch up. With a fatter TDP budget (the A11 has a TDP of something like 5W, the i7-7920HQ a TDP of 45W) they could not only increase the clock ceiling, they could start copy-pasting the big core.
A few years back people were talking about Apple starting to move their chip designs to their laptops and desktops. It sounded insane. Now it's actually entirely possible if they can get their software stacks and targeting all working.
EDIT: Found an image. More a simple understatement than a severe one.
https://wccftech.com/apple-a10-fusion-cores-bigger-than-comp...
Qualcomm simply fell behind. While Apple went for powerful, enormous cores in small numbers, Qualcomm and friends bet on simpler, smaller cores. Apple has started copy/pasting their fantastic cores, yielding the enormous transistor counts.
I admit to being a skeptic when Apple went off to do their own thing, sure that a whole industry (and options like the Tegra) would make them eat their hat. Apple executed and are in a remarkable position now.
NT was available on Intel, Alpha, PowerPC, and MIPS chips. I'm surprised it was that hard to add ARM. Or is this something different?
Windows Phone 8 ran on the Windows 8 kernel, and Windows 10 Mobile ran on the Win10 kernel.
It seems like the hard part here was doing the seamless emulation of x86 apps. Writing a production quality general purpose emulator is hard.
I wonder how UWP apps work technically on ARM. I heard apps will be compiled on the fly to run on ARM. Managed code (C#) just runs on the CLI or can be AOT compiled. But C++ is also a first-class citizen. Will you ship x86 code that is emulated/recompiled, or will you ship both x86 and ARM, or some kind of intermediate representation (like I think you do on iOS)?
Also, I wonder the internals of that x86 emulation, if a linux program can leverage it?
It could probably be adapted for that, but since either Microsoft or Qualcomm is in control of it right now, and it generates a competitive advantage, I doubt either would be enthusiastic to publish it in such a form.
For what it's worth, if about 1/3 native performance (not sure, but I figure the QCOM/MS DBT gets maybe 1/2-3/4 native, from the way it seems to work with applications in the demos) is acceptable, QEMU can do more or less the same thing already on Linux: running x86 userspace programs on AArch64 (also some other architectures). In fact, you can add a binary format handler to your system to have it transparently load x86 binaries in QEMU.
Of course, this means having to set up a separate PATH and LD_LIBRARY_PATH, and a few other things.
So I'll hold my breathe before recommending ANY of my clients use this.
1. How can Intel sue MS for emulator, but linux(qemu) can get way with it?
2. Why MS tries to push the emulator, when they can just port their programs (already ported to Win RT I think) and provide developers some tools to port their apps?
2. No one ported apps to Windows RT besides Microsoft.