Installing Windows 11 on Legacy BIOS Without Secure Boot
allthings.how
allthings.how
https://linustechtips.com/topic/1351028-microsoft-makes-thin...
A security director now says that a blog post "clarifying the floor" is coming. But frankly, if this turns out to be a miscommunication, if you read those tweets Microsoft would have to be unbelievably incompetent in their use of words.
My older box, an i7 4790k, is still quite the performer. It, however, has no secure boot capabilities. No TPM socket on the motherboard, even.
This is what I run. It doesn't have firmware TPM according to Intel (https://ark.intel.com/content/www/us/en/ark/products/80807/i...), but the regular version does.
TPM >=1.2 is a hard requirement for Win11, and if your mobo doesn't have a socket for it, you're out in the cold.
So much for future-proofing.
If it's boot attestation someone will do it. This is probably to force enterprise vendors to move to devices that better support enterprise management, but yes, it drags us kicking and screaming along with it, at nontrivial personal expense.
https://twitter.com/dwizzzleMSFT/status/1408539533465985024
"Seems like you are assuming there is a specific security feature that defines 8th gen as the CPU floor. The floor is set for a range of quality, performance, support, and reliability reasons to ensure a great experience."
I have an i7-3930k on some Asus MB and it has Secure Boot but no TPM. There's a header for it, but it's empty.
My understanding is that the SB keys are known and verified by the BIOS, not by the TPM.
The TPM is a mechanism to verify that the BIOS (among other things) hasn't changed from a known state. If it hasn't, the TPM will then release some key, for example to automatically decrypt the root partition at boot. I've also seen it used as a store for SSH keys.
This is how the default setup of BitLocker works. On my machine, I have to switch BitLocker to password mode, or type in the key at each boot.
The early 00s were a fun time to be a Linux enthusiast.
I'm hopeful this spurs another surge of interest in better operating systems.
Only if you enjoyed configuring X11.
Only you enjoyed lifting weights."
For what it's worth, Microsoft research actively contribute to the research community regarding operating systems.
Is there a 3rd way out there that's better?
Oi! Mac oleee ole ole ole!
which is what?
But I was also smart about what distro I put on their systems. Endless OS or Solus, for example, are not prone to breakage on upgrade.
You've been using Linux for a long-time. You should know that Arch and Ubuntu are not the only two choices in this space.
You should also know that when manufacturers weren't threatened by Microsoft to do otherwise, there was a thriving ecosystem of SFF laptops, netbooks, that shipped delightful Linux distros that just worked. Moblin and Jolicloud were fantastic explorations of UI and OS design that might have been.
And here is our main Linux problem: its fragmentation, which is the natural byproduct of its freedom; everyone and his cat can develop or modify things, which translates in different distributions, which of course is a nightmare if you are a software producer with developers paid to port your software to Linux, and that's why a lot of commercial developers either choose one or max two distributions to support or ignore it at all.
One thing the Linux Foundation could do about that is mandating a minimum set of requirements that all Linux commercial software could count on, and all distributions should meet if they want a badge that guarantees the software will be 100% compatible out of the box, or that the host system can be adapted with extremely low effort. I'm not sure how much having Microsoft as Platinum Member would help with this, though.
What MS is doing here is forcing OEMs to package TPM 2.0, which will be a massive win for security.
The intel generation is seemingly a bit arbitrary, we'll see how that plays out. But again, it's not like people are being left behind - they have 4+ years of support left.
That's 7 years only, a lot of perfectly usable computers will be get rid of for no reason other than mild security benefit. Seems like they want to go in mobile direction forcing people to buy new hardware every 4 years.
You don't turn an Amiga 500 into a 600 by upgrading the OS.
Kickstart is in ROM you need 1.3 to play the old Amiga games, and 3.1 for the AmigaOS 3.X stuff.
Then again, I've stayed away from Windows 10 too.
Full-time Linux use is looking more and more pleasing...
This is a very significant win and critical to 'zero trust', which is now something the government is telling people to embrace.
The whole thing with security is silly. They said it about UEFI - and yet I run Linux on UEFI systems all the time. I also have systems with TPMs that run Linux. Works fine.
edit: People are downvoting you now, though I think your question is very reasonable and worth answering. Such is HN, though.
Not just any UEFI, UEFI with SecureBoot enabled specifically. On SecureBoot-enabled systems, you're booting a Microsoft-signed executable that chainloads Grub, which then loads Linux. This has given Microsoft a power they should not have: the power to refuse to sign future versions of that first executable.
I think the whole "MS-signed Grub" is a way by Ubuntu (and possibly others) to facilitate Linux installation by "non pros". And it's not that bad, I think.
I, personally, use Arch Linux and the installer isn't signed with anything. They have a "do your own signing" policy. I had to disable SecureBoot to install it, because I couldn't be bothered to create a new ISO, but then I registered my own keys to the UEFI and boot directly my own signed kernel [0], without using GRUB at all.
I did all this on multiple generation HP "enterprise" laptops and desktops and it worked without any issue. And those systems don't come with any sort of Linux support from HP.
---
[0] For the curious, this is EFISTUB combined with sbsign, that bundles the kernel image, initrd and CPU microcode in a single EFI binary and signs it. This is then booted directly by the UEFI, and you can even register multiple binaries and have them show up in the UEFI boot selection menu.
Pointing out the power that MS have is not FUD. If I suggested that there is a chance they would abuse it, that might be, but I didn't do that.
> or limited to specific systems with broken UEFI implementations.
A very quick Google search suggests there are quite a few of those, from mainstream vendors such as Dell and Lenovo.
> I, personally, use Arch Linux and the installer isn't signed with anything.
True, I oversimplified. The major distros use MS-signed shims, the rest mostly don't.
Also Ventoy needs to install user-defined keys into UEFI to make it work with Secure Boot.
So my assumption is that - at least on Thinkpads - you can add your own user-defined keys; the only Caudine Fork where a Microsoft blessed loader might be involved is the one used by the distro installer.
Or am I missing something
There is no reason to believe that this wasn't implemented thus far because of the high ethical standards Microsoft folks have historically adhered to and while we are to believe Microsoft has turned over a new leaf much of the current leadership was involved at the executive level in old bad Microsoft.
I thought we were trying to get away from identifiable fingerprints? This seems like the most unique one you could get.
I'm trying to learn about it, but all google wants to throw up these days is news articles on win11's requirement if it, marketing none-speak about "securing the platform" (which does to a layman, read similar to the other comments cry of lock-in), or dense whitepapers on threat models and cryptographic math.
Second, you're close but just a bit off. While the TPM has a secret internally, it wouldn't expose that - it would be used to generate other secrets, or to sign things, basically it's sort of like putting a crypto library into your device so that you can perform cryptographic operations without knowing the secrets involved. But yes, there's a seed that gets soldered into the device itself.
I use TPMs to ensure that no one can access our AWS environments from devices other than those we own, for example. I'm not really an expert on this sort of thing, though I do work in security professionally - hopefully I'm not butchering this. There are quite a few experts on the matter who comment on HN though, maybe one of them can speak more authoritatively on this.
edit: Actually, I misread maybe - you aren't off. The session cookie is tied to the TPM - either existing within it, or requiring re-validation via the TPM.
Separately from that, using the TPM to lock the session cookie to the device sounds useful.
Again, maybe someone more knowledgeable can explain more - I'm a consumer of TPMs, and I understand the concept, but I'm no expert.
Session cookies (until this) only identify a session, not a person or a piece of hardware.
There are plenty of people who'd prefer sessions to be as loosely tied to identity as possible / as necessary.
Each identity you want to protect has its own key (so its’s not necessarily de-anonymizing) with physical access - pin, biometric verification - required for use.
It’s potentially very useful, although I 100% expect it to be backdoored by every geopolitical block.
This is a very significant win and critical to 'zero trust', which is now something the government is telling people to embrace.
If the government is really saying the equivalent of "trust us, but not the people you usually trust", that should a huge warning sign. The analogies to 1984 are disturbingly close.
Why is this a problem?
> If the government is really saying the equivalent of "trust us, but not the people you usually trust",
I don't understand what you're talking about here. There is no additional trust necessary.
No problem the users install their own browser.
Now we ask Microsoft to limit software that is signed by it effectively granted permission to run some software but not others. The alternatively browser is right out.
The user installs his own OS now we ask Dell to only allow it's computers to boot software that implements the same restrictions as Microsoft has agreed to.
So the user gets his own computer. Now we simply ask your bank or better yet your ISP not to connect to "insecure" devices that don't follow the standards described.
Now you need a substantial unlatched vulnerability to be able to resolve foobar.com
At it's root to make a users own device effectively restrict what they are allowed to do you need something difficult to defeat that you control and they do not.
At one point a us senator wanted this used to allow music labels to remotely destroy users computers if they believed that you were pirating music and every other restriction described has been implemented or discussed using on user devices belonging to users and most implemented.
I mean sure, if Microsoft decided that it wanted to do all of the things you said, and could convince all of the OEMs to help, and a bunch of services and ISPs or whatever, yes, that would suck. It's a totally fabricated hypothetical that would never play out, but sure.
You have to trust every manufacturer of every other chip the same way also, and we have in fact found incredible breaches of that trust already many times over, and so it's too late to suggest it's a crazy thing to worry about.
The only saving grace with other chips is thst they are generic and at least you usually have your choice of some range of suppliers.
Will I be able to buy a laptop with an intentionally defective or fake tpm if I want, which will allow me to use modern software without trusting anyone?
Probably not. Probably plenty of Chinese manufacturers would be willing to produce them, like all the HDCP defeating hdmi switches, but probably software vendors will have some way to detect and invalidate them.
Why? What would a backdoor in the TPM do?
I know some Linux distros already supporting enabled Secure Boot
edit: sorry I reread your comment that you already mentioned Linux can run with TPM
It's not that secure boot nor the TPM in any fashion keeps Linux from inherently working. It's that it enables the OEM to decide what software is allowed to boot on the computer and enforce this.
Microsoft typically gives OEMs a substantial break and the OEMs in turn sell most SKUs to 99% windows users and make only a small margin on those devices. A small discount on the cost of windows could make devices disproportionately more profitable and MS might be apt to see a percentage in offering such a discount to help lock out the competition.
They have in fact over the years engaged in far more unethical behavior including investing tens of millions in a "partner's" fraudulent lawsuit/pump and dump scheme against various Linux vendors bankrolling an entire list of felonies.
A great many people who don't know as much about security or have a rational approach to threat modelling, alas.
Intel stopped taking orders for such chips in April 2020
https://www.kitguru.net/components/cpu/dominic-moass/intel-d...
presumably you could expect devices to be in use until around 2027 with some sticking around until 2033
You could have bought a new laptop just 3 or even 2 years ago that will now be effectively obsolete in 4 years.
It's basically the Chromebook model, if you think of it -- and kind of radical of Microsoft to go that route when historically they've never really had stringent hardware requirements beyond the ones for OEMs to put those Windows Ready stickers on.
OK but the 2025 EOL wasn't a secret, it was announced alongside the Windows 10 release a decade ahead of time, as well as the extended support date of 2029.
So you had a decade of notice for EOL, and currently you have 4 years of notice that you'll need a TPM 2.0.
Maybe you think that's unreasonable, but I'm not so sure.
This is a link to a PC sold as new in box with a 7th generation intel cpu.
https://www.newegg.com/platinum-microsoft-surface-laptop-jkq...
The average PC is kept for 6 years meaning people would be expecting to use this new computer they just received say tomorrow as late as 2027. A minority of machined will remain in service as long as 12 years
Historically for most of recent history Linux and Windows both continued to run on machines that were previously supported for much longer than 4 years subject to the machines capability to keep up with present software. For example not all hardware released in the XP era had vista drivers but not only did most XP machines work OK with vista if they had sufficient ram to run but whereas there weren't many machines sold with XP after 2006 MS provided updates to XP for another 8 years.
This means that machines sold in 2006 were either in the OK to update to vista camp or in the OK to stick with XP camp until they were rendered permanently insecure after no less than 8 years of service with machine capable of running vista mostly being capable of upgrading to 7 as well for another 6 years of service.
Even when an old machine has been necessarily retired by the shifting winds of software it normally has been due to being incapable hardware or oems not providing the means to keep moving forward.
It is unprecedented in Microsoft or Linux land for such a monkey wrench to put put in the works. It seems likely that they will end up having to move the date back to allow a greater portion of machines sold including as we speak with incompatible hardware to age out.
For today programs and most games it's perfectly fine. War Thunder, Arma 3 and many other AAA runs max quality without issue; recently COD Warzone required to cut back clutter a little and that was it.
Synthetic benchmarks are almost irrelevant, we've been in good enough territory for a decade now.
http://techrights.org/2009/04/23/bill-gates-security-as-a-lo...
http://techrights.org/2009/06/25/security-as-a-lock-in-gates...
"Unfortunately, the attestation model in TCG's current design can equally effectively prevent the software on a computer from being changed deliberately by the computer owner with his or her full knowledge and consent. While the owner is always free to alter software, attestation adds a new risk: doing so may now eliminate the computer's ability to interoperate with other computers."
Alex Jones is associated with fake news and there is plenty of evidence about that; the same can't be said of Techrights, or at least I didn't find any such claims.
Or fail to.
By the time Windows 10 support is EOL (2025), those laptops and CPUs will be 8 years old. Right now, Monterey (successor of Big Sur (aka macOS 11) won't suppport MBP 2013. So when Catalina (aka macOS 10.15 / last macOS 10.x version) is EOL, which should happen next year, then MBP is only supported by Big Sur which is probably lasting one more year compared to Catalina. So in two years, the 8 year old MBP 2013 is no longer supported. While its already only receiving security and reliability fixes since that's what Big Sur and Catalina receive. All in all that's 10 years of support, quite massive (but then again there have been very little progress on the CPU performance between 2014 and 2020). You can still run some other OS on any of this hardware, such as Linux or ChomeOS.
It might not be officially supported but it works just fine. And with an SSD and 8GB of ram it actually runs pretty well.
And actually, MacOS runs on much older hardware with some simple patches. I also have a late-2008 unibody MacBook Pro that runs Catalina and receives latest security updates. Installing it was a tiny bit complicated but again, it works.
Two wrongs don't make a right and I expect better of Microsoft.
In fact why even go this far? Most people have no idea what an OS is. They just buy a "device" and use whatever software platform comes baked into the device and all of them are proprietary.
That's a non issue since most businesses upgrade their fleet every 3 years or so and are also very slow and reluctant when upgrading to newer versions of Windows (my last job switched from Win 7 to 10 only 4 years ago) so by the time they finish waiting out for Microsoft to iron out Windows 11, years down the line, their fleet will have been already replaced at least once.
Have you ever trained a few hundred or more 'non-tech' people (and I mean people who don't know what a file is) on a switch from Windows to something non-proprietary? How did that go for you, if so?
Somebody in China been buying stock of TPM chips en masse, and they are out of stock everywhere now.
With >12 months backlog for new chips, Win 11 will have to wait at least a year.
Ah, the benefits of globalization.
Lmao! I'll cite you whenever someone posts "but muh windowz receives updates for 20 years, why your shitdroid can't do the same?!!?".
Announcement: https://www.microsoft.com/security/blog/2020/11/17/meet-the-...
> The Pluton design removes the potential for that communication channel to be attacked by building security directly into the CPU. Windows PCs using the Pluton architecture will first emulate a TPM that works with the existing TPM specifications and APIs, which will allow customers to immediately benefit from enhanced security for Windows features that rely on TPMs like BitLocker and System Guard. Windows devices with Pluton will use the Pluton security processor to protect credentials, user identities, encryption keys, and personal data. None of this information can be removed from Pluton even if an attacker has installed malware or has complete physical possession of the PC.
Speculation: https://www.reddit.com/r/Windows11/comments/o5r2qz/speculati...
Background on secure boot: https://cacm.acm.org/magazines/2020/3/243026-securing-the-bo...
Uh and how am I supposed to sell my used pc?
I'm actually starting to worry about opensource approaches since the Year of the Linux Desktop (TM) is getting farther and farther.
Today I gave a go at XUbuntu 21.04 without a VM (which is how i have been consuming my linux fix recently) and it was okay, but even basic things like suspend didn't work and simply crashed the X window manager or other non-poweruser-ready shit.
It's getting more and more complicated.. sometimes i wonder if it's NOT and it's just me getting grumpier. But it really seems that consumer devices are getting more bundled and less customizable and tinkerable by the year.
The biggest concern this presents is if your CPU dies and you want to recover your encrypted disk. All of this is the same situation with T2/M1 Macs or iOS devices today.
All for the sake of "consumer safety" when in reality it has to do with control and preventing someone from committing the horrible crime of copying a Netflix show. /s
The line between "attacker with physical possession" and "owner" keeps getting blurrier.
Lots of people keep computers for years now, and it's not that uncommon to see people still holding on 6 or 7 years old machines. Most people don't really need computers that much now that smartphones are ubiquitous, and even an old computer can run a browser or a word processor just fine.
Microsoft still can't realize they are not Apple. People won't just buy a new computer just to run Windows 11. That's not how it works, Microsoft still hasn't really accepted they don't have neither the mindshare nor the appeal for doing moves like this. I thought they had learnt from their mistakes after the Vista/8/Kinect debacle, but I guess they just cannot.
No, it took over only because of the silent forced upgrades that also included some typical malware-like dark patterns. There's plenty of stories here and elsewhere about it. Some examples:
Not sure why Adobe et al don't just show Microsoft the middle finger and move to Linux, with their support everyone wins.
Desktops are pretty good though.
If more good software ran on Linux, it would have a higher marketshare and hardware vendors would also pay more attention to it imo.
https://blogs.windows.com/windows-insider/2021/06/24/prepari...
Or are now rushing to give money to Microsoft and use WSL?
Well, that is how things eventually turn out to be.
So you're saying only enthusiasts have smartphones?
https://docs.microsoft.com/en-us/windows-hardware/drivers/br...
Why should I have to go to some company to let me use my hardware they didn't even make?
What happens if one day my distro starts to anger the gatekeeper, or worse, start to compete with them?
This is all wrong. Stop supporting them.
Yeah but then you can't boot into Windows? Who is actually going to go into the firmware settings to switch settings on and off for every single boot to the other OS?
if you want to sign your own kernels: the shim will also let you do that relatively easily ("machine owner keys")
if you want to own your entire boot process you can replace the platform key and sub-keys with your own, and then trust whoever you want (even adding MS' keys if you wish, so Windows can boot in secure mode)
Those distros also all use systemd. Do you think they'll sign an image that doesn't include it? We're heading down a path where developers need permission to innovate, and the switching cost of running something non-standard becomes too high for even the most technical users.
https://wiki.gentoo.org/wiki/User:Sakaki/Sakaki%27s_EFI_Inst...
We made it work and we'll make it work again.
Case in point: the countless Android devices out there.
One OS company has control over whether they allow competitor's OSs, on hardware that the company doesn't even produce. That should be an absolutely horrifying thing to anyone who believes in software freedom.
You can disable secure boot or add your own keys because Microsoft required all manufacturers to allow it. If it wasn't mandated by Microsoft, some manufacturers would not allow it. And for ARM devices, Microsoft required the opposite (https://softwarefreedom.org/blog/2012/jan/12/microsoft-confi...). So yes, the only reason we can run non-Microsoft operating systems on our computers is because Microsoft "gave permission".
Sorry for replying twice but I'm almost always stuck on noprocrast so I can't usually edit my comments.
I'm sure Microsoft hopes to achieve something similar here at some point: secure boot would give them enough trust to decrypt an install upon boot all the way to the login screen.
Things like tests/validation on new hardware is also costly. Microsoft (used to?) have an absolutely massive fleet of physical hardware to test Windows on
The reason they're doing this is because Microsoft doesn't control OEMs directly. They can't make Dell or whoever put in good hardware unless it's a hard-requirement to run their OS. They obviously want to start leveraging TPM 2.0, probably in order to properly compete with Chromebooks, which all require that tech already.
Chromebooks and GSuite are a meaningful threat to Microsoft - Google has a huge head start in that they've enforced much stricter restrictions from day 1 on Chromebook hardware. Microsoft is just getting aggressive about doing the same. And it's going to take at least 4 years for them to catch up, given that Windows 10 EOLs in 2015 at the earliest.
This fits far more into their business model of 0365, Sentinel, and Azure than it does with their Windows business model.
edit: Expanding on this, TPM technology is critical to Zero Trust Networking, which I'm quite sure Microsoft is going to want to push - especially since Active Directory is getting ripped out of networks practically by government order at this point. If they follow through on this, in 4 years Windows networks could be radically more secure than they are today. This fits in well with where Microsoft is taking its business (cloud, security, organization support).
They actually can. They have Windows Logo program, which specifies conditions that your product has to comply with, if you want to qualify. OEMs like Dell want to qualify, that allows them to put the Windows sticker on the box.
How do you think Microsoft made the OEMs ship UEFI and Secure Boot in the first place?
They control the Windows Logo standards, and have used these to enforce a variety of hardware requirements (including TPM) in the past.
Not to mention the rise of DRM and other user-hostile shit that they are now forcing you to have.
I fucking hate what this industry has become...
Forcing people to buy new hardware while there's a global chip shortage is going to be interesting.
Like it's happening on the Mac, it's getting harder for the average user to screw up since software from "unidentified developers" can't run by default.
I can still run anything I want as a power user and that will not change on macOS and won't change on Windows.
As for secure boot, I don't see how that could be anything else than policy (that can have an impact on a security model and so on associated security measures, granted, but not having secure boot should technically not prevent booting / installation unless it is enforced by an explicit artificial limitation). But they could at least remove legacy boot support, in which case it just won't work without UEFI.
Yeah, you can run Windows 10 on some pretty ancient unsupported hardware too, but when they break support for a driver a couple years in, you end up with a nonworking machine.
But such a setup will be very fragile to automatic updates (which are already difficult enough to turn off completely as it is), and with this whole "update mentality" I wouldn't be surprised if they eventually leave in certain security holes and use those as an additional force to coerce people to take their updates --- along with everything else the users didn't want.
the disk will be encrypted with a key stored in the TPM that will only be supplied to a signed OS, so you can't alter the contents on disk
if you've booted in secure mode you can't interfere with the boot process and the OS won't let you patch it online
if they pull it off correctly there's not much you can do
they can even detect the effects of exploits using remote attestation
if a machine has had its environment compromised it won't be able to get updates/watch youtube/play games/...
(using old software/firmware with known exploits can be similarly blocked, until you upgrade)
In the actual world they don't even enforce disk encryption right now and correct me if I'm wrong, but currently having your BitLocker "recovery code" is enough to decrypt the disk on another machine and changing that would be a massive issue for many data recovery processes.
Unless they plan to do massive changes to the system this is very likely to not be a problem and cracking is likely to still be quite possible.
These are not "massive changes to the system". Probably still a lot of effort, but closer to "MS now owns the ActualAdmin user who is the owner of system files; you get Administrator who can't touch them".
On Linux you can already prepare system like that fairly easily, with Arch wiki describing most of the steps.
Android now has remote attestation required to use several banking apps, presumably with games and video coming down the line soon
the lack of the mandatory TPM is the only thing missing that will allow MS to do the same thing to Windows
...yet.
Unless they plan to do massive changes to the system this is very likely to not be a problem and cracking is likely to still be quite possible.
The frog is boiling slowly.
I do agree at least that not enough people ever make that consideration that should, but that kind of requires qualities that free software either doesn’t care about or is not competent at (ie marketing)
Yes, AFAIK every TPM comes comes with a unique "endorsement key", signed by the TPM manufacturer, which can be used to prove that it's a real TPM from that manufacturer. A quick web search found https://tpm2-software.github.io/tpm2-tss/getting-started/201... which explains how it's used.
It makes sense for, say, an organization that provides the devices its employees use, because the organization can pre-register those devices' EKpubs in its servers and refuse to acknowledge any device that can't attest. But in the case of Windows, presumably MS is not going to become the single source of all Windows computers.
At best, they might register your device's EKpub when you install Windows and create a MS account or something, but if you already had a backdoored TPM at the time, that backdoored TPM is what will get registered.
It is also possible that MS could require a TPM with an EK certificate that is chained to a set of CAs based on some popular TPM manufacturers. That would certainly prevent you from using any device that doesn't have a "real official" TPM, but I feel this would be quite overkill of MS to do. Then again I would've said the same about an OS that requires a TPM in the first place, but here we are...
Plus, they don't think they want to break VM support, either on a personal or business level.
It seems to me like Linux is going through a growing phase with several growing pains.
Why are my graphics working worse out of the box with common Intel Graphics than back in the day? Bluetooth is a terrible experience. Wifi doesn’t work 60% of time and I don’t know why, the UI won’t tell me.
These used to be issues in the past but I figured that 15 years of progress would’ve changed. However I am aware that all these problems are open and it’s up to me to fix them and I feel no entitlement or have any expectations out of a free and open product. I wish I was better equipped to assist in fixing them myself.
Unfortunately I ended up putting Windows back in that laptop. For a while I used it as a hackintosh and to be honest it worked better with High Sierra than it did with Mankato or Ubuntu.
Keep in mind that using an MBR-layout HDD (SSD) is specified to be fully supported by UEFI.
No need for a GPT-layout HDD to begin with except on some screwy sub-specification UEFI firmware on a number of crummy things like tablets which have no Legacy CSM and which for a while were too defective to even recognize an MBR-layout USB device for booting.
Recently worked out the latest reference implementation of a dual-boot Windows/Ubuntu HDD that boots on "any" x86_64 hardware whether BIOS or UEFI, using the most recent W10 21H1 and Ubuntu 21.04 released over the last few months.
There's never been a reason to settle for less than a HDD which will boot on the widest variety of PCs that you might need to quickly physically transfer the HDD hardware over to. Just in case the PC fries in the middle of an important session and the HDD is still good, you need to be able to just remove the HDD and place it into whichever backup PC you might have available. In this type emergency you really need a HDD layout that can accomodate the widest variety of new & vintage PC hardware, just in case.
Nothing less is an option.
Unless you want to admit that you haven't really tried to get maximum reliability out of fundamental hardware & software to begin with.
For partition 1 it still works great to have a plain ordinary FAT32 volume (which is preferred by UEFI and still works the regular old way for Legacy BIOS boot) and for that a 32GB size is the traditional maximum amount that is really comfortable for Windows98SE (and the FAT32+DOS it was based on). So I can actually boot to a W98SE DOS floppy if I needed to and (re)format partiton 1. This is a bog-standard boot partition layout on the HDD, which will be used by both BIOS or UEFI, whichever one you need at the time.
At this point the HDD is so conventional that you can even install W98SE or at least its underlying DOS version if you tried but it will only boot with UEFI+LegacyCSM (or a real BIOS mainboard), and you may have to use IDE mode for the HDD to load W98 (like often needed with WXP), plus maybe even more changes to BIOS settings. DOS alone still works OK in SATA mode, and DOS can also handle USB drives recognized by the BIOS if they are plugged into the PC before you boot to DOS. No need for trying to load USB hardware drivers in DOS unless you need to plug in USB drives after you have booted the DOS PC. DOS handles FAT format volumes only, and not even NTFS. And this is on a high-performance layout for improved reliability operating the latest Windows (plus dual-boot Linux to boot) for current mainboards at the same time.
But normally you don't need DOS or W98 so I just make the first partition 30GB in size and format it FAT32 using Windows 10 or using the command line when booted to the W10 setup media.
Backward-compatibility in so many ways, exactly along these lines is the main thing that makes Windows worthwhile, without it why bother?
Last time I checked, mbr2gpt would only handle about a 1GB FAT32 boot volume, so if I did want a quick conversion that would seem helpful, but I have tested this app for reliability well within this limitation and it failed miserably even on simple layouts like I am posting here (using a much smaller FAT32 volume for testing). There is also another comment about failed conversion on what is probably a regular Dell business machine. Not good enough for general use as can be seen. So might as well treat your HDD, Windows, Linux and youself to the roomy & useful 30GB FAT32 volume of your '90's dreams. Even if all we're really going to put there are some non-sizable boot files & folders, I still would use the full 30GB unless the HDD is smaller than about 120GB. Then any night you want to in the future you could actually party like it's 1999 if you get a wild hair.
Could also add a bootable live Linux distribution right there on the FAT32 volume independently of the Linux which will be fully installed to its own EXT-formatted volume later. Live distributions usually boot on FAT32-formatted USB sticks anyway. This would be another optional OS you don't really need on the (functionally hidden) FAT32 boot volume of the basic Windows/Ubuntu dual-boot HDD, unless the installed Ubuntu itself turns out to be unsatisfactory for something.
So none of that at this point either, no extra distribution(s), no W98, nor DOS.
Just a regular valid binary Master Boot Record with its accompanying partition table stored in sector 0.
The partition table which defines a 32GB or less Actively Marked partition1, and this boot partition has been formatted FAT32 and has the appropriate Volume Boot Record for either Windows or Linux bootability under Legacy BIOS.
On the FAT32 volume, boot files and all accompanying boot folders readable from the filesystem for both Windows and Linux, supporting BIOS and UEFI booting for either OS. Concentrated in this particular choice of default locations, all the boot files for everything can easily be backed up, restored, or manually modified even when booted to an OS as simple as ordinary DOS if perhaps that might be needed as a last resort or something. If needed the entire FAT32 partiton can easily & quickly be reformatted and the boot files & folders replaced from backup. Without ever touching anything on the main Windows or Ubuntu partitions, each of which simply stand by waiting to be booted to from some appropriate boot files of some kind, whether bootfiles are executed by BIOS or UEFI. To support both Windows and Ubuntu for either BIOS or UEFI that makes a total of four complete sets of independent boot files on the Active bootable FAT32 volume.
The same partition table which is also defining an NTFS partition2 and an EXT partiton3 in addition to FAT32 partition1.
Windows ends up on NTFS partition2 except for its boot files and maybe the Recovery console folder on partition1.
Ubuntu gets completely installed to EXTx partition3 except for its boot files on partition1. No separate /swap, /usr, none of that.
Works like a charm and in Windows 10 the defects which could cause difficulties when physically moving the HDD to a different PC have been largely overcome. You may need to go into safe mode when including IDE mainboards or jumping to way different graphics, but usually any new drivers needed are autoloaded and you can do what you were doing as long as the alternative mainboard is not lacking some unique showstopping hardware your apps need.
Both Ubuntu and Windows are continuously improving the relability of physical HDD relocation, and Windows actually seems to be pulling ahead of Linux in this respect, but it's still neck & neck.
Of course this is only a fundamental layout for a full stand-alone PC without any dependence on web access or even networking to install, boot and be fully functional. Taking this into consideration in your approach when it comes to file management and things like that, you can join networks and webs to taste while maintaining full functionality during times when ethernet and wifi are disconnected, whether the disconnection is intentional or not. I actually enjoy plugging & unplugging my ethernet cord without any hesitation all the time. That's how I got completely comfortable leaving it unplugged almost always when in Windows except when I really need it.
There is a stepwise outline and a full installation procedure to build the Windows/Ubuntu HDD if there is any interest.
IIRC the hard minimal req different from Win 10 is a TPM, 64 bits >= dual core, I think UEFI + secure boot, and WDDM >= 2.0. I just checked on a Kaby Lake and I have everything needed.
The published list of processors is probably for the soft floor and/or for OEMs.
Now, knowing MS and especially the situation in regard with some processors following the Win7 -> 10 migration, there is always the risk they fuck up the support even more for unlisted processor, voluntarily or not...
https://linustechtips.com/topic/1351028-microsoft-makes-thin...
So a hard cut-off at Intel 8th gen and Ryzen 2nd gen really makes no strategic sense whatsoever. I have no doubt MS employs plenty of clueless people, but maybe not going that far to insanity-land.
I mean I was starting to consider switching to a Mac, undecided still, but if MS persist this will really be a no-brainer.
The specs are especially for CPUs are for manufacturer and never list discontinued CPUs. If you look at the same specs for win 10 you would assume it needs modem hardware but it does not it runs on 10 year old laptop.
I tested the leaked version on single core CPU with 1GB ram and it just works. (probably not enough ram to install updates but it boots)
The fact is the leaked version runs on a 10 year old toster. the only limit is 64-bit CPU.
Edit: Oh, but I have Windows on a separate HDD from Clover!
The continuous build integration system for windows makes it so that new builds come out every week. Under the hood W10 and W11 are the same thing barring UI refresh and regular feature updates.
Its Windows 11 because marketers know most people are technically illiterate and want higher version numbers. Its mainly about the UI refresh to pull more people away from Apple and build out the MSFT store.
https://www.theverge.com/2015/5/7/8568473/windows-10-last-ve...
Well, then why does it require TPM and EFI, and drop support for all CPUs more than ~5 years old?
Instead, it was made by an employee making an off-the-cuff comment without context.
It would be a lot worse if this was a Windows 10 update that was incompatible with the majority of Windows 10 machines!
The comment above is 100% correct.
Just because Apple left v10 it doesn't absolutely mean Microsoft is just doing it to copy it. You're talking absolute nonsense. Apple doesn't even call it macOS 11 publicly so it doesn't even make sense from a marketing perspective.
Got some other reason in mind? I'm very confident it wasn't backwards compatibility, by the way, so please name a specific program that would have errored if you claim that. Windows lies about its version to old programs.
This Reddit post says otherwise[1]:
Microsoft dev here, the internal rumours are that early testing revealed just how many third party products that had code of the form
if(version.StartsWith("Windows 9"))
{ /* 95 and 98 */
} else {
and that this was the pragmatic solution to avoid that.[1] https://www.reddit.com/r/technology/comments/2hwlrk/new_wind...
The only plausible version of that I've seen was Java code, and the Java runtime would not have returned "Windows 9" to that API unless deliberately changed to do so.
Not to be rude, but did you skip the second line of my post after reading the first one? Your reply confuses me if you didn't.
I think Microsoft wants people to buy newer hardware so OEMs can profit from it.
I remember when a Pentium 4 could run Windows 7, 8.1, and 10 in the 32 bit edition.
Also you can "deploy" window 11 on any SSD as windows2go and boot from it directly if you just want to test it out on real hardware. All checks are skipped this way and you can put the SSD in any toaster as long as it has a 64-bit CPU it will most likely run.
You’d think that they could build a USB TPM or something.