https://blogs.windows.com/windows-insider/2021/06/24/prepari...
https://blogs.windows.com/windows-insider/2021/06/24/prepari...
Things like tests/validation on new hardware is also costly. Microsoft (used to?) have an absolutely massive fleet of physical hardware to test Windows on
One OS company has control over whether they allow competitor's OSs, on hardware that the company doesn't even produce. That should be an absolutely horrifying thing to anyone who believes in software freedom.
You can disable secure boot or add your own keys because Microsoft required all manufacturers to allow it. If it wasn't mandated by Microsoft, some manufacturers would not allow it. And for ARM devices, Microsoft required the opposite (https://softwarefreedom.org/blog/2012/jan/12/microsoft-confi...). So yes, the only reason we can run non-Microsoft operating systems on our computers is because Microsoft "gave permission".
I'm sure Microsoft hopes to achieve something similar here at some point: secure boot would give them enough trust to decrypt an install upon boot all the way to the login screen.
Sorry for replying twice but I'm almost always stuck on noprocrast so I can't usually edit my comments.
https://docs.microsoft.com/en-us/windows-hardware/drivers/br...
Yeah but then you can't boot into Windows? Who is actually going to go into the firmware settings to switch settings on and off for every single boot to the other OS?
if you want to sign your own kernels: the shim will also let you do that relatively easily ("machine owner keys")
if you want to own your entire boot process you can replace the platform key and sub-keys with your own, and then trust whoever you want (even adding MS' keys if you wish, so Windows can boot in secure mode)
if you don't like it... turn off secure boot, or enroll your own keys (the mok approach takes about 30 seconds)
Why should I have to go to some company to let me use my hardware they didn't even make?
What happens if one day my distro starts to anger the gatekeeper, or worse, start to compete with them?
This is all wrong. Stop supporting them.
Those distros also all use systemd. Do you think they'll sign an image that doesn't include it? We're heading down a path where developers need permission to innovate, and the switching cost of running something non-standard becomes too high for even the most technical users.
https://wiki.gentoo.org/wiki/User:Sakaki/Sakaki%27s_EFI_Inst...
We made it work and we'll make it work again.
Case in point: the countless Android devices out there.
Or are now rushing to give money to Microsoft and use WSL?
Well, that is how things eventually turn out to be.
So you're saying only enthusiasts have smartphones?
As for secure boot, I don't see how that could be anything else than policy (that can have an impact on a security model and so on associated security measures, granted, but not having secure boot should technically not prevent booting / installation unless it is enforced by an explicit artificial limitation). But they could at least remove legacy boot support, in which case it just won't work without UEFI.
Forcing people to buy new hardware while there's a global chip shortage is going to be interesting.
Not to mention the rise of DRM and other user-hostile shit that they are now forcing you to have.
I fucking hate what this industry has become...
The reason they're doing this is because Microsoft doesn't control OEMs directly. They can't make Dell or whoever put in good hardware unless it's a hard-requirement to run their OS. They obviously want to start leveraging TPM 2.0, probably in order to properly compete with Chromebooks, which all require that tech already.
Chromebooks and GSuite are a meaningful threat to Microsoft - Google has a huge head start in that they've enforced much stricter restrictions from day 1 on Chromebook hardware. Microsoft is just getting aggressive about doing the same. And it's going to take at least 4 years for them to catch up, given that Windows 10 EOLs in 2015 at the earliest.
This fits far more into their business model of 0365, Sentinel, and Azure than it does with their Windows business model.
edit: Expanding on this, TPM technology is critical to Zero Trust Networking, which I'm quite sure Microsoft is going to want to push - especially since Active Directory is getting ripped out of networks practically by government order at this point. If they follow through on this, in 4 years Windows networks could be radically more secure than they are today. This fits in well with where Microsoft is taking its business (cloud, security, organization support).
They control the Windows Logo standards, and have used these to enforce a variety of hardware requirements (including TPM) in the past.
They actually can. They have Windows Logo program, which specifies conditions that your product has to comply with, if you want to qualify. OEMs like Dell want to qualify, that allows them to put the Windows sticker on the box.
How do you think Microsoft made the OEMs ship UEFI and Secure Boot in the first place?
Like it's happening on the Mac, it's getting harder for the average user to screw up since software from "unidentified developers" can't run by default.
I can still run anything I want as a power user and that will not change on macOS and won't change on Windows.
Yeah, you can run Windows 10 on some pretty ancient unsupported hardware too, but when they break support for a driver a couple years in, you end up with a nonworking machine.
But such a setup will be very fragile to automatic updates (which are already difficult enough to turn off completely as it is), and with this whole "update mentality" I wouldn't be surprised if they eventually leave in certain security holes and use those as an additional force to coerce people to take their updates --- along with everything else the users didn't want.
the disk will be encrypted with a key stored in the TPM that will only be supplied to a signed OS, so you can't alter the contents on disk
if you've booted in secure mode you can't interfere with the boot process and the OS won't let you patch it online
if they pull it off correctly there's not much you can do
they can even detect the effects of exploits using remote attestation
if a machine has had its environment compromised it won't be able to get updates/watch youtube/play games/...
(using old software/firmware with known exploits can be similarly blocked, until you upgrade)
In the actual world they don't even enforce disk encryption right now and correct me if I'm wrong, but currently having your BitLocker "recovery code" is enough to decrypt the disk on another machine and changing that would be a massive issue for many data recovery processes.
Unless they plan to do massive changes to the system this is very likely to not be a problem and cracking is likely to still be quite possible.
...yet.
Unless they plan to do massive changes to the system this is very likely to not be a problem and cracking is likely to still be quite possible.
The frog is boiling slowly.
These are not "massive changes to the system". Probably still a lot of effort, but closer to "MS now owns the ActualAdmin user who is the owner of system files; you get Administrator who can't touch them".
On Linux you can already prepare system like that fairly easily, with Arch wiki describing most of the steps.
Android now has remote attestation required to use several banking apps, presumably with games and video coming down the line soon
the lack of the mandatory TPM is the only thing missing that will allow MS to do the same thing to Windows