Corporate security has been fine for years: TPM 1.2 (if I remember the versions correctly) alongside bitlocker and sensible corporate policies render computers all but impervious to everything. However, this implies a competent IT division in your company... I've worked in plenty without them!
Social engineering or clicking a dodgy link/download is probably a bigger threat than someone hacking your computer and that can be mitigated to a huge extent by restricting access to only the things that the user needs, locking down apps, running with low privileges, auditing relevant things etc... again, competent IT division needed for this too.
Now, if your threat matrix includes nation-states then one could argue that any device is hackable.
My take is that hardware vendors saw the writing on the wall with the pandemic-buying about to ease-up and worked with Microsoft (or pressured them...) to help out. We're already seeing Chromebooks on the wane[0].
From my perspective (long-time Windows guy now on Fedora) I see nothing of value in Windows 11 that 10 didn't have already.
Edit: Forgot the answer I was gonna write :)
[0] - https://chromeunboxed.com/canalys-report-chromebook-sales-do...
Microsoft.
Remember, you run Linux on modern hardware only because Microsoft allows you to. Microsoft signed the Red Hat shim, and if you disabled Secure Boot, it's only because a Microsoft policy gave you the ability to disable it -- a policy they can later reverse.
Operating systems with "signed binaries or GTFO" policies are not really protecting the user. Any protection the user receives is a secondary concern to the fact that the OS vendor wants to control what the user runs on the device.
Factually wrong.
Any regular PC owner can run Linux on modern x86 hardware in at least three ways:
- Legacy BIOS MBR boot
- UEFI boot
- UEFI secure boot
Only the last one of those three options requires a signed shim, and only if you don’t enrol your own keys.
> Microsoft signed the Red Hat shim, and if you disabled Secure Boot, it's only because a Microsoft policy gave you the ability to disable it -- a policy they can later reverse.
This FUS has been repeated the last 10 years+ and it gets less convincing every year.
No OEM or PC vendor wants to limit their amount of potential in what is already a cut-margin business.
Taking away the ability to disable secure boot or taking away the legacy BIOS boot option will only cost them customers, and they literally have nothing to gain.
I definitely recall Microsoft killing hardware manufacturers putting Linux on the machines that they sold by mandating that if they put Linux on any consumer desktop they would not get the OEM discount for a Windows licence for any computer they sold. It stopped new non Windows PC sales dead at the time IIRC. This was something like over a decade ago.
So far, users did not use their shitty store because they had alternatives.