Bizarre take. It's not random, it's specifically CPUs that support modern hardware security mitigations + features.
There's a pretty great talk from Bluehat a few days ago that goes into why Microsoft is doing this:
Bizarre take. It's not random, it's specifically CPUs that support modern hardware security mitigations + features.
There's a pretty great talk from Bluehat a few days ago that goes into why Microsoft is doing this:
I'm well aware computing power for practical use cases has plateaued since around 2011, but those Coffee Lake and Zen+ systems (let alone older) are coming due for replacement/upgrade soon for anyone inside of a lifecycle cadence whether Windows 11 demanded it or not.
For anyone who isn't who cares about hanging on to old hardware, it's perfectly fine to just keep running Windows 10. All those guys saying "yOuR sYStEM iS iNSeCurE!!1!1!1" are snake oil merchants wanting to sell you something.
Increasingly hard to get this days, especially through official channels. Currently, Microsoft actively prevents you from getting a Win10 installer/image, by redirecting all the relevant links to Windows 11 pages.
> All those guys saying "yOuR sYStEM iS iNSeCurE!!1!1!1" are snake oil merchants wanting to sell you something.
You mean like Microsoft? Saying that the new system is more secure is equivalent to saying your old system is insecure, given everyone's insistence that you either are fully secured or not at all.
Really? I used this just a few weeks ago and definitely got a Windows 10 ISO.
https://www.microsoft.com/software-download/windows10ISO
For reference, I searched the following on Google
> windows 10 iso
Additionally, I suspected I'll need a new product key. I couldn't get that from Microsoft - every link I've managed to Google also had a redirect to Windows 11.
(In the end, I purchased an electronic license from some local software shop. Then it turned out that somehow, Microsoft considers my wife's Win7 license still valid for Win10 Pro, which is nice. I used the key to upgrade another machine, which I thought was on Pro, but actually was on Home.)
You're (probably unintentionally) exaggerating, but that's not how it works. When a new CPU comes out, all the machines on the market don't magically replace their CPUs with that one on day 1. The machine I'm typing this comment on right now was a pretty high-end one I got after those CPUs came out, and its CPU is from an older generation. In fact, I don't even recall having seen machines with newer CPUs on the market (at least not with the minimum specs I was looking at) until quite a few months later, though my memory might be hazy here. Sometimes the price points are also a factor here too.
> those Coffee Lake and Zen+ systems (let alone older) are coming due for replacement/upgrade soon for anyone inside of a lifecycle cadence whether Windows 11 demanded it or not.
That's by no means universally true; there are plenty of good machines out there that work just fine and that people want to keep using. Again, speaking from personal experience, I know my machine is perfectly good and I hope to keep using it for several more years. An older one I had from several years before that, which I gave away for unrelated reasons, was also great, and I would still use it if I had it and my current one somehow broke. There's been literally no reason for me to throw these away anytime soon other than Microsoft forcing me to. Lots of people are being forced to throw away perfectly good hardware because Microsoft/Google/Apple/etc. force them to, often via software.
As I already said, if you want to keep running Windows 10 (or 7, or XP) it's perfectly fine. Tell everyone who screams "SECURITY!" at you to screw off, they all want to sell you something.
Even if you do upgrade to a new machine, why does someone have to throw away their old one? Keep it as a sub computer, or give it a new role in your life. Windows 11 mandates TPM2 and SecureBoot, but it doesn't mandate throwing your old machine in the trash.
We are indeed!
https://blogs.windows.com/windows-insider/2021/08/27/update-...
It only added 7th gen processors that have DCH driver support, which is the absolute minimum baseline for W11 support.
Could you explain in what way "DCH driver support" is a "hardware security mitigation" as you wrote?
Moreover, doesn't basing this on "DCH driver support" basically let the hardware vendors decide which otherwise-capable CPUs they'd like to make obsolete through software updates?
And furthermore, note that the OS isn't even turning on the CPU features they require by default, as the article also mentions.
(I'm probably going to just leave it at this, but suffice it to say the evidence doesn't seem in their favor.)
[1] https://forums.lenovo.com/t5/ThinkPad-T400-T500-and-newer-T-...
That statement seems misleading at best. According to Microsoft's page[0] on that processor, the Dell Precision 5520 is supported as well, which means this support is clearly not limited to Microsoft's own hardware.
Depending on how Lenovo configured the BIOS, it is entirely possible that they disabled certain features that Microsoft deemed critical later on with Windows 11. Vendors do plenty of weird things with BIOSes, which can have far reaching impacts on what an operating system is able to do with the hardware. Or Lenovo didn't provide a necessary driver, or whatever the actual problem was here. Dell managed to meet the requirements just fine, apparently.
Yes, obsoleting a bunch of hardware sucks, but your claim that this was to help Intel sell more chips is extremely dubious. Your claim that Microsoft isn't doing this for security reasons because they're exempting only their own hardware doesn't mesh with the reality of that Dell laptop. None of the evidence here supports some grand conspiracy here, as far as I can tell.
I also found a forum thread[1] where at least one person was struggling to update their Surface Studio 2 to Windows 11, so even that hardly seems cut and dry.
[0]: https://learn.microsoft.com/en-us/windows-hardware/design/mi...
[1]: https://answers.microsoft.com/en-us/surface/forum/all/window...
> Depending on BIOS settings, it is entirely possible
"Entirely possible" is quite a big umbrella that covers planned obsolescence quite well, too. It's not like using software to make hardware obsolete is lacking in historical precedent.
> There isn't some grand conspiracy here, as far as I can tell.
Well, it's "entirely possible", as far as I can tell. Though I'm not even claiming there is one - there isn't a particular need for a conspiracy here.
> I also found an entire forum thread[1] of people struggling to update a Surface Studio 2 to Windows 11, so even that hardly seems cut and dry.
All of those comments were posted in the span of the first 4 days Windows 11 was officially released. If you dig a bit more you see people have succeeded afterward. [1] So that was most likely just a bug on their side, which isn't surprising given their own device was an edge case they were trying to make an exception for.
[1] https://techcommunity.microsoft.com/t5/windows-11/windows-11...
No, someone else responded to that. I was just here to look at a specific claim and see what your evidence showed. If that claim had been supported by the evidence, it would have been scandalous, but it wasn’t. I’m not an expert in the Windows security model, so I don’t claim to know anything about DCH drivers.
If you're going to complain about people not responding to every single thing in your comments, then why didn't you respond to the main point I was making? The Dell laptop was supported as well. Clearly Dell put in the effort, where Lenovo did not.
> Though I'm not even claiming there is one - there isn't a particular need for a conspiracy here.
Your previous comments absolutely are making claims that there were large conspiracies at play. You claimed that Microsoft did this to help Intel sell more chips, which would be a huge conspiracy between Microsoft and Intel. Claiming that Microsoft lied about their reasons for obsoleting old processors by trying to present evidence that Microsoft wasn’t following their own stated reasons naturally also requires the existence of a significant conspiracy within Microsoft. Perhaps you didn’t mean to claim those things?
Because Lenovo did not bother writing DCH drivers, given DCH drivers are the baseline requirement.
> Could you explain in what way "DCH driver support" is a "hardware security mitigation" as you wrote?
I was recalling a 2 year old blog post in my head, but the point is still that much of the requirement is around baseline security. If you watch the video I linked, the speaker does go over all of this.
> basically let hardware vendors decide which otherwise-capable CPUs they'd like to make obsolete through software updates?
I'm not sure what you're getting at. DCH drivers were already the default for current-gen hardware _before_ W11 even came out, W11 just made it a requirement. Vendors clearly aren't going to go write some greenfield drivers for a years-old 6th gen intel product just to support W11, as those devices will be 10 years old by the time W10 support ends.
> note that the OS isn't even turning on the CPU features they require by default
Note that you're still referencing a blog post from 2021. W11 22H2 enables core isolation by default for new installations, and HVCI is enabled by default when using the Windows Enterprise security baseline.
https://techcommunity.microsoft.com/t5/microsoft-security-ba...
I have in fact. It's a nice talk about security in Windows 11, but I haven't seen anything in it answering these issues. He says absolutely nothing about DCH and doesn't give any explanation for the minimum hardware requirements. The closest I recall was he was mentioned of integrating Pluton on chip and making its firmware directly updatable, but I don't believe for example that the 7820HQ and the 7700HQ are any different with regards to Pluton.
> I'm not sure what you're getting at. DCH drivers were already the default for current-gen hardware _before_ W11 even came out, W11 just made it a requirement.
No, they didn't even make DCH a requirement; Windows 11 runs with standard drivers too. [1] And, again, DCH doesn't imply anything about hardware security mitigations, which was purportedly their reason for this.
> Note that you're still referencing a blog post from 2021. W11 22H2 enables core isolation by default for new installations, and HVCI is enabled by default when using the Windows Enterprise security baseline.
Because the situation is fundamentally the same since 2021. Core isolation support is not a distinguishing feature between (say) the 7700HQ and 7820HQ, as far as I know. And the Windows Enterprise security baseline seems kind of irrelevant for the millions of average consumer devices out there. A company that cares about consumers or the environment is telling consumers across the planet to turn perfectly good devices into electronic trash now because they might add something that helps security years later?
I'm going to let my comments rest here; people draw their own conclusions.
[1] https://www.reddit.com/r/Windows11/comments/pr4kmr/why_is_wi...
The hardware security baseline is one of the first topics he covers as part of Windows 11 security strategy, with mention given to features that require hardware support and how they intend to enable these by default going forward as not doing so was a failure of the Windows 10 strategy. He even mentions "virtualization extensions" aka HVCI-related features which would be non-performant to enable by default in older hardware.
How exactly would a strategy of enabled-by-default work if the hardware wasn't there to support it? You seem to be looking for some hard "gotcha" statement to refute your argument instead of considering all of the information available in front of you.
> No, they didn't even make DCH a requirement;
By setting the minimium CPU requirement to systems that use DCH drivers, they effectively did.
> Core isolation support is not a distinguishing feature between (say) the 7700HQ and 7820HQ, as far as I know.
That's not the issue here. The 7700HQ lacks Trusted Execution support (aka TPM), whilst it's included in the 7820HQ, thus it does not meet the minimum requirements.
> electronic trash now because they might add something that helps security years later?
No, it's giving people the heads up that Windows 11 security strategy requires these features and gives people & companies time to adapt. For example, motherboards now ship with TPM 2.0 enabled by default, so as Windows 11 rolls out more features that require it (some aspects of Windows Hello already do), users aren't stuck with a system that needs a BIOS update or are unable to use the new features. Windows 12 will very likely make these requirements hard-enforced rather than soft-enforced and thus it'll make the 11-to-12 upgrade a smoother experience.
> How exactly would a strategy of enabled-by-default work if the hardware wasn't there to support it? You seem to be looking for some hard "gotcha" statement to refute your argument instead of considering all of the information available in front of you.
I'd say the core issue here is of priorities. Microsoft may be treating aggressive enabled-by-default approach to security as a good thing. A lot of other people don't. If you don't, then the high-level summary of the issue is, essentially, "By making some relatively recent hardware features a requirement for Win11 in the name of sekhurity, while also aggressively pushing users to upgrade and actively preventing them from continuing to use Win10, they're forcing people to destroy perfectly good machines for bullshit reasons".
I'm having hard time seeing fault in this view.
Declarative:
Install the driver by using only declarative INF directives.
Don't include co-installers or RegisterDll functions.
Componentized:
Edition-specific, OEM-specific, and optional customizations to the driver are separate from the base driver package.
As a result, the base driver, which provides only core device functionality, can be targeted, flighted, and serviced independently from the customizations.
Hardware-support-app:
Any user interface (UI) component associated with a Windows Driver must be packaged as a Hardware Support App (HSA) or preinstalled on the OEM device.
The D and C parts of the description appear to be what you're looking for here.
No special hooks or modifications of the system paired with independent modules.https://www.techrepublic.com/article/windows-11-understandin...
I'm typing this on a T430 with an i7-3632QM running Win 11. The stupid thing is I never wanted Win 11 on it. MS suckered me into installing Windows 10 update ver 22000 (just after ver 19043) which didn't mention anything about Win 11.
That's because those are NT kernel version numbers, not Windows marketing version numbers.
Windows 10 and 11 both identify internally as NT10.0.X.Y where the X and Y are the specific build numbers.
So suddenly, all the Windows 10 computers are insecure or what?
A normal person looking at "Windows 11 is not supported on your device" WILL think that their hardware is not good enough to run the authoritative OS.
This is less about security and more about planning a strategy to sell more devices. Anybody denying this possibility is just ignoring on purpose.
Here, I am not actually arguing against the addition of TPM or anything. I am arguing against them being a fixed requirement to run the OS that would otherwise run without any issues because it quite literally is a Windows 10 reskin, nothing more.
This is proven by the fact that they broke their own requirements on their own surface devices. Which tells me that this is less about them being serious about security and more about declaring most fairly recent hardware obsolete.
It's anti-consumer at best and deceitful attempt to sell more computers to non-tech folks at worst.
"Intel® 6th Generation Core Processors or Newer Processors are supported by Windows DCH Drivers."