New Win11 insider build blocks install on older hardware, prevents TPM bypass
tomshardware.com
tomshardware.com
I gave up because it's been over three years during which MSFT has repeatedly demonstrated the Windows business is being operated with fundamentally different priorities in the Win11 era than it ever has been. The myriad things which have been removed from Win11 and the new things which are annoying on a daily basis are not regressions. They're not going to be fixed because these new priorities are now part of MSFT's core strategy for the Windows business. They have prioritized incessantly promoting adjacent subscription businesses and de-prioritized making Windows a complete, feature-rich, functional and streamlined tool for individual power users.
For the past 30 years, Windows has generally gotten better for users like me (with a few detours, which were corrected). It's not that MSFT always did everything the way I'd prefer but, even when we disagreed on implementation, we remained largely in sync on the overall goals. Since Win11, it's become clear that Microsoft's interests are no longer mostly aligned with my own interests as an individual power user.
undoubtedly
>...and get better
well that would buck the entire constant downward UX trend that has happened ever since data exfiltration became the actual revenue stream for Microsoft.
I get the "I hate new windows version Y" statements are getting old, i've been reading them for at least as long -- but it doesn't make the points that they extrapolate upon wrong. Windows has long been trending 'anti-user' , and has recently met a threshold that has thrown a lot of long-time users off the scent -- especially since other OSs have never been better/compatible/capable.
> Windows will go on and get better.
Well, we can probably agree on the first half of that.
This is not a big deal. Most laptops have TPM 2.0, and most motherboards can have a dTPM accessory if they don't have it onboard.
Windows 11, has a lot of useful things, which 10 did not, for example DoH in the system resolver and a variety of other security benefits.
It's literally like people complaining if Windows doesn't work on old-BIOS only computers, it's not going to make much difference as nobody has those. If they do have those then a cut down Linux OS makes more sense as those devices likely won't have much RAM either to run a modern browser etc.
There seems to be a clear focus on attestation and preventing persistent malware from taking root in a system's boot chain and potentially firmware.
https://learn.microsoft.com/en-us/windows/security/hardware-...
Just FYI, Windows never had any security "support". The fact that Microsoft releases some security patches, is just a fact. With Windows you, as an individual, were always on your own regarding security.
Microsoft has been doing a lot in recent years to make people care, including (but not limited to) pop-ups near EOL that throw a scare into people.[0]
[0]: https://support.microsoft.com/en-us/topic/you-received-a-not...
If you spend a lot of time in tech circles, it's easy to get the impression that literally no one really thinks like this. A lot of us may think Windows 11 is mostly just a reskin with some integrated AI bloat that can be mostly replaced with just a bookmark to ChatGPT, but you would have a real hard time explaining that to an average non-techie. These decisions have significant effects on the choices average people make, and you can't just ignore it and assume everyone knows better
Considering there are around twice as many Linux desktop users as Windows 7 (according to Statcounter global stats), I would hardly call it a lot of people
HW restrictions are not arbitrary. TPM is a requirement for added security (Macs and smartphones also had TPM for a long time now), and CPUs before 8th gen don't have functional HW instructions needed for VBS (virtualization based security) which also adds to Windows 11 security hardening.
https://www.intel.com/content/www/us/en/support/articles/000...
https://learn.microsoft.com/en-us/windows-hardware/design/de...
The loss was on security and potential stability, not on functionality.
They always did, ever since the introduction of Protected Media Path (PMP) in Windows 2000, followed by tightening of the kernel access and now requiring the TPM. The end goal is to take away full control of the machines from their owners.
It's been a very long game for them, but they are almost there.
And then they will have fun.
It's absurd that I have a Netflix subscription, but the easiest way to watch Netflix 4K content on my PC is to just download it from a bay filled with pirates.
But I hope that scene gets revived if/when they get rid of local accounts altogether, and this would be another thing that would make custom builds attractive again.
Windows is a sinking ship.
I got a kick out of Windows' responses to me installing Chrome on some machines at work.
First, search (good) Bing for Chrome. Get a sponsored result from MS saying something like "Oh, really, no reason to install that, Edge is x, y, z marketing bs, you should just use it instead."
Second, go to Chrome download page. Windows then pops up a notification bubble or something in the top right again extolling Edge, finishing with "and it's Microsoft Trusted!"
Thanks for the laughs MS.
Those tend to be shipped on some validated hardware that will take years to validate, then eventually gets approved for use, and won't be replaced for many years. My guess is in many of these use cases (industrial etc) you won't see TPMs present or used, because they value availability and uptime over all else (i.e. confidentiality and integrity) - you won't be encrypting the filesystem or doing any kind of TPM checks on an industrial control system, as the operational technology mindset is to put availability above all else, and a TPM or encryption issue would compromise availability.
So not really for workstations - they'd probably say you should use enterprise and just accept constant changes and new features being pushed down to users causing support hassle. They don't officially consider LTSC to be something used by regular users for daily productivity though.