Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs
neowin.net
neowin.net
I'm thinking, either I need to get used to different workflows or just try virtualization. I heard Figma is great for presentations, anything that Excel can do where the alternatives are lacking is probably better done in R/Python anyway, but for Word I don't see an alternative. No way I'll use LaTeX for all my writing, and anything Markdown-based just won't cut it formatting-wise. Or just use something like Wine I guess. Anyone facing a similar situation?
That tells you everything.
Performance wise it's smooth as heck, and Geekbench scores show it performing better than Win11 across the board. The default install uses KDE Plasma for its desktop, which is a perfect fit for Windows users like myself in terms of UX/UI.
For an alternative to MS Office, I've been using OnlyOffice[2] with no compatibility issues yet (though I am only a casual user and not a hardcore Word/Excel user).
I reinstalled Win11 last week to confirm whether or not I was experiencing bias, and there was noticeable feeling of "lag" when using Win11 compared to CachyOS (this test was with the latest Win drivers and patches on relatively recent Thinkpad hardware). I went back to Cachy with no hesitation after that.
All kidding aside, I recently migrated to EndeavourOS, but CachyOS looks dope too
Without much fuss.
Tu(r)ned to eleven, speed, bliss & heaven.
On BTRFS, no less!
>> Since Qt5 is now already outdated,
> Yes, every dependency onlyoffice uses is outdated. They even use v8 8.9 that doesn't include any security patches. They also uses outdated CEF binary downloaded from an http url and doesn't check its integrity at all. Even worse, that CEF binary might be closed source as suggested by dbermond in https://github.com/ONLYOFFICE/DesktopEditors/issues/1664
> I would advise anyone who uses onlyoffice to avoid opening any untrusted documents with it. It appears that onlyoffice upstream doesn't care about security at all. See https://github.com/ONLYOFFICE/DesktopEditors/issues/1664 for more details
I went with Mint instead of an arch-based distro, but my experience has been really great even dealing with Geforce drivers.
I use the 365 suite in a web browser if I need to work on it , no issues.
I have been able to do pretty much everything I need to workflow-wise with LibreOffice.
And any office basic dev work, I just do on the client machine or a virtual machine now.
I, too, spent far too long trapped in Windows because I couldn't get away from MS Office
I would say that 99.9% of the time I can get away with using the web app versions, even for things like Teams meetings it works really well. Once in a blue moon I will have a document that I can't open in the web versions so I fire up the VM and open it on there.
There are definitely some annoyances around this workflow but IMHO the annoyances pale in comparison to the annoyance of having to use Windows or MacOS every day.
“Better formatting” is not nearly enough to stay in an abusive relationship.
There's no document formatting that can't be copied elsewhere. Start with new documents and convert the old ones (to pdf or whatever) at some point.
Even Valve can't get the folks targeting Android to port their NDK powered games into SteamDeck, they have to translate Windows/DirectX instead.
That's probably the easiest step to take next, before looking at virtualization or a full Linux install with Wine.
I still use desktop Office for spreadsheets that need to be shared. Word docs are pretty well supported by Libre at this point.
Since I am not to pay Apple prices for private gear, I rather keep Windows with Linux VM approach.
At work, it is a mix of Windows and macOS, depending on the project.
We leave Linux for the cloud servers, and embedded devices.
I went down the fun path of running Windows on Linux with a pass-through VM for a while but found that most of what I was trying to do worked well in Linux.
Of course, I don't do any development or work on my own computer. Work computer is now 11 and I dislike it but honestly the IT lockdown drives more ire than the Microsoft redesign
(LibreOffice was constantly having compatibility problems when I used it.)
Bugs aplenty, a user interface which has seriously deteriorated over the last decade bundled with an ever-increasing user hostility and tendency to lock you out of your system.
One example: you can no longer manage which applications may run as daemons/background tasks. Any application can register itself with the OS to do so, and your only recourse is a little tiny switch in the system preferences.
Only, in the case of Google Chrome this does not work; the application constantly re-registers itself, overriding the setting. I can no longer prevent Chrome from doing whatever the hell it wants to do, and — adding insult to injury — every time it does, I get a persistent notification from macOS that it is now doing what ever the hell it wants to do. About a dozen times a day.
It cannot replace Microsoft Office, but it's getting close. Most people don't use the full functionality of Microsoft Office, so LibreOffice and Google's online suite are good enough, but I still keep a remote Windows Virtual Machine (VM) around for those time I need Windows-specific stuff and RDP into the VM. I look forward to the day Microsoft finally wakes up and ports Microsoft Office to Linux.
Have a look at Typst[0]. It's a lot easier to use than LaTeX, while still offering full formatting and layout.
Or you could give macOS a go. UNIX with proper desktop versions of the Office apps. ;)
[0]: https://typst.app/
Apart from that every other part of the MS ecosystem is replaceable. If there would be a solution for corporate IT account management, Windows could be replaced without much friction.
https://en.wikipedia.org/wiki/GNU_TeXmacs ?
De nada…
* Microsoft believes the improvements in windows 11 provide genuine benefit to their users.
* Microsoft doesn't want to maintain their older OS forever.
What we are seeing play out however is that the consumer / small business market either does not understand or does not care about those benefits. I don't see any viable end-state for this other than Microsoft relaxing the requirements for Windows 11 or extending the end-of-support date for Windows 10. Based on this action my money is on the latter.
I'd imagine that cutting off support for 10+ year old machines and hardware would give a much bigger advantage then the revenue they get from a hardware refresh itself.
Metric stuffing. Everyone at Microsoft is graded on "impact". All the EVP-types at Microsoft have their eye on boldface jobs, so they need a track record of massive impact. Beimg able to claim that they got W11 from X billion devices to Y is how theyll be judged. Another example is how in Azure, the only metric that matters is consumed revenue. That sort of thing drives behavior.
Land grab. W11 infamously makes the Start menu a billboard and has all kinds of usage data going back to the mother ship. If adoption slows, then Microsoft misses out on eyeballs, misses out on the ability to weld users to Copilot, misses the opportunity to earn money from ads, misses the opportunity to improve Windows by learning how people really use their conputers.
Security. Windows is embedded in modern life and although Microsoft gets a lot of flak, (and sometimes it takes a major beating to remind them of their responsibilities), they do want to elevate the security of users. They believe that W11 and TPM will give them a basis to really deliver stronger services. I dont know that they are right (eg if the #1 exposure for home users is ransomware, does a tpm help at all?), but I am prepared to give them dome grace.
Then again, I plan to use this opportunity to install Linux on my old PC.
There's a pretty interesting video from 2023 that goes through much of Microsoft's thoughts around Windows security. It flew under the radar unfortunately:
- Admin accounts are a continued security problem within the Windows ecosystem, so a future version of Windows will be adding a new "Adminless" account model with linux-like just-in-time escalation. This new model intends to provide a secure middle-ground between the frustrations of a standard user account and the security risks of an Admin account. "Adminless" accounts will run as a "less privileged" user by default and prompt users with Windows Hello when an application requires escalation for a given operation, rather than permanently running the account as a standard or admin user.
- Win32 Applications will be bundled under the new Win32 App Isolation model, which provides the security benefits of UWP sandboxing & clean uninstalls without the API limitations of UWP. Developers will be able to specify what privileges an application requires, much like other application platforms. A demo was shown of Notepad++ running under this sandbox model with minimal modification.
-TPMs within the ecosystem are not in a healthy state, with telemetry telling Microsoft that many are running vulnerable firmware due to manufactures not pushing out updates, and some being inoperable due to hardware failures or other issues. Microsoft is working on its Pluton security chip to replace/augment the existing TPM ecosystem and have the ability to push out firmware updates via Windows Update.
- Software/Hardware mitigations are reaching the end of the road in terms of viability. Microsoft is now focused on eliminating classes of security bugs with extensive R&D going into the use of Memory-safe languages (Rust) in areas of the system that exploits often appear in.
This was the promise of User Account Control, was it not? Or does that just prompt for confirmation for various actions, without actually enforcing a security boundary?
UAC is per-process and monotonic. Once elevated, the entire process stays elevated.
The new model is per-operation. Even if the same process has been allowed to elevate before, it must ask to do it again. I don't know how granular this is, and whether there's a grace period like sudo.
However, the biggest problem with UAC was that it was considered too noisy for the end user, leading to people just blindly accepting every dialog and Microsoft turning down the default level to the much less secure "don't always prompt". I don't know how this new model will address that problem; naively, it seems to be worse on this front.
Given that they didn't mention which Linux security model the new system was like, I presumed they meant the most commonly referenced model for performing administrative tasks: sudo/doas - which elevates a process for its entire runtime.
But if it's a per-operation model, I guess they might have been comparing it to the "desktop portal"/"policykit-dbus" model instead? Which does kind of fit, but I don't think is the security model that most people think of when someone says "linux-like just-in-time escalation"?
It's less granular than a task though, it's an execution context. If you're running Notepad++ and it wants to update, it requires an elevation. The installer is now running in an admin context and can do whatever it wants, once it's finished installing it usually asks if you want to launch Notepad++ again. At that point the installer running in the admin context can launch Notepad++ within that admin context.
Thus there's a potential for the admin context to persist indefinitely.
In my mind, tasked based elevation is more granular. Something like "I need to write to the program files directory" and not a carte blanche "gimmie admin access to do whatever the hell I want".
"Adminless" is a funny name given that there's still an admin account involved, it's just an admin account that is much more than before not a user account but more like a service account.
Wow that thing they probably should've been doing in the first place. I'll be curious if it'll end up as a supervisor (AI) model or if each program will have its own scope of a file system. The latter of course will be very tricky with how intertwined legacy software can be for file and registry access.
Ironically, TPM requirement comes from the same company that invented logging your screen every few seconds and storing it unencrypted and without your consent.
Security is important but like every company, will take a backseat to "revenue" or "growth".
One particularly generous view is that the TPM requirements catch PCs up with the TPM requirements of modern phones. (Both iOS and Android have had very strict TPM requirements for a while now.) With a lot of industry interest in moving to hardware security-backed Passkeys to replace passwords, it would help to have PCs on an equal security footing with phones.
Passkeys are a pretty big deal to reduce home user exposure. Phishing and all of its variants are as much or more a home user problem as ransomware.
And the security reason is nonsense because as you point out, the overwhelming majority of Windows security problems are in no way improved by a TPM.
The most likely real explanation is that Microsoft is constantly at war with itself and the manager currently occupying the relevant coign of vantage finds it to be in their personal interest for some muddy reason having to do with internal politics.
Use this opportunity to install Linux and your NEW PC, and then buckle in!
But on the other hand there are valid reasons for requiring a minimum baseline for Windows 11.
The TPM requirements for example allow seamless BitLocker (which provides feature-parity with macOS), it allows secure system credential storage (in both consumer and enterprise contexts) and it's also useful for application developers. For example Chrome can defend user data better against malware or provide features like Device Bound Session Credentials (DBSC).
Requiring certain CPU features on the other hand makes it easier to ship better-optimized executables.
The two combined make it possible to provide things like VBS/HVCI, which is a massive leap for Windows security (it's actually considered a security boundary, unlike UAC).
Sooner or later, these non windows 11 compliant machines will mostly disappear from most households and offices and will only attract retro computing and linux users when they will not match the usual memory requirements of the day. These are usually the kind of computers that came with 8GB or less of memory out of the box and they could quietly drop support for them somewhere later within the next 10 years when everybody is running 128GB of ram or so and only a handful of people care about it.
If anything it's the CPU requirements that create a hard requirement for newer HW. But in that case, that support is a cost for them. Why should they spend the effort for what is likely going to be a very subpar experience?
Microsoft is just putting a huge environmental waste of a mandated obsolesence tax on the entire world. But Microsoft doesn't pay the opportunity cost of losing all that hardware. (I wonder how much the hardware Microsoft wants destroyed is worth, hundreds of millions of dollars?)
I also don't think the share of TPM-less computers out there is actually that significant. Most laptops have shipped with one for a long time. Desktops that lack one can often buy one. Which is way cheaper than a new PC should you need W11. (I also suspect there are options way cheaper than $500 as well.)
Saying that not being able to run W11 turns something into e-waste is frankly rather crazy. Neither do they want that hardware destroyed.
There is also plenty of hardware that isn't fast but is being used in a situation where that doesn't matter. Some Haswell quad core being used for web and email could continue to be used for that indefinitely. That is old enough that it could be replaced with something newer for less than $500, but the entirety of the replacement cost is still lost money because it otherwise wouldn't have had to be replaced at all.
So then Microsoft decided to follow this up with UWP. UWP was the intended successor to WPF, the 'Universal Windows Platform'. It was supposed to run on any Windows platform. But then the Windows Phone got cancelled, and they also eventually cancelled all support for anything except Windows 10. So it turned into the Windows 10 Platform. And it was heavily tied into the Microsoft store to the point that actually deploying it elsewhere was rendered infeasible. Outside of that it was a technically inferior WPF with a few nicer looking default UI elements and a bunch of new bugs. Oh and some namespaces and other things were changed mostly pretty randomly just enough to make it completely incompatible with WPF.
And then this process repeated multiple times over. Each time they lost more and more developers. If they had simply continued building on WPF I think they would likely be a universal standard for UI development, at least for desktop. Instead they're now onto WinUI 3 which nobody uses, including Microsoft. Oh and all the while this was happening they were also developing Xamarin (and similar timeline of a million subsequent renamings and 'refactorings') which is pretty much the same thing, but different, and cross platform, but not.
I'm the sort that'd naturally leap to conspiratorial explanations - Microsoft pushing anything called "trusted" feels like a rusted van with darkened windows sitting outside a school with "FREE CANDY" sloppily painted on the side. But in this case.. no, Microsoft is just so completely weird and irrational with how they push things, often to the point of self defeat.
Microsoft ships a UWP demo repository which includes the most fully functional Bluetooth manager anyone has ever built for W10. The stock Bluetooth manager has maybe 10% of the functionality. It's also fundamentally broken in a lot of ways. But this UWP demo they have should have been the stock app. It's wild.
Then of course you still have 50 year old UIs hiding in the lowest levels of the control panel. You can dig through the archeological record on your own pc and look at Win3 UI designs. It's astonishing.
At this point, I don't know anyone who uses any of Microsoft's UI frameworks for a real product. It's either QT or Avalonia or something. Who would ever trust their newest framework when every prior framework was abandoned half-finished and left to rot for years?
I imagine it's only my MOBO which is missing TPM, but a suggestion of what mobo to buy which would be compatible with all my other components (RAM DIMMS, PCI-e cards) would be killer.
Ensuring that a critical mass of people use remote attestation[0] capable devices.
The next step is a browser API[1] for this so that content owners can exclude devices capable of storing the content, or stripping out ads/tracking, etc.
Sure, there will be a cat-and-mouse game where people will figure out how to fake the attestation for some period of time, but general computation[2] is probably on the way out.
----
[0] https://en.wikipedia.org/w/index.php?title=Trusted_Computing...
You can also use the unattended installation system: https://github.com/memstechtips/UnattendedWinstall
A true clean Windows installation.
They are used to Windows so they want to stay there, I want to suggest Linux Mint but I am not aware of how much of the apps used daily is supported in Linux.
Not every user want to fiddle with the terminal.
Have an older device? It maybe didn’t come with WiFi, or came with an older card you replaced with a better one. Better hope the distro and version of that distro you picked has a kernel with drivers already baked in!
Otherwise it’s off to some random git following some random “download this source” and oh wait I’m not connected to the Internet.
This is a 2020 full-intel, basic enterprise machine, nothing fancy. Worked fully out of the box under Linux, including sleep. The display output was borken for about a year under Windows (wouldn't output 4k@60 without doing a stupid plug-unplug-replug-just-at-the-right-time dance). At one point, installing the latest driver from intel worked, but Windows would helpfully "update" it to an earlier, borked version every other day.
My point is that the current hardware situation seems pretty much hit-and-miss, and figuring that running windows to avoid fiddling with drivers and whatnot isn't such a sure-thing as people in this thread make it out to be.
The kinds of usages that consumer windows has had and the software ecosystem that's promoted for 3+ decades compared to what has been developed for linux affects this too. Windows is extremely broad in all the software available for all the little utilities users are going to look for, and hardware it's going to need to support (and support well). Even trying to pull windows applications that don't do anything too complex over to linux via Wine is very much a YMMV area. It's impressive what has been accomplished and the recent rate of progress, but there's always more to do so it's not an awkward, poorer version of doing the same task in windows.
The aspect I wonder about is what proportion of the 60% of people still using win10 are actually aware or care about it going end of life, assuming windows doesn't auto-update to 11 for them any EOL warning will just be swatted away like most other annoyances so they can get on with their intended task. Getting that type of user to switch to linux seems like it'd remain a herculean task.
But no, the experience is nowhere near "polished", and troubleshooting is a joke. "Something unexpected happened" or "contact your administrator" isn't exactly helpful. Sure, there may be some log somewhere in that godawful event viewer, but who has the patience to wait for that abomination to load? And then to go spelunking in the millions of categories?
Windows is hands-down the most annoying and janky computing experience among all my devices. I put up with it because I like Photoshop, and since I have PCs lying around can't justify buying a MacBook (plus Linux works well enough for all my other needs).
HiDPI support is a joke, with windows showing up wherever they want, the start menu becoming blurry, taskbar menus appearing at random locations on the screen. The windows jump up and down when switching virtual desktops. Windows appear as active, complete with a blinking cursor and everything, yet won't register text input until I click on them. I could go on for days.
Windows wins 100-0 in terms of polish in the eyes of the average user, and that's saying something given that it's not very polished as you said.
I got to thinking in this thread I can even convert the "gamer" types to Linux - I need to make sure Facebook games work on chromium... And show them Steam.
As always, it depends on what the user uses the computer for. Not everyone can run Windows full-time, as some applications don't work on Linux. I am a full-time Linux user for decades at this point, yet I still use applications that only run on Windows and are too latency sensitive to run well through a VM (and don't work at all via Wine).
Maybe though, these applications could get some love if there was a PR campaign for people to move to Linux...
Give me some names that works out of the box and resembles Windows. I have not tried Linux mint so I don't know how well it works for older people. Ubuntu has been quite good and stable but it has also required fiddling with the terminal.
The only one I found to be the best alternative to Windows is ... believe it or not, DeepinOS.
Even Windows can be quite different from older versions of Windows.
However, I don't think some of the older people are willing to go through all that. I wish to see an easier option for people who wants a smoother transition from Win10 to something else, especially now since Win10 is being discontinued october this year.
People like to freak about how arch isn't for newbies but honestly it's fine. I find it to be just as stable as Debian.
But let's be real, aside from gaming, 99% of what the average user does with a computer is open a web browser. Dekstop apps are secondary. If you put a Firefox/chrome button in the task bar, you've covered most user requirements.
Power users who actually need a bunch of proper desktop applications have a different set of needs. It's impossible to generalize, but a very large fraction of those users would probably be happy with the Linux alternatives, or wine and proton. A lobotomized W10 LTSC VM is also quite usable.
most users won't know or care they're on Linux if the browser works.
- AGI/ASI
- Fusion Energy
- Linux overtaking Windows
(The exponent has been increasing since MS decided to snapshot the user screen all the time. But it's hard to say if it's just noise.)
It's like saying Windows has too many versions because there is Home/Pro/Education/Enterprise and then 23H2 vs. 24H2 etc. There is barely any difference between them.
The distro wars are a bunch of programmers arguing about which one has the best toys for power users. Any of them will run a web browser and the boring popular Debian Stable or LTS derivatives are the ones least likely to deliver unscheduled maintenance as a result of an update.
Newer users who started with the GUI are less likely to have these habits.
I've played around with Debian for several years using it for small little servers. They do not need to have a monitor connected, so i never use a gui.
When using my Steam Deck i don't have a keyboard and the virtual keyboard is kinda annoying, so i use the gui.
I can't seem to get used to work with a Debian installed laptop. I've tried many times, but i don't see a daily beneficial goal to use Linux, mostly because i'll always get Windows 10/11 working :)
If you don't know how to do it, then yeah, you'll probably use a GUI manager. But those people will probably learn how to use a terminal if they do something a lot.
I never have to mess with it, it just works for him. Win11.
https://www.ghacks.net/2024/10/11/rufus-4-6-bypasses-windows...
https://news.ycombinator.com/item?id=41809287
For next version of Windows 11, I'll wait what Rufus will do.
Bonus: LTSC gets extended security patching support lifespan.
For work, I am stuck dealing with 11. There are many things I hate about 11, but why is it so damned slow and laggy on a brand new Copilot PC? File explorer is like loading file lists with a 2400 bps modem, and Office apps take far too long to load. It’s absurd how bad it is, and I can’t figure out why.
I’m getting old, I forget why I load an app before it loads…
Since this is a work PC maybe you don't have the option but if that's the case you should talk to your IT nerd and get permission. Also, make a donation. Great software like Everything is worth buying.
[0] https://www.voidtools.com/downloads/
I can't help with Office. Too bad you have to use Win11. Win7 Pro still works great for me when I need a Winbox.
The users? No.
The corporations that make DRM? Yes.
A TPM is useless for DRM, and there are way more suited solutions like Intel's PAVP that takes an encrypted video stream and puts it on the screen directly, yet I don't see nearly as much uproar about that.
(...or use things such as the already-dead Intel SGX, which never touched TPMs at all)
Encrypted video is a red herring. The real long game is to also get your "secure" video player to refuse playback if it detects watermark in the pirated video. This patches the analog hole.
If you have attested Windows it can just refuse to download "freeworld" VLC because it can be used for piracy and/or even watching child pornography. Imagine that!
Of course you can use Linux instead but now you have to use the approved distro that also won’t let you run "dangerous" apps.
This is of course slippery slope argument and Microsoft would not be able to force all that right now, but better get started on the foundations. Some future government can then just force them to implement the rest, but by then it will be just a flip of a switch.
"TPM is not DRM" argument seriously lacks imagination.
A TPM may only attest that it has received an expected set of measurements (hashes). As long as discrete TPMs or PCs with unlocked CPUs exist (w/o Boot Guard), one may simply take a TPM and replay "golden" measurements to it. Bypassing this would be trivially easy.
A TPM does not have control over execution on the CPU. It only receives data from the CPU. If you have control over execution on the CPU from the reset vector, you can just replay whatever you want to a TPM and extract secrets that way. That's why TPM backed disk encryption without configuring a PIN is insecure.
Microsoft does not have the same level of control over the entire PC ecosystem as Google has over Android. That's why it's important to support open source alternatives.
You’re also entirely missing the point. Yes, you can bypass TPM based DRM to extract the unencrypted video (or just analog hole it) that’s why the game is to lock down the OS so you just can’t play it.
If all DVD players came with watermark detection instead of copy protection you wouldn’t have bootlegs because now every single client device needs to do the bypass instead of just once to extract unencrypted stream.
How many people have bypassed or hardware modded Playstations or Switches? This is what you’re talking about. Almost everyone will just accept it.
That is an enormous "if". Do you think Microsoft is going to or is able to enforce this on every single software provider? Even in your Android example that's just not happening, and you can happily sideload apps. You can still develop your own apps on the same Android phone that you use for banking.
> And sorry but how many people have bypassed Playstations or Switches. This is what you’re talking about. Most people will just accept it.
People accept this with consoles because a console is a device exclusively for consuming media, and all developers apply for a devkit. I just don't see that happening in the PC space. You think Microsoft is suddenly going to dump this on third party software developers and force everyone to go through certification and to buy devkits? Without a mass exodus to Linux?
> you can happily sideload apps.
This is extremely weak argument when the other major platform does not let you do that, right? Sideloading could go away at any moment just like that. That’s my point. There’s nothing technical stopping it.
> People accept this with consoles because a console is a device exclusively for consuming media, and all developers apply for a devkit.
Already Windows has: Smart screen (which requires code signing) and app store. Locking down the OS and Apps is hardly unprecedented. Both Windows and MacOS now have developer modes which is a software devkit equivalent.
> Without a mass exodus to Linux?
That’s why you wait until mass adoption (win11) only then start boiling the frog.
Look, I acknowledge this is slippery slope argument. But the slope is very slippery. Something is clearly going on.
There are TPM 2.0 dTPMs. If the conspiracy is that they want to push people towards "hardware attestation", then they're doing a pretty bad job.
>You’re also entirely missing the point. Yes, you can bypass TPM based DRM to extract the unencrypted video (or just analog hole it) that’s why the game is to lock down the OS so you just can’t play it.
There's no need to "lock down the OS" when there's already a locked down OS on the CPU itself (intel SGX), is way more secure (because it doesn't have a bazillion userspace programs and third party drivers loaded), but for whatever reason gets way less flak than TPM.
> There are TPM 2.0 dTPMs. If the conspiracy is that they want to push people towards "hardware attestation", then they're doing a pretty bad job.
No "normies" are doing TPM bypasses. That’s the point. Majority will eventually be on unbypassable TPM.
Considering that's the only way to play most DRM protected 4K videos, it's probably more of a "push" than requiring TPM. It didn't even have the fig leaf of being usable for FDE or webauthn.
>No "normies" are doing TPM bypasses. That’s the point. Majority will eventually be on unbypassable TPM.
If the bar is "normies", then you don't even need TPM. You can just slap denuvo or whatever and call it a day.
> If the bar is "normies", then you don't even need TPM. You can just slap denuvo or whatever and call it a day.
Again, missing the point. Denuvo, Widevine, whatever, it’s all weak to crack once & enjoy but only if you control the OS. The Great TPM Conspiracy Theory is about limiting what you can do with your mainstream Windows/Linux/Macos installation, in the ways I’ve laid out earlier. Taking the ‘P’ out of PC.
I wouldn't expect many examples to exist yet. You want to wait until almost everyone is on Windows 11 before you get up to those shenanigans.
https://support-valorant.riotgames.com/hc/en-us/articles/169...
I've maintained for several years now that the actual corporate wet dream is that they can lock down the average PC architecture/OS to the same degree they have on phones. Because unfortunately, in the phone sector, the market has already shown the majority of users don't care who really owns their devices.
My hope is that Linux gets wide enough adoption to prevent that from becoming a feasible option for them in the future.
May be "certified UNIX" (when you look at it funny), but it feels like no freedom-loving UNIX-style system I've ever used.
This has already happened: Linux had wide enough adoption that Microsoft could be convinced to allow alternative operating systems in Secure Boot.
My hope is that Linux gets wide enough adoption to prevent that from becoming a feasible option for them in the future.
Linux already got a really wide adoption --- in the form of Android.
Yes, anticheat tends to detect virtualization too, so there's extra cat and mouse there, of course.
I'm not sure that tying their horse to SGX is good for adoption of the format.
Please read this, and do your part to make the world a bit more educated, on average: https://en.wikipedia.org/wiki/Trusted_Platform_Module#Overvi...
If you don't dismiss my comment as the comment of a corporate shill, you might learn something, and in the future that knowledge may help you. I don't know, I can't predict the future, but I do know that ignorance is dumb.
¿Porque no los dos? As noted elsewhere in this thread, TPM certainly facilitates VBS [0], and games like Valorant are already using that for anticheat [1]. As long as application programs can use it to help detect the environment being 'tampered' with (as opposed to the system just wrapping it up in a report for the user), they can use it to protect their particular application state, and I don't see why that shouldn't include DRM state.
[0] https://learn.microsoft.com/en-us/windows-hardware/design/de...
[1] https://support-valorant.riotgames.com/hc/en-us/articles/169...
What prevents boot sector viruses is Secure Boot, not TPM.
Disk encryption, Windows Hello and PIN bruteforce prevention. I have no love Microsoft and avoid using Windows whenever I can, but I think making those features accessible to more people is a good thing.
https://learn.microsoft.com/en-us/windows-hardware/design/de...
https://techcommunity.microsoft.com/blog/virtualization/virt...
If you have an older computer, without TPM 1.2/2.0, then you already don't things like Windows Hello, but you might have secure boot and some brute force prevention, so you wouldn't be worse of as a home user if Microsoft allowed you to run Windows 11.
For new computers I can completely understand that Microsoft would demand that vendors ship systems with TPM 2.0. For upgrades I just struggle to see any really compelling reason, it's not like Apple where Microsoft is trying to also sell hardware, that's mostly on the OEMs.
(Personally I think you probably shouldn't bother with it unless you set a boot PIN, which still requires Pro to be allowed to change the right group policy settings.)
https://support.microsoft.com/en-us/windows/device-encryptio...
The existence of a TPM also lets DPAPI use it, which in turn lets things like browsers and other software protect user data (from malware for example). It also makes new features like Device Bound Session Credentials (DBSC) possible.
But there's also VBS and by extension things like Device Guard. Which in turn entails things like ESS (Enhanced Sign-in Security, more secure biometric auth), Trusted Boot, HVCI, Credential Guard and so on.
DRM is like the last thing it's actually good for, if you actually look into it.
- Windows 11: 36%
- Windows 10: 60%
Using Steam Hardware survey, it shows:
- Windows 11: 53.46% (-1.50%)
- Windows 10: 42.87% (+0.48%)
Whilst these numbers look very bad for Microsoft, especially given that we're less than 10 months away from Windows 10's home user support, it's potentially even worse if the data is correct and more people are reverting to Windows 10. Reasons I can think of there might be due to some of the recent Windows 11 updates harming performance in applications, notably many major Ubisoft titles.
I'm still on Windows 10, for two reasons. My motherboard does not support TPM 2.0, and I have not had any reason to need to upgrade given it still runs everything I need perfectly. Secondly, I have not seen any reason to go to 11 from 10; I don't love 10, but 11 doesn't seem to fix any of my issues, if anything I see many worse features.
https://www.theregister.com/2025/01/02/windows_10_grows/
https://gs.statcounter.com/windows-version-market-share/desk...
https://www.pcworld.com/article/2532669/ubisoft-games-are-cr...
My application does not work at all on W11. The Bluetooth stack is somehow even more broken than W10. It's to the point where we're developing our own wireless dongle to bypass this entire mess.
Microsoft has forcibly installed W11 on our test machine three times and every time it's completely broken and we have to revert.
It's not good.
Most of my machines are 12th gen Intel and they meet all the requirements for Windows 11. However frequently Win 11 updates have caused annoying boot loops, reset preferences, problems with apps already installed and more.
These are Dell Precision workstations so you would think they would have pretty good compatibility with Microsoft... but alas disappointed is the best word I can use.
Given that, there is not the same need to force hardware updates. That said, it also illustrates how the TPM requirement is a business decision, not a technical one.
These are $10k-100k+ servers. My multitenant/offload capable NICs are usually $10k-25k themselves.
Now I will be forced to I guess.
I'm not asking what 2.0 does better than 1.2, I am asking why is it a must have.
2.0 is required for Microsoft's purposes. Here's one of them:
https://learn.microsoft.com/en-us/windows/security/hardware-...
TPM 2.0 is guaranteed to support SHA-256.
(Vs. Windows 10 is just under 10 years old now - and I don't know what's the newest Windows 10 system that can't update to Window 11.)
https://support.apple.com/en-us/120282
A few years shorter than the Win 10 lifecycle. Much shorter than the XP lifecycle, though that was unusual.
MacOS apps target the latest few versions and given macOS' rapid release cycle (in comparison to Windows, at least), you can easily find yourself with a machine <10 years old that can't run the latest versions of apps you're using.
I had a Dell Laptop that, when I bought it in 2006, had Windows XP on it. I was able to upgrade it all the way to Windows 10, at no charge. (The beta versions of Windows 7 and Windows 8 both just kind of rolled over into full fledged versions of the OS. Now, even by the time I had Win8 on that machine, it was just for fun. I mostly kept it around because the screen resolution was unusually high for 2006, and for a period afterward, laptop screen resolutions were almost all lower than WXGA+ even on higher end machines. But you could run Windows 10 and modern browsers on a machine built for the WinXP era. Also, I think I paid $700 for that machine, from the Dell Outlet. That's a lot of mileage for the price paid.
So when Windows 10 told me that my 12-year-old Ship of Theseus Dell XPS desktop was unable to take an upgrade to Windows 11, I took a long hard look, and sprung for an M1 Macbook w/ 64gb of RAM. They had a pretty killer deal on these at B&H, and it's the first time I've ever felt like I've had a true "desktop replacement" laptop. I still think Explorer is better than Finder (and I'm not going to argue with anyone about why so don't bother asking), there are things I will miss about having an ATX case, but Apple's abdication on proprietary ports is ultimately what pushed me over the edge. Everything is USB-C. Great! I had gotten a lot of mileage out of Firewire hardware, but I saw this as a pivotal moment to use some of that money I'd saved over the last decade and a half to completely modernize my setup.
If Windows 11 hadn't forced me to consider new core hardware (and if Apple silicon hadn't leapfrogged everything else on the market - using a laptop all day without charging? Phenomenal.) I'd still be using Windows.
I've been using MS operating systems since DOS 3.1, I just have to assume I'm no longer their target market.
I switched when Apple Silicon came out as well, but had a few flirtations with macOS prior to that with Intel macs. Finder is dog shit compared to almost any other file manager on both Windows and Linux. So much so that I just use the terminal now for almost all file tasks.
I don't love macOS, but I hate what Windows has become more, and these laptops are hard to beat, almost perfect combination of performance & battery life.
I suppose if Apple ever fully iOS-isfys macOS I'll just end up on Linux full-time, and I keep Mint on a spare laptop to toy with, I don't mind it, but I have no need to fully switch yet.
I'm still on macOS Ventura (13.x), and am already seeing numerous apps with a minimum version of 14.x or 15.x.
Operational reasons:
* You often replace hardware and move disks, etc, around
* The TPM is not compatible with hardware that you have: https://wiki.archlinux.org/title/Trusted_Platform_Module
* You have a TPM that is too old: https://www.dell.com/support/kbdoc/en-uk/000132583/dell-syst...
* Your TPM is damaged
Security reasons:
* For some reason the TPM is actually seriously compromised itself (i.e. RCE or firmware backdoors):
- https://www.reddit.com/r/sysadmin/comments/1akxbfn/youtuber_...
- https://www.beyondidentity.com/resource/cybersecurity-mythbu...
- https://www.bleepingcomputer.com/news/security/new-tpm-20-fl...
* You have an alternative security model, i.e. PTT: https://uk.crucial.com/support/articles-faq-ssd/alternatives...
* As others have pointed out, what if you're locked into using Windows, Windows requires TPM, and TPM implements something you don't like, for example DRM or it snoops on you. Maybe you have to let it scan your drives, maybe your TPM doesn't like your politics.
Stop spreading FUD.
The TPM is fundamentally about storing cryptographic keys, platform integrity checks, unique IDs, etc. It is already used for secure logins by the Windows OS. Microsoft are successfully enforcing your email, ID, logins, etc, to be associated directly with your unique hardware.
One day you will request a video from Netflix or Youtube, and your device will be the only device in the world that can view it. You might think to screen record, but the OS does not allow it. You might think to record it via an external display, but this has to interface with the TPM. You decide to record your screen from your phone, but the phone's TPM recognises that the camera tries to record DRM material.
Don't get me wrong, security devices should exist 100%. But. It should never be forced.
Unique IDs of a system don't require a TPM. Microsoft uses unique IDs from various hardware to bind a product key to a particular device, and has been doing that since the XP era.
Intel and gfx vendors already provide secure DRM paths. TPM isn't capable of doing so.
> Don't get me wrong, security devices should exist 100%. But. It should never be forced.
They should be forced otherwise users would continue leaving themselves open to attack. Security has moved on from ACLs. Microsoft recognizes the need for things like VBS to protect against modern threats, which in turn requires TPM.
Apple has been doing this for roughly 15 or so years now with no fanfare on consumer devices. TPM has been around on x86 since the late '00s with little-to-no fanfare.