Metric stuffing. Everyone at Microsoft is graded on "impact". All the EVP-types at Microsoft have their eye on boldface jobs, so they need a track record of massive impact. Beimg able to claim that they got W11 from X billion devices to Y is how theyll be judged. Another example is how in Azure, the only metric that matters is consumed revenue. That sort of thing drives behavior.
Land grab. W11 infamously makes the Start menu a billboard and has all kinds of usage data going back to the mother ship. If adoption slows, then Microsoft misses out on eyeballs, misses out on the ability to weld users to Copilot, misses the opportunity to earn money from ads, misses the opportunity to improve Windows by learning how people really use their conputers.
Security. Windows is embedded in modern life and although Microsoft gets a lot of flak, (and sometimes it takes a major beating to remind them of their responsibilities), they do want to elevate the security of users. They believe that W11 and TPM will give them a basis to really deliver stronger services. I dont know that they are right (eg if the #1 exposure for home users is ransomware, does a tpm help at all?), but I am prepared to give them dome grace.
Then again, I plan to use this opportunity to install Linux on my old PC.
Ironically, TPM requirement comes from the same company that invented logging your screen every few seconds and storing it unencrypted and without your consent.
Security is important but like every company, will take a backseat to "revenue" or "growth".
One particularly generous view is that the TPM requirements catch PCs up with the TPM requirements of modern phones. (Both iOS and Android have had very strict TPM requirements for a while now.) With a lot of industry interest in moving to hardware security-backed Passkeys to replace passwords, it would help to have PCs on an equal security footing with phones.
Passkeys are a pretty big deal to reduce home user exposure. Phishing and all of its variants are as much or more a home user problem as ransomware.
And the security reason is nonsense because as you point out, the overwhelming majority of Windows security problems are in no way improved by a TPM.
The most likely real explanation is that Microsoft is constantly at war with itself and the manager currently occupying the relevant coign of vantage finds it to be in their personal interest for some muddy reason having to do with internal politics.
There's a pretty interesting video from 2023 that goes through much of Microsoft's thoughts around Windows security. It flew under the radar unfortunately:
- Admin accounts are a continued security problem within the Windows ecosystem, so a future version of Windows will be adding a new "Adminless" account model with linux-like just-in-time escalation. This new model intends to provide a secure middle-ground between the frustrations of a standard user account and the security risks of an Admin account. "Adminless" accounts will run as a "less privileged" user by default and prompt users with Windows Hello when an application requires escalation for a given operation, rather than permanently running the account as a standard or admin user.
- Win32 Applications will be bundled under the new Win32 App Isolation model, which provides the security benefits of UWP sandboxing & clean uninstalls without the API limitations of UWP. Developers will be able to specify what privileges an application requires, much like other application platforms. A demo was shown of Notepad++ running under this sandbox model with minimal modification.
-TPMs within the ecosystem are not in a healthy state, with telemetry telling Microsoft that many are running vulnerable firmware due to manufactures not pushing out updates, and some being inoperable due to hardware failures or other issues. Microsoft is working on its Pluton security chip to replace/augment the existing TPM ecosystem and have the ability to push out firmware updates via Windows Update.
- Software/Hardware mitigations are reaching the end of the road in terms of viability. Microsoft is now focused on eliminating classes of security bugs with extensive R&D going into the use of Memory-safe languages (Rust) in areas of the system that exploits often appear in.
This was the promise of User Account Control, was it not? Or does that just prompt for confirmation for various actions, without actually enforcing a security boundary?
"Adminless" is a funny name given that there's still an admin account involved, it's just an admin account that is much more than before not a user account but more like a service account.
It's less granular than a task though, it's an execution context. If you're running Notepad++ and it wants to update, it requires an elevation. The installer is now running in an admin context and can do whatever it wants, once it's finished installing it usually asks if you want to launch Notepad++ again. At that point the installer running in the admin context can launch Notepad++ within that admin context.
Thus there's a potential for the admin context to persist indefinitely.
In my mind, tasked based elevation is more granular. Something like "I need to write to the program files directory" and not a carte blanche "gimmie admin access to do whatever the hell I want".
UAC is per-process and monotonic. Once elevated, the entire process stays elevated.
The new model is per-operation. Even if the same process has been allowed to elevate before, it must ask to do it again. I don't know how granular this is, and whether there's a grace period like sudo.
However, the biggest problem with UAC was that it was considered too noisy for the end user, leading to people just blindly accepting every dialog and Microsoft turning down the default level to the much less secure "don't always prompt". I don't know how this new model will address that problem; naively, it seems to be worse on this front.
Given that they didn't mention which Linux security model the new system was like, I presumed they meant the most commonly referenced model for performing administrative tasks: sudo/doas - which elevates a process for its entire runtime.
But if it's a per-operation model, I guess they might have been comparing it to the "desktop portal"/"policykit-dbus" model instead? Which does kind of fit, but I don't think is the security model that most people think of when someone says "linux-like just-in-time escalation"?
Wow that thing they probably should've been doing in the first place. I'll be curious if it'll end up as a supervisor (AI) model or if each program will have its own scope of a file system. The latter of course will be very tricky with how intertwined legacy software can be for file and registry access.
Use this opportunity to install Linux and your NEW PC, and then buckle in!
* Microsoft believes the improvements in windows 11 provide genuine benefit to their users.
* Microsoft doesn't want to maintain their older OS forever.
What we are seeing play out however is that the consumer / small business market either does not understand or does not care about those benefits. I don't see any viable end-state for this other than Microsoft relaxing the requirements for Windows 11 or extending the end-of-support date for Windows 10. Based on this action my money is on the latter.
But on the other hand there are valid reasons for requiring a minimum baseline for Windows 11.
The TPM requirements for example allow seamless BitLocker (which provides feature-parity with macOS), it allows secure system credential storage (in both consumer and enterprise contexts) and it's also useful for application developers. For example Chrome can defend user data better against malware or provide features like Device Bound Session Credentials (DBSC).
Requiring certain CPU features on the other hand makes it easier to ship better-optimized executables.
The two combined make it possible to provide things like VBS/HVCI, which is a massive leap for Windows security (it's actually considered a security boundary, unlike UAC).
Microsoft is just putting a huge environmental waste of a mandated obsolesence tax on the entire world. But Microsoft doesn't pay the opportunity cost of losing all that hardware. (I wonder how much the hardware Microsoft wants destroyed is worth, hundreds of millions of dollars?)
I also don't think the share of TPM-less computers out there is actually that significant. Most laptops have shipped with one for a long time. Desktops that lack one can often buy one. Which is way cheaper than a new PC should you need W11. (I also suspect there are options way cheaper than $500 as well.)
Saying that not being able to run W11 turns something into e-waste is frankly rather crazy. Neither do they want that hardware destroyed.
There is also plenty of hardware that isn't fast but is being used in a situation where that doesn't matter. Some Haswell quad core being used for web and email could continue to be used for that indefinitely. That is old enough that it could be replaced with something newer for less than $500, but the entirety of the replacement cost is still lost money because it otherwise wouldn't have had to be replaced at all.
Sooner or later, these non windows 11 compliant machines will mostly disappear from most households and offices and will only attract retro computing and linux users when they will not match the usual memory requirements of the day. These are usually the kind of computers that came with 8GB or less of memory out of the box and they could quietly drop support for them somewhere later within the next 10 years when everybody is running 128GB of ram or so and only a handful of people care about it.
If anything it's the CPU requirements that create a hard requirement for newer HW. But in that case, that support is a cost for them. Why should they spend the effort for what is likely going to be a very subpar experience?
I'd imagine that cutting off support for 10+ year old machines and hardware would give a much bigger advantage then the revenue they get from a hardware refresh itself.
Ensuring that a critical mass of people use remote attestation[0] capable devices.
The next step is a browser API[1] for this so that content owners can exclude devices capable of storing the content, or stripping out ads/tracking, etc.
Sure, there will be a cat-and-mouse game where people will figure out how to fake the attestation for some period of time, but general computation[2] is probably on the way out.
----
[0] https://en.wikipedia.org/w/index.php?title=Trusted_Computing...
So then Microsoft decided to follow this up with UWP. UWP was the intended successor to WPF, the 'Universal Windows Platform'. It was supposed to run on any Windows platform. But then the Windows Phone got cancelled, and they also eventually cancelled all support for anything except Windows 10. So it turned into the Windows 10 Platform. And it was heavily tied into the Microsoft store to the point that actually deploying it elsewhere was rendered infeasible. Outside of that it was a technically inferior WPF with a few nicer looking default UI elements and a bunch of new bugs. Oh and some namespaces and other things were changed mostly pretty randomly just enough to make it completely incompatible with WPF.
And then this process repeated multiple times over. Each time they lost more and more developers. If they had simply continued building on WPF I think they would likely be a universal standard for UI development, at least for desktop. Instead they're now onto WinUI 3 which nobody uses, including Microsoft. Oh and all the while this was happening they were also developing Xamarin (and similar timeline of a million subsequent renamings and 'refactorings') which is pretty much the same thing, but different, and cross platform, but not.
I'm the sort that'd naturally leap to conspiratorial explanations - Microsoft pushing anything called "trusted" feels like a rusted van with darkened windows sitting outside a school with "FREE CANDY" sloppily painted on the side. But in this case.. no, Microsoft is just so completely weird and irrational with how they push things, often to the point of self defeat.
Microsoft ships a UWP demo repository which includes the most fully functional Bluetooth manager anyone has ever built for W10. The stock Bluetooth manager has maybe 10% of the functionality. It's also fundamentally broken in a lot of ways. But this UWP demo they have should have been the stock app. It's wild.
Then of course you still have 50 year old UIs hiding in the lowest levels of the control panel. You can dig through the archeological record on your own pc and look at Win3 UI designs. It's astonishing.
At this point, I don't know anyone who uses any of Microsoft's UI frameworks for a real product. It's either QT or Avalonia or something. Who would ever trust their newest framework when every prior framework was abandoned half-finished and left to rot for years?
I imagine it's only my MOBO which is missing TPM, but a suggestion of what mobo to buy which would be compatible with all my other components (RAM DIMMS, PCI-e cards) would be killer.