Retiring Windows 10 and Microsoft's move towards a surveillance state
scottrlarson.com
scottrlarson.com
I would say that specifically with Secure Boot, Microsoft actually promoted user choice: A Windows Logo compliant PC needs to have Microsoft's root of trust installed by default. Microsoft could have stopped there, but they didn't. A Windows Logo compliant PC _also_ needs a way for users to install their own root of trust. Microsoft didn't need to add that requirement. Sure, there are large corporate and government buyers that would insist on that, but they could convince (without loss of generality) Dell to offer it to them. Instead, Microsoft said all PCs need it, and as a result, anybody who wants to take advantage of secure boot can do so if they go through the bother of installing their own root of trust and signing their boot image.
This was not the case with the initial rollout of Secure Boot, it was combined with locked BIOS to lock PCs so that they could only boot Windows 8 on some devices. This was the case on Windows RT ARM machines from that era.
All that has to be done today for machines to be locked down again is to flip a bit or blow an e-fuse. It's already the case on phones and tablets.
There is also a real potential for abusing TPMs or cryptographic co-processors to enforce remote attestation.
I say this as someone who agrees with your first paragraph and uses Secure Boot + TPMs on all of my machines.
People here REALLY need to start understanding this issue. Remote Attestation is the kind of tech that if abused will end free computing over night.
Okay, but, that was like 15 years ago, on some shitty first-run computers that no one bought. A failed first attempt. I've never met a single person that owned, or has ever used, a Windows RT device.
The world has moved on. But oddly continues to buy bootloader-locked iPhones and Androids by the bucketful.
Dwelling on the past isn't going to move us forward. Anyone pushing the "Secure Boot and TPM are evil" trope in 2025 is objectively a fool and should be ignored. Most don't even realize what a TPM does, they think it's some secret chip inserted by glowies into their computers to prevent them from running free software. No.
Remote attestation can be misused, yes. But why writing it as TPM is the problem? In cases where remote attestation is used for good, TPM improves the setup, if anything.
I dont see the rationale for what you wrote, and am genuinely curious what it is.
Being able to install another OS isn't much good if critical applications and websites refuse to run on it.
The battle has already been lost on this. Just look at all the companies that are app-only and don't offer a web version.
If it’s on my computer, I should be allowed to read and write to it. End of story. I don’t care if that makes it vulnerable. So far as I’m concerned, letting Microsoft keep secrets from me on my own computer is similarly catastrophic to losing my HD to a crypto-locker virus.
This is exactly what a TPM was made for, so your statement is a little bit paradoxical.
There's no issue booting a boot rootkit with the standard Windows bootloader unless you manually seal the image with command line or group policy, and even then it's possible to bypass by installing a fresh bootloader because the images are identical and will boot after a wipe.
This. It is secure only for MS, AMD or Intel.
I had a Win 7 system and just entered a password on boot, this decrypted the disk. It was supported without mods or TPM (maybe some registry tweaks though). On Ubuntu I do the same, no need for TPM. Am I missing something? My disk is encrypted. If they take it apart, they need my password to crack the encryption.
With a TPM you can set it up that your disk is unlocked automatically, but only if no-one changed anything in the signed boot chain. This is the default with Bitlocker on Windows and is also possible on Linux, though somewhat more finicky.
You’re not protected from an evil maid attack. An attacker with physical access could make your device boot their own payload to capture your encryption key and install a rootkit.
https://linustechtips.com/topic/1610033-hp-charges-for-warra...
Let’s not give Microsoft too much credit here…
Between 2011 and 2013, multiple Linux / free software organisations raised the issue with the EC. There was an actual antitrust investigation which at the time was seen as what motivated Microsoft to open the solution to third parties by 2013.
So in a way, thank you EU for making it so we have choices at all.
With that said, I think the technology still does more to promote vendor lock-in and as others have said, it’s one windows update away from a dystopian hellscape where all your bits have been pre-approved by someone else.
I don't see how my TPM module will prevent me from using the machine the way I want. The offer of a cryptographic assurance to a 3rd party is something I happily provide in order to gain access to a competitive gaming resource. Cheaters really fucking suck and if this is what it takes to ruin their day, then fantastic. I'm looking forward to TPM3.0 now after seeing how ruinous this has been to their schemes. These tools are effective.
Battlefield 6 is especially problematic for malcontents because its developers also enjoy using statistical methods to detect cheaters. TPM2.0 + statistical methods + $69.99 per try = probably can't afford to play this game unfairly for very long. Even if you can afford it, the in game progression takes an eternity. You're gonna need that 8x scope if you want your "undetectable" frame scanning aimbot to be of any use.
I guess people don't know this particular dystopia is implemented.
First a platform gets third parties (games, banks, etc.) to impose their attestation system on customers. Congrats, you're locked in! This is the gun they point at you but the bullet comes after.
Now you can't leave the platform or you lose all your games, have to get a new bank, etc. The more stuff they can get to require that, the more stuck you are. This also prevents any new competitors from building a network effect. But competition -- the ability to switch to a competitor -- is the only thing stopping them from being the worst people in the world. Ads in the start menu. Censoring whatever they don't like. If you want to buy something -- anything -- they want a 30% cut. They'll hide it from you but take it anyway. All your local files get uploaded to their cloud and the terms let them use it for AI training, or whatever else they want. And soon you have to pay a monthly fee if you don't want them to be deleted. Why would not paying also delete them from your local machine? Because screw you, you don't have a choice anymore.
"Your version of TPM is unsupported. Please update your hardware to enjoy playing Battlefield 7". Your 69.99 per try just went up to 769.99 _for legitimate users_ because you need a new CPU with updated TPM for every new version. I'm being hyperbolic, but only slightly.
If you want a real example of this, Windows 11 requires TPM 2.0 to run. Hardware predating wide TPM2 adoption can be powerful enough to run Windows 11, except the company decided you need a new computer to do that.
This is overkill for a feature that is only relevant to one specific usage of PCs. Imagine if your PC got crippled because farmer IT admin benefits from it
I think this is very misleading. Secure boot was a response to the poor security of commodity operating systems which allowed programs easy access to make low-level system modifications. In other words, the poor security models of commodity operating systems was the actual cause that allowed rootkits to spread and become a major threat that required mitigation.
In an alternate world in which operating systems enforced least privilege on all programs, the likelihood of a rootkit spreading would be orders of magnitude smaller, almost not even worth mentioning. The motivation for secure boot in this world is really only to prevent supply chain attacks, which can also be solved by just buying hardware from reputable companies. Secure boot arguably would not have been created in this world, thus avoiding the new dangers inherent to it.
Also remote attestation has pro-social uses. Without it, photographs will soon become useless as evidence because soon there will be no way to distinguish a photo of a real scene from the output of generative AI.
Now with remote attestation they do.
> installing their own root of trust and signing their boot image
Won't matter. They can tell we did this. They won't trust our keys. Only their own.
Yes, they did. It was written by the specter of the US Department Of Justice.
Secure boot is a rootkit.
But now, after more than two decades, I am certain Windows 10 is my last Windows.
Nothing lasts for ever, not even Microsoft's domination on personal computers. It took them decades, but now they finally f'd up so bad that there is just no going back.
I think, like many people, it will take me few years to need to reinstall my computer(or get a new one). So I will still be a Windows user and that will skew the numbers for upcoming years. But I think that also means that in 1-5 years, Microsoft will see a massive double digit percentage drop of users, almost over night, and nobody will have a clue what is going on.
By then, I bet the distributions will be even better. The gaming will be event better. The drivers will be even better. The saturation will be even better. So the transition will be even more seamless than it is today.
I am looking forward to it. I think Linux, or open source and free OS, should have been the norm. But we took a bad turn in the past and got hijacked by few smart people. That will come to a natural end, finally.
Biggest pain point actually are not programs, but the need to format all hard drives to some linux file system. I cannot just replace windows with linux and that is it. No, I have to migrate all my data somehow to reformat all my drives and then move the data back. That was always huge pain in the ass.
I tried Bazzite for a while on my desktop, it's fantastic for gaming, but I'm also a dev and a Linux user since I was a teen (almost all of the years of Linux) so I found it a little limiting for my other PC related stuff (I typically prefer to run Arch and Arch based distros on my machines).
For anyone with a computer dedicated to gaming I'd recommend Bazzite, I still run it on my ROG Ally since the moment I took it out of the box; I bought it _because_ Bazzite existed, never even considered booting Windows. It's a great distro tuned for gaming, and comes with some features like VRR and HDR that aren't as easily available on other distros (I've been able to get HDR on Arch/Gnome but not VRR).
It's hard for someone who relies on Windows software to be entirely rid of Windows, which is why I don't tell people they should switch to Linux, but it's not impossible if you really want to, unless you rely on a piece of software that just won't run under WINE or doesn't have an alternative.
For me, I grew up with Linux alongside Windows, went into a career that uses and targets Linux exclusively (backend SE) and for my computer based hobbies; gaming, coding, 3D printing/modelling they're served very well these days, and constantly improving.
I ran into that problem on DS2 also. It seems that game picks the first input device it finds, so I was able to force it to use the controller by unplugging my keyboard (or maybe it was the mouse? It was one of those).
I recently got into playing Helldivers 2 with some family members and luckily for me it works just fine.
My opinion is that Linux gaming is most suited for majority single-player gamers like myself.
This has a good list of what works and what doesn't: https://areweanticheatyet.com
This is like saying you won't stop smoking because then you might get less cancer.
My way of switching over was to set up my system as a dual-boot, and then to set up my Linux in a way that enabled as much of my needs as possible. I got overwhelmed at first multiple times, but realized later that I'm just resistant to change. After a few tries, it stuck, and instead of feeling overwhelmed with change, I felt relief that I don't have to deal with Windows, and all the corporate bullshit that comes with it. Instead I have the vibrant culture of free software, and all the bullshit that comes with that, hehe. And I take that anytime over the former.
I'm also using KDE btw. I think it's by far the best DE, for me anyways. Fun fact, Valve's Steam Deck also uses it.
The reason Windows (and Microsoft itself) is not 6' deep yet is a relatively small number of commercial creative software like DAWs, graphics suits and CAD modellers. Yes, there's a huge amount of legacy software in CAM, plant control and whatnot, but that can run alright on all those Windows XP and 7 machines like forever.
All major software vendors who think that Windows has too much inertial following and that its users will embrace whatever fascist surveillance machine their computers become under this abomination of OS, and refuse to port their products to Linux, will be in trouble soon.
Out of all DAW developers, only Bitwig got this trend right yet.
At this point, I need a nice gpu on a linux machine and a mac mini. It is a dream setup. I think I booted windows once on my most recent laptop because I messed up booting from the thumb drive to blow it away.
Reaper runs incredible on linux for DAW software but you always run into something that is not available with creative software. Then it is really nice keeping the mac only for creative pursuits.
Google is likely actively working towards a future where all of those programs run on a browser.
You don't want the migration to be harder than it should be, and doing everything at once is way too hard.
But on WinME that was complete trash.. Never has an is crashed so much on me... I went to Win2k after that ... Win2k was the last windows I ran in a PC and was IMO peak windows.
So I have to decided to promote Linux over Windows for computers I build for customers. If you have any suggestions on how I can make this promotion, better let me know.
The business customers might want to know that databases are a lot cheaper on Linux, especially for small business.
Literally spoke to an automation company the other week that told me "we have to delete a bunch of stuff every time the database gets near 10GB or we'll have to pay Microsoft".
Plus there's no license cost for linux itself either.
This stuff might not be viable for hundreds of employees in a business where MS is already entrenched, but for a small business it absolutely is a better deal.
Probably an unpopular thing to say here, but in my experience pushing non-tech people to use libreoffice as part of a Linux transition is a fast track to getting them to hate Linux.
Using Google Docs has been much more welcoming in my experience. Something about libreoffice doesn’t resonate with a lot of non-tech people.
As an example, I recently submitted a manuscript following standard format [0] with libreoffice. Nothing difficult, just basic professional functionality.
The only way to do it involved editing global default page styles (because custom page styles can't be used for title pages?) and other advanced features. Fair enough, at least it was possible. It's a shame the export process didn't preserve the formatting and screwed up page numbering.
I had to fix the manuscript in gdocs instead, where it was easy.
Examples: [1] I selected a range of cells recently, by clicking and dragging, and when I let go of the mouse button, all of the selected cells shifted up and to the right by one cell, and CTRL-Z didn't undo it! [2] I have a workbook and when i duplicate a sheet with a chart, the chart is blank, so i have to delete it and re-insert a new one. [3] Sometimes the left-hand X-axis is cut in half, and I have no idea why, but if I create a new doc it goes away. I really, really want to promote LO, but it is very buggy. I can deal with it but I don't think others would.
I run firefox+UBO+privacy badger on my machines, and the only sites I've had to disable my privacy extensions in the last few years for were work related, B2B SaaS apps. A few years ago I pushed UBO to user machines (Chrome on win10) at work, and had a ton of user issues. I finally had to disable it, it wasn't a net benefit to us. It's not just a 'turn it on and leave it alone' thing, and people don't always think or remember to try toggling it off and reloading the page when they encounter issues.
That said, it's insane to me to be paying MS for a database with a 10GB limit, but I've seen their price lists. I've also worked with small businesses that don't have in-house IT, and they just end up overpaying for crappy service for many of those things.
I hope this win11 migration causes more MSPs and consultants to move small businesses over to linux though, MS has been predatory on pricing for business customers for far too long and with as much work has migrated to a browser there will be way less issues switching than there were years ago.
It's time for change. VMware have tossed themselves off into limbo and MS seem hell bent on alienating a vast swathe of humanity with W11's requirements - weirdest A/B test ever.
I'm working on some bigger clients ...
IMO, if they need Office, they should just use Windows.
IMO, if a user's needs can be met with a Chromebook, Linux + a browser + email + Zoom/or whatever would suit them well.
I think you're going to have a hard sell if they rely on Office or other Windows-only software, and although well meaning, it might be doing them a disservice if they can't run the software they're accustomed to.
I think this is even more true in the era of LLMs, because on the rare difference somebody might get hung up on - there's no longer real need for support. LLMs absolutely excel at questions like 'In MS Office I can do [x] to achieve [y]. How do I do that in Libre Office?'
Why wait for mass survellience and remote attesention when u can have it today!!! :D
Create a 'showroom', virtual through network screen sharing or physical if possible. Demo machines where you can let customers get a bit of immediate experience with GNOME, Xfce and possibly something more. You can walk them through checking their email, creating a document and doing a bit of web browsing.
Don't front 'Linux', it's a tainted word that is of no use to typical public sector and small to medium business people, preferably don't mention it. Instead talk about your solutions being secure, cheap, enterprise grade, customisable, long term supported, things like that.
The Linux choice matrix is confusing even for programmers. Like I can understand the pieces in theory, but in practice with hardware, user-installed software, varying degrees of compatibility between components, and updates...
Ever.
Forever.
I avoid snap myself because I use apt, but apt is a hard sell and arguably not ideal as well. E.g. I added Spotify repos which in theory could break other packages. In practice this doesn't happen (probably due to Ubuntu essentially freezing major versions for packages in their releases).
if you promote, facillitate, provide resources for installation free of charge, thats probably fine. providing a system for sale, with linux pre-installed, may require, at least some attribution.
We'll have a few macs and 2 win11 machines, but the rest are getting migrated.
We're in the Google ecosystem for email, docs, and drive so I'll just deploy Chrome instead of a Libre chromium. I'd rather not troubleshoot user profile issues, and they have access to all our data anyway. Honestly, I fully expect I'll have more than a few users that don't even notice the OS change.
The UI in LibreOffice feels quite clunky and outdated and never seems to have been given any thought since the OpenOffice days. But Google Docs is so feature poor that I'd rather live with LibreOffice's UI. Especially as you can adjust to the latter after using the software for a while.
Things that intrigue me:
- For photos, darktable is surprisingly good. I think this was my biggest single surprise, being a Lightroom user.
- GIMP was always great and now it's even better.
- LibreOffice is good enough that I can live on it just fine. I do miss Keynote, but it's not a showstopper.
- Dia is good enough for diagrams, though I miss OmniGraffle.
- Notice how there aren't any Windows apps I miss. There are Mac apps I miss (Keynote and OmniGraffle).
- Anything involving the web just works.
- Suspend/resume on my Linux laptop works better than suspend/resume on Windows, but not as good as what you get on Apple M hardware.
- Battery life on my Linux laptop is better than on Windows, almost entirely because Windows wakes the laptop up while it's suspended, so if you close the Windows laptop and carry it around unplugged, you'll find that the battery is totally drained after some number of hours. Linux doesn't have this problem.
- Development workflow is amazing. I'd rather program on Linux than anything else.
- The lack of crapware and nagware is so amazing.
- Similarly for Photoshop users, Photopea might suit them better than GIMP. And there's also Photoshop Express/Online if they really want to stay in the Adobe ecosystem.
I like OmniGraffle but personally I didn't think it was worth it when draw.io was free anyway. Like I don't feel it was $150-$250 better than draw.io, especially since it's not cross platform.
For adding shapes/colours/annotations etc to photos, I found krita to be more accessible than gimp. E.g. I wanted to do changes to my contractor's realistic concept drawings and I could learn krita (guided by Claude Sonnet) and make the changes in a span of couple of hours.
Install Fedora with KDE.
Install Firefox, Thunderbird and Chrome.
Install uBlock Origin, Privacy Badger.
Install LibreOffice & bookmark Google Docs.
Install multimedia support, h264/h265, VLC/mpv/ffmpeg, enable DRM in browser.
Install Steam if applicable.
If they have a printer, connect it and show them how to print a page.
Configure & tweak KDE to be cleaner & more user friendly (its already near perfect out of the box). Show them how to manage wifi/lan connections.
Stick with Intel & AMD hardware, Nvidia drivers breaks on most kernel updates (and it messes with luks/secureboot/dracut). Intel & AMD, Just Works.
Educate the user on how to do Software Updates, install/remove software, how the file explorer works, maybe some terminal stuff if they seem inclined. Give them a high level overview of the benefits of linux.
With Fedora and KDE you can accomplish 95% of your computering needs, including software development. Only a handful of games & creative softwares don't work.
It will only take 6 months to have them permanently converted.
Also, how are the graphics drivers affecting LUKS for you? They are two independent and unrelated things for me, Nvidia drivers aren't doing anything disk or pam related
> If they have a printer, connect it and show them how to print a page.
This however is the thing that doesn't "just work" for me, even with a common hp printer. The one time in a year you need to use the printer, something will have broken about its drivers again in Linux. I just transfer the pdf to the printer with a USB stick now
Furthermore, last time I tried printing, it was a surreal non-deterministic process. It wouldn't print, then it would, then it would get stuck in a handshake or something, rebooting wouldn't fix it, but rebooting twice would, then turning off the printer would break it again, and so on. No system update in between attempts. I genuinely want to know what the fuck the engineers for those machines are doing.
[Disclaimer: in the above process there was the extra hurdle that the printer was one of several on a local university network that may also have had cooky configuration]
Immutable/atomic distros are rock solid and extremely hard to break, the automatic updates/upgrades are a godsend for newbies, and in the rare event something does break, you can boot directly into the previous version right from the boot menu - no command line wizardry required. Immutables also don't suffer from the dependency issues that can sometimes plague regular distros, so I would highly recommend them over a regular distro for most newbies.
Sorry to tell you that, manual updates are not a thing your average user is familiar with. In Windows land, updates install themselves
Maybe because it's Windows Pro, not Home? Maybe because I have 2 profiles. The one I used to install it which required a microsoft account, and a separate, local only account which is the one I use always. I can't remember the last time I had to use the other account. Maybe when I upgraded to Windows 11. I don't remember.
I'm not trying to excuse Microsoft. I had to go into settings and turn off everything I could find. I had to futs around to get it to stop trying to get me to install Exchange every time I pressed Win-E (or was it Win-W) which I press often because I use the same keyboard on Mac and Win-W is Cmd-W (open new Window) (A: Powertoys). So yea, I cursed that. But, I found a solution.
Other than that, so far, it stays mostly out of my way and just works. I'm hard pressed to notice too many differences. Is it because I'm on Pro? Is it because it's a local account? Is it just luck? I don't know. It only suggests that it's at least possible, so far, to use it.
* Needing internet and a microsoft account to install the OS
* Start menu now requiring two clicks to get to programs list
* Right-click requiring two clicks to get to the options you most likely want to use (e.g. 7z unzip or opening in a specific program)
* Task manager being slow and laggy
* Random ads asking you to install a game pop up in the notification area
* ...
And then there's little bugs everywhere that just grind away at you on a daily basis:
* A tab in explorer will sometimes randomly stop accepting clicks (keyboard select works). So I have to close the tab and re-open
* The keyboard layout setting gets corrupted and there's no proper way to reset it (nevermind the fact tha this setting is now burried twenty levels deep in the new settings app)
* The settings app search does not work
* ...
It is by far the worst Windows version (beating Vista and ME to that title) in my opinion. I use linux as my daily but am forced to use Windows at work and they have of course been forced to upgrade us to Windows 11...
Right-click requiring two clicks to get to the options you most likely want to use (e.g. 7z unzip or opening in a specific program)
This one you can still change. It is some hidden registry tweak, but there is the capacity to always "show more options".When I create a new folder or file in a directory in explorer it hangs for a bit and doesn’t show up unless I click refresh. Ditto if I save a file to a directory that is open in explorer.
Thinking about trying to get a copy of Win 10 IoT LTSC instead at this point.
* A microsoft account is only needed for Windows 11 Home. A "semi-power user" is hopefully not using that edition of Windows...
* I'm also greatly annoyed by the right click - but holding shift when right-clicking opens the expected menu, removing the extra click requirement.
Some of my own annoyances though:
* The taskbar/windows button seems to just...crash...sometimes. It'll eventually restart, but extremely annoying. Left clicking taskbar icons still works, but right clicks or the start button don't work as expected.
* Additional clicks to change audio devices...drives me crazy on my main system.
* I like the autosaving aspect of notepad, but they've killed the main reason I used it - an instantaneous, lightweight text app. It's still quick, but is noticeably slower.
* Settings and Control Panel is still a mess, and even less usable than Windows 10 was.
And wsl2 is mostly fine. But that doesn't stop the rest of the OS from being a dumpster fire. Why is it asking me to install or play Xbox games constantly? It feels like I have malware...
Windows 10 eventually breached my capacity due to the number of defaults I had to change post installation, and then often, again, post-patch/update. This was very soon after Windows 10 was released, and I already didn't like Windows 8's hybrid monstrosity following on from the sublime Windows 7, which I consider to be peak Windows.
I moved to Pop! OS and have been enjoying it on both desktop and laptop for over 5 years.
The PC also had Win10 before Ubuntu, and I remember that being way worse because of the constant updates which always triggered more nags and resetting my default browser.
I thought that was not possible
See this for all OSs/platforms: https://gs.statcounter.com/os-market-share#monthly-200901-20...
See this for Desktop OSs: https://gs.statcounter.com/os-market-share/desktop/worldwide...
They are on a slow death spiral. Their solution to raise revenue when their marketshare goes down is to squeeze harder. So they lose more users and the vicious cycle continues. In 10-15 years, they'll dip below 50% of marketshare, at which point there will be various alternatives which will accelerate their downfall. This already happened in tablets/phones.
It might also happen faster since they have a stronghold in Asia and China is now looking to accelerate the building of alternatives.
https://cdimage.debian.org/debian-cd/current/amd64/iso-dvd/d...
There are several options for desktop environment, and you can select which ones to install when you boot that installer image (and also add/subtract more later, and change your preference at login time).
One of the nicest-looking ones that should be self-explanatory to use (for anyone who's used any version of Microsoft Windows since 95) is Cinnamon. Most of other desktop environments default to similar, except for the current default Gnome one, which is a bit more creative in a way that's not intuitive.
The Cinnamon desktop will use a lot of that Gnome stuff, but things like a start menu and task bar will be more familiar than the corresponding elements of the default Gnome desktop.
I like the fact that it has done a lot for the linux ecosystem, but there are a few things:
- it has a privacy policy
- it forces updates
- their hardwired package ubuntu-advantage-tools cannot be uninstalled without breaking the os
- motd has telemetry and nags
- can't disable snaps
- whoopsie uploads crashes to canonical
now, this is different from windows because the os is mostly open source, but it is important to know not all linux distros are the same
(note that because the source is generally open, you can probably figure out how to "fix" most of these problems, but not easily and they are moving targets)
I also have a good out of the box experience with Zorin (an Ubuntu-based distro). Their goal is to be an alternative to Windows, to make the transition smoother for people coming from Windows. I wanted to test that and just installed it, never used the command line, etc. It feels nice and did everything via a graphical interface I wanted out of a desktop system.
>I think holds some non-technical people back.
That might seem like an issue, but what matters for adoption is what is packaged with hardware, and what gets support later. Microsoft realized this and capitalized on it big time, and that's why the de facto default PC is Windows. Microsoft took care that governments, schools use Windows and Office, that Windows comes bundled with PCs and laptops, meanwhile they took care that it all interacts at least on a basic level, but at least somewhat reliably.
The problem is not that they exist or that Windows 11 supports them. It's that Microsoft pretends they are required, when they are not.
I think that's what "artificial limitations" mean. Microsoft pretending they are required when they are not.
They can also often be used as a (slow) source of hardware randomness.
Most modern intel (seris 8 onwards) and AMD Zen onwards have fTPM too. Often these can be enabled in the bios during upgrade then disabled again.
Personally I upgraded to Win11 the moment it became available, but that's because I want to continue my run of free MS windows forever and I only ever boot into it to play games, with even that becoming less common.
But it's kind of MSFT's choice whether TPM and secure boot are requirements for their software. If their software makes security assumptions that the OS has access to trusted hardware then it's a requirement. One could argue that they should create secure and less secure versions of Windows, but I don't think anyone is really going to take that seriously beyond rhetoric.
There are a lot of advantages to assuming the hardware is mildly trustworthy. The downside is you may not want Microsoft to be controlling what counts as trusted on your machine. If so, then you probably don't want MSFT to have root in your machine either and you're better off with a different OS.
In an IT security context, "trusted" (example: "trusted computing") means distrusting the users.
If you want to add better security to a computer make it opt-in and not expect people to use it who don't need it.
TPM also enables things that average users care less about like DRM, but Passkeys are a good idea and having them more-secure-by-default is good for the average user (even with accidental vendor lock-in implications).
There are security boons, sure, but these are a side effects. They are not what TPM is for.
Oh, yeah, this is absolutely perfect. Thanks again, that's amazing! It was really the only thing I wasn't sure about upfront for the person I'm thinking of. So awesome :D
But of a bait and switch from that to the actual article title…
> Retiring Windows 10 and Microsoft's move towards a surveillance state
If nothing else adhering to HN’s guideline on titles would have saved me having to suffer through reading “recomming.”
Use-case is:
* Dual-boot where I choose in BIOS/UEFI to go to either the existing Win10 drive or new Linux drive.
* I don't need unattended boot at all, I'd rather enter a passphrase every time.
* Resistance to evil-maid attacks is nice but not top-priority compared to theft.
* I want to be able to take my drive out of a dead computer and access it elsewhere if something goes wrong, as opposed to needing to reformat and reload from backups.
* If I install a distro with secure-boot off, can I turn it on later for benefits, or vice-versa?
Just put linux's boot drive on a removable USB that has boot priority over the builtin drive. Then configure UEFI secure boot so that it works for both windows and your custom keys.
https://wiki.gentoo.org/wiki/User:Sakaki/Sakaki%27s_EFI_Inst...
This setup has the added benefit of making it so that windows can't overwrite your linux boot drive, but from linux you can still access your disk from disklocker
So for it to be effective against the evil maid, you really need to bind the LUKS key to it. But you can do that _and_ set a strong PIN for your LUKS key.
1. Your data on the drive/partition is encrypted by $BIGKEY, which basically never changes because that would require redoing everything.
2. The LUKS header stores one-or-more encrypted versions of $BIGKEY, generally encrypted using a more convenient $SMALLKEY that a human could memorize. Optionally, $PIN can also be part of the encryption step.
3. Unlike $BIGKEY, the $SMALLKEY and/or $PIN can be changed over time. This changes the ciphertext of $BIGKEY and rewrites the LUKS header.
4. Optionally, secure boot is capable of storing and retrieving $SMALLKEY into system chips in such a way that most tampering ought to destroy $SMALLKEY.
> So for [Secure Boot] to be effective against the evil maid, you really need to bind the LUKS key to it.
If my $SMALLKEY is not stored inside the secure-boot chips, I can see how that would be inconvenient, but I'm not sure how that is safer.
Is it because the route $SMALLKEY automatically travels bypasses tricks like a hardware keylogger?
Your drive does need to support OPAL though, check out sedcli for managing SEDs.
You can set HDD/SSD password via the BIOS/UEFI or (my preferred method) using HDPARM —SECURITY commands.
Then if you take the drive out you can unlock it from another computer so as long as you plug it in directly and the UEFI supports HDD/SSD unlocking during post; if not you can install a Pre-Boot authentication on the drive that runs Linux to unlock the drive and then once unlocked it with the PBA it re-boots and it works as a normal un-encrypted drive.
Look into HDPARM and OPAL standard for full disk encryption.
Other than that, FDE and Secure Boot are unrelated.
The board's UEFI will boot the EFI binary that is either your kernel + initramfs (UKI binary), or a bootloader of your choice that then boots your kernel + initramfs. Depending on your distro, you may have a bootloader like grub or systemd-boot that is already signed by the MS third-party CA and your board may already allow the third-party CA, in which case you don't need to generate and sign with your own keys. Otherwise generate your own keys, set up Secure Boot with them, and then figure out how to sign your UKI binary / bootloader binary with those keys.
This initramfs will then be responsible for locating and mounting your root etc partitions. For a systemd distro using the UAPI Discoverable Partitions spec (use a specific type ID for the root partition), systemd has a builtin cryptsetup target that will prompt you on tty to enter the LUKS password for that partition. Otherwise investigate your distro's initramfs options for doing that.
>* Dual-boot where I choose in BIOS/UEFI to go to either the existing Win10 drive or new Linux drive.
grub and systemd-boot both show menus to select one of the available EFI binaries to chain to. Otherwise your UEFI might give you a similar menu.
>* I want to be able to take my drive out of a dead computer and access it elsewhere if something goes wrong, as opposed to needing to reformat and reload from backups.
Any other PC can mount and decrypt the drive with cryptsetup just like your original PC could, as long as you specify the same password.
>* If I install a distro with secure-boot off, can I turn it on later for benefits, or vice-versa?
Yes. You will launch board's UEFI, set the SB status to "Setup mode", boot your OS, then generate and enroll new keys which will set the SB to "User mode" and start enforcing signatures on next boot. And if it breaks you can set it back to "Setup mode" in board's UEFI, boot the OS and troubleshoot / re-enroll keys. The OS wouldn't care that you had previously enabled SB but are now booting with SB disabled.
Note that Secure Boot != Measured Boot. With a standard Measured Boot setup the disk encryption key is protected by secure element on the board (eg TPM) measuring the boot chain, so your disk will automatically decrypt when the boot chain matches the previous measurement and automatically fail to decrypt when it doesn't match. Your concerns about failing to decrypt the disk apply to this setup, not to SB. But also LUKS-encrypted partitions can have multiple keys to unlock them, so you can have both a Measured Boot-guarded encryption key and an emergency fallback password to unlock the disk manually.
-unable to execute a clean chip-architecture transition (while Apple shipped three clean ones)
-unable to modernize its operating system consistently (5 layers of different UI/UX and 30 years old DLLs spread all over the place)
-unable to harden its own software
-unable to design its own hardware
-unable to keep users's data secure
I could continue, but the pattern is clear
I will never store personal or government issued documents on a Windows device and I will never use any form of digital ID to login on infrastructure that depends on Azure AD
TPM, Secure Boot, Windows Update stories are the evidence that the more you entrust Microsoft, the worse it gets
Linux users can install the free software suite LibreOffice, which not only replaces Office but reads and writes the same file formats. Many similar choices exist, this is just one.
Gamers can install the free Steam game compatibility layer on Linux, then play many of the same games they play on Windows.
Meanwhile, Redmond's recent requirement that everyone sign up for a Microsoft account, and its pushing the Recall eavesdropping-to-cloud feature with no user opt-out provisions, clearly signals Microsoft's belief that their customers should't be allowed to choose.
Here is a list of current Windows traits that should be options, but are out of an end-user's control:
* Required Microsoft account.
* User tracking and telemetry without knowledge or consent.
* OneDrive, which is cloud storage and tracking, requires technical skill to disable.
* Desktop-recall images to the cloud, essentially Microsoft mass surveillance.
* Edge browser, cannot disable or remove.
* Unintuitive user interface, out of user's control.
* Advertising everywhere.
All these frequently heard complaints are addressed by Linux, and Linux is free.
I've been a Linux user for 30 years. I maintain one Windows dual-boot system, partly to help friends deal with Windows issues, partly to entertain myself with what most people believe constitutes a normal end-user computer experience.
A bit of context -- my first computer was an Apple II in 1977, so my definition of personal computing might seem out of touch with modern times (https://www.atariarchives.org/deli/cottage_computer_programm...).
> contradicts the open nature of Linux
How do you feel about binary blobs required to run most WiFi cards in Linux? And, I am pretty sure that both NVidia and AMD have similar (binary blobs).> And, I am pretty sure that both NVidia and AMD have similar (binary blobs).
Yes, all true, and as more powerful GPUs appear, this is likely to become a more contentious issue.
So I say, choose where we have a choice.
That's not what Recall is and not how it works.
You're right, I overstated how Recall works, right now. At the moment, it's opt-in and the images are only stored locally. I was wrong -- my claims were several months out of date.
Recall's current form results from a heated online debate about its original form, which was neither encrypted nor opt-in.
At the time I write this, Microsoft won't allow users to uninstall Recall, a demand made by security professionals who see serious risks for non-technical end users in the event of a compromised system.
Having said that, let's revisit this feature some years from now. Let's see whether Microsoft's perennial corporate death-by-a thousand-cuts strategy has changed anything.
Those who chose Linux were happy with the choice. But they were only a minority.
Now, Windows 11 requirements make a lot of PCs obsolete unless they install Linux on them.
Try to identify the problems the customers have. If privacy isn't one of their concerns, convincing them to switch PC OS is not a great fit on that basis.
I feel like there needs to be some way to explain the changes to Windows 11 as hostile from a longevity perspective with the ads and the lock-in.. With one-drive being activated and moving customer data to the cloud without consent, the LLM that gets in the way of the user experience, recall, ect. It would still be their choice but at least they would know what they were getting into..
I feel like id be doing some justice by letting customers who qualify (who don't have use-cases that Linux cannot handle) know that its a better experience because Microsoft is creating friction in the desktop experience now..
Normies desperately want privacy, but think it is too hard to do, they're too dumb to figure it out, even if they figure it out it still won't really work, and that they won't be able to use stuff that they don't want to live without. They are often right, because they are smarter than they think and the industry is working against them full-time. A lot of people's incomes (on this very site) depend on keeping normies ignorant.
After evaluating a lot of options, pyQT + nuitka gave a reliable cross-platform result (can target distros based on Debian and Enterprise Linux easily.) And we are still able to target Windows for the customers that remain there.
[0] If "it [Xubuntu] works like Windows" offended you, I'd like to point out that normies don't care about how operating system kernels are designed. They care about things like a start menu, and that the X in the corner closes programs.
That said, for home use freecad has gotten a lot better after the ondsel changes were merged, I was using the free liscence of fusion360 for personal projects, and moved over to freecad 6 months ago. I'd originally tried it 7 or 8 years ago, and it was just absolutely awful to use, but modern versions are really very good. There wasn't a huge learning curve, and I haven't run into anything that the program can't do. For hobby CAD, I'm using it for 3d printing, a Cnc mill, and making prints for manual machining. Honestly, I've been less frustrated with freecad than fusion360, it does a better job of getting out of my way and letting me design things. That said, I'm a software dev and IT guy, I don't know if it would work for commercial use. I certainly didn't push for the engineers to change, but their workstations are already running win11 that I had to debloat.
On linux, you have OpenSCAD (which is okay for some applications) and you have FreeCAD (which sucks imo). Right now, I just use OnShape which works in my web browser and is similar to SOLIDWORKS (and it's $0 for students).
In the future I will try running windows CAD under linux using kvm and this: https://github.com/casualsnek/cassowary
I'm using Ubuntu as my daily driver for the first time since ~2010, and I'm solidly not hating it.
Thinking about other desktop environments and what not, but this was easy and familiar. Everything literally just worked... Which is the first for me with Linux.
I have a bog standard AMD graphics card that does not work in Linux. I've tried multiple distributions and version in those distributions and both the Linux and AMD drivers. It just randomly flashes. Where do I go to get help? Who knows?
AMD's kernel developers are incredibly responsive there, I've worked with them to fix a bunch of bugs I've run into.
I hear you though, I still have printing problems with my Epson WF printer.
This would seem to require a little elaboration. LibreOffice Calc is supposed to be decent, but I practically never hear about it being used in the professional contexts where Excel typically appears. I'd be willing to bet that it will handle all of the spreadsheets currently used at our firm, but that's a convenient case where only a small number of spreadsheets matter and I know how they all work. For anyone managing a larger ecosystem the switching cost is daunting. Some links to case studies or analyses of when Calc can take over for Excel would probably be pretty helpful, since as far as I can tell Excel is the reason people stick to Microsoft, while Outlook, Teams and Word are mostly just tolerated.
One issue I've always had is when updating applications you use every day, one bad library could make the application unusable. Most are a dependency nightmares and there just aren't enough people paid to work on Linux apps to offer good support.
When I was young and poor, I had all the time in the world to tinker with my Linux machine to figure to get everything working again. I just want an operating system to work. If not Windows, I would recommend a Mac.
That's not really a problem anymore with immutable/atomic distros. Your entire system is upgraded in one go as a single image, any dependency issues are handled on the server (basically the image won't get built if there are issues). And most of your user apps will be installed via Flatpak or other means (homebrew/Nix etc) so you won't ever have to suffer from dependency issues unlike regular distros.
So if you want to get a distro that "just works", get an immutable+atomic distro (eg Aurora, Bazzite etc). Assuming of course, you've got compatible hardware.
Some of the more annoying stuff like ads in the start menu and the like only really affect americans, as far as I know. I've never seen it. Had a brief battle turning copilot off everywhere when that became a thing - including in notepad! - but thats hardly just a microsoft thing.
Don't really understand all this drama over the TPM chip, especially since you can bypass that requirement with a little effort if you can't upgrade your hardware.
That being said, make sure to install printer, camera, and GPU drivers for new users before leaving your care (note iphone PhotoSync app also works with ssh.) Additionally, loading a suite of common Applications to replace web/email/CAD/publishing/media/gthumb/zoom tools will ease new users experience looking to complete some task.
Linux workstations are easier now given most services are web or App based. MacOS also tends to be easier for the people locked into Adobe =3
My mom got an automatic update to Windows 11, and it bricked her computer. It wouldn't boot; it would spin and then say it needed to go into repair mode, and then doing repair mode didn't do anything.
My initial thought was that the disk was hosed, but of course my parents had a bunch of priceless documents that were never backed up anywhere else, so I talked my dad through flashing a USB of Ubuntu so I could boot into it [1], mounted the NTFS partition, and ran smartctl and the disk wasn't reporting any errors. I found and ran a few other diagnostic commands and again, no errors. I was able to rsync the files to my home server, so nothing was loss. My initial assumption is that the Windows Update team didn't properly check to see if the CPU was compatible, and that maybe they were calling a newer instruction that wasn't on my mom's relatively old laptop.
After unsuccessfully trying to convince my parents to move to Linux, I talked them through flashing a USB drive with Windows 11 with an official image from Microsoft and using Microsoft's official disk flashing software, and we were able to install Windows 11, and as far as we can tell, it worked completely fine.
My hypothesis now is that whomever built Windows Update fucked up some kind of boot key and it was failing as a result. That or they just decided my mom should buy a new computer.
I was actually more annoyed after Windows 11 worked perfectly fine, not just because that means my parents aren't going to move to Linux, but also because that means that there's no technical reason that the computer should have been bricked, it was just the utter incompetence of Windows Update. Just to reiterate, this wasn't some hacked version of Windows 11, this was directly downloaded from Microsoft, flashed with their tools, with no adulteration on our end, meaning regular Windows 11 works fine. I highly doubt that my mom is the only person who has gone through or will go through this, and a lot of the people that will go through this won't have kids who are software engineers and probably be forced to buy a new computer.
Genuinely, how much e-waste is going to be generated by this forced update?
[1] Why the hell isn't there any kind of "Live USB" version of Windows? I mean officially, not some hacked thing? Why is the best way to fix Windows to use Linux?
The windows installer image includes repair tools (which probably wouldn't work much better than the automatic repair), and you can get a command prompt in there and do whatever.
Ideally I would want to use Linux but I also want to play games that are only supported on windows.
Does using WSL help or is an outdated windows base still going to be the weakest link in the security onion?
But you can always dual-boot between Windows and Linux. Just uninstall all your browsers (to mitigate risk) and other non-essential app in your Windows install, configure the firewall to block everything except games. And boot into Linux for everything else.
WSL2 is mostly just a virtual machine. All of its networking bugs aren't that weird, they are pretty common networking issues you'd see from any other virtual machine configuration. Depending on what you are trying to do, switching WSL2's networking mode to "Mirrored" can be a useful way to fix networking issues by more closely aligning the VM network stack with the host network stack. This is often the fix for VM networking issues in other environments, too. Things like the host's VPN get reused directly instead of the VM needing to run its own VPN copy, for instance.
20 years ago Ubuntu was the go-to for baby's first Linux. Is that still the case?
Unless you want to be the perpetual IT support for your parents, I would recommend getting a user-friendly immutable/atomic distro, like Aurora[1]. Aurora uses KDE, which most Windows users would find familiar. It is immutable, which makes it very hard to break, and it uses atomic updates (basically updates either apply or don't: there's no partial state which can break the system). And in the rare event that something does break, you can boot directly to the previous version right from the boot menu, no need to run any manual rollback commands. My 70yr old mother also uses Aurora and has zero issues.
Also: Almost all replacements for Excel are much worse, and incompatible with existing VBA macros that run a lot of HR, accounting, budgets, and other support functions.
Regarding Teams desktop app vs web app: Is there a big difference? I don't have experience with the web app.
I seem to recall : it would only work on Edge; and you couldn't share your screen in the web environment.
I say "only work on Edge" but, to be fair, it's possible I may not have tried Chrome as I never use it. It didn't work on Firefox.
As much as I agree with the article's general tone, uninstalling Copilot is actually quite straightforward and easy.
It’s still a bridge too far for most
The hardware landfill issue is real though. My 70 year old dad announced he’s getting a new laptop out of the blue. Reason…this
Can you fix?
Luckily OnlyOffice is a pretty decent alternative with excellent compatibility with MSO formats. And there's also the web versions of office, which is now a decent alternative (unless you're a power user who needs macros/VBA etc).
Linux isn't going to be any more secure than Windows was if everyone switches to it.
I say this as someone who uses Linux daily. It's simply not ready for mass exposure. The second a layman wants to do anything remotely custom with it, they are going to struggle.
It's the power users, or users who've got specific proprietary software/hardware requirements that usually run into issues: gamers who play games with kernel-level anti-cheat, professionals who're dependent on Adobe/AutoCAD etc.
Windows value to me was "everything just worked". But that's no longer the case now, unless you are willing to walk down Microsoft's centralized rails. Need an MS Account and OneDrive... need expensive modern hardware... get ads and crapware... get telemetry and data exfiltration. The effort of working around all that is non trivial. EDIT: and if I was ok with all that stuff I'd already by captured by Apple.
If I have to fuck around with something in my home OS, that OS might as well be Linux. So now I am compiling wifi and printer drivers from github (FFS Linux!) instead of disabling telemetry and hacking an install with local accounts only.
The challenge, as always, is going to be taking the family with me.
General public won't care until they can buy laptops with GNU/Linux on their favourite shopping mall PC store.
As it stands today they are more likely to buy an iPad or Android tablet than such alternative, which aren't much better than Microsoft in user tracking, and much worse in user freedom allowed by the OS.
Yeh, and it works great. Your point?
The Steam Deck hardware itself can run the original 32-bit libraries if your distro supports it, Valve wasn't "forced" to do anything. They chose WoW64 because it's the mature and functional solution.
It's my own opinion that windows enforcement of TPM while retiring Windows 10 is a rough direction, but I also get the executive decision. Support for old software is costly, and Windows 10 is very old at this point. Add that to how many security issues Microsoft has been having, and this seems like the only sensible decision.
Win11 is a hard no, I’m keeping a laptop with Win10 for the small amount of games I play. I will likely even try WINE for them soon but just haven’t got around to it.
Like, secure boot is not a bad feature, and I use it with Linux to enhance my security posture. It is a good thing. TPM is rather useful for encrypting your disks. Stop telling non-technical people stuff like this. The hypotheticals of a future of corporate control via TPM are completely outweighed by the importance of encrypting your data today. As of right now TPM isn’t enabling some kind of horrendous dystopian present. Maybe it will in the future but I dunno, I haven’t see it yet.
And then a lot of other parts of this article are gross exaggerations of reality, and a lot of those complaints already existed with Windows 10 users anyway. Some of these were actually worse at previous points in time (e.g., it used to be way more difficult to remove OneDrive and now it just uninstalls cleanly).
Windows Recall and Copoilot are entirely optional features that are very easy to disable entirely.
The author is straight up lying about windows recall and the “surveillance state,” Microsoft has directly stated that it is 100% local (doesn’t even work on hardware that lacks AI processing optimizations) and no information from the feature leaves your device. It also comes with a rather extensive list of security controls and sensible defaults if you actually read the documentation. Sure, a pre-release beta version had a security issue, but that was pre-release. If we want to start claiming that Microsoft is just directly lying about things they document very specifically and directly about Windows Recall that’s a really big accusation.
Windows 11 prevents complete uninstallation of features…yeah it’s an operating system, no shit. No they’re not going to let me uninstall File Explorer. Yes I know Linux lets you do that.
And the complaints about edge, sure, it’s true and all, but it is again a one-time issue that goes away once you change your default browser to some other browser that also begs you to make it default. It’s a minor annoyance at worst and judging by the marketshare of chrome everyone pretty much ignored Microsoft’s pathetic pleading. Everyone pretty much sleepwalks into installing chrome anyway.
Look, I say all this as a Linux user myself. There’s no need to exaggerate and lie about Windows just because we prefer Linux. I would still not recommend to most average joe windows 10 users that they should switch over to Linux, but I am recommending to more people than ever before.
And very easy for Microsoft to enable silently. Missing the point here. The fact that they are enabled by default is the concerning bit. You shouldn't need to fight against your OS or worry if the next update will do something to your system that you don't like. This is the crux of it all
There's no 'Recall'. Co-pilot isn't all over in your face so removing it isn't really a priority. Edge isn't forced on you, it's just part of the bundled software just like a bunch of other items as in every Windows for decades. Not saying it doesn't get hairy if you're going out of your way to remove them or not be in the ecosystem, but consumers don't care, and for the most part stuff isn't being forced in front of them.
a) the lock screen gets stuck from time to time if you hit enter to get to the password entry, until you turn off all the pushed content on the lock screen. Which ok, I'm happy I turned that off... but then I had to log out and back in for that setting to take effect. Now that I know about that setting, I turned it off on my windows 10 machines, and it takes effect instantly.
b) I like my windows round on the top and square on the bottom. It's cutting off the bottom left character in my putty windows; you used to be able to undo that in the registry, but now you need to force load dlls (maybe putty can fix it?)
c) I don't want notepad to have tabs or autosaving
d) it feels like keyboard focus gets lost to the ether a lot more. I had this happen in new style apps on 10 (like the new calc), but it happens at the desktop from time to time on 11.
I had been using linux as my main desktop at home for years, and went back to windows 7 when gnome2 ended. 7 was very good, but it's been downhill since then, especially since Microsoft killed off SDET roles. I'll probably keep windows on the laptops (useful for FRC), but when support for 10 runs out, the desktops are going to move to FreeBSD and I dunno, fvwm maybe?
If you’re measuring “Windows isn’t annoying” from the corporate perch, that’s not a fair comparison to what consumers and home users put up with.
Not to mention the forced upgrade and reboots that can’t easily be disabled for same.
Because now is the real push to get everyone off 10.
The hate is hardly unprecedented and indeed well-deserved. MS has shown in the past that they’ll respond to poor OS reception with attempts to win back customers and that’s what I’m hoping for in this case.
Rather:
2000: good
XP: decent (after a long series of patches)
Vista: bad
7: good
8: horrific
10: bad (basically all the people hated it because of the surveillance stuff)
11: horrific