182 karma · joined August 6, 2021
All opinions mine unless expressly stated otherwise.
That is an enormous "if". Do you think Microsoft is going to or is able to enforce this on every single software provider? Even in your Android example that's just not happening, and you can happily sideload apps. You can still develop your own apps on the same Android phone that you use for banking.
> And sorry but how many people have bypassed Playstations or Switches. This is what you’re talking about. Most people will just accept it.
People accept this with consoles because a console is a device exclusively for consuming media, and all developers apply for a devkit. I just don't see that happening in the PC space. You think Microsoft is suddenly going to dump this on third party software developers and force everyone to go through certification and to buy devkits? Without a mass exodus to Linux?
A TPM may only attest that it has received an expected set of measurements (hashes). As long as discrete TPMs or PCs with unlocked CPUs exist (w/o Boot Guard), one may simply take a TPM and replay "golden" measurements to it. Bypassing this would be trivially easy.
A TPM does not have control over execution on the CPU. It only receives data from the CPU. If you have control over execution on the CPU from the reset vector, you can just replay whatever you want to a TPM and extract secrets that way. That's why TPM backed disk encryption without configuring a PIN is insecure.
Microsoft does not have the same level of control over the entire PC ecosystem as Google has over Android. That's why it's important to support open source alternatives.
Disk encryption, Windows Hello and PIN bruteforce prevention. I have no love Microsoft and avoid using Windows whenever I can, but I think making those features accessible to more people is a good thing.
A TPM is useless for DRM, and there are way more suited solutions like Intel's PAVP that takes an encrypted video stream and puts it on the screen directly, yet I don't see nearly as much uproar about that.
I believe if given the tools, people would gladly donate their time to make something fun with it. Heck, that's what I do in my spare time. But it's impossible if everything is completely locked down, as if a music streaming box contains nuclear launch codes that must be protected at all costs.
Otherwise we're just manufacturing e-waste.
Likewise, demand and use cases for network boot exist, otherwise it wouldn't be here. Same goes for every other feature most users would consider bloat.
The fTPM does indeed run on the PSP, so on the ARM cores, among many other things like DRAM training.
If I wanted to mess with clients I don't like, I'd just return a random valid code.
If you want to you can just not save the recovery password. In that case I guess they'll just beat you to death with that $5 wrench.
I'm at the point where I'm not even looking for laptops with coreboot OOTB, I just want a good laptop that is not fused to the vendor's keys. I'll port coreboot to it myself.
> One more thing - how is the signal range for you?
With four 5dBi antennas it's sufficient to have >800mbps in every corner of my single bedroom apartment. Other than that I have no means to test, sorry :)
I'm happy with it, but I did have to get a heatsink for it, since otherwise it overheats easily. Since I got it they released a couple of dual-band dual-concurrent cards like this one: https://www.asiarf.com/shop/wifi-wlan/wifi_mini_pcie/wifi6e-... , which is pretty neat, since you don't need to get a separate card for 2.4GHz devices.
I honestly don't know why they bother with this PPPoE + VLAN setup on top of a modern fiber network, but it is what it is.
You could probably get an ONT in an SFP package, if you want to eliminate a separate box. The problem there is that ISPs tend to have an allowlist of permitted ONTs on the network. Some ONTs allow you to change the serial number so that may work in place of the ISP box.