New Win11 insider build blocks install on older hardware, prevents TPM bypass(tomshardware.com)
tomshardware.com
New Win11 insider build blocks install on older hardware, prevents TPM bypass
https://www.tomshardware.com/software/operating-systems/microsoft-patches-tpm-20-bypass-to-prevent-windows-11-installs-on-pcs-with-unsupported-cpus
7 comments
I always find these comments hilarious, because at some point Windows 10 will no longer have any security support. It certainly won't come as OEM with new hardware.
This is not a big deal. Most laptops have TPM 2.0, and most motherboards can have a dTPM accessory if they don't have it onboard.
Windows 11, has a lot of useful things, which 10 did not, for example DoH in the system resolver and a variety of other security benefits.
It's literally like people complaining if Windows doesn't work on old-BIOS only computers, it's not going to make much difference as nobody has those. If they do have those then a cut down Linux OS makes more sense as those devices likely won't have much RAM either to run a modern browser etc.
This is not a big deal. Most laptops have TPM 2.0, and most motherboards can have a dTPM accessory if they don't have it onboard.
Windows 11, has a lot of useful things, which 10 did not, for example DoH in the system resolver and a variety of other security benefits.
It's literally like people complaining if Windows doesn't work on old-BIOS only computers, it's not going to make much difference as nobody has those. If they do have those then a cut down Linux OS makes more sense as those devices likely won't have much RAM either to run a modern browser etc.
Do you also find it hilarious that Microsoft is making completely fine working CPUs on millions of computers unusable for Windows 11 ?
They will always need to strengthen requirements to strengthen security. In the past Microsoft has too heavily aimed for compatibility at the cost of security. This was pretty much their thing in the Windows XP days and everyone laughed at all the ways they screwed up.
There seems to be a clear focus on attestation and preventing persistent malware from taking root in a system's boot chain and potentially firmware.
https://learn.microsoft.com/en-us/windows/security/hardware-...
There seems to be a clear focus on attestation and preventing persistent malware from taking root in a system's boot chain and potentially firmware.
https://learn.microsoft.com/en-us/windows/security/hardware-...
So, I should abandon my laptop that I bought in 2017 and buy a new one???
> because at some point Windows 10 will no longer have any security support.
Just FYI, Windows never had any security "support". The fact that Microsoft releases some security patches, is just a fact. With Windows you, as an individual, were always on your own regarding security.
Just FYI, Windows never had any security "support". The fact that Microsoft releases some security patches, is just a fact. With Windows you, as an individual, were always on your own regarding security.
I've only been bitten by the TPM stuff when trying to run Windows in a VM, but annoying (and seemingly pointless in that particular case).
Some of us find people like you hilarious. We prefer a car that feels nice to drive. New one is safer but darn, it's no longer a car to me.
I’ve been reading comments like these since Windows ME. Vista was supposed to doom Microsoft because XP was the best. I don’t want to sound dismissive, but it’s a boring drop in the bucket. Windows will go on and get better.
>Windows will go on
undoubtedly
>...and get better
well that would buck the entire constant downward UX trend that has happened ever since data exfiltration became the actual revenue stream for Microsoft.
I get the "I hate new windows version Y" statements are getting old, i've been reading them for at least as long -- but it doesn't make the points that they extrapolate upon wrong. Windows has long been trending 'anti-user' , and has recently met a threshold that has thrown a lot of long-time users off the scent -- especially since other OSs have never been better/compatible/capable.
undoubtedly
>...and get better
well that would buck the entire constant downward UX trend that has happened ever since data exfiltration became the actual revenue stream for Microsoft.
I get the "I hate new windows version Y" statements are getting old, i've been reading them for at least as long -- but it doesn't make the points that they extrapolate upon wrong. Windows has long been trending 'anti-user' , and has recently met a threshold that has thrown a lot of long-time users off the scent -- especially since other OSs have never been better/compatible/capable.
Windows versions are like Trek films.
> Windows will go on and get better.
Well, we can probably agree on the first half of that.
> Windows will go on and get better.
Well, we can probably agree on the first half of that.
If Microsoft cares about the environment and becoming carbon-negative by 2030, why the seemingly arbitrary hardware restrictions that are pushing consumers to replace hardware that's still modest today?
Microsoft cares about creating end-to-end secure media delivery from the Hollywood to your monitor.
They always did, ever since the introduction of Protected Media Path (PMP) in Windows 2000, followed by tightening of the kernel access and now requiring the TPM. The end goal is to take away full control of the machines from their owners.
It's been a very long game for them, but they are almost there.
And then they will have fun.
They always did, ever since the introduction of Protected Media Path (PMP) in Windows 2000, followed by tightening of the kernel access and now requiring the TPM. The end goal is to take away full control of the machines from their owners.
It's been a very long game for them, but they are almost there.
And then they will have fun.
These media copy protection schemes remind me of web application firewalls. They're both digital snake oil, but huge corporations keep buying them.
It's absurd that I have a Netflix subscription, but the easiest way to watch Netflix 4K content on my PC is to just download it from a bay filled with pirates.
It's absurd that I have a Netflix subscription, but the easiest way to watch Netflix 4K content on my PC is to just download it from a bay filled with pirates.
>why the seemingly arbitrary hardware restrictions
HW restrictions are not arbitrary. TPM is a requirement for added security (Macs and smartphones also had TPM for a long time now), and CPUs before 8th gen don't have functional HW instructions needed for VBS (virtualization based security) which also adds to Windows 11 security hardening.
https://www.intel.com/content/www/us/en/support/articles/000...
https://learn.microsoft.com/en-us/windows-hardware/design/de...
HW restrictions are not arbitrary. TPM is a requirement for added security (Macs and smartphones also had TPM for a long time now), and CPUs before 8th gen don't have functional HW instructions needed for VBS (virtualization based security) which also adds to Windows 11 security hardening.
https://www.intel.com/content/www/us/en/support/articles/000...
https://learn.microsoft.com/en-us/windows-hardware/design/de...
Are they only implementing the additional hardening now? Or is it only required by now? Because obviously it worked before, so something must have changed.
Now? Hardening was in place since 2021 when Windows 11 launched. The HW requirement haven't changed since then.
But it was possible to circumvent it without any problem, which it won’t be in the future. That’s literally what the Article is about. So what changed?
The better question would be why they allowed the bypass in the first place since MS made the TPM and CPU requirements quite clear from day one, and why people are surprised the requirements are being enforced.
Well as far as I know there was no loss of functionality from the bypass, so either the requirement is completely arbitrary to deprecate old devices or there will be new features in the future that depend on the TPM.
Literally no one is going to throw away a working computer running Windows 10. There are still a lot of people running Windows 7. This is a nonsensical talking point.
A lot of people don't want to go without security patches. It's barely over a year until EOL for 10.
The vast majority of people still running Windows 10 won't even know what an EOL date is or why they should care. Businesses or anyone else who really cares can pay for the security fixes that will continue beyond 2025.
>The vast majority of people still running Windows 10 won't even know what an EOL date is or why they should care
Microsoft has been doing a lot in recent years to make people care, including (but not limited to) pop-ups near EOL that throw a scare into people.[0]
[0]: https://support.microsoft.com/en-us/topic/you-received-a-not...
Microsoft has been doing a lot in recent years to make people care, including (but not limited to) pop-ups near EOL that throw a scare into people.[0]
[0]: https://support.microsoft.com/en-us/topic/you-received-a-not...
Users are probably so use to dismissing all these pop-ups of things like the ghost of clippy trying to trick you into using one drive that they don't even know what pop up #6446 says.
Microsoft is putting a shiny new version in front of people's faces, with marketing about advanced AI features, security, etc, and then telling them their hardware isn't supported. Even if Windows 10 is still receiving security patches, your average person is likely going to have the fear of missing out on something great, maybe getting left behind in the AI race by not having Copilot. The logical next choice is to consider buying a new computer just to make sure they're running the latest and greatest, because Microsoft told them it's the only way.
If you spend a lot of time in tech circles, it's easy to get the impression that literally no one really thinks like this. A lot of us may think Windows 11 is mostly just a reskin with some integrated AI bloat that can be mostly replaced with just a bookmark to ChatGPT, but you would have a real hard time explaining that to an average non-techie. These decisions have significant effects on the choices average people make, and you can't just ignore it and assume everyone knows better
Considering there are around twice as many Linux desktop users as Windows 7 (according to Statcounter global stats), I would hardly call it a lot of people
If you spend a lot of time in tech circles, it's easy to get the impression that literally no one really thinks like this. A lot of us may think Windows 11 is mostly just a reskin with some integrated AI bloat that can be mostly replaced with just a bookmark to ChatGPT, but you would have a real hard time explaining that to an average non-techie. These decisions have significant effects on the choices average people make, and you can't just ignore it and assume everyone knows better
Considering there are around twice as many Linux desktop users as Windows 7 (according to Statcounter global stats), I would hardly call it a lot of people
They don't care, simple as that.
In the old days I remember various custom (unofficial) builds of Windows XP etc. that stripped it down to basics. And then that scene went away as storage and cpu became plentiful and it was simpler to disable various annoyances through the official means.
But I hope that scene gets revived if/when they get rid of local accounts altogether, and this would be another thing that would make custom builds attractive again.
But I hope that scene gets revived if/when they get rid of local accounts altogether, and this would be another thing that would make custom builds attractive again.
Custom builds still are popular to some extent, such as the options in Rufus to disable various things.
Maybe I'm out of the loop. Allowing local accounts after a hypothetical point where it's forced to be online seems outside the scope of that project. But I hope there will be some projects keeping local Windows going after that point.
FYI this is a Windows vNext build and the current placeholder name for its development branch is XY30H1. It is not launching anytime soon.
I am having problems switching to Linux because of my relatives and ignorant companies. One hard example is that all kids in my daughter school play roblox games, and roblox go to great extent to make sure you're on native windows without emulator or VM or anything. Baremetal windows only. I do not want to force my kid to be the weird outsider who don't play roblox with friends because of a crazy IT father. Because of my work I offc use enterprise editions and have AD at home with GPOs so no forced reboots and no online accounts and not ads etc, but if things start to get uglier my escape plan is to install windows server. As they say - It's not much but its dishonest work.
FWIW, Roblox, specifically, will run on a Chromebook, which is a Linux, though a non-traditional one, and may or may not be better for some people compared than to have a home AD setup.
My kid had to quit Roblox for that patch that forbid linux. Took him weeks debugging and although failing it was still a learning experience
I still can't enable the TPM on my AMD Zen 3 PC without getting random hitches (I've applied all firmware updates and tried switching to a hardware TPM), guess back to Windows 10 I go.
Consider giving desktop Linux a go. Linux Mint and Fedora Workstation are good starters these days.
Windows is a sinking ship.
Windows is a sinking ship.
> Windows is a sinking ship.
I got a kick out of Windows' responses to me installing Chrome on some machines at work.
First, search (good) Bing for Chrome. Get a sponsored result from MS saying something like "Oh, really, no reason to install that, Edge is x, y, z marketing bs, you should just use it instead."
Second, go to Chrome download page. Windows then pops up a notification bubble or something in the top right again extolling Edge, finishing with "and it's Microsoft Trusted!"
Thanks for the laughs MS.
I got a kick out of Windows' responses to me installing Chrome on some machines at work.
First, search (good) Bing for Chrome. Get a sponsored result from MS saying something like "Oh, really, no reason to install that, Edge is x, y, z marketing bs, you should just use it instead."
Second, go to Chrome download page. Windows then pops up a notification bubble or something in the top right again extolling Edge, finishing with "and it's Microsoft Trusted!"
Thanks for the laughs MS.
I mean... edge is chrome today lol, its just branded as MS.
I gave edge another shot last year, because it's just chrome right? Sure. That's what it started out as. Until MS middle-managers trying to get promotions added enough shit to onboarding that it repelled me back to Chrome
The AI spyware Recall feature was the last straw for me, even as I mostly use Windows for games and had no intent to go beyond Windows 10. After that announcement and kerfuffle I updated my PopOS partition and got my games working via Steam/Proton. Mostly drama free. Valve is really doing god's work here.
I use NixOS as my main driver on the same system (on a separate NVME drive) but I use Windows for gaming.
What kind of random hitches?
Random micro-freezes (less than a second), typically in-games.
Why does LTSC not have the same requirement? I could understand the IoT builds, but LTSC is made for user workstations I thought?
The Microsoft view is that LTSC is for "single purpose devices", more akin to appliances or embedded systems (https://learn.microsoft.com/en-us/windows/whats-new/ltsc/ove...)
Those tend to be shipped on some validated hardware that will take years to validate, then eventually gets approved for use, and won't be replaced for many years. My guess is in many of these use cases (industrial etc) you won't see TPMs present or used, because they value availability and uptime over all else (i.e. confidentiality and integrity) - you won't be encrypting the filesystem or doing any kind of TPM checks on an industrial control system, as the operational technology mindset is to put availability above all else, and a TPM or encryption issue would compromise availability.
So not really for workstations - they'd probably say you should use enterprise and just accept constant changes and new features being pushed down to users causing support hassle. They don't officially consider LTSC to be something used by regular users for daily productivity though.
Those tend to be shipped on some validated hardware that will take years to validate, then eventually gets approved for use, and won't be replaced for many years. My guess is in many of these use cases (industrial etc) you won't see TPMs present or used, because they value availability and uptime over all else (i.e. confidentiality and integrity) - you won't be encrypting the filesystem or doing any kind of TPM checks on an industrial control system, as the operational technology mindset is to put availability above all else, and a TPM or encryption issue would compromise availability.
So not really for workstations - they'd probably say you should use enterprise and just accept constant changes and new features being pushed down to users causing support hassle. They don't officially consider LTSC to be something used by regular users for daily productivity though.
Only one specific version of LTSC doesn't have them.
I gave up because it's been over three years during which MSFT has repeatedly demonstrated the Windows business is being operated with fundamentally different priorities in the Win11 era than it ever has been. The myriad things which have been removed from Win11 and the new things which are annoying on a daily basis are not regressions. They're not going to be fixed because these new priorities are now part of MSFT's core strategy for the Windows business. They have prioritized incessantly promoting adjacent subscription businesses and de-prioritized making Windows a complete, feature-rich, functional and streamlined tool for individual power users.
For the past 30 years, Windows has generally gotten better for users like me (with a few detours, which were corrected). It's not that MSFT always did everything the way I'd prefer but, even when we disagreed on implementation, we remained largely in sync on the overall goals. Since Win11, it's become clear that Microsoft's interests are no longer mostly aligned with my own interests as an individual power user.