Live data from Hacker News

Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs

neowin.net

171–180 of 288 posts

Re: Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs

#171
post #18

What is Microsoft hoping to accomplish here? Given the rate of adoption of Windows 11, it seems unlikely that a majority of Windows 10 users will replace their hardware between now and October. It also seems to me that the scenario where a majority of PC users are running an unsupported Windows release is likely to create MS more problems than is offset by potential revenue from a hardware refresh cycle. Is there an…

I would it is a combination of metric-stuffing, land grab, and genuine concern about security. Metric stuffing. Everyone at Microsoft is graded on "impact". All the EVP-types at Microsoft have their eye on boldface jobs, so they need a track record of massive impact. Beimg able to claim that they got W11 from X billion devices to Y is how theyll be judged. Another example is how in Azure, the only metric that matters…

> I dont know that they are right (eg if the #1 exposure for home users is ransomware, does a tpm help at all?), but I am prepared to give them dome grace.

One particularly generous view is that the TPM requirements catch PCs up with the TPM requirements of modern phones. (Both iOS and Android have had very strict TPM requirements for a while now.) With a lot of industry interest in moving to hardware security-backed Passkeys to replace passwords, it would help to have PCs on an equal security footing with phones.

Passkeys are a pretty big deal to reduce home user exposure. Phishing and all of its variants are as much or more a home user problem as ransomware.

Re: Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs

#172

My (unsupported) desktop PC is an AMD Ryzen 7 2700 eight-core CPU running at 3.2Ghz with 16GB of RAM and 2TB of SSD storage. It handles Windows 10 Professional but is apparently incapable of running Windows 11. I don't have a Webcam, but maybe face ID login is now mandated? It will be something stupid like that. I have no interest in replacing this machine though.

The missing requirement might be no TPM 2.0

Re: Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs

#173

My (unsupported) desktop PC is an AMD Ryzen 7 2700 eight-core CPU running at 3.2Ghz with 16GB of RAM and 2TB of SSD storage. It handles Windows 10 Professional but is apparently incapable of running Windows 11. I don't have a Webcam, but maybe face ID login is now mandated? It will be something stupid like that. I have no interest in replacing this machine though.

It's more likely you have TPM disabled—there's no webcam requirement, and Zen+ is supported.

Re: Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs

#174
post #18

What is Microsoft hoping to accomplish here? Given the rate of adoption of Windows 11, it seems unlikely that a majority of Windows 10 users will replace their hardware between now and October. It also seems to me that the scenario where a majority of PC users are running an unsupported Windows release is likely to create MS more problems than is offset by potential revenue from a hardware refresh cycle. Is there an…

Why not release a tool that runs and shows me the minimum I need to spend to get my PC windows 11 ready? Hide it behind a few menus/drop downs since it will be an "advanced" pc-builder tool. I imagine it's only my MOBO which is missing TPM, but a suggestion of what mobo to buy which would be compatible with all my other components (RAM DIMMS, PCI-e cards) would be killer.

PC Health check will tell you if your existing PC will run Win11. If you are building a computer, any new MOBO has TPM.

Re: Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs

#176

Earlier quoted context omitted.

Linux is in desperate need of a PR campaign. The popular distros are just as functional out of the box as Windows, but no one knows it.

> The popular distros are just as functional out of the box as Windows Give me some names that works out of the box and resembles Windows. I have not tried Linux mint so I don't know how well it works for older people. Ubuntu has been quite good and stable but it has also required fiddling with the terminal. The only one I found to be the best alternative to Windows is ... believe it or not, DeepinOS.

Why is resembles Windows important? Macos does not and is doing fine, so is Chromeos, so is Android.

Even Windows can be quite different from older versions of Windows.

Re: Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs

#177
post #109

Earlier quoted context omitted.

- Windows 11 has provided a hardware security baseline for Microsoft, with features that require hardware support (HVCI, TPM etc) to be enabled by default going forward, stating that Windows 10 strategy of off-by-default was a failure. - Admin accounts are a continued security problem within the Windows ecosystem, so a future version of Windows will be adding a new "Adminless" account model with linux-like just-in-ti…

> a new "Adminless" account model with linux-like just-in-time escalation This was the promise of User Account Control, was it not? Or does that just prompt for confirmation for various actions, without actually enforcing a security boundary?

The way I read it, the difference between existing UAC and "Adminless" is that the user is always in the Administrators group and UAC just unlocks an Administrator token/ACL temporarily to bestow the actual powers of the Administrators group. In "Adminless" the user is only a less privileged/low privilege user, a new system-managed Admin User is created, and the new security boundary prompts instead of unlocking a temporary token/ACL are more "runas" the system-managed Admin User. It's similar to Linux sudo sending commands to the root account, where Linux doesn't have a token/ACL model that allows temporarily upgrading the existing user "in place". It's also similar to how Windows Admin security was managed pre-UAC in places that separated standard accounts and Admin accounts, and similar to how many corporations still manage security, with the difference being that the new "Adminless" admin account is system owned (like the various internal service accounts), supposedly does not allow interactive login, has no password only a hardware security key (hence why the new security boundary requires Windows Hello unlocks every time, versus UAC can be as subtle as Yes/No, depending on configuration/group policy).

"Adminless" is a funny name given that there's still an admin account involved, it's just an admin account that is much more than before not a user account but more like a service account.

Re: Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs

#178
post #126

Earlier quoted context omitted.

UAC provides just-in-time elevation. The user belongs to the 'admin' group (aka wheel) and only receives an admin token when performing a task that requires elevation. Once the task is complete, the token is destroyed.

Sorry, I'm confused. I can't figure out from your explanation how the new adminless just-in-time elevation is supposed to be different from UAC's just-in-time elevation?

As far as I can tell, the difference is this:

UAC is per-process and monotonic. Once elevated, the entire process stays elevated.

The new model is per-operation. Even if the same process has been allowed to elevate before, it must ask to do it again. I don't know how granular this is, and whether there's a grace period like sudo.

However, the biggest problem with UAC was that it was considered too noisy for the end user, leading to people just blindly accepting every dialog and Microsoft turning down the default level to the much less secure "don't always prompt". I don't know how this new model will address that problem; naively, it seems to be worse on this front.

Re: Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs

#179
post #57
post #39

Earlier quoted context omitted.

Just to name a few... Operational reasons: * You often replace hardware and move disks, etc, around * The TPM is not compatible with hardware that you have: https://wiki.archlinux.org/title/Trusted_Platform_Module * You have a TPM that is too old: https://www.dell.com/support/kbdoc/en-uk/000132583/dell-syst... * Your TPM is damaged Security reasons: * For some reason the TPM is actually seriously compromised itself (…

> for example DRM or it snoops on you Stop spreading FUD.

It's not a guarantee, you may consider it FUD, but you can't tell me it's impossible - you can't even promise me it won't happen.

The TPM is fundamentally about storing cryptographic keys, platform integrity checks, unique IDs, etc. It is already used for secure logins by the Windows OS. Microsoft are successfully enforcing your email, ID, logins, etc, to be associated directly with your unique hardware.

One day you will request a video from Netflix or Youtube, and your device will be the only device in the world that can view it. You might think to screen record, but the OS does not allow it. You might think to record it via an external display, but this has to interface with the TPM. You decide to record your screen from your phone, but the phone's TPM recognises that the camera tries to record DRM material.

Don't get me wrong, security devices should exist 100%. But. It should never be forced.

Re: Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs

#180
post #120

Earlier quoted context omitted.

Valorant requires it for anticheat. The purpose is to prevent users from running unauthorized software on the computers they allegedly own. I wouldn't expect many examples to exist yet. You want to wait until almost everyone is on Windows 11 before you get up to those shenanigans.

Given than qemu (and I assume other virtual machines) can emulate a TPM 2.0 device, does this even work? Yes, anticheat tends to detect virtualization too, so there's extra cat and mouse there, of course.

There’s an embedded immutable Endorsment Key (EK) sometimes along with public crypto cert (EKCert) signed by manufacturer the TPM can use to prove its authenticity. With the certificate you can detect the QEMU case.
Post reply on HN