Live data from Hacker News

Windows 11 will create heaps of needless trash

nbailey.ca

11–20 of 343 posts

Re: Windows 11 will create heaps of needless trash

#13
people are forgetting w11 will be the useless windows version.

everyone knows that between actual windows versions (3, 95, vista, xp, 10) there are the BS money making by selling flashy badges to PC OEM manufacturers (98, me, forgot the name , 8)

so obviously w11 can be safely ignored by everyone.

Re: Windows 11 will create heaps of needless trash

#14

Sorry for the aside, but do these TPM 2.0 modules actually guarantee any additional security?

An encrypted hdd/ssd will help of someone steals your computer, removes your drive, and tries to read it from another computer in order to bypass your passwords. It won’t do shit for ransom ware. Ransom ware runs as a user land program and does encryption from within your OS where you data is live and unencrypted. The end result will be a hard drive full of encrypted files that is then reencrypted by bitlocker.

Re: Windows 11 will create heaps of needless trash

#17

Sorry for the aside, but do these TPM 2.0 modules actually guarantee any additional security?

As ever with security questions, the answer to that depends a lot on your threat model.

Microsoft say that the main features of TPMs are that they [1]:

> Generate, store, and limit the use of cryptographic keys.

> Use TPM technology for platform device authentication by using the TPM’s unique RSA key, which is burned into itself.

> Help ensure platform integrity by taking and storing security measurements.

One can, in principle, imagine situations á la Apple's T2 chip whereby this could be very useful to the end user -- for example, in hardware rate-limiting whole drive encryption decryption requests. Microsoft don't actually state this as a potential use-case. They go for the rather more prosaic

> Antimalware software can use the boot measurements of the operating system start state to prove the integrity of a computer running Windows 10 or Windows Server 2016. These measurements include the launch of Hyper-V to test that datacenters using virtualization are not running untrusted hypervisors. With BitLocker Network Unlock, IT administrators can push an update without concerns that a computer is waiting for PIN entry.

The rest of the page then goes on about hardware attestation. In reality, I am increasingly convinced that this is all an elaborate DRM scheme, similar to what they integrated in the XBox, with its on-chip crypto. I think we will see increasingly user-hostile, but more "transparent" DRM schemes based around this idea, and continue the cat-and-mouse game of "you are running this code in a VM and that is unauthorised for $MONEY_REASONS".

I'll stick to Linux, thanks.

[1] https://docs.microsoft.com/en-us/windows/security/informatio...

Re: Windows 11 will create heaps of needless trash

#19
post #14

Sorry for the aside, but do these TPM 2.0 modules actually guarantee any additional security?

An encrypted hdd/ssd will help of someone steals your computer, removes your drive, and tries to read it from another computer in order to bypass your passwords. It won’t do shit for ransom ware. Ransom ware runs as a user land program and does encryption from within your OS where you data is live and unencrypted. The end result will be a hard drive full of encrypted files that is then reencrypted by bitlocker.

If someone steals your computer, they also have the TPM, which has the key, right? What am I missing about what TPM does that is so secure?
Post reply on HN