Live data from Hacker News

Windows 11: TPMs and Digital Sovereignty

secret.club

11–20 of 66 posts

Re: Windows 11: TPMs and Digital Sovereignty

#11
post #2

> You’ve probably noticed that the marketing for this requirement is vague and confusing, and that’s intentional. It doesn’t do much for you, the consumer. However, it does set the stage for the future where Microsoft begins shipping their TPM on your processor. Enter Microsoft’s Pluton. The same technology is present in the Xbox. It would be an absolute dream come true for companies and vendors with special interest…

When Microsoft originally published a short page with their justification of the advantages of UEFI and GPT drive layout, everything touted as an advantage was false. As this was foisted and users became accustomed to the migration away from more well-proven traditional operation, the page was edited into oblivion as it could be seen users would have better recognized the falsehood by then after having some direct ex…

Do you know the URL of that page? Is it available on archive.org?

Re: Windows 11: TPMs and Digital Sovereignty

#12
post #4

I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

I don’t use Windows for work or home. I keep a VM around for the couple of times a year someone sends me a word document.

Re: Windows 11: TPMs and Digital Sovereignty

#13
post #7
post #4

I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

If Windows is required for work then you've already lost. Seriously I'm unable to be productive in Windows (or Mac, I tried). I don't know what the stats are on employers requiring Windows but my current one doesn't (mainly because of a sizable chunk of Mac users, not that there's any support for Linux).

Lots of semiconductor design tools are Windows only.

Re: Windows 11: TPMs and Digital Sovereignty

#14
post #7
post #4

I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

If Windows is required for work then you've already lost. Seriously I'm unable to be productive in Windows (or Mac, I tried). I don't know what the stats are on employers requiring Windows but my current one doesn't (mainly because of a sizable chunk of Mac users, not that there's any support for Linux).

Where I work pretty much everyone who's not a developer or system admin uses Windows. Most of them never leave the confines of Edge, Teams, Sharepoint, Outlook, and MS Office with maybe the exception being Zoom. It's an enterprise config of some sort so it more or less stays out of their way. Windows Home sounds absolutely horrific and I can't imagine why anyone uses it, other than they don't know anything else.

Re: Windows 11: TPMs and Digital Sovereignty

#15
post #4

I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

I switched to full time macOS in 2019 from a 15 year background professionally on Windows in IT admin/architect type roles.

Granted, at that point Windows was web browser, IDE, and remoting into Linux machines for 95% of my work.

I appreciate having first class support for all my command line tools and utils, which I generally get on macOS. I have linuxified my macOS experience, installing and pathing gnu versions of everything you would normally expect. I rarely use the utils from macOS.

I have a Windows gaming PC that hasn't been powered on this year.

I like my MBP battery life and lack of futzing needed for my work (I do use better touch tool, but that's it).

I have turned down further interviews if I find out I'm going to be saddled with a corporate locked down Windows laptop.

Re: Windows 11: TPMs and Digital Sovereignty

#16
post #4

I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

Except, in the future, your Linux partition will be unable to access most online services because they'll all rely on remote attestation to check if your device is running an unmodified Windows OS, similar to what many android apps already do.

Re: Windows 11: TPMs and Digital Sovereignty

#17
post #4

I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

> I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

If statistics bear out, you'd be incorrect (at least with regards to a non-Windows OS being run by 'most').

Re: Windows 11: TPMs and Digital Sovereignty

#18
I agree with the sentiment of the piece, but I disagree with the idea that TPMs don't add much value for end users.

TPMs were originally designed in the early days of ecommerce, when it became clear that home computers would need better security if they were going to be used for financial transactions.

Today's TPMs don't have a lot of compute power, but they have a lot of features. It's just that we don't have that much software taking the best advantage of those features yet, probably because they have only just become ubiquitous in the last couple years.

TPMs lay the groundwork for unphishable credentials, using hardware-bound asymmetric keys.

TPMs add a user-friendly option for full-disk encryption, in a way that's resistant to physical attacks.

TPMs can be used to protect symmetric credentials too, instead of storing them on disk (see systemd-creds TPM2 support).

And, TPMs do have actual privacy mechanisms. End-user TPMs do not offer up their endorsement key to any third party. Attestation workflows shield third parties from the endorsement key.

I'm excited for more widespread use of TPMs in Linux especially. Lately systemd has been making some good progress here.

Re: Windows 11: TPMs and Digital Sovereignty

#19
post #4

I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

If my job wants me to run Windows, they are free to supply a Windows machine for me to use.

I keep a bright line between personal equipment and work equipment.

Anyway, my last few jobs have given me Macs for development.

Re: Windows 11: TPMs and Digital Sovereignty

#20
Wow ... I am getting old and jaded.

I was so into locking down systems, making sure I knew where every packet was going, not trusting anything. Meanwhile I'm also "wardriving", phreaking with a red box, running an underground BBS ... all sorts of stuff. I had one of those fancy t-shirts with the export-restricted RSA encryption source code printed it. Because, why not?

Now I just quickly skim a 2 year old article about Windows 11 and TPM again, on a Windows 11 device, and have just enough left in me to post a comment.

> You see, the PC (emphasis on personal here) is in a way the last bastion of digital freedom you have. The TPM requirement of Windows 11 furthers the agenda to protect the PC against you, its owner. These keys are then cryptographically tied to the vendor who issued them, and as such, not only does a TPM uniquely identify your machine anywhere in the world, but content distributors can pick and choose what TPM vendors they want to trust.

Every time these technologies come out, there are similar "it's all over" scenarios. But so far it hasn't been all over, and I've been around a while. I recall Intel Management Engine (ME) really piquing my interest for a bit. So my computer now has a computer running on it, that still runs when I turn it off, has access to the system hardware, including memory, the contents of the display, keyboard input, and the network? And the keys to the kingdom are secure ... they haven't been shared with anyone else who may be highly interested in having those ... ?

Hello, anyone ... I'm still secure, right? ... right!? Forget it, I'll just disable it. Oh. Nevermind. Wait ... what? Intel ME has a ring −3 rootkit??! Just ... ah, forget it ... what's on TV?

And then AMD shows up with their own. At least that one can be disabled by BIOS. I think? Hope?

> Did we mention that a TPM isn’t going to protect you from UEFI malware that was planted on the device by a rogue agent at manufacture time?

If you are the target of a rogue agent at manufacturing time, that is way past "game over". If they want it they're going to get it and you're not going to stop it by having, or not having, things like TPM on a Windows machine. I can't tell if this is more about losing the ability to watch HD video and DRM, or if nation states are coming after you. Those are slightly different. I'd personally prefer neither but I'd settle for the former. If it's security then it's more Tor/Tails and a USB key than Windows.

Certain groups can even shut down highly specialized air-gapped equipment that is deeply underground. It's like "if there's a will, there's a way".

Post reply on HN