Live data from Hacker News

Windows 11: TPMs and Digital Sovereignty

secret.club

21–30 of 66 posts

Re: Windows 11: TPMs and Digital Sovereignty

#21
The underlying point you should be calling out if you want to present this argument is that "User freedom should prevail over companies' freedom". The only thing attestation enables is companies enacting their own policies along the lines of "I only want users who are willing to let their device attest x level of security". The user is not required to use that service, they're not required to run W11 or to enable the fTPM in their BIOS.

Asking for widespread change and the death of TPM attestation is like saying that companies should be forced to serve all customers even if it degrades the services they provide, if it requires x orders of magnitude more personnel for fraud/risk/etc management, or if it degrades the experience of other users on the service willing to perform attestation. Maybe this is the right approach, maybe we just need some good regulation that won't deepen the moat of existing players, but this is the crux of the argument being made.

> We are here to remind you that the TPM requirement of Windows 11 furthers the agenda to protect the PC against you, its owner.

No. It's to protect third party services that your PC makes network requests to. Your PC in itself doesn't need any protection from you.

Re: Windows 11: TPMs and Digital Sovereignty

#22
post #7

Earlier quoted context omitted.

If Windows is required for work then you've already lost. Seriously I'm unable to be productive in Windows (or Mac, I tried). I don't know what the stats are on employers requiring Windows but my current one doesn't (mainly because of a sizable chunk of Mac users, not that there's any support for Linux).

Lots of semiconductor design tools are Windows only.

So are CAD design tools.

Re: Windows 11: TPMs and Digital Sovereignty

#23
One of the reasons why Microsoft and OEMs are promoting TPM is to encourage planned obsolescence, so that users will replace their PCs as often as they replace their smartphones, right?

"(Lenovo) said people buy new smartphones every other year but became accustomed used to buying new PCs every six or seven years. The industry needs to do better at motivating people to buy new devices"

https://www.cnbc.com/2021/10/05/microsofts-panos-panay-expla...

Re: Windows 11: TPMs and Digital Sovereignty

#24
post #4

I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

> I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point. If statistics bear out, you'd be incorrect (at least with regards to a non-Windows OS being run by 'most').

I also imagine I'm not the only one who doesn't use their work laptop for personal stuff (even on a separate partition). At my previous job, I never even took my work laptop home, and in my current remote job, my work laptop gets booted up at the start of each work day and shut down at the end; I have my own devices for non-work use.

Re: Windows 11: TPMs and Digital Sovereignty

#25
post #7
post #4

I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

If Windows is required for work then you've already lost. Seriously I'm unable to be productive in Windows (or Mac, I tried). I don't know what the stats are on employers requiring Windows but my current one doesn't (mainly because of a sizable chunk of Mac users, not that there's any support for Linux).

Then how are you going to do the majority of native desktop app/game development (where most of your users use Windows)?

Re: Windows 11: TPMs and Digital Sovereignty

#26

One of the reasons why Microsoft and OEMs are promoting TPM is to encourage planned obsolescence, so that users will replace their PCs as often as they replace their smartphones, right? "(Lenovo) said people buy new smartphones every other year but became accustomed used to buying new PCs every six or seven years. The industry needs to do better at motivating people to buy new devices" https://www.cnbc.com/2021/10/05…

Push local LLMs and generative AI then. That’ll require people to upgrade old machines.

Re: Windows 11: TPMs and Digital Sovereignty

#27

One of the reasons why Microsoft and OEMs are promoting TPM is to encourage planned obsolescence, so that users will replace their PCs as often as they replace their smartphones, right? "(Lenovo) said people buy new smartphones every other year but became accustomed used to buying new PCs every six or seven years. The industry needs to do better at motivating people to buy new devices" https://www.cnbc.com/2021/10/05…

Tbh I'd expect the trend of upgrading phones to start to slow down as well as they become "good enough" but there are still pretty big gains being made in cameras.

Laptops are just good enough now. If you took the 3 year old M1 internals, and stuck them in the new case and told me it was the 2024 model, I'd not notice anything was off.

Re: Windows 11: TPMs and Digital Sovereignty

#28
post #18

I agree with the sentiment of the piece, but I disagree with the idea that TPMs don't add much value for end users. TPMs were originally designed in the early days of ecommerce, when it became clear that home computers would need better security if they were going to be used for financial transactions. Today's TPMs don't have a lot of compute power, but they have a lot of features. It's just that we don't have that m…

Seems like a lot of banking and other secure business is moving to mobile first or mobile only, presumably as it's likely the only secure device the user has.

Re: Windows 11: TPMs and Digital Sovereignty

#29

The underlying point you should be calling out if you want to present this argument is that "User freedom should prevail over companies' freedom". The only thing attestation enables is companies enacting their own policies along the lines of "I only want users who are willing to let their device attest x level of security". The user is not required to use that service, they're not required to run W11 or to enable the…

Ok, so instead of Microsoft turning my PC into an Xbox, it's banks asking Microsoft to turn my PC into a credit card reader. This is not materially different.

We already know how this works on Android. Attestation requirements and DRM tend to creep beyond their initial scope if implementing them is easy. And those requirements will include not having owner-level control over your machine[0]. If you root Android, you basically forefeit access to all banking apps, most gaming apps, and a whole bunch of things that you wouldn't even think should require secure attestation.

On the web, we all thought that EME DRM was going to lock down web video and cascade into audio and text. This didn't come to pass primarily because DRM vendors charge money that free web video platforms don't have. If EME had made DRM ubiquitous, the best case would have been one distro vendor offering "blessed" kernel builds that can still "go online", and anyone wanting to be online with their own Linux kernel potentially violating DMCA 1201 or being limited to an increasingly shrinking "clearweb".

There's three types of companies here:

- People that absolutely need user-hostile attestation: banks, competitive multiplayer games, and streaming services

- People that would never demand attestation on principle: normal websites, blogs, web forums, the Fediverse, and YouTube[1]

- People who would implement attestation if it were available regardless of the impact on their user base: Facebook/Meta, Twitter, basically any social media network.

That third group is arguably the largest. They will tolerate unattested users, but they wish they didn't have to. Making attestation easier makes it way more likely for them to demand it.

[0] This could be made less onerous with per-partition boot policies, but only Apple Macs do this AFAIK.

[1] YouTube's stance on DRM is very very weird. Google has the capability to DRM all their content, but they don't. And they've used YouTube as a trojan horse to push open standards like VP8/9 and AV1. On the other hand, they do try to obfuscate video download in ways that the RIAA thinks is DRM.

Re: Windows 11: TPMs and Digital Sovereignty

#30

One of the reasons why Microsoft and OEMs are promoting TPM is to encourage planned obsolescence, so that users will replace their PCs as often as they replace their smartphones, right? "(Lenovo) said people buy new smartphones every other year but became accustomed used to buying new PCs every six or seven years. The industry needs to do better at motivating people to buy new devices" https://www.cnbc.com/2021/10/05…

A capitalist economy predicated on infinite growth necessarily needs planned obsolescence to artificially churn consumption to increase growth (with new devices costing more). With public-traded companies bound to make profits for shareholders, this is no surprise.
Post reply on HN