Live data from Hacker News

Windows 11 is no longer compatible with Oracle VirtualBox VMs

bleepingcomputer.com

31–39 of 39 posts

Re: Windows 11 is no longer compatible with Oracle VirtualBox VMs

#31

Earlier quoted context omitted.

I fear that might not be a good thing. Wouldn't it be better and safer to just emulate TPM in the VM?

It sounds like VMWare agrees with you. > Unlike VMware, which creates a virtual TPM, VirtualBox's new driver will require a host to have a TPM 2.0 processor for this feature to work.

VMWare's is the right approach. I wouldn't want a Linux system's TPM polluted with MS keys.

Re: Windows 11 is no longer compatible with Oracle VirtualBox VMs

#32
post #23

Earlier quoted context omitted.

Well, modules can be designed to protect my security, or to harm my security (e.g. to enforce DRM). I'm unclear on how "real TPM" functionality helps me. If it helps secure Microsoft, and hurts my security, that's a good reason to not use Windows. I have not found good docs on what TPM exactly does in Windows 11, but people I trust tell me to distrust it, so I do.

It’s used to store BitLocker (Full Disk Encryption) keys so you don’t have to type a password for the system to boot. If you don’t use BitLocker, it’s not used for much else. One could conclude that they are requiring TPM so they can eventually turn on BitLocker by default.

This is really stupid. So you can use your hard drive only in the first computer.

Re: Windows 11 is no longer compatible with Oracle VirtualBox VMs

#33

Earlier quoted context omitted.

How would they detect the difference?

Probably built-in crypto keys signed by Intel/AMD keys.

That would be unfortunate for Infineon who create the majority of TPM chips. Who’s going to be the gatekeeper who decides who can create TPM chips and what’s going to happen when a new manufacturer wants to enter the stage?

Re: Windows 11 is no longer compatible with Oracle VirtualBox VMs

#34

My life is no longer compatible with Windows.

Indeed. With the existence of Proton my last reason for keeping Windows around is gone. I'm about to switch my last computer to Linux.

I’m actually considering just blowing away Windows on my gaming media center and just replacing it with Ubuntu. Most of my games work on proton anyway, anti cheat support is coming (thanks Stram Deck) and I’m just fed up with Microsoft’s constant built-in ads and notifications nagging, constant intrusive updates if I don’t use it for a while and even just the other day my video driver was corrupt and had to do a factory reset reinstall. Tired of the nonsense.

Re: Windows 11 is no longer compatible with Oracle VirtualBox VMs

#35
Hopefully I don't use windows, but it is incredible that it does not piss off more people that you can't use an entire OS just because of a hw module required only for a small feature used by a minority of users. Mostly corporate.

But if you think long term, it makes sense for Microsoft:

They dream about having the same control as apple and Google have on their devices. The problem is that nothing prevent users to be the master of their machine and doing whatever they want with it. With the tpm module, they can start to restrict some things to you on your own computer, controlled by the tpm, and as an user you will have not way to do anything about it. Like copy your data to another computer.

Re: Windows 11 is no longer compatible with Oracle VirtualBox VMs

#36
post #3

Earlier quoted context omitted.

Because it is not RTM. More restrictions on the way.

Why they they so hot on needing the TPM?

Several reasons, but the biggest I see is Passwordless.

Windows 10 can act as a FIDO2 authenticator like a Yubikey, but needs a TPM to do so. They want this to be something that actually happens for the average user in windows 11.

Re: Windows 11 is no longer compatible with Oracle VirtualBox VMs

#37
post #3

How come I currently have an instance of Windows 11 working just fine under VirtualBox?

Because it is not RTM. More restrictions on the way.

Sigh. Already happened, went to update my Windows 11 instance to latest and I was greeted with a message TPM now required.

Hopefully some big corps will get annoyed and start twisting arms to make it optional. To upgrade computers can run to the millions.

Re: Windows 11 is no longer compatible with Oracle VirtualBox VMs

#38
post #32
post #23

Earlier quoted context omitted.

It’s used to store BitLocker (Full Disk Encryption) keys so you don’t have to type a password for the system to boot. If you don’t use BitLocker, it’s not used for much else. One could conclude that they are requiring TPM so they can eventually turn on BitLocker by default.

This is really stupid. So you can use your hard drive only in the first computer.

If VirtualBox takes the pass though approach, will we be able to migrate Windows 11 VMs between computers?

Re: Windows 11 is no longer compatible with Oracle VirtualBox VMs

#39

Earlier quoted context omitted.

Probably built-in crypto keys signed by Intel/AMD keys.

That would be unfortunate for Infineon who create the majority of TPM chips. Who’s going to be the gatekeeper who decides who can create TPM chips and what’s going to happen when a new manufacturer wants to enter the stage?

I should have said TPM manufacturers, but it’s the same basic idea. Here’s Infineon’s key: https://www.infineon.com/cms/en/product/promopages/optiga_tp... I guess new manufacturers have to beg people to recognize their root key as legitimate.
Post reply on HN