Live data from Hacker News

Retiring Windows 10 and Microsoft's move towards a surveillance state

scottrlarson.com

441–450 of 514 posts

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#441

Earlier quoted context omitted.

Couldn’t agree more, if you’re pitching Linux to a non-technical user, you need a gentler off-ramp, not a cliff dive. LibreOffice is a UI time capsule..more archaeology than productivity. Most millennials would think they’d accidentally opened a flight simulator.

I’m relieved to see I’m not alone. I expected my comment to be downvoted because speaking against LibreOffice triggers some people > LibreOffice is a UI time capsule..more archaeology than productivity. I agree. Seeing the comments here claiming the outdated UI is a good thing, actually, brings up one of the big problems with a lot of open source and/or Linux soecific software: The resistance to UI change is huge amo…

>The resistance to UI change is huge among die-hard users so the projects tend to get stuck in whatever UI language they had a decade ago when they started

Oh, worse: stuck in whatever weird, half-baked UI decisions that were made because someone had a great idea that they did not test at all, or because they hated the industry standard approach that everyone else uses. It's no secret that Blender adoption exploded when they added normal menus, and then made right-click select an optional function, and then finally added an auto Maya-like interface option.

But that's one instance where we lucked out. Not just because they fixed it, but also because the thing that needed to be fixed was in users' face and obvious.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#442

Earlier quoted context omitted.

> Make sure libreoffice is included Probably an unpopular thing to say here, but in my experience pushing non-tech people to use libreoffice as part of a Linux transition is a fast track to getting them to hate Linux. Using Google Docs has been much more welcoming in my experience. Something about libreoffice doesn’t resonate with a lot of non-tech people.

Couldn’t agree more, if you’re pitching Linux to a non-technical user, you need a gentler off-ramp, not a cliff dive. LibreOffice is a UI time capsule..more archaeology than productivity. Most millennials would think they’d accidentally opened a flight simulator.

OTOH I installed it on my elderly mother's computer, and she said that it did everything that MS Office could do. She's perfectly happy with it.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#443

Earlier quoted context omitted.

> I would say that specifically with Secure Boot, Microsoft actually promoted user choice: A Windows Logo compliant PC needs to have Microsoft's root of trust installed by default. Microsoft could have stopped there, but they didn't. This was not the case with the initial rollout of Secure Boot, it was combined with locked BIOS to lock PCs so that they could only boot Windows 8 on some devices. This was the case on W…

> This was not the case with the initial rollout of Secure Boot, it was combined with locked BIOS to lock PCs so that they could only boot Windows 8 on some devices. This was the case on Windows RT ARM machines from that era. Okay, but, that was like 15 years ago, on some shitty first-run computers that no one bought. A failed first attempt. I've never met a single person that owned, or has ever used, a Windows RT de…

> Okay, but, that was like 15 years ago, on some shitty first-run computers that no one bought.

I wouldn't call the first Microsoft Surface, Surface 2, Dell XPS 10, and Lenovo IdeaPad Yoga 11 products that no one bought.

> I've never met a single person that owned, or has ever used, a Windows RT device.

I have and I also regrettably bought one myself.

> Dwelling on the past isn't going to move us forward.

The past dictates the future, and history repeats itself. Microsoft made their intentions known, it would be foolish to pretend they haven't. They continue to make their intentions known today with the Pluton cryptographic co-processor, that paired with a TPM, can enforce remote attestation by design. That is literally the intent of the Pluton chip: ensuring platform integrity and securely attesting to 3rd parties that your system is Blessed/trusted.

> Anyone pushing the "Secure Boot and TPM are evil" trope in 2025 is objectively a fool and should be ignored

Anyone tearing down this strawman is tilting at windmills for some reason.

> Most don't even realize what a TPM does, they think it's some secret chip inserted by glowies into their computers to prevent them from running free software.

I wouldn't project ignorance on those you don't actually know. You can understand what a TPM does, understand how it can be abused today and acknowledge how it was abused in the past.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#444

Earlier quoted context omitted.

But most people don't want to enter a password, and if you make people enter a password too much, they'll choose terrible passwords and put them on a sticky note. Windows Hello can only be done securely with a TPM. A server that I want to turn back on all by itself after a power outage can only be done securely with a TPM. I want a TPM in my computer so I can have the security and convenience. Yes, it's another point…

>Windows Hello can only be done securely with a TPM I think in general biometrics are in the same ballpark as low-entropy passwords. IDK, I personally have no faith in trusted computing hardware because it can be broken with the right equipment. You're right that it can be used alongside ordinary security measures, but I just think it encourages putting your eggs into a cryptographicially-weak hardware-strong basket…

I agree that biometrics are in the same ballpark as low-entropy passwords, which means their security relies on avoiding offline attacks. My ATM card is protected by a 4-digit pin. That's perfectly secure, because the ATM network won't let you enter a wrong pin more than a single-digit number of times before locking the account.

Windows Hello allows you to log in with a 6-digit pin. That's perfectly secure, because the TPM lets them design a system where you can't do an offline attack on the pin. Too many wrong entries and you'll need to use your password.

I doubt there's more than two dozen bits of entropy provided by finger print readers or facial recognition authentication, but you can make an acceptably secure login experience with it because, again, the TPM lets you prevent offline attacks.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#445

Earlier quoted context omitted.

The important part in the parent is "that don't need a user password". You just said you had to supply a (user) password. With a TPM you can set it up that your disk is unlocked automatically, but only if no-one changed anything in the signed boot chain. This is the default with Bitlocker on Windows and is also possible on Linux, though somewhat more finicky.

But without password, anybody can physically access the device and exfiltrate data. That is even easier than regular password protection, where the storage medium would have to be removed or a live OS would have to be booted. The risk is data leakage. With a TPM and no password, there is no data leakage protection.

Passwordless boot with a TPM means the software can control what secrets it gives out. Yeah, if you boot to a desktop operating system and auto-login as an admin user, that doesn't leave things very secure, but that's not the only scenario.

Consider a server. It can have an encrypted hard drive, boot with the TPM without a password, and run its services. In order to steal data from it, you need to either convince software running on the server to give you that data, or you need to do some sort of advanced hardware attack, like trying to read the contents of DRAM while the computer is running.

There are other use cases too, like kiosks, booting to a guest login, corporate owned laptops issued to employees, allowing low-entropy (but rate limited) authentication after booting, to name a few.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#446

I have said this 10 times on HN and i ll say it again. Release a version of Windows 11 called "Windows Optinmal" that has 0 telemetry, 0 trackers, 0 bloatware that runs faster than Windows 7 on modern hardware. Charge 4x the prices if you want, I ll pay happily

What if 4x is too low? How much more would you agree to pay?

good question, answer is we need to find out how much value they are getting currently and only slightly incentivize them

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#447
post #105

This is an excellent article as well as a sign of the times. I wish the list of Linux choices had included Mint, which is essentially Ubuntu without Snaps. Snaps are a partly closed-source Ubuntu project that contradicts the open nature of Linux. Linux users can install the free software suite LibreOffice, which not only replaces Office but reads and writes the same file formats. Many similar choices exist, this is j…

> pushing the Recall eavesdropping-to-cloud feature with no user opt-out provisions That's not what Recall is and not how it works.

> That's not what Recall is and not how it works.

You're right, I overstated how Recall works, right now. At the moment, it's opt-in and the images are only stored locally. I was wrong -- my claims were several months out of date.

Recall's current form results from a heated online debate about its original form, which was neither encrypted nor opt-in.

At the time I write this, Microsoft won't allow users to uninstall Recall, a demand made by security professionals who see serious risks for non-technical end users in the event of a compromised system.

Having said that, let's revisit this feature some years from now. Let's see whether Microsoft's perennial corporate death-by-a thousand-cuts strategy has changed anything.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#448
post #271
post #181

Earlier quoted context omitted.

I largely agree with your points, but in this context - * A microsoft account is only needed for Windows 11 Home. A "semi-power user" is hopefully not using that edition of Windows... * I'm also greatly annoyed by the right click - but holding shift when right-clicking opens the expected menu, removing the extra click requirement. Some of my own annoyances though: * The taskbar/windows button seems to just...crash...…

> * A microsoft account is only needed for Windows 11 Home. A "semi-power user" is hopefully not using that edition of Windows... Both Home and Pro require Microsoft account to install and start using. Then you can create local only users in both editions and delete user joined to Microsoft account. This is standard operation even in OEM installs.

Pro does not. We only use Pro and Enterprise, and Pro certainly does not actually require a Microsoft account (as of last week, anyways). The options given do make it appear to be required, but it is not.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#449
post #399
post #271

Earlier quoted context omitted.

> * A microsoft account is only needed for Windows 11 Home. A "semi-power user" is hopefully not using that edition of Windows... Both Home and Pro require Microsoft account to install and start using. Then you can create local only users in both editions and delete user joined to Microsoft account. This is standard operation even in OEM installs.

Neither Home nor Pro really require a MS account. You can skip that during setup (for example with "bypassNRO"). This might change in the future, but as of 25H2 the workarounds still work.

bypassnro no longer works for Windows 11 Home, unfortunately. If you're using an ISO built prior to the change (a few weeks ago?), you'll be fine.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#450

Earlier quoted context omitted.

No, GP is misinterpreting Windows's message. It prompts for a recovery key because the TPM is bound to, among other things, Secure Boot == enabled. When Secure Boot is disabled, the TPM notices that and refuses to release the key, that's how you know to reënable Secure Boot or throw away your device. The fact that Windows is compromised does not make it capable of extracting secrets from the TPM, though maybe a naïve…

> When Secure Boot is disabled, the TPM notices that and refuses to release the key, that's how you know to reënable Secure Boot or throw away your device. But the attacker isn't trying to get the key from the TPM right now, they're trying to get the credentials from the user. It's the same thing that happens with full disk encryption and no TPM. They can't read what's on the device without the secret but they can al…

So this attack is to steal my Windows password or Windows Hello credentials, but doesn't get my encryption key...? That's...not ideal, but I think you'll see it's an improvement over unencrypted disks (again, TPMs are for people who can't be bothered to set a strong password).

And again this presupposes that you can disable Secure Boot, boot a malicious OS from another drive, fool the user into entering their password, automatically reboot, enable Secure Boot, boot into the legit OS, then come back later and have the ability to boot the OS yourself and log in as the user (because again, you don't have the decryption key, you have the user's login credentials).

You are also presupposing what the TPM is bound to. I don't use Windows, but using systemd-cryptsetup I could configure a TPM to bind to the drives in the system; in this way, it will refuse to boot my legit OS while your malicious disk is installed (well, it will demand a recovery key). Again, setting off alarm bells, and if I discover the disk with my recorded credentials before you can physically access it, I can just destroy it.

Post reply on HN