Live data from Hacker News

Windows 11: TPMs and Digital Sovereignty

secret.club

1–10 of 66 posts

Re: Windows 11: TPMs and Digital Sovereignty

#2
> You’ve probably noticed that the marketing for this requirement is vague and confusing, and that’s intentional. It doesn’t do much for you, the consumer. However, it does set the stage for the future where Microsoft begins shipping their TPM on your processor. Enter Microsoft’s Pluton. The same technology is present in the Xbox. It would be an absolute dream come true for companies and vendors with special interests to completely own and control your PC to the same degree as a phone or the Xbox.

Explains why official sites don't explain what the TPM is beyond "security" [1], nor that this "security" means "security against the owner" - though the computer is nominally yours, it's built to keep secrets from you.

[1] https://support.microsoft.com/en-us/topic/what-is-tpm-705f24...

Re: Windows 11: TPMs and Digital Sovereignty

#3
post #2

> You’ve probably noticed that the marketing for this requirement is vague and confusing, and that’s intentional. It doesn’t do much for you, the consumer. However, it does set the stage for the future where Microsoft begins shipping their TPM on your processor. Enter Microsoft’s Pluton. The same technology is present in the Xbox. It would be an absolute dream come true for companies and vendors with special interest…

When Microsoft originally published a short page with their justification of the advantages of UEFI and GPT drive layout, everything touted as an advantage was false.

As this was foisted and users became accustomed to the migration away from more well-proven traditional operation, the page was edited into oblivion as it could be seen users would have better recognized the falsehood by then after having some direct experience.

So many "influencers" were already carrying the flag on their own that the page was eventually removed.

TPM came next.

Re: Windows 11: TPMs and Digital Sovereignty

#5
post #4

I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

I would like to think so too, but the reality seems to be a lot of Windows-only or macOS-only folks.

Re: Windows 11: TPMs and Digital Sovereignty

#6
post #4

I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

Nope. Least, not me. Windows 11 pro for workstations on my personal desktop. Linux in WSL2. Linux in docker.

Re: Windows 11: TPMs and Digital Sovereignty

#7
post #4

I have to believe most of us here on HN are in the boat of keeping a W11 partition for work and a Linux partition for everything else at this point.

If Windows is required for work then you've already lost. Seriously I'm unable to be productive in Windows (or Mac, I tried). I don't know what the stats are on employers requiring Windows but my current one doesn't (mainly because of a sizable chunk of Mac users, not that there's any support for Linux).

Re: Windows 11: TPMs and Digital Sovereignty

#9
>Did we mention that a TPM isn’t going to protect you from UEFI malware that was planted on the device by a rogue agent at manufacture time?

DRTM, a technology supported by Windows 11 that is layered on top of the TPM, aims to solve this very problem.

Post reply on HN