Skip to content

Forced E-Waste PCs And The Case Of Windows 11’s Trusted Platform

Technology
116 79 1.4k
  • Because it's so hard to use Rufus and make a win 11 install that bypasses the tpm requirements.

    That and having to manually upgrade CUs. It just doesn’t scale. It’s easier for most people to buy a new machine.

  • This post did not contain any content.

    This is on top of potential tariffs which if enacted will make PC costs skyrocket. I feel like a lot of people are just going to skip the generation like they do with every other windows OS version. They will just keep windows 10 forever kinda like XP did back in the day.

  • That and having to manually upgrade CUs. It just doesn’t scale. It’s easier for most people to buy a new machine.

    It's easier for most people to just continue using their current PC past the end of support.

  • I can hear the ‘just use Linux/BSD/etc.’ crowd already clamoring in the comments, and will preface this by saying that although I use Linux and BSD on a nearly daily basis, I would not want to use it as my primary desktop system for too many reasons to go into here.

    Still though.

    🐧

    I would not want to use it [Linux or BSD] as my primary desktop system for too many reasons to go into here.

    The Linux kernel not having a stable driver ABI is why Linux will never amount to anything outside of some embedded and server applications.

    --- Maya Posch, author of the submitted article

    I guess maybe that's their reason.

  • I can hear the ‘just use Linux/BSD/etc.’ crowd already clamoring in the comments, and will preface this by saying that although I use Linux and BSD on a nearly daily basis, I would not want to use it as my primary desktop system for too many reasons to go into here.

    Still though.

    🐧

    This rings a little hollow to me. Most of the people I know that understand Linux can quickly summarize why they might not use it as their daily driver (eg staying on macOS for graphics/video or staying on Windows for desktop Word/Excel). If you can’t summarize that quickly, it really makes me wonder if you really understand it. I’m not trying to No True Scotsman my way around it; I really don’t understand.

  • This post did not contain any content.

    The article focuses a lot on the security of the boot process, but there's no reason the TPM can't be used for DRM as well (as an example, https://ieeexplore.ieee.org/document/5283799). It's correct when it points out the locked down nature of consoles and phones.

    We could conceivably be in for a future where Windows refuses to run code that's not validated even after the OS boots. Or where it sees pirated software on the system and refuses to function in some manner until the software is removed/corrected to its liking.

    There are so many possibilities here and all of them are bad.

    • Forced online accounts so Microsoft always knows when/where you login
    • Stored encryption keys so Microsoft could theoretically provide access to any computer the government requests
    • Telemetry already reporting god only knows what metrics about what and how you use your software
    • Forced AI that literally watches everything you do on your screen storing it in a known location making for a valuable target and also potentially/likely being used to create more telemetry and insights into your habits
    • Eventual full control over your hardware by enforcing "trusted platform" restrictions

    It's so fucking brazen I'm gobsmacked. As an elder Millennial, I get it, I can already hear most of you tallying in your head if having to care about your OS is gonna be the final straw . This is no longer a nerdy request to please use Linux, this is a five alarm fire. Add to all this how much Microsoft is in bed with the US government and potential issues with all that on the horizon and I really, truly believe it's time to switch, for your own good.

    Please. Even if you're not going to run out and install Linux tomorrow, you need to start mentally preparing yourself for the inevitability of the task. Get yourself accustomed to the idea and when you're ready to dip your toes in, just know how many resources are out there for you.

    And to the Linux community out there, there are going to be a lot of newcomers who don't have the technical skills to undertake this and enjoy/appreciate this in the same way as you do. Be kind to them, the need for us to support each other has never been greater. Please.

  • This post did not contain any content.

    It's not really a TPM problem, my Dell has TPM2.0 which is perfectly compatible with win11. My problem is the CPU (i5 6th gen) missing some stuff for modern device drivers or something, that is preventing me from upgrading win10 to win11.

    Yes I dual boot MX Linux on it 🙂

  • The article focuses a lot on the security of the boot process, but there's no reason the TPM can't be used for DRM as well (as an example, https://ieeexplore.ieee.org/document/5283799). It's correct when it points out the locked down nature of consoles and phones.

    We could conceivably be in for a future where Windows refuses to run code that's not validated even after the OS boots. Or where it sees pirated software on the system and refuses to function in some manner until the software is removed/corrected to its liking.

    There are so many possibilities here and all of them are bad.

    • Forced online accounts so Microsoft always knows when/where you login
    • Stored encryption keys so Microsoft could theoretically provide access to any computer the government requests
    • Telemetry already reporting god only knows what metrics about what and how you use your software
    • Forced AI that literally watches everything you do on your screen storing it in a known location making for a valuable target and also potentially/likely being used to create more telemetry and insights into your habits
    • Eventual full control over your hardware by enforcing "trusted platform" restrictions

    It's so fucking brazen I'm gobsmacked. As an elder Millennial, I get it, I can already hear most of you tallying in your head if having to care about your OS is gonna be the final straw . This is no longer a nerdy request to please use Linux, this is a five alarm fire. Add to all this how much Microsoft is in bed with the US government and potential issues with all that on the horizon and I really, truly believe it's time to switch, for your own good.

    Please. Even if you're not going to run out and install Linux tomorrow, you need to start mentally preparing yourself for the inevitability of the task. Get yourself accustomed to the idea and when you're ready to dip your toes in, just know how many resources are out there for you.

    And to the Linux community out there, there are going to be a lot of newcomers who don't have the technical skills to undertake this and enjoy/appreciate this in the same way as you do. Be kind to them, the need for us to support each other has never been greater. Please.

    DRM is already the primary purpose of trusted compute if you read shareholder meeting transcripts; security is a marketing side effect.

  • DRM is already the primary purpose of trusted compute if you read shareholder meeting transcripts; security is a marketing side effect.

    Ya boy Richard Stallman agrees and has been saying this for years (although this article is more recentish), https://www.gnu.org/philosophy/can-you-trust.en.html

    “Treacherous computing” is a more appropriate name, because the plan is designed to make sure your computer will systematically disobey you. In fact, it is designed to stop your computer from functioning as a general-purpose computer. Every operation may require explicit permission.

    As of 2022, the TPM2, a new “Trusted Platform Module”, really does support remote attestation and can support DRM. The threat I warned about in 2002 has become terrifyingly real.

    Actual, honest to god reasons to upgrade to Windows 11 are already vague and questionable. Your average user probably doesn't even see any particular reason and only perceives the nuisance of it. But it's hard to fully close your iron fist around a platform when TPM enablement is so sparse in the consumer space. So what better way to do it than a mandatory OS upgrade with it as a system requirement and assure all (or a vast majority of) systems align at once?

    Of course there are ways for stubborn users to skirt those requirements, but that misses the primary point of Trusted Computing. While the OS may baseline function to some degree, there's no telling what functionality may be crippled by not being in a trusted state. EDIT: For example, this could easily tie into games with anti-cheat such that they will refuse to run on Windows 11 unless TPM is enabled.

    I don't know the future any better than anyone else, I'm just trying to read the winds at the moment. I suspect they may not try to pull the entire trap closed all at once and that Windows 11 may continue to more or less function as we've seen past iterations. But the pieces will be in place by then and it's only a matter of time before some greedy exec gives the word .....

  • This rings a little hollow to me. Most of the people I know that understand Linux can quickly summarize why they might not use it as their daily driver (eg staying on macOS for graphics/video or staying on Windows for desktop Word/Excel). If you can’t summarize that quickly, it really makes me wonder if you really understand it. I’m not trying to No True Scotsman my way around it; I really don’t understand.

    Right? I tried to switch my primary computer (framework laptop) to Linux earlier this year and ended up going back to windows after I had absolute nightmares with my type-c KVM. Coupled with performance issues while gaming (and the absolute hassle of having to force games to use my graphics card). Add in whatever random issues I was getting trying to remote into other windows machines on my domain (for CAD work). My day job is in software engineering/ programming, so I'm not exactly a stranger to digging through documentation and fixing computer issues, but spending time fixing my computer instead of using it got old pretty quick.

    Perfectly happy with Linux in my HomeLab and on my steamdeck though!

  • I would not want to use it [Linux or BSD] as my primary desktop system for too many reasons to go into here.

    The Linux kernel not having a stable driver ABI is why Linux will never amount to anything outside of some embedded and server applications.

    --- Maya Posch, author of the submitted article

    I guess maybe that's their reason.

    never

    That tweet must be some kind of joke, because I don't know what to make of the many people who use Linux outside of embedded and server applications. And it doesn't even have to be my hearsay because the Steam Deck is exactly such a device.

    In fact, I have a USB audio interface which I use near daily on Linux that has no driver support in modern Windows, because the vendor only provided beta support for Windows 7 as that OS was releasing. By Windows 8 it was unsupported. So the journey of that device is XP->Stable, Vista->Stable, 7->Unstable, 8+-> Non-functioning. If the driver ABI were so stable, why does my device not work on Windows anymore?

  • The article focuses a lot on the security of the boot process, but there's no reason the TPM can't be used for DRM as well (as an example, https://ieeexplore.ieee.org/document/5283799). It's correct when it points out the locked down nature of consoles and phones.

    We could conceivably be in for a future where Windows refuses to run code that's not validated even after the OS boots. Or where it sees pirated software on the system and refuses to function in some manner until the software is removed/corrected to its liking.

    There are so many possibilities here and all of them are bad.

    • Forced online accounts so Microsoft always knows when/where you login
    • Stored encryption keys so Microsoft could theoretically provide access to any computer the government requests
    • Telemetry already reporting god only knows what metrics about what and how you use your software
    • Forced AI that literally watches everything you do on your screen storing it in a known location making for a valuable target and also potentially/likely being used to create more telemetry and insights into your habits
    • Eventual full control over your hardware by enforcing "trusted platform" restrictions

    It's so fucking brazen I'm gobsmacked. As an elder Millennial, I get it, I can already hear most of you tallying in your head if having to care about your OS is gonna be the final straw . This is no longer a nerdy request to please use Linux, this is a five alarm fire. Add to all this how much Microsoft is in bed with the US government and potential issues with all that on the horizon and I really, truly believe it's time to switch, for your own good.

    Please. Even if you're not going to run out and install Linux tomorrow, you need to start mentally preparing yourself for the inevitability of the task. Get yourself accustomed to the idea and when you're ready to dip your toes in, just know how many resources are out there for you.

    And to the Linux community out there, there are going to be a lot of newcomers who don't have the technical skills to undertake this and enjoy/appreciate this in the same way as you do. Be kind to them, the need for us to support each other has never been greater. Please.

    You're making up scenarios so you can get outraged over them and push linux lol.

  • Right? I tried to switch my primary computer (framework laptop) to Linux earlier this year and ended up going back to windows after I had absolute nightmares with my type-c KVM. Coupled with performance issues while gaming (and the absolute hassle of having to force games to use my graphics card). Add in whatever random issues I was getting trying to remote into other windows machines on my domain (for CAD work). My day job is in software engineering/ programming, so I'm not exactly a stranger to digging through documentation and fixing computer issues, but spending time fixing my computer instead of using it got old pretty quick.

    Perfectly happy with Linux in my HomeLab and on my steamdeck though!

    See‽ Easy explanation. I get it, absolutely reasonable issues, and one of several areas Linux just isn’t great with. “Too many issues to explain here” doesn’t click with me.

  • You're making up scenarios so you can get outraged over them and push linux lol.

    Didn't Apple brick ipods if they had pirated audio files?

    Didn't Microsoft push a few updates that BSOD Windows OS if you weren't setup for their OneDrive cloud?

    Doesnt seem very made up.

  • Didn't Apple brick ipods if they had pirated audio files?

    Didn't Microsoft push a few updates that BSOD Windows OS if you weren't setup for their OneDrive cloud?

    Doesnt seem very made up.

    I had an ipod that was filled with "pirated" (ripped) audio files, never owned a single itunes purchased song, and have used Windows on many computers that didnt have OneDrive setup and never experienced either of those.

    Do you have some sources for those cause I'd be interested to read about them.

  • You're making up scenarios so you can get outraged over them and push linux lol.

    TPM was known to be a DRM Trojan horse in 2004. Then everyone forgot about that fact.

    Sure, pushing Linux is just a new angle, but don't think for a second that TPM has any purpose other than making your own computer trust a cabal of corporations over you, the owner. And if there is a critical mass of TPM standardized hardware, such that a "trusted" environment is the standard, it will lock you out of major use cases on all "untrusted" systems, including Linux.

    And that deserves a lot of outrage.

  • You're making up scenarios so you can get outraged over them and push linux lol.

    Hey man, yeah, I get it. I worry a lot about sounding like a conspiracy theorist; a real Chicken Little.

    But when I look internally and ask myself why I make these posts, why I conspire so much about unknown futures, I come to two most likely outcomes:

    1. I'm trying to trick you into installing Linux for some reason. Selfishly I guess if there's a larger userbase demanding support for things then I can expect better support for myself. Or I'm just trying to sound like a pompous smartass in front of internet strangers. But those are a little obtuse.
    2. I see a bunch of people standing in what I perceive (possibly incorrectly, but nonetheless) a trap and I'm shouting, "Hey, get outta there now before it springs!" because I have general empathy towards other people.

    Worst case I'm wrong and I look a fool. I really don't have a problem with that. I know who I'd trust if the positions were switched 💯

  • Ya boy Richard Stallman agrees and has been saying this for years (although this article is more recentish), https://www.gnu.org/philosophy/can-you-trust.en.html

    “Treacherous computing” is a more appropriate name, because the plan is designed to make sure your computer will systematically disobey you. In fact, it is designed to stop your computer from functioning as a general-purpose computer. Every operation may require explicit permission.

    As of 2022, the TPM2, a new “Trusted Platform Module”, really does support remote attestation and can support DRM. The threat I warned about in 2002 has become terrifyingly real.

    Actual, honest to god reasons to upgrade to Windows 11 are already vague and questionable. Your average user probably doesn't even see any particular reason and only perceives the nuisance of it. But it's hard to fully close your iron fist around a platform when TPM enablement is so sparse in the consumer space. So what better way to do it than a mandatory OS upgrade with it as a system requirement and assure all (or a vast majority of) systems align at once?

    Of course there are ways for stubborn users to skirt those requirements, but that misses the primary point of Trusted Computing. While the OS may baseline function to some degree, there's no telling what functionality may be crippled by not being in a trusted state. EDIT: For example, this could easily tie into games with anti-cheat such that they will refuse to run on Windows 11 unless TPM is enabled.

    I don't know the future any better than anyone else, I'm just trying to read the winds at the moment. I suspect they may not try to pull the entire trap closed all at once and that Windows 11 may continue to more or less function as we've seen past iterations. But the pieces will be in place by then and it's only a matter of time before some greedy exec gives the word .....

    I suspect they may not try to pull the entire trap closed all at once and that Windows 11 may continue to more or less function as we've seen past iterations

    Microsoft will be taking a page from Google playbook. Google has be gradually reducing the "openness" of their android platform. They now have these "security checks" enforced on android. Meaning that it's trivial for an application to determine if the phone a "genuine android" or not.

    This'll trickle into webbrowser too (if it's not already in browsers like chrome). It's only a matter of time before web pages will be able to determine if they're running on a "secure OS" and fail to run. It'll start out with your banking website, then expand to shopping websites, ultimately every page will enforce it ("oh, I see you have an unauthorized browser plug in installed. We care about your security, therefore we won't run. Please restore your device to it's secure defaults.")

    This future is so horrible and Linux with its 4% market share won't change anything.

  • I suspect they may not try to pull the entire trap closed all at once and that Windows 11 may continue to more or less function as we've seen past iterations

    Microsoft will be taking a page from Google playbook. Google has be gradually reducing the "openness" of their android platform. They now have these "security checks" enforced on android. Meaning that it's trivial for an application to determine if the phone a "genuine android" or not.

    This'll trickle into webbrowser too (if it's not already in browsers like chrome). It's only a matter of time before web pages will be able to determine if they're running on a "secure OS" and fail to run. It'll start out with your banking website, then expand to shopping websites, ultimately every page will enforce it ("oh, I see you have an unauthorized browser plug in installed. We care about your security, therefore we won't run. Please restore your device to it's secure defaults.")

    This future is so horrible and Linux with its 4% market share won't change anything.

    Agreed.

    And what's particularly galling about this is that it's never made any sense to me. Are you telling me an Android app, on compromised hardware or otherwise, could send malformed data that would for instance deposit $1M into my bank account? That doesn't sound like an issue of local security. An app is just a frontend, all validation would still be through the banking infrastructure.

  • This rings a little hollow to me. Most of the people I know that understand Linux can quickly summarize why they might not use it as their daily driver (eg staying on macOS for graphics/video or staying on Windows for desktop Word/Excel). If you can’t summarize that quickly, it really makes me wonder if you really understand it. I’m not trying to No True Scotsman my way around it; I really don’t understand.

    The reasons I personally know are "I have to use an app for work, there is no interoperable alternative, I have no leverage to replace that entire ecosystem and it won't run with wine" and "It's a company-issued device where I have no rights to change anything anyway."
    Combined, they make the reason that my work Laptop runs Win11, but my private PC is Linux through and through. I'd like to be able to use said app on my private PC too, but if it doesn't, no big deal.