56 ms·
Installing Windows 11 on Legacy BIOS Without Secure Boot
- easton 5y agoMicrosoft said that the secure boot and TPM requirements will not be enforced by the OS now but will by time Windows 11 hits RTM (which is why the Windows 11 installer enforces it even though the OS runs fine). https://blogs.windows.com/windows-insider/2021/06/24/preparing-for-insider-preview-builds-of-windows-11/ https://blogs.windows.com/windows-insider/2021/06/24/prepari...
- swiley 5y agoPersonal computing is completely dead except for enthusiasts. We've completed our regression to the late 70s.
- nijave 5y agoWhat does this even mean? Secure boot has little impact on anything except reducing the complexity of Windows (since it doesn't need as many boot configurations)
- zozbot234 5y agoReducing the complexity how? Their Legacy boot code is already written, and legacy BIOSes aren't going to change either. That code basically comes for free to MS.
- nijave 5y agoMaintaining old code has a cost. Any changes Microsoft wants to make need to be compatible with the old code unless they remove it Things like tests/validation on new hardware is also costly. Microsoft (used to?) have an absolutely massive fleet of physical hardware to test Windows on
- swiley 5y agoI guess if the firmware allows users to install their own CA it's ok. I wouldn't be surprised if that feature was neglected by the OEMs or intentionally removed with windows 12.
- zozbot234 5y agoTo their credit, Microsoft has signed a secure boot "shim" that allows the user to do that, with explicit prompting. It's being used in the boot flow of many Linux distributions.
- userbinator 5y agoIn other words, it was Microsoft who effectively "gave permission" for Linux to run. One OS company has control over whether they allow competitor's OSs, on hardware that the company doesn't even produce. That should be an absolutely horrifying thing to anyone who believes in software freedom.
- foobar33333 5y agoYou can disable secure boot and add your own keys in the firmware config page. Who knows how long that will last though.
- cesarb 5y ago> You can disable secure boot and add your own keys in the firmware config page. You can disable secure boot or add your own keys because Microsoft required all manufacturers to allow it. If it wasn't mandated by Microsoft, some manufacturers would not allow it. And for ARM devices, Microsoft required the opposite (https://softwarefreedom.org/blog/2012/jan/12/microsoft-confirms-UEFI-fears-locks-down-ARM/ https://softwarefreedom.org/blog/2012/jan/12/microsoft-confi...). So yes, the only reason we can run non-Microsoft operating systems on our computers is because Microsoft "gave permission".
- wildrhythms 5y agoI understand the risk and want to forego secure boot. What's wrong with that?
- philistine 5y agoI'm on the Mac side, and I wanted to reinstall macOS. I messed up the hard drive wipe and ended up breaking the chain of trust. That meant Apple could no longer guarantee the correctness of my install, and no longer allowed my laptop to decrypt my data to reach the login screen directly. I had to input the password for my login at an earlier step during boot, which comes with a litany of small caveats. I'm sure Microsoft hopes to achieve something similar here at some point: secure boot would give them enough trust to decrypt an install upon boot all the way to the login screen.
- zozbot234 5y agoAt least you could recover by simply typing a login password. A similar screwup on a Windows box might require you to resort to BitLocker recovery keys, which add a fair bit of complexity and some users might not have these at all.
- Datagenerator 5y agoNothing wrong with freedom. Not running the master of all telemetry OS increases the possibility to read and study what you want without feeding the data hungry sensors Microsoft has set in stone for you. These datasets are brought to market with your consent (see the thousands of EULA pages you accepted directly and indirectly).
- swiley 5y agoAlso, turning off secure boot doesn't change the boot process on Microsoft's side, they have to ask the firmware after booting if it was disabled. Sorry for replying twice but I'm almost always stuck on noprocrast so I can't usually edit my comments.
- selfhoster11 5y agoIt makes Linux more complicated to deploy, for one. And if they ever change their mind and don't allow it on x86 any more, Linux is basically exiled from the PC OEM market.
- easton 5y agoIt shouldn't, as Microsoft made sure that the major distros (Ubuntu, RHEL, Fedora, CentOS, maybe Debian?) have access to a signing key that is trusted by the major OEMs. And you can trust your own keys, per the Microsoft guidelines that require that x86 machines allow their secure boot to be disabled. https://docs.microsoft.com/en-us/windows-hardware/drivers/bringup/uefi-requirements-that-apply-to-all-windows-platforms#security-requirements https://docs.microsoft.com/en-us/windows-hardware/drivers/br...
- dataflow 5y ago> per the Microsoft guidelines that require that x86 machines allow their secure boot to be disabled. Yeah but then you can't boot into Windows? Who is actually going to go into the firmware settings to switch settings on and off for every single boot to the other OS?
- blibble 5y agoyou can boot debian/redhat/... out of the box without disabling it, as the shim used as part of the boot process has been signed by MS if you want to sign your own kernels: the shim will also let you do that relatively easily ("machine owner keys") if you want to own your entire boot process you can replace the platform key and sub-keys with your own, and then trust whoever you want (even adding MS' keys if you wish, so Windows can boot in secure mode)
- kelnos 5y agoI'm pretty sure we don't want to be in a world where we can only use one of a few Microsoft-approved Linux distros without it being a pain the the ass to deal with.
- bserge 5y agoSorry, but 7 was way more stable than 8-10 and it didn't even support SecureBoot.
- dlp211 5y agoAs much as you want this to be true, it simply isn't.
- formerly_proven 5y agoAny "Windows x was more stable than Windows y" (including the legally mandated "No, it wasn't" replies) is mostly rooted in what drivers the person used and if the hardware had issues, and has less to do with Windows.
- pjmlp 5y agoWhat do you expect when people buy Apple laptops to do GNU/Linux work instead of improving the ecosystem of Linux OEMs? Or are now rushing to give money to Microsoft and use WSL? Well, that is how things eventually turn out to be.
- jk7tarYZAQNpTQa 5y ago> Personal computing is completely dead except for enthusiasts So you're saying only enthusiasts have smartphones?
- zozbot234 5y agoWhat's even the point of enforcing these requirements when the OS seems to be running quite fine otherwise? Users who are running without SB or a compliant TPM will simply stay on Windows 10, and maybe stay on it past the official EOL date.
- temac 5y agoThat's an early build, maybe Windows 11 RTM will actually always use a TPM (1.2 is advertised as minimally supported though). As for secure boot, I don't see how that could be anything else than policy (that can have an impact on a security model and so on associated security measures, granted, but not having secure boot should technically not prevent booting / installation unless it is enforced by an explicit artificial limitation). But they could at least remove legacy boot support, in which case it just won't work without UEFI.
- omegalulw 5y agoI suppose they don't want to support legacy hardware. If they let it install, people will complain when something breaks.
- opencl 5y agoIf the other requirements they've posted are accurate then the CPU list alone will eliminate anything more than about 3 years old.
- wubbert 5y agoThey're doing this to force people to buy new hardware and a new Windows licence. If they let you upgrade from Windows 10 for free, they don't make any money. They've already gotten people used to free updates, so they can't charge money for Windows 11 upgrades directly. Most people buy pre-built computers, so a Windows 11 licence will be included by default for most, so they will make more money.
- kawsper 5y ago> They're doing this to force people to buy new hardware Forcing people to buy new hardware while there's a global chip shortage is going to be interesting.
- arsome 5y agoIs Windows 11 likely to perform some sort of attestation for this? Or are we likely to see something like the way the old Windows cracks used to work - a hacked up version of Grub or another bootloader able to patch the necessary firmware and BIOS information before chainloading Windows.
- userbinator 5y agoUnless it's doing some sort of remote-code-download-and-execute(!) based on the attestation results, it will always be possible to crack everything locally. All the checks just need to be patched out, and finding them all is the hard part, but it is theoretically possible as long as you still have full control over the hardware. But such a setup will be very fragile to automatic updates (which are already difficult enough to turn off completely as it is), and with this whole "update mentality" I wouldn't be surprised if they eventually leave in certain security holes and use those as an additional force to coerce people to take their updates --- along with everything else the users didn't want.
- blibble 5y agohow would you patch them out? the disk will be encrypted with a key stored in the TPM that will only be supplied to a signed OS, so you can't alter the contents on disk if you've booted in secure mode you can't interfere with the boot process and the OS won't let you patch it online if they pull it off correctly there's not much you can do they can even detect the effects of exploits using remote attestation if a machine has had its environment compromised it won't be able to get updates/watch youtube/play games/... (using old software/firmware with known exploits can be similarly blocked, until you upgrade)
- arsome 5y agoYou're talking about a fantasy world that doesn't exist where Microsoft has gone to extreme precautions like you see on mobile devices and game consoles where there are constant attempts to steal the ownership from users. In the actual world they don't even enforce disk encryption right now and correct me if I'm wrong, but currently having your BitLocker "recovery code" is enough to decrypt the disk on another machine and changing that would be a massive issue for many data recovery processes. Unless they plan to do massive changes to the system this is very likely to not be a problem and cracking is likely to still be quite possible.
- gjsman-1000 5y agoIn other bad news, Microsoft developers on Twitter stated that 8th Gen Intel or 2nd Gen Ryzen CPUs will, actually, be required to install Windows 11 at all by RTM. If you are on 7th gen Intel or 1st gen Ryzen, there is no mercy. A 2013 MacBook gets more support than a 2017 Windows laptop. https://linustechtips.com/topic/1351028-microsoft-makes-things-worse-again-windows-11-actually-will-not-run-on-anything-below-8th-gen-intel-ryzen-2000/ https://linustechtips.com/topic/1351028-microsoft-makes-thin... A security director now says that a blog post "clarifying the floor" is coming. But frankly, if this turns out to be a miscommunication, if you read those tweets Microsoft would have to be unbelievably incompetent in their use of words.
- JohnTHaller 5y agoIf you meant an Early 2013 MacBook Pro, the current macOS Big Sur doesn't support that. If you meant a Late 2013 MacBook Pro, macOS Monterey releasing later this year drops support for it and all MacBook Air/Pro before 2015 as well as all MacBooks before 2016.
- gjsman-1000 5y agoOld versions of MacOS get about 2-3 years of additional security updates. So if you bought a 2017 laptop with a 7th gen processor, you got 8 years of support from 2017 to 2025. Unless you bought Surface Studio 2, which is $3499 from Microsoft and comes with a 7th gen chip so it only gets 4 years of support. If you bought a 2013 MacBook which just got cut off at Big Sur, you'll probably get supported to 2024, or 11 years.
- Wowfunhappy 5y agoYes, Apple sucks at legacy support in many respects. Luckily, Macs are only ~10% of the PC market, so they can't create as much of an e-waste disaster. Two wrongs don't make a right and I expect better of Microsoft.
- techrat 5y agoThat CPU list was missing CPUs that were still being sold in new builds even less than 3 years ago. That's quite the severe cut off point. My older box, an i7 4790k, is still quite the performer. It, however, has no secure boot capabilities. No TPM socket on the motherboard, even.
- Sherl 5y agoSo my perfectly fine Thinkpad P51 can't run a win11 because of processor requirements? Are they selling CPU chips or Windows 11 to the market??
- gruez 5y agoAre you sure it doesn't have PTT? AFAIK recent-ish intel CPUs should have TPM support using the trusted computing capabilities of the CPU itself, without the need for a discrete TPM chip.
- gjsman-1000 5y agoMicrosoft has clarified on Twitter of all places that TPM 2.0 isn't the only requirement. It must be 8th Gen Intel or 2nd Gen Ryzen or newer regardless of whether it has a TPM.
- noxer 5y agoBut no one actually cares if it meats the requirement. What matters is only if it runs. Unless you need some kind of MS verified system. The fact is the leaked version runs on a 10 year old toster. the only limit is 64-bit CPU.
- homero 5y agoWhat CPUs have TPMs?
- gruez 5y ago>Firmware TPMs are firmware-based (e.g. UEFI) solutions that run in a CPU's trusted execution environment. Intel, AMD and Qualcomm have implemented firmware TPMs. https://en.wikipedia.org/wiki/Trusted_Platform_Module https://en.wikipedia.org/wiki/Trusted_Platform_Module
- temac 5y agoIt's very probable that Windows 11 will run on your P51. You may have a warning advising you to stay on Windows 10, but it will fit the hard floor so you will be able to upgrade regardless. IIRC the hard minimal req different from Win 10 is a TPM, 64 bits >= dual core, I think UEFI + secure boot, and WDDM >= 2.0. I just checked on a Kaby Lake and I have everything needed. The published list of processors is probably for the soft floor and/or for OEMs. Now, knowing MS and especially the situation in regard with some processors following the Win7 -> 10 migration, there is always the risk they fuck up the support even more for unlisted processor, voluntarily or not...
- codetrotter 5y agoI thought they said that Windows 10 would be the only version of Windows forever, and that everything would be updates of Windows 10. Did they change their mind or did I misunderstand in the first place?
- mirthflat83 5y agoYes. They’re copying macOS. Apple decided to change their numbering with Big Sur
- Dah00n 5y agoThis has nothing to do with Apple. Big Sur, released in 2020, cannot possibly have any impact on the naming of Windows that started in 2009 with Windows 7.
- Dylan16807 5y agoBig Sur is when they went from "everything is 10" to 11. The accusation is that moving off of TenVer is following them, as was getting onto TenVer in the first place. And Microsoft was definitely on TenVer. If they were merely incrementing from 7 they wouldn't have skipped 9 and they wouldn't have stuck on 10 nearly as long.
- cunthorpe 5y agoYou don't know why they skipped 9? Your argument makes no sense. The comment above is 100% correct. Just because Apple left v10 it doesn't absolutely mean Microsoft is just doing it to copy it. You're talking absolute nonsense. Apple doesn't even call it macOS 11 publicly so it doesn't even make sense from a marketing perspective.
- Dylan16807 5y agoThey skipped 9 because they thought ten sounded better. Because TenVer, which is what apple was also doing. Got some other reason in mind? I'm very confident it wasn't backwards compatibility, by the way, so please name a specific program that would have errored if you claim that. Windows lies about its version to old programs.
- teekert 5y agoPsst, you can install Linux directly on the metal, no need for WSL!
- lazypenguin 5y agoLinux as the main OS with windows as a guest VM feels like the right idea for me. Setting this up with gpu pass-through is on my todo list!
- djrogers 5y agoNot unless your hypervisor can emulate a TPM chip.
- RandomBK 5y agoAlready done: https://qemu-project.gitlab.io/qemu/specs/tpm.html https://qemu-project.gitlab.io/qemu/specs/tpm.html
- useryman 5y agoI don't think most of these restrictions apply if you're running in a VM anyway. Plus, they don't think they want to break VM support, either on a personal or business level.
- MeinBlutIstBlau 5y agoThey kinda can't seeing as that's kind of the goal with Azure with cloud based VM's and whatnot.
- culopatin 5y agoI tried to go back to Linux in one of my laptops recently (old x220 I want to use for ECU programming). I used to be a gentoo user before their wiki disappeared. It seems to me like Linux is going through a growing phase with several growing pains. Why are my graphics working worse out of the box with common Intel Graphics than back in the day? Bluetooth is a terrible experience. Wifi doesn’t work 60% of time and I don’t know why, the UI won’t tell me. These used to be issues in the past but I figured that 15 years of progress would’ve changed. However I am aware that all these problems are open and it’s up to me to fix them and I feel no entitlement or have any expectations out of a free and open product. I wish I was better equipped to assist in fixing them myself. Unfortunately I ended up putting Windows back in that laptop. For a while I used it as a hackintosh and to be honest it worked better with High Sierra than it did with Mankato or Ubuntu.
- neilv 5y agoAlternatively, you can avoid repeating the historical cycle of lobster-boiling, with the help of https://www.debian.org/ https://www.debian.org/ , https://archlinux.org/ https://archlinux.org/ , or other distros.
- least 5y agoYou’re just replacing one set of problems with a different set of problems. Linux isn’t a panacea. It has its own set of meaningful issues that make it an unattractive option to a lot of people. I do agree at least that not enough people ever make that consideration that should, but that kind of requires qualities that free software either doesn’t care about or is not competent at (ie marketing)
- MeinBlutIstBlau 5y agoI love linux but it's still not at a point where I'd even recommend it to any computer illiterate person.
- 542458 5y agoThis is getting downvoted, but honestly? It’s kinda true. Normal tasks like setting up hardware (drivers), using HiDPI displays, and installing software can be a struggle. Many tasks require a user to jump into a terminal and run arcane commands (which sometimes have to be tweaked for your specific distribution - good luck). Even the user-friendly Linux distros can be very challenging.
- MeinBlutIstBlau 5y agoI mean today compared to 10 years ago it is in a far better spot. But the FOSS nature of everything still makes it difficult to fix every nit picking gui bug. Right now there is an issue I've encountered with Manjaro where it just doesn't register a left click for some reason. No idea why but I need to restart to fix it if it happens. That is enough for any end user to write it off completely.
- 5y ago
- Wowfunhappy 5y agoFor the Legacy BIOS piece, has anyone tried using Clover? It's a bootloader designed for Hackintosh systems. macOS is and always has been EFI-only on Intel computers, and when Clover was released EFI was still uncommon on PCs. So, Clover has its own EFI implementation that can be started from a BIOS boot.
- culopatin 5y agoThe problem is that Windows updates overwrite the EFI partition very frequently. I have updates disabled in my dual boot hack in case I accidentally pick Windows at boot. I have Windows just in case I mess something up on the Mac side and I NEED to get something done
- Wowfunhappy 5y agoHuh, I don't seem to have that issue using Clover for Hackintosh/Windows dual boots. Edit: Oh, but I have Windows on a separate HDD from Clover!
- culopatin 5y agoYeah that’ll do it. I have it on a Thinkpad X1 yoga with just one physical drive
- Causality1 5y agoI wonder if an AME version of W11 will get released. Requiring me to have a Microsoft account to log into my own computer is a do-not-pass-Go unacceptable condition.
- FridayoLeary 5y agoI wonder how long it will take MS to close this gap.
- walterbell 5y agoFor those considering a new machine for Windows 11, remember that upcoming Intel and AMD and Qualcomm-Nuvia-Mx CPUs will include the built-in Microsoft Pluton (inspired by XBox) hardware root of trust, which will play a role similar to Apple T2 or Google Titan. Announcement: https://www.microsoft.com/security/blog/2020/11/17/meet-the-microsoft-pluton-processor-the-security-chip-designed-for-the-future-of-windows-pcs/ https://www.microsoft.com/security/blog/2020/11/17/meet-the-... > The Pluton design removes the potential for that communication channel to be attacked by building security directly into the CPU. Windows PCs using the Pluton architecture will first emulate a TPM that works with the existing TPM specifications and APIs, which will allow customers to immediately benefit from enhanced security for Windows features that rely on TPMs like BitLocker and System Guard. Windows devices with Pluton will use the Pluton security processor to protect credentials, user identities, encryption keys, and personal data. None of this information can be removed from Pluton even if an attacker has installed malware or has complete physical possession of the PC. Speculation: https://www.reddit.com/r/Windows11/comments/o5r2qz/speculation_windows_11_will_be_the_first_to/ https://www.reddit.com/r/Windows11/comments/o5r2qz/speculati... Background on secure boot: https://cacm.acm.org/magazines/2020/3/243026-securing-the-boot-process/fulltext https://cacm.acm.org/magazines/2020/3/243026-securing-the-bo...
- megous 5y agoGreat that it can't be removed, but can it be used by the malware on the system to perform the task on behalf of the user? In the days of always connected computers just remotely controlling the SW on the HW itself is enough to do pretty much all the interesting things you could do (as a criminal) if you were in physical possession of the computer itself.
- avereveard 5y ago> None of this information can be removed from Pluton even if an attacker has installed malware or has complete physical possession of the PC. Uh and how am I supposed to sell my used pc?
- wazzaps 5y agoBy "removed" they mean "stolen" or "copied"
- tyingq 5y agoWindows 10 does have mbr2gpt.exe now, so migrating from Legacy to UEFI isn't a terrible experience, provided you do it from the recovery/boot/troubleshoot Windows screen.
- shadilay 5y agoI've used it migrating from MBR/SATA to GPT/NVMe and I still have nightmares about it. That and Dell's truly atrocious UEFI.
- tyingq 5y agoI've not used it to move from one physical drive to another. Just in-place migration. It's worked fine that way several times.
- shadilay 5y agoNothing ever works as it should. I've also had several GPT->MBR automatic downgrades borking the install.
- fuzzfactor 5y agoThere really shouldn't be a need for mbr2gpt.exe except as an instructional aid to see how they accomplish the deed. Keep in mind that using an MBR-layout HDD (SSD) is specified to be fully supported by UEFI. No need for a GPT-layout HDD to begin with except on some screwy sub-specification UEFI firmware on a number of crummy things like tablets which have no Legacy CSM and which for a while were too defective to even recognize an MBR-layout USB device for booting. Recently worked out the latest reference implementation of a dual-boot Windows/Ubuntu HDD that boots on "any" x86_64 hardware whether BIOS or UEFI, using the most recent W10 21H1 and Ubuntu 21.04 released over the last few months. There's never been a reason to settle for less than a HDD which will boot on the widest variety of PCs that you might need to quickly physically transfer the HDD hardware over to. Just in case the PC fries in the middle of an important session and the HDD is still good, you need to be able to just remove the HDD and place it into whichever backup PC you might have available. In this type emergency you really need a HDD layout that can accomodate the widest variety of new & vintage PC hardware, just in case. Nothing less is an option. Unless you want to admit that you haven't really tried to get maximum reliability out of fundamental hardware & software to begin with. For partition 1 it still works great to have a plain ordinary FAT32 volume (which is preferred by UEFI and still works the regular old way for Legacy BIOS boot) and for that a 32GB size is the traditional maximum amount that is really comfortable for Windows98SE (and the FAT32+DOS it was based on). So I can actually boot to a W98SE DOS floppy if I needed to and (re)format partiton 1. This is a bog-standard boot partition layout on the HDD, which will be used by both BIOS or UEFI, whichever one you need at the time. At this point the HDD is so conventional that you can even install W98SE or at least its underlying DOS version if you tried but it will only boot with UEFI+LegacyCSM (or a real BIOS mainboard), and you may have to use IDE mode for the HDD to load W98 (like often needed with WXP), plus maybe even more changes to BIOS settings. DOS alone still works OK in SATA mode, and DOS can also handle USB drives recognized by the BIOS if they are plugged into the PC before you boot to DOS. No need for trying to load USB hardware drivers in DOS unless you need to plug in USB drives after you have booted the DOS PC. DOS handles FAT format volumes only, and not even NTFS. And this is on a high-performance layout for improved reliability operating the latest Windows (plus dual-boot Linux to boot) for current mainboards at the same time. But normally you don't need DOS or W98 so I just make the first partition 30GB in size and format it FAT32 using Windows 10 or using the command line when booted to the W10 setup media. Backward-compatibility in so many ways, exactly along these lines is the main thing that makes Windows worthwhile, without it why bother? Last time I checked, mbr2gpt would only handle about a 1GB FAT32 boot volume, so if I did want a quick conversion that would seem helpful, but I have tested this app for reliability well within this limitation and it failed miserably even on simple layouts like I am posting here (using a much smaller FAT32 volume for testing). There is also another comment about failed conversion on what is probably a regular Dell business machine. Not good enough for general use as can be seen. So might as well treat your HDD, Windows, Linux and youself to the roomy & useful 30GB FAT32 volume of your '90's dreams. Even if all we're really going to put there are some non-sizable boot files & folders, I still would use the full 30GB unless the HDD is smaller than about 120GB. Then any night you want to in the future you could actually party like it's 1999 if you get a wild hair. Could also add a bootable live Linux distribution right there on the FAT32 volume independently of the Linux which will be fully installed to its own EXT-formatted volume later. Live distributions usually boot on FAT32-formatted USB sticks anyway. This would be another optional OS you don't really need on the (functionally hidden) FAT32 boot volume of the basic Windows/Ubuntu dual-boot HDD, unless the installed Ubuntu itself turns out to be unsatisfactory for something. So none of that at this point either, no extra distribution(s), no W98, nor DOS. Just a regular valid binary Master Boot Record with its accompanying partition table stored in sector 0. The partition table which defines a 32GB or less Actively Marked partition1, and this boot partition has been formatted FAT32 and has the appropriate Volume Boot Record for either Windows or Linux bootability under Legacy BIOS. On the FAT32 volume, boot files and all accompanying boot folders readable from the filesystem for both Windows and Linux, supporting BIOS and UEFI booting for either OS. Concentrated in this particular choice of default locations, all the boot files for everything can easily be backed up, restored, or manually modified even when booted to an OS as simple as ordinary DOS if perhaps that might be needed as a last resort or something. If needed the entire FAT32 partiton can easily & quickly be reformatted and the boot files & folders replaced from backup. Without ever touching anything on the main Windows or Ubuntu partitions, each of which simply stand by waiting to be booted to from some appropriate boot files of some kind, whether bootfiles are executed by BIOS or UEFI. To support both Windows and Ubuntu for either BIOS or UEFI that makes a total of four complete sets of independent boot files on the Active bootable FAT32 volume. The same partition table which is also defining an NTFS partition2 and an EXT partiton3 in addition to FAT32 partition1. Windows ends up on NTFS partition2 except for its boot files and maybe the Recovery console folder on partition1. Ubuntu gets completely installed to EXTx partition3 except for its boot files on partition1. No separate /swap, /usr, none of that. Works like a charm and in Windows 10 the defects which could cause difficulties when physically moving the HDD to a different PC have been largely overcome. You may need to go into safe mode when including IDE mainboards or jumping to way different graphics, but usually any new drivers needed are autoloaded and you can do what you were doing as long as the alternative mainboard is not lacking some unique showstopping hardware your apps need. Both Ubuntu and Windows are continuously improving the relability of physical HDD relocation, and Windows actually seems to be pulling ahead of Linux in this respect, but it's still neck & neck. Of course this is only a fundamental layout for a full stand-alone PC without any dependence on web access or even networking to install, boot and be fully functional. Taking this into consideration in your approach when it comes to file management and things like that, you can join networks and webs to taste while maintaining full functionality during times when ethernet and wifi are disconnected, whether the disconnection is intentional or not. I actually enjoy plugging & unplugging my ethernet cord without any hesitation all the time. That's how I got completely comfortable leaving it unplugged almost always when in Windows except when I really need it. There is a stepwise outline and a full installation procedure to build the Windows/Ubuntu HDD if there is any interest.
- qalmakka 5y agoSo Microsoft has chosen to go down the Windows Vista route again. People are notoriously reluctant to update Windows, and if they really want to start this early with FUD about their next OS, it's very likely it's going to be rejected by the masses like Vista and 8. 10 took over 7 only because it was actually what people asked for, worked well and it worked like people expect Windows to behave. Lots of people keep computers for years now, and it's not that uncommon to see people still holding on 6 or 7 years old machines. Most people don't really need computers that much now that smartphones are ubiquitous, and even an old computer can run a browser or a word processor just fine. Microsoft still can't realize they are not Apple. People won't just buy a new computer just to run Windows 11. That's not how it works, Microsoft still hasn't really accepted they don't have neither the mindshare nor the appeal for doing moves like this. I thought they had learnt from their mistakes after the Vista/8/Kinect debacle, but I guess they just cannot.
- userbinator 5y ago10 took over 7 only because it was actually what people asked for, worked well and it worked like people expect Windows to behave. No, it took over only because of the silent forced upgrades that also included some typical malware-like dark patterns. There's plenty of stories here and elsewhere about it. Some examples: https://news.ycombinator.com/item?id=11837609 https://news.ycombinator.com/item?id=11837609 https://news.ycombinator.com/item?id=11784337 https://news.ycombinator.com/item?id=11784337
- bserge 5y agoAnd 7 being dropped by major software companies, which is the only reason Windows is the most popular OS, might I say. Not sure why Adobe et al don't just show Microsoft the middle finger and move to Linux, with their support everyone wins.
- novok 5y agoFind me a functional ecosystem of linux laptops that does basic shit such as... suspend and works for 10 years and does not need a linux IT professional to maintain for a small shop.
- vermilingua 5y agoWhat Windows 11 ISO are they talking about here? I haven't seen anything resembling an early access program.
- fwipsy 5y agoThere was a leaked ISO a week or two ago.
- Cyder 5y agoDdg or google tpm highjacking. There is no cure all for security just Microsoft taking control
- fsfod 5y agoI wonder if you can also install it using dism /Apply-Image from an existing windows 10 installation skipping the need to run the installer.
- csours 5y agoWasn't Win10 supposed to be evergreen?
- cube00 5y agoSomeone must have figured out evergreen doesn't equal enough flow of the green stuff.
- fouc 5y agoTL;DR: Install windows 10 installer on usb drive, then replace the sources/install.wim with the one from windows 11 ISO. Then boot off of that usb drive and it'll install windows 11 now.
- cube00 5y agoMy five year old Acer doesn't have a TPM, suspect a lot of people will be caught out by this.
- 542458 5y agoYep. i7 6700K on a relatively-high-end Asus matx board. No cpu support and no TPM slot. Kinda crazy, since it’s plenty powerful - I’ve felt no need to upgrade the processor or motherboard. You’d think that they could build a USB TPM or something.
- kaszanka 5y agoAll this talk of TPMs has me wondering: most of the premise of a TPM is that it's basically a hardware cryptographic device that lets you generate keys and do various operations with them, but never extract the key itself, right? Then, if you do actually want a TPM-like device that behaves mostly like a normal one but lets you get at the keys through some backdoor, what's stopping you from making and using one? Some manufacturer (model? batch?)-specific private key programmed at the factory that lets it authenticate itself as a genuine TPM?
- cesarb 5y ago> Some manufacturer (model? batch?)-specific private key programmed at the factory that lets it authenticate itself as a genuine TPM? Yes, AFAIK every TPM comes comes with a unique "endorsement key", signed by the TPM manufacturer, which can be used to prove that it's a real TPM from that manufacturer. A quick web search found https://tpm2-software.github.io/tpm2-tss/getting-started/2019/12/18/Remote-Attestation.html https://tpm2-software.github.io/tpm2-tss/getting-started/201... which explains how it's used.
- Arnavion 5y agoRemote attestation is for identifying yourself to a remote that has already agreed to trust you previously. If the remote has already agreed to trust device foo based on its TPM's EKpub, then foo's TPM can later prove that it's foo by signing something with its TPM's EKpriv. There still needs to be some prior out-of-band registration to register foo's TPM's EKpub with the remote. It makes sense for, say, an organization that provides the devices its employees use, because the organization can pre-register those devices' EKpubs in its servers and refuse to acknowledge any device that can't attest. But in the case of Windows, presumably MS is not going to become the single source of all Windows computers. At best, they might register your device's EKpub when you install Windows and create a MS account or something, but if you already had a backdoored TPM at the time, that backdoored TPM is what will get registered. It is also possible that MS could require a TPM with an EK certificate that is chained to a set of CAs based on some popular TPM manufacturers. That would certainly prevent you from using any device that doesn't have a "real official" TPM, but I feel this would be quite overkill of MS to do. Then again I would've said the same about an OS that requires a TPM in the first place, but here we are...
- bleair 5y agoHas Microsoft publicly made it clear that the true reason for the tpm requirement is all about shepherding all users into the windows App Store? As in users might be allowed to install non App Store programs for a while, but the operating system will give complaint/hassle dealings and require the user to go through several extra steps (aka macis). Some future windows releases will likely be licked to only allow Microsoft App Store-signed apps.
- Black101 5y agoWhat a surprise... MS following Google and Apple.
- Black101 5y agono thanks... I'll stick with Linux.
- SubiculumCode 5y agoWhat I am most concerned with for Win11 is Privacy...I suspect we are going to see some major consternation on that front as soon as Microsoft can be cornered on it.
- zenlambda 5y agoWhy is it acceptable to market an OS in 2021 where throwing out your current machine is “plan A”? Why is no one challenging microsoft to come up with an e-waste strategy?
- timonoko 5y agoCant u just install it in VirtualBox and copy and boot to the created virtual disk? I was just thinking about this, because I needed Windows 10 on old laptop.
- orionblastar 5y agoI usually upgrade my computer every 3 to 5 years. It won't run Windows 11 because of the CPU, but I can buy a new CPU and motherboard and RAM for a faster system that can run Windows 11 and transplant my other hardware to it. I think Microsoft wants people to buy newer hardware so OEMs can profit from it. I remember when a Pentium 4 could run Windows 7, 8.1, and 10 in the 32 bit edition.
- noxer 5y agoThis blog is 8 days old how is this relevant now? Also you can "deploy" window 11 on any SSD as windows2go and boot from it directly if you just want to test it out on real hardware. All checks are skipped this way and you can put the SSD in any toaster as long as it has a 64-bit CPU it will most likely run.
- xg15 5y agoOut of couriosity, would Win 11 install on a system with UEFI, Secure Boot and TPM2 enabled, but where you supplied your own keys - or does it require hardwired keys from Microsoft?
- dncornholio 5y agoOlder gen cpu's still run so well, they needed to think of something
- a11an 5y agoLooks like Microsoft will be getting a lot of people to move over to Linux. My pc is more than capable with 2 xeon cpus but my Dell t5500 has no secure boot!