4 ms·
> I find it quite interesting how they whitelisted their own Surface devices but not, say, Thinkpads, despite them having the same CPUs Because Lenovo did not
by Hawxy 3y ago
> I find it quite interesting how they whitelisted their own Surface devices but not, say, Thinkpads, despite them having the same CPUs
Because Lenovo did not bother writing DCH drivers, given DCH drivers are the baseline requirement.
> Could you explain in what way "DCH driver support" is a "hardware security mitigation" as you wrote?
I was recalling a 2 year old blog post in my head, but the point is still that much of the requirement is around baseline security. If you watch the video I linked, the speaker does go over all of this.
> basically let hardware vendors decide which otherwise-capable CPUs they'd like to make obsolete through software updates?
I'm not sure what you're getting at. DCH drivers were already the default for current-gen hardware _before_ W11 even came out, W11 just made it a requirement. Vendors clearly aren't going to go write some greenfield drivers for a years-old 6th gen intel product just to support W11, as those devices will be 10 years old by the time W10 support ends.
> note that the OS isn't even turning on the CPU features they require by default
Note that you're still referencing a blog post from 2021. W11 22H2 enables core isolation by default for new installations, and HVCI is enabled by default when using the Windows Enterprise security baseline.
https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-11-version-22h2-security-baseline/ba-p/3632520 https://techcommunity.microsoft.com/t5/microsoft-security-ba...
- dataflow 3y ago> If you watch the video I linked I have in fact. It's a nice talk about security in Windows 11, but I haven't seen anything in it answering these issues. He says absolutely nothing about DCH and doesn't give any explanation for the minimum hardware requirements. The closest I recall was he was mentioned of integrating Pluton on chip and making its firmware directly updatable, but I don't believe for example that the 7820HQ and the 7700HQ are any different with regards to Pluton. > I'm not sure what you're getting at. DCH drivers were already the default for current-gen hardware _before_ W11 even came out, W11 just made it a requirement. No, they didn't even make DCH a requirement; Windows 11 runs with standard drivers too. [1] And, again, DCH doesn't imply anything about hardware security mitigations, which was purportedly their reason for this. > Note that you're still referencing a blog post from 2021. W11 22H2 enables core isolation by default for new installations, and HVCI is enabled by default when using the Windows Enterprise security baseline. Because the situation is fundamentally the same since 2021. Core isolation support is not a distinguishing feature between (say) the 7700HQ and 7820HQ, as far as I know. And the Windows Enterprise security baseline seems kind of irrelevant for the millions of average consumer devices out there. A company that cares about consumers or the environment is telling consumers across the planet to turn perfectly good devices into electronic trash now because they might add something that helps security years later? I'm going to let my comments rest here; people draw their own conclusions. [1] https://www.reddit.com/r/Windows11/comments/pr4kmr/why_is_windows_11_still_force_installing_the/hdgp8z0/ https://www.reddit.com/r/Windows11/comments/pr4kmr/why_is_wi...
- Hawxy 3y ago> He says absolutely nothing about DCH and doesn't give any explanation for the minimum hardware requirements The hardware security baseline is one of the first topics he covers as part of Windows 11 security strategy, with mention given to features that require hardware support and how they intend to enable these by default going forward as not doing so was a failure of the Windows 10 strategy. He even mentions "virtualization extensions" aka HVCI-related features which would be non-performant to enable by default in older hardware. How exactly would a strategy of enabled-by-default work if the hardware wasn't there to support it? You seem to be looking for some hard "gotcha" statement to refute your argument instead of considering all of the information available in front of you. > No, they didn't even make DCH a requirement; By setting the minimium CPU requirement to systems that use DCH drivers, they effectively did. > Core isolation support is not a distinguishing feature between (say) the 7700HQ and 7820HQ, as far as I know. That's not the issue here. The 7700HQ lacks Trusted Execution support (aka TPM), whilst it's included in the 7820HQ, thus it does not meet the minimum requirements. > electronic trash now because they might add something that helps security years later? No, it's giving people the heads up that Windows 11 security strategy requires these features and gives people & companies time to adapt. For example, motherboards now ship with TPM 2.0 enabled by default, so as Windows 11 rolls out more features that require it (some aspects of Windows Hello already do), users aren't stuck with a system that needs a BIOS update or are unable to use the new features. Windows 12 will very likely make these requirements hard-enforced rather than soft-enforced and thus it'll make the 11-to-12 upgrade a smoother experience.
- TeMPOraL 3y agoIs it time to bring up the old "TPM is a good thing for you only if you're holding the keys - which almost nobody on the non-enterprise level is, so it's actually bad for you" discussion? > How exactly would a strategy of enabled-by-default work if the hardware wasn't there to support it? You seem to be looking for some hard "gotcha" statement to refute your argument instead of considering all of the information available in front of you. I'd say the core issue here is of priorities. Microsoft may be treating aggressive enabled-by-default approach to security as a good thing. A lot of other people don't. If you don't, then the high-level summary of the issue is, essentially, "By making some relatively recent hardware features a requirement for Win11 in the name of sekhurity, while also aggressively pushing users to upgrade and actively preventing them from continuing to use Win10, they're forcing people to destroy perfectly good machines for bullshit reasons". I'm having hard time seeing fault in this view.