3 ms·
> He says absolutely nothing about DCH and doesn't give any explanation for the minimum hardware requirements The hardware security baseline is one of the firs
by Hawxy 3y ago
> He says absolutely nothing about DCH and doesn't give any explanation for the minimum hardware requirements
The hardware security baseline is one of the first topics he covers as part of Windows 11 security strategy, with mention given to features that require hardware support and how they intend to enable these by default going forward as not doing so was a failure of the Windows 10 strategy. He even mentions "virtualization extensions" aka HVCI-related features which would be non-performant to enable by default in older hardware.
How exactly would a strategy of enabled-by-default work if the hardware wasn't there to support it? You seem to be looking for some hard "gotcha" statement to refute your argument instead of considering all of the information available in front of you.
> No, they didn't even make DCH a requirement;
By setting the minimium CPU requirement to systems that use DCH drivers, they effectively did.
> Core isolation support is not a distinguishing feature between (say) the 7700HQ and 7820HQ, as far as I know.
That's not the issue here. The 7700HQ lacks Trusted Execution support (aka TPM), whilst it's included in the 7820HQ, thus it does not meet the minimum requirements.
> electronic trash now because they might add something that helps security years later?
No, it's giving people the heads up that Windows 11 security strategy requires these features and gives people & companies time to adapt. For example, motherboards now ship with TPM 2.0 enabled by default, so as Windows 11 rolls out more features that require it (some aspects of Windows Hello already do), users aren't stuck with a system that needs a BIOS update or are unable to use the new features. Windows 12 will very likely make these requirements hard-enforced rather than soft-enforced and thus it'll make the 11-to-12 upgrade a smoother experience.
- TeMPOraL 3y agoIs it time to bring up the old "TPM is a good thing for you only if you're holding the keys - which almost nobody on the non-enterprise level is, so it's actually bad for you" discussion? > How exactly would a strategy of enabled-by-default work if the hardware wasn't there to support it? You seem to be looking for some hard "gotcha" statement to refute your argument instead of considering all of the information available in front of you. I'd say the core issue here is of priorities. Microsoft may be treating aggressive enabled-by-default approach to security as a good thing. A lot of other people don't. If you don't, then the high-level summary of the issue is, essentially, "By making some relatively recent hardware features a requirement for Win11 in the name of sekhurity, while also aggressively pushing users to upgrade and actively preventing them from continuing to use Win10, they're forcing people to destroy perfectly good machines for bullshit reasons". I'm having hard time seeing fault in this view.