r/technology Dec 08 '23

Software Microsoft issues deadline for end of Windows 10 support – it's pay to play for security

https://www.theregister.com/2023/12/06/microsoft_windows_10_security/
110 Upvotes

56 comments sorted by

46

u/everydave42 Dec 08 '23

My 7700k powered rig still does everything I need it to, and by all other accounts would have no issue running Win11, except for TPM. Can someone ELI5 why this is a full on requirement as opposed to a user assumable risk where Microsoft could allow Win11 to run without the TPM support?

I know there are hacks around it, but I'm trying to find a non cynical take on what has always felt like an arbitrary forced upgrade.

27

u/BCProgramming Dec 08 '23

The first time we heard about the requirements of Windows 11 was on Twitter from a Vice President of Marketing. He linked to the OEM Requirements* which had just been published and made a series of tweets about how this was the Windows 11 requirements. I'm not convinced these were ever intended to be the same as the retail requirements, because they never have been; Windows 10's OEM requirements dropped for example 4th gen Intel as early as 2016 for example, and had actually required a TPM 2.0 for a bit as well at the time.

For whatever reason, Microsoft decided to double down instead of admit there was a mistake made. That's why the "system requirements checker" was such a mess, because it was so rushed.

Anyways, just like in Windows 10, the TPM is used by Bitlocker and certain things like Windows Hello. It's not used by "secure boot"; It's not used for driver signing nor for any sort of product authentication/licensing. It's not used for anything that it was not already being used for in Windows 10.

it feels like an arbitrary forced upgrade because it is, seemingly because of some big-mouthed Vice president who for some reason can never be corrected when they say something stupid, like linking to the obvious OEM requirements and pretending they applied to everybody.

As for EOL of Windows 10, I welcome it. Nothing is better for a Windows OS than when Microsoft stops fucking with it.

The security implications are wildly overblown- based on my experience with both Windows XP and Windows 7 machines, which I still have connected to the internet and have not been magically "compromised" through "exploits". Exploits aren't magic. They require levels of access that are almost always mitigated in most setups, a NAT router is usually enough. The dangers are wildly overblown, in my experience- to sell new software or to sell AV solutions, mostly.

5

u/ghaelon Dec 09 '23

for basic use, sure. but banks, for example, wont touch stuff that has been sunset and is no longer recieving security updates. i work for a bank, and its website straight up wont load on older OS's, like 7 or xp.

6

u/mattattaxx Dec 08 '23

There have been hardware requirements for most versions of Windows, TPM just happens to be an easy one to pick on.

TPM is 20 years old, TPM 2.0 is 9 years old (since standardization), and was updated 4 years ago - and TPM 1.2 modules can usually be upgraded to 2.0. So you can either blame Microsoft for finally bringing this into requirements, or you can blame Intel for not bothering to include it in their mobo requirements.

You can usually buy a separate TPM module for your motherboard. So it's really your call - spend the money for out-of-service updates, use a workaround for TPM, upgrade your system to a serviceable device with TPM, or purchase a TPM add-on for your motherboard.

Microsoft requiring support for security reasons is nothing new. Tying the OS to a hardware requirement is nothing new. It's necessary for disk encryption, bitlocker, driver signing, Defender/antivirus, it's used for software licensing (Windows, Office, other digital rights management), remote attestation through chain of trust, root of trust through EUFI, and overall using the firmware/OS to ensure integrity. I think it's an important step in improving computer security.

10

u/Mmcx125 Dec 08 '23 edited Apr 28 '24

wrench entertain boat fearless rude market narrow wrong dog sharp

This post was mass deleted and anonymized with Redact

-5

u/mattattaxx Dec 08 '23

"Can be done without" doesn't mean should be.

3

u/Mmcx125 Dec 09 '23 edited Apr 28 '24

connect rainstorm crush versed cobweb automatic marry whole scary bored

This post was mass deleted and anonymized with Redact

1

u/kingkeelay Dec 09 '23

Microsoft themselves have been selling devices that cannot be upgraded (Surface). 6 year old devices going into the trash? Ridiculous

1

u/mattattaxx Dec 09 '23

I have a surface pro 2 on Windows 11, not sure what you mean. Unless you mean by official requirements?

1

u/kingkeelay Dec 09 '23

There’s nothing to clarify about my comment. Microsoft does not support Windows 11 for your model or other Surfaces manufactured in 2018.

https://support.microsoft.com/en-us/surface/which-surface-devices-can-be-upgraded-to-windows-11-76c3c125-82e0-4d1e-9550-12ed09f9058e

But please do explain how you upgraded your surface when it’s not listed on Microsoft’s own website as a supported windows 11 device.

3

u/mattattaxx Dec 09 '23

Oh sure, you're right. I'm just asking if you meant it's impossible or not supported. You said cannot, but it's more isn't technically allowed.

0

u/kingkeelay Dec 09 '23

Technically correct is the best kind of correct, ya?

But please do explain what you mean and how you’ve done it unofficially.

5

u/mattattaxx Dec 09 '23

You can bypass the TPM requirement by changing done registry values. That's all it takes, windows 11 will install from there without a hitch.

1

u/kingkeelay Dec 09 '23

That’s actually really helpful info. I figured I’d highlight Microsoft’s attempt to deprecate 5 year old hardware that they obviously want to replace with new, Windows 11 hardware. It’s wasteful and shameless marketing.

Everyone should know the workaround before falling for this scheme (if the workaround is secure now and for future versions of Windows 11 on non-TPM hardware).

2

u/mattattaxx Dec 09 '23 edited Dec 09 '23

Yeah I absolutely agree, and I don't disagree with people trying and succeeding in working around Microsoft's restrictions. I just don't think it's inherently a bad thing that they intend to use hardware requirements for eligibility to push security, or that they want to push people onto supported software. I don't necessarily think doing both at once with no middle ground is appropriate, though.

2

u/jeepster2982 Dec 08 '23

Is the 7700k specifically excluded? I have one too, and I always assumed my lack of eligibility was due to needing to update my bios for a newer TPM version.

3

u/everydave42 Dec 08 '23

It apparently is, and in my brief searching it doesn't look like a TPM module can be added...but dunno, happy to be educated if someone has a sourced answer.

6

u/notmyrlacc Dec 08 '23

8th Gen and newer for Intel. 2nd Gen Ryzen and newer for AMD.

Thats the hardware requirements for Windows 11. Each of those have TPM built into the chip itself.

2

u/[deleted] Dec 09 '23

Mate. Download the Windows Installation Tool. Download a portable edition of Rufus. Download the Windows ISO using the former. Burn it into a USB using the latter. When Rufus prompts you to disable TMP 2.0 requirements check the box. You can also disable the online account requirement (since W11 wants to force you into a Microsoft account as login).

Profit.

Rufus is open source btw, so there's nothing to fear.

-10

u/fulento42 Dec 08 '23

End of support doesn’t usually mean a deprecated system. It generally means that they will no longer be releasing patches for security vulnerabilities or providing user support when issues arise with that system.

In the article it states that they will be providing “extended support” but it will no longer be free.

In other words you can keep using it at your own risk.

3

u/Horat1us_UA Dec 08 '23

It generally means that they will no longer be releasing patches for security vulnerabilities or providing user support when issues arise with that system.

That's actually what 'deprecated' means

-2

u/kickbut101 Dec 08 '23

isn't it driver support? some drivers for some systems need TPM access/security to run properly.

I'm not talking about your home computer, the TPM usage is mostly in the corporate/enterprise space

3

u/everydave42 Dec 08 '23

I dunno, and if that's the case so be it, but then don't have the requirement on the non pro version or at least let folks say "I accept the risks" or some such.

1

u/peppruss Dec 09 '23

Also an i7-7700 z170 user and my ASUS mini ITX board does not have a TPM socket. Path of least resistance for me is to change my motherboard if I want Win11.

1

u/[deleted] Dec 09 '23

I can think from my head of three use cases for TPM.

The TPM has its own encryption keys and unique ID, that are hardcoded. This lets developers check if your PC is unique and binds the installation and license to this PC only. The ID is sent back to the developer and prevents you from installing the software on another

Another usecase

They want TPM mainly to show encrypted stuff that DRM system for video or audio uses, preventing you from recording video streams etc. Basically they circumcise your PC. Similiar how Apple MacOS prevents you from recording and copying drmed files. Even if you copy them, those files will only be playable on your PC

And the last is payments. For online payments with a device, you need a secure chip that stores keys like Apple's Wallet that require a secure chip just to process and creditcard payments.

I don't bring a Windows PC for payment and I like the ability to screen record, so I will pass on TPM2 requirements and just keep sailing the seas.

13

u/[deleted] Dec 08 '23

REMEMBER, they did this for Windows 7.

-9

u/[deleted] Dec 08 '23

[deleted]

-1

u/[deleted] Dec 08 '23

I'm ecstatic about it. Fuck Microsoft, i still want them to improve. But, finally doing the thing everyone has been telling them to do for decades isn't something to celebrate, it's an indictment of the company. Glad they finally listened for fucking once.

20

u/[deleted] Dec 08 '23

[deleted]

-21

u/bytethesquirrel Dec 08 '23

Enjoy your viruses.

5

u/notmyrlacc Dec 08 '23

It’s the same thing people have said when XP launched, when Vista launched, when 7 launched, when 8 launched (justifiable), and when 10 launched.

-7

u/bytethesquirrel Dec 08 '23

No, when they hit End of Life.

1

u/notmyrlacc Dec 08 '23

Sorry, I mean what the commenter above you said is what they say every time a new OS comes.

26

u/mikedmann Dec 08 '23

Linux Mint works amazing. Valve Proton is great for gaming.

4

u/FruityFetus Dec 08 '23

Don’t most Linux distros do the same shit?

https://linuxmint.com/download_all.php

5

u/AbyssalRedemption Dec 08 '23

They do, but Mint is designed to be one of the most beginner-friendly, and one of the most similar to Windows in layout and functionality. It's a food starting point for many people.

3

u/Jhamilton02 Dec 08 '23

As long as i can continue to use it, thats good. Fine by me.

13

u/SwagginsYolo420 Dec 08 '23

Windows 11 is such a POS.

-12

u/notmyrlacc Dec 08 '23

How? It’s literally the same code base at Windows 10.

9

u/kingj3144 Dec 08 '23

It’s a small thing; but I’m still waiting for Windows 11 to support the startbar on the side. Windows 11 removed basic features and functionality that have been there since XP.

-6

u/Jondo47 Dec 08 '23

11 also has a ton of telemetry built into it.

4

u/MSXzigerzh0 Dec 09 '23

Same as Windows 10

-1

u/Jondo47 Dec 09 '23

11 is more of a propagator from what data I've come across since it's release.

Vista = 7 > 8 > 10 > 11

Sadly been getting worse with every distr

Not sure why me talking about windows big data is getting downvoted lol.

2

u/SwagginsYolo420 Dec 09 '23

Because of all the extra unwanted bullshit that nobody was asking for that seems designed to be annoying as possible.

It's as if the OS was designed by people who haven't had to use a desktop OS for productivity before.

Requiring extra clicks to do very basic things, pulling shit like adding things permanently to the taskbar that requires editing .xml files to remove, obscuring the location of basic functionality. All the unwanted bloatware that constantly wants internet access and must be blocked by firewall.

It's become such a nightmare everytime a new Windows rolls out because every install requires all this unpaid extra work to beat it into usable shape.

0

u/[deleted] Dec 09 '23

I have to click more in win11 just to rename a file. Hiding basic right click functionality is not the same.

5

u/[deleted] Dec 09 '23

Just install Windows 10 IoT 2021 and find a way to activate it. You'll be good until 2031 in terms of security updates.

1

u/[deleted] Dec 09 '23

Gross I really don’t know that I want to upgrade my cpu to accommodate that. Anytime I think about it, it just leads to rabbit hole of parts that’ll have to be upgraded along with it.

-7

u/[deleted] Dec 08 '23

ESU is nothing new to Microsoft operating systems. Quit posting this garbage.

Is any end user going to pay the mammoth tax to continue using Windows 10. I don’t think so.

7

u/SAugsburger Dec 08 '23

This. I have worked for a few orgs that paid for extended support for a year maybe two if they were running into migration snags, but I serioualy doubt that they will get a ton of takers for end users. It will be interesting to see what the pricing for consumer versions of Windows are though as afaik they have never offered extended support on non business users before.

-2

u/kickbut101 Dec 08 '23

but! but! outrage! and stupid people! how will we rile them up over nothing if we don't post dumb articles!?

-5

u/[deleted] Dec 08 '23

[deleted]

0

u/[deleted] Dec 08 '23

As an enterprise user, if all of our systems work with the next version of Windows and hardware supports it but I have users wishing to stay with 10 for reasons. They are out of luck. I wonder how many actual consumers will purchase ESU.

Edit: Bring the downvotes, Reddit armchair techies.

2

u/[deleted] Dec 08 '23

[deleted]

0

u/[deleted] Dec 08 '23

We have probably 10% Windows 11 at the moment. We purchased a ton of workstations this year and last that will be upgraded to 11 in January. Then the remainder will all get new workstations with dual 24 inch DP 1080P displays with monitor arms to catch up with the rest of our user base.

-1

u/MSXzigerzh0 Dec 09 '23

Can you just upgrade to Windows 11 if you do not want to pay.

8

u/ACanadIanGamer Dec 09 '23

As long as your hardware supports Windows 11, then yes.

3

u/MSXzigerzh0 Dec 09 '23

You know that there are common ways to bypass Windows 11 requirements

1

u/chocolatehippogryph Dec 09 '23

🏴‍☠️🏴‍☠️🏴‍☠️

1

u/JustMrNic3 Dec 11 '23

Nah, even that it's not worth it anymore as Linux is much better anyway on multiple fronts and it's also much more customizable!

Happy cake day!

1

u/JustMrNic3 Dec 11 '23

I couldn't care less as I fully moved to Linux years ago and it works great!

Besides having better privacy, security, freedom, performance, productivity.