One can wish. The more likely end game seems to be one where no one actually bothers using a real Linux installation, as you can do everything you'd need Linux for on your Windows machine. But your Windows machine has become a 'trusted computing' device that only boots and runs most software if it 'hasn't been tampered with'. Say, by actually installing Linux on it.
> The more likely end game seems to be one where no one actually bothers using a real Linux installation, as you can
do everything you'd need Linux for on your Windows machine.
I'm 100% convinced this is Microsoft's actual goal, and it's going to succeed very quickly at least on the desktop.
Then one day, when a good number of apps will conveniently require WSL to run properly, or to run at all, MS could build their own Linux distribution containing licensed parts of Windows (drivers for closed hardware, graphics libraries, etc.) de facto displacing the original Linux from every other field of application including embedded, automotive, industrial, etc.
Right, they've ceded the server space to Linux but want to cement Windows' position on desktops in a Linux-server world (maybe regaining some ground from Macs in the process, since this is one of the reasons they're so popular with devs)
Because those devs have proven they only care about POSIX, if it Linux or something else they don't care at all, otherwise they would be giving money to Linux OEMS.
> Did we mention that a TPM isn’t going to protect you from UEFI malware that was planted on the device by a rogue agent at manufacture time?
I find this to be a pretty weak strawman, and one that not many people would consider to be part of their threat model (and if they are, they'd just purchase the part from a brick-and-mortar store so that, if there is malware, it's non-targeted).
Microsoft is mostly doing this for their endpoint security enterprise customers. The objectives aren't exactly hidden, either:
- Don't want anyone to be able to get data off of a bitlocker-encrypted drive[0]
- Don't allow things like O365 login credentials (including temporary auth tokens) to be pulled off a drive[1]
- Prevent thunderbolt 3 DMA (eg. from a rogue usb on the back of the computer)[2]
And yes, they probably also don't want people to keep hacking online video games, which is why Riot uses TPM attestation as an additional security measure to preventing people banned for hacking from evading bans in Valorant[3].
> And yes, they probably also don't want people to keep hacking online video games, which is why Riot uses TPM attestation as an additional security measure to preventing people banned for hacking from evading bans in Valorant[3].
on most of my gaming boards you buy the TPM and plug it into the board like you would a USB connector
total cost: ~$15 (ignoring currently craziness)
if I'm a wallhacker/aimbotter how would this stop me?
Usually they ban every part they can get a SN/unique ID for, TPM being just another signal. Modular TPMs are being phased out anyhow, with new AMD and Intel chips having it built in.
As I said, it doesn't actually do much for anti-cheat besides act as a hardware ID for bans. You can still run cheats and hack your own system with the TPM fully in-tact, it's just another method to increase the cost required to get back in after being banned - now you have to have an entirely new CPU every time, at least once they fully drop Windows 10 support in \d{2} years.
There's quite literally only one potential exploit that would work for the purposes of ban-evasion: extracting the private key. Since every CPU is signed by Intel/AMD's CA, the Riot servers require your CPU attest by signing a secret message, so you'd need a surefire way to extract the private key from other machines to then spoof TPM responses using your existing hardware - that, or you have an active worker agent on other PCs proxying the attestation process.
And, if you were actually able to find a way to extract the private key on TSMC's newest process nodes, there are much more profitable ways to use that knowledge.. ie. selling it to zerodium or nation state actors that are eager to decrypt iPhones.
Reliable chain of trust combined with hardware bans is a pretty high entry barrier, though. You need to change most of your PC hardware to not be banned again, and HWID spoofers are also cheats that have to squeeze through the same filter.
So no, it's not a completely invalid idea. At some iteration, it will make the anticheats even better, and they already work pretty well (regardless of players' oversized perception of cheaters running unpunished). A proper chain of trust + hardware signing of mouse input + kernel hardening + hardware fingerprinting will make most cheats irrelevant (including the ML-based ones). You'd have to mod your hardware to be even able to run cheats; which is also preventable, just ask console manufacturers.
The only downside is, this would turn your computing device into an appliance remotely controlled by several companies. And the gamers will be perfectly happy to have it at that, because everybody hates cheaters, and even talking about that is stigmatized.
How many cheats have you seen on consoles? I guess none. Besides maybe an occasional lagswitch, or a packet manipulation/sniffing thing, but that's due to developers' lack of expertise, because all of that is avoidable. That's because consoles are locked down completely. So yes, it is useful if implemented properly, and if your PC is totally locked down. It would be silly to deny that.
(and BTW my bank already does that, requiring non-rooted stock firmware for its app on mobile. With Samsung for example, rooting amounts to warranty loss; maybe in EU it's different, but I'm not in EU)
Whether you or me say yes or no to TPM is not hugely important. Most people are absolutely happy to trade freedom for convenience, and it aligns with Microsoft's incentive to lock everyone into using their products. This isn't new at all, I've seen loss of PC modularity and openness discussed since late 90s.
However, there are several counterbalances for that incentive.
1. Platform fragmentation, the major one. This alone can delay the inevitable for any amount of time.
2. Backwards compatibility.
3. PCs being used for many purposes, not just as an appliance. This is a minor but noticeable one.
4. Some groups advocating for the platform openness. This one is of little relevance in practice.
Expecting the x86/MS platform to stay open forever is not realistic, because the incentives are biased towards locking down. How much time it'll take to get to that state is a different question, though. It haven't happened yet is all that can be said.
Stop playing devil's advocate. It's worse than useless because it takes away the best part of computing: our freedom to own, operate and modify.
> Expecting the x86/MS platform to stay open forever is not realistic, because the incentives are biased towards locking down.
It's only unrealistic when these fatalist certainties are pushed as inevitable. Free, live free is more than the name of a novella, it's an act to be performed, to fight for.
So yes, say no to the TPM and other such measures such as SafetyNet, which are worse than useless to the most important endgame, to live free.
The purpose of my computer is not to protect anyone else's business model.
If there is no way to deal with cheating at games other than relinquishing ownership, disposition, and functionality of my own hardware, that is not my problem, and, it's not true anyway.
> The purpose of my computer is not to protect anyone else's business model.
It is if you want to use someone else’s software that requires it; you can’t have something on your terms just because the cost of using it is paid in something other than fiat currency.
Neither would I, personally. But Linux is hard to manage for corporations especially when people use different distros.
These things may be required by the security department. So WSL is a nice carrot there for them. Management through Windows and Linux on top of it. I worked in endpoint management so I can see the appeal.
However personally I really like the way Linux is free of corporate influence. In fact I switched to FreeBSD for that reason as I feel that big IT is getting too involved with Linux.
But that's a startup, I was speaking more of enterprise (in which I work). We have much more rigid security rules, and we're also a much bigger target for bad actors.
I am pretty sure that WSL was implemented to avoid the gradual loss of users, most of them being developers, to Linux. There is very little reason for existing Linux users to adopt Windows due to WSL.
Been seeing a lot more developers jumping from mac to Linux and even windows lately. If something more competitive to M1 comes from amd and Intel we should expect the trend to continue. I think the tide is moving the opposite direction now than 10 years ago.
It's not going to happen. The Windows NT kernel is one of Microsoft's greatest assets; in fact it's better designed than Linux on many axes. Until recently it had better support for async I/O (and the developer experience of io_uring may still not measure up to IOCP under Windows), it was designed for multithreading, and it has a more advanced security model. It also has a more advanced driver model, which is to say it has a driver model at all. The fact that there's a standard ABI for drivers means hardware Just Works under Windows and is still incredibly fiddly under Linux. Microsoft essentially has stewardship over the entire PC platform because they play very nicely with OEMs and make hardware easy for Windows to support.
They are not going to give that up. It'd be the OS-kernel equivalent of giving up Alpha for Itanium.
If anything, the future of Linux is to be a guest under Windows NT. How many Hackernews have I heard repeat the mantra that the best Linux desktop environment is WSL?
Microsoft defines the hardware specification for Windows compatible x86 and all the OEMs that manufacture x86 servers (even ones most likely destined to never run anything other than Linux), desktops, and laptops certify against it.
There are no other standards for what a PC is. All of the open OSes, including Linux, just piggyback on Microsoft's standard. (And if anyone believes that the various giants building custom ARM processors aren't hoping that they can get dominance based on their own spec so that they can displace Microsoft and wield the same power, think again.)
> And if anyone believes that the various giants building custom ARM processors aren't hoping that they can get dominance based on their own spec so that they can displace Microsoft and wield the same power, think again.
ARM already has their own spec for that, the SBSA. So the one wielding power will most probably be ARM itself, not one of the "various giants building custom ARM processors".
I looked around briefly but I mostly see articles saying "SBSA is eventually a goal" for various products. Is the ARM ecosystem coalescing around SBSA?
I think Intel designs specifications for x86 platform, not MS. And someone should do it after IBM quit doing it.
Otherwise we would have the same level of fragmentation in x86 hardware space that we have in Linux software or that we see in ARM space. Much less compatibility.
Don't forget, before the last step, they'll first subsidise universities and schools to explicitly train their students to have a dependence on WSL, so that they can maximally exploit their users when they introduce a fee.
Except Microsoft doesn't offer WSL-based hosting, and they currently don't offer their own Linux distro. This is a complement to their Azure business, basically.
That would only happen if sometime between 2027 and 2030 they buy out both Linus and the Linux Foundation, re-write all GPL code not owned by the Foundation, and re license Linux to some other license other than GPL.
I think it would be much easier to just design another POSIX compatible OS and give users some incentive over Linux: stable ABI, stable API, software and hardware that just works out of the box and don't need configuration and maintenance.
- 2024: dual support for native Linux & Windows 13 apps
- 2027: Linux & Windows 15 interop support
- 2030: run legacy Windows apps on Windows L (Linux)