[HN Gopher] Windows 11 is no longer compatible with Oracle Virtu...
       ___________________________________________________________________
        
       Windows 11 is no longer compatible with Oracle VirtualBox VMs
        
       Author : jnieminen
       Score  : 21 points
       Date   : 2021-09-18 20:47 UTC (2 hours ago)
        
 (HTM) web link (www.bleepingcomputer.com)
 (TXT) w3m dump (www.bleepingcomputer.com)
        
       | PragmaticPulp wrote:
       | Until VirtualBox implements TPM 2.0 pass through, which they've
       | already started working on:
       | https://www.virtualbox.org/changeset/90946/vbox
       | 
       | Qemu already supports TPM pass through and secure boot.
        
         | mrlonglong wrote:
         | I fear that might not be a good thing. Wouldn't it be better
         | and safer to just emulate TPM in the VM?
        
           | gtvwill wrote:
           | Errr they want real TPM functionality. Emulation kinda nerfs
           | the whole point of it. It's a hardware key. If you could just
           | emulate it what would stop you spoofing it?
           | 
           | Edit: autocorrect TPM
        
             | tinus_hn wrote:
             | How would they detect the difference?
        
             | murgindrag wrote:
             | Well, modules can be designed to protect my security, or to
             | harm my security (e.g. to enforce DRM). I'm unclear on how
             | "real TPM" functionality helps me. If it helps secure
             | Microsoft, and hurts my security, that's a good reason to
             | not use Windows.
             | 
             | I have not found good docs on what TPM exactly does in
             | Windows 11, but people I trust tell me to distrust it, so I
             | do.
        
           | freemint wrote:
           | Because that would break TPM or mean adding another chain of
           | trust to the OS verifying TPM which also has problems.
        
         | mindslight wrote:
         | As a QEMU user, why would I ever allow a Windows VM to talk to
         | a real TPM? The entire point of a VM is to isolate Windows in a
         | predictable and secure manner. Giving it access to some secret
         | state, especially as a hostile coprocessor that has been
         | designed to work against my own interests, completely
         | undermines this goal. Hopefully this restriction will simply be
         | cracked in the popular Windows torrents (or better yet, TPM
         | keys leaked). But more likely by the time any application
         | specifically requires Windows 11 to run, Windows will have
         | faded even further into irrelevance.
        
       | mrlonglong wrote:
       | How come I currently have an instance of Windows 11 working just
       | fine under VirtualBox?
        
         | mycall wrote:
         | Because it is not RTM. More restrictions on the way.
        
           | mrlonglong wrote:
           | Why they they so hot on needing the TPM?
        
       | rejectfinite wrote:
       | I always preferred VMWare workstation anyway. The downside is its
       | harder to install a small easy VM on work PCs.
        
         | marcodiego wrote:
         | Virtualbox license is better.
        
       | teruakohatu wrote:
       | Does TPM pass though mean that the virtualized OS knows the
       | identity of the host hardware?
        
         | azalemeth wrote:
         | Yes, and I can't help but think this will be used for more
         | draconian DRM. I'm equally sure that soon people will have
         | emulated TPMs that will act as a plug-in too.
        
       | yummypaint wrote:
       | What does this do for the end user?
        
       | captainmuon wrote:
       | Is there a way around this restriction? Does the registry hack
       | that floated around when the first beta came out still work?
        
       | rubyist5eva wrote:
       | My life is no longer compatible with Windows.
        
       ___________________________________________________________________
       (page generated 2021-09-18 23:02 UTC)