[video] Telemetry and TPM comparitively and Win11
- KVRian
- 1314 posts since 7 Apr, 2019 from Canada
The real question is whether we need to fear those who in the future will be using quantum computing. Sure, a tpm will provide some defense, but tbh it's effect is negligible. The only one good defense is a hardware firewall. It'd be nice if they had seperate mobos that could do just that to be put inside of a tower. But they don't.
Another chip on new mobos however to handle just telemetry, that'd be genius for sure. But apparently there's other ways to avoid needing to use a tpm with windows 11. So really, why bother using one. There's combinations of using poweriso to remake the cd file into an iso for instance and there's workarounds that do not seem like they would require a computer genius.
With My older/newer Asus Gaming Pro Aura 970 I can use a tpm 2.0-m and that's cool. I guess I may prepare for that, but ultimately I will likely avoid the scenario. Like in the case of windows 10 also, there is the realization that there will be many bugs in the initial release. I remember losing a new pc I bought to a buggy windows 10 in its infancy.
There had been a problem installing a backup with Acronis, the fix utility did not work and it died. I don't think I'd try windows 11 for a few years at least with that in mind, but at least this video helps you to understand the pressures already exerted on your system and exactly what the result of paranoia has on your system and workflow.
Though a simplistic explanation, there's really no other way to explain it, to tackle the entire issue would be a 24 hour seminar.
Maybe older is better, especially like in the resulting impact of hd content causing problems for gpu's; there's so much bad coding out there, and it stands to reason that even nvidia or amd / intel can screw up in their hardware or drivers.
I'll often be vexed when I find the perfect driver for My gpu, but it doesn't work well with nvenc and obs, because I know better than to try the other versions, causing problems in both games and system stability overall.
Last edited by kingozrecords on Thu Sep 02, 2021 4:57 pm, edited 2 times in total.
I don't make audio products anymore. I sell furniture & smart products.
- KVRAF
- 16890 posts since 8 Mar, 2005 from Utrecht, Holland
TPM means Trusted Platform Module: https://en.wikipedia.org/wiki/Trusted_Platform_Module
Nothing to do with telemetry afaik
Nothing to do with telemetry afaik
We are the KVR collective. Resistance is futile. You will be assimilated. 
My MusicCalc is served over https!!
My MusicCalc is served over https!!
- KVRian
- Topic Starter
- 1314 posts since 7 Apr, 2019 from Canada
What happens is as the processor processes each new bit of data, before that processor is allowed to, the certificate must first be checked by windows 11 and the tpm to ensure that everything is as it should be. One could argue that the size of a hashed certificate id, or file id is minute and only in bytes; but with a limitation of only 1gb in ram so to hold such data, the question arises how fast is the chip and the circuitry.BertKoor wrote: Wed Sep 01, 2021 6:54 am TPM means Trusted Platform Module: https://en.wikipedia.org/wiki/Trusted_Platform_Module
Nothing to do with telemetry afaik![]()
What I'm saying is that the effect of telemetry is going to be amplified. Imagine, leaving telemetry on and having it need to be checked and re-checked by the tpm so as to ensure that every background service collecting and co-allating data is in fact the real deal.
It's a bottleneck that's worse than anything we've seen before. Though it has existed in windows 8 and a bit earlier; it's never been enforced and it has been an option. However, the more bloated an os becomes, and the faster a processor does I cannot help but to realize that there will be a problem with the speed of data being congruous. There's no avoiding that fact.
One might argue that a TPM given the fact that it is not multi-core, removes the multi core and thread ability from a processor, limiting it and defining its instrumentation via a serial device that has a linear nature, and a so-called unavoidable nature at that.kingozrecords wrote:What's really dissapointing is that shows like linus tech tips will routinely employ their own measures to remove windows bloat so as to run in their minds a fair test of peak system efficiency. And yet, the average user even Myself would probably not be as good at getting rid of such bloat so we could never hope to attain the same levels as they have.
It makes their results and tests inaccurate and miseading. If they and others were instead to use vanilla computers it would become very clear to the public that there is a clear and present problem.
how then, are multi cores supposed to run something in parallel when instead each function processed needs to be checked one after the other before such load can occur. Like in the case when 3-4 or 5 jobs are being done at the same time? And what about multi-threaded downloading, the list goes on.
It's a logical nightmare.
BTW: re-uploaded video and used some different methods with video that cause less antialiasing. I'd like to upgrade to an AMD 5500, 5700 or so in time because its interlace is better; even with My usb2 1080 webcam the difference would be night and day. For the sake of affordability I purchased the GTX 970 at the time however. I use the 456.71 driver which is really well made; having no problems and yet the video quality is terrible. It takes a lot of post processing to get rid of interlacing and shimmering / rainbows.
What I did however was employ qtgmc using hybrid which is the best I've tried until now, it does most of the denoising and operates quickly I have not found any other deinterlace method to date of any effect, I ommited the audio as I'd employed nch switch to save the audio as a 256 aac at vcbr.
Next in video enhancer 2 I used a CMYK fiter, I brought the Y slightly up and brought the Y offset down. Next I raised the blue and reduced the red (natural daylight).
I proceeded next to apply mmx denoising using only a setting of 4 and then applied Donald Graft's Msharpen at minimal settings, I may have used it to too great a degree. Next I used videopad in lossless mode added the intro and de-interlaced video with the aac audio added.
Interestingly the audio or video did not need to be retimed. Instead all that was required was to match the end of the audio with the end of the video and then the initial av offset was perfect.
I don't make audio products anymore. I sell furniture & smart products.
-
- KVRist
- 109 posts since 24 Apr, 2021
That's not what TPM is for - it's used for a handful of functions, not checking every bit of code.
- KVRian
- Topic Starter
- 1314 posts since 7 Apr, 2019 from Canada
That would be nice if you were right; but unfortunately it is. It checks and allows each registered function that requires the internet. It's the gate before the data is sent on to the processor. Since services are also employing the internet like telemetry, they will be equally affected ausing a stuttering. With so many audio services being cloud based, it's an eye opener.kperry wrote: Fri Sep 03, 2021 10:01 am That's not what TPM is for - it's used for a handful of functions, not checking every bit of code.
Software starting up, looking for updates and so on.
TPM 1.2 overview
Full article: https://www.cryptomathic.com/news-event ... -explainedhttps://www.cryptomathic.com/ wrote:The current generation of TPMs (version 1.2) are stand-alone chips which are usually surface mounted onto the motherboard of a PC, or integrated into a custom PCB for an embedded device. The TPM can monitor and access the main bus of the computer, which allows it to keep track of and report on the configuration state of the entire computer, from the moment of power-on right through - potentially - to the execution of applications on a modern graphical operating system. Monitoring in itself has limited uses, but combined with access control for secrets based on the monitoring of state, all sorts of interesting applications become possible. For example if a PC is booted into a certain trustworthy state where only a fixed set of applications are installed, the monitoring TPM could then grant access to data storage and encryption keys for high security email. Additionally, the TPM can attest to the configuration of the computer to external third parties, be it the owner of a device wishing to remotely manage it, or a device manufacturer leaving a device in the hands of an untrusted third party. Finally, in order to support requirements for availability, and to guard against equipment failure, the TPM includes command infrastructure and protocols for migration of data between trusted devices, and for use of third parties as privacy or migration brokers. At time of creation, data can be designated as either migrateable or non-migrateable, depending upon the protection model required.
TPM 2.0 overview
Full article: https://www.laptopmag.com/articles/tpm-chip-faqhttps://www.laptopmag.com/articles/tpm-chip-faq wrote:What does a TPM do?
Some, but not all, of the data we transmit throughout the day is sent unencrypted, as plain text. TPM chips use a mix of software and hardware to protect any important passwords or encryption keys when they are sent in this unencrypted form.
If a TPM chip senses that a system's integrity has been compromised by a virus or malware, it can start up in a quarantine mode to help fix the problem. Some Google Chromebooks include TPMs, and during startup, the chip scans the BIOS (a motherboard firmware that initiates the startup process) for unauthorized changes.
TPM chips also provide safe storage of encryption keys, certificates and passwords used for logging in to online services, which is a more secure method than storing them inside software on the hard drive.
TPM chips in network-connected set-top boxes enable digital rights management, so media companies can distribute content without worrying about theft.
The effect on the internet
A tpm adds extra functions to encryption.
Like in the case of IDM for instance, downloading with a multi-threaded processor; the connection may be rocky and files may go corrupt more often, only because of the nature of a serial device. With many cloud audio programs that will be annoying.
Theories about a new age of less piracy
Some companies like Atari, earlier in the TPM's existence thought that the TPM could reduce piracy, but seasoned programmers of the day said that was unlikely and also said what it could really do is hand over more control to the software creator of a system, so My theory of viruses designed to use it apparently is not far off.
Full Article: https://www.schneier.com/blog/archives/ ... _pira.htmlAtari founder Nolan Bushnell wrote:“There is a stealth encryption chip called a TPM that is going on the motherboards of most of the computers that are coming out now,” he pointed out
“What that says is that in the games business we will be able to encrypt with an absolutely verifiable private key in the encryption world — which is uncrackable by people on the internet and by giving away passwords — which will allow for a huge market to develop in some of the areas where piracy has been a real problem.”
The author and commentors go on to say that there have been some interesting tpm hacks designed by open source developer for kicks that can do a lot of things, which is interesting because their conclusions and methods are something like dos software.
The thing that's clear is that the line between hardware (as is popularly coined the use for TPM) and software is blurred, if there's a lot of ways to hack it; I guess that's something that eventually will be affected by both software developers and developers as a whole.https://www.schneier.com/ wrote: “TPM” stands for “Trusted Platform Module.” It’s a chip that is probably already in your computer and may someday be used to enforce security: both your security, and the security of software and media companies against you. The system is complicated, and while it will prevent some attacks, there are lots of ways to hack it. (I’ve written about TPM here, and here when Microsoft called it Palladium. Ross Anderson has some good stuff here.)
Common TPM problems in regards to installation
For instance, in the way of encryption and installing your cloned os to a new drive there are certain issues which arise. Here's one on Tom's hardware forum that is not necessarily indicative of something solely being due to a tpm but it is the responses of professionals which is a learning experience:
Forum Post https://forums.tomshardware.com/threads ... d.3458873/SerialSniper14 wrote:I don't have BitLocker it seems. I looked through Control Panel and didn't see anything. I did have TrueCrypt but when I opened it nothing was actually encrypted and I don't recall encrypting any drive so I just uninstalled it.jojesa wrote: You need to disable Bitlocker encryption before cloning the drive.
If you have an active TPM chip and Bitlocker is enable you won't be able to access the new cloned drive.
There was a program in control panel called Infineon Security Platform but I've never used it and I received an error messge when I try to open it.
Though to Me that's nothing new; it's important for those who are unaware to consider this.
One such solution is here:
https://social.technet.microsoft.com/Fo ... W8ITProWTG
Here's an individual explaining that it was impossible to diagnose what the problem was with tpm and bitlocker; forced ultimately to reinstall windows twice. Likely however, this user did not have the same knowledge level (follow the link above to see that fix):
https://social.technet.microsoft.com/Fo ... rosecurity
The concrete
Beyond this information I wanted something concrete and meaningful; and I heard a lot of theory. There was a pretty good video by a computer refurb / shop owner who was explaining that like in the case of m.2 not allowing linux; this will be standard with bitlockered drives employing a tpm with windows 11.
At first, I found his video a mere rant though I watched it all. But besides, he may be explicitly right because pcworld has this to say:
Full Article: https://www.pcworld.com/article/3623827 ... thing.htmlPCWorld wrote: BitLocker will be enabled by default on all Windows 11 PCs. Once the drive is encrypted with BitLocker, Windows asks where you’d like to back up the encryption key. The key reduces the odds of the data being tampered with, should your laptop get stolen or lost. It’s stored inside of the firmware TPM in the CPU, or in a discrete TPM 2.0 module, where it will be called upon to unseal the drive during the login process.
The emotion warnings and rants
And finally I'll provide the emo rant from youtube. I don't like his style during this video; but he makes several good points. Like in the case of windows s mode, windows has been playing with the idea of controlling and seizing control of systems worldwide, by preventing what you install and how and where.
While I found that paranoid I conceded that fact as he went over that chromebooks, amazon devices and Iphones have doing the same thing for a long time. He went over how android for instance is trying to prevent sideloading (uncertified app download and install) which is a popular thing.
So, yes; if PCworld is correct; this will have the largest and most significant impact on those who wish to update and transfer their system. From what I've read this process will be a bit more complicated but less restricted for the windows 11 pro version, being that a person can write down their key and merely type it in before the reinstall / cloning or upgrade and that's re-assuring.
But it is an extra step; and I hadn't wanted to do that. And it is only in this context that a TPM is given control over functions in general. Obviously; without encryption one could suggest that there would be no impact but with complicit encryption being a standard it's a defacto seemingly/impossible hard to avoid. But will the hacked windows 11 versions made to work without a TPM that's the question. There's something to the idea of this being the introduction of a mandatory S mode perhaps.
God bless your emo, lol.
Last edited by kingozrecords on Sat Sep 04, 2021 5:27 pm, edited 1 time in total.
I don't make audio products anymore. I sell furniture & smart products.
- KVRAF
- 16890 posts since 8 Mar, 2005 from Utrecht, Holland
Still it is not telemetry, and it works not as you described.
We are the KVR collective. Resistance is futile. You will be assimilated. 
My MusicCalc is served over https!!
My MusicCalc is served over https!!
- KVRian
- Topic Starter
- 1314 posts since 7 Apr, 2019 from Canada
With windows 11, we're forced to use bitlocker and telemetry that connects to the internet has to go through the tpm. So does every cloud device; and so does the hash have to be a cyclic dependency. You're right, if we were to assume that windows 11 did not force encryption; but it does.BertKoor wrote: Sat Sep 04, 2021 5:26 pm Still it is not telemetry, and it works not as you described.
Though, perhaps less a tpm maybe it'd be better; and maybe even still bitlocker could also be turned off; which would be ideal. I hope that to be the case.
I don't make audio products anymore. I sell furniture & smart products.
- KVRian
- 1266 posts since 6 Jun, 2016
Right. It's the TPM which establishes the trust. i.e. a cryptographic UID which works as the machine's identity--your identity, ultimately. Then it's the OS and or other software which establishes the trusted telemetry, trusted DRM or whatever else, via an Endorsement Key (RSA keypair) within the TPM.
I was introduced to TPM back in 2007, as a sysadmin. The promise then was a better way to administer security for machines. In particular, laptops which could be altered/hacked in the field, and might then enter your network as an attack vector.
I was introduced to TPM back in 2007, as a sysadmin. The promise then was a better way to administer security for machines. In particular, laptops which could be altered/hacked in the field, and might then enter your network as an attack vector.
Last edited by lunardigs on Sun Sep 05, 2021 3:27 am, edited 10 times in total.
-
- KVRAF
- 6323 posts since 30 Dec, 2004 from London uk
You do know that Mac has had TPM for many years? You should be more worried about Apples decision to scan devices for child porn, which is a huge invasion of privacy. Id stay off the drugs if I were you. You post reams of misleading junk that no one reads.
https://www.bloomberg.com/news/articles ... porn-issue
OSX also has other telemetry problems :
https://mspoweruser.com/macos-big-sur-h ... nightmare/
https://www.bloomberg.com/news/articles ... porn-issue
OSX also has other telemetry problems :
https://mspoweruser.com/macos-big-sur-h ... nightmare/
