• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Certain "Special Purpose Systems" Variants of Windows 11 Ship Without the TPM 2.0 Requirement

btarunr

Editor & Senior Moderator
Staff member
Joined
Oct 9, 2007
Messages
46,283 (7.69/day)
Location
Hyderabad, India
System Name RBMK-1000
Processor AMD Ryzen 7 5700G
Motherboard ASUS ROG Strix B450-E Gaming
Cooling DeepCool Gammax L240 V2
Memory 2x 8GB G.Skill Sniper X
Video Card(s) Palit GeForce RTX 2080 SUPER GameRock
Storage Western Digital Black NVMe 512GB
Display(s) BenQ 1440p 60 Hz 27-inch
Case Corsair Carbide 100R
Audio Device(s) ASUS SupremeFX S1220A
Power Supply Cooler Master MWE Gold 650W
Mouse ASUS ROG Strix Impact
Keyboard Gamdias Hermes E2
Software Windows 11 Pro
Perhaps the most controversial system requirement of the upcoming Windows 11 operating system is the need for a hardware trusted platform module that meets TPM 2.0 specs. Most modern computers fulfill this requirement using fTPM (firmware TPM) solutions built into their processors; and those that don't, have TPM headers for add-on TPMs, which scalpers have their eye on. It turns out, that Microsoft is designing special variants of Windows 11 for special contracts Microsoft will execute.

Computers sold under the scheme will be marked "special purpose systems," and the Windows 11 version running them will do away with the TPM 2.0 requirement. These systems are very likely to be Government or Military; or perhaps even variants Microsoft exports to countries like China and Russia, which have their own specialized cybersecurity policies and dictate software to be written a certain way to be sold in the country.



View at TechPowerUp Main Site
 
Joined
Oct 1, 2006
Messages
4,884 (0.76/day)
Location
Hong Kong
Processor Core i7-12700k
Motherboard Z690 Aero G D4
Cooling Custom loop water, 3x 420 Rad
Video Card(s) RX 7900 XTX Phantom Gaming
Storage Plextor M10P 2TB
Display(s) InnoCN 27M2V
Case Thermaltake Level 20 XT
Audio Device(s) Soundblaster AE-5 Plus
Power Supply FSP Aurum PT 1200W
Software Windows 11 Pro 64-bit
If only they would allow 7th gen Intel CPU's... sigh. M$ is so smart... like when they fail security in-house... lol

Fun fact, many of the 8th gen U-series cpus are supported and those are Kaby Lake R.
Meanwhile the 7900X from Q2 2017 is not supported while Xeon 8180 from Q3 is. Both of these being Skylake.
Microsoft literally drew a line in the sand at around mid 2017.
 

TheLostSwede

News Editor
Joined
Nov 11, 2004
Messages
16,001 (2.26/day)
Location
Sweden
System Name Overlord Mk MLI
Processor AMD Ryzen 7 7800X3D
Motherboard Gigabyte X670E Aorus Master
Cooling Noctua NH-D15 SE with offsets
Memory 32GB Team T-Create Expert DDR5 6000 MHz @ CL30-34-34-68
Video Card(s) Gainward GeForce RTX 4080 Phantom GS
Storage 1TB Solidigm P44 Pro, 2 TB Corsair MP600 Pro, 2TB Kingston KC3000
Display(s) Acer XV272K LVbmiipruzx 4K@160Hz
Case Fractal Design Torrent Compact
Audio Device(s) Corsair Virtuoso SE
Power Supply be quiet! Pure Power 12 M 850 W
Mouse Logitech G502 Lightspeed
Keyboard Corsair K70 Max
Software Windows 10 Pro
Benchmark Scores https://valid.x86.fr/5za05v
This is related to countries that don't allow certain "foreign" crypto technology or that are on lists that ban export of such technology to said countries.
 
Joined
Aug 23, 2013
Messages
453 (0.12/day)
Fun fact, many of the 8th gen U-series cpus are supported and those are Kaby Lake R.
Meanwhile the 7900X from Q2 2017 is not supported while Xeon 8180 from 3 is. Microsoft literally drew a line in the sand at around mid 2017.
Same as Ryzen 1000 not been support while 2000 series is, and it's the same cpus
 
Joined
Oct 22, 2014
Messages
13,210 (3.83/day)
Location
Sunshine Coast
System Name Black Box
Processor Intel Xeon E3-1260L v5
Motherboard MSI E3 KRAIT Gaming v5
Cooling Tt tower + 120mm Tt fan
Memory G.Skill 16GB 3600 C18
Video Card(s) Asus GTX 970 Mini
Storage Kingston A2000 512Gb NVME
Display(s) AOC 24" Freesync 1m.s. 75Hz
Case Corsair 450D High Air Flow.
Audio Device(s) No need.
Power Supply FSP Aurum 650W
Mouse Yes
Keyboard Of course
Software W10 Pro 64 bit
Joined
Feb 11, 2009
Messages
5,389 (0.98/day)
System Name Cyberline
Processor Intel Core i7 2600k -> 12600k
Motherboard Asus P8P67 LE Rev 3.0 -> Gigabyte Z690 Auros Elite DDR4
Cooling Tuniq Tower 120 -> Custom Watercoolingloop
Memory Corsair (4x2) 8gb 1600mhz -> Crucial (8x2) 16gb 3600mhz
Video Card(s) AMD RX480 -> ... nope still the same :'(
Storage Samsung 750 Evo 250gb SSD + WD 1tb x 2 + WD 2tb -> 2tb MVMe SSD
Display(s) Philips 32inch LPF5605H (television) -> Dell S3220DGF
Case antec 600 -> Thermaltake Tenor HTCP case
Audio Device(s) Focusrite 2i4 (USB)
Power Supply Seasonic 620watt 80+ Platinum
Mouse Elecom EX-G
Keyboard Rapoo V700
Software Windows 10 Pro 64bit
Fun fact, many of the 8th gen U-series cpus are supported and those are Kaby Lake R.
Meanwhile the 7900X from Q2 2017 is not supported while Xeon 8180 from Q3 is. Both of these being Skylake.
Microsoft literally drew a line in the sand at around mid 2017.

well...not literally, but we get your point
 
Joined
Jul 16, 2014
Messages
8,115 (2.29/day)
Location
SE Michigan
System Name Dumbass
Processor AMD Ryzen 7800X3D
Motherboard ASUS TUF gaming B650
Cooling Artic Liquid Freezer 2 - 420mm
Memory G.Skill Sniper 32gb DDR5 6000
Video Card(s) GreenTeam 4070 ti super 16gb
Storage Samsung EVO 500gb & 1Tb, 2tb HDD, 500gb WD Black
Display(s) 1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
Case Phanteks Enthoo Primo w/8 140mm SP Fans
Audio Device(s) onboard (realtek?) - SPKRS:Logitech Z623 200w 2.1
Power Supply Corsair HX1000i
Mouse Steeseries Esports Wireless
Keyboard Corsair K100
Software windows 10 H
Benchmark Scores https://i.imgur.com/aoz3vWY.jpg?2
m$ does it again, think they know whats best for everyone and forces you to buy into it.
 
Joined
Aug 20, 2007
Messages
20,714 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches
Software Windows 11 Enterprise (legit), Gentoo Linux x64
Some consumer motherboards have an option to disable the M.E.
I know mine does and it is disabled.

Reminds me of how Intel CPU's include that secretive ME (Remote Management Engine) embedded 2nd micro-processor, whilst PC's designed for High Assurance Platform (government purposes) get the ability to turn the "security feature" off for... security reasons... ;)
HAP bit is literally present on every ME ever made. There just isn't neccesarily a bios menu option for it, but it can still be toggled.

It's also not a "second processor." It's your same processor, running code with above admin level priviledges.
 
Joined
Feb 20, 2019
Messages
7,194 (3.86/day)
System Name Bragging Rights
Processor Atom Z3735F 1.33GHz
Motherboard It has no markings but it's green
Cooling No, it's a 2.2W processor
Memory 2GB DDR3L-1333
Video Card(s) Gen7 Intel HD (4EU @ 311MHz)
Storage 32GB eMMC and 128GB Sandisk Extreme U3
Display(s) 10" IPS 1280x800 60Hz
Case Veddha T2
Audio Device(s) Apparently, yes
Power Supply Samsung 18W 5V fast-charger
Mouse MX Anywhere 2
Keyboard Logitech MX Keys (not Cherry MX at all)
VR HMD Samsung Oddyssey, not that I'd plug it into this though....
Software W10 21H1, barely
Benchmark Scores I once clocked a Celeron-300A to 564MHz on an Abit BE6 and it scored over 9000.
....and there we go, this was inevitable. Of course the first official offering from Microsoft to the public will be full of false caveats and requirements to entice trick users into using a Microsoft account and giving Microsoft even more hardware authority over a system than they already have. The TPM 'requirement' is just stronger identification and control of your OS license and despite TPM having beneficial security uses for a user, its only real high-profile press coverage so far been (ab)use by OEMs taking advantage of the "trust" in TPM to push their own software/firmware without requiring user consent.

So many people are still using older systems that don't have TPM built in and Microsoft doesn't want to lose those users so W11 variants without the draconian requirements weren't just expected, they are practically guaranteed.

You may have to jump through some hoops to legally obtain these versions, just like you had to for the old LTSB licenses. However, the ole' Mary Celeste will still no doubt be a backup for people with ethics as shady as Microsoft's.
 

freeagent

Moderator
Staff member
Joined
Sep 16, 2018
Messages
7,421 (3.67/day)
Location
Winnipeg, Canada
System Name Altered Beast
Processor AMD R9 5900X/5800X3D
Motherboard Asus Crosshair VIII Dark Hero
Cooling Thermalright Phantom Spirit 120 EVO, 1x T30
Memory 2x8 G.Skill Trident Z Royal 3200C14, 2x8GB G.Skill Trident Z Black and White 3200 C14
Video Card(s) Zotac 4070 Ti Trinity OC
Storage WD SN850X 2TB, SN850 1TB, SN770 1TB - Asus Hyper M.2, 2x SN770 1TB
Display(s) LG 50UP7100
Case Fractal Torrent Compact RGB
Audio Device(s) JBL 2.1 Deep Bass
Power Supply EVGA SuperNova 750w G+, Monster HDP1800
Mouse Logitech G502 Hero
Keyboard Logitech G213
VR HMD Oculus 3
Software Yes
Benchmark Scores Yes
I can see this turning into a real shit show pretty quick..
 
Joined
Aug 12, 2017
Messages
21 (0.01/day)
I'm loving windows 11 !! On dev mode. Took less than 5 minutes today. So far ,so good.
Seamless upgrade from existing W/10 install . Way to go MS.
 
Joined
Feb 20, 2019
Messages
7,194 (3.86/day)
System Name Bragging Rights
Processor Atom Z3735F 1.33GHz
Motherboard It has no markings but it's green
Cooling No, it's a 2.2W processor
Memory 2GB DDR3L-1333
Video Card(s) Gen7 Intel HD (4EU @ 311MHz)
Storage 32GB eMMC and 128GB Sandisk Extreme U3
Display(s) 10" IPS 1280x800 60Hz
Case Veddha T2
Audio Device(s) Apparently, yes
Power Supply Samsung 18W 5V fast-charger
Mouse MX Anywhere 2
Keyboard Logitech MX Keys (not Cherry MX at all)
VR HMD Samsung Oddyssey, not that I'd plug it into this though....
Software W10 21H1, barely
Benchmark Scores I once clocked a Celeron-300A to 564MHz on an Abit BE6 and it scored over 9000.
Joined
Jun 29, 2018
Messages
444 (0.21/day)
It's also not a "second processor." It's your same processor, running code with above admin level priviledges.
It is a second processor. It always has been. It lives in the chipset and since Skylake is also a x86.
From Wikipedia:
The Intel Management Engine (ME), also known as the Intel Manageability Engine,[1][2] is an autonomous subsystem that has been incorporated in virtually all of Intel's processor chipsets since 2008.[1][3][4] It is located in the Platform Controller Hub of modern Intel motherboards.
 
Joined
Aug 20, 2007
Messages
20,714 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches
Software Windows 11 Enterprise (legit), Gentoo Linux x64
It is a second processor. It always has been. It lives in the chipset and since Skylake is also a x86.
From Wikipedia:
It used to be a seperate arc core on the chipset but it hasn't been since X58, when it both became x86, minix based, and on your general cpu. Keep in mind, I'm one of the chief researchers in the effort to disable the Intel ME in firmware, so I know a lot more than wikipedia.
 
Joined
Jun 29, 2018
Messages
444 (0.21/day)
It used to be a seperate arc core on the chipset but it hasn't been since X58, when it both became x86, minix based, and on your general cpu. Keep in mind, I'm one of the chief researchers in the effort to disable the Intel ME in firmware, so I know a lot more than wikipedia.
And yet what you wrote is wrong, because ME was never located on the CPU itself. Obviously Intel themselves are wrong about where they put it:


Also how come AMT is functional with the CPU not in the socket? :)
 
Joined
Aug 20, 2007
Messages
20,714 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches
Software Windows 11 Enterprise (legit), Gentoo Linux x64
Also how come AMT is functional with the CPU not in the socket?
AMT is a vPro technology which does feature a chipset coprocessor. It is somewhat seperate from the core Intel ME suite but interacts with it fully. And interestingly, all modern chipsets do have this coprocessor, but it is off by default in consumer SKUs. You can toggle it on with some hackery to the image but I don't really desire out of band management.

I know what Intel says but I've been through the minix binaries and it's quite clear where the core ME binaries (as well as the watchdog) run.

Intel also claimed for years the HAP bit was non-existant. They aren't beyond telling what is in generous terms, a simplified version of the truth.

Fun fact while we are at it: their RAID solution is run on your primary cpu, too.
 
Last edited:
Joined
Jun 29, 2018
Messages
444 (0.21/day)
AMT is a vPro technology which does feature a chipset coprocessor. It is somewhat seperate from the core Intel ME suite but interacts with it fully. And interestingly, all modern chipsets do have this coprocessor, but it is off by default in consumer SKUs. You can toggle it on with some hackery to the image but I don't really desire out of band management.

I know what Intel says but I've been through the minix binaries and it's quite clear where the core ME binaries (as well as the watchdog) run.

Intel also claimed for years the HAP bit was non-existant. They aren't beyond telling what is in generous terms, a simplified version of the truth.

Fun fact while we are at it: their RAID solution is run on your primary cpu, too.
You are aware that what you wrote has no sources other than: trust me bro.
You claim to be a researcher, why haven't you edited the wikipedia article citing your published papers yet? What you wrote directly contradicts it, and Intel's documentation. This is a genuine question, not mockery.
 
Joined
Aug 20, 2007
Messages
20,714 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches
Software Windows 11 Enterprise (legit), Gentoo Linux x64
You are aware that what you wrote has no sources other than: trust me bro.
Yes. I no longer work on this (am employed elsewhere now) but people on this forum remember my work and successes. The threads are still here too, most recently ASrock boards pretty sure.

Feel free to look up my modified images. And if you still don't buy it, tough but not much I can do. I was a researcher who made images, not papers, so nothing to find. But my username is known amognst just about every ME researcher out there, FWIW.

As for why I haven't corrected wikipedia, probably because they'd have to start paying me. I'm a very busy man now.

I don't mean this rude. You are correct to be skeptical. I am just unsure what more I can provide, sorry. Good on you not taking things at face value though. I mean that honestly.
 
Last edited:
Joined
Jun 29, 2018
Messages
444 (0.21/day)
Yes. I no longer work on this (am employed elsewhere now) but people on this forum remember my work and successes. The threads are still here too, most recently ASrock boards pretty sure.

Feel free to look up my modified images. And if you still don't buy it, tough but not much I can do. I was a researcher who made images, not papers, so nothing to find. But my username is known amognst just about every ME researcher out there, FWIW.

As for why I haven't corrected wikipedia, probably because they'd have to start paying me. I'm a very busy man now.

I don't mean this rude. You are correct to be skeptical. I am just unsure what more I can provide, sorry. Good on you not taking things at face value though. I mean that honestly.
Alright, I understand. I'm just surprised that nobody from the ME research community wanted to fix the publicly available misinformation on the wikipedia page. Like... literally nobody? There must be tons of PhD students interested in this, willing to score easy points and having the civic duty to fix this.

(But you're not too busy to reply to my posts on this forum tho ;) )
 
Joined
Aug 20, 2007
Messages
20,714 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches
Software Windows 11 Enterprise (legit), Gentoo Linux x64
But you're not too busy to reply to my posts on this forum tho
Never. TPU is half the reason I have my current job. Besides, it's far too hot to work today:


Wikipedia isn't honestly a haven for firmware researchers. You may try win-raid.com forums. I think plutomaniac could help you. You could also look into if the author of me_cleaner is still about, he may remember my work. May not, too. Hard to say we didn't talk much (probably why his user handle is escaping now)

There must be tons of PhD
Nope. I think only one of us finished college. Firmware stuff is reverse engineering galore and colleges don't like to touch it. Too many grey areas.

EDIT: It appears I forgot about this hackaday article on my work on the Taichi boards... something maybe?

 
Last edited:
Joined
Jun 29, 2018
Messages
444 (0.21/day)
Never. TPU is half the reason I have my current job. Besides, it's far too hot to work today:


Wikipedia isn't honestly a haven for firmware researchers. You may try win-raid.com forums. I think plutomaniac could help you. You could also look into if the author of me_cleaner is still about, he may remember my work. May not, too. Hard to say we didn't talk much (probably why his user handle is escaping now)


Nope. I think only one of us finished college. Firmware stuff is reverse engineering galore and colleges don't like to touch it. Too many grey areas.
All the materials I can find for Blackhat, USENIX point to ME being in the chipset. Even Intel presented that on Blackhat 2019. Maybe the reason you thought Minix runs on the CPU is the fact that it actually runs on a modified i486 embedded into the chipset since Skylake?
Why would Intel lie about this on the biggest security-focused conference?
 
Joined
Aug 20, 2007
Messages
20,714 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches
Software Windows 11 Enterprise (legit), Gentoo Linux x64
Maybe the reason you thought Minix runs on the CPU is the fact that it actually runs on a modified i486 embedded into the chipset since Skylake?
Actually, that is possible admitedly because the Minux binaries are single threaded. But they also are x64, and I guess the core contention I have is that I find it unlikely they could stuff that in the chipset without a thermal envelope that is unacceptably large. Maybe atom is way better than the old day, I am not really as up to date on architectures as I once was.

Also, spectre style exploits work on protected enclaves, suggesting what is running them indeed is an out of order cpu, at least. Are atoms out of order? I thought they weren't.

I guess I'll back off a little and admit this: anything is possible but I don't find it likely.

Why would Intel lie about this on the biggest security-focused conference?
My only guess is if they are lying, they don't see it as lying. The firmware itself lives in the bios chip which connects directly to the PCH. Maybe they consider that when they say the ME "lives" there. But it's just speculation.
 
Last edited:
Top