Windows

microsoft-finally-releases-generic-install-isos-for-the-arm-version-of-windows

Microsoft finally releases generic install ISOs for the Arm version of Windows

For some PC buyers, doing a clean install of Windows right out of the box is part of the setup ritual. But for Arm-based PCs, including the Copilot+ PCs with Snapdragon X Plus and Elite chips in them, it hasn’t been possible in the same way. Microsoft (mostly) hasn’t offered generic install media that can be used to reinstall Windows on an Arm PC from scratch.

Microsoft is fixing that today—the company finally has a download page for the official Arm release of Windows 11, linked to but separate from the ISOs for the x86 versions of Windows. These are useful not just for because-I-feel-like-it clean installs, but for reinstalling Windows after you’ve upgraded your SSD and setting up Windows virtual machines on Arm-based PCs and Macs.

Previously, Microsoft did offer install media for some Windows Insider Preview Arm builds, though these are for beta versions of Windows that may or may not be feature-complete or stable. Various apps, scripts, and websites also exist to grab files from Microsoft’s servers and build “unofficial” ISOs for the Arm version of Windows, though obviously this is more complicated than just downloading a single file directly.

Microsoft finally releases generic install ISOs for the Arm version of Windows Read More »

not-just-chatgpt-anymore:-perplexity-and-anthropic’s-claude-get-desktop-apps

Not just ChatGPT anymore: Perplexity and Anthropic’s Claude get desktop apps

There’s a lot going on in the world of Mac apps for popular AI services. In the past week, Anthropic has released a desktop app for its popular Claude chatbot, and Perplexity launched a native app for its AI-driven search service.

On top of that, OpenAI updated its ChatGPT Mac app with support for its flashy advanced voice feature.

Like the ChatGPT app that debuted several weeks ago, the Perplexity app adds a keyboard shortcut that allows you to enter a query from anywhere on your desktop. You can use the app to ask follow-up questions and carry on a conversation about what it finds.

It’s free to download and use, but Perplexity offers subscriptions for major users.

Perplexity’s search emphasis meant it wasn’t previously a direct competitor to OpenAI’s ChatGPT, but OpenAI recently launched SearchGPT, a search-focused variant of its popular product. SearchGPT is not yet supported in the desktop app, though.

Anthropic’s Claude, on the other hand, is a more direct competitor to ChatGPT. It works similarly to ChatGPT but has different strengths, particularly in software development. The Claude app is free to download, but it’s in beta, and like Perplexity and OpenAI, Anthropic charges for more advanced users.

When ChatGPT launched its Mac app, it didn’t release a Windows app right away, saying that it was focused on where its users were at the time. A Windows app recently arrived, and Anthropic took a different approach, simultaneously introducing Windows and Mac apps.

Previously, all these tools offered mobile apps and web apps, but not necessarily native desktop apps.

Not just ChatGPT anymore: Perplexity and Anthropic’s Claude get desktop apps Read More »

what-i-learned-from-3-years-of-running-windows-11-on-“unsupported”-pcs

What I learned from 3 years of running Windows 11 on “unsupported” PCs


where we’re going, we don’t need support

When your old PC goes over the Windows 10 update cliff, can Windows 11 save it?

Credit: Andrew Cunningham

Credit: Andrew Cunningham

The Windows 10 update cliff is coming in October 2025. We’ve explained why that’s a big deal, and we have a comprehensive guide to updating to Windows 11 (recently updated to account for changes in Windows 11 24H2) so you can keep getting security updates, whether you’re on an officially supported PC or not.

But this is more than just a theoretical exercise; I’ve been using Windows 11 on some kind of “unsupported” system practically since it launched to stay abreast of what the experience is actually like and to keep tabs on whether Microsoft would make good on its threats to pull support from these systems at any time.

Now that we’re three years in, and since I’ve been using Windows 11 24H2 on a 2012-era desktop and laptop as my primary work machines on and off for a few months now, I can paint a pretty complete picture of what Windows 11 is like on these PCs. As the Windows 10 update cliff approaches, it’s worth asking: Is running “unsupported” Windows 11 a good way to keep an older but still functional machine running, especially for non-technical users?

My hardware

I’ve run Windows 11 on a fair amount of old hardware, including PCs as old as a late XP-era Core 2 Duo Dell Inspiron desktop. For the first couple of years, I ran it most commonly on an old Dell XPS 13 9333 with a Core i5-4250U and 8GB of RAM and a Dell Latitude 3379 2-in-1 that just barely falls short of the official requirements (both systems are also pressed into service for ChromeOS Flex testing periodically).

But I’ve been running the 24H2 update as my main work OS on two machines. The first is a Dell Optiplex 3010 desktop with a 3rd-generation Core i5-3xxx CPU, which had been my mother’s main desktop until I upgraded it a year or so ago. The second is a Lenovo ThinkPad X230 with a i5-3320M inside, a little brick of a machine that I picked up for next to nothing on Goodwill’s online auction site.

Credit: Andrew Cunningham

Both systems, and the desktop in particular, have been upgraded quite a bit; the laptop has 8GB of RAM while the desktop has 16GB, both are running SATA SSDs, and the desktop has a low-profile AMD Radeon Pro WX2100 in it, a cheap way to get support for running multiple 4K monitors. The desktop also has USB Wi-Fi and Bluetooth dongles and an internal expansion card that provides a pair of USB 3.0 Type-A ports and a single USB-C port. Systems of this vintage are pretty easy to refurbish since components are old enough that they’ve gone way down in price but not so old that they’ve become rare collectors’ items. It’s another way to get a usable computer for $100—or for free if you know where to look.

And these systems were meant to be maintained and upgraded. It’s one of the beautiful things about a standardized PC platform, though these days we’ve given a lot of that flexibility up in favor of smaller, thinner devices and larger batteries. It is possible to upgrade and refurbish these 12-year-old computers to the point that they run modern operating systems well because they were designed to leave room for that possibility.

But no matter how much you upgrade any of these PCs or how well you maintain them, they will never meet Windows 11’s official requirements. That’s the problem.

Using it feels pretty normal

Once it’s installed, Windows 11 is mostly Windows 11, whether your PC is officially supported or not. Credit: Andrew Cunningham

Depending on how you do it, it can be a minor pain to get Windows 11 up and running on a computer that doesn’t natively support it. But once the OS is installed, Microsoft’s early warnings about instability and the possible ending of updates have proven to be mostly unfounded.

A Windows 11 PC will still grab all of the same drivers from Windows Update as a Windows 10 PC would, and any post-Vista drivers have at least a chance of working in Windows 11 as long as they’re 64-bit. But Windows 10 was widely supported on hardware going back to the turn of the 2010s. If it shipped with Windows 8 or even Windows 7, your hardware should mostly work, give or take the occasional edge case. I’ve yet to have a catastrophic crash or software failure on any of the systems I’m using, and they’re all from the 2012–2016 era.

Once Windows 11 is installed, routine software updates and app updates from the Microsoft Store are downloaded and installed on my “unsupported” systems the same way they are on my “supported” ones. You don’t have to think about how you’re running an unsupported operating system; Windows remains Windows. That’s the big takeaway here—if you’re happy with the performance of your unsupported PC under Windows 10, nothing about the way Windows 11 runs will give you problems.

…Until you want to install a big update

There’s one exception for the PCs I’ve had running unsupported Windows 11 installs in the long term: They don’t want to automatically download and install the yearly feature updates for Windows. So a 22H2 install will keep downloading and installing updates for as long as they’re offered, but it won’t offer to update itself to versions 23H2 or 24H2.

This behavior may be targeted specifically at unsupported PCs, or it may just be a byproduct of how Microsoft rolls out these yearly updates (if you have a supported system with a known hardware or driver issue, for example, Microsoft will withhold these updates until the issues are resolved). Either way, it’s an irritating thing to have to deal with every year or every other year—Microsoft supports most of its annual updates for two years after they’re released to the public. So 23H2 and 24H2 are currently supported, while 22H2 and 21H2 (the first release of Windows 11) are at the end of the line.

This essentially means you’ll need to repeat the steps for doing a new unsupported Windows 11 install every time you want to upgrade. As we detail in our guide, that’s relatively simple if your PC has Secure Boot and a TPM but doesn’t have a supported processor. Make a simple registry tweak, download the Installation Assistant or an ISO file to run Setup from, and the Windows 11 installer will let you off with a warning and then proceed normally, leaving your files and apps in place.

Without Secure Boot or a TPM, though, installing these upgrades in place is more difficult. Trying to run an upgrade install from within Windows just means the system will yell at you about the things your PC is missing. Booting from a USB drive that has been doctored to overlook the requirements will help you do a clean install, but it will delete all your existing files and apps.

If you’re running into this problem and still want to try an upgrade install, there’s one more workaround you can try.

  1. Download an ISO for the version of Windows 11 you want to install, and then either make a USB install drive or simply mount the ISO file in Windows by double-clicking it.
  2. Open a Command Prompt window as Administrator and navigate to whatever drive letter the Windows install media is using. Usually that will be D: or E:, depending on what drives you have installed in your system; type the drive letter and colon into the command prompt window and press Enter.
  3. Type setup.exe /product server

You’ll notice that the subsequent setup screens all say they’re “installing Windows Server” rather than the regular version of Windows, but that’s not actually true—the Windows image that comes with these ISO files is still regular old Windows 11, and that’s what the installer is using to upgrade your system. It’s just running a Windows Server-branded version of the installer that apparently isn’t making the same stringent hardware checks that the normal Windows 11 installer is.

This workaround allowed me to do an in-place upgrade of Windows 11 24H2 onto a Windows 10 22H2 PC with no TPM enabled. It should also work for upgrading an older version of Windows 11 to 24H2.

Older PCs are still very useful!

This 2012-era desktop can be outfitted with 16 GB of memory and a GPU that can drive multiple 4K displays, things that wouldn’t have been common when it was manufactured. But no matter how much you upgrade it, Windows 11 will never officially support it. Credit: Andrew Cunningham

Having to go out of your way to keep Windows 11 up to date on an unsupported PC is a fairly major pain. But unless your hardware is exceptionally wretched (I wouldn’t recommend trying to get by with less than 4GB of RAM at an absolute bare minimum, or with a spinning hard drive, or with an aging low-end N-series Pentium or Celeron chip), you’ll find that decade-old laptops and desktops can still hold up pretty well when you’re sticking to light or medium-sized workloads.

I haven’t found this surprising. Major high-end CPU performance improvements have come in fits and starts over the last decade, and today’s (Windows 11-supported) barebones bargain basement Intel N100 PCs perform a lot like decade-old mainstream quad-core desktop processors.

With its RAM and GPU updates, my Optiplex 3010 and its Core i5 worked pretty well with my normal dual-4K desktop monitor setup (it couldn’t drive my Gigabyte M28U at higher than 60 Hz, but that’s a GPU limitation). Yes, I could feel the difference between an aging Core i5-3475S and the Core i7-12700 in my regular Windows desktop, and it didn’t take much at all for CPU usage to spike to 100 percent and stay there, always a sign that your CPU is holding you back. But once apps were loaded, they felt responsive, and I had absolutely no issues writing, recording and editing audio, and working in Affinity Photo on the odd image or two.

I wouldn’t recommend using this system to play games, nor would I recommend overpaying for a brand-new GPU to pair with an older quad-core CPU like this one (I chose the GPU I did specifically for its display outputs, not its gaming prowess). If you wanted to, you could still probably get respectable midrange gaming performance out of a 4th-, 6th-, or 7th-gen Intel Core i5 or i7 or a first-generation AMD Ryzen CPU paired with a GeForce RTX 4060 or 3060, or a Radeon RX 7600. Resist the urge to overspend, consider used cards as a way to keep costs down, and check your power supply before you install anything—the years-old 300 W power supply in a cheap Dell office desktop will need to be replaced before you can use it with any GPU that has an external power connector.

My experience with the old Goodwill-sourced ThinkPad was also mostly pretty good. It had both Secure Boot and a TPM, making installation and upgrades easier. The old fingerprint sensor (a slow and finicky swipe-to-scan sensor) and its 2013-era driver even support Windows Hello. I certainly minded the cramped, low-resolution screen—display quality and screen-to-bezel ratio being the most noticeable changes between a 12-year-old system and a modern one—but it worked reliably with a new battery in it. It even helped me focus a bit at work; a 1366×768 screen just doesn’t invite heavy multitasking.

But the mid-2010s are a dividing line, and new laptops are better than old laptops

That brings me to my biggest word of warning.

If you want to run Windows 11 on an older desktop, one where the computer is just a box that you plug stuff into, the age of the hardware isn’t all that much of a concern. Upgrading components is easier whether you’re talking about a filthy keyboard, a failing monitor, or a stick of RAM. And you don’t need to be concerned as much with power use or battery life.

But for laptops? Let me tell you, there are things about using a laptop from 2012 that you don’t want to remember.

Three important dividing lines: In 2013, Intel’s 4th-generation Haswell processors gave huge battery life boosts to laptops thanks to lower power use when idle and the ability to switch more quickly between active and idle states. In 2015, Dell introduced the first with a slim-bezeled design (though it would be some years before it would fix the bottom-mounted up-your-nose webcam), which is probably the single most influential laptop design change since the MacBook Air. And around the same time (though it’s hard to pinpoint an exact date), more laptops began adopting Microsoft’s Precision Touchpad specification rather than using finicky, inconsistent third-party drivers, making PC laptop touchpads considerably less annoying than they had been up until that point.

And those aren’t the only niceties that have become standard or near-standard on midrange and high-end laptops these days. We also have high-resolution, high-density displays; the adoption of taller screen aspect ratios like 16: 10 and 3:2, giving us more vertical screen space to use; USB-C charging, replacing the need for proprietary power bricks; and backlit keyboards!

The ThinkPad X230 I bought doesn’t have a backlit keyboard, but it does have a bizarre little booklight next to the webcam that shines down onto the keyboard to illuminate it. This is sort of neat if you’re already the kind of person inclined to describe janky old laptops as “neat,” but it’s not as practical.

Even if you set aside degraded, swollen, or otherwise broken batteries and the extra wear and tear that comes with portability, a laptop from the last three or four years will have a ton of useful upgrades and amenities aside from extra speed. That’s not to say that older laptops can’t be useful because they obviously can be. But it’s also a place where an upgrade can make a bigger difference than just getting you Windows 11 support.

Some security concerns

Some old PCs will never meet Windows 11’s more stringent security requirements, and PC makers often stop updating their systems long before Microsoft drops support. Credit: Andrew Cunningham

Windows 11’s system requirements were controversial in part because they were focused mostly on previously obscure security features like TPM 2.0 modules, hypervisor-protected code integrity (HVCI), and mode-based execution control (MBEC). A TPM module makes it possible to seamlessly encrypt your PC’s local storage, among other things, while HVCI helps to isolate data in memory from the rest of the operating system to make it harder for malicious software to steal things (MBEC is just a CPU technology that speeds up HVCI, which can come with a hefty performance penalty on older systems).

Aside from those specific security features, there are other concerns when using old PCs, some of the same ones we’ve discussed in macOS as Apple has wound down support for Intel Macs. Microsoft’s patches can protect against software security vulnerabilities in Windows, and they can provide some partial mitigations for firmware-based vulnerabilities since even fully patched and fully supported systems won’t always have all the latest BIOS fixes installed.

But software can’t patch everything, and even the best-supported laptops with 5th- or 6th-generation Core CPUs in them will be a year or two past the days when they could expect new BIOS updates or driver fixes.

The PC companies and motherboard makers make some of these determinations; cheap consumer laptops tend to get less firmware and software support regardless of whether Intel or AMD are fixing problems on their ends. But Intel (for example) stops supporting its CPUs altogether after seven or eight years (support ended for 7th-generation CPUs in March). For any vulnerabilities discovered after that, you’re on your own, or you have to trust in software-based mitigations.

I don’t want to overplay the severity or the riskiness of these kinds of security vulnerabilities. Lots of firmware-level security bugs are the kinds of things that are exploited by sophisticated hackers targeting corporate or government systems—not necessarily everyday people who are just using an old laptop to check their email or do their banking. If you’re using good everyday security hygiene otherwise—using strong passwords or passkeys, two-factor authentication, and disk encryption (all things you should already be doing in Windows 10)—an old PC will still be reasonably safe and secure.

A viable, if imperfect, option for keeping an old PC alive

If you have a Windows 10 PC that is still working well or that you can easily upgrade to give it a new lease on life, and you don’t want to pay whatever Microsoft is planning to charge for continued Windows 10 update support, installing Windows 11 may be the path of least resistance for you despite the installation and update hurdles.

Especially for PCs that only miss the Windows 11 support cutoff by a year or two, you’ll get an operating system that still runs reasonably well on your PC, should still support all of your hardware, and will continue to run the software you’re comfortable with. Yes, the installation process for Windows’ annual feature updates is more annoying than it should be. But if you’re just trying to squeeze a handful of years out of an older PC, it might not be an issue you have to deal with very often. And though Windows 11 is different from Windows 10, it doesn’t come with the same learning curve that switching to an alternate operating system like ChromeOS Flex or Linux would.

Eventually, these PCs will age out of circulation, and the point will be moot. But even three years into Windows 11’s life cycle, I can’t help but feel that the system requirements could stand to be relaxed a bit. That ship sailed a long time ago, but given how many PCs are still running Windows 10 less than a year from the end of guaranteed security updates, expanding compatibility is a move Microsoft could consider to close the adoption gap and bring more PCs along.

Even if that doesn’t happen, try running Windows 11 on an older but still functional PC sometime. Once you clean it up a bit to rein in some of modern Microsoft’s worst design impulses, I think you’ll be pleasantly surprised.

Photo of Andrew Cunningham

Andrew is a Senior Technology Reporter at Ars Technica, with a focus on consumer tech including computer hardware and in-depth reviews of operating systems like Windows and macOS. Andrew lives in Philadelphia and co-hosts a weekly book podcast called Overdue.

What I learned from 3 years of running Windows 11 on “unsupported” PCs Read More »

openai-releases-chatgpt-app-for-windows

OpenAI releases ChatGPT app for Windows

On Thursday, OpenAI released an early Windows version of its first ChatGPT app for Windows, following a Mac version that launched in May. Currently, it’s only available to subscribers of Plus, Team, Enterprise, and Edu versions of ChatGPT, and users can download it for free in the Microsoft Store for Windows.

OpenAI is positioning the release as a beta test. “This is an early version, and we plan to bring the full experience to all users later this year,” OpenAI writes on the Microsoft Store entry for the app. (Interestingly, ChatGPT shows up as being rated “T for Teen” by the ESRB in the Windows store, despite not being a video game.)

A screenshot of the new Windows ChatGPT app captured on October 18, 2024.

A screenshot of the new Windows ChatGPT app captured on October 18, 2024.

Credit: Benj Edwards

A screenshot of the new Windows ChatGPT app captured on October 18, 2024. Credit: Benj Edwards

Upon opening the app, OpenAI requires users to log into a paying ChatGPT account, and from there, the app is basically identical to the web browser version of ChatGPT. You can currently use it to access several models: GPT-4o, GPT-4o with Canvas, 01-preview, 01-mini, GPT-4o mini, and GPT-4. Also, it can generate images using DALL-E 3 or analyze uploaded files and images.

If you’re running Windows 11, you can instantly call up a small ChatGPT window when the app is open using an Alt+Space shortcut (it did not work in Windows 10 when we tried). That could be handy for asking ChatGPT a quick question at any time.

A screenshot of the new Windows ChatGPT app listing in the Microsoft Store captured on October 18, 2024.

Credit: Benj Edwards

A screenshot of the new Windows ChatGPT app listing in the Microsoft Store captured on October 18, 2024. Credit: Benj Edwards

And just like the web version, all the AI processing takes place in the cloud on OpenAI’s servers, which means an Internet connection is required.

So as usual, chat like somebody’s watching, and don’t rely on ChatGPT as a factual reference for important decisions—GPT-4o in particular is great at telling you what you want to hear, whether it’s correct or not. As OpenAI says in a small disclaimer at the bottom of the app window: “ChatGPT can make mistakes.”

OpenAI releases ChatGPT app for Windows Read More »

eleven-things-to-know-about-in-the-windows-11-2024-update

Eleven things to know about in the Windows 11 2024 Update


A look at some of the changes and odds and ends in this year’s Windows release.

The Windows 11 2024 Update, also known as Windows 11 24H2, started rolling out last week. Your PC may have even installed it already!

The continuous feature development of Windows 11 (and Microsoft’s phased update rollouts) can make it a bit hard to track exactly what features you can expect to be available on any given Windows PC, even if it seems like it’s fully up to date.

This isn’t a comprehensive record of all the changes in the 2024 Update, and it doesn’t reiterate some basic but important things like Wi-Fi 7 or 80Gbps USB4 support. But we’ve put together a small list of new and interesting changes that you’re guaranteed to see when your version number rolls over from 22H2 or 23H2 to 24H2. And while Microsoft’s announcement post spent most of its time on Copilot and features unique to Copilot+ PCs, here, we’ll only cover things that will be available on any PC you install Windows 11 on (whether it’s officially supported or not).

Quick Settings improvements

The Quick Settings panel sees a few nice quality-of-life improvements. The biggest is a little next/previous page toggle that makes all of the Quick Settings buttons accessible without needing to edit the menu to add them. Instead of clicking a button and entering an edit menu to add and remove items from the menu, you click and drag items between pages. The downside is that you can’t see all of the buttons at once across three rows as you could before, but it’s definitely more handy if there are some items you want to access sometimes but don’t want to see all the time.

A couple of individual Quick Settings items see small improvements: a refresh button in the lower-right corner of the Wi-Fi settings will rescan for new Wi-Fi networks instead of making you exit and reopen the Wi-Fi settings entirely. Padding in the Accessibility menu has also been tweaked so that all items can be clearly seen and toggled without scrolling. If you use one or more VPNs that are managed by Windows’ settings, it will be easier to toggle individual VPN connections on and off, too. And a Live Captions accessibility button to generate automatic captions for audio and video is also present in Quick Settings starting in 24H2.

More Start menu “suggestions” (aka ads)

Amid apps I’ve recently installed and files I’ve recently opened, the “recommended” area of the Start menu will periodically recommend apps to install. These change every time I open the Start menu and don’t seem to have anything to do with my actual PC usage. Credit: Andrew Cunningham

One of the first things a fresh Windows install does when it connects to the Internet is dump a small collection of icons into your Start menu, things grabbed from the Microsoft Store that you didn’t ask for and may not want. The exact apps change from time to time, but these auto-installs have been happening since the Windows 10 days.

The 24H2 update makes this problem subtly worse by adding more “recommendations” to the lower part of the Start menu below your pinned apps. This lower part of the Start menu is usually used for recent files or newly (intentionally) installed apps, but with recommendations enabled, it can also pull recommended apps from the Microsoft Store, giving Microsoft’s app store yet another place to push apps on you.

These recommendations change every time you open the Start menu—sometimes you’ll see no recommended apps at all, and sometimes you’ll see one of a few different app recommendations. The only thing that distinguishes these items from the apps and files you have actually interacted with is that there’s no timestamp or “recently added” tag attached to the recommendations; otherwise, you’d think you had downloaded and installed them already.

These recommendations can be turned off in the Start menu section of the Personalization tab in Settings.

Context menu labels

Text labels added to the main actions in the right-click/context menu. Credit: Andrew Cunningham

When Windows 11 redesigned the right-click/context menu to help clean up years of clutter, it changed basic commands like copy and paste from text labels to small text-free glyphs. The 2024 Update doesn’t walk this back, but it does add text labels back to the glyphs, just in case the icons by themselves didn’t accurately communicate what each button was used for.

Windows 11’s user interface is full of little things like this—stuff that was changed from Windows 10, only to be changed back in subsequent updates, either because people complained or because the old way was actually better (few text-free glyphs are truly as unambiguously, universally understood as a text label can be, even for basic commands like cut, copy, and paste).

Smaller, faster updates

The 24H2 update introduces something that Microsoft calls “checkpoint cumulative updates.”

To recap, each annual Windows update also has a new major build number; for 24H2, that build number is 26100. In 22H2 and 23H2, it was 22621 and 22631. There’s also a minor build number, which is how you track which of Windows’ various monthly feature and security updates you’ve installed. This number starts at zero for each new annual update and slowly increases over time. The PC I’m typing this on is running Windows 11 build 26100.1882; the first version released to the Release Preview Windows Insider channel in June was 26100.712.

In previous versions of Windows, any monthly cumulative update that your PC downloads and installs can update any build of Windows 11 22H2/23H2 to the newest build. That’s true whether you’re updating a fresh install that’s missing months’ worth of updates or an actively used PC that’s only a month or two out of date. As more and more updates are released, these cumulative updates get larger and take longer to install.

Starting in Windows 11 24H2, Microsoft will be able to designate specific monthly updates as “checkpoint” updates, which then become a new update baseline. The next few months’ worth of updates you download to that PC will contain only the files that have been changed since the last checkpoint release instead of every single file that has been changed since the original release of 24H2.

If you’re already letting Windows do its update thing automatically in the background, you probably won’t notice a huge difference. But Microsoft says these checkpoint cumulative updates will “save time, bandwidth, and hard drive space” compared to the current way of doing things, something that may be more noticeable for IT admins with dozens or hundreds of systems to keep updated.

Sudo for Windows

A Windows version of the venerable Linux sudo command—short for “superuser do” or “substitute user do” and generally used to grant administrator-level access to whatever command you’re trying to run—first showed up in experimental Windows builds early this year. The feature has formally been added in the 24H2 update, though it’s off by default, and you’ll need to head to the System settings and then the “For developers” section to turn it on.

When enabled, Sudo for Windows (as Microsoft formally calls it) allows users to run software as administrator without doing the dance of launching a separate console window as an administrator.

By default, using Sudo for Windows will still open a separate console window with administrator privileges, similar to the existing runas command. But it can also be configured to run inline, similar to how it works from a Linux or macOS Terminal window, so you could run a mix of elevated and unelevated software from within the same window. A third option, “with input disabled,” will run your software with administrator privileges but won’t allow additional input, which Microsoft says reduces the risk of malicious software gaining administrator privileges via the sudo command.

One thing the runas command supports that Sudo for Windows doesn’t is the ability to run software as any local user—you can run software as the currently-logged-in user or as administrator, but not as another user on the machine, or using an account you’ve set up to run some specific service. Microsoft says that “this functionality is on the roadmap for the sudo command but does not yet exist.”

Protected print mode

Enabling the (currently optional) protected print mode in Windows 11 24H2. Credit: Andrew Cunningham

Microsoft is gradually phasing out third-party print drivers in Windows in favor of more widely compatible universal drivers. Printer manufacturers will still be able to add things on top of those drivers with their own apps, but the drivers themselves will rely on standards like the Internet Printing Protocol (IPP), defined by the Mopria Alliance.

Windows 11 24H2 doesn’t end support for third-party print drivers yet; Microsoft’s plan for switching over will take years. But 24H2 does give users and IT administrators the ability to flip the switch early. In the Settings app, navigate to “Bluetooth & devices” and then to “Printers & scanners” and enable Windows protected print mode to default to the universal drivers and disable compatibility. You may need to reconnect to any printer you had previously set up on your system—at least, that was how it worked with a network-connected Brother HL-L2340D I use.

This isn’t a one-way street, at least not yet. If you discover your printer won’t work in protected print mode, you can switch the setting off as easily as you turned it on.

New setup interface for clean installs

When you create a bootable USB drive to install a fresh copy of Windows—because you’ve built a new PC, installed a new disk in an existing PC, or just want to blow away all the existing partitions on a disk when you do your new install—the interface has stayed essentially the same since Windows Vista launched back in 2006. Color schemes and some specific dialog options have been tweaked, but the interface itself has not.

For the 2024 Update, Microsoft has spruced up the installer you see when booting from an external device. It accomplishes the same basic tasks as before, giving you a user interface for entering your product key/Windows edition and partitioning disks. The disk-partitioning interface has gotten the biggest facelift, though one of the changes is potentially a bit confusing—the volumes on the USB drive you’re booted from also show up alongside any internal drives installed in your system. For most PCs with just a single internal disk, disk 0 should be the one you’re installing to.

Wi-Fi drivers during setup

Microsoft’s obnoxious no-exceptions Microsoft account requirement for all new PCs (and new Windows installs) is at its most obnoxious when you’re installing on a system without a functioning network adapter. This scenario has come up most frequently for me when clean-installing Windows on a brand-new PC with a brand-new, as-yet-unknown Wi-Fi adapter that Windows 11 doesn’t have built-in drivers for. Windows Update is usually good for this kind of thing, but you can’t use an Internet connection to fix not having an Internet connection.

Microsoft has added a fallback option to the first-time setup process for Windows 11 that allows users to install drivers from a USB drive if the Windows installer doesn’t already include what you need. As a failover, would we prefer to see an easy-to-use option that didn’t require Microsoft account sign-in? Sure. But this is better than it was before.

To bypass this entirely, there are still local account workarounds available for experts. Pressing Shift + F10, typing OOBEBYPASSNRO in the Command Prompt window that opens, and hitting Enter is still there for you in these situations.

Boosted security for file sharing

The 24H2 update has boosted the default security for SMB file-sharing connections, though, as Microsoft Principal Program Manager Ned Pyle notes, it may result in some broken things. In this case, that’s generally a good thing, as they’re only breaking because they were less secure than they ought to be. Still, it may be dismaying if something suddenly stops functioning when it was working before.

The two big changes are that all SMB connections need to be signed by default to prevent relay attacks and that Guest access for SMB shares is disabled in the Pro edition of Windows 11 (it had already been disabled in Enterprise, Education, and Pro for Workstation editions of Windows in the Windows 10 days). Guest fallback access is still available by default in Windows 11 Home, though the SMB signing requirement does apply to all Windows editions.

Microsoft notes that this will mainly cause problems for home NAS products or when you use your router’s USB port to set up network-attached storage—situations where security tends to be disabled by default or for ease of use.

If you run into network-attached storage that won’t work because of the security changes to 24H2, Microsoft’s default recommendation is to make the network-attached storage more secure. That usually involves configuring a username and password for access, enabling signing if it exists, and installing firmware updates that might enable login credentials and SMB signing on devices that don’t already support it. Microsoft also recommends replacing older or insecure devices that don’t meet these requirements.

That said, advanced users can turn off both the SMB signing requirements and guest fallback protection by using the Local Group Policy Editor. Those steps are outlined here. That post also outlines the process for disabling the SMB signing requirement for Windows 11 Home, where the Local Group Policy Editor doesn’t exist.

Windows Mixed Reality is dead and gone

Several technology hype cycles ago, before the Metaverse and when most “AI” stuff was still called “machine learning,” Microsoft launched a new software and hardware initiative called Windows Mixed Reality. Built on top of work it had done on its HoloLens headset in 2015, Windows Mixed Reality was meant to bring in app developers and the PC makers and allowed them to build interoperable hardware and software for both virtual reality headsets that covered your eyes entirely and augmented reality headsets that superimpose objects over the real world.

But like some other mid-2010s VR-related initiatives, both HoloLens and Windows Mixed Reality kind of fizzled and flailed, and both are on their way out. Microsoft officially announced the end of HoloLens at the beginning of the month, and Windows 11 24H2 utterly removes everything Mixed Reality from Windows.

Microsoft announced this in December of 2023 (in a message that proclaims “we remain committed to HoloLens”), though this is a shorter off-ramp than some deprecated features (like the Android Subsystem for Windows) have gotten. Users who want to keep using Windows Mixed Reality can continue to use Windows 23H2, though support will end for good in November 2026 when support for the 23H2 update expires.

WordPad is also dead

WordPad running in Windows 11 22H2. It will continue to be available in 22H2/23H2, but it’s been removed from the 2024 update. Credit: Andrew Cunningham

We’ve written plenty about this already, but the 24H2 update is the one that pulls the plug on WordPad, the rich text editor that has always existed a notch above Notepad and many, many notches below Word in the hierarchy of Microsoft-developed Windows word processors.

WordPad’s last update of any real substance came in 2009, when it was given the then-new “ribbon” user interface from the then-recent Office 2007 update. It’s one of the few in-box Windows apps not to see some kind of renaissance in the Windows 11 era; Notepad, by contrast, has gotten more new features in the last two years than it had in the preceding two decades. And now it has been totally removed, gone the way of Internet Explorer and Encarta.

Photo of Andrew Cunningham

Andrew is a Senior Technology Reporter at Ars Technica, with a focus on consumer tech including computer hardware and in-depth reviews of operating systems like Windows and macOS. Andrew lives in Philadelphia and co-hosts a weekly book podcast called Overdue.

Eleven things to know about in the Windows 11 2024 Update Read More »

unicode-16.0-release-with-new-emoji-brings-character-count-to-154,998

Unicode 16.0 release with new emoji brings character count to 154,998

right there with you, bags-under-eyes emoji —

New designs will roll out to phones, tablets, and PCs over the next few months.

Emojipedia sample images of the new Unicode 16.0 emoji.

Enlarge / Emojipedia sample images of the new Unicode 16.0 emoji.

The Unicode Consortium has finalized and released version 16.0 of the Unicode standard, the elaborate character set that ensures that our phones, tablets, PCs, and other devices can all communicate and interoperate with each other. The update adds 5,185 new characters to the standard, bringing the total up to a whopping 154,998.

Of those 5,185 characters, the ones that will get the most attention are the eight new emoji characters, including a shovel, a fingerprint, a leafless tree, a radish (formally classified as “root vegetable”), a harp, a purple splat that evokes the ’90s Nickelodeon logo, and a flag for the island of Sark. The standout, of course, is “face with bags under eyes,” whose long-suffering thousand-yard stare perfectly encapsulates the era it has been born into. Per usual, Emojipedia has sample images that give you some idea of what these will look like when they’re implemented by various operating systems, apps, and services.

Unicode 16.0 also adds support for seven new modern and historical scripts: the West African Garay alphabet; the Gurung Khema, Kirat Rai, Ol Onal, and Sunuwar scripts from Northeast India and Nepal; and historical Todhri and Tulu-Tigalari scripts from Albania and Southwest India, respectively.

We last got new emoji in 2023’s Unicode 15.1 update, though all of these designs were technically modifications of existing emoji rather than new characters—many emoji, most notably for skin and hair color variants, use a base emoji plus a modifier emoji, combined together with a “zero-width joiner” (ZWJ) character that makes them display as one character instead. The lime emoji in Unicode 15.1 was actually a lemon emoji combined with the color green; the phoenix was a regular bird joined to the fire emoji. This was likely because 15.1 was only intended as a minor update to 2022’s Unicode 15.0 standard.

Most of the Unicode 16.0 emoji, by contrast, are their own unique characters. The one exception is the Sark flag emoji; flag sequences are created by placing two “regional indicator letters” directly next to each other and don’t require a ZWJ character between them.

Incorporation into the Unicode standard is only the first step that new emoji and other characters take on their journey from someone’s mind to your phone or computer; software makers like Apple, Google, Microsoft, Samsung, and others need to design iterations that fit with their existing spin on the emoji characters, they need to release software updates that use the new characters, and people need to download and install them.

We’ve seen a few people share on social media that the Unicode 16.0 release includes a “greenwashing” emoji designed by Shepard Fairey, an artist best known for the 2008 Barack Obama “Hope” poster. This emoji, and an attempt to gin up controversy around it, is all an elaborate hoax: there’s a fake Unicode website announcing it, a fake lawsuit threat that purports to be from a real natural gas industry group, and a fake Cory Doctorow article about the entire “controversy” published in a fake version of Wired. These were all published to websites with convincing-looking but fake domains, all registered within a couple of weeks of each other in August 2024. The face-with-bags-under-eyes emoji feels like an appropriate response.

Unicode 16.0 release with new emoji brings character count to 154,998 Read More »

asus-rog-ally-x-review:-better-performance-and-feel-in-a-pricey-package

Asus ROG Ally X review: Better performance and feel in a pricey package

Faster, grippier, pricier, and just as Windows-ed —

A great hardware refresh, but it stands out for its not-quite-handheld cost.

Updated

It's hard to fit the perfomance-minded but pricey ROG Ally X into a simple product category. It's also tricky to fit it into a photo, at the right angle, while it's in your hands.

Enlarge / It’s hard to fit the perfomance-minded but pricey ROG Ally X into a simple product category. It’s also tricky to fit it into a photo, at the right angle, while it’s in your hands.

Kevin Purdy

The first ROG Ally from Asus, a $700 Windows-based handheld gaming PC, performed better than the Steam Deck, but it did so through notable compromises on battery life. The hardware also had a first-gen feel and software jank from both Asus’ own wraparound gaming app and Windows itself. The Ally asked an awkward question: “Do you want to pay nearly 50 percent more than you’d pay for a Steam Deck for a slightly faster but far more awkward handheld?”

The ROG Ally X makes that question more interesting and less obvious to answer. Yes, it’s still a handheld that’s trying to hide Windows annoyances, and it’s still missing trackpads, without which some PC games just feel bad. And (review spoiler) it still eats a charge faster than the Steam Deck OLED on less demanding games.

But the improvements Asus made to this X sequel are notable, and its new performance stats make it more viable for those who want to play more demanding games on a rather crisp screen. At $800, or $100 more than the original ROG Ally with no extras thrown in, you have to really, really want the best possible handheld gaming experience while still tolerating Windows’ awkward fit.

Asus

What’s new in the Ally X

Specs at a glance: Asus ROG Ally X
Display 7-inch IPS panel: 1920×1080, 120 Hz, 7 ms, 500 nits, 100% sRGB, FreeSync, Gorilla Glass Victus
OS Windows 11 (Home)
CPU AMD Ryzen Z1 Extreme (Zen 4, 8 core, 24M cache, 5.10 Ghz, 9-30 W (as reviewed)
RAM 24GB LPDDR5X 6400 MHz
GPU AMD Radeon RDNA3, 2.7 GHz, 8.6 Teraflops
Storage M.2 NVME 2280 Gen4x4, 1TB (as reviewed)
Networking Wi-Fi 6E, Bluetooth 5.2
Battery 80 Wh (65W max charge)
Ports USB-C (3.2 Gen2, DPI 1.4, PD 3.0), USB-C (DP, PD 3.0), 3.5 mm audio, Micro SD
Size 11×4.3×0.97 in. (280×111×25 mm)
Weight 1.49 lbs (678 g)
Price as reviewed $800

The ROG Ally X is essentially the ROG Ally with a bigger battery packed into a shell that is impressively not much bigger or heavier, more storage and RAM, and two USB-C ports instead of one USB-C and one weird mobile port that nobody could use. Asus reshaped the device and changed the face-button feel, and it all feels noticeably better, especially now that gaming sessions can last longer. The company also moved the microSD card slot so that your cards don’t melt, which is nice.

There’s a bit more to each of those changes that we’ll get into, but that’s the short version. Small spec bumps wouldn’t have changed much about the ROG Ally experience, but the changes Asus made for the X version do move the needle. Having more RAM available has a sizable impact on the frame performance of demanding games, and you can see that in our benchmarks.

We kept the LCD Steam Deck in our benchmarks because its chip has roughly the same performance as its OLED upgrade. But it’s really the Ally-to-Ally-X comparisons that are interesting; the Steam Deck has been fading back from AAA viability. If you want the Ally X to run modern, GPU-intensive games as fast as is feasible for a battery-powered device, it can now do that a lot better—for longer—and feel a bit better while you do.

The Rog Ally X has better answered the question “why not just buy a gaming laptop?” than its predecessor. At $800 and up, you might still ask how much portability is worth to you. But the Ally X is not as much of a niche (Windows-based handheld) inside a niche (moderately higher-end handhelds).

I normally would not use this kind of handout image with descriptive text embedded, but Asus is right: the ROG Ally X is indeed way more comfortable (just maybe not all-caps).

I normally would not use this kind of handout image with descriptive text embedded, but Asus is right: the ROG Ally X is indeed way more comfortable (just maybe not all-caps).

Asus

How it feels using the Rog Ally X

My testing of the Rog Ally X consisted of benchmarks, battery testing, and playing some games on the couch. Specifically: Deep Rock Galactic: Survivor and Tactical Breach Wizards on the devices lowest-power setting (“Silent”), Deathloop on its medium-power setting (“Performance”), and Shadow of the Erdtree on its all-out “Turbo” mode.

All four of those games worked mostly fine, but DRG: Survivor pushed the boundaries of Silent mode a bit when its levels got crowded with enemies and projectiles. Most games could automatically figure out a decent settings scheme for the Ally X. If a game offers AMD’s FSR (FidelityFX Super Resolution) upscaling, you should at least try it; it’s usually a big boon to a game running on this handheld.

Overall, the ROG Ally X was a device I didn’t notice when I was using it, which is the best recommendation I can make. Perhaps I noticed that the 1080p screen was brighter, closer to the glass, and sharper than the LCD (original) Steam Deck. At handheld distance, the difference between 800p and 1080p isn’t huge to me, but the difference between LCD and OLED is more so. (Of course, an OLED version of the Steam Deck was released late last year.)

Asus ROG Ally X review: Better performance and feel in a pricey package Read More »

microsoft-to-host-security-summit-after-crowdstrike-disaster

Microsoft to host security summit after CrowdStrike disaster

Bugging out —

Redmond wants to improve the resilience of Windows to buggy software.

Photo of a Windows BSOD

Microsoft is stepping up its plans to make Windows more resilient to buggy software after a botched CrowdStrike update took down millions of PCs and servers in a global IT outage.

The tech giant has in the past month intensified talks with partners about adapting the security procedures around its operating system to better withstand the kind of software error that crashed 8.5 million Windows devices on July 19.

Critics say that any changes by Microsoft would amount to a concession of shortcomings in Windows’ handling of third-party security software that could have been addressed sooner.

Yet they would also prove controversial among security vendors that would have to make radical changes to their products, and force many Microsoft customers to adapt their software.

Last month’s outages—which are estimated to have caused billions of dollars in damages after grounding thousands of flights and disrupting hospital appointments worldwide—heightened scrutiny from regulators and business leaders over the extent of access that third-party software vendors have to the core, or kernel, of Windows operating systems.

Microsoft will host a summit next month for government representatives and cyber security companies, including CrowdStrike, to “discuss concrete steps we will all take to improve security and resiliency for our joint customers,” Microsoft said on Friday.

The gathering will take place on September 10 at Microsoft’s headquarters near Seattle, it said in a blog post.

Bugs in the kernel can quickly crash an entire operating system, triggering the millions of “blue screens of death” that appeared around the globe after CrowdStrike’s faulty software update was sent out to clients’ devices.

Microsoft told the Financial Times it was considering several options to make its systems more stable and had not ruled out completely blocking access to the Windows kernel—an option some rivals fear would put their software at a disadvantage to the company’s internal security product, Microsoft Defender.

“All of the competitors are concerned that [Microsoft] will use this to prefer their own products over third-party alternatives,” said Ryan Kalember, head of cyber security strategy at Proofpoint.

Microsoft may also demand new testing procedures from cyber security vendors rather than adapting the Windows system itself.

Apple, which was not hit by the outages, blocks all third-party providers from accessing the kernel of its MacOS operating system, forcing them to operate in the more limited “user-mode.”

Microsoft has previously said it could not do the same, after coming to an understanding with the European Commission in 2009 that it would give third parties the same access to its systems as that for Microsoft Defender.

Some experts said, however, that this voluntary commitment to the EU had not tied Microsoft’s hands in the way it claimed, arguing that the company had always been free to make the changes now under consideration.

“These are technical decisions of Microsoft that were not part of [the arrangement],” said Thomas Graf, a partner at Cleary Gottlieb in Brussels who was involved in the case.

“The text [of the understanding] does not require them to give access to the kernel,” added AJ Grotto, a former senior director for cyber security policy at the White House.

Grotto said Microsoft shared some of the blame for the July disruption since the outages would not have been possible without its decision to allow access to the kernel.

Nevertheless, while it might boost a system’s resilience, blocking kernel access could also bring “real trade-offs” for the compatibility with other software that had made Windows so popular among business customers, Forrester analyst Allie Mellen said.

“That would be a fundamental shift for Microsoft’s philosophy and business model,” she added.

Operating exclusively outside the kernel may lower the risk of triggering mass outages but it was also “very limiting” for security vendors and could make their products “less effective” against hackers, Mellen added.

Operating within the kernel gave security companies more information about potential threats and enabled their defensive tools to activate before malware could take hold, she added.

An alternative option could be to replicate the model used by the open-source operating system Linux, which uses a filtering mechanism that creates a segregated environment within the kernel in which software, including cyber defense tools, can run.

But the complexity of overhauling how other security software works with Windows means that any changes will be hard for regulators to police and Microsoft will have strong incentives to favor its own products, rivals said.

It “sounds good on paper, but the devil is in the details,” said Matthew Prince, chief executive of digital services group Cloudflare.

© 2024 The Financial Times Ltd. All rights reserved Not to be redistributed, copied, or modified in any way.

Microsoft to host security summit after CrowdStrike disaster Read More »

microsoft-will-try-the-data-scraping-windows-recall-feature-again-in-october

Microsoft will try the data-scraping Windows Recall feature again in October

recall reincarnated —

Initial Recall preview was lambasted for obvious privacy and security failures.

The Recall feature provides a timeline of screenshots and a searchable database of text, thoroughly tracking everything about a person's PC usage.

Enlarge / The Recall feature provides a timeline of screenshots and a searchable database of text, thoroughly tracking everything about a person’s PC usage.

Microsoft

Microsoft will begin sending a revised version of its controversial Recall feature to Windows Insider PCs beginning in October, according to an update published today to the company’s original blog post about the Recall controversy. The company didn’t elaborate further on specific changes it’s making to Recall beyond what it already announced in June.

For those unfamiliar, Recall is a Windows service that runs in the background on compatible PCs, continuously taking screenshots of user activity, scanning those screenshots with optical character recognition (OCR), and saving the OCR text and the screenshots to a giant searchable database on your PC. The goal, according to Microsoft, is to help users retrace their steps and dig up information about things they had used their PCs to find or do in the past.

The problem was that other users on the same PC, or attackers with physical or remote access to your PC, could easily access, view, and export those screenshots and the OCR database since none of the information was encrypted at rest or protected in any substantive way.

Microsoft had planned to launch Recall as one of the flagship features of its Copilot+ PC launch in July, along with the new Qualcomm Snapdragon-powered Surface devices, but its rollout was bumped back and then paused entirely so that Recall could be reworked and then sent out to Windows Insiders for testing like most other Windows features are.

Among the changes Microsoft has said it will make: The database will be encrypted at rest and will require authentication (and periodic reauthentication) with Windows Hello before users will be allowed to access it. The feature will also be off by default, whereas the original plan was to turn it on by default and make users go into Settings to turn it off.

“Security continues to be our top priority and when Recall is available for Windows Insiders in October we will publish a blog with more details,” reads today’s update to Microsoft Windows and Devices Corporate Vice President Pavan Davuluri’s blog post.

When the preview is released, Windows Insiders who want to test the Recall preview will need to do it on a PC that meets Microsoft’s Copilot+ system requirements. Those include a processor with a neural processing unit (NPU) capable of at least 40 trillion operations per second (TOPS), 16GB of RAM, and 256GB of storage. The x86 builds of Windows for Intel and AMD processors don’t currently support any Copilot+ features regardless of whether the PC meets those requirements, but that should change later this year.

That said, security researchers and reporters who found the holes in the original version of Recall could only find them because it was possible to enable them on unsupported PCs, just as it’s possible to run Windows 11 on PCs that don’t meet the system requirements. It’s possible that users will figure out how to get Recall and other Copilot+ features running on unsupported PCs at some point, too.

Microsoft will try the data-scraping Windows Recall feature again in October Read More »

windows-recall-demands-an-extraordinary-level-of-trust-that-microsoft-hasn’t-earned

Windows Recall demands an extraordinary level of trust that Microsoft hasn’t earned

The Recall feature as it currently exists in Windows 11 24H2 preview builds.

Enlarge / The Recall feature as it currently exists in Windows 11 24H2 preview builds.

Andrew Cunningham

Microsoft’s Windows 11 Copilot+ PCs come with quite a few new AI and machine learning-driven features, but the tentpole is Recall. Described by Microsoft as a comprehensive record of everything you do on your PC, the feature is pitched as a way to help users remember where they’ve been and to provide Windows extra contextual information that can help it better understand requests from and meet the needs of individual users.

This, as many users in infosec communities on social media immediately pointed out, sounds like a potential security nightmare. That’s doubly true because Microsoft says that by default, Recall’s screenshots take no pains to redact sensitive information, from usernames and passwords to health care information to NSFW site visits. By default, on a PC with 256GB of storage, Recall can store a couple dozen gigabytes of data across three months of PC usage, a huge amount of personal data.

The line between “potential security nightmare” and “actual security nightmare” is at least partly about the implementation, and Microsoft has been saying things that are at least superficially reassuring. Copilot+ PCs are required to have a fast neural processing unit (NPU) so that processing can be performed locally rather than sending data to the cloud; local snapshots are protected at rest by Windows’ disk encryption technologies, which are generally on by default if you’ve signed into a Microsoft account; neither Microsoft nor other users on the PC are supposed to be able to access any particular user’s Recall snapshots; and users can choose to exclude apps or (in most browsers) individual websites to exclude from Recall’s snapshots.

This all sounds good in theory, but some users are beginning to use Recall now that the Windows 11 24H2 update is available in preview form, and the actual implementation has serious problems.

“Fundamentally breaks the promise of security in Windows”

This is Recall, as seen on a PC running a preview build of Windows 11 24H2. It takes and saves periodic screenshots, which can then be searched for and viewed in various ways.

Enlarge / This is Recall, as seen on a PC running a preview build of Windows 11 24H2. It takes and saves periodic screenshots, which can then be searched for and viewed in various ways.

Andrew Cunningham

Security researcher Kevin Beaumont, first in a thread on Mastodon and later in a more detailed blog post, has written about some of the potential implementation issues after enabling Recall on an unsupported system (which is currently the only way to try Recall since Copilot+ PCs that officially support the feature won’t ship until later this month). We’ve also given this early version of Recall a try on a Windows Dev Kit 2023, which we’ve used for all our recent Windows-on-Arm testing, and we’ve independently verified Beaumont’s claims about how easy it is to find and view raw Recall data once you have access to a user’s PC.

To test Recall yourself, developer and Windows enthusiast Albacore has published a tool called AmperageKit that will enable it on Arm-based Windows PCs running Windows 11 24H2 build 26100.712 (the build currently available in the Windows Insider Release Preview channel). Other Windows 11 24H2 versions are missing the underlying code necessary to enable Recall.

  • Windows uses OCR on all the text in all the screenshots it takes. That text is also saved to an SQLite database to facilitate faster searches.

    Andrew Cunningham

  • Searching for “iCloud,” for example, brings up every single screenshot with the word “iCloud” in it, including the app itself and its entry in the Microsoft Store. If I had visited websites that mentioned it, they would show up here, too.

    Andrew Cunningham

The short version is this: In its current form, Recall takes screenshots and uses OCR to grab the information on your screen; it then writes the contents of windows plus records of different user interactions in a locally stored SQLite database to track your activity. Data is stored on a per-app basis, presumably to make it easier for Microsoft’s app-exclusion feature to work. Beaumont says “several days” of data amounted to a database around 90KB in size. In our usage, screenshots taken by Recall on a PC with a 2560×1440 screen come in at 500KB or 600KB apiece (Recall saves screenshots at your PC’s native resolution, minus the taskbar area).

Recall works locally thanks to Azure AI code that runs on your device, and it works without Internet connectivity and without a Microsoft account. Data is encrypted at rest, sort of, at least insofar as your entire drive is generally encrypted when your PC is either signed into a Microsoft account or has Bitlocker turned on. But in its current form, Beaumont says Recall has “gaps you can drive a plane through” that make it trivially easy to grab and scan through a user’s Recall database if you either (1) have local access to the machine and can log into any account (not just the account of the user whose database you’re trying to see), or (2) are using a PC infected with some kind of info-stealer virus that can quickly transfer the SQLite database to another system.

Windows Recall demands an extraordinary level of trust that Microsoft hasn’t earned Read More »

microsoft-plans-to-lock-down-windows-dns-like-never-before-here’s-how.

Microsoft plans to lock down Windows DNS like never before. Here’s how.

Microsoft plans to lock down Windows DNS like never before. Here’s how.

Getty Images

Translating human-readable domain names into numerical IP addresses has long been fraught with gaping security risks. After all, lookups are rarely end-to-end encrypted. The servers providing domain name lookups provide translations for virtually any IP address—even when they’re known to be malicious. And many end-user devices can easily be configured to stop using authorized lookup servers and instead use malicious ones.

Microsoft on Friday provided a peek at a comprehensive framework that aims to sort out the Domain Name System (DNS) mess so that it’s better locked down inside Windows networks. It’s called ZTDNS (zero trust DNS). Its two main features are (1) encrypted and cryptographically authenticated connections between end-user clients and DNS servers and (2) the ability for administrators to tightly restrict the domains these servers will resolve.

Clearing the minefield

One of the reasons DNS has been such a security minefield is that these two features can be mutually exclusive. Adding cryptographic authentication and encryption to DNS often obscures the visibility admins need to prevent user devices from connecting to malicious domains or detect anomalous behavior inside a network. As a result, DNS traffic is either sent in clear text or it’s encrypted in a way that allows admins to decrypt it in transit through what is essentially an adversary-in-the-middle attack.

Admins are left to choose between equally unappealing options: (1) route DNS traffic in clear text with no means for the server and client device to authenticate each other so malicious domains can be blocked and network monitoring is possible, or (2) encrypt and authenticate DNS traffic and do away with the domain control and network visibility.

ZTDNS aims to solve this decades-old problem by integrating the Windows DNS engine with the Windows Filtering Platform—the core component of the Windows Firewall—directly into client devices.

Jake Williams, VP of research and development at consultancy Hunter Strategies, said the union of these previously disparate engines would allow updates to be made to the Windows firewall on a per-domain name basis. The result, he said, is a mechanism that allows organizations to, in essence, tell clients “only use our DNS server, that uses TLS, and will only resolve certain domains.” Microsoft calls this DNS server or servers the “protective DNS server.”

By default, the firewall will deny resolutions to all domains except those enumerated in allow lists. A separate allow list will contain IP address subnets that clients need to run authorized software. Key to making this work at scale inside an organization with rapidly changing needs. Networking security expert Royce Williams (no relation to Jake Williams) called this a “sort of a bidirectional API for the firewall layer, so you can both trigger firewall actions (by input *tothe firewall), and trigger external actions based on firewall state (output *fromthe firewall). So instead of having to reinvent the firewall wheel if you are an AV vendor or whatever, you just hook into WFP.”

Microsoft plans to lock down Windows DNS like never before. Here’s how. Read More »

the-spam-came-from-inside-the-house:-how-a-smart-tv-can-choke-a-windows-pc

The spam came from inside the house: How a smart TV can choke a Windows PC

There are a million protocols in the naked city —

The curious case of a living room screen making Windows’ Settings app disappear.

Image of silhouetted girl trapped inside a television inside an entertainment center

Enlarge / I have hundreds of UUIDs and I must scream.

Getty Images

The modern “smart” TV asks a lot of us. In exchange for connecting you to a few streaming services you use, a TV will collect data, show ads, and serve as another vector for bad actors. In a few reported cases, though, a modern connected TV has been blamed for attacks not on privacy, eyeballs, or passwords but on an entirely different computer.

The TV in question is a Hisense TV, and the computer is a Windows PC, specifically one belonging to Priscilla Snow, a musician and audio designer in Montréal, Quebec. Her post about her Hisense experience reads like a mystery. Of course, because you already know the crime and the culprit, it’s more like a Columbo episode. Either way, it’s thrilling in a very specific I-can’t-believe-that-fixed-it kind of thrill.

Disappearing Settings, keyboards, remote desktops, and eventually taskbars

Snow’s Windows PC had “a few hiccups over the past couple of years,” Snow wrote on April 19. She couldn’t open display settings, for one. A MIDI keyboard interface stopped working. Task manager would start to hang until force-closed. Video capture cards had trouble connecting. As Snow notes, any veteran of a Windows computer that has had lots of stuff installed on it can mentally write off most of these things, or at least stash them away until the next reinstall.

Then, while trying to figure out why a remote desktop session wasn’t working, the task bars on Snow’s PC disappeared. The PC refused to launch any settings panels. After updating drivers and restarting the PC, the taskbars returned, but only for six days. Snow hunted for solutions, and after using “the exact right string in my search,” she found a Reddit thread that led to a Microsoft support question, all describing the same kinds of seemingly spectral problems her computer was having over time, with no clear cause.

User Narayan B wrote in Microsoft’s forum that the issue is the Hisense TV generating “random UUIDs for UPNP network discovery every few minutes.” Windows, seemingly not knowing why any device would routinely do this, sees and adds those alternate Hisense devices to its Device Association Framework, or DAF. This service being stuffed full of attention-grabbing devices can hang up Task Manager, Bluetooth, the Settings apps, File Explorer, and more.

The fix is deleting hundreds of keys from the registry. Narayan B wrote that noticed his Hisense TV flooding Windows’ device discovery systems before but “didn’t think Windows would go for a toss due to this.” Snow did the same, and everything—Task Manager, MIDI keyboard, remote desktop, even a CRT monitor she had assumed was broken—started working again.

UUID, UPNP, DAF, and hundreds of Registry keys

Along with deleting hundreds of keys with maniacal keyboard pounding, Snow notes in chats attached to her post that she disabled “Set up network connected devices automatically” on her “Private networks” settings in Windows. And, of course, she recommend not buying the same Hisense 50Q8G she bought, or at least not having it on the same network.

The mystery is solved, but the culprit remains very much at large. Or culprits—plural—depending on how you think a Windows PC should react to a shapeshifting TV.

Ars reached out to Hisense to ask for comment and will update the post if we hear back.

The spam came from inside the house: How a smart TV can choke a Windows PC Read More »