Windows 11 Security Approach: Zero-Trust Juggernaut Launched
October 5 Is the Day of the Long-Expected Windows 11 Official Release. Let’s See What Data Protection News It Brings Around. It Provides a Lot! Security Has...
October 5 is the day of the long-expected Windows 11 official release. Let’s see what data protection news it brings around. It provides a lot! Security has become a cornerstone of Microsoft’s newest creation. Moreover, it dictates Windows 11 hardware requirements that millions of modern machines don’t satisfy. Here you can read about nature, reasons, and principles for such drastic changes.
Hardware requirements and what lies behind them
A lot has been said already about Windows 11 for many unbearable requirements. How To Fix Guide previously posted an article on that. Attentive gaze into the requirements list won’t miss one nuance about it. The new standard is not about performance as much as it is about security and data protection.
The notorious Trusted Platform Module 2.0, that half of the aspiring Windows devotees lack, is a device for secure cryptographic operations. That means it does not let decrypted data leave the physically protected environment, which is the cryptoprocessor itself. TPM serves to generate keys, store them, and authenticate devices.
You can find more information on security processors in the How To Fix Guide tutorial article about TPMs.
Red flags raised back in 2018 can explain Windows 11 security level.
TPM 2.0. So much for a tiny chip!
Windows 11 Security Portfolio
A user must turn on these features to install Windows 11: hardware-based isolation, secure boot, hypervisor-protected code integrity.
Hardware-based isolation is the abovementioned deployment of a secure cryptoprocessor.
Secure boot is a UEFI feature. Previously, it could be toggled on/off arbitrarily by the user. But it also becomes a requirement for Windows 11 security. It keeps the critical system software protected from any unauthorized access by digital signature check. Secure boot eliminates threats that an operating system or drivers attempting to load can introduce.
As before, Microsoft stakes a lot on virtualization-based security as a reliable safety measure against some side-channel hardware vulnerabilities. Hypervisor-protected code integrity (also known as Memory Integrity) is a measure working out Meltdown-like flaws that proved to be unexploitable if the targeted system runs on a virtual machine. You will recall that Windows 10 failed to combine security with convenience in this matter. The 2018 Memory Integrity feature had its shortcomings, and hopefully, Microsoft has updated it well since then.
The Windows 11 anti-malware software is still Windows Defender. Features like Windows Hello (non-password biometrics-based authentication feature) and BitLocker (drive encryption tool) go alongside it.
Microsoft claims a 60% betterment in terms of malware protection if all the measures are on. However, it is unclear whence comes that percentage.