Wednesday, 1 September 2021

Microsoft Kicks Unsupported PCs From Windows 11 Testing Program

The Windows Insider program is usually a good way to see what’s next in the world of Microsoft’s ubiquitous operating system…unless you’re trying to run Windows 11 without the right hardware. As the October launch date for Windows 11 grows closer, Microsoft is standing firm on the new software’s spec requirements. In fact, anyone running the beta on unacceptable hardware is being booted from the program, and their only option is to accept defeat and reinstall Windows 10. 

Windows has traditionally accepted all comers. Even a toaster with a sufficiently powerful CPU could run Windows, albeit slowly. With Windows 11, Microsoft is narrowing its focus to newer hardware. To run Windows 11, PCs need to have a 64-bit processor, and that CPU needs to be at least an 8th generation Intel or Ryzen 3. There’s also support for ARM chips starting with the Snapdragon 7c. The other sticking point is support for Trusted Platform Model (TMP) 2.0. 

Anyone who thought they could get away with running the dev or beta Insiders channels on old or unsupported hardware is in for a rude awakening today. These systems are getting update notifications that tell them the free ride is over. “Your PC does not meet the minimum hardware requirements for Windows 11,” Microsoft’s warning states. “Your device is not eligible to join the Windows Insider Program on Windows 11. Please install Windows 10 to participate in the Windows Insider Program in the Release Preview Channel.”

Technically, anyone running the Insiders build of the OS will be able to use a disk ISO to install the final version when it launches. However, these systems still won’t be eligible for Windows Update, and that means no guaranteed security patches. As everyone should know at this point, running an unpatched version of Windows online is a great way to end up with viruses and ransomware. Thus, the recommendation that these systems revert back to Windows 10. 

It could be worse. Windows 10 has gone through years of updates, and it’s well-supported and stable at this point. With its expanded “classic” hardware support, Windows 10 will provide security patches for all users through 2025. 

This is all undeniably annoying, particularly for Insiders who are often the biggest Microsoft fans. At the same time, we have seen Microsoft flub numerous updates to Windows 10. Perhaps narrowing hardware support a bit will make it easier to keep the OS running smoothly. We can only hope.

Now read:



ARM Refutes Accusations of IP Theft by Its ARM China Subsidiary

Earlier this week, we reported that ARM China had seized IP belonging to ARM, its parent company. The author of the story we linked apparently did not fully understand the context of the situation, however, and we inadvertently magnified an article with some misapprehensions in it. We have spoken to ARM and done some follow-up investigating of our own, and want to set the record straight.

Not everything in the original article was incorrect. ARM is currently in a legal fight with ARM China and Allen Wu. Wu was voted out for reportedly using ARM China’s resources to procure orders for his own company. The various allegations that Wu has hired security guards, fired a number of employees, and still holds the seal of the company have been reported on by multiple publications. There is an ongoing dispute between ARM and ARM China.

But the accusations that ARM China had stolen ARM IP and was relaunching it under its own banner? Those don’t appear to be true. First, here’s a formal statement, as provided to us by an ARM representative:

Arm has seen strong growth in our business as our global partners shipped more than 25 billion Arm-based chips in 2020. Of those 25 billion chips, more than 3 billion were shipped by our partners based in China.

Arm continues to have a successful working relationship with the Arm China team in support of this growth, and both the structure and ownership of the JV remains unchanged since its inception in 2018.

This doesn’t explicitly refute the idea of IP theft, so we did a bit of additional digging ourselves and spoke to a few other sources with knowledge of the situation. The reason ARM hasn’t transferred higher-end CPU IP to the Chinese market is said to be related to the fact that most cutting-edge mobile silicon in mainland China was built by Huawei/HiSilicon, and HiSilicon is under restrictions via the US Entity List. I don’t have any information about the accusation that ARM withheld data on its latest ISA, ARMv9, but that could also be explained as a bargaining chip in the ongoing legal fight, not as a retaliatory response to IP theft.

We’ve seen a translated version of the AnMou (ARM China) press release, and it offers some important context.

What AnMou Technologies announced is that it would be launching its own line of products based on its own in-house IP, branded as Core Power. The press release states: “Core Power improves the computing by extension from CPU to other computing units represented by NPU, ISP, VPU, and GPU.”

Core Power isn’t trying to steal already-developed ARM IP. The company makes this clear later in the press release when it writes:

AnMou Technology officially announced [a] “two wheels” strategy. On one hand, the company continues driving localization and ecosystemization development of ARM CPU architecture. On the other hand, the company will focus on autonomous self-development to develop autonomous-architecture-based XPU products and diversified ecosystem. Via the combination of innovation of XPU and traditional IP, the company will provide diversified and customized computing units to address the demands of China industry and market. xDSA-based XPU is an open intelligent-data-stream-fusion computing platform.

This is not theft. It’s no different than the idea of AMD licensing a Cortex CPU from ARM while simultaneously continuing to develop Ryzen. Regardless of the other problems between ARM and ARM China, the IP theft angle is apparently incorrect. Core Power is not a new tech company intended to steal IP, it’s a new brand the ARM subsidiary created to sell its own IP at home. ARM’s business model is designed to encourage this kind of flexibility.

The story ExtremeTech originally linked was based on accurate reporting but was not, itself, particularly accurate. ET regrets the error.

Now Read:



Intel Does Not Launch Different SSD Configurations Under the Same SKU

As part of our investigation into the consumer SSD market, we’ve reached out to multiple manufacturers to better understand the practice of shipping different versions of an SSD under the same SKU. Over the past 10 days, we’ve learned that at least four manufacturers — Western Digital, Samsung, Crucial, and Adata — have engaged in this practice in the recent past.

The net effect of this behavior is that the drives that go out for launch day reviews and the drives that consumers later buy may offer very different performance. This sabotages trust between readers, reviewers, and manufacturers to the detriment of all three groups. We have discussed this practice with Crucial and Western Digital, both of whom have already pledged to take steps and make this right (WD) or signaled they are at least open to the conversation (Crucial). We’ll see how things play out the next time a new tranche of SSDs hit the market.

We asked Intel if it had ever shipped a high-performing drive variant at launch and then swapped it for a drive that performed worse in any industry-standard benchmark:

No. Intel does not, and has never, engaged in the practice of swapping SSD hardware components in any of our product lines for lower-performing ones after product launch. To do so would violate company principles of integrity and product quality. Any change that would impact performance would be clearly communicated to customers.

Intel is not the largest player in consumer SSDs, but right now it’s one of the companies selling hardware that we’re completely confident will meet the performance you see in online reviews. We do not think every manufacturer is swapping NAND on every drive — there’s no indication of that — and the problem does seem mostly confined mostly to the budget market. Just last week, however, we thought the problem was confined to just a few companies and that Samsung was unaffected. Given this, we’re a bit leery of making pronouncements about affected drive configurations without manufacturer statements.

Drives like the Samsung 970 EVO Plus don’t drop to 100MB/s – 300MB/s, but they still take a heavy hit. (Photo: 潮玩客)

This is welcome news. It is no secret that I have criticized some of Intel’s behavior with respect to benchmarks in the past, but that has never extended to whether Intel sold the hardware it claimed to be selling. AMD and Nvidia are no different. While it’s true that Intel and AMD have sometimes updated their products without changing the branding, I cannot think of an instance in which the swap harmed customers. The newer version of a chip always improves on the original, either in terms of slightly higher boost frequencies or lower power consumption at the same frequency.

The closest example might be the fact that the various Spectre and Meltdown patches had a negative impact on x86 performance, but it’s not a good comparison. Intel and AMD were up-front about the problem and the objective reasons why patches were needed. Multiple sites published articles on the impact of the Spectre and Meltdown fixes on both Windows and Linux. There are ways to disable certain fixes to regain lost performance. Every facet of the topic has been publicly discussed from the beginning. The companies affected by Spectre and Meltdown were clear about the impacts of both the security flaws and the various changes required to mitigate them. Intel and AMD continue to participate in vulnerability disclosures three and a half years after the problem was discovered.

The SSD manufacturers who have departed from best practices need to return to them. Crucial and WD have indicated a willingness to take at least some steps towards doing so. This can best be achieved through better transparency, the release of updated SKUs when new product variants launch, and by manufacturer’s paying closer attention to what it means to offer equivalent performance between two different versions of an SSD. What’s going on is a problem, but it’s not a problem without a solution. It’s also a problem Intel doesn’t need to solve. This should not be read to mean Intel is the only honest SSD manufacturer, but it’s the only large company we’ve contacted thus far that provided a definitive “No” when we asked about this practice.

Now Read:



Astronomers: Many Sun-Like Stars Already Devoured Their Planets

(Image: NASA/EASA/G. Bacon)
The sun won’t consume the earth for another few billion years. This is either good or bad news, depending on how you look at it. But in the meantime, we can look at other sun-like stars and see what they’ve been up to – and even what they’ve eaten recently. Spoiler: a lot of planets. A new spectral survey of sun-like binary pairs published in Nature gives the odds of a star ingesting one or more of its planets at around one in four.

You can tell a lot about a star by the lines of its spectral “fingerprint,” starting with what chemical elements it must be made of. From there, we can draw conclusions about lots of stellar phenomena, including how old a star is, how hot it’s burning, how fast it’s moving, and whether it’s due to explode. That’s how we figured out that Betelgeuse — one of Orion’s shoulders — is a baby rogue star doing its best to live fast and die young.

Our sun is not like Betelgeuse, thankfully. Just like the overwhelming majority of known stars, Sol is a nice quiet stable main-sequence star. Main sequence refers to the period of a dwarf star’s life when it’s fusing hydrogen into helium. As a main-sequence star ages, a cascade of reactions and explosions creates heavier elements, with some of the raw materials flung away into space at every step. The debris from this unbroken sequence creates a forensic record that reliably links a main sequence star’s color and composition to its temperature and age.

Earth has yet to be consumed. (Photo: NASA)

Stars born in the same place at the same time should be, in the authors’ words, “chemically identical.” If the stars in a pair are of different kinds, that can tell us a binary pair came about as a capture. Trace differences in stellar composition can even tell us what a star has eaten recently.  Twin studies are important to science, and twin stars are no exception: Twins are also why the authors of this new study are able to so confidently assert these odds of planetary snackage. Based on how often they observed the presence of certain heavy elements in just one of the twins in a binary pair, the researchers estimated that up to one in three stars will eat “at least one” of their rocky planets.

“If a star is anomalously rich in iron but not in other elements such as carbon and oxygen, this can be interpreted as a signature of planetary engulfment,” explained lead study author Lorenzo Spina, an astrophysicist at the Astronomical Observatory of Padua. Furthermore, sun-like stars burn off their lithium pretty fast, but there’s lithium in the crust of planets – so lithium in an older star’s spectral signature is another tipoff that it may have consumed a planet. So too for metals, and silica from rock.

This all confirms our expectation of Sol eventually expanding to consume everything from Earth inward, right before it explodes into a planetary nebula. It could also help point us toward earthlike worlds outside our own star system.

It also means that there’s a timeline where one of the twin suns of Tatooine ate the planet long before Anakin could start whining about sand. And the only way anyone would know there ever was any sand is by staring straight at the system and noticing the barest glow of silica in the light of one slightly mismatched star. Just like Anakin would have wanted.

Now Read:



Report: Future iPhones Will Let You Contact Emergency Services Via Satellite

(Photo: Nate Isaac/Unsplash)
(Photo: Nate Isaac/Unsplash)
Apple is introducing a way to stay connected to first responders in emergency situations by way of satellite. According to a source who spoke to Bloomberg about the development, the company is focusing on creating two safety features that will allow iPhone users to send emergency texts and report crises in areas without cellular service. Those close to the project say the hardware necessary for satellite connectivity could be included in the iPhone 13 releasing this fall—but that doesn’t mean users in spotty service areas can rest easy just yet. The features themselves, which could always be deprioritized or done away with prior to release, are more likely to become available in or after 2022.  

The report suggested a Qualcomm X60 baseband chip will allow the phone to connect to low earth orbit satellites, similar to how SpaceX is beginning to provide widespread satellite internet through Starlink. Although the Qualcomm X60 is a 5nm 5G baseband chip with mmWave-sub6 aggregation, Bloomberg tech guru Mark Gurman’s source confirmed a custom version of the X60 could also support Apple’s satellite connectivity efforts. Analyst Ming-Chi Kuo has said Globalstar is the satellite provider “most likely to cooperate with Apple in terms of technology and service coverage.” Unlike earlier rumors had indicated, however, the phone’s satellite connectivity will be reserved for crisis communications only.

One of the rumored safety features will allow users to report extreme emergencies (such as plane crashes, fires, or sinking ships, according to Bloomberg) via satellite network when traditional cell service isn’t an option. This one will request specific information, like whether search-and-rescue services were required, weapons were involved, or someone had been severely injured. The other, Emergency Message via Satellite, will allow iPhone users to connect to a satellite network, then text contacts and emergency services. Text messages will be limited in length and will push through the do-not-disturb mode on the recipient’s phone. When the message is sent to emergency services, it could also tell first responders the iPhone user’s location and Health app Medical ID, which contains the user’s demographic information, medical history, and medication (if the user has provided that information). 

(Photo: Arnel Hasanovic/Unsplash)

As a former 911 operator for both urban and mountainous regions, I find these features particularly exciting, especially as I recall emergency calls from hikers with spotty cell service. Text-to-911 services have been around since about 2014, but those, too, have always relied on users’ proximity to cell towers. Bloomberg reports that the satellite features will push messages to users asking them to be outside and to walk in specific directions toward a satellite to properly connect, which brings me down to Earth a little, as this isn’t always practical—people who have been kidnapped or who find themselves in the middle of the ocean don’t really have that type of agency.

But the above is better than nothing, and Apple’s preparedness for connection issues (i.e. knowing people may need help finding a satellite network) brings me a bit of relief. I’m looking forward to seeing how first responders harness these future features to react more efficiently and get people the help they need.

Now Read:



All AMD CPUs Found Harboring Meltdown-Like Security Flaw

When news began to break three and a half years ago regarding a pair of new security flaws, Meltdown and Spectre, it quickly became apparent that plenty of eyeballs were laser-focused on Intel’s security implementations. There was nothing wrong with this, as such — CPU security deserves to be scrutinized — but in many cases, far more attention was being given to Intel over AMD.

The question of whether AMD CPUs were more secure than Intel CPUs was widely debated in the enthusiast community, but to no clear conclusion. While far more vulnerabilities were found in Intel chips, the researchers investigating these flaws often acknowledged that they either did not have access to AMD hardware to test or that the limited tests they had run on AMD kit using techniques known to disrupt Intel processors had not worked.

We know there are differences in how AMD and Intel implement speculative execution, so it was never clear how much of AMD’s apparent immunity was due to hardware design and how much was provided by “security through obscurity.” AMD, to its credit, never told the press that its CPUs were immune to attacks like Spectre and Meltdown, and it didn’t launch any major advertising campaigns around the idea that it represented the “safe” x86 choice. Good thing, too. Researchers have now found a Meltdown-equivalent attack that affects AMD processors.

This exploit targets the fact that non-canonical loads and stores only use the lower 48 address bits, not the full range.

The research paper acknowledges that the attack against AMD CPUs is not executed in precisely the same manner as Intel CPUs, but the end result is the same. Meltdown is a vulnerability that abuses speculative execution to leak kernel data to applications that shouldn’t have access to it. The authors write: “This class targets architecturally illegal data flow from microarchitectural elements s (e.g., L1 Cache, Store/Load-Buffer, Special Register Buffer). Such an illegal data flow allows an attacker to exploit transient execution to expose data and change the microarchitectural state.”

According to the authors’ security analysis, AMD’s Meltdown variant “does not lead to cross-address space leaks, but it provides a reliable way to force an illegal data flow between microarchitectural elements.” The team believes this is the first demonstration of this type of flaw in an AMD chip. AMD describes the issue as “AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits.” The full 64-bits of an address are not evaluated when performing speculative execution, and this can be exploited to leak data out of the CPU. AMD also states: “Potential vulnerabilities can be addressed by inserting an LFENCE or using existing speculation mitigation techniques as described in [2].” [2] refers to AMD’s most recent guide on how to manage speculative execution safely in AMD processors.

It is not clear how relevant these ongoing Meltdown and Spectre issues are to the consumer market. Intel CPUs that are vulnerable to MDS are vulnerable to this attack as well, and AMD’s Zen, Zen+, Zen 2, and Zen 3 are all affected. But in the more than three years since Spectre and Meltdown were disclosed, only one Spectre exploit is known to exist in the wild, and none targeting Meltdown. Meanwhile, companies continue to grapple with an epidemic of ransomware that clearly isn’t springing from speculative execution flaws.

Perhaps more to the point: Nobody seems much closer to fielding an actual replacement for speculative execution. The Morpheus chip we wrote about earlier this year is very interesting, but it’s also nowhere near to being a commercialized, shipping product for a number of reasons, not least of which is its speed. The performance benefit of executing some instructions before the CPU knows if it will need the results is one of the most fundamental building blocks of modern CPU cores. There’s a reason why every high-performance core from every company, x86 or not, uses speculative execution. They may use it differently with a different level of exposure to a specific type of exploit, but the attack surface here is enormous. Locking out all possibility of attack without killing performance has proven very challenging.

We’ve raised this point regarding Meltdown and Spectre-style attacks in previous articles about Intel and we’re raising it here as well. This is not meant to diminish the importance of hardware-based security, but after 3.5 years of disclosures, there’s very little evidence to suggest this is currently a meaningful problem.

Now Read:



Synthetic Bacteria Can Produce Muscle Fibers Stronger Than Kevlar

(Photo: University of Washington)
Try as we might, the most advanced synthetic materials pale in comparison to super-strong biological compounds like spider silk and muscle fibers. On that second count, researchers may be closer to growing usable amounts of muscle fiber that can be used in place of fabrics like cotton, silk, and even Kevlar. This could lead to clothing made from real muscle. That might sound like an unsettling option, but the fibers aren’t what you’re imagining. 

Animal muscles are jam-packed with proteins, which is why eating muscle provides so much dietary protein. The most common muscle proteins are myosin and actin, both of which are essential to the motor functionality of muscles. Right behind myosin and actin is titin, the largest protein known in nature. There’s a little over a pound of it in your body right now. Titin is essentially a molecular spring that gives muscles passive elasticity. It’s that property that made it the focus of new research from Washington University. 

To make large amounts of titin, the team turned to engineered bacteria. By introducing the genes for titin into the genome of E. coli bacteria, it’s possible to hijack the cell’s molecular machinery to produce what you want. The same recombinant DNA techniques can also produce useful molecules like insulin, but insulin is tiny compared with titin. The team had to get creative to make titin production possible in bacteria. In nature, titin would only appear in eukaryotic (animal) cells. 

A cluster of E. coli bacteria, magnified 10,000 times. (Photo: USDA/Wikimedia)

The engineered bacteria are able to produce small segments of titin with their molecular machinery. Next, the cells link those segments together into long titin polymers, resulting in fibers about 50 times larger than the average bacterial protein. The team used a “wet spinning” process to collect the titin fibers, which are about 10 micrometers in diameter — thinner than a human hair but much stronger. 

Because the titin fibers harvested from this process are even stronger than Kevlar, the team has speculated they could be used for protective clothing. There could also be medical applications like biocompatible sutures made from titin. They might also find use in soft robotics, taking over from less durable synthetic materials. The researchers believe this same polymerization strategy could be used to produce other large molecules in engineered bacteria, too.

Now read: