Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Many of you who are users of Windows 10
are likely in panic since Windows 10 is
about to be classified as end of life by
Microsoft. End of life is today, October
14th, 2025,
a day that will live in tech infamy.
Currently, still 40% of Windows users
are still on Windows 10.
Likely the main reason you have not
updated to Windows 11 is because you
cannot. Your old computer is considered
junk now because it doesn't have this
thing called a TPM chip. You're being
pushed to get a C-pilot PC, one that is
equipped to handle the AI companion,
even though likely you have not come up
with a reason to want to use some spying
AI in your daily computer life. So, you
don't want this. But it's worse. So,
Microsoft has basically been
systematically
exerting dominance over its users to the
point that you question now if your
machine is yours or if it is Microsoft
and you're just paying for it. Just to
put some balance in this video, let me
show you that I have a long career as a
Windows developer and I've had Bill
Gates demonstrate my software at a
keynote speech and I'm a Windows expert.
And for many years, even as a privacy
guru, I had a tolerant approach to
Windows since there were many ways I
could configure it to avoid privacy
dangers. But in recent years, with the
advent of Windows 11, I have to say that
Microsoft has truly gone crazy. And the
current direction of Windows 11 tells me
that it is time for all of you to go.
You are not a Microsoft slave. You own
your device. Take your freedom back.
dump Windows otherwise it will own you.
Microsoft has plans for you and you will
not like those plans. What I'm going to
discuss here are the specific reasons
that I have to part ways with Windows
and hopefully software developers make
good versions of their products in
Linux. So we have little reason to use
this Windows 11 garbage and you will
discover that it is garbage. Yes, this
is a rant. So, if you want to learn the
specifics, stay right there.
Windows 10 end of life. While it is
definitely the right of a software
company to classify their old software
as end of life, especially after 10
years of release, one needs to ask why
there's so much resistance. I've never
encountered so much resistance to moving
to a newer version. likely since DOSs
3.1 to Windows and that was justifiable.
Windows required new hardware since DOS
3.1 was textbased and Windows was
graphical and tons of software had to
change to go to Windows which took time.
But in theory, most apps that work in
Windows 10 will still work in Windows
11. Yet there's so much resistance and
much of it likely is because the users
cannot upgrade to Windows 11. Microsoft
itself is blocking them. In order for
many users to move to Windows 11, they
have to buy newer computers. And the
justification for this on the Microsoft
side is twofold. First is the push for
this security chip called a TPM chip
which is lacking on old computers and
which I will tell you now is a huge risk
to privacy. And the second justification
for Microsoft is to encourage more
people to use Windows C-Pilot, which
creates AI capable computers. Again, a
massive risk to privacy. But there's
more. New computers using Windows 11 now
turn on Bit Locker, which is disk
encryption by default. You might think
this is a good thing, but not really.
Windows has been forcing us to use cloud
services constantly with features like
one drive to ensure that you keep your
files on Microsoft servers. And now
they're pushing the new Windows backup.
There's the push for Office 365 again to
ensure that Microsoft keeps your
documents.
Or how about the Microsoft ID and the
constant battle to ensure that you have
a computer free from a privacy invading
identifier? or how Microsoft keeps
forcing updates that you cannot turn
off. I'm going to cover all these
approaches by Microsoft and explain to
you why you don't want them.
Microsoft ID.
I'm sure this irks a lot of people
lately. It is extremely difficult to
install Windows without a Microsoft ID.
Basically, Microsoft wants you to log
into them just like Apple and Google
requires you to to ensure that device is
tied to an identity. There's still a way
to avoid the Microsoft ID, but it is not
obvious and requires so much trial and
error to figure out. But basically, most
people will be forced to put an ID card
on your computer. So, whatever you do on
the internet can be attributed to your
particular machine. When Microsoft began
pushing this heavily in later updates of
Windows 10 and now locked in in Windows
11 for the most part, it was the first
sign of a red flag. Microsoft became big
all of a sudden again as a company once
they moved their infrastructure to a
cloud-based one. This has guaranteed the
income stream to Microsoft and raised
their position as the number two company
in valuation at $3.9 trillion. This
growth in the cloud is Satiana Dela's
claim to fame. So the idea of the
Microsoft ID is to tie you to the cloud.
One drive means you store your data to
the cloud. Lately they're pushing
Windows backup. And of course with
Office 365, Xbox, and now with Copilot,
your life will truly reside in Microsoft
servers. This of course is the original
Google formulas, so they're keen to
dominate that now. And as proof,
Microsoft has surpassed even Google in
valuation. As a privacy expert, one of
the main goals I have is to ensure that
devices have anonymity. And you cannot
do that if your device is currently
logged into Microsoft where app and
device telemetry ensures that they know
everything you're doing on your machine.
And the Microsoft ID is a big and
primary part of this. Since they don't
want you to have an anonymous device,
then this is definitely a nogo for me.
It's my machine. I paid for it.
Microsoft didn't pay for it. So, as I
will explain in many details here,
Microsoft is definitely not interested
in respecting your rights to have other
things on your computer, even in
separate partitions. I have had multiple
instances of Windows wiping out entire
Linux partitions and even a data only
partition just because it didn't
recognize the format. This is extremely
aggravating. I have lost so much data
from unexpected events like doing a
Windows update and having it wipe the
dual boot files and then continuing on
to overwriting partition data to wipe
Linux completely. As an advanced user,
even if I had no gripes with Microsoft,
there are many reasons for me to have
multiple operating systems on my
machine. This is not that uncommon with
software developers. Yet, they force
updates on you and you can't stop it and
then they act like they're the only
users of the machine. Now, over time,
I've come up with workarounds to the
stupidity of Windows and Windows
policies, and I'll discuss that in an
upcoming dual boot video. But generally,
this lack of certainty to what Windows
will do is a dangerous roll of the dice
for people who make a living off
computers.
TPM is for you or for them. One of the
biggest changes that Microsoft made is
to not allow updates to Windows 11 from
Windows 10. If your computer doesn't
have the security chip called ATPM,
which is an acronym for trusted platform
module, you don't need to worry about
what it means. It's a security chip and
it has similar functions to the Titan M2
chip on Pixels or the Apple secure
enclave on iPhones. The basic
functionality of the TPM, as with all
other security chips, is that
cryptographic keys used for encryption
are not kept in the open in accessible
memory or hard drive where third parties
can potentially have access to them.
Instead, the keys are stored inside the
TPM with inaccessible private keys.
There's no way to see the private keys.
You present a public key to the TPM chip
and it can validate it via the chip by
checking the private key internally.
This allows things like dis encryption
to be done without creating some
loophole for some hacker to capture an
encryption key because its processes are
locked inside a separate chip. There's
theoretically no outside access to it.
Sounds good in theory, right? Now, let
me tell you the multiple problems with
this TPM module. As it turns out,
Microsoft actually stores your Microsoft
ID together with the device ID
identifiers in the cloud tied to your
Microsoft account. This will become
important when we talk about Bit Locker,
which I'll discuss next. But the main
issue here is that the TPM module is a
device identifier. In fact, on most
operating systems, whether it is Apple,
Google or Microsoft, the security chip
actually announces a unique device
identifier. Since each security chip is
flashed with a unique value for each
device, it is like an IMEI on a phone.
It gives out a unique ID. The problem is
that some specific Microsoft products
and services validate you based on this
unique ID. And because it is now
connected to the cloud, added to your
upcoming extreme relationship with the
Windows Copilot AI Companion, this is
now going to be extra dangerous. What
would have been a better option is to be
able to insert your own security chip in
your computer, similar to a UB key,
where you can plug it or remove it at
will, depending on what you're doing.
Then at least you're given a choice.
Now, there's no choice. Windows 11
requires a TPM and Windows 11 will track
your Microsoft ID together with your
device ID based on the TPM. New software
utilizes this. Now, gamers are suddenly
discovering that their device ID are
known to Microsoft and didn't know how.
Yes, of course, there's the Xbox ID for
Xbox gamers, but now the device ID is
specifically known and is pulled from
the TPM.
Third parties can access this now with
no restriction via API. If you want to
know how to check your TPM status, here
are example commands on Windows. By the
way, you can restrict access to the TPM
in Linux, and I'll make a separate TPM
video in the future to manage all this.
There's a deliberate purpose to all this
madness, and it's all tied to the AI.
So, don't think this is some random
choice by Microsoft, but I'll get to
that. In the meantime, let's go to the
next level, which is Bit Locker.
Bit Locker.
Bit Locker is new. If you buy a new
Windows computer, you will have this
shock when you try to install Linux on
it or if you try to turn off secure
boot. Bit Locker is a new Microsoft
drive encryption. It is a Microsoftonly
product. It is tied to the full hard
drive. So you cannot for example have a
Linux partition freely. It will also be
subject to Bit Locker. Yes, I'll discuss
secure boot later as well. I just got
myself a new laptop. It's a brand new
Lenovo ThinkPad X1 Carbon. And as usual,
as the first step to installing Linux, I
would typically go to BIOS and turn off
secure boot. Was I in for a shock?
First, Windows 11 Bit Locker was enabled
by default. So the moment I turn off
secure boot without warning the drive
locked up and I basically had no access
to the SSD drive. The lock up is at the
BIOS level. So basically it will refuse
to boot the hard drive. Now I can of
course reformat the hard drive some
other way or insert a different SSD
drive. But unlike older versions of
Windows on my particular computer there
is no longer a recovery partition. So
you can't just boot to recovery. I had
to find a custom boot image from Lenovo
and flash it to a USB. I spent an entire
day making a boot partition, copying all
my data, and I lost it all and had to
start from scratch. Now, here's the
kicker. When you lose access because of
Bit Locker, it revealed some interesting
things. Apparently, when you log in
using your Microsoft ID, the recovery
key for your hard drive as stored in the
TPM and the device ID are all now stored
at Microsoft and tied to your Microsoft
ID. So basically, while you think your
Bit Locker is tied to just your TPM
chip, in reality, it is tied to
Microsoft since someone with access to
your Microsoft ID can basically recover
your Bit Locker encrypted drive recovery
key. In my case, and maybe because I
turned off my Microsoft ID, I actually
could not unlock my Bit Locker lock
drive. I had to start from scratch.
However, this exposes how this supposed
security protection is fundamentally
tied to Microsoft control. The thing
that angers me the most is that this is
a drive where I, as the owner, decided
to make a separate partition for another
operating system. And yet Microsoft
decides that it will override that and
take control of the entire drive. Linux
of course does not have rights to Bit
Locker. It is not some open-source
software. So Microsoft here decided that
it owned your computer, not you.
Secure boot.
Secure boot is a BIOS setting and if
enabled anytime you boot an operating
system like Windows or a DRO like
Ubuntu, the UP boot software will check
the signing key of the product and see
if it is an approved OS, meaning it is
signed using Microsoft keys. That alone
is problematic, but we'll ignore that
for now. In some ways, secure boot was a
waste of time because for the average
person, it did not offer any kind of
security. at least until Bit Locker and
TPM happened. All you had to do was turn
secure boot off. There's no security
whatsoever required in turning off
secure boot in BIOS. You could do this
to any computer, but this was only an
inconvenience as it potentially delayed
a hacker by maybe only 2 minutes.
However, what I didn't realize is that
since DROs like Ubuntu are actually
signed using Microsoft keys that they
don't need secure boot to be turned off.
It does bother me that Microsoft inserts
themselves into security features of the
bootloader, but at least popular distros
are exempt. Special distros will require
secure boot to be turned off though. But
the worst part about secure boot is that
it totally messes up using virtual
machines. If you're going to use any
virtual machine like KVM or virtual box,
it's actually going to use the same
bootloader programs with secure boot and
it will cause the VM to fail. So you
have to run a bunch of command line
instructions to sign the virtual machine
software itself again using the same
Microsoft keys.
I mean it's really hard to get Microsoft
away from anything. The tendrils of
control are just everywhere.
And again to remind you of what I just
said, secure boot is now tied to Bit
Locker. If you turn off secure boot, Bit
Locker will lock up and there's no
direct recovery by turning secure boot
back on. And in case you're wondering,
yes, secure boot is another Microsoft
invention.
Force updates.
just to make sure that they have full
control over your machine. Microsoft of
course forces updates on you. All these
are under the guise of cyber security of
course and I'm sure all these cyber
security experts will all chime in and
say that I need all this. Yeah, right.
Why not let me decide that? You don't
know what I want or need. And in any
case, I have limited use of Windows.
Extremely limited. Like 1% usage. So, I
don't want an OS I use 1% of the time to
dictate my use of the computer 100% of
the time. You want to hack my Windows
installation? Go ahead. I have nothing
on it. It just bugs me that someone else
decides what I need and choices are kept
from me. And these force updates have
caused me massive problems. One of the
well-known incidents was when Microsoft
overwrote the boot instructions, which
in my case is set up to be dual boot. I
can choose to boot Linux or Windows. I'm
primarily a Linux user. Then it
completely overrides the boot
instruction. So now I can't boot to
Linux. So usually I have to always put a
delay on Windows updates, which you can
only delay up to two weeks. This gives
me an allowance to prepare for a
catastrophe, but that's the limit, 2
weeks. So I have to find some time
within a twoe window to do an update. I
don't want to be in the middle of an
important project and be shut down just
because I voted to zucking Windows. For
my specific use, I rarely want a Windows
update if some specific major security
thing is announced. I would like to be
given the choice. Tell me the risk and
I'll decide. But I guess it is no longer
your computer when you run Windows 11.
Overwriting partitions.
Again, similar to the updates
overwriting the boot instructions, you
have some dangerous utilities like
Windows disk management utility. Again,
one that was designed to prevent other
operating systems from running. If you
accidentally go into disk management and
decide to view a Linux partition, which
it will not recognize, you might
accidentally overwrite the entire
partition and lose everything. And this
is something that already happened to
me. At the very least, it should
recognize a foreign partition and not
allow a write, at least without a ton of
warnings. But there's no warning. It
just overwrites and your Linux partition
with all your data is suddenly wiped out
just because you decided to have Linux
coexist with Windows because, you know,
you think it's your own computer. A
Linux partition is formatted using ext4.
You think in this day and age that
Windows with its resources could
recognize an ext4 partition, especially
since it is zucking open source, but of
course they do this intentionally.
The real objective is AI. Like I said,
there's a reason to all this madness,
and it is the control that Microsoft
wants to put on us. So, let me show you
this again in case you forgot. Well, I
mean, I guess the first thing to say is
that we are on a mission to create a
true AI companion. And to me, an AI
companion is one that can hear what you
hear um and see what you see and live
life essentially alongside you. um you
know your AI companion will be able to
remember uh everything that you've
talked about session to session
understand the content of the web pages
that you browse um and be able to talk
to you just like I'm talking to you now
so it's going to have this seamless
fluid very very smooth conversational
interaction yes the purpose of this is
to immerse yourself in the see what you
see technology for the computer to get
to know you intimately ly for the
computer to be a copy of your brain. So
the way this is intended to work, the
vast majority of you have to be running
on a Windows Copilot PC with Windows 11.
And if you have this setup, then Windows
recall starts recording all your
activity by screenshots every few
seconds. Then the AI analyzes what's
happening on screen and notates it and
stores that information on the hard
drive. in which case Windows 11 will
have a complete history of your life.
Now, of course, philosophically
speaking, putting your entire life on a
computer changes the way you use a
computer. Suddenly, you have to be super
interested in cyber security because you
need to protect your device in ways you
didn't have to do before. Makes sense.
This information used to be private in
your brain. and now it is on your
computer and now you have to lock it up
with all the security BS. Did you need
this? If you're like me where you
partition what you do in your life, you
don't need to put your entire life on
display in social media. Just like I
don't need my computer to know
everything, but they're not making it a
choice. It is a crazy decision, but it
comes with all the baggage of requiring
Bit Locker, Secure Boot, and a TPM. And
I'm sure they'll add more in the future
because without all this, someone could
hack your computer and read all your
data. Of course, no one tells you that
HQ could just ask the AI what it knows
about you and it is able to summarize
that for someone without having to do
any special decryption. This is the
stupidity of all this. This is the
purpose of all this BS. The answer, of
course, is just to say no. Thank you.
We're not given a choice. So, make the
choice and not use Windows 11 unless you
believe in this AI companion BS. People
often argue with me about issues related
to cyber security versus privacy. This
is a clear explanation of the
difference. All the cyber security
protections put in by Microsoft are here
to take away all your privacy. If you're
a follower of mine, you are at odds with
this reasoning. So, install Linux and
tell Microsoft to go zuck themselves.
Folks, thank you for watching my videos.
As many of you know, this channel does
not have sponsors and we primarily
sustain ourselves by just creating
products and services that we use to
defend our privacy posture. I'd like to
invite you to visit our community site
Braxme which has a growing community of
privacy enthusiasts. There are people
from various walks of life and beliefs
and they converge together in the mutual
support of privacy issues. We have a
store there with products ranging from
the Bra virtual phone service,
Braxmail,
BytesVPN
and other services like flashing an OS.
All these are tools used by the privacy
aware and you can even talk to the
actual users of the products directly.
Join us. We'd love to have you there and
you don't even have to identify yourself
to be part of the community. The very
successful Bra 3 phone is also available
for pre-order on a second batch. The
first batch has been sold out.
Information about that is on
bratech.net.
Thanks also to those who donate to us on
Patreon, locals, and YouTube
memberships. You are all appreciated.
See you next time.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.