They Forgot What Happened Last Time: hacking the Windows 365 Link

Talk by Rairii (he/him)

The Windows 365 Link is a thin client, running a special edition of Windows 11, that can only connect to a "Windows 365 Cloud PC" and is otherwise useless ewaste. When it was announced, Microsoft boasted its total vendor lock-in plan, which they described as "secure-by-design architecture": no admin rights, no local data, EFI Secure Boot locked on, BitLocker always enabled. The last time EFI Secure Boot was locked on was Windows RT devices, and that caused me to personally break the Windows bootloader chain of trust, several times. Challenge accepted.

If you would like to mark this as a favourite please log in.

 

Return to: