← Back to Gists

Review of article

📝 Markdown Rendered
retoor
retoor · Level 1860 ·

Review of article by rok, I am a fan of battle penguin articles but they contain so much knowledge that I don't have, so I let rok fact check it by making a rating framework upfront. It was about this article: https://battlepenguin.com/tech/the-systematic-removal-of-security-in-consumer-operating-systems/

Sorry for my typos, some are real, but some of my keys are broken. I normally fix this issue using my wm, but I downgraded my wm accidentally and now I miss some 😛 And my AI correction doesn't work here.

Rating Framework (designed upfront)

I use a structured, multi-axis framework for every major claim/statement and the article overall:

  1. Factual Accuracy: True / Mostly True / Partially True / Misleading / False / Unverifiable
  2. Evidence Quality: Strong (multiple independent reputable sources, primary docs, confirmation) / Moderate / Weak / Speculative / None
  3. Context & Completeness: Full context provided? Important caveats, timelines, counter-evidence, or benign explanations omitted?
  4. Interpretation / Bias: Neutral reporting / Mild interpretive lean / Strong conspiracy framing / Overstatement
  5. Claim Score (1-10):
    • 9-10: Fully accurate, well-sourced, properly contextualized
    • 7-8: Largely accurate with minor issues or missing nuance
    • 5-6: Mixed/partially true; significant omissions or overreach
    • 3-4: Mostly misleading or weakly supported
    • 1-2: False or pure speculation presented as fact

For the full article I also score: Overall Factual Accuracy, Source Use & Citation Quality, Logical Coherence of the Narrative, Strength of the Conspiracy/Intentionality Thesis, Balance/Fairness, Predictive Value, and a Total Article Score (1-10).

All fact-checks use current (as of 20 July 2026) public reporting from Ars Technica, The Register, TechCrunch, 9to5Mac, Apple Support, Slashdot, PCMag, Cybernews, Wikipedia (cross-checked), Microsoft statements, developer posts, etc.


Section-by-Section Fact-Check

Opening / Framing

  • “This year we’ve seen cracks in Windows 11 BitLocker, VeraCrypt developers losing their ability to distribute their software on Windows, and Apple removing encryption support from the HFS+ filesystem.”
    Accuracy: Mostly True. All three events occurred in 2026.
    Score: 8/10. Minor: “cracks” is mild for the BitLocker issues; Apple did not remove HFS+ itself, only encrypted HFS+.

  • Reference to historical opposition to “government mandated keys under doormats” (Abelson et al. 1997 + 2015 “Keys Under Doormats” paper).
    Accuracy: True. Classic, well-known papers.
    Score: 10/10.

  • “every big company seems like a willing participant in the coming technocracy.”
    Accuracy: Opinion/framing.
    Score: N/A (interpretive).

BitLocker / Nightmare Eclipse

  • Nightmare Eclipse found BitLocker bypasses on Windows 11 / Server 2025 (YellowKey, later GreatXML / related). Claimed it looks like an intentional backdoor.
    Accuracy: Mostly True. YellowKey (CVE-2026-45585) and subsequent disclosures are real, widely reported (Ars, Register, BleepingComputer, etc.). Researcher publicly called it backdoor-like. Independent researchers confirmed YellowKey works against default TPM-only BitLocker. GreatXML claims were more contested (some testers said it did not work as advertised without already having admin access).
    Score: 7.5/10. Core events true; “intentional backdoor” is researcher’s opinion, not proven. TPM+PIN generally mitigates the main YellowKey path (article notes the dispute correctly).

  • TPM+PIN claimed exploitable by author but no public PoC; later Defender Offline Scan related bypass.
    Accuracy: Partially True / as reported by the researcher.
    Score: 7/10.

  • Microsoft criticized non-responsible disclosure and threatened legal action / criminal investigation; researcher claimed prior reports ignored and account deleted; other researchers complained about MSRC.
    Accuracy: True. Microsoft MSRC blog condemned uncoordinated disclosure, invoked Digital Crimes Unit language that was widely read as a threat. Backlash ensued; Microsoft later clarified it would not pursue good-faith researchers. Multiple researchers (including named ones on X) have longstanding complaints about MSRC closing reports, silent patches, and bounty/credit issues.
    Score: 9/10.

VeraCrypt and WireGuard

  • VeraCrypt (and WireGuard, Windscribe, others) Microsoft publishing/signing accounts terminated/suspended in March 2026, blocking Windows driver/bootloader updates. Linked to new mandatory account verification for Windows Hardware Program. Developers said they completed verification or never received notices and were still locked out. Scott Hanselman publicly said he was working to restore access and called it “paperwork.” Accounts were restored after public pressure.
    Accuracy: True. Extensively reported (Cybernews, TechCrunch, PCMag, The Register, SourceForge posts by Mounir Idrassi, Jason Donenfeld statements, Hanselman posts). Microsoft cited the Oct 2025 verification policy. Communication failures were real; it was not a targeted anti-encryption purge, though the impact on security tools was severe and poorly handled.
    Score: 9/10. Article is accurate on facts; the “I don’t believe… paperwork” dismissal is opinion.

  • TrueCrypt history: sudden 2014 shutdown, cryptic message recommending BitLocker, instructions provided, speculation of warrant canary / NSL, author claimed forking “impossible,” yet VeraCrypt succeeded.
    Accuracy: True on the facts and the long-standing speculation. No definitive proof it was a canary; audits found no backdoors.
    Score: 8.5/10.

macOS / HFS+ Encrypted Volumes

  • Apple announced macOS 28 drops support for encrypted HFS+ (Mac OS Extended) volumes; users should migrate to APFS (Encrypted). Unencrypted HFS+ still supported. Official support article exists.
    Accuracy: True. Confirmed by Apple Support document (July 2026), 9to5Mac, Slashdot, etc. macOS 26 already starts warning. Reason is almost certainly deprecation of the old CoreStorage layer that provided HFS+ encryption (APFS has native encryption).
    Score: 9/10 on the facts.
    Interpretation score lower: The rhetorical questions (“is support being dropped because the previous filesystem had strong encryption? Is Apple trying to move users to formats that aren’t really secure, allowing for their own backdoors…?”) are pure speculation with zero evidence. APFS encryption is the modern, recommended, and generally stronger/more feature-rich path.
    Claim Score for the suspicious framing: 3/10.

AMD Hardware

  • AMD removed Transparent Secure Memory Encryption (TSME / Memory Guard) support from consumer (non-PRO) processors via firmware/AGESA updates; public outcry; AMD reinstated it.
    Accuracy: True. Discovered ~April 2026, widely reported (Ars Technica), AMD confirmed removal on non-PRO Ryzen 9000 and promised reinstatement in July BIOS updates after backlash.
    Score: 9.5/10.

Broader Context Claims

  • Windows 11 aggressively pushes Microsoft account / internet during setup; local accounts require obscure terminal commands / workarounds.
    Accuracy: True and longstanding. Multiple bypass methods (Shift+F10 + commands like start ms-cxh:localonly, Rufus, etc.) are still needed/documented in 2026.
    Score: 9/10.

  • Discord requiring government ID for some users; ties to Palantir/Thiel via Persona (age verification).
    Accuracy: Mostly True. Discord rolled out/expanded age verification (facial estimation + ID options) in 2026, partnered with Persona (Founders Fund / Thiel-linked, Palantir associations raised alarms), faced major backlash, ended the Persona partnership, and adjusted the rollout.
    Score: 8/10.

  • Governments pushing mandatory ID verification for web services and OS use “under the lie of protecting children” (Brazil OS age verification with short deadlines, US proposals, etc.).
    Accuracy: Partially True / directionally correct. Brazil’s Digital ECA (Law 15.211/2025) imposes significant age-assurance obligations on OSes, app stores, and high-risk services, with phased enforcement in 2026-2027 and high fines. California and other US states have OS-level age laws/proposals; federal ideas exist. Framing as pure “lie… designed to uniquely identify and track… everyone” is strong interpretive overreach-child safety is a real (if often overstated/poorly designed) policy driver, even if privacy risks and mission creep are legitimate concerns.
    Score: 6/10.

Conclusions Section

  • Individual stories could have benign explanations (LLM-era security tightening, dropping unmaintained code, paperwork).
    Accuracy: Fair acknowledgment.
    Score: 8/10.

  • Clustering “back-to-back within weeks” + Microsoft account forcing + ID laws + Discord = intentional erosion of real encryption/security/privacy in favor of broken big-tech tools; not incompetence but malice; will accelerate with more backdoors for mass data collection.
    Accuracy: Speculative synthesis. The events are real and the timeline is compressed in 2026, which understandably raises eyebrows. However:

    • VeraCrypt/WireGuard was (badly executed) bureaucracy, quickly reversed under pressure.
    • AMD was reversed under pressure.
    • Apple HFS+ encrypted drop is classic deprecation of old stack.
    • BitLocker issues are serious vulnerabilities (and disclosure drama), not proven intentional backdoors.
    • Broader surveillance/ID trends are real and concerning, but “concerted effort to remove all real encryption” and “this seems intentional” go well beyond the evidence into conspiracy territory. Hanlon’s razor (or corporate incompetence/bureaucracy + genuine security hardening + regulatory pressure) still fits better than coordinated malice across MS/Apple/AMD.
      Score: 4/10 for the strong intentionality/conspiracy conclusion.

Article-Level Assessment

Criterion Score Notes
Overall Factual Accuracy of Events 8.5/10 Core incidents (BitLocker bypasses + drama, VeraCrypt/WireGuard lockouts + Hanselman, Apple HFS+ encrypted drop, AMD TSME removal/reinstatement, TrueCrypt history, Windows account forcing, Discord age-ID issues, Brazil/US age laws) are real and correctly dated.
Source Use & Citation Quality 8/10 Good primary/secondary links (Slashdot, 9to5Mac, Apple Support, Ars, developer posts, Hanselman X, etc.). Some secondary or researcher blogs.
Context & Nuance 5.5/10 Frequently omits or downplays benign explanations, reversals under pressure, technical reasons (CoreStorage deprecation, verification policy failures), and independent confirmation status of some exploits.
Logical Coherence 6/10 Events real dots, but the leap to “systematic intentional removal… concerted effort… not incompetency mistaken for malice” is the weakest link.
Bias / Framing 4/10 Strong privacy-absolutist / anti-big-tech / surveillance-state lens. Presents researcher opinions and speculative questions as near-facts. Acknowledges possible benign explanations then largely discards them.
Strength of Central Thesis 3.5/10 Pattern of friction around strong user-controlled encryption and identity is real and worth watching. “Systematic removal… intentional… technocracy” is overstated.
Predictive Value 5/10 More stories about encryption friction, ID mandates, and vendor lock-in are likely. Claiming acceleration of intentional backdoors is unproven.
Balance / Fairness 4.5/10 Low. Little steelmanning of vendor positions beyond a brief nod.

Total Article Score: 6.2 / 10

Summary Judgment
The article is a competent roundup of several real, concerning 2026 events that legitimately worry privacy- and security-conscious people. The individual factual building blocks are mostly solid (high 7-9s). The historical references are accurate. Where it falls down is in synthesis and interpretation: it repeatedly prefers the most sinister reading, underweights reversals and bureaucratic explanations, and elevates a cluster of (sometimes quickly reversed) problems into evidence of a deliberate industry-wide campaign to eliminate real encryption. That central claim is weakly supported and tips into conspiracy-adjacent territory.

It is useful as an alert/signal piece (“these things happened; pay attention”) but should not be treated as rigorous proof of coordinated malice. Readers should verify the primary sources (many of which the article itself links) and apply extra skepticism to the “this seems intentional” conclusion.

Strongest parts: VeraCrypt/WireGuard timeline + Hanselman quotes, AMD reversal, Apple announcement, BitLocker disclosure drama.
Weakest parts: Apple “backdoor” implication, overall intentionality thesis, Discord/government ID framing as pure tracking conspiracy.

Comments

No comments yet. Start the discussion.