Bonum Certa Men Certa

Windows Vista Service Pack '11' Will Have “Virtualization Based Security” Theater That Slows Down Games Almost 30% and Enables Security Vulnerabilities on Intel Tiger Lake CPUs (Probably Others Too)

Guest post by Ryan, reprinted with permission from the original

Windows 11 will have “virtualization based security” theater that slows down games almost 30% and enables security vulnerabilities on Intel Tiger Lake CPUs (probably others).



According to PC Gamer, “Microsoft ‘will be enabling VBS on most new PCs over this next year’ and that can tank PC gaming performance by around 25%.”.



"Nothing Microsoft has ever done has slowed them down for long, and I suspect your svchost will still be svchosting malware in short order."Where VBS is “Virtualization Based Security”. (Not to be confused with Visual Basic Scripting, which was their scripting language, and what the Melissa and I Love You viruses, along with countless others were written in.)



The interesting facts about VBS (the “security” thing, not the virus scripting language) is that it is designed to wall off “critical parts” of the Windows OS so that it’s harder for malware to inject malicious code into them. But I wouldn’t count out those industrious malware authors. Nothing Microsoft has ever done has slowed them down for long, and I suspect your svchost will still be svchosting malware in short order.



What it does do is cripple performance, at least gaming. Could be one reason why my games run so much better in Wine on Debian 11.



I had turned “VBS” on when I had Windows because it’s in Windows 10, and it didn’t mention anything about performance problems.



To get it to even turn on at all required uninstalling a useless incompatible driver meant for Windows 8 that Windows 10 had brought in from the manufacturer of my old WD EasyStore drive.



"So to enable VBS “security”, you have to make your system impossible to secure against a speculative execution attack, and then in exchange for this, you get to slow your video games down 28%. Wow, sign me up!"So it appears that pretty much all an attacker needs to do in order to shut it off is manage to get a driver that’s written for an earlier version of Windows installed somehow, which shouldn’t be difficult, and then at least in Windows 10 it’s gone and you don’t get an alert(?).



Also, buried in the details are that since this thing relies on Microsoft HyperV, it will stop other virtualization software from running correctly.



And if you look in the Event Viewer (sorry, I didn’t take a picture, I should have), you’ll see that Windows lists CVE numbers belonging to Spectre attacks that it isn’t mitigating because they want the “Hypervisor” to perform well and don’t want to get in the way of Intel’s Hyperthreading, which is being used to speed up HyperV, which is running VBS.



So to enable VBS “security”, you have to make your system impossible to secure against a speculative execution attack, and then in exchange for this, you get to slow your video games down 28%. Wow, sign me up!



“While we are not requiring VBS when upgrading to Windows 11,” explains the post, “we believe the security benefits it offers are so important that we wanted the minimum system requirements to ensure that every PC running Windows 11 can meet the same security the DoD relies on. 

Microsoft


It’s amazing what money can buy. Microsoft bought a Pentagon. Former President Trump was about to hand them “JEDI” to put in their Azure Clown, which has caused so many security disasters for other organizations that we don’t have all day for me to list them.



"Microsoft bribes and “lobbying” got the government to ditch them and weaken them so that Windows could get government contracts."In the 1980s and 1990s, there were these security standards that the US government still used called the Rainbow Books, which pretty much only a UNIX system could provide. Microsoft bribes and “lobbying” got the government to ditch them and weaken them so that Windows could get government contracts.



Then in exchange for bringing Windows in, we got the “smart ship” stuck at port due to a Windows NT crash, worm mess on Windows 2000 and XP (which didn’t even enable the software firewall in the first release and logged everyone in as Administrator or apps broke, and had raw sockets for normal users), Vista LULZ (and their current operating systems are still basically Vista service packs), and everything else that Windows has brought with it but to name a few.



It’s time to bring real standards back to computing.



Microsoft is better at public corruption than they are with security, as you can no doubt see.

Recent Techrights' Posts

Windows Falls Below 20% in the UK
Many people choose to leave Windows altogether
Microsoft's Search Business Falls to Lowest Point in 2 Years, Based on statCounter
what can Microsoft sell other than shares in Microsoft?
Evidence Regarding Layoffs at Red Hat
Seems like IBM layoffs
Microsoft: Our "Goodwill" Value Grew More Than Tenfold Since 2011
Hallmark of pseudo-economics
GNU/Linux as a Boarding Pass
being mostly analogue is still feasible
Links 03/11/2025: Lack of Trust in LLMs and Windows TCO at Jaguar
Links for the day
Gemini Links 03/11/2025: Books in October and Change
Links for the day
Mozilla Firefox Won't Survive and Many Sites Don't Work With It (Compatibility Abandoned)
The Web has become monocultural
Debian is Non-Free
Devuan might be worth looking into
Slopwatch: Brian Fagioli and LinuxSecurity
This is a real problem and most certainly a big problem because when people try to find real information about security and GNU/Linux they instead read "word salads" made by bots
Four Reasons to Party With Us in Four Days, Celebrating the Four Freedoms
Today we expect to be back to a more-or-less regular publication pace
Links 03/11/2025: The "Smartphone Panopticon" and Belarus' Hybrid Attacks on EU Intensify
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, November 02, 2025
IRC logs for Sunday, November 02, 2025
Microsoft's Debt Has Skyrocketed by More Than 15 Billion Dollars in 6 Months or 8.2 Billion Dollars in the Past 3 Months Alone
The corporate media intentionally disregards - or merely turns a blind eye to - such data
Rumour: IBM Layoffs in Canada Starting Tomorrow
"RA (IBM's term for layoffs) Coming to Canada this week (Nov 3rd)"
Debunking False/Misleading Statements Made or Told to the High Court
People who try to cheat the system by gaslighting judges will end up discrediting themselves
Fear, Uncertainty, Doubt (FUD) by LLM Slop
The Web has become such a sordid mess that this FUD made by bots is what Google News deems to be "the news"
This Month's Analytics Show Vista 11 Down, GNU/Linux Up
After pulling the plug on Vista 10 we see losses - not gains - for Vista 11
Almost Fully Caught Up
The EPO series will continue very soon, maybe tomorrow or on Tuesday
Links 02/11/2025: Another Halloween Bust and MAGA Regime Says Public Universities Should No Longer Hire 'Foreign' Employees
Links for the day
The Long-Coveted Milestone of 3,200 Active Gemini Capsules
Despite being away some days last week, about 50,000 Gemini requests were served each day, on average
Five More Days Till Techrights Party
We'll have many more batches of Daily Links as we catch up with a 'backlog' of news
Links 02/11/2025: More Nuclear Escalations and "Anti-Cybercrime Laws Are Being Weaponized to Repress Journalism"
Links for the day
Gemini Links 02/11/2025: "The Pragmatic Programmer", Perl New Features and Foostats
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, November 01, 2025
IRC logs for Saturday, November 01, 2025
Linux.com is Becoming Microsoft
They took a once-reputable site with a vast audience and turned it into a pile of trash
Microsoft Lunduke: People Pointing Out I'm a Bigot is a Badge of Honour
It's almost as if he openly admits being a troll and is proud of it
Oracle's Debt Continues Rising to All-Time Highs, The "Slop Bubble" is a Smokescreen for Larry Ellison
wishful-thinking bubble waiting to implode completely
News on the Web is Becoming Rare, Shallow, and Difficult to Find
To efficiently and rapidly find original and important news without underlying comprehension/understanding of the news (and its context) is a hard task
Slopwatch: Linux Journal, Serial Slopper, WebProNews, and More
getting back into the habit
The Cocaine Patent Office - Part III: European Patent Office Officials Cannot Claim False Identification
Corroborating with other sources is always desirable if possible. We shall do so later in this series.
Facebook's Debt Leaps to Over 51 Billion Dollars
A lot of this is a bubble, aside from the bubble the media irresponsibly dubs "AI"
Still Catching Up, Daily Links a Top Priority
Readers who have additional information about the EPO can send it along to us
3 Days Ago Over at Tux Machines...
GNU/Linux news
Links 01/11/2025: "Americans Are Defaulting on Car Loans at an Alarming Rate" While Many Left to Starve (SNAP)
Links for the day
Gemini Links 01/11/2025: FIFO and Gemini Age Survey
Links for the day
Why Does German Media Protect the EPO From Accountability for Cocaine?
Can we trust such media to properly inform the public?
Most of This Month Will Deal With EPO Scandals
A timeline of sorts
Links 01/11/2025: Microsoft Azure Goes Offline Again
Links for the day
Links 01/11/2025: Microsoft Distributes Malware Again, Radio Free Asia Shut Down by Dictator
Links for the day
November is Here, Anniversary Party This Coming Friday
Expect this site to return to its normal publication pace either by tomorrow or Monday
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, October 31, 2025
IRC logs for Friday, October 31, 2025
Gemini Links 01/11/2025: Synergetic Disinformation and Software Maintenance
Links for the day
IRC Proceedings: Thursday, October 30, 2025
IRC logs for Thursday, October 30, 2025
IRC Proceedings: Wednesday, October 29, 2025
IRC logs for Wednesday, October 29, 2025