Live data from Hacker News

Microsoft built its own custom Linux kernel for its new IoT service

techcrunch.com

101–110 of 304 posts

Re: Microsoft built its own custom Linux kernel for its new IoT service

#101
post #97

Earlier quoted context omitted.

"Don't roll your own security" has been the marching drum of an entire sector of IoT companies working within the connectivity "slice of the pie." The general mindset has been that iot has a couple slices: the "thing" (air conditioner vibration sensor), how that thing is connected (Ethernet plugged directly into a smart vibration sensor, or vibration sensor plugged into a connected data-recording device), the transmi…

...and even then, you're not secure forever. So many times the best security practices have been shown to be insufficient. In fact, I wonder what the scoreboard actually would read, 'roll your own' vs 'best practice'? Maybe not all that different.

I like your idea of a scoreboard. I'm gonna float this at the office. Then again, we're not keen to talk about the fact that nobody has found a flaw in our security model because it'll just invite a ddos, which, yea, I guess that counts as a flaw?

As for forever, hence why companies like Microsoft and EI have models for "continual update" on connected devices The idea being that the security upgrades never stop.

Re: Microsoft built its own custom Linux kernel for its new IoT service

#102
post #61

Earlier quoted context omitted.

Have you used Windows 10 Server Core, or Windows 10 Enterprise LTSB? There's no data collection in either of those, because they're for serious people. The Home and Pro editions, meanwhile, are effectively "Xbox OS for PCs." They turn your computer into an entertainment appliance run and maintained by Microsoft itself. Of course they collect data, just like there are data-collection agents on all the nodes of your av…

>Windows 10 Enterprise LTSB So tell me, where can I buy that for my personal computer? >because they're for serious people No, because those who can get Windows 10 LTSB actually have the power to push back. Imagine telling Dell or HP that everything they type may be sent to MS at any time. >You can still take control So how can I permanently end all telemetry, now and forever on my box. I'm even willing to sign a let…

I just built a gaming rig, and I tried really hard to get LTSB, because I don't want to use this computer for anything beyond CS:GO. Was impossible.

Re: Microsoft built its own custom Linux kernel for its new IoT service

#103
post #42

Earlier quoted context omitted.

> After seeing this I think the Amazon AWS/FreeRTOS combo is looking like the better architecture for a node solution. FreeRTOS can run on lowly M3s at 120Mhz, like the LPC2478 Is that supposed to imply linux can't? Or that linux plus a GNU subsystem can't? I've personally run it on a lot lower end hardware than that seems to be.

> Is that supposed to imply linux can't? Regular Linux can't. uCLinux might.

Since late 2.5.x, uCLinux has been more or less mainlined.

You can run regular Linux on these, you just probably don't want to.

Re: Microsoft built its own custom Linux kernel for its new IoT service

#104

Earlier quoted context omitted.

...and even then, you're not secure forever. So many times the best security practices have been shown to be insufficient. In fact, I wonder what the scoreboard actually would read, 'roll your own' vs 'best practice'? Maybe not all that different.

I like your idea of a scoreboard. I'm gonna float this at the office. Then again, we're not keen to talk about the fact that nobody has found a flaw in our security model because it'll just invite a ddos, which, yea, I guess that counts as a flaw? As for forever, hence why companies like Microsoft and EI have models for "continual update" on connected devices The idea being that the security upgrades never stop.

Yet that update channel is a door for other attacks. Either its perfectly secure, in which case you need to use that security for your whole app! Or its not, and its vulnerable too. And terribly dangerous, because when broken it may allow complete compromise of the entire device.

Re: Microsoft built its own custom Linux kernel for its new IoT service

#105

Am I paraphrasing this correctly: > Microsoft-branded ARM microcontrollers running an embedded linux distribution. Microsoft rolls out security updates over Azure to reduce the risk of the device becoming part of a botnet. It sounds great.

> over Azure

Microsoft now cares about subscriptions (office365, etc) and monthly recurring "rental" revenue. Anything that gets people to spin up more Azure VMs and pay for them monthly, forever, and possibly get locked into the hosting platform, they're totally OK with. Doesn't matter if it's a Linux VM or a Windows VM running on their hypervisors as long as people are paying the bills.

Re: Microsoft built its own custom Linux kernel for its new IoT service

#106
post #61
post #49

Earlier quoted context omitted.

Have you actually used Windows 10?? The spotlight is squarely on Facebook and it's privacy intrusions right now, but the data collection when you own the OS must be several orders of magnitude larger. Don't be so eager to forgive them. They're not hugging Linux right now because they're a Good Company trying to Do No Evil.

Have you used Windows 10 Server Core, or Windows 10 Enterprise LTSB? There's no data collection in either of those, because they're for serious people. The Home and Pro editions, meanwhile, are effectively "Xbox OS for PCs." They turn your computer into an entertainment appliance run and maintained by Microsoft itself. Of course they collect data, just like there are data-collection agents on all the nodes of your av…

IIRC Windows 10 Enterprise LTSB is for Specialized systems—such as PCs that control medical equipment, point-of-sale systems, and ATMs.

I wouldn't recommend to a developer or an average user.

Re: Microsoft built its own custom Linux kernel for its new IoT service

#107

Earlier quoted context omitted.

I like your idea of a scoreboard. I'm gonna float this at the office. Then again, we're not keen to talk about the fact that nobody has found a flaw in our security model because it'll just invite a ddos, which, yea, I guess that counts as a flaw? As for forever, hence why companies like Microsoft and EI have models for "continual update" on connected devices The idea being that the security upgrades never stop.

Yet that update channel is a door for other attacks. Either its perfectly secure, in which case you need to use that security for your whole app! Or its not, and its vulnerable too. And terribly dangerous, because when broken it may allow complete compromise of the entire device.

I do frontend so I don't have intimate knowledge with our device onboard security, but I do know at the very least any update must have the correct key, access to which is remarkably controlled.

The "ensure device updates are not malicious" question gets asked at least once a month here. It only gets stronger.

You are asking exactly the right questions, though. These are the sort of holes we find in customer home rolled solutions. Another one is factory enrollment vulnerabilities - how do you guarantee that factories don't walk out with your code, stick some malicious stuff on it, then install it on the device before shipping it?

Re: Microsoft built its own custom Linux kernel for its new IoT service

#108
post #102

Earlier quoted context omitted.

>Windows 10 Enterprise LTSB So tell me, where can I buy that for my personal computer? >because they're for serious people No, because those who can get Windows 10 LTSB actually have the power to push back. Imagine telling Dell or HP that everything they type may be sent to MS at any time. >You can still take control So how can I permanently end all telemetry, now and forever on my box. I'm even willing to sign a let…

I just built a gaming rig, and I tried really hard to get LTSB, because I don't want to use this computer for anything beyond CS:GO. Was impossible.

It is on bittorrent of course. Different spyware than the standard edition though probably.

Re: Microsoft built its own custom Linux kernel for its new IoT service

#109
post #41

Am I paraphrasing this correctly: > Microsoft-branded ARM microcontrollers running an embedded linux distribution. Microsoft rolls out security updates over Azure to reduce the risk of the device becoming part of a botnet. It sounds great.

It does. But, it's also pretty surreal for those of us that worked through the anti-linux Microsoft of the 90's. Windows subsystem for Linux, and initiatives like this are a real confirmation that MS finally "gets it". Right tool for the right job. Good for them. It's also a big swing for me in that I trust MS more than Google now to do the right thing. I'd have thought that impossible a couple of decades ago.

Remember the first two E's fellow 90s person. It's the third one that gets you.

Re: Microsoft built its own custom Linux kernel for its new IoT service

#110
post #75
post #61

Earlier quoted context omitted.

Have you used Windows 10 Server Core, or Windows 10 Enterprise LTSB? There's no data collection in either of those, because they're for serious people. The Home and Pro editions, meanwhile, are effectively "Xbox OS for PCs." They turn your computer into an entertainment appliance run and maintained by Microsoft itself. Of course they collect data, just like there are data-collection agents on all the nodes of your av…

Yeah I have to use it for work, the machine has 16 gigs and like 8 gigs are used for MS to spy on me while I'm using it.

sigh no
Post reply on HN