Live data from Hacker News

“Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

anandtech.com

11–20 of 172 posts

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#11

A previous HN link is here -- https://news.ycombinator.com/item?id=25131431 -- which links to MS's original press release -- https://www.microsoft.com/security/blog/2020/11/17/meet-the-... . That article explicitly states that it was designed originally for the xbox. I worry that going to be a very anti-consumer, anti-free-speech, DRM heavy chip that MS want to popularise as an alternative to the (still hated in some…

[deleted]

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#12
post #2

Is Pluton specifically Windows related? Will this affect how easy it is to run Linux on hardware using Pluton?

If Qualcomm is implementing it, I'm sure it will on a technical level. Linux is important to AMD and Intel, but Linux-running devices represent nearly all of Qualcomm's non-embedded SOC market. Whether vendors can use it to restrict such things, I don't think anyone can say right now, but I would guess and hope not. The TPM does not.

If Qualcomm is implementing it then it should be easy enough to break. Qualcomm's secure enclave software for Android has had an absolutely abysmal security track record. Apple gets all the press precisely because it's such an achievement (well, that and Apple is more well known). Qualcomm hacks have come out like every 6 months for nearly a decade, and nobody cares anymore.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#14
> What the Pluton project from Microsoft and the agreement between AMD, Intel, and Qualcomm will do is build a TPM-equivalent directly into the silicon of every Windows-based PC of the future.

CPUs with security modules controlled by MS? Who will guarantee it won't be abused against non MS systems and users?

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#15
post #6
post #3

Earlier quoted context omitted.

Booting Linux is really a policy question, not technical.

Is it a policy question without Pluton? I.e. will this allow hardware vendors additional means to prevent me from installing Linux?

> will this allow hardware vendors additional means to prevent me from installing Linux?

No. Pluton serves as an on-chip secure enclave for encryption keys and the like. This is unrelated to installing operating systems.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#16
post #5

Isn't this basically fTPM (basically software TPM implemented in the trusted execution environment of the CPU) that both AMD and Intel already offer?

It'll be built into the CPU, instead of having a separate chip, and seems to have secret-management functionality for user-specified keys, biometrics, etc.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#17
I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this.

Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-...

Disclaimer: I still work at MSFT but in a different org.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#19
post #14

> What the Pluton project from Microsoft and the agreement between AMD, Intel, and Qualcomm will do is build a TPM-equivalent directly into the silicon of every Windows-based PC of the future. CPUs with security modules controlled by MS? Who will guarantee it won't be abused against non MS systems and users?

How many Qualcomm CPUs run Windows?

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#20
post #17

I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this. Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-... Disclaimer: I still work at MSFT but in a different org.

The pressing concern for me: what does this mean for non-Windows operating systems running on Pluton-equipped systems? Will there be a possibility for non-Windows software to use Pluton's features?
Post reply on HN