Live data from Hacker News

“Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

anandtech.com

21–30 of 172 posts

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#22
post #17

I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this. Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-... Disclaimer: I still work at MSFT but in a different org.

The pressing concern for me: what does this mean for non-Windows operating systems running on Pluton-equipped systems? Will there be a possibility for non-Windows software to use Pluton's features?

I can only comment on the technical details I know of, not the business objectives of the parties involved.

From a technical standpoint, Azure Sphere's OS was built on Linux. As far as I know, there isn't anything Windows specific to Pluton. Pluton was a separate (heavily-modified) ARM M4 core which we interfaced with from the main A7 core via a secure mailbox channel, which was again OS agnostic.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#23
post #17

I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this. Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-... Disclaimer: I still work at MSFT but in a different org.

A TPM integrated into the CPU makes sense (and I am puzzled why TPMs aren't a standard feature of all MB given the modest cost). But what about that diagram in the article with a link to the cloud? Will this thing phone home outside of the control of the OS?

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#24

A previous HN link is here -- https://news.ycombinator.com/item?id=25131431 -- which links to MS's original press release -- https://www.microsoft.com/security/blog/2020/11/17/meet-the-... . That article explicitly states that it was designed originally for the xbox. I worry that going to be a very anti-consumer, anti-free-speech, DRM heavy chip that MS want to popularise as an alternative to the (still hated in some…

How do you see it being anti-free-speech?

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#25
post #14

> What the Pluton project from Microsoft and the agreement between AMD, Intel, and Qualcomm will do is build a TPM-equivalent directly into the silicon of every Windows-based PC of the future. CPUs with security modules controlled by MS? Who will guarantee it won't be abused against non MS systems and users?

How many Qualcomm CPUs run Windows?

Not that I think Pluton will be a problem for Linux (as in, one that won't be present on Windows also) but AFAIK Qualcomm and Microsoft had partnered to not only run Windows on ARM, but to run x86 software on ARM Windows.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#26

Call me sceptical, but I hope m$ is not pulling Apple tricks to lock computers to their OS. Is this open source? Will consumer be able to audit it down to the silicon level?

They already said it is OS agnostic. MS 2020 is far away from MS 2010.

With regards to the auditing need, can you audit a CPU down to the silicon level today?

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#27
post #15
post #6

Earlier quoted context omitted.

Is it a policy question without Pluton? I.e. will this allow hardware vendors additional means to prevent me from installing Linux?

> will this allow hardware vendors additional means to prevent me from installing Linux? No. Pluton serves as an on-chip secure enclave for encryption keys and the like. This is unrelated to installing operating systems.

Will the final purchaser of the computer chip, i.e., the consumer, have r/w access to the contents of the enclave?

EDIT: s/access/r\/w & to the contents of/

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#28
post #12

Earlier quoted context omitted.

If Qualcomm is implementing it, I'm sure it will on a technical level. Linux is important to AMD and Intel, but Linux-running devices represent nearly all of Qualcomm's non-embedded SOC market. Whether vendors can use it to restrict such things, I don't think anyone can say right now, but I would guess and hope not. The TPM does not.

If Qualcomm is implementing it then it should be easy enough to break. Qualcomm's secure enclave software for Android has had an absolutely abysmal security track record. Apple gets all the press precisely because it's such an achievement (well, that and Apple is more well known). Qualcomm hacks have come out like every 6 months for nearly a decade, and nobody cares anymore.

well apple's enclave is broken aswell. https://arstechnica.com/information-technology/2020/10/apple...

well at least it needs physical access.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#29

Call me sceptical, but I hope m$ is not pulling Apple tricks to lock computers to their OS. Is this open source? Will consumer be able to audit it down to the silicon level?

Apple allows you to boot any OS you want on their apple silicon macs (as long as you have uploaded the key so it can verify the kernel you tell it to boot)

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#30
post #17

I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this. Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-... Disclaimer: I still work at MSFT but in a different org.

So.. this basically means swapping your CPU gets rid of anything you stored on its "TPM", or can it be backuped up to the TPM of your Mainboard and restored to the new one you install?
Post reply on HN