A previous HN link is here -- https://news.ycombinator.com/item?id=25131431 -- which links to MS's original press release -- https://www.microsoft.com/security/blog/2020/11/17/meet-the-... . That article explicitly states that it was designed originally for the xbox. I worry that going to be a very anti-consumer, anti-free-speech, DRM heavy chip that MS want to popularise as an alternative to the (still hated in some…
“Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm
31–40 of 172 posts
Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm
#32I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this. Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-... Disclaimer: I still work at MSFT but in a different org.
A TPM integrated into the CPU makes sense (and I am puzzled why TPMs aren't a standard feature of all MB given the modest cost). But what about that diagram in the article with a link to the cloud? Will this thing phone home outside of the control of the OS?
When the main core wanted to talk to the Azure Sphere cloud service (from Linux user land), it would go through a remote attestation process that involved Pluton. Pluton can securely track what software was booted on the main core (called "measure boot") and it basically sends a hash of that to the cloud to prove to the cloud what software is currently running.
So I imagine the chip-to-cloud thing they're talking about is this remote attestation protocol.
Also, it's possible the term "Pluton" has been expanded to refer to more than just the M4 chip we used in Azure Sphere.
Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm
#33Earlier quoted context omitted.
If Qualcomm is implementing it then it should be easy enough to break. Qualcomm's secure enclave software for Android has had an absolutely abysmal security track record. Apple gets all the press precisely because it's such an achievement (well, that and Apple is more well known). Qualcomm hacks have come out like every 6 months for nearly a decade, and nobody cares anymore.
well apple's enclave is broken aswell. https://arstechnica.com/information-technology/2020/10/apple... well at least it needs physical access.
I was keeping track of hacks for marketing material related to a security startup I was working on. The competition would have principally been smartphone-based authentication apps, both Android and iPhone.
Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm
#34I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this. Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-... Disclaimer: I still work at MSFT but in a different org.
So.. this basically means swapping your CPU gets rid of anything you stored on its "TPM", or can it be backuped up to the TPM of your Mainboard and restored to the new one you install?
But the Pluton I know of didn't really have any writeable storage. It had some special ROM and fuses that it uses internally for its private keys but that's basically it.
Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm
#35I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this. Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-... Disclaimer: I still work at MSFT but in a different org.
- Was Pluton based on an RTOS or is it running on bare-metal on top of the M4? - Is the architecture on the i.MX8-based Sphere the same as the one on MT3620? - Does the Security Subsystem running on the Cortex-A's secure world have any relationship with Pluton? Is the Security Subsystem running on top of the Sphere's modified Linux kernel like the normal world is?
Thanks, cheers!
Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm
#36I assume this also means cloud-to-chip, which means it might give Microsoft/NSA the ability to tap into it at will "from the cloud"?
After all, Windows 10's tracking features were like a longtime wishlist from the FBI/NSA, so I wouldn't be surprised if this is their "...one more thing" in the same vein.
Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm
#37Is Pluton specifically Windows related? Will this affect how easy it is to run Linux on hardware using Pluton?
>Known Elements of the Palladium System:
> The system purports to stop viruses by preventing the running of malicious programs. The system will store personal data within an encrypted folder.
>The system will depend on hardware that has either a digital signature or a tracking number.
> The system will filter spam. The system has a personal information sharing agent called "My Man."
> The system will incorporate Digital Rights Management technologies for media files of all types (music, documents, e-mail communications). Additionally, the system purports to transmit data within the computer via encrypted paths
Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm
#38I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this. Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-... Disclaimer: I still work at MSFT but in a different org.
Greetings! - Was Pluton based on an RTOS or is it running on bare-metal on top of the M4? - Is the architecture on the i.MX8-based Sphere the same as the one on MT3620? - Does the Security Subsystem running on the Cortex-A's secure world have any relationship with Pluton? Is the Security Subsystem running on top of the Sphere's modified Linux kernel like the normal world is? Thanks, cheers!
Hope that helps!
Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm
#39Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm
#40> What the Pluton project from Microsoft and the agreement between AMD, Intel, and Qualcomm will do is build a TPM-equivalent directly into the silicon of every Windows-based PC of the future. CPUs with security modules controlled by MS? Who will guarantee it won't be abused against non MS systems and users?
How many Qualcomm CPUs run Windows?