Live data from Hacker News

“Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

anandtech.com

51–60 of 172 posts

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#51
post #49

A previous HN link is here -- https://news.ycombinator.com/item?id=25131431 -- which links to MS's original press release -- https://www.microsoft.com/security/blog/2020/11/17/meet-the-... . That article explicitly states that it was designed originally for the xbox. I worry that going to be a very anti-consumer, anti-free-speech, DRM heavy chip that MS want to popularise as an alternative to the (still hated in some…

> Why else would they design it for the xbox, of all things? If you really want to know the answer, here's the lead engineer explaining it en detail: https://www.youtube.com/watch?v=quLa6kzzra0

He says in pretty much literally the opening sentence that it's for DRM: "we want to prevent the piracy of games", and then goes on to justify that their business model involves making a loss on each xbox sold, and wants to ensure that the CPU only runs Microsoft code against the wishes of the Xbox owner. A later direct quote is "the fundamental difference between Windows security and Xbox security is that the owner _is_ the bad guy".

That's not something I want in my general-purpose computing device where I am the owner.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#52

A previous HN link is here -- https://news.ycombinator.com/item?id=25131431 -- which links to MS's original press release -- https://www.microsoft.com/security/blog/2020/11/17/meet-the-... . That article explicitly states that it was designed originally for the xbox. I worry that going to be a very anti-consumer, anti-free-speech, DRM heavy chip that MS want to popularise as an alternative to the (still hated in some…

Boiling frog stuff... We complained about this 20 years ago, all these moves were known back then, yet here we are.

More to come - TPM required to connect to the Internet and access news sources without any ability to store information on our own devices. Followed by rewriting historical articles to properly "sanitize" content.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#53
post #24

Earlier quoted context omitted.

How do you see it being anti-free-speech?

Virtually every technology that can be used to create a walled garden with moderation can be bent to limit people's ability to speak freely. How long until someone has a device which can go to Netflix, social networking, etc. but doesn't have a web browser on it that can load arbitrary pages, and it's impossible to jailbreak? Since we have no freedom of speech within FAANG properties, that would be a considerable res…

> principles matter

To whom, though? Everybody is praising Apple for their (admittedly quite excellent) M1 hardware and no one seems to take issue with that either.

You cannot have truly open hardware as long as (software-) patents and IP exist, simple as that. Companies need to protect their investment, since the days of comparatively simple CPUs are over and a lot of "secret sauce" is actually software and licensed IP blocks.

Since patent holders are free to select who their licensee is, they'll always target the ones with the biggest margins (see for example [1]) so mainly consumer products and thus those won't be free (as in speech) anytime soon.

[1] https://www.bloomberg.com/news/articles/2020-10-20/nokia-see...

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#54
post #22

Earlier quoted context omitted.

The pressing concern for me: what does this mean for non-Windows operating systems running on Pluton-equipped systems? Will there be a possibility for non-Windows software to use Pluton's features?

I can only comment on the technical details I know of, not the business objectives of the parties involved. From a technical standpoint, Azure Sphere's OS was built on Linux. As far as I know, there isn't anything Windows specific to Pluton. Pluton was a separate (heavily-modified) ARM M4 core which we interfaced with from the main A7 core via a secure mailbox channel, which was again OS agnostic.

Frustrating that the announcement was made with so little technical details easily findable.

This kind of decision- to use an ARM core- seem pretty questionable. That's how things always were done, but it feels like another UEFI/FAT32 situation, dragging in old encumbering legacy baggage with big IP implications, when there are available other options (RISC-V).

It feels like this decision is being made literally one year too soon. Fixing the old, archaic in to place.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#55
post #52

A previous HN link is here -- https://news.ycombinator.com/item?id=25131431 -- which links to MS's original press release -- https://www.microsoft.com/security/blog/2020/11/17/meet-the-... . That article explicitly states that it was designed originally for the xbox. I worry that going to be a very anti-consumer, anti-free-speech, DRM heavy chip that MS want to popularise as an alternative to the (still hated in some…

Boiling frog stuff... We complained about this 20 years ago, all these moves were known back then, yet here we are. More to come - TPM required to connect to the Internet and access news sources without any ability to store information on our own devices. Followed by rewriting historical articles to properly "sanitize" content.

User experience is everything, and without a good profitable business model FOSS can't afford the massive investment of time and effort required to bring a competitive user experience. Making stuff work is only maybe 20% of the work required to build a product... sometimes less.

I've been yelling about that for years and years and very few people seem to get it. Free as in freedom got conflated with free as in beer years ago, and FOSS today is not much more than "waaah gimme free stuff!" It's not a gift culture. It's a "take culture."

Anyone who suggests any change to FOSS culture to remedy this problem gets shouted down. Any license that tries to remedy it gets attacked as "not OSI compliant" and restricting peoples' rights.

Meanwhile commercial closed source and SaaS vendors have the resources to leave FOSS and open ecosystems in the dust in terms of features and user experience. While the license purists yell about "restrictive licenses" taking away rights, the gravity of the walled gardens becomes more and more powerful.

The choice is between free and freedom.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#56
post #17

I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this. Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-... Disclaimer: I still work at MSFT but in a different org.

[deleted]

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#57
post #49

Earlier quoted context omitted.

> Why else would they design it for the xbox, of all things? If you really want to know the answer, here's the lead engineer explaining it en detail: https://www.youtube.com/watch?v=quLa6kzzra0

He says in pretty much literally the opening sentence that it's for DRM: "we want to prevent the piracy of games", and then goes on to justify that their business model involves making a loss on each xbox sold, and wants to ensure that the CPU only runs Microsoft code against the wishes of the Xbox owner. A later direct quote is "the fundamental difference between Windows security and Xbox security is that the owner…

Then don't buy stuff like that.

None of this stuff will change unless people vote with their wallets. Companies have the idea that nobody cares. I've actually heard "nobody cares about privacy and security" repeated as a mantra in multiple circles.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#58
post #57

Earlier quoted context omitted.

He says in pretty much literally the opening sentence that it's for DRM: "we want to prevent the piracy of games", and then goes on to justify that their business model involves making a loss on each xbox sold, and wants to ensure that the CPU only runs Microsoft code against the wishes of the Xbox owner. A later direct quote is "the fundamental difference between Windows security and Xbox security is that the owner…

Then don't buy stuff like that. None of this stuff will change unless people vote with their wallets. Companies have the idea that nobody cares. I've actually heard "nobody cares about privacy and security" repeated as a mantra in multiple circles.

There are two meaningful options for CPU. If they both adopt the tech...

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#60
post #49

Earlier quoted context omitted.

> Why else would they design it for the xbox, of all things? If you really want to know the answer, here's the lead engineer explaining it en detail: https://www.youtube.com/watch?v=quLa6kzzra0

He says in pretty much literally the opening sentence that it's for DRM: "we want to prevent the piracy of games", and then goes on to justify that their business model involves making a loss on each xbox sold, and wants to ensure that the CPU only runs Microsoft code against the wishes of the Xbox owner. A later direct quote is "the fundamental difference between Windows security and Xbox security is that the owner…

> That's not something I want in my general-purpose computing device where I am the owner.

Consoles aren't general computing devices, though.

Apple disagrees with your idea of ownership, too ;) and so do the customers who Pluton is targeted at - https://www.microsoft.com/en-us/windowsforbusiness/windows10...

The whole project isn't targeted at end-users. It's IoT, businesses, hospitals, government agencies, utility companies, etc.

We need to stop seeing us (as private end users) as the centre of the world and start to acknowledge that there's hundreds of millions of PC devices out there that don't serve private end users. It's the security needs of these organisations that are addressed by this technology, not yours, not mine.

The unfortunate truth is that Windows is still the backbone of many government agencies, power plants, hospital IT, businesses and so on.

It's also a fact that most of these machines are not well managed, lack updates , aren't hardened or secured in any way and are targeted by cyber criminals on a daily basis; sometimes with grim consequences. It gets even worse when you look at IoT and the mess that manufacturers get us into (default passwords, unsecured data transfer, ...).

I see this chip in the same area as Intel's vPro, TPM 2.0, AMDs ASP (in their Ryzen PRO line), and so on; not necessarily aimed at end users (aside from the occasional buzzword) and more aimed towards businesses and government users (as part of their Zero-Trust initiative).

Post reply on HN