Live data from Hacker News

“Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

anandtech.com

61–70 of 172 posts

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#61
post #57

Earlier quoted context omitted.

Then don't buy stuff like that. None of this stuff will change unless people vote with their wallets. Companies have the idea that nobody cares. I've actually heard "nobody cares about privacy and security" repeated as a mantra in multiple circles.

There are two meaningful options for CPU. If they both adopt the tech...

... they create a niche for a third ... provided there are enough people who care.

If nobody cares nobody cares.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#62

A previous HN link is here -- https://news.ycombinator.com/item?id=25131431 -- which links to MS's original press release -- https://www.microsoft.com/security/blog/2020/11/17/meet-the-... . That article explicitly states that it was designed originally for the xbox. I worry that going to be a very anti-consumer, anti-free-speech, DRM heavy chip that MS want to popularise as an alternative to the (still hated in some…

So, the Trusted Platform Module itself isn't a DRM solution. It's a chip that hangs off the LPC/ISA bus and holds a crypto key generated from boot stage hashes that your BIOS, bootloader, and operating system provide to it. The idea is that all of those hashes together form a key that would change if any stage were tampered with, and that by encrypting things with the key you can prove that those particular things haven't changed.

It's not particularly practical to build a DRM scheme out of a Trusted Platform Module, notably because the key attestation the TPM provides audits a particular combination of boot stages, not a particular piece of hardware. DRM vendors don't care about you updating your firmware, but they do care about videos being locked to a particular authorized piece of hardware. If you had a TPM-based DRM, you'd deauthorize your video downloads by just updating your BIOS, while videos you passed from one person to another on the same OS version would play just fine.

I imagine Pluton is trying to be a competitor to Intel ME or AMD PSP, which are things you can use to isolate software running on shared hardware. For example, Intel ME provides hardware support for Intel Software Guard Extensions, which is used to isolate DRM from the host operating system. AMD has something similar with Secure Encrypted Virtualization, which uses the PSP to set up different memory-encrypted containers for each VM that higher security rings can't access. In this case, locking down PCs from arbitrary code, like an Xbox, isn't really on the menu. What they're looking to do is carve out space in Ring 3 that Ring 0 can't touch.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#64
post #61

Earlier quoted context omitted.

There are two meaningful options for CPU. If they both adopt the tech...

... they create a niche for a third ... provided there are enough people who care. If nobody cares nobody cares.

I don't have infinite resources to care with.

Even if everyone is willing to spend an extra $100, a duopoly can ignore them and lose no money. That's not enough money to bootstrap a competitor desktop/laptop CPU.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#65
post #55
post #52

Earlier quoted context omitted.

Boiling frog stuff... We complained about this 20 years ago, all these moves were known back then, yet here we are. More to come - TPM required to connect to the Internet and access news sources without any ability to store information on our own devices. Followed by rewriting historical articles to properly "sanitize" content.

User experience is everything, and without a good profitable business model FOSS can't afford the massive investment of time and effort required to bring a competitive user experience. Making stuff work is only maybe 20% of the work required to build a product... sometimes less. I've been yelling about that for years and years and very few people seem to get it. Free as in freedom got conflated with free as in beer y…

> User experience is everything

It's very important, but it's not "everything".

> and without a good profitable business model FOSS can't afford the massive investment of time and effort required to bring a competitive user experience.

By that logic, most FOSS should not have existed at all.

> Making stuff work is only maybe 20% of the work required to build a product... sometimes less.

That's often true. It's certainly true for some of the software projects I maintain.

> Commercial closed source and SaaS vendors have the resources to leave FOSS and open ecosystems in the dust in terms of features and user experience

That's not possible even with infinite resources, because FOSS software is sometimes great, often good, and also often the only thing available.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#66
post #17

I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this. Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-... Disclaimer: I still work at MSFT but in a different org.

Will this be virtualisable so multiple VMs sharing a host will see separate, independent devices?

On desktops and laptops, will this device have a hardwired user-presence sensor, like Yubikeys do?

Would this device be performance-oriented enough to, for example, terminate SSL? I gather TPMs can, but only unhelpfully slowly [1]

Would it be performance-oriented enough to perform disk encryption? What about memory encryption?

[1] https://blog.habets.se/2012/02/Benchmarking-TPM-backend-SSL....

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#67
post #60

Earlier quoted context omitted.

He says in pretty much literally the opening sentence that it's for DRM: "we want to prevent the piracy of games", and then goes on to justify that their business model involves making a loss on each xbox sold, and wants to ensure that the CPU only runs Microsoft code against the wishes of the Xbox owner. A later direct quote is "the fundamental difference between Windows security and Xbox security is that the owner…

> That's not something I want in my general-purpose computing device where I am the owner. Consoles aren't general computing devices, though. Apple disagrees with your idea of ownership, too ;) and so do the customers who Pluton is targeted at - https://www.microsoft.com/en-us/windowsforbusiness/windows10... The whole project isn't targeted at end-users. It's IoT, businesses, hospitals, government agencies, utility c…

> The whole project isn't targeted at end-users. It's IoT, businesses, hospitals, government agencies, utility companies, etc.

> It's the security needs of these organisations that are addressed by this technology, not yours, not mine.

It's perfectly fine to let a sysadmin lock down a computer to reduce what the end user can do.

None of these use cases or security benefits require taking power away from the sysadmin. And that's what the argument is about: not whether the end-user is losing control, but whether the sysadmin is losing control. With the obvious note that lots of home users are their own sysadmins.

> I see this chip in the same area as Intel's vPro, TPM 2.0, AMDs ASP (in their Ryzen PRO line), and so on; not necessarily aimed at end users (aside from the occasional buzzword) and more aimed towards businesses and government users (as part of their Zero-Trust initiative).

Those are basically fine, as long as they can be disabled when not needed.

But if I'm forced to give someone else special beyond-root access to my device for DRM purposes, that's not acceptable.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#68
post #53

Earlier quoted context omitted.

Virtually every technology that can be used to create a walled garden with moderation can be bent to limit people's ability to speak freely. How long until someone has a device which can go to Netflix, social networking, etc. but doesn't have a web browser on it that can load arbitrary pages, and it's impossible to jailbreak? Since we have no freedom of speech within FAANG properties, that would be a considerable res…

> principles matter To whom, though? Everybody is praising Apple for their (admittedly quite excellent) M1 hardware and no one seems to take issue with that either. You cannot have truly open hardware as long as (software-) patents and IP exist, simple as that. Companies need to protect their investment, since the days of comparatively simple CPUs are over and a lot of "secret sauce" is actually software and licensed…

All of that hardware would be just fine if we had a Bill of Rights for the Internet that ensured free speech rights and ability to host content (of any sort that isn't strictly prohibited already) is enshrined in law.

Pity all these laws end up spending most of their time enabling obscenity instead of political speech.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#69
post #50

Earlier quoted context omitted.

Imagine it being capable of enforcing something like which executables you are able to load... Quite in the vein of Apple sending the executables hash to some random server

That's not how that works. At all.

Another commenter familiar with the tech said: Pluton can securely track what software was booted on the main core (called "measure boot") and it basically sends a hash of that to the cloud to prove to the cloud what software is currently running.

That sounds like most of what you need to build a system that can enforce what executables you're allowed to load and prevent you from attaching a debugger.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#70
post #32
post #23

Earlier quoted context omitted.

A TPM integrated into the CPU makes sense (and I am puzzled why TPMs aren't a standard feature of all MB given the modest cost). But what about that diagram in the article with a link to the cloud? Will this thing phone home outside of the control of the OS?

In Azure Sphere, Pluton didn't do any direct network communication, that was all handled by the main core. Also there was no cellular so the whole system depended on user interaction to get online. When the main core wanted to talk to the Azure Sphere cloud service (from Linux user land), it would go through a remote attestation process that involved Pluton. Pluton can securely track what software was booted on the m…

I guess I’m wondering how Pluton and SGX coexist...
Post reply on HN