Live data from Hacker News

“Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

anandtech.com

121–130 of 172 posts

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#121

A previous HN link is here -- https://news.ycombinator.com/item?id=25131431 -- which links to MS's original press release -- https://www.microsoft.com/security/blog/2020/11/17/meet-the-... . That article explicitly states that it was designed originally for the xbox. I worry that going to be a very anti-consumer, anti-free-speech, DRM heavy chip that MS want to popularise as an alternative to the (still hated in some…

So, the Trusted Platform Module itself isn't a DRM solution. It's a chip that hangs off the LPC/ISA bus and holds a crypto key generated from boot stage hashes that your BIOS, bootloader, and operating system provide to it. The idea is that all of those hashes together form a key that would change if any stage were tampered with, and that by encrypting things with the key you can prove that those particular things ha…

But that would also make your device even more uniquely identifiable which is a massive security flaw in my opinion.

edit: I think it is plainly incorrect to brush off fears about DRM deployment and device lock down. This technology was specifically invented for it, there is evidence and direct statements from manufacturers about this.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#122
post #118
post #99

Earlier quoted context omitted.

I see Pluton more as a "competitor" to Apple's Secure Enclave Processor and Google's Titan chip, and getting rid of the nightmare that TPM was/is.

I thought that specific implementations had issues in the past but that the concept of a TPM in general was fine? The Intel ME and AMD PSP, on the other hand, are proper nightmares. For that matter, so is any other "security co-processor" that operates as an unauditable black box below ring 0 (presumably this applies to both Apple's and Google's solutions).

Problem of a TPM is that it’s not an integrated chip, you can easily intercept messages going to and coming from the TPM

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#123
post #60

Earlier quoted context omitted.

He says in pretty much literally the opening sentence that it's for DRM: "we want to prevent the piracy of games", and then goes on to justify that their business model involves making a loss on each xbox sold, and wants to ensure that the CPU only runs Microsoft code against the wishes of the Xbox owner. A later direct quote is "the fundamental difference between Windows security and Xbox security is that the owner…

> That's not something I want in my general-purpose computing device where I am the owner. Consoles aren't general computing devices, though. Apple disagrees with your idea of ownership, too ;) and so do the customers who Pluton is targeted at - https://www.microsoft.com/en-us/windowsforbusiness/windows10... The whole project isn't targeted at end-users. It's IoT, businesses, hospitals, government agencies, utility c…

Without those pesky users computing wouldn't be as successful. Windows isn't secure enough to use it in government or IOT in my opinion, aside from office software for clerks.

But if it is not aimed at end users, I am sure a simple switch will help. Somehow I doubt we will see it.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#124
post #82

Earlier quoted context omitted.

> The whole project isn't targeted at end-users. It's IoT, businesses, hospitals, government agencies, utility companies, etc. > It's the security needs of these organisations that are addressed by this technology, not yours, not mine. It's perfectly fine to let a sysadmin lock down a computer to reduce what the end user can do. None of these use cases or security benefits require taking power away from the sysadmin.…

> None of these use cases or security benefits require taking power away from the sysadmin. Yes, they do! That's the whole point of the product. Why would you even trust the sysadmin in the first place? The fact of the matter is that a lot of data leaks have been caused by insiders - either willingly or via social engineering. This technology provides a method of closing this loophole and aims to enable users (not pr…

This argument of "trust no one, not even the sysadmin you employ" is actually "trust no one except me and this black box I'd like to sell you". Even ignoring the externalities of this kind of push I don't really see the value.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#126
post #61

Earlier quoted context omitted.

There are two meaningful options for CPU. If they both adopt the tech...

... they create a niche for a third ... provided there are enough people who care. If nobody cares nobody cares.

You downvote this, HN, but this is spot on.

You keep gobbling up this shit, you all drool over the toys Intel and MS push into your faces. Shoveling this manure up your own asses for decades. Now you are complaining and claiming you have no choice. Yeah, _now_ you don't anymore, but there is still wiggle room to influence the future. If we all go belly up and give up dystopia will come sooner than you are comfortable with.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#127
post #61

Earlier quoted context omitted.

... they create a niche for a third ... provided there are enough people who care. If nobody cares nobody cares.

You make it seem like anybody can make a competitive CPU and take it to market. You need billions of dollars of R&D to make a good CPU, and if everyone who can afford that R&D signs on to taking your freedom away, there is no alternative .

Yet billionairs don't invest in this, they make rockets and fancy cars. Fancy phones..

You don't care, just admit it. They know it.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#129
post #94

Earlier quoted context omitted.

There's a lot of open source software that provides a fantastic user experience to developers , perhaps the solution is somehow getting some users to work on your open source product when developers aren't your intended users.

Even as a developer the things I want just don't work reliably: 1. Bluetooth; Audio especially, but all BT is flaky. 2. Low Latency audio; I have tried Jack on numerous machines and always find myself staring at high latency buffers because the kernel audio driver can't perform any better, and then there's how often it just ... goes silent without any trace in the logs. 3. Suspend and battery usage are, in general, s…

> 3. Suspend and battery usage are, in general, still a decade behind the competition.

For suspend there's been some regressions a few years back, but I use it all the time now on both Dell Latitude and Thinkpad X without any issue.

Battery usage is way better with Linux than with Windows, at least on the Latitude where I can easily compare with my Windows 10 using colleagues. It's not even close, and I also avoid the constant fan noise ;)

Now there's one thing to keep in mind: if you don't use a pre-installed Linux distro (which I don't, I use Debian stable) then you are the system integrator ;) No way around this.

But on well supported models like the Latitude and Thinkpad at least this integration is very easy: for me I just install the "tlp" (The Laptop Project) package, and because I only use SSD I aggressively idle the disk. This configuration I did years ago and simply reuse it. Done.

Re: “Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

#130
post #26

Call me sceptical, but I hope m$ is not pulling Apple tricks to lock computers to their OS. Is this open source? Will consumer be able to audit it down to the silicon level?

They already said it is OS agnostic. MS 2020 is far away from MS 2010. With regards to the auditing need, can you audit a CPU down to the silicon level today?

> MS 2020 is far away from MS 2010.

I haven't seen evidence of this. Their OS is at least as user hostile as before and they desperately seek developers.

If I have a specific technical problem I have to slay hundreds of sales people before I find someone with real expertise.

That they aren't as dominant as before is probably due to the fact that they have few developers and need to regain some. Financially Office is probably the largest income and sure, the standard corporate AD solutions are wide spread. But their cloud tech seems to be restricted to very large companies and I haven't seen much of it.

Post reply on HN