Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

51–60 of 554 posts

Re: The Dangers of Microsoft Pluton

#51
In a landscape where security and privacy is imminent Pluton will sold as a saviour.

And I am pretty sure it's a darn good idea and well thought off and executed.

I cannot see why this is a bad idea besides the usual cargo cults claiming corporate distrust.

Heck we trusted Intel for decades and no one asked what Apple put in their silicon, because its Apple and Steve was so trustworthy.

Re: The Dangers of Microsoft Pluton

#52

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

The capacity for abuse is huge, way beyong the potential benefits.

From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly.

Those kind of people will abuse such system to prevent things to be shared.

It will be used for putting DRM on everything and create a more and more closed web.

It will be used by corporations and govs to prevent wisthleblowers and journalists to do their job. Or to prevent employees to get evidences of mistreatments in case they need to sue.

Because if you look at it, it's basically just a system for information control. And bad actors love that.

And of course it will be "for security reasons".

Trusting people with a terrible track record to not abuse a massive power in the future, espacially one that can be scaled up with the push of a button once the infrastructure is in place, is not a good bet.

Re: The Dangers of Microsoft Pluton

#53

In a landscape where security and privacy is imminent Pluton will sold as a saviour. And I am pretty sure it's a darn good idea and well thought off and executed. I cannot see why this is a bad idea besides the usual cargo cults claiming corporate distrust. Heck we trusted Intel for decades and no one asked what Apple put in their silicon, because its Apple and Steve was so trustworthy.

After PRISM and xkeyscore, you don't get to doubt it's going to be abused for the worse.

Not anymore.

Re: The Dangers of Microsoft Pluton

#54

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

Sure it's fantastic in a corporate environment. Not so fantastic for personal devices. Basically this: https://youtu.be/XgFbqSYdNK4

Re: The Dangers of Microsoft Pluton

#56
post #25

Regardless of all the FUD against Pluton, it has a great feature, it is yet another CPU with hardware memory tagging, as the last resort against C flaws and derived languages.

FUD is no longer FUD when it becomes a realistic danger. Given that remote attestation already had deleterious effects for user freedoms on smartphones and tablets (meaning, choose between banking apps and any deviation from the factory ROM), Pluton should be seen as a danger.

Smartphones and tablets are electronic gadgets.

If you want a general purpose computer get a laptop.

Most likely one sold by Linux OEMs, like Tuxedo and System76.

Re: The Dangers of Microsoft Pluton

#58

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

What you can install on YOUR pc will be at the sole mercy of microsoft/or maybe someone else.... That's the cusp of it. Not that it can be used for good, but that it sets the way for heavy misuse by large corporations. Wait a few years. Smaller companies won't even be allowed to order high end cpu's. You'll be at 100% mercy of these corporations. If after 2 years they decide to brick your pc, they'll just do it. You…

still waiting on the secure boot lockdown everyone has insisted is coming for the better part of two decades...

Re: The Dangers of Microsoft Pluton

#59

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

The capacity for abuse is huge, way beyong the potential benefits. From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly. Those kind of people will abuse such system to prevent things to be shared. It will be used for putting DRM on everything and create a more and more closed web. It will be used by corporations…

Ron DeSantis doesn't need hardware-level DRM to ban math books.

https://www.baynews9.com/fl/tampa/news/2022/05/06/florida-ba...

If you're worried about book bannings in states like Florida, DeSantis is up for reelection in just over 3 months. Go volunteer or donate money to his opponent (probably Charlie Crist).

Re: The Dangers of Microsoft Pluton

#60

Earlier quoted context omitted.

The conspiratorial answers here are emotionally satisfying, but ultimately wrong. The reason chip makers and OS vendors are adding this is customer demand, by which I mean enterprises. Companies want remote attestation and guaranteed-immutable OS images on their networks, and I honestly can't say I blame them. In a perfect world they could have it and we could somehow firewall it away from the consumer space entirely…

On-premise, open-source, customer-owned remote attestation servers are possible. Avoid outsourcing integrity verification to 3rd-party clouds.

Yes, they are possible... And they are implemented using all the evil things like Secure Boot, TPM, and Pluton.

MS remote attestation doesn't require remote cloud or anything like that, I recall it supporting air-gapped environment from the start (guess why, the top-price enterprise clients want that, including resigning windows with their own secure boot keys).

Disclaimer: for various reasons open source remote attestation in corporate is currently on my roadmap at work

Post reply on HN