Can RISC-V save us here? Or is it time to start hoarding CPUs?
The Dangers of Microsoft Pluton
71–80 of 554 posts
Re: The Dangers of Microsoft Pluton
#72Separating the groups of those who have a good anti cheat system enabled (such as this) and those who don’t is a good compromise for everybody. I think more reasonable companies such as Valve will go that way.
Re: The Dangers of Microsoft Pluton
#73Regardless, I think that the pc platform deserves a good anti cheat solution. Separating the groups of those who have a good anti cheat system enabled (such as this) and those who don’t is a good compromise for everybody. I think more reasonable companies such as Valve will go that way.
Re: The Dangers of Microsoft Pluton
#74Re: The Dangers of Microsoft Pluton
#75"DRM will be unusable outside Windows" is already the case.
"Documents can only be opened by authorised users" sounds like a dream come true.
"You can't boot Linux by default" is annoying, but hardly a deal breaker. Statistically, almost nobody runs Linux on their devices. Valve could make a change in the Linux landscape if they actually get SteamOS off the ground (third time's the charm, right?) but so far SteamOS 3 is only meant to be used by their own hardware.
It's been decades since I last heard about powerful Windows rootkits because you can't just swap out the bootloader anymore. You could try it and risk a non booting victim system, but you're not extracting data or injecting ads into the kernel that way. Malware hasn't gone away (partially because Microsoft doesn't want to break old, signed, vulnerable device drivers that are used to bypass signature requirements and gain kernel access) but it's harder to gain good persistence now.
I get it, I want to run Linux on these devices as well. All of this stuff should be easy enough to disable if you're the owner of the device. However, your freedom to use your device however you want doesn't imply that others have to put up with your choices. If I choose to only accept Microsoft Panopticon Validated Devices onto my network, that's my business, no matter how foolish it might be. Distributing my software as a .exe isn't some kind of violation of your constitutional right to run OpenBSD, it's a business choice.
Personally, I'd love to see a similar system provide a hardware root of trust for Linux as well. Qubes being able to verify every single step of the boot process and securely loading the system's (several) security keys would be a great security benefit. Hell, I'd even like to see the option to only run signed software on my machine to ensure the executables haven't been tampered with, either signed by the distro maintainers or by myself during the install process, but Linux doesn't have such features or configuration accessible.
As long as it's possible to disable this stuff or to configure it for your own, personal key set, I'm all for this stuff. I want the freedom to secure my (Linux or Windows) system in hardware, as long as you have the freedom to turn it all off if you disagree. I don't buy Microsoft hardware specifically because I can't disable or configure that crap, despite their excellent pen support and fancy designs, and I think others should do the same. That's my personal choice, though.
Re: The Dangers of Microsoft Pluton
#76The video does a good job of the original threat model for this technology and how it works on Xbox.
Re: The Dangers of Microsoft Pluton
#77Earlier quoted context omitted.
FUD is no longer FUD when it becomes a realistic danger. Given that remote attestation already had deleterious effects for user freedoms on smartphones and tablets (meaning, choose between banking apps and any deviation from the factory ROM), Pluton should be seen as a danger.
Smartphones and tablets are electronic gadgets. If you want a general purpose computer get a laptop. Most likely one sold by Linux OEMs, like Tuxedo and System76.
That device is likely to be a smartphone because everything is slowly moving in the direction of requiring one.
If I need to spend extra money to get an additional "freedom device" and can't afford it, I just won't have one and will miss out on the good stuff.
Re: The Dangers of Microsoft Pluton
#78What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…
Windows security models and policies are the enemy, not remote attestation (RA). RA is a technology that has its fair use, and can be desired for other systems, like in Linux. With a pure RA system your services can decide to trust or not those devices on your network that can be compromised, and report to other devices that there is something suspicious. As anything, this can be used properly to increase the securit…
Re: The Dangers of Microsoft Pluton
#79I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…