Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

81–90 of 554 posts

Re: The Dangers of Microsoft Pluton

#81

Earlier quoted context omitted.

I'm not really worried myself that alternative Operating Systems will be locked out. However, I am concerned that the functionality of alternative Operating Systems will be locked out. If you see the (speculative but grounded) area near the end of the article - imagine if assertion becomes popular for things such as games or digital movies or the school WiFi. Your Linux PC will never be able to do that, and WINE (pro…

> imagine if assertion becomes popular for things such as [...] digital movies You don't need that. Streaming is already crippled on Linux. Hell, Netflix won't even stream full quality on Chrome! > https://help.netflix.com/en/node/13444 4K Ultra HD on a computer Netflix is available in Ultra HD on Windows and Mac computers with: Microsoft Edge for Windows Windows app for Windows 10 and Windows 11 Safari for MacOS 11.…

... and this is why piracy will always continue to be a viable alternative.

Re: The Dangers of Microsoft Pluton

#82
post #73
post #72

Regardless, I think that the pc platform deserves a good anti cheat solution. Separating the groups of those who have a good anti cheat system enabled (such as this) and those who don’t is a good compromise for everybody. I think more reasonable companies such as Valve will go that way.

Good anti-cheat solution is server side AI. Anything client side is malware.

I know that this is a popular take here, which is why I proposed that there should be a mechanism to opt out. But that would mean that you would have to play against those who opted out as well.

Re: The Dangers of Microsoft Pluton

#83
post #61

What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…

Windows security models and policies are the enemy, not remote attestation (RA). RA is a technology that has its fair use, and can be desired for other systems, like in Linux. With a pure RA system your services can decide to trust or not those devices on your network that can be compromised, and report to other devices that there is something suspicious. As anything, this can be used properly to increase the securit…

Yes, lots of Linux devices apply it like that today: You can't use your banking app or consume DRM crippled media on your Android phone if you have root or run a open source Android distribution.

Re: The Dangers of Microsoft Pluton

#84

Earlier quoted context omitted.

Ron DeSantis doesn't need hardware-level DRM to ban math books. https://www.baynews9.com/fl/tampa/news/2022/05/06/florida-ba... If you're worried about book bannings in states like Florida, DeSantis is up for reelection in just over 3 months . Go volunteer or donate money to his opponent (probably Charlie Crist).

Technologists often have such tunnel vision that limits their concerns to tyranny driven by technology when there's plenty of low tech attacks on open society all the time. It reminds me of the good old "my password takes 2 billion years to crack, but my kneecaps only take a few seconds" metaphor about people in tech forgetting that physical coercion is, in fact, a possible attack vector for your IT security.

While this is true for a few people, applying coercion on a mass scale using the kind of tech described in the article makes it much more convenient... so IMO the argument still holds

Re: The Dangers of Microsoft Pluton

#85
post #78
post #61

Earlier quoted context omitted.

Windows security models and policies are the enemy, not remote attestation (RA). RA is a technology that has its fair use, and can be desired for other systems, like in Linux. With a pure RA system your services can decide to trust or not those devices on your network that can be compromised, and report to other devices that there is something suspicious. As anything, this can be used properly to increase the securit…

Is it possible to realize this with Linux systems / networks today? Do you have any good project / description / URL? Thanks!

GrapheneOS remote attestation arguably fits this criteria by being built on Android.

Re: The Dangers of Microsoft Pluton

#86

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

The same things that make it good in a corporate environment can make it abusive in a personal machine.

By forcing the kernel to be untamperable, Microsoft can arbitrarily enforce ANY policy they choose on your PC. They could spy on every single piece of network communication. They could ban any given software from being able to run on Windows - maybe Chrome, maybe Steam, any competitor at all. They actually could easily enforce laws on banned content too - any given website, book, audio or video could be impossible to consume, and an attempt to try could be reported to Microsoft. They could stream the contents of your display and mic and camera at any time to anyone they choose. There is literally nothing they cannot do with complete control over the kernel. And since the kernel and Windows itself is closed source, there are ways to hide all of it so you would never even know.

Security is great but it also goes hand-in-hand with control and surveillance. Every capability to increase security also increases the amount of control those providing the security have.

Re: The Dangers of Microsoft Pluton

#87

Earlier quoted context omitted.

The capacity for abuse is huge, way beyong the potential benefits. From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly. Those kind of people will abuse such system to prevent things to be shared. It will be used for putting DRM on everything and create a more and more closed web. It will be used by corporations…

Ron DeSantis doesn't need hardware-level DRM to ban math books. https://www.baynews9.com/fl/tampa/news/2022/05/06/florida-ba... If you're worried about book bannings in states like Florida, DeSantis is up for reelection in just over 3 months . Go volunteer or donate money to his opponent (probably Charlie Crist).

Mein Kampf is a banned book which I don't think many would disagree with. There are many other such books filled with propaganda that are rightly banned. I don't see why other propaganda-filled books that are being pushed on unsuspecting children shouldn't be banned too, unless the only reason is that you dislike the direction of the propaganda.

Re: The Dangers of Microsoft Pluton

#88

Earlier quoted context omitted.

What you can install on YOUR pc will be at the sole mercy of microsoft/or maybe someone else.... That's the cusp of it. Not that it can be used for good, but that it sets the way for heavy misuse by large corporations. Wait a few years. Smaller companies won't even be allowed to order high end cpu's. You'll be at 100% mercy of these corporations. If after 2 years they decide to brick your pc, they'll just do it. You…

still waiting on the secure boot lockdown everyone has insisted is coming for the better part of two decades...

You may be right, of course. But if you read the article closely, it is already here.

The difference is for now you can still go to BIOS and enable Microsoft's key for 3rd party OS.

Maybe when Windows 12 comes out that option isn't there.

Re: The Dangers of Microsoft Pluton

#89
post #83
post #61

Earlier quoted context omitted.

Windows security models and policies are the enemy, not remote attestation (RA). RA is a technology that has its fair use, and can be desired for other systems, like in Linux. With a pure RA system your services can decide to trust or not those devices on your network that can be compromised, and report to other devices that there is something suspicious. As anything, this can be used properly to increase the securit…

Yes, lots of Linux devices apply it like that today: You can't use your banking app or consume DRM crippled media on your Android phone if you have root or run a open source Android distribution.

> if you have root

Because god forbid you have control of your own PC?

Re: The Dangers of Microsoft Pluton

#90
post #66

nowadays 98% of things implying "security" are actually unwanted products, protections for "the other side" or trivial distortions of reality where, conveyed by "security" itself, the user himself becomes the product - no, I don't need protections for the side channel, I never asked for them - no, I don't need a unique identifier, who is the demented person who asked you for it - no, I am not going to glitch the powe…

Yes ... I certainly look for chips WITHOUT certain "security features" when I'm building a system - makes it more difficult for the "bad guys" (really, just the greedy guys) to force me to do things the way they want.
Post reply on HN