Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

151–160 of 554 posts

Re: The Dangers of Microsoft Pluton

#151
post #145
post #72

Regardless, I think that the pc platform deserves a good anti cheat solution. Separating the groups of those who have a good anti cheat system enabled (such as this) and those who don’t is a good compromise for everybody. I think more reasonable companies such as Valve will go that way.

Anything that prevents me from modding or cheating in my single player games is anathema to me. And companies like Activision, Ubisoft and Rockstar would love a hardware-based system that takes control away from gamers.

I didn’t say anything about single player games.

Re: The Dangers of Microsoft Pluton

#152
post #82
post #73

Earlier quoted context omitted.

Good anti-cheat solution is server side AI. Anything client side is malware.

I know that this is a popular take here, which is why I proposed that there should be a mechanism to opt out. But that would mean that you would have to play against those who opted out as well.

I would like to have an anti-cheat mechanism (that works), not a god damned security-nightmare rootkit that scans and uploads my private files to god knows where.

Re: The Dangers of Microsoft Pluton

#153
post #89
post #83

Earlier quoted context omitted.

Yes, lots of Linux devices apply it like that today: You can't use your banking app or consume DRM crippled media on your Android phone if you have root or run a open source Android distribution.

> if you have root Because god forbid you have control of your own PC?

Uhm, these things don't really take away your control, rather, they shift it from you to you.

The software you boot sets up some state and then toggles a bit, and after that something can't be changed. The state is secure against much modification after that time, but not before that time.

The "you" that boots the device are in control, and the "you" that uses the device after that have exactly what "you" set up at boot time, neither more nor less. If both "you" are the same person, then there's no loss of control.

But of course they're often not really the same person. If you want to boot a Microsoft-signed image, the party that boots is more or less Microsoft, not you personally. But in that case, you also want to use that Microsoft-signed OS, right? So the shift towards boot-time control is then a shift from mostly-Microsoft use-time control to mostly-Microsoft boot-time control. Mostly Microsoft here, mostly Microsoft there, even if the two mostlies aren't quite the same percentage it's difficult to regard this as a significant loss of control.

Re: The Dangers of Microsoft Pluton

#154
The NSA and other three-letter US agencies will be all inside this chip, or have side-channels to the firmware update mechanism, obviously.

A secure operating system means nothing if the hardware itself cannot be secured, and the case for a new, trusted, transparent manufacturer of Intel-compatible CPUs and hardware in general grows stronger.

Re: The Dangers of Microsoft Pluton

#156

Earlier quoted context omitted.

Damn, now I'm nostalgic for the older days of hacker news where RMS was quoted every other post. The community is forgetting it's roots.

That sounds more like /. than HN.

There was a time when someone ran a bot on /g/ where every post that mentioned just 'Linux' would get the full 'Excuse me...' copypasta interjected. Good times.

Re: The Dangers of Microsoft Pluton

#157
post #89
post #83

Earlier quoted context omitted.

Yes, lots of Linux devices apply it like that today: You can't use your banking app or consume DRM crippled media on your Android phone if you have root or run a open source Android distribution.

> if you have root Because god forbid you have control of your own PC?

I think this is more for Android phones, and preventing a malicious app on your phone from using the root access to hijack data from your banking app.

Re: The Dangers of Microsoft Pluton

#158

Earlier quoted context omitted.

Quoted post unavailable.

> pornographic examples in it I can't fathom a math textbook with pornographic examples. Is this a thing in the US?

>> pornographic examples in it

>I can't fathom a math textbook with pornographic examples. Is this a thing in the US?

I've been out of school for quite a while, but AFAIK while there is plenty of porn out there, it's not in our math books.

No, it's just Florida politicos pandering to their base[0].

I'm guessing that what GP is going on about (please do correct me if I'm wrong) is probably some word problems that include references to non-heterosexual/non-binary folks, which seems to trigger the intolerant among us.

Which is a result of decades of attempts to put christian dogma and ideology back into US public schools, and failing that, destroy the public school system.

And more's the pity.

[0] https://www.politico.com/news/2022/05/05/fldoe-releases-math...

Edit: Added the missing link.

Re: The Dangers of Microsoft Pluton

#159
post #127
post #94

Earlier quoted context omitted.

Well, don't put that on a personal device. It's like your company giving you serious protecting gear to wear while doing your work on a nuclear reactor is a good thing. But having to wear such gear at home is not a popular choice, and should not be required.

How do you choose what you put in your CPU? What when Windows forces you to have that kind of hardware? You can choose not to wear that gear, but choosing to not use Windows is much more complicated, at least for most people.

I imagine if the proponents of these systems had their way, they'd add remote attestation to websites too. Imagine your bank's website only loading on a "secure" windows environment, non-rooted android phone or an iphone.

Once these chips are in everyone's devices, it would be quite easy to add this stuff technically. And in doing so, break the web on non-approved hardware or software (like linux).

Edit: Actually on the subject of worst case scenarios: If the trusted computing attestation process was extended through the web browser, it would be possible to build a website which is impossible to scrape or interact with in any unapproved way, from any unapproved device. Eat your heart out Aaron Schwartz.

Post reply on HN