Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

171–180 of 554 posts

Re: The Dangers of Microsoft Pluton

#171

What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…

Same with TPM and why it had so many critics. Some people still seem adamant to say that boot viruses are the greatest threat in the 21st century, but the economic interest are far more dangerous for general computing in my opinion. And it isn't even close.

Re: The Dangers of Microsoft Pluton

#172

Earlier quoted context omitted.

I would assume chinese made RISC-V have their own special sauce.

That's a big assumption.

...if the schematics and tapeouts are entirely public.

Otherwise you can be assured that there will be backdoors.

Re: The Dangers of Microsoft Pluton

#173
post #153
post #89

Earlier quoted context omitted.

> if you have root Because god forbid you have control of your own PC?

Uhm, these things don't really take away your control, rather, they shift it from you to you. The software you boot sets up some state and then toggles a bit, and after that something can't be changed. The state is secure against much modification after that time, but not before that time. The "you" that boots the device are in control, and the "you" that uses the device after that have exactly what "you" set up at b…

This is false and just redefining control.

Re: The Dangers of Microsoft Pluton

#174

Earlier quoted context omitted.

Quoted post unavailable.

In a sane society these features would allow secure voting. In this one... that's not what they'll be used for. This is the end game for the corporate internet. Not only can all your activity be logged, but if any of it is unwelcome - on any scale, from family to school to work to country to world - you can be locked out.

An operating system that prevents other operating systems from being installed is the equivalent of a citizen that becomes a dictator.

Re: The Dangers of Microsoft Pluton

#175
post #81

Earlier quoted context omitted.

... and this is why piracy will always continue to be a viable alternative.

Until access to the internet or methods of circumventing DRM are crippled without submitting to these technologies. That's the road we're heading down. Can't hack the current-gen Xbox, apparently. I'm wondering if someone will take that as a "challenge accepted".

> Can't hack the current-gen Xbox, apparently.

Yet.

Re: The Dangers of Microsoft Pluton

#176

What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…

Damn, now I'm nostalgic for the older days of hacker news where RMS was quoted every other post. The community is forgetting it's roots.

What fascinates me is that for many here software and tech is their livelihood. You should be able to take care of access and ensure future generations still have the same opportunities.

Sure, you can sell yourself and make good money with software on some proprietary app store with proprietary tools. You are a freelance employee of the company providing that infrastructure at that point.

It is short-sighted, lazy and stupid in my opinion. There is merit for such security mechanism, especially for cloud applications, but it should be crystal clear that there are secondary motivations here. And that the security argument often falls short if you take a good look at current threats.

Re: The Dangers of Microsoft Pluton

#178
post #143

Interesting naming. "Microsoft Hell God". Pluto (Greek: Πλούτων Plouton, "giver of wealth", Pluton in French and German) the most common name for the classical ruler of the underworld. Plouton was one of several euphemistic names for Hades, described in the Iliad as the god most hateful to mortals. https://en.wikipedia.org/wiki/Pluto_(mythology)

Well, they already use Kerberos, his dog.

Re: The Dangers of Microsoft Pluton

#179
post #66

nowadays 98% of things implying "security" are actually unwanted products, protections for "the other side" or trivial distortions of reality where, conveyed by "security" itself, the user himself becomes the product - no, I don't need protections for the side channel, I never asked for them - no, I don't need a unique identifier, who is the demented person who asked you for it - no, I am not going to glitch the powe…

Security has degraded to snake oil on a lot of topics. Boot infection are really rare and the whole TPM module isn't really needed in my opinion and I don't want it either for my systems. There are edge cases and sensible applications, but I don't want to see it as standard.

Re: The Dangers of Microsoft Pluton

#180

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

Because that doesn't work. 2h before someone complains to IT that he cannot write/read/delete said Word document. Then management says X indeed needs access. Now you have created a maintenance nightmare sourced in rather weird security requirements.

Could as well gouge out the eyes of everyone not having a read permission on said document. There are 1001 solution to solve such problems. And as a gigantic bonus it doesn't have to be bound to hardware! User permission management is much easier.

Post reply on HN