Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

191–200 of 554 posts

Re: The Dangers of Microsoft Pluton

#191
i think this is simply Microsoft noticing Nike's embrace of Taking a Stance for the Bottom Line.

microsoft is smart enough to realize that NSA tinfoil types already do not trust them, and likely will never trust them (which, if you are that worried about security, why are you on windows anyway? NSAKEY?)

the predominant share of windows machines are sold to businesses and enterprises who DO want to lock down at a hardware level.

it's way too easy to steal a windows machine and wipe it clean. you can't do that with DEP-enrolled macs because of the TPM they already have, which is a strange misalignment when Windows' core market (enterprise) really cares about this kind of security.

apple has every reason to care about DRM more than microsoft, but the TPM advent on mac was mostly a welcomed one as I recall. perhaps that is because apple has taken a strong and public stance towards user privacy. but they have to: it is consumers who are buying their devices, and consumers rightly want a device that works for them.

microsoft is not in that position, or at least, is not with windows, from an economic standpoint. similarly, they are mostly selling to enterprises and business and governments for this product line, and those customers rightly want a device that is verifiably secure.

if you're worried about security for your personal use, buy a mac, because they've made their bottom line and your privacy intertwined. or, buy a linux box and purity check it down to the circuits. you have already decided against convenience in your trade-off equation by your a priori decision to care about this in the first place.

Re: The Dangers of Microsoft Pluton

#192
post #143

Interesting naming. "Microsoft Hell God". Pluto (Greek: Πλούτων Plouton, "giver of wealth", Pluton in French and German) the most common name for the classical ruler of the underworld. Plouton was one of several euphemistic names for Hades, described in the Iliad as the god most hateful to mortals. https://en.wikipedia.org/wiki/Pluto_(mythology)

Well, they already use Kerberos, his dog.

But they also have winsock trumpet. They need to pick a lane, I can't deal with the oscillation between goofy and evil.

Re: The Dangers of Microsoft Pluton

#193

Earlier quoted context omitted.

That's a big assumption.

...if the schematics and tapeouts are entirely public. Otherwise you can be assured that there will be backdoors.

You can post hoc modify circuits so they look like doing logic A but they actually do logic B by adding new p or n junctions.

Re: The Dangers of Microsoft Pluton

#194

Earlier quoted context omitted.

Could this be disabled by the user? Presumably doing so would mean you cannot boot Windows, but if thats a trade off Microsoft is forcing me to make, I'll accept it. If you can't, it goes without saying that that is unacceptable

You can disable it for now. But there is no guarantee that you will always be able to. Personally I think its very likely MS will eventually push to strongarm OEMs into locking secure boot to be enabled. All it will take is another round of "security improvements" and the public eats it up. The market would then fragment into laptops that can only run Windows and maybe more expensive laptops that allow you to disable…

> Personally I think its very likely MS will eventually push to strongarm OEMs into locking secure boot to be enabled.

Not as long as the EU remains functioning.

Re: The Dangers of Microsoft Pluton

#195

Just to be clear, is this a case where you can't dual boot windows and another OS, or you can't boot another OS at all (in either case, the other OS being non Microsoft authorised)? Or something else entirely? Would it be possible to disable this at all, even that means you can't boot Windows?

You cannot boot the other OS at all if secure boot is enabled and Microsoft drops support for the 3rd party UEFI CA list. The machine will refuse to boot any kernel that has not been signed by the CAs already included in the machine. This is typically only Microsoft and sometimes the OEM like Lenovo or Dell.

This matched my guess: it's about MS extracting a $x per machine tax on all non-MS OSs to stay on their certificate list. Same playbook they've used on Android.

Re: The Dangers of Microsoft Pluton

#196
post #143

Interesting naming. "Microsoft Hell God". Pluto (Greek: Πλούτων Plouton, "giver of wealth", Pluton in French and German) the most common name for the classical ruler of the underworld. Plouton was one of several euphemistic names for Hades, described in the Iliad as the god most hateful to mortals. https://en.wikipedia.org/wiki/Pluto_(mythology)

maybe its because pluto is the "king of the underworld", the underworld being the root of trust?

Re: The Dangers of Microsoft Pluton

#197

Earlier quoted context omitted.

> pornographic examples in it I can't fathom a math textbook with pornographic examples. Is this a thing in the US?

>> pornographic examples in it >I can't fathom a math textbook with pornographic examples. Is this a thing in the US? I've been out of school for quite a while, but AFAIK while there is plenty of porn out there, it's not in our math books. No, it's just Florida politicos pandering to their base[0]. I'm guessing that what GP is going on about (please do correct me if I'm wrong) is probably some word problems that incl…

Music videos are now porn!

Re: The Dangers of Microsoft Pluton

#198

What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…

Same with TPM and why it had so many critics. Some people still seem adamant to say that boot viruses are the greatest threat in the 21st century, but the economic interest are far more dangerous for general computing in my opinion. And it isn't even close.

So basically, Cory Doctorow's "The Upcoming War Against General Computation"?

https://boingboing.net/2011/12/27/the-coming-war-on-general-...

https://github.com/jwise/28c3-doctorow/blob/master/transcrip...

Don't know enough about the subject to tell if his "attempts to control general computation will converge on rootkits" prediction has held up.

Re: The Dangers of Microsoft Pluton

#199
post #87

Earlier quoted context omitted.

Mein Kampf is a banned book which I don't think many would disagree with. There are many other such books filled with propaganda that are rightly banned. I don't see why other propaganda-filled books that are being pushed on unsuspecting children shouldn't be banned too, unless the only reason is that you dislike the direction of the propaganda.

Mein Kampf is not banned in my country, I can buy it, and I think everybody should be able to read it. You cannot defend against something you don't understand. Reading it (or the little red book), you will notice there is nothing incredible about it. It's a good way to understand the banality of evil. It's a good way to see what currently in our society echoes it: we are not freed from evil, it can come back any tim…

Ironically Harry Potter was banned at my school. (Witchcraft!)

Re: The Dangers of Microsoft Pluton

#200
post #66

nowadays 98% of things implying "security" are actually unwanted products, protections for "the other side" or trivial distortions of reality where, conveyed by "security" itself, the user himself becomes the product - no, I don't need protections for the side channel, I never asked for them - no, I don't need a unique identifier, who is the demented person who asked you for it - no, I am not going to glitch the powe…

Security has degraded to snake oil on a lot of topics. Boot infection are really rare and the whole TPM module isn't really needed in my opinion and I don't want it either for my systems. There are edge cases and sensible applications, but I don't want to see it as standard.

> Boot infection are really rare

Gee I wonder why. /s Such statements are tedious to say the least, preventions have been implemented, obviously it curtails such abuse, obviously that reduces frequency.

> the whole TPM module isn't really needed in my opinion

It's nice that you have no key material that would need to be kept strictly on the device, but a lot of users actually do. We don't want people's Webauthn tokens carried away, we don't want Bitlocker keys stolen, most certainly we do not want biometric authentication data stolen. Maybe you have reduced that risk to near zero, but that's not the case for the vast majority of users.

Post reply on HN