Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

201–210 of 554 posts

Re: The Dangers of Microsoft Pluton

#201

What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…

> Remote attestation is the true enemy of your freedom. Technology is a tool. What is true however is that under the current way how the economy is structured remote attestation weakens freedoms of individuals mostly. If Facebook was under remote attestation that private information was only used in limited and specific ways and even the NSA can not get to them without breaking the remote attestation, that would be a…

But it'd make a lot of whistleblowing impossible too

Re: The Dangers of Microsoft Pluton

#202

Earlier quoted context omitted.

I imagine if the proponents of these systems had their way, they'd add remote attestation to websites too. Imagine your bank's website only loading on a "secure" windows environment, non-rooted android phone or an iphone. Once these chips are in everyone's devices, it would be quite easy to add this stuff technically. And in doing so, break the web on non-approved hardware or software (like linux). Edit: Actually on…

> imagine if the proponents of these systems had their way, they'd add remote attestation to websites too. Imagine your bank's website only loading on a "secure" windows environment, non-rooted android phone or an iphone. Actually, IIUC this is already the case on Android[0]. Some (many? most?) banks/banking apps are rejecting (and/or complaining about) access from rooted phones right now . I can't confirm this perso…

Yes, this is already the case on Android. Two years ago I canceled smart-id contract (https://www.smart-id.com/) and stopped using any "smart" devices. Because one day the smart-id app ceased to work on my rooted smartphone.

Soon my old 3G dumbphone will be useless as the mobile operator ends the service. People are pushed to newer phones^W surveillance devices and I have to hunt for real 2G phone soon.

Re: The Dangers of Microsoft Pluton

#203
post #4
post #2

Ew. Why are all the chip manufacturers going along with this stupid plan? I want to buy a processor and then own it and have it work in my best interests, not consume electricity and generatie heat enforcing draconian 3rd party DRM policies.

The market (software/system builders) say that locked down platforms like the iPhone are fabulously profitable. Sorry.

So is war. Don't reproduce.

Re: The Dangers of Microsoft Pluton

#205
post #120

Earlier quoted context omitted.

The capacity for abuse is huge, way beyong the potential benefits. From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly. Those kind of people will abuse such system to prevent things to be shared. It will be used for putting DRM on everything and create a more and more closed web. It will be used by corporations…

In the UK movie screening used to be and probably still is decided at the smallest municipal level of town councils, see The Life of Brian.

District councils (so the second 'lowest' of the possible tiers) but yes. In practice, they've all deferred to the judgement of the British Board of Film Classification (née ...Film Censorship) for nearly every film since it was set up.

Re: The Dangers of Microsoft Pluton

#206
post #105

Earlier quoted context omitted.

Librem 5 and Pinephone smartphones are general-purpose computers.

Up to the community to prove their have a market value to be kept around and aren't yet another OpenMoko.

That is precisely the proof I need before I ever buy into either. I'm very optimistic about PinePhone but AIUI it's currently quite far from being a reliable daily driver for the kinds of tasks I need one for.

Re: The Dangers of Microsoft Pluton

#207
post #89
post #83

Earlier quoted context omitted.

Yes, lots of Linux devices apply it like that today: You can't use your banking app or consume DRM crippled media on your Android phone if you have root or run a open source Android distribution.

> if you have root Because god forbid you have control of your own PC?

For me that’s a problem for the average user? That’s everyone else’s problem that idiots don’t care to control their technology and need big tech to do so with an iron fist

Re: The Dangers of Microsoft Pluton

#208

What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…

Same with TPM and why it had so many critics. Some people still seem adamant to say that boot viruses are the greatest threat in the 21st century, but the economic interest are far more dangerous for general computing in my opinion. And it isn't even close.

Can you explain what is the issue with TPM?

I get the issue with Pluton but TPM is only a dedicated and certified secure key and random number generator that does a better job than CPUs doing it in software, and it's also a secure enclave for storing your encryption keys. Would you rather store the keys in memory where they can be easily grabbed by malicious apps like Mimikatz? Macs had the same feature for years in the T2 chip.

It's the exact system that enables wireless payment and other strong security features on your phone.

So having TPM on PCs and using it for its interested purpose is a boon for everyone's security so I don't see the issue, just FUD.

Re: The Dangers of Microsoft Pluton

#209

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

The difference between ransomware/spyware/extortion/espionage and whistleblowing/free sharing of information is just one of perspective.

Re: The Dangers of Microsoft Pluton

#210
post #143

Interesting naming. "Microsoft Hell God". Pluto (Greek: Πλούτων Plouton, "giver of wealth", Pluton in French and German) the most common name for the classical ruler of the underworld. Plouton was one of several euphemistic names for Hades, described in the Iliad as the god most hateful to mortals. https://en.wikipedia.org/wiki/Pluto_(mythology)

Hey, did I tell you I use Doric Arch? No MS here!
Post reply on HN