Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

211–220 of 554 posts

Re: The Dangers of Microsoft Pluton

#211
This is exactly what big corporations ask for. In the pharmaceutical industry stakes are very high and directed attacks are common. It is just the next step securing your IT.

However, for private users these are dark capabilities.

Re: The Dangers of Microsoft Pluton

#212

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

Yeah I totally would like all "doomsday scenarios" in my company, non ironically.

Re: The Dangers of Microsoft Pluton

#213

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

what's stopping someone from taking photos of your precious document and posting them on 4chan?

nothing. there's nothing you can do to stop that.

Re: The Dangers of Microsoft Pluton

#214
post #143

Interesting naming. "Microsoft Hell God". Pluto (Greek: Πλούτων Plouton, "giver of wealth", Pluton in French and German) the most common name for the classical ruler of the underworld. Plouton was one of several euphemistic names for Hades, described in the Iliad as the god most hateful to mortals. https://en.wikipedia.org/wiki/Pluto_(mythology)

And the processor etc are under the operating system.

Re: The Dangers of Microsoft Pluton

#215

Earlier quoted context omitted.

Same with TPM and why it had so many critics. Some people still seem adamant to say that boot viruses are the greatest threat in the 21st century, but the economic interest are far more dangerous for general computing in my opinion. And it isn't even close.

Can you explain what is the issue with TPM? I get the issue with Pluton but TPM is only a dedicated and certified secure key and random number generator that does a better job than CPUs doing it in software, and it's also a secure enclave for storing your encryption keys. Would you rather store the keys in memory where they can be easily grabbed by malicious apps like Mimikatz? Macs had the same feature for years in…

Among that, the TPM enables verification of a particular state of your system, i.e., a particular set of binaries and OS configuration. Simplifying the description of the process a bit - at every bootup it checks the checksum of all programs loaded at every boot stage (UEFI, kernel, userspace) with respect to one that is known to be approved - process called "attestation".

So in worst case, if your attestation server is very strict, any new binary installed on your machine will prevent it from booting or satisfying the attestation. This is the main concern that TPM enables.

Re: The Dangers of Microsoft Pluton

#216

Earlier quoted context omitted.

Same with TPM and why it had so many critics. Some people still seem adamant to say that boot viruses are the greatest threat in the 21st century, but the economic interest are far more dangerous for general computing in my opinion. And it isn't even close.

Can you explain what is the issue with TPM? I get the issue with Pluton but TPM is only a dedicated and certified secure key and random number generator that does a better job than CPUs doing it in software, and it's also a secure enclave for storing your encryption keys. Would you rather store the keys in memory where they can be easily grabbed by malicious apps like Mimikatz? Macs had the same feature for years in…

TPM is part of the system that means I can't my phone for wireless payment or use all sorts of other apps if I also want to do something outlandish like record phone calls, change the theme or delete Facebook... and everything it achieves can be done by other means anyway, making the device's owner a 2nd class citizen is a lazy solution.

Re: The Dangers of Microsoft Pluton

#217

Earlier quoted context omitted.

Same with TPM and why it had so many critics. Some people still seem adamant to say that boot viruses are the greatest threat in the 21st century, but the economic interest are far more dangerous for general computing in my opinion. And it isn't even close.

So basically, Cory Doctorow's "The Upcoming War Against General Computation" ? https://boingboing.net/2011/12/27/the-coming-war-on-general-... https://github.com/jwise/28c3-doctorow/blob/master/transcrip... Don't know enough about the subject to tell if his "attempts to control general computation will converge on rootkits" prediction has held up.

To this talk, there exists a less well-known sequel:

DEF CON 23 - Cory Doctorow - Fighting Back in the War on General Purpose Computers

https://www.youtube.com/watch?v=pT6itfUUsoQ

Re: The Dangers of Microsoft Pluton

#218

The NSA and other three-letter US agencies will be all inside this chip, or have side-channels to the firmware update mechanism, obviously. A secure operating system means nothing if the hardware itself cannot be secured, and the case for a new, trusted, transparent manufacturer of Intel-compatible CPUs and hardware in general grows stronger.

It's not out of the question.

Though I get the feeling we're missing the forest in the trees. Smartphones with proprietary basebands have been here for more than a decade or so. It's not only Intel-compatible we need, it would really take legislation to turn all these things more transparent or controllable.

Re: The Dangers of Microsoft Pluton

#219

Earlier quoted context omitted.

The capacity for abuse is huge, way beyong the potential benefits. From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly. Those kind of people will abuse such system to prevent things to be shared. It will be used for putting DRM on everything and create a more and more closed web. It will be used by corporations…

Ron DeSantis doesn't need hardware-level DRM to ban math books. https://www.baynews9.com/fl/tampa/news/2022/05/06/florida-ba... If you're worried about book bannings in states like Florida, DeSantis is up for reelection in just over 3 months . Go volunteer or donate money to his opponent (probably Charlie Crist).

Did they actually ban the books, or did they merely ban their usage in K-12 instruction with the news outlet rounding that up to a book ban for dramaturgical reasons? Not that a ban in school instruction is necessarily good (though, I would guess, not nearly as rare), but the actual full-fledged ban that DRM could aid in enforcing, which would prevent you as an individual from reading a book you want to read in _any_ plausible context, is on a different level.

Re: The Dangers of Microsoft Pluton

#220
post #143

Interesting naming. "Microsoft Hell God". Pluto (Greek: Πλούτων Plouton, "giver of wealth", Pluton in French and German) the most common name for the classical ruler of the underworld. Plouton was one of several euphemistic names for Hades, described in the Iliad as the god most hateful to mortals. https://en.wikipedia.org/wiki/Pluto_(mythology)

maybe its because pluto is the "king of the underworld", the underworld being the root of trust?

> the underworld being the root of trust

Pun intended?

Post reply on HN