Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

221–230 of 554 posts

Re: The Dangers of Microsoft Pluton

#221

Earlier quoted context omitted.

> imagine if the proponents of these systems had their way, they'd add remote attestation to websites too. Imagine your bank's website only loading on a "secure" windows environment, non-rooted android phone or an iphone. Actually, IIUC this is already the case on Android[0]. Some (many? most?) banks/banking apps are rejecting (and/or complaining about) access from rooted phones right now . I can't confirm this perso…

Yes, this is already the case on Android. Two years ago I canceled smart-id contract ( https://www.smart-id.com/ ) and stopped using any "smart" devices. Because one day the smart-id app ceased to work on my rooted smartphone. Soon my old 3G dumbphone will be useless as the mobile operator ends the service. People are pushed to newer phones^W surveillance devices and I have to hunt for real 2G phone soon.

Your 3G dumbphone is not as dumb as you think. Considering the threat models from that era, it's most likely more manageable remotely and less compartmentalised.

Btw, you could acquire a Mobile-ID SIM that will work on a rooted phone (but also with feature phones, if you wish).

Re: The Dangers of Microsoft Pluton

#223

Earlier quoted context omitted.

Can you explain what is the issue with TPM? I get the issue with Pluton but TPM is only a dedicated and certified secure key and random number generator that does a better job than CPUs doing it in software, and it's also a secure enclave for storing your encryption keys. Would you rather store the keys in memory where they can be easily grabbed by malicious apps like Mimikatz? Macs had the same feature for years in…

TPM is part of the system that means I can't my phone for wireless payment or use all sorts of other apps if I also want to do something outlandish like record phone calls, change the theme or delete Facebook... and everything it achieves can be done by other means anyway, making the device's owner a 2nd class citizen is a lazy solution.

I've always heard this argument but never understood it, what other ways are available to have a SRTM?

Re: The Dangers of Microsoft Pluton

#224

Earlier quoted context omitted.

Technologists often have such tunnel vision that limits their concerns to tyranny driven by technology when there's plenty of low tech attacks on open society all the time. It reminds me of the good old "my password takes 2 billion years to crack, but my kneecaps only take a few seconds" metaphor about people in tech forgetting that physical coercion is, in fact, a possible attack vector for your IT security.

This is not an Xor proposition. It's like saying "don't worry about gun control because car accidents kill way more people right now".

But I never said it's not a problem. I said the priorities are wrong.

Establishing technical means to do something (limiting access to files via DRM) is not as urgent as actually doing it (Florida carting books out of school libraries). And technology is not a monolith. Pluton specifically is far from being a universal requirement on Windows, and the entire PC platform is open enough to support alternatives for a very long time. It's possibly worrying (though it looks like Microsoft's intention is confidentiality management in enterprises for now), but far from "turnkey tyranny".

Re: The Dangers of Microsoft Pluton

#225

Earlier quoted context omitted.

> imagine if the proponents of these systems had their way, they'd add remote attestation to websites too. Imagine your bank's website only loading on a "secure" windows environment, non-rooted android phone or an iphone. Actually, IIUC this is already the case on Android[0]. Some (many? most?) banks/banking apps are rejecting (and/or complaining about) access from rooted phones right now . I can't confirm this perso…

Yes, this is already the case on Android. Two years ago I canceled smart-id contract ( https://www.smart-id.com/ ) and stopped using any "smart" devices. Because one day the smart-id app ceased to work on my rooted smartphone. Soon my old 3G dumbphone will be useless as the mobile operator ends the service. People are pushed to newer phones^W surveillance devices and I have to hunt for real 2G phone soon.

My operator terminated its 2G network last year, forcing me to upgrade to a 3G phone. Let's hope your operator won't do the same thing.

Re: The Dangers of Microsoft Pluton

#226

Earlier quoted context omitted.

I'm not really worried myself that alternative Operating Systems will be locked out. However, I am concerned that the functionality of alternative Operating Systems will be locked out. If you see the (speculative but grounded) area near the end of the article - imagine if assertion becomes popular for things such as games or digital movies or the school WiFi. Your Linux PC will never be able to do that, and WINE (pro…

> imagine if assertion becomes popular for things such as [...] digital movies You don't need that. Streaming is already crippled on Linux. Hell, Netflix won't even stream full quality on Chrome! > https://help.netflix.com/en/node/13444 4K Ultra HD on a computer Netflix is available in Ultra HD on Windows and Mac computers with: Microsoft Edge for Windows Windows app for Windows 10 and Windows 11 Safari for MacOS 11.…

Fun fact, that app hasn't been updated in years. It's super buggy.

It's a nice demonstration how vendors won't bother to improve if the user has no choice.

Re: The Dangers of Microsoft Pluton

#227
post #81

Earlier quoted context omitted.

... and this is why piracy will always continue to be a viable alternative.

Until access to the internet or methods of circumventing DRM are crippled without submitting to these technologies. That's the road we're heading down. Can't hack the current-gen Xbox, apparently. I'm wondering if someone will take that as a "challenge accepted".

There's always the analog loophole.

Re: The Dangers of Microsoft Pluton

#228

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

It doesn't protect from malicious document leakage: you can still take screenshots or photographs or use a plain txt file. For unintentional leakage, MSIP already does what you are saying this just bakes into hardware where patching/fixes are harder than the cloud

Re: The Dangers of Microsoft Pluton

#229
post #2

Ew. Why are all the chip manufacturers going along with this stupid plan? I want to buy a processor and then own it and have it work in my best interests, not consume electricity and generatie heat enforcing draconian 3rd party DRM policies.

Alphabet soup, probably, along with iphone profitability.

Re: The Dangers of Microsoft Pluton

#230

Earlier quoted context omitted.

Security has degraded to snake oil on a lot of topics. Boot infection are really rare and the whole TPM module isn't really needed in my opinion and I don't want it either for my systems. There are edge cases and sensible applications, but I don't want to see it as standard.

> Boot infection are really rare Gee I wonder why. /s Such statements are tedious to say the least, preventions have been implemented, obviously it curtails such abuse, obviously that reduces frequency. > the whole TPM module isn't really needed in my opinion It's nice that you have no key material that would need to be kept strictly on the device, but a lot of users actually do. We don't want people's Webauthn token…

> Gee I wonder why

The frequency dropped even before TPM was deployed on most machines and I guess most systems still haven't it enabled today. Reason for that is that there are simply more direct and profitable ways to get system access, see most applications of ransomware for example.

> It's nice that you have no key material

You can use many different types of authenticators. If you use Windows Hello you need TPM and they try to hinder you adding alternative means without TPM being activated. But that is a different story and solely on Microsoft. No need to falsely or passive aggressively suggest that a system would be insecure without these specific means.

Post reply on HN