Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

231–240 of 554 posts

Re: The Dangers of Microsoft Pluton

#231
post #90
post #66

nowadays 98% of things implying "security" are actually unwanted products, protections for "the other side" or trivial distortions of reality where, conveyed by "security" itself, the user himself becomes the product - no, I don't need protections for the side channel, I never asked for them - no, I don't need a unique identifier, who is the demented person who asked you for it - no, I am not going to glitch the powe…

Yes ... I certainly look for chips WITHOUT certain "security features" when I'm building a system - makes it more difficult for the "bad guys" (really, just the greedy guys) to force me to do things the way they want.

What chips are left? When they've got Intel and AMD that's the vast majority right there. We really need some kind of open and transparent chip manufacturer who is unwilling to infest their product with user hostile code at Microsoft's demand.

Re: The Dangers of Microsoft Pluton

#232

Just to be clear, is this a case where you can't dual boot windows and another OS, or you can't boot another OS at all (in either case, the other OS being non Microsoft authorised)? Or something else entirely? Would it be possible to disable this at all, even that means you can't boot Windows?

You cannot boot the other OS at all if secure boot is enabled and Microsoft drops support for the 3rd party UEFI CA list. The machine will refuse to boot any kernel that has not been signed by the CAs already included in the machine. This is typically only Microsoft and sometimes the OEM like Lenovo or Dell.

Can't wait for EU antitrust and the courts to punish this attempt

Re: The Dangers of Microsoft Pluton

#233

Earlier quoted context omitted.

What you can install on YOUR pc will be at the sole mercy of microsoft/or maybe someone else.... That's the cusp of it. Not that it can be used for good, but that it sets the way for heavy misuse by large corporations. Wait a few years. Smaller companies won't even be allowed to order high end cpu's. You'll be at 100% mercy of these corporations. If after 2 years they decide to brick your pc, they'll just do it. You…

still waiting on the secure boot lockdown everyone has insisted is coming for the better part of two decades...

It creeps closer with every release, and is the status quo for arm devices (including windows ones).

It's only through constant vigilance and fighting back that it has been slowed dowm by two decades.

Re: The Dangers of Microsoft Pluton

#234

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

Author has a bias against Microsoft. So do hacker news readers.

News of Pluton and its security goals have been readily available since 2020 from reputable hardware sites like Anandtech, or directly from Microsoft themselves. There's nothing new or hidden or surprising about it unless you live to dream up Microsoft conspiracy theories.

Many other hardware manufacturers have similar security offerings including Intel and Apple. Microsoft is arguably late to the game here, given their only recent interest in PC hardware. OS integration isn't even new. Macs have been shipping with T1 and T2 chips for over five years. Has the sky fallen on that ecosystem?

Re: The Dangers of Microsoft Pluton

#235
post #9
post #6

Earlier quoted context omitted.

Quoted post unavailable.

Simple solution: don't care about up or down -votes. Believe me, Internet points are a sham and waste of time. Focus on interesting conversations and connections instead.

you can't have an interesting conversations if it takes 3 or so powerusers to gag you

I see tons of interesting comments flagged/dead within minutes. there are rarely controversial, or low-quality, or rule-breaking

there are plenty of topics you are only allowed to express a pre-approved opinion about, and I can't even give you examples without getting muted

Re: The Dangers of Microsoft Pluton

#236

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

The capacity for abuse is huge, way beyong the potential benefits. From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly. Those kind of people will abuse such system to prevent things to be shared. It will be used for putting DRM on everything and create a more and more closed web. It will be used by corporations…

> From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly.

Books are not banned, just not used in the classroom anymore. While the reasons for it may be wrong, it's something that happens constantly all over the world. No one prevents children or adults to read those books at home. Banning books could mean that owning them is illegal and that just hasn't happened.

Re: The Dangers of Microsoft Pluton

#237
post #98

Earlier quoted context omitted.

That's an invalid argument for multiple reasons, not the least of which is that some people can afford just one device. That device is likely to be a smartphone because everything is slowly moving in the direction of requiring one. If I need to spend extra money to get an additional "freedom device" and can't afford it, I just won't have one and will miss out on the good stuff.

Welcome to the 8 and 16 bit home computer days when OSes were written in ROMs.

Those OSes were distributed on ROM by necessity, because that was the most cost effective option available. Any modern limitations that prevent running your own software are not just artificial, but actually require additional effort to implement bootloader locking/integrity checks.

Re: The Dangers of Microsoft Pluton

#238

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

Author has a bias against Microsoft. So do hacker news readers. News of Pluton and its security goals have been readily available since 2020 from reputable hardware sites like Anandtech, or directly from Microsoft themselves. There's nothing new or hidden or surprising about it unless you live to dream up Microsoft conspiracy theories. Many other hardware manufacturers have similar security offerings including Intel…

And that's why Microsoft needs to include such a chip. If we move to a world where security is enforced more and more by hardware, you'll need a device that can participate.

Re: The Dangers of Microsoft Pluton

#239

Earlier quoted context omitted.

What you can install on YOUR pc will be at the sole mercy of microsoft/or maybe someone else.... That's the cusp of it. Not that it can be used for good, but that it sets the way for heavy misuse by large corporations. Wait a few years. Smaller companies won't even be allowed to order high end cpu's. You'll be at 100% mercy of these corporations. If after 2 years they decide to brick your pc, they'll just do it. You…

still waiting on the secure boot lockdown everyone has insisted is coming for the better part of two decades...

>As of January 2021 deleting SecureBoot keys and installing your own keys (for example by using KeyTool) will brick the device. This is a problem that is similar to one which has been reported on some other Lenovo laptops [0] and is likely due to a faulty firmware. If the device is stuck in a boot loop after replacing the SecureBoot keys, the only way to repair it is by replacing the mainboard of the device.

[0] https://forums.lenovo.com/t5/ThinkPad-X-Series-Laptops/BIOS-...

From https://wiki.archlinux.org/title/Lenovo_ThinkPad_T14/T14s_(I...

Re: The Dangers of Microsoft Pluton

#240

Earlier quoted context omitted.

Ron DeSantis doesn't need hardware-level DRM to ban math books. https://www.baynews9.com/fl/tampa/news/2022/05/06/florida-ba... If you're worried about book bannings in states like Florida, DeSantis is up for reelection in just over 3 months . Go volunteer or donate money to his opponent (probably Charlie Crist).

Technologists often have such tunnel vision that limits their concerns to tyranny driven by technology when there's plenty of low tech attacks on open society all the time. It reminds me of the good old "my password takes 2 billion years to crack, but my kneecaps only take a few seconds" metaphor about people in tech forgetting that physical coercion is, in fact, a possible attack vector for your IT security.

The low tech attacks often have low tech workarounds. DeSantis may "ban" a math book but there's nothing stopping a Florida resident from buying it and giving it to a child. There's plenty of other marketplaces and similar publishers I can pull from.

When computing is controlled at a hardware level, you have far fewer competitors and market places. Working around things can be significantly more difficult and you may be stuck with scrapping up old less capable tech trying to do something you should have better options for. This is the reason technologists fear technology control, not so much because of tunnel vision but because the general population can't work around it, even experts may not be able to work around such protections. Low tech always has easy work arounds--the option exists even if you may fear the consequences.

Post reply on HN