Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

251–260 of 554 posts

Re: The Dangers of Microsoft Pluton

#251
post #241

Earlier quoted context omitted.

What you can install on YOUR pc will be at the sole mercy of microsoft/or maybe someone else.... That's the cusp of it. Not that it can be used for good, but that it sets the way for heavy misuse by large corporations. Wait a few years. Smaller companies won't even be allowed to order high end cpu's. You'll be at 100% mercy of these corporations. If after 2 years they decide to brick your pc, they'll just do it. You…

Secure chips like this are already in all devices but PCs. And in none of these areas has any of that happened. Quite the opposite, Apple got a fine when they slowed down older devices to save battery (at least what they said). So the government will clearly help out here. And none of these companies has an incentives to stop sales to smaller companies, they make a lot of money with those.

> Secure chips like this are already in all devices but PCs. And in none of these areas has any of that happened.

Ah, that must be why we all have root access and can freely modify or install anything we want on every device we own! Oh, wait, we don't have those things and our non-PC systems are increasingly locked down and routinely do things against the wishes of the people who own them.

Re: The Dangers of Microsoft Pluton

#252
post #87

Earlier quoted context omitted.

Mein Kampf is a banned book which I don't think many would disagree with. There are many other such books filled with propaganda that are rightly banned. I don't see why other propaganda-filled books that are being pushed on unsuspecting children shouldn't be banned too, unless the only reason is that you dislike the direction of the propaganda.

Mein Kampf was not banned in Germany either. It is just that after Hitler's death, having no heirs, the state of Bavaria got the printing rights and decided not to allow printing of them (there was a heavily commented version made for academics like a study bible). Meaning all prints violated copyright until the book enters public domain.

Shouldn't this be considered as strong evidence that copyright is just censorship?

Re: The Dangers of Microsoft Pluton

#253
post #89

Earlier quoted context omitted.

> if you have root Because god forbid you have control of your own PC?

For me that’s a problem for the average user? That’s everyone else’s problem that idiots don’t care to control their technology and need big tech to do so with an iron fist

Calling the problem is “idiots” is a cognitive trap which prevents you from meaningfully dealing with it. Everyone is at risk from zero-days, almost anyone can be phished (yes, this includes you), many people have no way or time to investigate whether some well-known vendor is misrepresenting their product, and even security experts have to trust other people on a daily basis because they don’t have time to reverse-engineer every software update. Most people who get snide about this are a single malicious package in their favorite programming language away from a big mess!

The best progress we’ve seen in decades came from most people using locked-down phone operating systems, followed by stricter desktop OSes. If you don’t like that trajectory, you should be focused on how to get the benefits with other trade offs. One of the first steps is respecting people enough to understand their needs rather than calling them idiots.

Re: The Dangers of Microsoft Pluton

#255

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

what's stopping someone from taking photos of your precious document and posting them on 4chan? nothing. there's nothing you can do to stop that.

I can discretely copy GBs of email messages and word docs in a reasonable amount of time, but I couldn't discretely take cell phone pictures of every page of every one of those messages and documents if I had years to do it. You don't always have to prevent something 100% of the time in every possible situation to have a devastating effect on people who want to do that thing.

Re: The Dangers of Microsoft Pluton

#256

Earlier quoted context omitted.

> Boot infection are really rare Gee I wonder why. /s Such statements are tedious to say the least, preventions have been implemented, obviously it curtails such abuse, obviously that reduces frequency. > the whole TPM module isn't really needed in my opinion It's nice that you have no key material that would need to be kept strictly on the device, but a lot of users actually do. We don't want people's Webauthn token…

> Gee I wonder why The frequency dropped even before TPM was deployed on most machines and I guess most systems still haven't it enabled today. Reason for that is that there are simply more direct and profitable ways to get system access, see most applications of ransomware for example. > It's nice that you have no key material You can use many different types of authenticators. If you use Windows Hello you need TPM…

> The frequency dropped even before TPM was deployed on most machines

I interpreted your sentence as two disjoint statements and thought you find UEFI/SB and TPMs all useless. But yes, it indeed started dropping before. TPMs don't deal with that topic unless we're speaking of Trusted Boot, which is a whole separate concept.

> [...] hinder you adding alternative means without TPM being activated. But that is a different story and solely on Microsoft.

No it's not solely on Microsoft. If there isn't a safe place to store keys, it makes sense to dissuade storing them. Fairly obvious, isn't it?

> You can use many different types of authenticators.

It's not a very realistic suggestion for most users and use-cases. Having a built-in module that does the job has a lot of upsides.

> No need to falsely or passive aggressively suggest that a system would be insecure without these specific means.

I didn't say such a system would be insecure, however it can't safely store key material, it would be less secure in a bunch of contexts.

Re: The Dangers of Microsoft Pluton

#258

What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…

> It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Stallman was.

I think it’s also worth asking why he didn’t have more impact despite pretty clearly seeing this problem. Part of the answer has to be resource disparities but I don’t think it’s just that - Linux didn’t really capitalize at all on Microsoft’s lost decade, and much of the innovation in security has happened on other platforms. I think there’s also some kind of blind spot in the open source community where a lot of people see this as something other people need, not them personally.

Re: The Dangers of Microsoft Pluton

#259
post #2

Ew. Why are all the chip manufacturers going along with this stupid plan? I want to buy a processor and then own it and have it work in my best interests, not consume electricity and generatie heat enforcing draconian 3rd party DRM policies.

> Ew. Why are all the chip manufacturers going along with this stupid plan?

Because if they don't add whatever garbage Microsoft orders them to include in their chips then Microsoft can simply require that shit for the next version of their OS to boot. They could even force an update on existing PCs to check for it. Nobody is going to buy a chip if having it means they can't run the OS that 99% of computers on the plant are using. If Intel dared to say no, MS could pretty much run them out of business.

Re: The Dangers of Microsoft Pluton

#260

Earlier quoted context omitted.

Quoted post unavailable.

I feel like it's flawed. Voters and politicians abuse it left and right - pun intended. I don't think we ever came up with anything more humane though, and I don't wish to change it for anything other - to be honest, for the simple reason of not wanting the responsibility that goes along with it. Choosing a party is not like choosing an OS for your PC, though. Choosing the OS would be like choosing the political syst…

So, putting it all together, someone should choose and restrict which OS can be installed on your PC, so that you can feel safe in the thought that everyone has the same restriction?

At least that's how I managed to understand your comment to the best of my abilities, so hopefully I'm missing something. Though if there is such a something, the point did not get across successfully.

Post reply on HN