Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

261–270 of 554 posts

Re: The Dangers of Microsoft Pluton

#261

Earlier quoted context omitted.

What you can install on YOUR pc will be at the sole mercy of microsoft/or maybe someone else.... That's the cusp of it. Not that it can be used for good, but that it sets the way for heavy misuse by large corporations. Wait a few years. Smaller companies won't even be allowed to order high end cpu's. You'll be at 100% mercy of these corporations. If after 2 years they decide to brick your pc, they'll just do it. You…

still waiting on the secure boot lockdown everyone has insisted is coming for the better part of two decades...

They tried with Windows RT. It was UEFI system, booting only Windows. That booted Windows went even further, allowing to run only signed binaries.

Market rejected it. At the time, there was an alternative. What are most people going to do, when there is not?

Re: The Dangers of Microsoft Pluton

#262
post #236

Earlier quoted context omitted.

The capacity for abuse is huge, way beyong the potential benefits. From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly. Those kind of people will abuse such system to prevent things to be shared. It will be used for putting DRM on everything and create a more and more closed web. It will be used by corporations…

> From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly. Books are not banned, just not used in the classroom anymore. While the reasons for it may be wrong, it's something that happens constantly all over the world. No one prevents children or adults to read those books at home. Banning books could mean that owni…

Banning their use in classrooms is lesser but still a step on that path, and the same Republicans trying to do that are not going to stop at schools after they win but will rather see that as an invigorating first step in a long campaign. For example, book sellers in Virginia are currently fighting a lawsuit against an attempt which would ban private sales:

https://www.virginiamercury.com/2022/07/06/free-speech-group...

Re: The Dangers of Microsoft Pluton

#263
post #241

Earlier quoted context omitted.

What you can install on YOUR pc will be at the sole mercy of microsoft/or maybe someone else.... That's the cusp of it. Not that it can be used for good, but that it sets the way for heavy misuse by large corporations. Wait a few years. Smaller companies won't even be allowed to order high end cpu's. You'll be at 100% mercy of these corporations. If after 2 years they decide to brick your pc, they'll just do it. You…

Secure chips like this are already in all devices but PCs. And in none of these areas has any of that happened. Quite the opposite, Apple got a fine when they slowed down older devices to save battery (at least what they said). So the government will clearly help out here. And none of these companies has an incentives to stop sales to smaller companies, they make a lot of money with those.

> So the government will clearly help out here.

I...don't share your optimism, to put it lightly.

Re: The Dangers of Microsoft Pluton

#264
post #89

Earlier quoted context omitted.

> if you have root Because god forbid you have control of your own PC?

I think this is more for Android phones, and preventing a malicious app on your phone from using the root access to hijack data from your banking app.

Well that's the problem.... the next step would be requiring users to use MS Edge, because a malicious version of firefox could capture/modify banking/transaction data. Want to pay bills? Give money to microsoft first.

Re: The Dangers of Microsoft Pluton

#265

Earlier quoted context omitted.

what's stopping someone from taking photos of your precious document and posting them on 4chan? nothing. there's nothing you can do to stop that.

Try to scan banknotes with a scanner and you will see.

if you mean there are scanners that prevent you from scanning of a banknote, that's another great example of wasting time, money and resources to accomplish nothing

Re: The Dangers of Microsoft Pluton

#266
post #190

Earlier quoted context omitted.

This is false and just redefining control.

How so? Redefines from what to what? Please elaborate. Perhaps you mean that if you, as owner and legitimate user of a device, are able to perform a particular change only during a brief window of time rather than at any time of your choosing, then that limits your control over the device? If so, then my answer is yes, certainly it does. But it also limits the access of anyone who impersonates you (such as the evil e…

You're wrong because the bootloader is more often locked than not, and there are various other nefarious controls in place that prevent you from doing it without voiding your warranty, such as one-time fuses.

In theory, yes, you could implement it like you said, but that's not what happens in practice nor the direction we've been tending towards in recent times.

Re: The Dangers of Microsoft Pluton

#267

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

The same things that make it good in a corporate environment can make it abusive in a personal machine. By forcing the kernel to be untamperable, Microsoft can arbitrarily enforce ANY policy they choose on your PC. They could spy on every single piece of network communication. They could ban any given software from being able to run on Windows - maybe Chrome, maybe Steam, any competitor at all. They actually could ea…

> They could ban any given software from being able to run on Windows - maybe Chrome, maybe Steam, any competitor at all.

IIRC, this was the reason Valve created SteamOS: they feared Microsoft would use their control over Windows so that the only viable software store on PCs would be Microsoft's own store.

Re: The Dangers of Microsoft Pluton

#268

Earlier quoted context omitted.

I imagine if the proponents of these systems had their way, they'd add remote attestation to websites too. Imagine your bank's website only loading on a "secure" windows environment, non-rooted android phone or an iphone. Once these chips are in everyone's devices, it would be quite easy to add this stuff technically. And in doing so, break the web on non-approved hardware or software (like linux). Edit: Actually on…

> imagine if the proponents of these systems had their way, they'd add remote attestation to websites too. Imagine your bank's website only loading on a "secure" windows environment, non-rooted android phone or an iphone. Actually, IIUC this is already the case on Android[0]. Some (many? most?) banks/banking apps are rejecting (and/or complaining about) access from rooted phones right now . I can't confirm this perso…

> I'd rather have my tonsils extracted through my ears than use a surveillance device^W^W smart phone to do anything financially related.

Well, it gets even better, even for folks with principles like you have.

If you want to use general computer, you need to log in. For logging in, you need second factor. That second factor is going to be in 99,99% cases exactly the app in the smartphone, that refuses to run on rooted devices.

So no avoidance, if you want access to your account.

Re: The Dangers of Microsoft Pluton

#269
post #26
post #22

Earlier quoted context omitted.

The same enterprises asking for this stuff are also asking for it to be taken out of their hands because they don't trust themselves to operate it securely or reliably.

So this turns into security theater because ultimately they can't trust those third parties too.

I'm frankly already appalled by how much data (proprietary data, customer data, employee data, etc) companies are fine leaking to 3rd parties, MS especially. Even if you assume that Microsoft could never ever possibly be hacked, or would never favor one of your competitors enough to hand them your data, Microsoft's MO has often been basically stealing other people's work/ideas and stomping out or absorbing the people they took it from. The data they get from outlook alone must be worth a fortune, but with everything the OS collects these days it's insane how little anyone cares.

Re: The Dangers of Microsoft Pluton

#270
post #241

Earlier quoted context omitted.

Secure chips like this are already in all devices but PCs. And in none of these areas has any of that happened. Quite the opposite, Apple got a fine when they slowed down older devices to save battery (at least what they said). So the government will clearly help out here. And none of these companies has an incentives to stop sales to smaller companies, they make a lot of money with those.

> Quite the opposite, Apple got a fine when they slowed down older devices to save battery But the devices were actually slowed down, so the danger is real.

And Apple had to revert it and got punished for it. What more do you want?
Post reply on HN