Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

291–300 of 554 posts

Re: The Dangers of Microsoft Pluton

#291
post #258

What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…

> It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Stallman was. I think it’s also worth asking why he didn’t have more impact despite pretty clearly seeing this problem. Part of the answer has to be resource disparities but I don’t think it’s just that - Linux didn’t really capitalize at all on Microsoft’s lost decade, and much of the innovation in security has…

The reason the OSS community has had no impact is that it's never managed to produce software that regular non-tech-geeks want to use. The reason it's never managed to do that is lack of an economic model to finance the incredible amount of work required to make software usable by normal people.

I've been saying this ad nauseum forever and I'm not the only one.

A related problem is that the OSS world is mostly tech enthusiasts. It's like having car people design cars. They'd be full of special switches and options and stuff that car people want. Car people don't understand that most people hate cars. What they like is mobility. Same goes for computers. Most people hate computers. They just like what computers let them do: communication, making content, getting their work done, etc.

Re: The Dangers of Microsoft Pluton

#292

"""Microsoft believes they need to exercise more control over PC Security than previously""" This has little to to with security. It's about having more control over the user.

When I clicked the link, I expected to see media security DRM functionality or something along those lines. However, from what I can tell, this is all critical security stuff; the security community has been begging for features like these for ages.

Kind of feels like Microsoft can’t win here. Everything is free and unprotected and their OS is a security joke, or they harden and get accused of DRM and monopolizing.

Re: The Dangers of Microsoft Pluton

#293
post #2

Ew. Why are all the chip manufacturers going along with this stupid plan? I want to buy a processor and then own it and have it work in my best interests, not consume electricity and generatie heat enforcing draconian 3rd party DRM policies.

> Ew. Why are all the chip manufacturers going along with this stupid plan? Because if they don't add whatever garbage Microsoft orders them to include in their chips then Microsoft can simply require that shit for the next version of their OS to boot. They could even force an update on existing PCs to check for it. Nobody is going to buy a chip if having it means they can't run the OS that 99% of computers on the pl…

This works both ways however. No one is going to buy the OS that can't even run on their latest chip. Microsoft can make all the demands they want, but the chip manufacturers still have the power to refuse to implement it; if Microsoft wants to brick their own OS, that's not their problem.

Re: The Dangers of Microsoft Pluton

#294
post #89

Earlier quoted context omitted.

> if you have root Because god forbid you have control of your own PC?

I think this is more for Android phones, and preventing a malicious app on your phone from using the root access to hijack data from your banking app.

If this was the reason they'd be blocking access from phones that are not up to date on security updates and are being actively exploited by malware to get root.

But it's the other way around, if you improve your old device by installing a up to date Android on your vendor-abandoned previously vulnerable device, you go from working banking to banned from banking.

Re: The Dangers of Microsoft Pluton

#295

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

I can see a situation where "the authorities" decide that, say, the list of people who flew on Epstein's "Lolita express" is "evidence in a pending trial" or "confidential" in the name of "national security," and simply flip a switch to prevent our computers from being able to access any file with particular hashes that they've identified as containing the information.

Also, thank God for the Internet Archive.

Re: The Dangers of Microsoft Pluton

#296

Earlier quoted context omitted.

> Gee I wonder why The frequency dropped even before TPM was deployed on most machines and I guess most systems still haven't it enabled today. Reason for that is that there are simply more direct and profitable ways to get system access, see most applications of ransomware for example. > It's nice that you have no key material You can use many different types of authenticators. If you use Windows Hello you need TPM…

> The frequency dropped even before TPM was deployed on most machines I interpreted your sentence as two disjoint statements and thought you find UEFI/SB and TPMs all useless. But yes, it indeed started dropping before. TPMs don't deal with that topic unless we're speaking of Trusted Boot, which is a whole separate concept. > [...] hinder you adding alternative means without TPM being activated. But that is a differe…

> Having a built-in module that does the job has a lot of upsides.

And downsides, especially for corporate usage you don't want your data protected by device keys if they aren't set by yourself or replicated elsewhere. But it is a security risk to deploy such keys on local machines in the first place in many circumstances.

> If there isn't a safe place to store keys, it makes sense to dissuade storing them. Fairly obvious, isn't it?

The behavior is that you can only add keys if you already activated TPM. This is an implementation detail of Windows Hello. Perhaps they changed it but I can think of some reasons why they forgot to add the option.

> it would be less secure in a bunch of contexts

No, I disagree. Severely less secure depends on the security model. Applications cannot usually randomly access any memory, but yes, the system would need to ensure that and there can be attacks. If you assume your system is compromised on that level your device encryption will be bypassed via the same channel. TPM comes with its own suite of security flaws in regards of device identification (bug or feature?). That is a relevant threat model compared to many memory attacks regardless of the countless other fingerprinting problems we currently are subjected to. Plus the DRM issues around remote attestation and sealed storage.

Re: The Dangers of Microsoft Pluton

#297
post #89
post #83

Earlier quoted context omitted.

Yes, lots of Linux devices apply it like that today: You can't use your banking app or consume DRM crippled media on your Android phone if you have root or run a open source Android distribution.

> if you have root Because god forbid you have control of your own PC?

This is the root of the pro market / mainstream market split.

For the pro market people want control. Pros also generally know a bit more about how to use that control and tend to be less likely to end up getting pwned immediately.

For regular users people just want shit that works. Not having control is a feature, because if you have control then the malware you are tricked into installing from "ɡeτflrêfox.com" also has control.

You can see it in the Apple ecosystem with iOS vs. macOS. Macs and iPads are now almost the same hardware. (The M chips are just A chips on 'roids.) But Macs can run other OSes and you can "sudo root." That's because Macs are for pros.

Re: The Dangers of Microsoft Pluton

#298
post #293

Earlier quoted context omitted.

> Ew. Why are all the chip manufacturers going along with this stupid plan? Because if they don't add whatever garbage Microsoft orders them to include in their chips then Microsoft can simply require that shit for the next version of their OS to boot. They could even force an update on existing PCs to check for it. Nobody is going to buy a chip if having it means they can't run the OS that 99% of computers on the pl…

This works both ways however. No one is going to buy the OS that can't even run on their latest chip. Microsoft can make all the demands they want, but the chip manufacturers still have the power to refuse to implement it; if Microsoft wants to brick their own OS, that's not their problem.

> No one is going to buy the OS that can't even run on their latest chip.

Unless that latest chip is vastly superior to what we have today, almost nobody is going to care. Most people couldn't tell you which chip is in their computer right now. They don't even care what a processor is. They just want to be able to click on the little picture that makes facebook happen and they don't want to have to learn anything new to make that happen.

If every chip manufacturer refused, you're right that we'd be pretty safe, but the moment they can get just one chip manufacturer on board every OEM will buy those chips or go out of business. Intel was "evil inside" decades ago for a reason, so we knew how this was going to play out.

Re: The Dangers of Microsoft Pluton

#299

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

Likewise. I see only potential for enormous hassle reduction if my employer (a bank, currently) can treat its entire compute infrastructure as a honking big cryptographically assured parallel universe.

Re: The Dangers of Microsoft Pluton

#300

Earlier quoted context omitted.

...if the schematics and tapeouts are entirely public. Otherwise you can be assured that there will be backdoors.

You can post hoc modify circuits so they look like doing logic A but they actually do logic B by adding new p or n junctions.

In theory, yes. In practice it is not realistic to implement a plausible-deniable hardware backdoor targeting all CPUs being manufactured while keeping the schematics and tapeout open.

While the same CPUs are even fabbed in different locations around the world.

While also going undetected for years and while none of the engineers involved blows the whistle.

In short no, you can get away with a targeted attack but nothing so massive.

Post reply on HN