Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

311–320 of 554 posts

Re: The Dangers of Microsoft Pluton

#311

Earlier quoted context omitted.

> The frequency dropped even before TPM was deployed on most machines I interpreted your sentence as two disjoint statements and thought you find UEFI/SB and TPMs all useless. But yes, it indeed started dropping before. TPMs don't deal with that topic unless we're speaking of Trusted Boot, which is a whole separate concept. > [...] hinder you adding alternative means without TPM being activated. But that is a differe…

> Having a built-in module that does the job has a lot of upsides. And downsides, especially for corporate usage you don't want your data protected by device keys if they aren't set by yourself or replicated elsewhere. But it is a security risk to deploy such keys on local machines in the first place in many circumstances. > If there isn't a safe place to store keys, it makes sense to dissuade storing them. Fairly ob…

> And downsides, especially for corporate usage you don't want your data protected by device keys if they aren't set by yourself or replicated elsewhere.

It's a solved problem in corporate environments.

> But it is a security risk to deploy such keys on local machines in the first place in many circumstances.

That's a massive stretch and no normal corporation agrees with that statement.

> No, I disagree.

Other people's threat models are not something you can disagree with.

> If you assume your system is compromised on that level your device encryption will be bypassed via the same channel.

Well not really, it's not a bypass. Continuous abuse of a compromised machine is significantly noisier than exfiltrating the keys needed and then abusing those. Plus you can't touch anything that would change TPM measurements, or you'll lock yourself out. It's much more cumbersome.

Re: The Dangers of Microsoft Pluton

#312
post #98

Earlier quoted context omitted.

That's an invalid argument for multiple reasons, not the least of which is that some people can afford just one device. That device is likely to be a smartphone because everything is slowly moving in the direction of requiring one. If I need to spend extra money to get an additional "freedom device" and can't afford it, I just won't have one and will miss out on the good stuff.

Welcome to the 8 and 16 bit home computer days when OSes were written in ROMs.

Those still allowed you to run your own code.

Re: The Dangers of Microsoft Pluton

#313

Earlier quoted context omitted.

Same with TPM and why it had so many critics. Some people still seem adamant to say that boot viruses are the greatest threat in the 21st century, but the economic interest are far more dangerous for general computing in my opinion. And it isn't even close.

So basically, Cory Doctorow's "The Upcoming War Against General Computation" ? https://boingboing.net/2011/12/27/the-coming-war-on-general-... https://github.com/jwise/28c3-doctorow/blob/master/transcrip... Don't know enough about the subject to tell if his "attempts to control general computation will converge on rootkits" prediction has held up.

> "attempts to control general computation will converge on rootkits" prediction has held up.

If you play video games, you probably have a couple of neat kernel rootkits installed as "anti cheat".

A lot of remote proctoring stuff for exams are looking a lot like rootkits too.

EDR/XDR is also just rootkits. For security. The only thing that can stop a bad guy with a rootkit is a good guy with a rootkit, after all.

Re: The Dangers of Microsoft Pluton

#314

Earlier quoted context omitted.

So, putting it all together, someone should choose and restrict which OS can be installed on your PC, so that you can feel safe in the thought that everyone has the same restriction? At least that's how I managed to understand your comment to the best of my abilities, so hopefully I'm missing something. Though if there is such a something, the point did not get across successfully.

I think if I pick two groups: all iPhone users, and all PC users, PC users en bloc are in greater general digital danger than iPhone users. By digital danger, I'm thinking of malware, ransomware, phishing and successful hacking. And I think this is because of how tightly Apple controls their devices. And so, I'd consider an iPhone a safe choice - for example a safe recommendation for someone who doesn't want to spend…

God forbid most people I know have control of their own PC, they have no clue, and nor should they need one.

iPhone users are safer from malware, PC users are safer from governments and Apple controlling what they can do on their computer.

Never-ending balance between safety and freedom.

The computer that requires a physical switch to disable secure boot is a good compromise (see many Chromebooks)

Re: The Dangers of Microsoft Pluton

#315
Is Pluton IP open? All hardware vendors embracing this is not the right path for security / computing.

Why can't hardware vendors embrace standards-based open platforms like Global Platform [1].

[Edit] Google is also pushing Android Ready SE Alliance [2].

[1] https://globalplatform.org/

[2] https://security.googleblog.com/2021/03/announcing-android-r...

Re: The Dangers of Microsoft Pluton

#316

Earlier quoted context omitted.

Same with TPM and why it had so many critics. Some people still seem adamant to say that boot viruses are the greatest threat in the 21st century, but the economic interest are far more dangerous for general computing in my opinion. And it isn't even close.

Can you explain what is the issue with TPM? I get the issue with Pluton but TPM is only a dedicated and certified secure key and random number generator that does a better job than CPUs doing it in software, and it's also a secure enclave for storing your encryption keys. Would you rather store the keys in memory where they can be easily grabbed by malicious apps like Mimikatz? Macs had the same feature for years in…

TPM has features like remote attestation and is in general a mechanism to bind data to hardware, which is interesting for DRM purposes.

Sure, there are theoretical attacks on memory, but they are far less relevant for security than the penalties I have to accept with TPM being widely established.

Not that there aren't different means, but TPM also creates unique hashes of your system which only reinforces the problems around fingerprinting.

> It's the exact system that enables wireless payment and other strong security features on your phone.

Phones suck as computing devices on every conceivable metric and are heavily locked down devices. And it is not true that you need a TPM chip to create secure transfers. I constantly do business transaction on my PC just fine.

Re: The Dangers of Microsoft Pluton

#317
post #289

Earlier quoted context omitted.

You're wrong because the bootloader is more often locked than not, and there are various other nefarious controls in place that prevent you from doing it without voiding your warranty, such as one-time fuses. In theory, yes, you could implement it like you said, but that's not what happens in practice nor the direction we've been tending towards in recent times.

Bootloader locking is orthogonal to whether there's a second CPU like that Pluton in the system.

To quote you:

> The "you" that boots the device are in control, and the "you" that uses the device after that have exactly what "you" set up at boot time, neither more nor less. If both "you" are the same person, then there's no loss of control.

How is it orthogonal? Okay, we're not strictly speaking of only bootloader locking, but of boot-time-control locking.

Re: The Dangers of Microsoft Pluton

#318

Earlier quoted context omitted.

The capacity for abuse is huge, way beyong the potential benefits. From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly. Those kind of people will abuse such system to prevent things to be shared. It will be used for putting DRM on everything and create a more and more closed web. It will be used by corporations…

Ron DeSantis doesn't need hardware-level DRM to ban math books. https://www.baynews9.com/fl/tampa/news/2022/05/06/florida-ba... If you're worried about book bannings in states like Florida, DeSantis is up for reelection in just over 3 months . Go volunteer or donate money to his opponent (probably Charlie Crist).

Deciding which textbooks that are going to be used in public schools isn't banning books. If you don't want the government to decide which books are used to teach your children then homeschooling or private schooling are what you should be focused on.

Re: The Dangers of Microsoft Pluton

#320
post #271

Earlier quoted context omitted.

Yep! Basically, it's safer if you don't own your PC. Think about users with a million toolbars and Bonzi Buddy installed. Of course, the system for it is rudimentary, and puts a disproportionate amount of control in the hands of providers. And that works very well for them too.

> Yep! Basically, it's safer if you don't own your PC. Think about users with a million toolbars and Bonzi Buddy installed. And it is a pretty terrible solution to the problem. - It is also keeping the good guys outside too: Anyone that want to analyse and understand the security of the system for good reasons cannot. Excepted if explicitly allowed by the corporation X and that is a terrible security property. - No r…

I agree. In a proposal like this, security is basically a byproduct, and sometimes not even that[0]. This is also a domain where the governmental and corporate powers have a similar goal, which is wresting away the control from the public / individual. They basically work in synergy, only to a point of course, but still.

Regarding Bonzi Buddy, I disagree. I think user data is as important, if not more important, than root access - which is why I'm dumbfounded when ancient server security features, like Linux's sudo system, are applied to the consumer device like a PC or a smartphone. These contexts are much better server by a sandboxing, permission-based whatever that seems to pick up steam, like the current permission systems on smartphones. Grandma's logins and bank data will be stolen from her own user account just the same as an admin account. Related XKCD[1]

[0] https://en.wikipedia.org/wiki/Security_theater

[0] https://xkcd.com/1200/

Post reply on HN