Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

321–330 of 554 posts

Re: The Dangers of Microsoft Pluton

#321

Earlier quoted context omitted.

So, putting it all together, someone should choose and restrict which OS can be installed on your PC, so that you can feel safe in the thought that everyone has the same restriction? At least that's how I managed to understand your comment to the best of my abilities, so hopefully I'm missing something. Though if there is such a something, the point did not get across successfully.

I think if I pick two groups: all iPhone users, and all PC users, PC users en bloc are in greater general digital danger than iPhone users. By digital danger, I'm thinking of malware, ransomware, phishing and successful hacking. And I think this is because of how tightly Apple controls their devices. And so, I'd consider an iPhone a safe choice - for example a safe recommendation for someone who doesn't want to spend…

> [...] which is, I think, very similar to how we don't really have control over a great many of things.

This is a very handwavey sentence and is doing far too much work in your reasoning. Yes, you don't have control "over a great many things", because the point is so vague so as to be meaningless. But it doesn't at all follow from that vague sentence that we should allow total corporate/government control over our personal digital devices.

In this case, the proposed cure is far worse than the disease.

Re: The Dangers of Microsoft Pluton

#322
post #302

Earlier quoted context omitted.

> Maybe I am too simplistic, but I do not see the evil in the TPM here, but only in the 3rd party policy. The evil is that the "Trusted" in "Trusted Computing" and "Trusted Platform Module (TPM)" means that one deeply distrusts the user (who might tamper with the system), but instead the trust lies in the computing (trusted computing) or TPM. In other words: Trusted Computing and TPM means a disempowerment of the use…

I'm not sure if I understand your argument. As long as you can put your own things on your TPM and use it for your own good it's not too bad right? And in corporate environments it's reasonable to not own your own device right? Sure Infineon can probably get my data, but that's far beyond the scope of my threat model. As long as the system is open to putting your own keys on there I'm fine with it.

> I'm not sure if I understand your argument. As long as you can put your own things on your TPM and use it for your own good it's not too bad right?

As long as software that uses the TPM cannot detect whether you tampered with the TPM or not, it is principally all right.

But as I wrote down: this is exactly the opposite of what trusted computing was invented for: make the machine trustable (for the companies that have control over the TPM/trusted computing), because the user is distrusted.

Re: The Dangers of Microsoft Pluton

#323

What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…

> Remote attestation is the true enemy of your freedom. Technology is a tool. What is true however is that under the current way how the economy is structured remote attestation weakens freedoms of individuals mostly. If Facebook was under remote attestation that private information was only used in limited and specific ways and even the NSA can not get to them without breaking the remote attestation, that would be a…

It is a tool, just like nuclear weapons are a weapon.

I'm definitely not on the "ban all crypto" side, but I see why the governments are in support of that, and for the longest time, strong crypto was (and still is?) classified as a munition; it's very powerful.

Re: The Dangers of Microsoft Pluton

#324

Earlier quoted context omitted.

As someone who was here from day two, this is not how old HN was. It was many things to many people, and it’s very difficult to break out of the illusion that rose-tintedness tends to give us. (Guilty of it myself.) HN has been consistently contrarian. That’s about all that you can say without quickly becoming mistaken.

>HN has been consistently contrarian. That’s about all that you can say without quickly becoming mistaken. until recently. Just like reddit, it has become less niche and more mainstream. For eg: HN majority opinion on covid's origin. It matched the official US govt lines as it switched back and forth between market and lab.

Presumably, HN will turn into reddit, but nobody will believe it's happening because people have been predicting it's turning into reddit for over a decade.

Re: The Dangers of Microsoft Pluton

#326
post #89

Earlier quoted context omitted.

> if you have root Because god forbid you have control of your own PC?

Yep! Basically, it's safer if you don't own your PC. Think about users with a million toolbars and Bonzi Buddy installed. Of course, the system for it is rudimentary, and puts a disproportionate amount of control in the hands of providers. And that works very well for them too.

Think about users with a million toolbars and Bonzi Buddy installed.

I say let them be. As long as they also have the freedom to remove or not install such software, it's a good thing. Instead we have locked-down devices with the functional equivalent of such unwanted software, protected so that you cannot remove it without somehow getting root.

"Those who give up freedom for security deserve neither."

Re: The Dangers of Microsoft Pluton

#327
post #98

Earlier quoted context omitted.

Welcome to the 8 and 16 bit home computer days when OSes were written in ROMs.

Or back to books where the OSes were written in ink. What's the point of this comparison?

I guess, the way Compaq was able to take advantage from IBM.

Re: The Dangers of Microsoft Pluton

#328
post #132

I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…

Remember when Snowden and Manning leaked huge troves of secret information about the crimes of the State? Remember when a bunch of journos got their hands on the so-called "Panama papers"? Basically, this will make transparency even harder than it already is. That's a terrible danger for democracy at large. Stalin's wet dream.

Yep that’s why we should ban passwords.

/s

Re: The Dangers of Microsoft Pluton

#329
post #66

nowadays 98% of things implying "security" are actually unwanted products, protections for "the other side" or trivial distortions of reality where, conveyed by "security" itself, the user himself becomes the product - no, I don't need protections for the side channel, I never asked for them - no, I don't need a unique identifier, who is the demented person who asked you for it - no, I am not going to glitch the powe…

no, I don't need a unique identifier

People fought against that and actually won, 23 years ago: https://news.ycombinator.com/item?id=10106870

Unfortunately, that may have been the only victory, as they slowly started introducing a lot of other stuff silently under the guise of "security".

"not secure by design" nowadays comes close to being a coveted feature

Absolutely. As the saying goes, "insecurity is freedom".

Re: The Dangers of Microsoft Pluton

#330

I will definitely not buy CPU with built-in MS core. If Intel will add it too, guess it's time to get 12700 and use it for looong time.

Problem is that the consoles market is very lucrative for CPU vendors because it is a guaranteed turnover of specific models. Intel, AMD and Qualcomm will implement them. You can disable it though. It would suck if it were enable by default, at least lenovo said they will disable it at first.
Post reply on HN