Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

371–380 of 554 posts

Re: The Dangers of Microsoft Pluton

#371

Earlier quoted context omitted.

What you can install on YOUR pc will be at the sole mercy of microsoft/or maybe someone else.... That's the cusp of it. Not that it can be used for good, but that it sets the way for heavy misuse by large corporations. Wait a few years. Smaller companies won't even be allowed to order high end cpu's. You'll be at 100% mercy of these corporations. If after 2 years they decide to brick your pc, they'll just do it. You…

still waiting on the secure boot lockdown everyone has insisted is coming for the better part of two decades...

The goal is not to prevent you from running Linux, is to make it so that Linux cannot access the content you are interested in.

Remote Attestation establishes a root of trust that can be used to verify that all of the software down the line is "approved":

- You won't be able to browse sites or use apps with ads unless you run a 'trusted' device, OS and browser that does not block ads.

- You won't be able to browse sites with captchas unless you run a 'trusted' device, OS and browser that does not allow bots to interact with the browser.

- You won't be able to run Netflix unless you run a 'trusted' device, OS and browser so that you can't record the content.

- You won't be able to play online games unless, again, you run a 'trusted' device and OS so that you cannot cheat, or more importantly modify it in any way (why would you purchase skins if you can mod them in?).

- You won't be able to use online banking unless you use a trusted OS because banks.

Remote Attestation is pretty terrifying and it will be here soon unless it is regulated out of existence, which is unlikely.

Re: The Dangers of Microsoft Pluton

#372
post #359

Earlier quoted context omitted.

> "attempts to control general computation will converge on rootkits" prediction has held up. If you play video games, you probably have a couple of neat kernel rootkits installed as "anti cheat". A lot of remote proctoring stuff for exams are looking a lot like rootkits too. EDR/XDR is also just rootkits. For security. The only thing that can stop a bad guy with a rootkit is a good guy with a rootkit, after all.

The remote proctoring stuff is downright dystopian. I bought an extra laptop to do tests; most people can’t do that and have to install this garbage on their daily driver. Of course, I guess most people don’t care.

What's hilarious is it doesn't seem to prevent exam cheating in any meaningful way anyway, according to some students I've chatted to.

Re: The Dangers of Microsoft Pluton

#373
post #291
post #258

Earlier quoted context omitted.

> It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Stallman was. I think it’s also worth asking why he didn’t have more impact despite pretty clearly seeing this problem. Part of the answer has to be resource disparities but I don’t think it’s just that - Linux didn’t really capitalize at all on Microsoft’s lost decade, and much of the innovation in security has…

The reason the OSS community has had no impact is that it's never managed to produce software that regular non-tech-geeks want to use. The reason it's never managed to do that is lack of an economic model to finance the incredible amount of work required to make software usable by normal people. I've been saying this ad nauseum forever and I'm not the only one. A related problem is that the OSS world is mostly tech e…

You really nailed it with that car analogy.

Most "car people" would agree that changing the oil in your car is super easy. To me, it is not easy. It's not something I'm willing to do, even though I know the steps of how to do it. I just don't know what I don't know. When I have my oil changed, the mechanic tells me what I should be concerned about. He tells me what upcoming work I need to have done, how much it will cost, and what could happen if I don't do it. He has experience, expertise, and specialized tools. He had knowledge gathered over years to be highly proficient in his profession.

I could do those things. I could read, and listen, and learn. I could be under my car every day learning new things about how to install this, or replace that. But I don't really have the drive or inclination to do so. I'd rather leave it to the pro. I also have the added novice-worry of screwing something up, and hurting myself or others as a result. I don't want that kind of pressure. I don't want my car breaking down while doing some long journey - I just want it to run when I need it to run, without any scary warning lights coming up on my dashboard.

To bring the analogy back to computers, I still know people - people in their 20's or 30's - who do not know how to copy and paste with keyboard shortcuts. I will sit there and see them highlight, right-click, click copy, move their cursor, left-click, right-click, choose paste. I'll tell them how much time they could save if they "just did ..." and get a basic "Yeah...I just don't really care though, ya know? This works." The thing is, there is no investment on their part to want or need to do that more efficiently. They get by well enough with not bothering.

They could get super into computers, and learn something as "technical" as `git clone https: //github.com/some/repo` and follow the process to configure and run a script. They could learn to do those things. But they don't really have that time to invest in it, or don't have that passion for it, or have a professional investment in needing to do it.

They want it to work. They want to not get hacked. They want to not have to think about computers at all. Computers are the interface to do "the thing" more easily. And if the computer breaks? They want it fixed so it won't happen again. The computer "does the internet thing". And I can respect that because they focus their energy into knowledge into other topics that I don't have a clue about, the same way I don't have a clue about cars, even if I know oil changes are "easy".

Re: The Dangers of Microsoft Pluton

#374

Earlier quoted context omitted.

TPM has features like remote attestation and is in general a mechanism to bind data to hardware, which is interesting for DRM purposes. Sure, there are theoretical attacks on memory, but they are far less relevant for security than the penalties I have to accept with TPM being widely established. Not that there aren't different means, but TPM also creates unique hashes of your system which only reinforces the problem…

> which is interesting for DRM purposes. You're thinking of SGX enclaves not TPM. > TPM also creates unique hashes of your system It doesn't. Your system creates hashes and appends to lists signed by TPM. And the point of those hashes is to be not unique, but verifiability matching known values.

No, I meant TPM. Media could be bound to have the TPM report certain hashes of the configuration registers that are either already set or TPM sets on system boot. Same mechanism that allows you to only open a document on specific hardware basically or allows an application to check if the system was perhaps compromised.

Re: The Dangers of Microsoft Pluton

#375
post #291
post #258

Earlier quoted context omitted.

> It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Stallman was. I think it’s also worth asking why he didn’t have more impact despite pretty clearly seeing this problem. Part of the answer has to be resource disparities but I don’t think it’s just that - Linux didn’t really capitalize at all on Microsoft’s lost decade, and much of the innovation in security has…

The reason the OSS community has had no impact is that it's never managed to produce software that regular non-tech-geeks want to use. The reason it's never managed to do that is lack of an economic model to finance the incredible amount of work required to make software usable by normal people. I've been saying this ad nauseum forever and I'm not the only one. A related problem is that the OSS world is mostly tech e…

This atrocious attitude is absolutely why software is such a hellscape of shitty UI and lack of features.

Normies should be eating our table scraps, not dictating how the software is written.

Normies learned how to drive a car. They can learn how to properly compute. And if they don't like the tech, they don't have to use the tech.

OSS is the last bastion of computing for people who know/like computing, because the armies of "designers" aren't selfless enough to donate their time like programmers are. And frankly it is better off that way, the prevailing trends in design seem to be all about limiting options.

Hard, powerful software over push-button appliances any day.

And, to use the car analogy, BMW gets away with this approach just fine.

Re: The Dangers of Microsoft Pluton

#377
post #356

Earlier quoted context omitted.

[dead]

That's character assassination and it has nothing to do with Stallman's prescient warnings, which have proven more or less true. Also, Stallman != Linux. Also also, his "rape" remarks have been mischaracterized but also came pretty late in the game, and had nothing to with with Linux's alleged lack of impact. Linux existed and was successfully deployed decades before any of these remarks. I really expect better from…

The statement was why Stallman specifically has not had much of an impact, not Linux writ large. and, you're right. The rape comments came late. But let me remind you that it's emblematic of a larger... issue with Stallman's ability to communicate effectively. If you don't think the way Stallman behaves is at least partly to blame for people's ability to take him seriously, I don't know what to tell you.

https://daringfireball.net/2019/09/richard_stallmans_disgrac...

Re: The Dangers of Microsoft Pluton

#378

What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…

It's so true, but I'm trying to imagine a normie's reaction to reading this, and all I'm coming up with is, "This guy is a paranoid schizo, back to TikTok for me...", and so unfortunately, I don't see us steering away from this fate anytime soon. These people won't respect you until you start taking their money. Become one of their techno-corporate overloads. Demonstrate how you're controlling/profiting off them, why…

An economic niche supports one or two overlords, not a bunch of them. You and I aren't overlords. We need a different strategy.

People have become aware and angry that tech monopolies are exploitative. The winning strategy will involve focusing this fuzzy, ambient anger at a concrete target.

Once Pluton outs itself as an exercise in naked monopolistic power covered by a fig leaf of security -- and it will, as all hustles must eventually involve monetization -- the bad optics will be our opportunity to act. Any strategy on our side that involves putting down TikTok is doomed to failure, but if we put the bad optics in front of people, make the connection, and get them to briefly agree "yeeah, f** the monopolies! F** Pluton!" then a political solution becomes possible. Not easy, but possible.

It's a pity that this dialog has to be so reactive and simplistic, but communication at scale cannot function any other way.

Re: The Dangers of Microsoft Pluton

#379
post #66

nowadays 98% of things implying "security" are actually unwanted products, protections for "the other side" or trivial distortions of reality where, conveyed by "security" itself, the user himself becomes the product - no, I don't need protections for the side channel, I never asked for them - no, I don't need a unique identifier, who is the demented person who asked you for it - no, I am not going to glitch the powe…

It’s worth distinguishing between security against software attacks and security against physical “attacks”.

I absolutely don’t want my internet connected pet cam to be accessed remotely (outside the set of companies i’ve decided to trust, namely the manufacturer.)

Protection against hardware tempering is less good and probably mostly anti-consumer. The most legitimate cases I’ve heard:

- Protection from (some) supply chain attacks

- Leasing models. Where you acquire the item for less than it’s hardware cost and pay over time.

But honestly I’m not convinced of either.

Disclosure: I worked on Azure Sphere, the first place Pluton was developed outside Xbox.

Edit: I’ve read the whole article now. These scenarios are really bad and really realistic. Pluton is bad.

Re: The Dangers of Microsoft Pluton

#380
post #343
post #291

Earlier quoted context omitted.

The reason the OSS community has had no impact is that it's never managed to produce software that regular non-tech-geeks want to use. The reason it's never managed to do that is lack of an economic model to finance the incredible amount of work required to make software usable by normal people. I've been saying this ad nauseum forever and I'm not the only one. A related problem is that the OSS world is mostly tech e…

> the OSS community [...] never managed to produce software that regular non-tech-geeks want to use That's true, barely, only if you equate "software" with "things that draw stuff presented on a display to a user". Regular non-tech-geeks are using open source software (in the real sense, meaning instructions given to a computer to make it do something) pervasively, everywhere, every day, on all their devices (yes, ev…

You're correct, of course. I think the point that was being made was more about people actively choosing to use open source.

If you were to approach a non-tech person and ask them how many open source apps they use on a daily basis, they would probably say "none", even if it's not the case.

Post reply on HN