Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

381–390 of 554 posts

Re: The Dangers of Microsoft Pluton

#381
post #359

Earlier quoted context omitted.

The remote proctoring stuff is downright dystopian. I bought an extra laptop to do tests; most people can’t do that and have to install this garbage on their daily driver. Of course, I guess most people don’t care.

What's hilarious is it doesn't seem to prevent exam cheating in any meaningful way anyway, according to some students I've chatted to.

It really doesn’t. I took an exam in a meeting room at work with huge TVs on the wall… they made me show them the TVs were “unplugged”, so I just unplugged some random thing from the wall and they were happy.

The TVs are hardwired, it’d be trivial to have an accomplice show answers or whatever on them.

Re: The Dangers of Microsoft Pluton

#382
post #66

nowadays 98% of things implying "security" are actually unwanted products, protections for "the other side" or trivial distortions of reality where, conveyed by "security" itself, the user himself becomes the product - no, I don't need protections for the side channel, I never asked for them - no, I don't need a unique identifier, who is the demented person who asked you for it - no, I am not going to glitch the powe…

> no, I am not going to glitch the power supply, and even if I did it means I am interested in doing it and wish it worked instead I was prevented from doing it Are you talking about brown-out detection circuits, or is there something else?

The first xbox was hacked using an attack via the power supply I believe. It caused some instructions in the boot sequence to be skipped i think. It’s a really cool story, wish i had a link.

Re: The Dangers of Microsoft Pluton

#383

Earlier quoted context omitted.

So basically, Cory Doctorow's "The Upcoming War Against General Computation" ? https://boingboing.net/2011/12/27/the-coming-war-on-general-... https://github.com/jwise/28c3-doctorow/blob/master/transcrip... Don't know enough about the subject to tell if his "attempts to control general computation will converge on rootkits" prediction has held up.

> "attempts to control general computation will converge on rootkits" prediction has held up. If you play video games, you probably have a couple of neat kernel rootkits installed as "anti cheat". A lot of remote proctoring stuff for exams are looking a lot like rootkits too. EDR/XDR is also just rootkits. For security. The only thing that can stop a bad guy with a rootkit is a good guy with a rootkit, after all.

Kernel rootkits are going to be redundant pretty soon.

There are cheats out there that use video captured by capture cards as input for an AI on a separate computer to actually play the game like a human would. Once that becomes widespread there is no way to stop it, save from banning capture cards entirely.

Re: The Dangers of Microsoft Pluton

#384

Earlier quoted context omitted.

Think about users with a million toolbars and Bonzi Buddy installed. I say let them be. As long as they also have the freedom to remove or not install such software, it's a good thing. Instead we have locked-down devices with the functional equivalent of such unwanted software, protected so that you cannot remove it without somehow getting root. "Those who give up freedom for security deserve neither."

My parents grew up in a non English speaking developing country, and they cannot be reasonably expected to learn the nuances of malware laden links to figure out which English text link is good or bad. Do they deserve to not be able to shop online without fear of having their payment information stolen? Or mistyping a URL in their non native language and ending up at a scam website that installs malware? Or simply ha…

The problem you are describing will be irrelevant in a generation or two, as kids grow up on the internet.

Re: The Dangers of Microsoft Pluton

#385

What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…

Damn, now I'm nostalgic for the older days of hacker news where RMS was quoted every other post. The community is forgetting it's roots.

Top-voted comments are linking directly to Right to Read and The Coming War on General-Purpose Computing, so I don't think the community has forgotten its roots.

You really wanna be scared? Go look at the multiple comments on the EU DMA announcement complaining that having a sideloading option is just a ploy for malware vendors to get into their iPhones. Or that someone else being able to sideload or jailbreak somehow hurts their security. These are coming from actual HN users!

Re: The Dangers of Microsoft Pluton

#386

Earlier quoted context omitted.

It's not mutually excusive. I think risks from hostile powers need to be called out, and I think we also need to be calling out this bad behavior on our side too.

The US is a hostile power everywhere else in the world. And then also for about 4-8 out of every 8 years to its own citizens.

> And then also for about 4-8 out of every 8 years to its own citizens.

And you can pretty much guarantee that ~50% of the population will always consider that statement true, no matter the government of the day.

Re: The Dangers of Microsoft Pluton

#387

Earlier quoted context omitted.

> Remote attestation is the true enemy of your freedom. Technology is a tool. What is true however is that under the current way how the economy is structured remote attestation weakens freedoms of individuals mostly. If Facebook was under remote attestation that private information was only used in limited and specific ways and even the NSA can not get to them without breaking the remote attestation, that would be a…

It is a tool, just like nuclear weapons are a weapon. I'm definitely not on the "ban all crypto" side, but I see why the governments are in support of that, and for the longest time, strong crypto was (and still is?) classified as a munition; it's very powerful.

Well, I think governments are mostly concerned with people having secrets. Who would need secrets who isn't a terrorist? That it was classified as munition is probably more due to old war hawks and how they saw encryption employed.

Re: The Dangers of Microsoft Pluton

#388
post #285

I remember when Microsoft introduced driver signing, i remember articles in Slashdot and TheRegister going wild about how Microsoft was about block side-loading third party software, and only allow software which they specifically authorized to run on Windows or that they would charge large % fees to allow 3rd party software to be installed. When those these restrictive practices were introduced with iOS and to a muc…

Yep. People have been banging the drum on TPMs and similar security chips being the end of personal computing for about 18 years now. Still waiting.

Re: The Dangers of Microsoft Pluton

#389

Earlier quoted context omitted.

It's so true, but I'm trying to imagine a normie's reaction to reading this, and all I'm coming up with is, "This guy is a paranoid schizo, back to TikTok for me...", and so unfortunately, I don't see us steering away from this fate anytime soon. These people won't respect you until you start taking their money. Become one of their techno-corporate overloads. Demonstrate how you're controlling/profiting off them, why…

You can take their money and still they won't care. Think about how many devices in a typical users home are incompatible for business reasons - for example that Chromecast that refuses to play Amazon prime movies. Or the iPhone charger cable that won't fit into an android. Users just live with it. "My weird laptop doesn't support the school WiFi" is the same.

We should thank widespread technical illiteracy for this: "Devices are from different vendors? Of course they can't share the same services or charger!" Marketers just love this, for enabling them to sell multiple times the same thing. What if basic technology familiarity (which has absolutely nothing to do with knowing how to use the latest gadget) and resistance to manipulative advertising was taught in school? That would be quite a change, but I guess it's going to remain a dream.

Re: The Dangers of Microsoft Pluton

#390
post #350

Earlier quoted context omitted.

The capacity for abuse is huge, way beyong the potential benefits. From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly. Those kind of people will abuse such system to prevent things to be shared. It will be used for putting DRM on everything and create a more and more closed web. It will be used by corporations…

If you want to use the OS to ban a book or program or whatever, you don't need fancy hardware features, just a database of hashes pushed down via a software update. Apple wanted to do a version of this for CSAM images, it only didn't happen because they chose to tell users about it and got massive backlash. The implication that governments need more powerful DRM features to do something similar just obscures the fact…

The EU just mandated chats to be scanned for content. Of course just for CSAM just as the meta data collection is only used for terrorism. Problem is that the latter is also used for parking tickets. They really try to hit the definition of a totalitarian state by the letter.
Post reply on HN