Earlier quoted context omitted.
> From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly. Books are not banned, just not used in the classroom anymore. While the reasons for it may be wrong, it's something that happens constantly all over the world. No one prevents children or adults to read those books at home. Banning books could mean that owni…
Banning their use in classrooms is lesser but still a step on that path, and the same Republicans trying to do that are not going to stop at schools after they win but will rather see that as an invigorating first step in a long campaign. For example, book sellers in Virginia are currently fighting a lawsuit against an attempt which would ban private sales: https://www.virginiamercury.com/2022/07/06/free-speech-group…
The Dangers of Microsoft Pluton
391–400 of 554 posts
Re: The Dangers of Microsoft Pluton
#392Earlier quoted context omitted.
> Yep! Basically, it's safer if you don't own your PC. Think about users with a million toolbars and Bonzi Buddy installed. And it is a pretty terrible solution to the problem. - It is also keeping the good guys outside too: Anyone that want to analyse and understand the security of the system for good reasons cannot. Excepted if explicitly allowed by the corporation X and that is a terrible security property. - No r…
I agree. In a proposal like this, security is basically a byproduct, and sometimes not even that[0]. This is also a domain where the governmental and corporate powers have a similar goal, which is wresting away the control from the public / individual. They basically work in synergy, only to a point of course, but still. Regarding Bonzi Buddy, I disagree. I think user data is as important, if not more important, than…
Ugh, except that one goes overboard in the completely opposite direction, and often doesn't let me properly share data between apps even when I want to.
Re: The Dangers of Microsoft Pluton
#393nowadays 98% of things implying "security" are actually unwanted products, protections for "the other side" or trivial distortions of reality where, conveyed by "security" itself, the user himself becomes the product - no, I don't need protections for the side channel, I never asked for them - no, I don't need a unique identifier, who is the demented person who asked you for it - no, I am not going to glitch the powe…
Security has degraded to snake oil on a lot of topics. Boot infection are really rare and the whole TPM module isn't really needed in my opinion and I don't want it either for my systems. There are edge cases and sensible applications, but I don't want to see it as standard.
Before you say, "well, they're the government, why don't they just compromise the secure boot CA"; the problem is that cryptographic signatures create evidence. If someone finds your boot sector malware you don't want it to be attributable - but signatures from an already-trusted entity create exactly the kind of paper trail you'd rather avoid. If Microsoft signs a boot sector virus, then it's obviously a US government cyberweapon, and any companies that find it in their systems will start suing. In this particular context, secure boot is a policy of "no execution without attribution".
[0] Which nowadays can even be done in a browser. Modern browsers actually have to have throttling and CPU usage limits because of this.
Re: The Dangers of Microsoft Pluton
#394Earlier quoted context omitted.
That's character assassination and it has nothing to do with Stallman's prescient warnings, which have proven more or less true. Also, Stallman != Linux. Also also, his "rape" remarks have been mischaracterized but also came pretty late in the game, and had nothing to with with Linux's alleged lack of impact. Linux existed and was successfully deployed decades before any of these remarks. I really expect better from…
The statement was why Stallman specifically has not had much of an impact, not Linux writ large. and, you're right. The rape comments came late. But let me remind you that it's emblematic of a larger... issue with Stallman's ability to communicate effectively. If you don't think the way Stallman behaves is at least partly to blame for people's ability to take him seriously, I don't know what to tell you. https://dari…
I also think when RMS made his more salient and prescient points, most people weren't familiar with him personally, just with his remarks. The world was less connected back then. So his personality flaws really didn't make a huge impact (nor should they have).
Re: The Dangers of Microsoft Pluton
#395Earlier quoted context omitted.
The same things that make it good in a corporate environment can make it abusive in a personal machine. By forcing the kernel to be untamperable, Microsoft can arbitrarily enforce ANY policy they choose on your PC. They could spy on every single piece of network communication. They could ban any given software from being able to run on Windows - maybe Chrome, maybe Steam, any competitor at all. They actually could ea…
Microsoft doesn't need an "untamperable" kernel to force spying on users. Windows 10/11 has horrible invasive telemetry that can't be disabled, but no one has figured out how to modify the OS and strip it out, all the "solutions" involve temporarily disabling services or blocking network traffic. Is there actually some new capability here that points to future surveillance and censorship, or are you just fitting ever…
Re: The Dangers of Microsoft Pluton
#396Earlier quoted context omitted.
> which is interesting for DRM purposes. You're thinking of SGX enclaves not TPM. > TPM also creates unique hashes of your system It doesn't. Your system creates hashes and appends to lists signed by TPM. And the point of those hashes is to be not unique, but verifiability matching known values.
No, I meant TPM. Media could be bound to have the TPM report certain hashes of the configuration registers that are either already set or TPM sets on system boot. Same mechanism that allows you to only open a document on specific hardware basically or allows an application to check if the system was perhaps compromised.
Re: The Dangers of Microsoft Pluton
#397Earlier quoted context omitted.
The reason the OSS community has had no impact is that it's never managed to produce software that regular non-tech-geeks want to use. The reason it's never managed to do that is lack of an economic model to finance the incredible amount of work required to make software usable by normal people. I've been saying this ad nauseum forever and I'm not the only one. A related problem is that the OSS world is mostly tech e…
You really nailed it with that car analogy. Most "car people" would agree that changing the oil in your car is super easy. To me, it is not easy. It's not something I'm willing to do, even though I know the steps of how to do it. I just don't know what I don't know. When I have my oil changed, the mechanic tells me what I should be concerned about. He tells me what upcoming work I need to have done, how much it will…
The great majority of people don't know or understand the difference between single click and double click. This baffled me the first time I found out. Age or education don't matter.
If you dig a little deeper you discover that most people think double-click is a kind of equivalent of "clicking louder". As if sometimes, for some reason, the computer becomes hard-of-hearing. It's both a little sad and quite funny.
Re: The Dangers of Microsoft Pluton
#398Earlier quoted context omitted.
My parents grew up in a non English speaking developing country, and they cannot be reasonably expected to learn the nuances of malware laden links to figure out which English text link is good or bad. Do they deserve to not be able to shop online without fear of having their payment information stolen? Or mistyping a URL in their non native language and ending up at a scam website that installs malware? Or simply ha…
The problem you are describing will be irrelevant in a generation or two, as kids grow up on the internet.
And no, it's not smartphones' faults. Most people just don't "get" desktop OS paradigms, or how web pages work, or any of that, and they don't really care to.
Re: The Dangers of Microsoft Pluton
#399What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…
Updating the Upton Sinclair quote without the gender bias; it’s difficult getting a person to understand something when their investment portfolio valuation depends on them not understanding it.
Who are they if they’re not what they are now?
When you all stop posting on corporate forums and working their jobs, shopping their stores, I’ll take you all sincerely and seriously.
Re: The Dangers of Microsoft Pluton
#400What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…
In order to deal with it, I had to create a subnet with a router, use an old laptop to do the verification, and then the whole subnet was added to the allow-list.