I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…
What you can install on YOUR pc will be at the sole mercy of microsoft/or maybe someone else.... That's the cusp of it. Not that it can be used for good, but that it sets the way for heavy misuse by large corporations. Wait a few years. Smaller companies won't even be allowed to order high end cpu's. You'll be at 100% mercy of these corporations. If after 2 years they decide to brick your pc, they'll just do it. You…
The Dangers of Microsoft Pluton
441–450 of 554 posts
Re: The Dangers of Microsoft Pluton
#442Re: The Dangers of Microsoft Pluton
#443HVCI is truly revolutionary, you can no longer just dump lsass and get credentials if it is enabled among other use cases. But to me, this all looks like MS building a house of cards again. If I am writing a rootkit or other malware why can I not use this to make sure only the compromised devices secure processor can read the contents of memory or does defender get a pass?! A defender/analyst won't also be able to du…
Re: The Dangers of Microsoft Pluton
#444Earlier quoted context omitted.
What you can install on YOUR pc will be at the sole mercy of microsoft/or maybe someone else.... That's the cusp of it. Not that it can be used for good, but that it sets the way for heavy misuse by large corporations. Wait a few years. Smaller companies won't even be allowed to order high end cpu's. You'll be at 100% mercy of these corporations. If after 2 years they decide to brick your pc, they'll just do it. You…
This smacks of fear mongering. The scenario you've outlined is just absurd. Many manufactures have pledged to turn this off by default and be an opt-in model. I'm not disagreeing that laptops given out by corporations for to you to use for work won't be heavily locked down and could be bricked remotely. But most laptops today already come this way from IT.
Re: The Dangers of Microsoft Pluton
#445What if you government's tax service requires such proof? Or bank? I cannot count how many machines I booted on Linux to rescue a hard drive, or image it, or wipe it, or just to install linux on them. All those devices, boom, paperweight for regular personal use.
I hate it so much that Microsoft is alone in this. It's not because it's M$, it's because they're alone on it.
Re: The Dangers of Microsoft Pluton
#446Ew. Why are all the chip manufacturers going along with this stupid plan? I want to buy a processor and then own it and have it work in my best interests, not consume electricity and generatie heat enforcing draconian 3rd party DRM policies.
Re: The Dangers of Microsoft Pluton
#447* SMM has been part of x86 for decades. The Secured Core requirements around SMM actually reduce its power.
* The claimed requirement to remove the third party UEFI CA certificate from 2022 Secured Core PCs is entirely unrelated to Pluton (it's required regardless of whether Pluton is enabled or not, and even whether the CPU has Pluton or not)
* Most of the description of Pluton is actually a description of a TPM. You don't need DICE for remote attestation. TPMs are already a hardware keystore.
* System firmware is already being updated via Windows Update. The discussion about Pluton and Windows Update is around Pluton getting firmware updates that way (the existing story around firmware updates for TPMs is largely not good)
* Existing TPM-based remote attestation already includes the secure boot state
The short version: everything that the article is worried about being enabled by Pluton is already possible, and has been for years.
But there's a meaningful point here. Remote attestation can certainly be used to restrict access to resources in ways that are incompatible with general purpose computing, or which reduce user choice. Remote attestation can also be used to give end users confidence that their machine is in a good state without constraining what they do with it. As a technology, remote attestation can be used in both good and bad ways. We do need to keep track of whether anyone is threatening to use it in bad ways and react appropriately.
(But tbh remote attestation as an attack on general purpose computing isn't the really scary thing about widespread remote attestation. Remote attestation ties back to the TPM's endorsement key, an immutable cryptographic key certified by the TPM vendor at manufacturing time. The straightforward implementation of allowing arbitrary remote sites to trigger remote attestation would tie all of these accesses back to a single piece of hardware, and would be a privacy nightmare.)
Re: The Dangers of Microsoft Pluton
#448Earlier quoted context omitted.
Did they actually ban the books, or did they merely ban their usage in K-12 instruction with the news outlet rounding that up to a book ban for dramaturgical reasons? Not that a ban in school instruction is necessarily good (though, I would guess, not nearly as rare), but the actual full-fledged ban that DRM could aid in enforcing, which would prevent you as an individual from reading a book you want to read in _any_…
All Florida did was add a criteria to their selection process to disallow books that include Critical Theory/Critical Race Theory or their praxis in the teaching of math, etc. Every state selects which text books can be used by their schools so if Florida "burns books" then by definition every single other state does too. Where are the text books in California that teach math using Biblical stories and imagery? Obvio…
Yep, one state decided to do something about this divisive indoctrination of kids and the peddlers of that stuff obviously don't like it, hence the "banning (math) books" stories. If you actually read into this you quicky realize that someone is clearly lying and (this time) it's not the Republicans.
Re: The Dangers of Microsoft Pluton
#449I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing. Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-a…
Re: The Dangers of Microsoft Pluton
#450This means to take anything written in that article with a grain of salt.