Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

461–470 of 554 posts

Re: The Dangers of Microsoft Pluton

#461
post #239

Earlier quoted context omitted.

>As of January 2021 deleting SecureBoot keys and installing your own keys (for example by using KeyTool) will brick the device. This is a problem that is similar to one which has been reported on some other Lenovo laptops [0] and is likely due to a faulty firmware. If the device is stuck in a boot loop after replacing the SecureBoot keys, the only way to repair it is by replacing the mainboard of the device. [0] http…

Does reflashing the BIOS EEPROM (via hardware clip) work? Or have they "secured" that out of the question too?

The goal is that it's secured as well; the bios image itself is measured into the TPM and pluton as part of secure boot.

Re: The Dangers of Microsoft Pluton

#462

Earlier quoted context omitted.

Until access to the internet or methods of circumventing DRM are crippled without submitting to these technologies. That's the road we're heading down. Can't hack the current-gen Xbox, apparently. I'm wondering if someone will take that as a "challenge accepted".

> Can't hack the current-gen Xbox, apparently. Yet.

Well, the Xbox One wasn't hacked either. That was released in 2013. If it was going to be hacked, it likely would have already happened given that its most popular moment has come and gone.

Re: The Dangers of Microsoft Pluton

#463
post #26
post #22

Earlier quoted context omitted.

The same enterprises asking for this stuff are also asking for it to be taken out of their hands because they don't trust themselves to operate it securely or reliably.

So this turns into security theater because ultimately they can't trust those third parties too.

You're thinking about companies as monoliths. They are groups of people.

The managers who want remote attestation aren't the people implementing it. They either pay someone else to do it, or they pay someone else to do it. The difference between paying a third-party company and an employee is that employees are more expensive, because the costs aren't amortized over other customers who want the same stuff. Why would they be more trustworthy? Why would they be better at it? Why would it be any less likely to be hacked if you did it at your company than if you outsourced it?

Re: The Dangers of Microsoft Pluton

#464
post #143

Interesting naming. "Microsoft Hell God". Pluto (Greek: Πλούτων Plouton, "giver of wealth", Pluton in French and German) the most common name for the classical ruler of the underworld. Plouton was one of several euphemistic names for Hades, described in the Iliad as the god most hateful to mortals. https://en.wikipedia.org/wiki/Pluto_(mythology)

Pluton is also a geological term, referring to magma domes that have solidified and since eroded to yield granite structures like Half Dome.

Re: The Dangers of Microsoft Pluton

#465
Every story about Microsoft--every time--ends with "...and then Microsoft fucked people over". After decades of watching the shitshow that is Microsoft, and the moral equivocating around defending them, I always return to this.

Re: The Dangers of Microsoft Pluton

#466
post #447

This is not a good article. At a technical level it's confused about a whole bunch of things: * SMM has been part of x86 for decades . The Secured Core requirements around SMM actually reduce its power. * The claimed requirement to remove the third party UEFI CA certificate from 2022 Secured Core PCs is entirely unrelated to Pluton (it's required regardless of whether Pluton is enabled or not, and even whether the CP…

You are incorrect yourself in several ways here. > The claimed requirement to remove the third party UEFI CA certificate from 2022 Secured Core PCs is entirely unrelated to Pluton (it's required regardless of whether Pluton is enabled or not, and even whether the CPU has Pluton or not) Pluton is de-facto a Secured Core PC implementation, and Secure Core PCs are also making this change. Thus it effects both Pluton and…

> Pluton is de-facto a Secured Core PC implementation

No, it's not. You can deploy Pluton without having to implement the Secured Core PC spec.

> Microsoft Pluton does not make the mistake of repeating,

No, seriously, the only remote attestation supported by Pluton on x86 at present is literally this TPM-based remote attestation. There's no meaningful fragility here - remote attestation means you can look at the individual log events rather than just looking at the composite PCR values, and that lets you ignore the noise created by things like hardware configuration changes. I have helped build and deploy infrastructure that makes use of remote attestation to validate secure boot state.

> the TPM could be easily virtualized

No, because the EK certificate won't chain back to a trusted CA>

> hacked over the bus

True in some cases, but already mitigated on all systems that are using fTPMs (ie, most Windows 11 systems).

> the Pluton is explicitly designed to give a computer a permanent identity that can never be erased, which (again) TPM does not guarantee.

TPM does, in fact, guarantee that. The endorsement key is static over the lifetime of the TPM.

> why does DICE even exist

DICE provides a set of features that don't require the functionality of a full TPM. This allows you to implement things like device identity attestation in a standardised way that works for both hardware with a full TPM and also IoT devices where a TPM would be too expensive.

> Today customers receive updates to their security firmware from a variety of different sources

Look at the diagram immediately above that quote. They're talking about the firmware that runs on Pluton, not the firmware executed by the main CPU.

Again, you're raising a legitimate issue (remote attestation can be used for bad things), but you're burying it under a bunch of misconceptions and just flat out inaccuracies. I agree that we should be worried about widespread use of remote attestation, both from a "War on general purpose computing" perspective and a privacy perspective. But literally everything you're legitimately worried about happening could happen right now. Framing this as something that's tied to Pluton risks giving people the impression that they can avoid it by just not buying anything with Pluton, and that's simply untrue.

Re: The Dangers of Microsoft Pluton

#467
post #448

Earlier quoted context omitted.

All Florida did was add a criteria to their selection process to disallow books that include Critical Theory/Critical Race Theory or their praxis in the teaching of math, etc. Every state selects which text books can be used by their schools so if Florida "burns books" then by definition every single other state does too. Where are the text books in California that teach math using Biblical stories and imagery? Obvio…

> All Florida did was add a criteria to their selection process to disallow books that include Critical Theory/Critical Race Theory or their praxis in the teaching of math, etc. Yep, one state decided to do something about this divisive indoctrination of kids and the peddlers of that stuff obviously don't like it, hence the "banning (math) books" stories. If you actually read into this you quicky realize that someone…

"It's not the Republicans"

Do you know what Critical Race Theory actually is, and where it's taught?

Re: The Dangers of Microsoft Pluton

#468
post #236

Earlier quoted context omitted.

The capacity for abuse is huge, way beyong the potential benefits. From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly. Those kind of people will abuse such system to prevent things to be shared. It will be used for putting DRM on everything and create a more and more closed web. It will be used by corporations…

> From the USA, we get news of banned book in some states. When I read that, my head goes back to my european history, and I reach the Godwin point very quickly. Books are not banned, just not used in the classroom anymore. While the reasons for it may be wrong, it's something that happens constantly all over the world. No one prevents children or adults to read those books at home. Banning books could mean that owni…

> Banning books could mean that owning them is illegal and that just hasn't happened.

Just within the last century it was illegal to send a copy of Ulyesses or The Canturbury Tales through US mail.

Re: The Dangers of Microsoft Pluton

#469

Earlier quoted context omitted.

The goal is not to prevent you from running Linux, is to make it so that Linux cannot access the content you are interested in. Remote Attestation establishes a root of trust that can be used to verify that all of the software down the line is "approved": - You won't be able to browse sites or use apps with ads unless you run a 'trusted' device, OS and browser that does not block ads. - You won't be able to browse si…

As someone who enjoys hacking, looking at that list sounds terrible. As a regular user, most of that list doesn't sound too bad. Their future devices will automatically have these features enabled, they're not likely to change those settings to "break" their device (from the perspective of Trusted Computing) so they'll have a smooth experience getting into it. - Can't block ads? A lot of average users already don't/d…

This is all just giving away control to corporations. Freedom is about having the option, not using it. Even if most "regular users" never use it, if they ever change their mind they'll surely appreciate having it. It also affects the ability to develop new hardware, and being locked to hardware/software approved by the remote side (e.g. Facebook or whichever app/site you're using) is a pretty Dystopian reality.

> My bank account online is more secure?

Sincerely, why? Because I can't customize my own software anymore? Fortunately banks around here don't require SafetyNet, some of them do require a mobile device though.

Re: The Dangers of Microsoft Pluton

#470
post #87

Earlier quoted context omitted.

Mein Kampf is a banned book which I don't think many would disagree with. There are many other such books filled with propaganda that are rightly banned. I don't see why other propaganda-filled books that are being pushed on unsuspecting children shouldn't be banned too, unless the only reason is that you dislike the direction of the propaganda.

If you're in the US there are not really any truly banned books. There are books that are banned from certain libraries (mostly school libraries). But, imagine that a school adopts the DRM processes described in the article and requires this study level of control even on personal devices that are used for school. Suddenly those book bans can be enforced digitally by the school and will totally cut off access to cert…

> But, imagine that a school adopts the DRM processes described in the article and requires this study level of control even on personal devices that are used for school.

The prerequisite for this to happen is that the school removes all physical editions of the books and has digital editions for all content, and a lending program for the books that is sufficient to satisfy publishers... and all students have digital book readers able to access the school library.

I don't see this happening in the near (or even within the decade) future. There is far too much content that is physical only, publishers haven't embraced digital editions for libraries, school libraries don't have the technical resources (physical or in many cases human) to convert their collections to digital.

The hypothetical school book ban for digital editions is needlessly alarmist.

When those resources are available to schools, then yes - lets talk about it... though the school banning books will continue to mean "that resource isn't in our collection" and a student can go to another library (or in many cases book store) and get a copy of that book for themselves. This is no different than today.

Post reply on HN