Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

501–510 of 554 posts

Re: The Dangers of Microsoft Pluton

#501

The thing I fear the most with this is "proof that secure boot has never been disabled". This is just a way to brick your device from accessing services. What if you government's tax service requires such proof? Or bank? I cannot count how many machines I booted on Linux to rescue a hard drive, or image it, or wipe it, or just to install linux on them. All those devices, boom, paperweight for regular personal use. I…

This is already a problem with SafetyNet hardware attestation on Android. Because it's so easy to implement on the app side, everything from banking apps to games is verifying the device is running a blessed system image with a locked bootloader and no root access (read: no access to general-purpose computing).

As a developer of a banking app, I do my best to avoid implementing this user-hostile crap, but not all developers are empowered to say "no" to this requirement and not all care. There is zero benefit to the user to block them from using your services, and I would argue the net benefit is negative to the service. Users aren't hacked via privilege escalation exploits, they are hacked by phishing, and they can be phished on a SafetyNet-compliant device just fine.

Re: The Dangers of Microsoft Pluton

#503
post #433

Earlier quoted context omitted.

But at least you could load your own OS. Chip manufacturers could even decide that nothing good happens on open source operating systems, so you're now only allowed to run Mac or Windows operating systems. The point is really that they're taking full ownership of the chips from you.

They could, but not with the new Pluton stuff. That would be enforced with secure boot, which has been around for a while already. Again, the capabilities already exist. The barrier for a would-be censor is political not technological.

Ah right, the robust guardian of our human freedoms! Politics!

I want my technological barrier back please.

Re: The Dangers of Microsoft Pluton

#504
post #343
post #291

Earlier quoted context omitted.

The reason the OSS community has had no impact is that it's never managed to produce software that regular non-tech-geeks want to use. The reason it's never managed to do that is lack of an economic model to finance the incredible amount of work required to make software usable by normal people. I've been saying this ad nauseum forever and I'm not the only one. A related problem is that the OSS world is mostly tech e…

> the OSS community [...] never managed to produce software that regular non-tech-geeks want to use That's true, barely, only if you equate "software" with "things that draw stuff presented on a display to a user". Regular non-tech-geeks are using open source software (in the real sense, meaning instructions given to a computer to make it do something) pervasively, everywhere, every day, on all their devices (yes, ev…

> it literally won the war.

Then why is everything on the consumer side becoming more closed?

The reality is that proprietary just moved to the cloud in the form of SaaS-as-DRM and we-own-your-data. Open source runs everything, but few things are open. The availability of the source for components of the stuff they use is irrelevant to 99% of users.

Re: The Dangers of Microsoft Pluton

#505
post #148

HVCI is truly revolutionary, you can no longer just dump lsass and get credentials if it is enabled among other use cases. But to me, this all looks like MS building a house of cards again. If I am writing a rootkit or other malware why can I not use this to make sure only the compromised devices secure processor can read the contents of memory or does defender get a pass?! A defender/analyst won't also be able to du…

For now (and I haven't seen an annoucement of a coming change about it), only trustlets signed by Microsoft can be executed in the VSM (Virtual Secure Mode), so you won't be able to write a malware or a rootkit that leverages it to hide the execution flow.

Thanks for clarifying. With drivers they get around that by using vulnerable drivers, but this isn't regular kernel mode code execution, and MS will probably revoke certs for future vulnerable trustlets? (Or not, since that can cause outages). Sounds like a whole new area of research.

Re: The Dangers of Microsoft Pluton

#507
post #459

Earlier quoted context omitted.

The both sides framing is a common tactic used to make this seem even but there’s a pretty notable difference if you look at the details. For example, Newsweek’s right-wing owners love this framing but the left example is a single school district removing a book from the curriculum whereas the right wing examples are far more widespread and include books being removed from libraries. The motives are also different: b…

According to the article that I linked, California has banned "To Kill a Mockingbird" in schools due to racism and you seem to be implying that is because the book "depict[s] racism positively"; however, I read it back in school and I remember discussing extensively how the book showed racism in a most negative light. It doesn't seem to me like you are willing to believe that both sides could be over stepping here, b…

According to the article you linked:

> Apparently no one told him that the stack of books in the photo included one banned in the state he leads, To Kill a Mockingbird, which was banned from California schools on the grounds that it contained racism.

Clear cut, right? Nope, here’s what their own linked article says:

> Schools in Burbank will no longer be able to teach a handful of classic novels, including Harper Lee's To Kill a Mockingbird, following concerns raised by parents over racism.

> Until further notice, teachers in the area will not be able to include on their curriculum Harper Lee's To Kill a Mockingbird, Mark Twain's The Adventures of Huckleberry Finn, John Steinbeck's Of Mice and Men, Theodore Taylor's The Cay and Mildred D. Taylor's Roll of Thunder, Hear My Cry.

The actual memo makes it sound like they’ll likely move these to the supplemental list and add some black authors: https://www.burbankusd.org/cms/lib/CA50000426/Centricity/Dom...

This is how the false-equivalence machine works. A single school district is expanded to an entire state (15k students isn’t nothing but it doesn’t represent many of the ~6M students in the state) and is presented as the equivalent of multiple state-wide attempts to remove books from schools & libraries, and again ignoring the difference between removing something from the curriculum with the goal of exclusion versus inclusion.

The urge to censor isn’t unique to right-wing politics but since they’re the ones pushing the most aggressively and successfully, I attributed more of it to the people causing the lion’s share of the harm.

Re: The Dangers of Microsoft Pluton

#508
post #478

Earlier quoted context omitted.

Given the apparent requirements around the Third Party UEFI CA, it's impossible for any device with a plug-in GPU to meet the Secured Core PC requirements. Unless Pluton is never going to be present in workstations, Pluton does not imply Secured Core. PSP and ME firmware isn't part of the CPU microcode. There's no fundamental reason why the updates couldn't be provided via Windows Update, but that would require Intel…

I'm not entirely sold for a few reasons. 1. This would require that Intel and AMD find it less intrusive to build an entire additional SoC into their processors, on whatever node necessary, than to package their software for Windows Update. Also, it leaves out the question, why couldn't Microsoft have required that AMD and Intel just implement a TPM outside of the PSP/ME with similar hardware protections? Intel would…

Ah... Yes. The vaunted, "we want a UUID for everything to eventually use to identify any system to create a namespace of for no reason at all, why are you acting so funny? There's no abuse potential at all."

Truly, there are days I feel like Oedipus had a good idea. Tired of reading the rampant industry gaslighting around what our current crop of engineering talent is whipping up for the up-and-comings to be subjected to.

Re: The Dangers of Microsoft Pluton

#509
post #503
post #433

Earlier quoted context omitted.

They could, but not with the new Pluton stuff. That would be enforced with secure boot, which has been around for a while already. Again, the capabilities already exist. The barrier for a would-be censor is political not technological.

Ah right, the robust guardian of our human freedoms! Politics! I want my technological barrier back please.

This. We never should have built these things.

Re: The Dangers of Microsoft Pluton

#510

The thing I fear the most with this is "proof that secure boot has never been disabled". This is just a way to brick your device from accessing services. What if you government's tax service requires such proof? Or bank? I cannot count how many machines I booted on Linux to rescue a hard drive, or image it, or wipe it, or just to install linux on them. All those devices, boom, paperweight for regular personal use. I…

You get two devices.
Post reply on HN