Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

511–520 of 554 posts

Re: The Dangers of Microsoft Pluton

#511

The thing I fear the most with this is "proof that secure boot has never been disabled". This is just a way to brick your device from accessing services. What if you government's tax service requires such proof? Or bank? I cannot count how many machines I booted on Linux to rescue a hard drive, or image it, or wipe it, or just to install linux on them. All those devices, boom, paperweight for regular personal use. I…

You get two devices.

And more e-waste? Thanks but no thanks, I already have enough paperweights.

Re: The Dangers of Microsoft Pluton

#512
post #447

This is not a good article. At a technical level it's confused about a whole bunch of things: * SMM has been part of x86 for decades . The Secured Core requirements around SMM actually reduce its power. * The claimed requirement to remove the third party UEFI CA certificate from 2022 Secured Core PCs is entirely unrelated to Pluton (it's required regardless of whether Pluton is enabled or not, and even whether the CP…

Arguing about the technicalities DOES NOT MATTER one bit about what the final outcome will be, and in fact appears to be a carefully calculated means of distraction.

everything that the article is worried about being enabled by Pluton is already possible, and has been for years.

There's a HUGE difference between "possible" and "very easy to deploy". https://news.ycombinator.com/item?id=29859106

Re: The Dangers of Microsoft Pluton

#513
post #356

Earlier quoted context omitted.

[dead]

That's character assassination and it has nothing to do with Stallman's prescient warnings, which have proven more or less true. Also, Stallman != Linux. Also also, his "rape" remarks have been mischaracterized but also came pretty late in the game, and had nothing to with with Linux's alleged lack of impact. Linux existed and was successfully deployed decades before any of these remarks. I really expect better from…

I don’t think it’s simple character assassination: the question isn’t just “did he have some good points?” but, critically, “why did those points not reach more people?” and that underscores the degree to which a leader for a movement needs social skills at least as much as technical. Having trouble connecting with people outside of a certain MIT CS bubble, making sexist jokes or - especially - being on the whisper list women use to protect themselves for 3+ decades, choosing not to participate online or in person in ways which are effective for getting favorable media coverage or direct reach, are (with the exception of the creeper allegations) personal choices anyone is free to make but not great for building a movement.

Even if all of the harassment claims are the social awkwardness his defenders claim, turning off that many people is a terrible way to build a movement. Maybe we say many open source developers are willing to overlook that, and there aren’t many developers deterred (citation needed, but let’s ignore that for now), but that’s still a problem if it means that reporters and people who are not developers say “this guy’s a weirdo” and that leads to skepticism or simply not investing energy promoting those ideas.

Re: The Dangers of Microsoft Pluton

#514
post #447

This is not a good article. At a technical level it's confused about a whole bunch of things: * SMM has been part of x86 for decades . The Secured Core requirements around SMM actually reduce its power. * The claimed requirement to remove the third party UEFI CA certificate from 2022 Secured Core PCs is entirely unrelated to Pluton (it's required regardless of whether Pluton is enabled or not, and even whether the CP…

Arguing about the technicalities DOES NOT MATTER one bit about what the final outcome will be, and in fact appears to be a carefully calculated means of distraction. everything that the article is worried about being enabled by Pluton is already possible, and has been for years. There's a HUGE difference between "possible" and "very easy to deploy". https://news.ycombinator.com/item?id=29859106

There's literally zero difference in how easy it is to deploy using Pluton and using existing TPMs.

Re: The Dangers of Microsoft Pluton

#515
post #514

Earlier quoted context omitted.

Arguing about the technicalities DOES NOT MATTER one bit about what the final outcome will be, and in fact appears to be a carefully calculated means of distraction. everything that the article is worried about being enabled by Pluton is already possible, and has been for years. There's a HUGE difference between "possible" and "very easy to deploy". https://news.ycombinator.com/item?id=29859106

There's literally zero difference in how easy it is to deploy using Pluton and using existing TPMs.

This is partly true but its not quite. Think a little long-term here. Windows 10 ends support in just three years, in 2025. Windows 11 requires TPM 2.0, which was a big headache when Windows 11 was announced.

That means in three years, every supported PC will have TPM 2.0. Within ~1 year, assuming that Intel and AMD fulfill what they've implied in the launch announcement, every new PC will also come with Pluton.

That's a lot easier to deploy to compared to having some PCs with TPM, others without, some out-of-date on TPM 1.1, some with unpatched firmware (like the 2017 Infineon bug), so forth.

Now... some say, what about non-Windows systems, like macOS and Chrome? Think bigger for a second - Cisco (as an example) is in the Trusted Computing Group that designed a lot of this stuff, and Cisco Meraki is deployed in so many businesses for Wi-Fi security its incredible. All Cisco Meraki has to do (for example, maybe its not Cisco) is make a connection app that uses Pluton/TPM on Windows, Secure Enclave/T2 on macOS/iOS with Apple DeviceCheck, and SafetyNet on ChromeOS/Android. And you are all done - you've successfully made sure every new system is almost certainly untampered with. You've locked the door. For any system that can't be verified, no problems sending them to the IT Help Desk to be manually registered with a private key and sign a disclaimer.

It wasn't possible before, but five years from now, it will be much easier. Every Windows PC will be on the same page, and all major systems will have consistent assertion frameworks. Now, is Pluton wholly responsible? No. Windows 11 plays a role. Pluton just makes it broader and stronger, and Pluton also provides a long-term strengthening as eventually the TPM 2.0-only level will be able to be cut off for just Pluton.

Re: The Dangers of Microsoft Pluton

#516
post #514

Earlier quoted context omitted.

There's literally zero difference in how easy it is to deploy using Pluton and using existing TPMs.

This is partly true but its not quite. Think a little long-term here. Windows 10 ends support in just three years, in 2025. Windows 11 requires TPM 2.0, which was a big headache when Windows 11 was announced. That means in three years, every supported PC will have TPM 2.0. Within ~1 year, assuming that Intel and AMD fulfill what they've implied in the launch announcement, every new PC will also come with Pluton. That…

If your argument is "It's bad that all Windows systems will be guaranteed to have TPMs", then that's a reasonable argument to have! Everything that you're scared of here is 100% possible using TPMs (I have deployed hardware backed 802.1x certificates! I have made it impossible to get onto networks unless you have a TPM!), and Pluton doesn't change that. Making this about Pluton rather than about TPMs in general just means that people will believe they're somehow safe from the worst case outcome because they bought a CPU that doesn't have Pluton, when in reality if Microsoft decides to suddenly be extremely evil here they're going to be screwed over just as badly.

Re: The Dangers of Microsoft Pluton

#517
post #333

Earlier quoted context omitted.

The same things that make it good in a corporate environment can make it abusive in a personal machine. By forcing the kernel to be untamperable, Microsoft can arbitrarily enforce ANY policy they choose on your PC. They could spy on every single piece of network communication. They could ban any given software from being able to run on Windows - maybe Chrome, maybe Steam, any competitor at all. They actually could ea…

Microsoft doesn't need an "untamperable" kernel to force spying on users. Windows 10/11 has horrible invasive telemetry that can't be disabled, but no one has figured out how to modify the OS and strip it out, all the "solutions" involve temporarily disabling services or blocking network traffic. Is there actually some new capability here that points to future surveillance and censorship, or are you just fitting ever…

If I'm not mistaken, "no one has figured out" is factually incorrect. https://ameliorated.info/ blocks nearly all OS network requests (and hopefully all OS telemetry) by physically removing the relevant files from the system (though this breaks UWP apps, .appx, and such), and disables Windows Update to prevent telemetry components from being reinstalled. I use it on a near-daily basis, and it works quite well in most cases, although having a separate admin account by default, not being able to create new accounts (they show black screens), and missing features (Action Center and notifications) do sting, and I'm worried about the lack of security updates. If you do choose to use it, https://git.ameliorated.info/Joe/amecs is important for configuring the system.

Re: The Dangers of Microsoft Pluton

#518
post #516

Earlier quoted context omitted.

This is partly true but its not quite. Think a little long-term here. Windows 10 ends support in just three years, in 2025. Windows 11 requires TPM 2.0, which was a big headache when Windows 11 was announced. That means in three years, every supported PC will have TPM 2.0. Within ~1 year, assuming that Intel and AMD fulfill what they've implied in the launch announcement, every new PC will also come with Pluton. That…

If your argument is "It's bad that all Windows systems will be guaranteed to have TPMs", then that's a reasonable argument to have! Everything that you're scared of here is 100% possible using TPMs (I have deployed hardware backed 802.1x certificates! I have made it impossible to get onto networks unless you have a TPM!), and Pluton doesn't change that. Making this about Pluton rather than about TPMs in general just…

At this point, even if a TPM can recreate much of Pluton's functionality, I still believe some fear regarding Pluton is still necessary and healthy, although I do not dispute that for some uses it may be useful - after all, why was my fear mongering section explicitly labeled "Fearmongering and Doomsday speculations"? Microsoft can still screw people over, but Pluton is different from a TPM and should still be (generally) regarded with caution where possible, and more caution than a standard TPM.

This is mainly because, at this point,

A. A TPM's level of access and capabilities to a system is well-known at this point. Pluton, we do not know with certainty what all of its capabilities are.

B. Microsoft has explicitly stated Pluton will have functionality added to it in the future though software updates, most likely that cannot be downgraded, that are not present yet. It's not that Pluton might have stuff added later - Microsoft has said stuff will be added later. What these upgrades entail or are capable of is also unknown.

C. Because of the above, Pluton requires a previously-unknown level of trust for Microsoft, because Pluton almost certainly has anti-downgrade procedures. Microsoft could, potentially, send out an update just blocking Linux and if Pluton received the update, it would be irreversible. Maybe this isn't within Pluton's abilities, but we just don't know. Just that Microsoft (or a hacker of Microsoft - I'm more concerned about a rogue employee than Microsoft at the moment) could have permanent effects on the security of a system is worth paying attention over.

D. Because of the reasons above, Pluton should be regarded with extra skepticism as it is a magical black box, with unknown capabilities, that it is not clear whether it can actually be disabled. (Already on my blog, there's a user talking about how Pluton briefly boots and then disables itself if the UEFI says that it should be disabled, not that it never starts, so theoretically a Pluton update could ignore its own disable switch.) I don't have verification of that, but until we know more... TPM is known, TPM can screw people, Pluton has the potential to extremely screw people over, and while many of my doomsday speculations can actually be recreated with just a TPM if TPMs are widely adopted, perhaps it could be enhanced with more Pluton-specific ones. Perhaps my doomsday predictions actually weren't far enough.

Thus, your point that Pluton doesn't add too much might be completely valid right now. That doesn't mean Pluton isn't also a potential Trojan horse that Microsoft updates as they please with new things that we didn't expect or ask for with no ability to undo them.

Edit: Removed a previous edit, and adding that, to complement the above notes, it does not help instill confidence that Microsoft isn't telling what Pluton can and cannot do at a hardware level. They've said a few things it can do right now, and just said more stuff will be coming in the future, but they won't talk about where its limits are. So... trust the black box without questions please. To be fair, this isn't the first time (Intel ME, AMD PSP?), but it is unsettling to have another one.

Re: The Dangers of Microsoft Pluton

#519
post #291
post #258

Earlier quoted context omitted.

> It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Stallman was. I think it’s also worth asking why he didn’t have more impact despite pretty clearly seeing this problem. Part of the answer has to be resource disparities but I don’t think it’s just that - Linux didn’t really capitalize at all on Microsoft’s lost decade, and much of the innovation in security has…

The reason the OSS community has had no impact is that it's never managed to produce software that regular non-tech-geeks want to use. The reason it's never managed to do that is lack of an economic model to finance the incredible amount of work required to make software usable by normal people. I've been saying this ad nauseum forever and I'm not the only one. A related problem is that the OSS world is mostly tech e…

I'd argue that most FOSS devs just have amnesia about certain things, like dual-licensing that lets you sell licenses to companies but keep things open for humans. For example an Office competitor could sell licenses to companies in this way, but allow individuals to use the software on their personal machines.

Say you have a game, you can make the source available and still charge money for the game, and it doesn't get any easier to pirate than before. You even get tons of people modding your game and contributing to its appeal.

There are also techniques like 'selling support' for your software.

Re: The Dangers of Microsoft Pluton

#520

Earlier quoted context omitted.

no, I don't need a unique identifier People fought against that and actually won, 23 years ago: https://news.ycombinator.com/item?id=10106870 Unfortunately, that may have been the only victory, as they slowly started introducing a lot of other stuff silently under the guise of "security". "not secure by design" nowadays comes close to being a coveted feature Absolutely. As the saying goes, "insecurity is freedom".

Hum... Looks like you didn't notice we losing. At that same time, Microsoft started using your HDD serial as an identifier. Nowadays there are unique identifiers in most of your hardware, including the north bridge of your motherboard and the TPM that windows now requires. Also, mobile devices got all kinds of unique identifiers from day 0.

No, I sure did notice --- that's why I said "the only victory". All the other battles seem to either have been lost or surrendered without a fight.
Post reply on HN