Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

521–530 of 554 posts

Re: The Dangers of Microsoft Pluton

#521
post #516

Earlier quoted context omitted.

This is partly true but its not quite. Think a little long-term here. Windows 10 ends support in just three years, in 2025. Windows 11 requires TPM 2.0, which was a big headache when Windows 11 was announced. That means in three years, every supported PC will have TPM 2.0. Within ~1 year, assuming that Intel and AMD fulfill what they've implied in the launch announcement, every new PC will also come with Pluton. That…

If your argument is "It's bad that all Windows systems will be guaranteed to have TPMs", then that's a reasonable argument to have! Everything that you're scared of here is 100% possible using TPMs (I have deployed hardware backed 802.1x certificates! I have made it impossible to get onto networks unless you have a TPM!), and Pluton doesn't change that. Making this about Pluton rather than about TPMs in general just…

Making this about Pluton rather than about TPMs in general just means that people will believe they're somehow safe from the worst case outcome because they bought a CPU that doesn't have Pluton

They certainly will be, if most people don't have Pluton. If only a minority have it, they wouldn't be able to even come close to requiring it.

Re: The Dangers of Microsoft Pluton

#522
post #258

What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network? Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Sta…

> It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Stallman was. I think it’s also worth asking why he didn’t have more impact despite pretty clearly seeing this problem. Part of the answer has to be resource disparities but I don’t think it’s just that - Linux didn’t really capitalize at all on Microsoft’s lost decade, and much of the innovation in security has…

Consider that the one whose comment is currently at the top is pro-cancel-Stallman, and he also works on "free" software related to secure boot --- not as in breaking, but instead aiding its adoption.

The FSF was strongly against secure boot, then inexplicably started seeming to be in favour of it.

Connect the dots yourself.

Re: The Dangers of Microsoft Pluton

#523
post #516

Earlier quoted context omitted.

If your argument is "It's bad that all Windows systems will be guaranteed to have TPMs", then that's a reasonable argument to have! Everything that you're scared of here is 100% possible using TPMs (I have deployed hardware backed 802.1x certificates! I have made it impossible to get onto networks unless you have a TPM!), and Pluton doesn't change that. Making this about Pluton rather than about TPMs in general just…

Making this about Pluton rather than about TPMs in general just means that people will believe they're somehow safe from the worst case outcome because they bought a CPU that doesn't have Pluton They certainly will be, if most people don't have Pluton. If only a minority have it, they wouldn't be able to even come close to requiring it.

Which would do nothing to prevent them from rolling out draconian remote attestation technologies, if they wanted to.

Re: The Dangers of Microsoft Pluton

#524
post #258

Earlier quoted context omitted.

> It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Stallman was. I think it’s also worth asking why he didn’t have more impact despite pretty clearly seeing this problem. Part of the answer has to be resource disparities but I don’t think it’s just that - Linux didn’t really capitalize at all on Microsoft’s lost decade, and much of the innovation in security has…

Consider that the one whose comment is currently at the top is pro-cancel-Stallman, and he also works on "free" software related to secure boot --- not as in breaking, but instead aiding its adoption. The FSF was strongly against secure boot, then inexplicably started seeming to be in favour of it. Connect the dots yourself.

Why don’t you spell out the conspiracy theory directly? It’s not relevant to this thread even if true but leaving the details vague makes it seem like you don’t think it would stand up.

Re: The Dangers of Microsoft Pluton

#525
post #523

Earlier quoted context omitted.

Making this about Pluton rather than about TPMs in general just means that people will believe they're somehow safe from the worst case outcome because they bought a CPU that doesn't have Pluton They certainly will be, if most people don't have Pluton. If only a minority have it, they wouldn't be able to even come close to requiring it.

Which would do nothing to prevent them from rolling out draconian remote attestation technologies, if they wanted to.

Of course it would. The fact that almost no one has the hardware to attest, would mean trying to do that becomes extremely unpopular and shunned.

Re: The Dangers of Microsoft Pluton

#526
post #524

Earlier quoted context omitted.

Consider that the one whose comment is currently at the top is pro-cancel-Stallman, and he also works on "free" software related to secure boot --- not as in breaking, but instead aiding its adoption. The FSF was strongly against secure boot, then inexplicably started seeming to be in favour of it. Connect the dots yourself.

Why don’t you spell out the conspiracy theory directly? It’s not relevant to this thread even if true but leaving the details vague makes it seem like you don’t think it would stand up.

You only think it's a "conspiracy theory" because that's what they have told you to believe. The organisations of OSS have been infected with those whose ultimate goal is to EEE, and they will do it by whatever means they have available to them.

Re: The Dangers of Microsoft Pluton

#527
post #523

Earlier quoted context omitted.

Which would do nothing to prevent them from rolling out draconian remote attestation technologies, if they wanted to.

Of course it would. The fact that almost no one has the hardware to attest, would mean trying to do that becomes extremely unpopular and shunned.

Windows 11 requires hardware that enables this capability. Any Windows certified client systems have required this since 2014. Pluton provides no attestation capabilities that are not present in TPMs.

Re: The Dangers of Microsoft Pluton

#528

Earlier quoted context omitted.

The problem you are describing will be irrelevant in a generation or two, as kids grow up on the internet.

I can assure you that the upcoming generations aren't much better at any of this, on average. And no, it's not smartphones' faults. Most people just don't "get" desktop OS paradigms, or how web pages work, or any of that, and they don't really care to.

Most people just don't "get" desktop OS paradigms, or how web pages work, or any of that, and they don't really care to.

That's because they "won't miss freedom they never had".

Re: The Dangers of Microsoft Pluton

#529
post #523

Earlier quoted context omitted.

Which would do nothing to prevent them from rolling out draconian remote attestation technologies, if they wanted to.

Of course it would. The fact that almost no one has the hardware to attest, would mean trying to do that becomes extremely unpopular and shunned.

Windows has had TPM 2.0 since 2016, and remote attestation can be accomplished with the TPM only without Pluton being necessary. However, Pluton has its own issues and appears to make implementing attestations easier, by supporting different attestation protocols - and by potentially receiving new updates for that functionality later on. Pluton is also significantly stronger against attacks which have occurred on TPMs previously.

https://www.bleepingcomputer.com/forums/t/613941/tpm-20-is-m...

Re: The Dangers of Microsoft Pluton

#530
post #448

Earlier quoted context omitted.

> All Florida did was add a criteria to their selection process to disallow books that include Critical Theory/Critical Race Theory or their praxis in the teaching of math, etc. Yep, one state decided to do something about this divisive indoctrination of kids and the peddlers of that stuff obviously don't like it, hence the "banning (math) books" stories. If you actually read into this you quicky realize that someone…

"It's not the Republicans" Do you know what Critical Race Theory actually is, and where it's taught?

What, are about to tell me that well akshually crt is only taught at the uni level? Give me a break. This is the most basic of defenses you can use and it has been done countless times before. Obviously CRT (or CT in general) itself is not being taught to little kids, but the C(R)T praxis is. I.e. C(R)T "applied" to concepts kids can understand. I've seen the books/questionnaires that are being used for this purpose, do I have to list some them?

I mean, this isn't even about Republicans, Trumpians or whatever, any self-respecting liberal can't possibly subscribe to c(r)t and still call himself/herself a "liberal".

Post reply on HN