Live data from Hacker News

The Dangers of Microsoft Pluton

gabrielsieben.tech

541–550 of 554 posts

Re: The Dangers of Microsoft Pluton

#541
Hardware-based attestation of the running software is an important security feature, especially in a world where data leaks and identity theft are rampant.

Let's say I'm a healthcare provider, and I'm about to send your medical data to a third party vendor. Wouldn't you prefer that your data only be able to be decrypted by a computer can prove to the world it booted a clean OS image with all the latest security patches installed?

If the vendor wants to install some self-built OS that they trust on their computer and not update it for 5 years, that's their business, but I may not want to trust their computer to have access to my data.

Remote attestation gives more control to the owners of data to dictate how that data is processed on third-party machines (or even their own machines that may have been compromised). This is useful for more than just DRM.

Re: The Dangers of Microsoft Pluton

#542

Earlier quoted context omitted.

The problem you are describing will be irrelevant in a generation or two, as kids grow up on the internet.

I can assure you that the upcoming generations aren't much better at any of this, on average. And no, it's not smartphones' faults. Most people just don't "get" desktop OS paradigms, or how web pages work, or any of that, and they don't really care to.

Nah dude. Most young people nowadays have an inbuilt sense of which links are sus; it's not exactly rocket science. If it looks sus, it is.

Re: The Dangers of Microsoft Pluton

#543

Earlier quoted context omitted.

The goal is not to prevent you from running Linux, is to make it so that Linux cannot access the content you are interested in. Remote Attestation establishes a root of trust that can be used to verify that all of the software down the line is "approved": - You won't be able to browse sites or use apps with ads unless you run a 'trusted' device, OS and browser that does not block ads. - You won't be able to browse si…

>- You won't be able to browse sites How would that work? HTTP is just HTTP

The website says "prove that you don't control this computer or I don't serve you"

As does every financial or government website for 'security'

Re: The Dangers of Microsoft Pluton

#544
post #285

I remember when Microsoft introduced driver signing, i remember articles in Slashdot and TheRegister going wild about how Microsoft was about block side-loading third party software, and only allow software which they specifically authorized to run on Windows or that they would charge large % fees to allow 3rd party software to be installed. When those these restrictive practices were introduced with iOS and to a muc…

Yep. People have been banging the drum on TPMs and similar security chips being the end of personal computing for about 18 years now. Still waiting.

"This water is only 90 degrees, you're fucking crazy, the pot's notgoing to boil."

Re: The Dangers of Microsoft Pluton

#545
post #447

This is not a good article. At a technical level it's confused about a whole bunch of things: * SMM has been part of x86 for decades . The Secured Core requirements around SMM actually reduce its power. * The claimed requirement to remove the third party UEFI CA certificate from 2022 Secured Core PCs is entirely unrelated to Pluton (it's required regardless of whether Pluton is enabled or not, and even whether the CP…

TPMs were often separate chips so you could just eavesdrop on a few pins and with that you could pretend that you are running an OS you are not.

Re: The Dangers of Microsoft Pluton

#546

The thing I fear the most with this is "proof that secure boot has never been disabled". This is just a way to brick your device from accessing services. What if you government's tax service requires such proof? Or bank? I cannot count how many machines I booted on Linux to rescue a hard drive, or image it, or wipe it, or just to install linux on them. All those devices, boom, paperweight for regular personal use. I…

This is already a problem with SafetyNet hardware attestation on Android. Because it's so easy to implement on the app side, everything from banking apps to games is verifying the device is running a blessed system image with a locked bootloader and no root access (read: no access to general-purpose computing). As a developer of a banking app, I do my best to avoid implementing this user-hostile crap, but not all dev…

I never knew SafetyNet was a thing, and wow, what a bullcrap thing for the basic consumer.

Thank you for being a smart banking app developer. There is so much bullshit in most of those apps that I consider them as "worst apps on my phone", but due to management incompetence rather than developer incompetence.

Re: The Dangers of Microsoft Pluton

#547
post #272
post #241

Earlier quoted context omitted.

Secure chips like this are already in all devices but PCs. And in none of these areas has any of that happened. Quite the opposite, Apple got a fine when they slowed down older devices to save battery (at least what they said). So the government will clearly help out here. And none of these companies has an incentives to stop sales to smaller companies, they make a lot of money with those.

Try to install a BitTorrent client on your iphone, or a game emulator, a sexually explicit game or even a browser with a different engine. All this has already happened since 2008 when the app store came out.

Soon you will be able to do it in EU, thanks to government.

Re: The Dangers of Microsoft Pluton

#548
post #204

and all that crap will get eventually pwned anyways

Pluton first debuted in the Xbox One. It's possibly the first home console that went it's entire lifespan without being hacked. That should tell you everything about the threat we are facing.

That may be true, though the problem with releasing such a high profile exploit is that it's patched quickly. So IMO anyone with access to hardware / talent required to crack the xbox is probably sitting on that knowledge and extracting as much value as possible from it, instead of taking it public.

Re: The Dangers of Microsoft Pluton

#549
post #2

Ew. Why are all the chip manufacturers going along with this stupid plan? I want to buy a processor and then own it and have it work in my best interests, not consume electricity and generatie heat enforcing draconian 3rd party DRM policies.

The conspiratorial answers here are emotionally satisfying, but ultimately wrong. The reason chip makers and OS vendors are adding this is customer demand, by which I mean enterprises. Companies want remote attestation and guaranteed-immutable OS images on their networks, and I honestly can't say I blame them. In a perfect world they could have it and we could somehow firewall it away from the consumer space entirely…

Haven’t looked at the Intel space, but doesn’t AMD have an “PRO” tier available for OEM only? Ryzen Pro, Threadripper Pro… Or Nvidia and their segmented RTX/GTX vs Quadro. These hardware companies love segmentation, let them have it, do that for PRO enterprise only, leave my personal use, no remote attestation, immutable OS needed PC alone.
Post reply on HN