Live data from Hacker News

Retiring Windows 10 and Microsoft's move towards a surveillance state

scottrlarson.com

401–410 of 514 posts

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#401

Earlier quoted context omitted.

But most people don't want to enter a password, and if you make people enter a password too much, they'll choose terrible passwords and put them on a sticky note. Windows Hello can only be done securely with a TPM. A server that I want to turn back on all by itself after a power outage can only be done securely with a TPM. I want a TPM in my computer so I can have the security and convenience. Yes, it's another point…

>Windows Hello can only be done securely with a TPM I think in general biometrics are in the same ballpark as low-entropy passwords. IDK, I personally have no faith in trusted computing hardware because it can be broken with the right equipment. You're right that it can be used alongside ordinary security measures, but I just think it encourages putting your eggs into a cryptographicially-weak hardware-strong basket…

> >A server that I want to turn back on all by itself after a power outage can only be done securely with a TPM.

> Can you describe how this prevents a MITM attack? I assume you mean a remote server? I've heard of colocation setups like this, but I think they rely on a couple of unstated assumptions.

I'm not sure what you mean by prevent a MitM attack, unless you're worried about someone with probes MitM-ing your TPM-CPU connection in the DC.

You can bind a TPM to measurements on the host (let's say for argument's sake you want Secure Boot state, Option ROM state, and UEFI state), then configure the OS to ask the TPM for the (or rather, a) decryption key during boot.

The TPM will check that the state(s) you bound to is (are) the same as when you bound them, and if so it will give the OS the key. Your disk is encrypted, but the boot process is automatic/unattended, as well as completely contained within the server chassis.

There are ways to attack this hypothetical setup, buuuuut there are ways to attack remotely entering your disk password as well, and bear in mind that denial of service is a security vulnerability. Tradeoffs.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#402
post #41

I agree with all of the articles points except for the first one: TPM and Secure Boot do not reduce user choice or promote state or corporate surveillance. If you want to be able to prevent root kits you need secure boot, and if you want to store secrets that don't need a user password to unlock and can't be stolen by taking apart the computer, you need a TPM; or you need substantially similar alternatives. I would s…

> If you want to be able to prevent root kits you need secure boot

I think this is very misleading. Secure boot was a response to the poor security of commodity operating systems which allowed programs easy access to make low-level system modifications. In other words, the poor security models of commodity operating systems was the actual cause that allowed rootkits to spread and become a major threat that required mitigation.

In an alternate world in which operating systems enforced least privilege on all programs, the likelihood of a rootkit spreading would be orders of magnitude smaller, almost not even worth mentioning. The motivation for secure boot in this world is really only to prevent supply chain attacks, which can also be solved by just buying hardware from reputable companies. Secure boot arguably would not have been created in this world, thus avoiding the new dangers inherent to it.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#403
post #342

Earlier quoted context omitted.

That's Windows doing that, which they've just compromised and then configured to display only the normal login prompt but send your credentials to the attacker. They can also decrypt your hard drive by doing the same thing without modifying the original machine by just stealing it and leaving you a compromised one of the same model to also steal your password.

If evil maid attack, and you see this prompt, you a) re-enable secure boot, if did not work b) throw away the device. In any case data stays secure. Edit: Hmm, you have a point, how do I know secure boot was disabled in the first place? Anyway, still works for servers and unattended reboots.

No, GP is misinterpreting Windows's message. It prompts for a recovery key because the TPM is bound to, among other things, Secure Boot == enabled. When Secure Boot is disabled, the TPM notices that and refuses to release the key, that's how you know to reënable Secure Boot or throw away your device.

The fact that Windows is compromised does not make it capable of extracting secrets from the TPM, though maybe a naïve user can be convinced to enter the recovery key anyway...

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#404
post #41

I agree with all of the articles points except for the first one: TPM and Secure Boot do not reduce user choice or promote state or corporate surveillance. If you want to be able to prevent root kits you need secure boot, and if you want to store secrets that don't need a user password to unlock and can't be stolen by taking apart the computer, you need a TPM; or you need substantially similar alternatives. I would s…

> If you want to be able to prevent root kits you need secure boot I think this is very misleading. Secure boot was a response to the poor security of commodity operating systems which allowed programs easy access to make low-level system modifications . In other words, the poor security models of commodity operating systems was the actual cause that allowed rootkits to spread and become a major threat that required…

Yes, but when an individual hacker needs a secure computer and is deciding which computer to buy, it does him no good to tell him that if the whole industry had evolved in a more convenient way over the last 4 decades, he would have been able to avoid secure boot: in the actual world, the only user-facing computers on the market with decent security use secure boot to help deliver that decent security where "user-facing" means "used to browse the web and maybe other things".

Also remote attestation has pro-social uses. Without it, photographs will soon become useless as evidence because soon there will be no way to distinguish a photo of a real scene from the output of generative AI.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#405

I have said this 10 times on HN and i ll say it again. Release a version of Windows 11 called "Windows Optinmal" that has 0 telemetry, 0 trackers, 0 bloatware that runs faster than Windows 7 on modern hardware. Charge 4x the prices if you want, I ll pay happily

What if 4x is too low? How much more would you agree to pay?

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#406
post #373
post #296

Earlier quoted context omitted.

ok, so someone makes the license available for end user to read or not, thats one down for providers responsibility. now the next is the nature of linux as a common good, generated by many contributors over some time. is it acceptable for anyone to turn a profit from distributing copies of linux on media, or as a component of a retail unit, for an additional price ? how does that scale up? suppose thousands of ISOs o…

You may find it morally objectionable to sell distributions of free software for a fee but for F/OSS licensing in no way forbids that. GPL version 3 explicitly says "you may charge any price or no price for each copy that you convey". The MIT license also explicitly allows selling the work. No other free or open source license forbids selling either. In fact the Open Source Definition from OSI expressly says: "The li…

thank you, that reinforces the idea that selling a "freeware" is how you harvest bad karma from your customers, it makes common sense. you want to provide value and pertinent disclosure to your customers.

theres nothing wrong with a wage for time and effort.

i think contributors could probably handle free coffees extended toward acknowledgement of the effort.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#407
post #141

Earlier quoted context omitted.

Some things that any semi-power user will notice and get angry at: * Needing internet and a microsoft account to install the OS * Start menu now requiring two clicks to get to programs list * Right-click requiring two clicks to get to the options you most likely want to use (e.g. 7z unzip or opening in a specific program) * Task manager being slow and laggy * Random ads asking you to install a game pop up in the noti…

Right-click requiring two clicks to get to the options you most likely want to use (e.g. 7z unzip or opening in a specific program) This one you can still change. It is some hidden registry tweak, but there is the capacity to always "show more options".

Changing the registry is far too much of a hurdle.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#408

Earlier quoted context omitted.

This. Google and Microsoft are the two juggernauts in this arena, Apple products live on the periphery of the corporate cloud ecosystem.

Based on the corporate IT emails I receive from time to time, it also sounds like Apple enterprise management controls are weak to non-existent. A few times a year, there is a blast sent out to not upgrade your corporate iphone/mac because of some incompatibility. In the Windows world, IT would just hold back the patch without requiring N users to do the right thing.

This is true. Anyone who needs to manage Apple devices in a corporate IT setting is probably using Jamf.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#409

I think describing TPM and Secure Boot as "artificial limitations" is unfair. Many Linux distros have no problem working with both of these and they serve a valuable purpose. The problem is not that they exist or that Windows 11 supports them. It's that Microsoft pretends they are required , when they are not.

They have good reasons to be required, though: Secure Boot reduces the ability of malware to infect the bootloader. TPM gives a strong foundation for things like Passkeys. TPM also enables things that average users care less about like DRM, but Passkeys are a good idea and having them more-secure-by-default is good for the average user (even with accidental vendor lock-in implications).

The reason they are required is that, so far, every platform that has widespread TPM use is completely locked down. Microsoft would very much love for you to essentially rent your computer from them like you do with Apple and Google.

There are security boons, sure, but these are a side effects. They are not what TPM is for.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#410

Earlier quoted context omitted.

> This was not the case with the initial rollout of Secure Boot, it was combined with locked BIOS to lock PCs so that they could only boot Windows 8 on some devices. This was the case on Windows RT ARM machines from that era. Okay, but, that was like 15 years ago, on some shitty first-run computers that no one bought. A failed first attempt. I've never met a single person that owned, or has ever used, a Windows RT de…

Normally I would agree that security measures are needed in many, but not all cases, but only if they are in complete control of the user and cannot by altered by any one organization. For-profit companies cannot be in control of these mechanisms. We have seen how they can be abused with the latest decision by Google to limit side-loading to people who identify themselves. So your take is really a misdirection from h…

> For-profit companies cannot be in control of these mechanisms.

But they are not in control of Secure Boot.

Microsoft runs a root CA that is pre-installed on most PCs. It could have been Verisign or someone else, but MS made sense at the time, likely because they had additional code signing expertise.

You are free to delete these keys and/or install your own. If there wasn't preexisting infrastructure, Secure Boot would be DOA for most people.

Post reply on HN