Live data from Hacker News

Retiring Windows 10 and Microsoft's move towards a surveillance state

scottrlarson.com

411–420 of 514 posts

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#411

Earlier quoted context omitted.

> If you want to be able to prevent root kits you need secure boot I think this is very misleading. Secure boot was a response to the poor security of commodity operating systems which allowed programs easy access to make low-level system modifications . In other words, the poor security models of commodity operating systems was the actual cause that allowed rootkits to spread and become a major threat that required…

Yes, but when an individual hacker needs a secure computer and is deciding which computer to buy, it does him no good to tell him that if the whole industry had evolved in a more convenient way over the last 4 decades, he would have been able to avoid secure boot: in the actual world, the only user-facing computers on the market with decent security use secure boot to help deliver that decent security where "user-fac…

My point is that secure boot isn't the only way forward, and depending on your circumstances, a foundation built on something like seL4 could suffice for particular applications. And it doesn't even require a whole new OS or foundation like seL4, even Windows has the right core primitives if they're used in the right way [1]. And that work was from 2005, not 40 years ago, but still long before any of this really became an issue.

[1] https://cacm.acm.org/research/polaris-2/

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#412
post #41

I agree with all of the articles points except for the first one: TPM and Secure Boot do not reduce user choice or promote state or corporate surveillance. If you want to be able to prevent root kits you need secure boot, and if you want to store secrets that don't need a user password to unlock and can't be stolen by taking apart the computer, you need a TPM; or you need substantially similar alternatives. I would s…

> Microsoft didn't need to add that requirement.

Yes, they did. It was written by the specter of the US Department Of Justice.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#413

Earlier quoted context omitted.

They have good reasons to be required, though: Secure Boot reduces the ability of malware to infect the bootloader. TPM gives a strong foundation for things like Passkeys. TPM also enables things that average users care less about like DRM, but Passkeys are a good idea and having them more-secure-by-default is good for the average user (even with accidental vendor lock-in implications).

The reason they are required is that, so far, every platform that has widespread TPM use is completely locked down. Microsoft would very much love for you to essentially rent your computer from them like you do with Apple and Google. There are security boons, sure, but these are a side effects. They are not what TPM is for.

Microsoft isn't Apple or Google, so assuming their intent here is a bit of an "all your friends are jumping off the bridge so you must want to jump off the bridge" fallacy.

Stated primary intent by Microsoft for TPM is Passkeys (because Microsoft has key incentives to kill Passwords and reduce Phishing) and Netflix-class DRM (because people want to still be able to watch Netflix on their PCs).

Sure, Microsoft has also tried locked down "Store-only" versions of Windows (partly to appease Educators who moved to Chrome OS for that need/compliance requirement), but also has heard loud and clear that isn't the version of Windows that will drive sales from the market at every one of those attempts. At this point there should be no way that Microsoft still thinks they can lock down Windows as much as Apple and Google lock down their phones. If anything Android moving even more locked down seems to be a marketing opportunity for Windows to point out that they generally won't.

Microsoft isn't perfect, and isn't a monolith (I'm sure there are executives that wish Microsoft was in the position of Apple or Google right now), but the flip side, Microsoft is a company with products to sell and the market tells it doesn't want locked down Windows and for the most part Microsoft is incentivized still to not lock down Windows. Basic greed is an easier explanation for their past and future behavior than imagining some conspiracy where Apple, Google, and Microsoft are all in it together to kill the unlocked computer.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#414
post #397

Earlier quoted context omitted.

Just use Linux Mint

i'll be looking at fedora kde, cachy os, arch, maybe omarchy. either way i am definitely going for KDE. i always run ubuntu servers, but i tested few distros this year, i was mostly looking at fedora and suse, which are not rpm distros, but i was not happy, still, with some things. so i will have to do proper testing when time comes. i see fedora as "big" distro with good backing. arch as configurable distro. cachy s…

Trust me, just Linux Mint

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#415
post #406
post #373

Earlier quoted context omitted.

You may find it morally objectionable to sell distributions of free software for a fee but for F/OSS licensing in no way forbids that. GPL version 3 explicitly says "you may charge any price or no price for each copy that you convey". The MIT license also explicitly allows selling the work. No other free or open source license forbids selling either. In fact the Open Source Definition from OSI expressly says: "The li…

thank you, that reinforces the idea that selling a "freeware" is how you harvest bad karma from your customers, it makes common sense. you want to provide value and pertinent disclosure to your customers. theres nothing wrong with a wage for time and effort. i think contributors could probably handle free coffees extended toward acknowledgement of the effort.

> thank you, that reinforces the idea that selling a "freeware" is how you harvest bad karma from your customers

Well, you should, because doing so generally requires exploitation of the ignorant or an outright scam.

But the additional value provided might be as simple as (pre)installing the OS and making sure it works with the hardware. Or transferring the customer's data from their old OS for them. I see nothing wrong with charging for those. I might not pay for them since I can easily do them myself but they can be valuable services to others.

Hypothetically you could also sell copies of a distro on physical media to somewhere with poor internet access and it would be fine. People did that in the 90's even in rich countries.

Of course it all sort of depends on how much you charge and for what. You probably still couldn't charge $100 just for the copy without some kind of exploitation since informed people would figure out cheaper ways of getting it.

And of course if you just took an existing distro, changed its name and branding to RolphOS without adding anything of value, and then sold ISO images for $100 to the ignorant by presenting it as your unique special OS, you would get a bad name in the community. It probably still wouldn't violate copyright if all the software were open source, you didn't claim copyright for anything you didn't write and you retained the original licenses, but it would be scammy.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#416

Where I work, I'd love to move our remaining Windows boxes to linux, but there's often software that only works on Windows. How well does Wine work these days? Can they run CAD software for example?

Not really. On linux, you have OpenSCAD (which is okay for some applications) and you have FreeCAD (which sucks imo). Right now, I just use OnShape which works in my web browser and is similar to SOLIDWORKS (and it's $0 for students). In the future I will try running windows CAD under linux using kvm and this: https://github.com/casualsnek/cassowary

Just use Windows lol

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#417
post #252

Earlier quoted context omitted.

> There is also a real potential for abusing TPMs or cryptographic co-processors to enforce remote attestation. Remote attestation can be misused, yes. But why writing it as TPM is the problem? In cases where remote attestation is used for good, TPM improves the setup, if anything. I dont see the rationale for what you wrote, and am genuinely curious what it is.

You can't do remote attestation without something like a TPM. Let's compare these scenarios: A) TPMs are optional and 30% of users have them. A bank is thinking about requiring remote attestation to use their services. Since they'd lock out 70% of users they decide to not do it. B) TPMs are mandatory and 90% of users have them. A bank is thinking about requiring remote attestation to use their services. Since they'd…

I see your point. Its the very unbalanced power balance between consumers and providers, and the dishonest tactics of the latter. It ought to be addressed politically (its idealistic, I know). Until then use free software and multiple devices, or something like that. The TPM chips in themselves are a powerful concept, that can, and should, be used to the consumers advantage.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#418
post #252

Earlier quoted context omitted.

> There is also a real potential for abusing TPMs or cryptographic co-processors to enforce remote attestation. Remote attestation can be misused, yes. But why writing it as TPM is the problem? In cases where remote attestation is used for good, TPM improves the setup, if anything. I dont see the rationale for what you wrote, and am genuinely curious what it is.

Because that's what has been going on in the Android world for years and for the iPhone was the case from the start. Root your phone, even if it is just for the ability to make full backups (because that is, to this day, not a thing on Android)? Say goodbye to banking, most games, even the proposed new EU "digital identity" government wallet was supposed to enforce attestation. And everyone with a phone on the "bad v…

Then you really should be angry at Apple and Google, not the hardware.

The preparations for eIDAS 2.0 (the EU thing) has been heavily inspired by SSI. If they keep up the good work, and implement it properly, security and privacy will be top notch. And that is only possible by using TPM (or really SE when we talk about mobile phones).

Yes, I know that eIDAS might end up not meeting the early promises. We will have to see. But in that case it will be despite the possibilities that the hardware provides, not because of them.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#420
post #41

I agree with all of the articles points except for the first one: TPM and Secure Boot do not reduce user choice or promote state or corporate surveillance. If you want to be able to prevent root kits you need secure boot, and if you want to store secrets that don't need a user password to unlock and can't be stolen by taking apart the computer, you need a TPM; or you need substantially similar alternatives. I would s…

> If you want to be able to prevent root kits you need secure boot

Secure boot is a rootkit.

Post reply on HN