7 ms·
Microsoft's Use of Pluton Suggests It Sees PC Owners as the Enemy
- car_analogy 4y agoThe strongest part of the article is piecing together the motivation and purpose behind Pluton: In order to perhaps peek behind Microsoft's curtain a bit, let us look at what Pluton was designed to accomplish. When Microsoft announced Pluton in 2020, it said, "The Pluton design was introduced as part of the integrated hardware and OS security capabilities in the Xbox One console" [..] But, what is the source of these physical attacks? Who are the attackers? As stated above, the Pluton design evolved from work done to prevent successful attacks against the Xbox One. Here is what Tony Chen, Xbox One's lead software engineer explained "I want to talk to you about what we did on Xbox One to guard against physical attacks. [..] Ever since the very first Atari game console, for decades and decades, every game console maker has had their console been hacked such that people can play pirated games. [..] I'm proud to say that the Xbox One, which was shipped in 2013 for the last six years, at least we have not seen any evidence that anyone was able to break it for piracy or cheating" In sum, it was designed to provide security against the owner. And all the defense of Pluton/TPM rests on persuading you that it won't be used for what it was designed and built for.
- schoen 4y agoWhen I was at EFF, I often made arguments like this. I was surprised to find that, in the video game console context, a pretty significant number of gamers vocally disagreed! Basically, they felt that a "good" console ecosystem was a rare and precious thing, and that it required things like curation, and inducement to developers to invest, which in turn required extensive control over players to make sure that they used their consoles only in approved ways, with approved software. I'm trying to think of analogies to make this make more sense to me or other people like me. I think there is some comparison to be made to security checkpoints that someone might try to require before giving the public access to some place or activity. Probably not coincidentally, I don't like those either and don't want to see them expanded to more places and circumstances and parts of life. However, someone might sympathize with the concerns of the people creating the checkpoints strongly enough as to say "although these measures are intrusive and could be viewed as intruding on my rights, I feel that realistically the likely alternative is not getting to (fly|meet the president|meet the Queen|hold this expensive diamond) and that I can't see a path to getting to do that otherwise, so the choice for me seems like I should naturally accept the intrusions in order to get to do the thing". Some of the gamers were saying, well, I want to play games that cost many millions of dollars to make, and the people who make those games say they want to target platforms where they get certain guarantees about restrictions on the players, otherwise they won't be able to invest that kind of money. Some possible responses that come to mind, both in the analogy and the world we live in: * We should have more Schelling fences to stop the spread of restrictions and control into more areas of life. * We should find other ways of addressing the legitimate parts of other people's concerns, without intruding on individual freedoms as much. * These rights should be treated as sacred, so too bad if other people aren't willing to respect them, or if they then don't do things that you wanted. (Or maybe activities that require certain levels of intrusion in order to be feasible or safe should just not occur at all.) * Maybe people are lying, or mistaken, about the level of control that they actually need in order to let you do the things you want. Can we coordinate to call their bluff? It's also a little complicated if you include the cheating part alongside the illegal copying part (and the games -- or HPC applications! -- developed with no royalty to the console maker part). There, many gamers do see gamers-in-general as the enemy, though not necessarily themselves; like "we're not trustworthy, as a group, so we need measures to stop the numerous cheaters among us from ruining things for the rest of us". I was genuinely surprised to see many of these phenomena. (In a couple of cases, I think EFF announced some kind of support for people who were reverse engineering hardware to make it able to run unofficial software, and some gamers said "hey, you're supporting the bad guys here"!) But I'd like to hear other people's ideas about how to contend with them.
- car_analogy 4y agoThe concerns about cheating are valid, but we already have consoles to address them. I dread the possibilities of control in moving more activities, not just gaming, to the console model. Forget ad-blockers, there are already sites that prevent even copy-pasting of text unless one disables javascript. > Maybe people are lying, or mistaken, about the level of control that they actually need in order to let you do the things you want. Can we coordinate to call their bluff? They were lying when they claimed home taping was killing music, and that VCRs [0] were to film producers "as the Boston strangler is to the woman home alone" [1], and more recently, a EU-funded study that found piracy causes little harm was suppressed [2], so they should certainly not be taken at their word. > When I was at EFF Thank you for your service :) [0] Ironic that, with how difficult saving video has become from streaming sites and services, we have largely lost the abilities the VCR afforded us. A good example of how quickly technology is turned against us. [1] https://en.wikipedia.org/wiki/Videocassette_recorder#Legal_challenges https://en.wikipedia.org/wiki/Videocassette_recorder#Legal_c... [2] https://juliareda.eu/2017/09/secret-copyright-infringement-study/ https://juliareda.eu/2017/09/secret-copyright-infringement-s...
- dane-pgp 4y ago> there are already sites that prevent even copy-pasting of text unless one disables javascript. Worse, there are sites that prevent even viewing of text unless one enables JavaScript. Anyway, to assist the GPP, and inspired by your user name, let me suggest that requiring TPM checks for people running (games on) PCs is like requiring your car to breathalyze you before starting the engine. (As Doctorow famously said "A car is a computer you put your body into"). The public would never allow that, right? https://www.forensicmag.com/578254-Infrastructure-Bill-Would-Require-Breathalyzers-for-All-New-Cars/ https://www.forensicmag.com/578254-Infrastructure-Bill-Would...
- Affric 4y ago>let me suggest that requiring TPM checks for people running (games on) PCs is like requiring your car to breathalyze you before starting the engine. There are situations where this would make an individual less safe but for people who have received DUI this is a reasonable and existing practice. I don't think it maps to computers, where rarely are lives on the line.
- naikrovek 4y ago> it was designed to provide security against the owner no. no, no, no, no, no. holy crap, no. no. it was designed to prevent unauthorized access to hardware. corporations own computers, too. and you know what is on a lot of the computers they own? trade secrets. who wants those trade secrets? competitors, copycats, and so on. what is something that such motivated actors have a large amount of? money. money to hire thieves. money to buy expensive equipment. people to attempt to circumvent security measures. Pluton is designed to address situations like this. no one cares about John and Jane computer owner. Pluton will not be used against John or Jane unless John or Jane allow it, in some unforeseen situation I can't imagine. Pluton is a very good weapon for corporate IT admins trying to secure their devices. "BUT TPMs ALREADY DO THAT" not unless you require a PIN on boot, and PINs on boot are a pain in the ass. no one likes them, no one wants them. they often have huge complexity requirements and can be easily forgotten. PINs suck. they suck so much that some unfortunate companies decide against the PIN requirement and implement things like BitLocker using the TPM alone, and that is extremely insecure to anyone with physical access to a device because TPM traffic can be captured. "that seems like something that is very difficult and will never happen." it's very easy: https://news.ycombinator.com/item?id=29258879 https://news.ycombinator.com/item?id=29258879 Pluton was designed for the same thing that the Intel Management Engine and other related technologies were designed for: corporate IT administrators.
- car_analogy 4y agoIn other cases where enterprises wanted something that consumers cared little about (ECC RAM comes to mind, or the artificial limit on number of concurrent connections in non-server Windows editions), manufacturers were happy to cripple their product for consumers, so they could charge a premium to less price-sensitive enterprises. But when it comes to Pluton, or the AMD and Intel management engines, they're making sure you can't buy a product without them at any price. > it was designed to prevent unauthorized access to hardware. Yes and it's all a big coincidence there's no owner override, so that only the manufacturer decides what is "authorized".
- naikrovek 4y ago
- meristohm 4y agoBrings to mind the book Little Brother by Cory Doctorow. I far prefer non-DRM media and avoid buying books with it. TOR publishes some non-DRM books, for one. There is DRM on public library ebooks, fine for now, but it feels like a symptom of a flawed system. Assuming most people want to live with a sense of purpose, and some find that purpose in making art (stories in whatever form), I'd rather a system in which we're more-free to follow a creative path and the barriers to learning from those stories is lower. Might be that a healthy baseline is small communities making art together (think hunter-gatherer community singing, dancing, playing instruments, making sculpture, drawing, and telling stories, no busking and no locked doors, unless an unwelcome stranger comes along). What would it look like to maintain some level of global electronic connectedness and significantly lower the barrier to accessing art? Is the current public-library model in the USA enough? From my experience with low-income high-school students afraid to enter a library because their parents borrowed a bunch of materials on the student card and racked up hundreds in late fees, there's room for improvement. And then there's the question of what's a healthy balance between work and leisure? We're riding a wonderful wave of petroleum for now, and I'm really enjoying keeping up with distant friends via co-op videogames, but I accept that it's icing on the cake of life. Sitting around a handmade wooden table in a makeshift shack playing chess by firelight is a few layers back down to earth.
- naikrovek 4y agoCory is the most "foam-at-the-mouth" person I have ever even heard of. Cory reads about something, stops at the very first hint of something that would inhibit his freedom, and writes extremely long and completely misguided manifestos that go directly away from the conclusion he would reach if he had even partial understanding of the situations he writes about. the very worst thing about him is that he sounds hinged, people read his stuff, when he is in fact very much unhinged almost all of the time. i dislike DRM too, a lot, but it exists for very good reasons. the public has repeatedly and strenuously shown every single company that produces anything that can be copied that large armies of people will do the copying and take the content without paying even a single penny. 25% of all PC video game players have pirated more than 50 games. approximately 1/3 of all PC gamers pirate games (as of 2016)[0]. Reminder that the video game market is larger than the movie and music industries combined, and that market does not include the games that are pirated. [0] https://www.pcgamer.com/pc-piracy-survey-results-35-percent-of-pc-gamers-pirate/ https://www.pcgamer.com/pc-piracy-survey-results-35-percent-...
- sally1620 4y agoThe physical attack Microsoft worried about is hacker extracting information from a stolen laptop. It only takes a single laptop (out of thousands) to infiltrate the company network and steal source code or whatever. For enterprise users, this attack vector is a real threat. Microsoft definitely wants to dog food this technology to their own employees to avoid getting hacked.
- elisharobinson 4y agoThey are making a case for treating your pc like a embedded device or consumer electronics device. Where changing the OS is considered to be a crime cause you "hacked" the firmware and installed a new one.
- josephcsible 4y agoOrdinary full-disk encryption protects against that just fine, though.
- naikrovek 4y agonot without requiring PIN entry upon boot. TPMs are external to the CPU and traffic to and from them can be intercepted and used to decrypt the disk. there was an article on that exact situation a few weeks ago, right here on HN. https://news.ycombinator.com/item?id=29258879 https://news.ycombinator.com/item?id=29258879
- josephcsible 4y agoI meant ordinary full-disk encryption with a regular passphrase and no TPM in the picture at all.
- astrange 4y agoTypical AES-XTS full disk encryption is not safe enough for the laptop case; it’s not authenticated and someone can edit encrypted files. File-based encryption (like the one T2 and later Macs use) is safest.
- jameslao 4y agoPluton seems like the next evolution of the TPM which has been around for many years. Many (most?) modern CPUs have a TPM built into the CPU already (Intel PTT and AMD fTPM) so it's not a huge change from the status quo as far as I can tell.
- ncmncm 4y agoYou are describing the "management engine", a different thing, also a problem.
- jameslao 4y agoHow so? Intel Platform Trust Technology is TPM implemented inside the CPU. Intel Management Engine is a separate thing as far as I can tell.
- naikrovek 4y agono, they're describing an fTPM. pro-privacy people always seem to lack a lot of understanding around modern security landscapes and make a lot of assumptions that aren't true anymore (if they ever were). I mean no offense, by the way, it makes me want to conceive a modern security primer for privacy advocates, because the community appears to have fallen behind a bit. like any community that focuses on one thing, that focus is often at the expense of other things.
- twirlock 4y ago
- antifa 4y agoSeeing users as their enemy would explain their windows 8+ and msteams strategy.
- naikrovek 4y ago
- antifa 4y agoWindows: forced updates, forced unscheduled restarts, telemetry, spying, ads, cortona, forced surprise download of the entire windows 10 onto windows 7 systems, dark patterns, https://en.m.wikipedia.org/wiki/Criticism_of_Windows_10 https://en.m.wikipedia.org/wiki/Criticism_of_Windows_10 Microsoft Teams: high CPU and RAM usage, electron, there is literally a UI/UX bug with every interaction, it strips away formatting I wanted while always keeping unwanted formatting, ignores the paste with shift convention to paste without formatting, forced WYSIWYG, scrolling randomly flies away seconds after I've reached where I wanted to scroll to, search is cumbersome, images sporadically timeout when trying to view them, users occasionally experience messages appearing sent but the recipient never got them or they never left the user's device. These bugs are over a year old and generally not fixed.
- naikrovek 4y agoneither I nor any of the people I work with have ANY of those issues with Teams, so I am going to have to blame an inadequate network or overzealous QoS somewhere causing a lot of that. updates: users have shown Microsoft time and time again, that unless forced, users simply will not update their computers. the result was that we had an internet teeming with unpatched Windows systems getting very bad worms when the vulnerability was patched 6-months prior. everyone, including powerful governments, blamed Microsoft when the users were at fault. so now Microsoft forces updates, because we won't do it unless we are forced, and now everyone blames Microsoft. we put them in a corner, and now we deal with our complacency. so, we blame Microsoft when we don't do the right thing, and we blame Microsoft when they force us. genius. restarts: literally never had a windows machine restart without telling me many hours prior. I think you all don't check your notification icons and let things live behind that "more..." arrow. telemetry is fine, you can view it and delete it. spying: doesn't happen. no one cares what you do and you are not important enough to spy on. the forced win 10 upgrades were bullshit. you got me there, and I've never once defended that practice.
- reanimus 4y agoTo be fair, this person openly admits they don't understand the security proposition here. Pluton is certainly daunting and brings concerns to mind, but I'm going to take this person's thoughts with a grain of salt considering they extend that same suspicion to the TPM -- a piece of hardware that arguably provides great security value to the user. That it's difficult to explain to the lay person (which I disagree with, personally) doesn't mean that it's bad, and while they acknowledge this, I think the answer is to try to dig in and understand better, not throw around suspicion out of some sense of intuition. When you dig into this, Pluton is generally going to be shipped in one of three configurations: 1. Pluton presents itself as a TPM 2. Pluton doesn't emulate a TPM, can run other code (usually platform resiliency features, so think enterprise systems) 3. Pluton is disabled Essentially, this is a standardization of the "firmware TPM" tech you can find in modern Intel/AMD processors, and they even mention that part of the driving reason behind this is that the current TPM status quo often incorporates a discrete TPM chip, which is vulnerable to attacks that intercept communication on the bus used by the TPM (thus allowing someone to steal encryption keys). This essentially moves to having a firmware TPM as a standard, as well as providing a more standardized API/update mechanism. I have qualms with Microsoft spearheading the effort alone, but at face value, I don't think this is something bad. I think that hardening hardware against all forms of attack -- even physical -- is good. Just because it's not something you have to worry about (re: evil maid) doesn't mean someone else doesn't! (For reference, this article covers a lot of what I'm referring to: https://noise.getoto.net/2022/01/09/pluton-is-not-currently-a-threat-to-software-freedom/ https://noise.getoto.net/2022/01/09/pluton-is-not-currently-...)
- naikrovek 4y ago> I have never understood the need for TPM's. that phrase alone renders any opinions of the entire article invalid. I stopped reading at that sentence, because it conveys a complete lack of understanding of the problems that TPMs, and Pluton, solve.