Most active commenters
  • npteljes(6)
  • userbinator(3)

←back to thread

The Dangers of Microsoft Pluton

(gabrielsieben.tech)
733 points gjsman-1000 | 20 comments | | HN request time: 1.91s | source | bottom
Show context
userbinator ◴[] No.32234457[source]
What is to prevent school WiFi from one day requiring a Pluton assertion that your Windows PC hasn’t been tampered with before you can join the network?

Remote attestation is the true enemy of your freedom. The power of the authoritarian corporatocracy to force you to use only the (entire) systems they control. It's worth reading https://www.gnu.org/philosophy/right-to-read.en.html again just to see how prescient Stallman was.

replies(12): >>32234704 #>>32235241 #>>32236203 #>>32236379 #>>32236408 #>>32237069 #>>32237245 #>>32238451 #>>32239672 #>>32239680 #>>32239999 #>>32240046 #
aplanas ◴[] No.32235241[source]
Windows security models and policies are the enemy, not remote attestation (RA).

RA is a technology that has its fair use, and can be desired for other systems, like in Linux. With a pure RA system your services can decide to trust or not those devices on your network that can be compromised, and report to other devices that there is something suspicious.

As anything, this can be used properly to increase the security of your edge architecture, or wrongly to limit the users actions.

Let me put another example. With RA I should be able to authorize validated systems in my R&D VPN. If you are using your own laptop with the company certificate, and the verifier tag the systems as "unknown" or "unhealthy", it will not allow the access to the internal network, but sure you can still use your laptop for anything else. This, IMHO, is a fair use of this technology.

replies(2): >>32235470 #>>32235515 #
fulafel ◴[] No.32235515[source]
Yes, lots of Linux devices apply it like that today: You can't use your banking app or consume DRM crippled media on your Android phone if you have root or run a open source Android distribution.
replies(1): >>32235557 #
Aeolun ◴[] No.32235557[source]
> if you have root

Because god forbid you have control of your own PC?

replies(6): >>32235581 #>>32235770 #>>32235990 #>>32236047 #>>32236569 #>>32237462 #
1. npteljes ◴[] No.32235770[source]
Yep! Basically, it's safer if you don't own your PC. Think about users with a million toolbars and Bonzi Buddy installed.

Of course, the system for it is rudimentary, and puts a disproportionate amount of control in the hands of providers. And that works very well for them too.

replies(3): >>32235924 #>>32237198 #>>32238033 #
2. TheOtherHobbes ◴[] No.32236192[source]
In a sane society these features would allow secure voting.

In this one... that's not what they'll be used for.

This is the end game for the corporate internet. Not only can all your activity be logged, but if any of it is unwelcome - on any scale, from family to school to work to country to world - you can be locked out.

replies(1): >>32236240 #
3. 29athrowaway ◴[] No.32236240{3}[source]
An operating system that prevents other operating systems from being installed is the equivalent of a citizen that becomes a dictator.
4. throwaway1348b3 ◴[] No.32236410[source]
Oh, modern democracies solved this nasty problem of voters possibly making the wrong choice by simply providing only the right choices to chose from: you get two slightly different brands of shit whose policies mostly coincide, enjoy your right to vote.
5. npteljes ◴[] No.32236929[source]
I feel like it's flawed. Voters and politicians abuse it left and right - pun intended. I don't think we ever came up with anything more humane though, and I don't wish to change it for anything other - to be honest, for the simple reason of not wanting the responsibility that goes along with it.

Choosing a party is not like choosing an OS for your PC, though. Choosing the OS would be like choosing the political system - and recognizing the incredible privilege I have by being born into a democracy, I very much wouldn't like other people to change it.

Going further into democracy, while you might put an X on a paper sometimes, still forbids a very high number of actions. I'd liken it to having the power of choosing between Apple's App Store and Google's Play Store for your phone. Which, getting back to the point, is safer for the users than installing any third party software. Like how in a well functioning democracy, I'm forbidden to do a great many things, but also I can feel safe in the thought that others have the same restrictions too.

replies(1): >>32237106 #
6. feanaro ◴[] No.32237106{3}[source]
So, putting it all together, someone should choose and restrict which OS can be installed on your PC, so that you can feel safe in the thought that everyone has the same restriction?

At least that's how I managed to understand your comment to the best of my abilities, so hopefully I'm missing something. Though if there is such a something, the point did not get across successfully.

replies(1): >>32237389 #
7. adev_ ◴[] No.32237198[source]
> Yep! Basically, it's safer if you don't own your PC. Think about users with a million toolbars and Bonzi Buddy installed.

And it is a pretty terrible solution to the problem.

- It is also keeping the good guys outside too: Anyone that want to analyse and understand the security of the system for good reasons cannot. Excepted if explicitly allowed by the corporation X and that is a terrible security property.

- No root access also means very little control or ability to scan the system itself if your are not the X corporation controlling it. That means no possibility to mandate reviewer corporation Y to check that corporation X is doing the right thing. TPMs currently make that even worst by design, they are undocumented and complex, therefore rely on blind trust that company X do the rthe ight thing. And since the Intel management engine fiasco, we do know they are not doing the right thing.

- Bonzi Buddy and toolbar type of problem can be easily avoided by separating properly the normal user account from any admin account(the unix way). It should be painful to be admin but not impossible, just to make sure your grandma do not install a rootkit by mistake when she want her 20% coupon.

In summary: That is mainly bullshit from company X to keep full control on the entire user device, and not for their own good.

replies(1): >>32237867 #
8. npteljes ◴[] No.32237389{4}[source]
I think if I pick two groups: all iPhone users, and all PC users, PC users en bloc are in greater general digital danger than iPhone users. By digital danger, I'm thinking of malware, ransomware, phishing and successful hacking. And I think this is because of how tightly Apple controls their devices. And so, I'd consider an iPhone a safe choice - for example a safe recommendation for someone who doesn't want to spend time managing their device.

This makes sense to entities providing a service, and also for many who doesn't mind not having control over their something, which is, I think, very similar to how we don't really have control over a great many of things. This is the point I wanted to get across to the original commenter, who protested "god forbid you have control of your own PC?".

replies(2): >>32237773 #>>32237872 #
9. mavhc ◴[] No.32237773{5}[source]
God forbid most people I know have control of their own PC, they have no clue, and nor should they need one.

iPhone users are safer from malware, PC users are safer from governments and Apple controlling what they can do on their computer.

Never-ending balance between safety and freedom.

The computer that requires a physical switch to disable secure boot is a good compromise (see many Chromebooks)

10. npteljes ◴[] No.32237867[source]
I agree. In a proposal like this, security is basically a byproduct, and sometimes not even that[0]. This is also a domain where the governmental and corporate powers have a similar goal, which is wresting away the control from the public / individual. They basically work in synergy, only to a point of course, but still.

Regarding Bonzi Buddy, I disagree. I think user data is as important, if not more important, than root access - which is why I'm dumbfounded when ancient server security features, like Linux's sudo system, are applied to the consumer device like a PC or a smartphone. These contexts are much better server by a sandboxing, permission-based whatever that seems to pick up steam, like the current permission systems on smartphones. Grandma's logins and bank data will be stolen from her own user account just the same as an admin account. Related XKCD[1]

[0] https://en.wikipedia.org/wiki/Security_theater

[0] https://xkcd.com/1200/

replies(1): >>32239554 #
11. feanaro ◴[] No.32237872{5}[source]
> [...] which is, I think, very similar to how we don't really have control over a great many of things.

This is a very handwavey sentence and is doing far too much work in your reasoning. Yes, you don't have control "over a great many things", because the point is so vague so as to be meaningless. But it doesn't at all follow from that vague sentence that we should allow total corporate/government control over our personal digital devices.

In this case, the proposed cure is far worse than the disease.

replies(1): >>32238266 #
12. userbinator ◴[] No.32238033[source]
Think about users with a million toolbars and Bonzi Buddy installed.

I say let them be. As long as they also have the freedom to remove or not install such software, it's a good thing. Instead we have locked-down devices with the functional equivalent of such unwanted software, protected so that you cannot remove it without somehow getting root.

"Those who give up freedom for security deserve neither."

replies(1): >>32238267 #
13. npteljes ◴[] No.32238266{6}[source]
I agree. It's basically appointing a dictator and hope that they'll stay benevolent.

With my reasoning I wanted to capture what people might think, while accepting something that they have no control of. I have a hard time with this, because I got a PC in my formative years and I loved to tinker with it, and hated, and still do, everything that stood in the way of that. But the general population doesn't share this experience. And if I look at my own life, I only have this experience with computers (and smartphones), all the other things are, even if not centrally managed, out of my control. At the first wrong noise I have to call an expert who hopefully fixes it and is hopefully benevolent to me, because I have no clue what happens to the device I own. Or even my own body, now that I think about it. And so, the PC and the phone is just in a long list of things that people depend on, but not control.

The addendum being here, and what most people miss who feel the way I described above, is that our ever-connected devices make a "paper trail" unprecendented in history. And it can be centrally managed, activated, replayed, assembled, or even more tracking could be remotely controlled to an extent[0] - and to an even larger extent with a specialized application[1]. This is where the otherwise similar level of "not being controlled" can lead to a much worse situation than ever before. And I wish I could point this out empathetically to people without sounding like a lunatic.

[0] https://money.cnn.com/2014/06/06/technology/security/nsa-tur...

[1] https://en.wikipedia.org/wiki/Pegasus_(spyware)

14. lotsofpulp ◴[] No.32238267[source]
My parents grew up in a non English speaking developing country, and they cannot be reasonably expected to learn the nuances of malware laden links to figure out which English text link is good or bad.

Do they deserve to not be able to shop online without fear of having their payment information stolen? Or mistyping a URL in their non native language and ending up at a scam website that installs malware? Or simply having a device that comes to a crawl such that they cannot reliably video call their grandkids?

replies(2): >>32238391 #>>32239292 #
15. npteljes ◴[] No.32238391{3}[source]
I don't mind the lock, but why don't we have the key? There's no reason to centally hold these hostage.
16. agileAlligator ◴[] No.32239292{3}[source]
The problem you are describing will be irrelevant in a generation or two, as kids grow up on the internet.
replies(1): >>32239646 #
17. iggldiggl ◴[] No.32239554{3}[source]
> like the current permission systems on smartphones

Ugh, except that one goes overboard in the completely opposite direction, and often doesn't let me properly share data between apps even when I want to.

18. corrral ◴[] No.32239646{4}[source]
I can assure you that the upcoming generations aren't much better at any of this, on average.

And no, it's not smartphones' faults. Most people just don't "get" desktop OS paradigms, or how web pages work, or any of that, and they don't really care to.

replies(2): >>32246795 #>>32251662 #
19. userbinator ◴[] No.32246795{5}[source]
Most people just don't "get" desktop OS paradigms, or how web pages work, or any of that, and they don't really care to.

That's because they "won't miss freedom they never had".

20. agileAlligator ◴[] No.32251662{5}[source]
Nah dude. Most young people nowadays have an inbuilt sense of which links are sus; it's not exactly rocket science. If it looks sus, it is.