←back to thread

The Dangers of Microsoft Pluton

(gabrielsieben.tech)
733 points gjsman-1000 | 1 comments | | HN request time: 0.215s | source
Show context
metadat ◴[] No.32234045[source]
Ew. Why are all the chip manufacturers going along with this stupid plan? I want to buy a processor and then own it and have it work in my best interests, not consume electricity and generatie heat enforcing draconian 3rd party DRM policies.
replies(12): >>32234130 #>>32234281 #>>32234326 #>>32234400 #>>32234486 #>>32234981 #>>32235753 #>>32235848 #>>32236170 #>>32236808 #>>32237073 #>>32240665 #
Analemma_ ◴[] No.32234486[source]
The conspiratorial answers here are emotionally satisfying, but ultimately wrong. The reason chip makers and OS vendors are adding this is customer demand, by which I mean enterprises. Companies want remote attestation and guaranteed-immutable OS images on their networks, and I honestly can't say I blame them. In a perfect world they could have it and we could somehow firewall it away from the consumer space entirely, but that's not going to happen.
replies(5): >>32234561 #>>32234804 #>>32234879 #>>32237705 #>>32261846 #
walterbell ◴[] No.32234561[source]
On-premise, open-source, customer-owned remote attestation servers are possible. Avoid outsourcing integrity verification to 3rd-party clouds.
replies(3): >>32234573 #>>32234629 #>>32235239 #
wmf ◴[] No.32234629[source]
The same enterprises asking for this stuff are also asking for it to be taken out of their hands because they don't trust themselves to operate it securely or reliably.
replies(1): >>32234737 #
pmontra ◴[] No.32234737[source]
So this turns into security theater because ultimately they can't trust those third parties too.
replies(4): >>32234813 #>>32234878 #>>32237183 #>>32241268 #
1. notriddle ◴[] No.32241268[source]
You're thinking about companies as monoliths. They are groups of people.

The managers who want remote attestation aren't the people implementing it. They either pay someone else to do it, or they pay someone else to do it. The difference between paying a third-party company and an employee is that employees are more expensive, because the costs aren't amortized over other customers who want the same stuff. Why would they be more trustworthy? Why would they be better at it? Why would it be any less likely to be hacked if you did it at your company than if you outsourced it?