zlacker

[return to "The Dangers of Microsoft Pluton"]
1. Gh0stR+eg[view] [source] 2022-07-26 06:26:56
>>gjsman+(OP)
I'm completely missing how his example of a Word document that can only be opened by approved users on approved hardware within the corporation is supposed to be a bad thing.

Honestly, that sounds pretty fantastic. I've been using 3rd party tools/extensions to do this sort of thing in corporate and government environments for years, but having the attestation go all the way down to the hardware level is a big value-add, especially with so much ransomware/spyware/extortion/espionage going on these days.

Can someone please explain to me how the author might see this level of security as a bad thing?

◧◩
2. ftyhbh+Ih[view] [source] 2022-07-26 06:39:43
>>Gh0stR+eg
What you can install on YOUR pc will be at the sole mercy of microsoft/or maybe someone else.... That's the cusp of it. Not that it can be used for good, but that it sets the way for heavy misuse by large corporations.

Wait a few years. Smaller companies won't even be allowed to order high end cpu's. You'll be at 100% mercy of these corporations.

If after 2 years they decide to brick your pc, they'll just do it. You think government will help you out here? Lol...

◧◩◪
3. eertve+qj[view] [source] 2022-07-26 06:59:09
>>ftyhbh+Ih
still waiting on the secure boot lockdown everyone has insisted is coming for the better part of two decades...
◧◩◪◨
4. alex77+ji1[view] [source] 2022-07-26 14:44:35
>>eertve+qj
The goal is not to prevent you from running Linux, is to make it so that Linux cannot access the content you are interested in.

Remote Attestation establishes a root of trust that can be used to verify that all of the software down the line is "approved":

- You won't be able to browse sites or use apps with ads unless you run a 'trusted' device, OS and browser that does not block ads.

- You won't be able to browse sites with captchas unless you run a 'trusted' device, OS and browser that does not allow bots to interact with the browser.

- You won't be able to run Netflix unless you run a 'trusted' device, OS and browser so that you can't record the content.

- You won't be able to play online games unless, again, you run a 'trusted' device and OS so that you cannot cheat, or more importantly modify it in any way (why would you purchase skins if you can mod them in?).

- You won't be able to use online banking unless you use a trusted OS because banks.

Remote Attestation is pretty terrifying and it will be here soon unless it is regulated out of existence, which is unlikely.

◧◩◪◨⬒
5. tester+G82[view] [source] 2022-07-26 18:45:50
>>alex77+ji1
>- You won't be able to browse sites

How would that work?

HTTP is just HTTP

◧◩◪◨⬒⬓
6. bilkow+Wf2[view] [source] 2022-07-26 19:19:26
>>tester+G82
Sites could require remote attestation via a new API just like some sites (Netflix, etc) require DRM to play content.
[go to top]