TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

“Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm

201 pointsby vanburenover 4 years ago

15 comments

darzuover 4 years ago
I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this.<p>Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: <a href="https:&#x2F;&#x2F;azure.microsoft.com&#x2F;en-us&#x2F;blog&#x2F;anatomy-of-a-secured-mcu&#x2F;" rel="nofollow">https:&#x2F;&#x2F;azure.microsoft.com&#x2F;en-us&#x2F;blog&#x2F;anatomy-of-a-secured-...</a><p>Disclaimer: I still work at MSFT but in a different org.
评论 #25192454 未加载
评论 #25192530 未加载
评论 #25192780 未加载
评论 #25193553 未加载
评论 #25192892 未加载
评论 #25197174 未加载
评论 #25192631 未加载
评论 #25193271 未加载
评论 #25194392 未加载
评论 #25195668 未加载
azalemethover 4 years ago
A previous HN link is here -- <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25131431" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25131431</a> -- which links to MS&#x27;s original press release -- <a href="https:&#x2F;&#x2F;www.microsoft.com&#x2F;security&#x2F;blog&#x2F;2020&#x2F;11&#x2F;17&#x2F;meet-the-microsoft-pluton-processor-the-security-chip-designed-for-the-future-of-windows-pcs&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.microsoft.com&#x2F;security&#x2F;blog&#x2F;2020&#x2F;11&#x2F;17&#x2F;meet-the-...</a>.<p>That article explicitly states that it was designed originally for the xbox. I worry that going to be a very anti-consumer, anti-free-speech, DRM heavy chip that MS want to popularise as an alternative to the (still hated in some circles) TPM. Why else would they design it for the xbox, of all things? Is it aimed to stop speculative execution attacks on a cloud server, or provide Level 4 DRM to Widevine&#x27;s as-yet-unannounced competitor?
评论 #25193346 未加载
评论 #25193186 未加载
评论 #25193078 未加载
评论 #25194888 未加载
评论 #25192544 未加载
评论 #25192066 未加载
评论 #25192935 未加载
评论 #25192648 未加载
fefe23over 4 years ago
The marketing for this chip is vague and confusing because the chip does absolutely nothing for you.<p>This chip is not here to protect you from compromised or malicious IoT devices, or to protect you from compromised or malicious cloud services.<p>This chip is here to protect the Microsoft cloud from compromised or malicious IoT devices. They would also like you to believe that the chip improves security in the cloud. In actuality it protects software running on your device from ... you. All this attestation stuff is great for DRM!<p>That poses a problem for marketing. They have to let it sound like it does something for you when it actually doesn&#x27;t.<p>It&#x27;s no surprise then that the marketing is basically a giant weasel word souffle with some buzzwords sprinkled on top, and a bit of name dropping.
评论 #25202500 未加载
tumblewitover 4 years ago
After reading through @darzu&#x27;s pluton explanation on the site linked, I realised this actually may give you the impression that it&#x27;s a security measure, but in reality now Azure can verify each chip (not just the computer anymore) and see if it runs authentic software (ding ding ding - Windows Licensing). The two key pair method mentions that each devices can be verified to be running authentic software by azure (the phone home thing everyone is worried about). While most laptops and computers do not ship with keys anymore and instead the hardware generates some kind of signature that is then verified by windows activation, this feels like an easier method of doing that. I wonder if this also means Microsoft is aggressively going to make more and new hardware (or some Microsoft verified hardware kind of thing to setup standards) to directly compete with Apple Silicon and keep profits healthy by forcing more customers to pay for authentic software.
hansdieter1337over 4 years ago
I stopped reading and started puking when I read “chip-to-cloud security”
skohanover 4 years ago
Is Pluton specifically Windows related? Will this affect how easy it is to run Linux on hardware using Pluton?
评论 #25191986 未加载
评论 #25191982 未加载
评论 #25191965 未加载
评论 #25192828 未加载
评论 #25193441 未加载
评论 #25192413 未加载
评论 #25191948 未加载
gruezover 4 years ago
Isn&#x27;t this basically fTPM (basically software TPM implemented in the trusted execution environment of the CPU) that both AMD and Intel already offer?
评论 #25192369 未加载
评论 #25196847 未加载
imbuhuoover 4 years ago
Locking out other OSes isn&#x27;t a main goal of Pluton (although technically it can), there are just too many issues (hey Infineon, Intel and Qualcomm I am looking at you) with existing dTPM and fTPM implementations.
shmerlover 4 years ago
<i>&gt; What the Pluton project from Microsoft and the agreement between AMD, Intel, and Qualcomm will do is build a TPM-equivalent directly into the silicon of every Windows-based PC of the future.</i><p>CPUs with security modules controlled by MS? Who will guarantee it won&#x27;t be abused against non MS systems and users?
评论 #25192434 未加载
dragoneliteover 4 years ago
Wouldn&#x27;t be surprised if this will be used to block programs coming from non western nations. Pompeo talked about creating a &quot;Clean network&quot; to keep foreign non allied nations hardware and software out of it.
TwoBitover 4 years ago
It&#x27;s hard for me to get interested in any hardware or software security news with ransomware amok and none of this addressing it.
musicaleover 4 years ago
Somehow I thought a Pluton should be a fundamental wealth particle, but apparently it&#x27;s a thing from geology.
评论 #25198018 未加载
intricatedetailover 4 years ago
Call me sceptical, but I hope m$ is not pulling Apple tricks to lock computers to their OS. Is this open source? Will consumer be able to audit it down to the silicon level?
评论 #25192598 未加载
评论 #25192617 未加载
29athrowawayover 4 years ago
An unnecessary solution for an inexisting problem.<p>I hope they lose their investment.<p>I also hope all their hordes of fanboys wake up to reality now. Yes, the people that &quot;&lt;3 open source&quot; and &quot;&lt;3 Linux&quot; and gave you VS Code for free, will now own your CPU now and you have nothing to do about it. And then, if they change their mind and don&#x27;t want you to run Linux, you won&#x27;t run Linux.
xvilkaover 4 years ago
I wonder if it will be one of the inferior technologies that were forced by Microsoft even outside of their Windows world. Like it happened with UEFI (that has no multithreading, uses PE as a format, Microsoft C ugly coding convention, bloated), SecureBoot (that was designed to stop anything non-Windows instead of real security), UTF-16 (everyone except them and JavaScript uses UTF-8), and so on. The list is long.
评论 #25194829 未加载
评论 #25194259 未加载
评论 #25195069 未加载
评论 #25194503 未加载
评论 #25197101 未加载