Microsoft brings Trusted Platform Module functionality directly to CPUs under securo-silicon architecture Pluton
- Reference: 1605640505
- News link: https://www.theregister.co.uk/2020/11/17/microsoft_pluton_cpu_hardware_security/
- Source link:
"Our vision for the future of Windows PCs is security at the very core, built into the CPU, for a more integrated approach where the hardware and software are tightly integrated, ultimately removing entire vectors of attack," said Microsfot [1]in a blog post this afternoon.
The "chip to cloud security technology", as Microsoft calls it, will be integrated into future CPU designs and is intended to defend against physical security attacks as well as preventing "the theft of credential and encryption keys", Microsoft added.
Conceptually, the Pluton architecture is an extension of hardware security work that Microsoft started in 2013 with onboard anti-piracy protections for the Xbox One console ( [2]with roots in the early 2000s ), though in case that sounds dangerously consumerish the firm is also keen to say the same approach was ported across to Arm-based system-on-chip IoT thingy [3]Azure Sphere too.
Future CPU designs from AMD, Intel, and Qualcomm will incorporate Pluton technology, with all three chipmakers queuing up to dutifully say what a great idea this is: "We believe an on-die, hardware-based Root-of-Trust like the Microsoft Pluton is an important component in securing multiple use cases and the devices enabling them," stated Asaf Shen, Qualcomm's senior director of product management in a prepared remark.
Trusted Platform Modules (TPMs) form the current root of Windows PC defences and are separate from existing CPU designs. Microsoft hopes to remove that distinction by adding the root-of-trust component directly into the silicon.
"Windows PCs using the Pluton architecture will first emulate a TPM that works with the existing TPM specifications and APIs which will allow customers to immediately benefit from enhanced security for Windows features that rely on TPMs like BitLocker and System Guard," said Microsoft. In theory, this means anything using a TPM today should be able to run on a Pluton-fitted CPU in the future.
It appears that Redmond's intent with Pluton is to better tackle more advanced PC and enterprise-level attack vectors that have emerged in recent years, something no longer confined solely to malicious people with physical access to your hardware. In its post Microsoft claimed: "Windows devices with Pluton will use the Pluton security processor to protect credentials, user identities, encryption keys, and personal data. None of this information can be removed from Pluton even if an attacker has installed malware or has complete physical possession of the PC."
Such boasts tend to spur on research from white and black hats alike determined to disprove them, though it's very early days.
Last year academics discovered that Windows TPMs, previously an important part of Windows' out-of-the-box defences, [4]leaked timing information that allowed attackers to remotely recover cryptographic private keys . Similarly, other research (MS cited a [5]blog post from infosec outfit Pulse Security) has shown how the bus between the CPU and the TPM can be successfully sniffed – albeit in the context of a hardware hack.
Pluton also appears intended to complement Microsoft's existing secured-core PC firmware-level security initiative which it [6]announced last year , and which are said to "combine identity, virtualization, operating system, hardware and firmware protection" in a concerted effort to shut out attackers. ®
Get our [7]Tech Resources
[1] https://www.microsoft.com/security/blog/2020/11/17/meet-the-microsoft-pluton-processor-the-security-chip-designed-for-the-future-of-windows-pcs/
[2] https://www.theregister.com/2005/08/30/infineon_xbox_360_chips/
[3] https://www.theregister.com/2020/02/24/azure_sphere_is_now_generally_available/
[4] https://www.theregister.com/2019/11/12/don/
[5] https://pulsesecurity.co.nz/articles/TPM-sniffing
[6] https://www.theregister.com/2019/10/22/microsoft_securecore_pcs/
[7] https://whitepapers.theregister.com/
Re: My next laptop ?
Installing Linux or a BSD is considered an attack (on Microsoft revenue).
Fine. As long as it's OPTIONAL.
Fine?
As long a Windows Update provides regular fixes of your Trusted Platform Module.
Warning! Warning!
Alien hardware approaching Will Robinson.
So, we have a hardware element that can't be bypassed, and of course is completely bug free, and lets you run any OS you like. Now and in the future.
Anyone want to buy this bridge?
P.S.
The only hardware security I want is a mechanical switch.
Correct me if I'm wrong, but didn't AMD already do this? The TPM functionality is implemented by the PSP, which makes largely the same claims as Pluton here.
Or was AMD lying somewhere about PSP capabilities?
Oh, and the PSP has already been hacked. Along with the IME. Seems the super secure secret environments running God-knows-what signed proprietary firmware weren't so secure after all! How is Pluton (supposedly) different?
Because as we all know ...
... the very first thing a Security Professional reaches for in an emergency is something endorsed by Microsoft.
Honestly, the mind boggles .. They can't write secure code, so they expect all of us to trust some hardware dingus that they endorse? Fuck that. I have better things to secure my systems with. And yes, that's a sight unseen statement. I have history on my side. Microsoft has NEVER been able to get security right. Only a fool would trust them at this point.
First example speaks volumes...
Anti-piracy on the new XBox. DRM so deep, everything is locked to the processor. Dell is already getting heat for fusable links in AMD processors that on first boot lock the CPU to the motherboard and firmware. Kills grey market right there for those processors. Microsoft and much of the gaming industry has always been intent on killing resales of anything.
Ho Hum ...... here we go again !!!
Anything that can be built ..... can be unbuilt [Broken] !!!
I expect that Pluton will be hacked by 2023 (at the latest) and more promises of 'Real Security' will be made by 2024.
I would much rather have software that worked and was not 'patched' in a never ending process.
i.e. Windows 10 and most[all ???!!!] software that runs on it !!!
I am sure all that money could be better spent on improving the software we all use.
If their idea of "securing the processor"...
...is as shown in your lede photo - LGA package on a PGA socket - then we have nothing to worry about; it won't work and will fall apart instantly.
Yes, I know that's just a generic shutterstock/alamy type image. Makes me laugh though. Did someone give the (non technical) photographer a pile of PC parts and say "take some photos we can license"?
My next laptop ?
Does that mean that I will be unable to install Linux on my next laptop ?
Maybe they will say: "not a problem, install it under a Microsoft hypervisor" - in which case all trust is lost anyway.