News: 1641384669

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Windows giant seeks Pluton-ic relationship with chip maker: AMD first out of the gates with Microsoft's security processor

(2022/01/05)


It's been a while coming, but it looks like PCs with Microsoft's Pluton security processor are [1]just around the corner . So long as your silicon of choice comes from AMD, for the time being at least.

Pluton was [2]first announced in 2020 and is rooted in anti-piracy protection developed for Microsoft's Xbox console some years previously as well as work done for Azure Sphere. The shipping incarnation can be configured three ways, according to Microsoft. As the Trusted Platform Module (TPM), as a security processor for non-TPM scenarios (Microsoft cites platform resiliency) or just turned off by an OEM.

Going beyond TPM, Microsoft suggested scenarios for the tech to provide greater visibility into the state of the platform with signals being reported back to Intune and Azure Attestation Service in the future.

[3]

TPM has been a thing for a while (and is infamously one of Windows 11's list of a hardware requirements). It'll perform tasks such as verifying the integrity of the OS but is separate from the CPU design. Popping the root-of-trust directly on the same silicon as the processor means that attack vectors such as sniffing the bus between CPU and TPM are mitigated. The promise of attestation service support in the future will also appeal to administrators tasked with doling out access.

[4]

Microsoft has also stated that the Pluton hardware will be updateable through Windows Update and it "provides a platform for innovation that allows customers to benefit from new features in future releases of Windows that leverage the Pluton hardware." Assuming, of course, you have a shiny new CPU replete with the tech. Microsoft has, after all, a bit of a reputation these days for [5]abruptly yanking support for older CPUs in the name of security and reliability.

[6]Microsoft rang in the new year with a cutesy tweet in C#. Just one problem: The code sucked

[7]Microsoft patches Y2K-like bug that borked on-prem Exchange Server

[8]US Government Accountability Office explains why it sustained Microsoft's protests over $10bn NSA contract

[9]When product names go bad: Microsoft's Raymond Chen on the cringe behind WinCE

Intel, Qualcomm, and AMD were signed up in 2020, but it is AMD that is first out of the gate with the tech in its [10]Ryzen 6000 series processors , announced at CES yesterday. Similarly, Lenovo unveiled its AMD-powered ThinkPad Z13 and Z16 laptops with the tech (due to ship in May).

AMD will have to share the thunder before long. [11]In December Qualcomm said it would include Pluton via an implementation in the Qualcomm Secure Processing Unit (SPU) for managed systems in the enterprise or education segments. Part of the Snapdragon 8cx Gen 3 SoC, the first laptops using the chip should turn up during 2022. ®

Get our [12]Tech Resources



[1] https://blogs.windows.com/windowsexperience/2022/01/04/ces-2022-chip-to-cloud-security-pluton-powered-windows-11-pcs-are-coming/

[2] https://www.theregister.com/2020/11/17/microsoft_pluton_cpu_hardware_security/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YdXOvVxvn83PE6p@etIU7wAAABE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YdXOvVxvn83PE6p@etIU7wAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2021/06/25/windows_11_processor/

[6] https://www.theregister.com/2022/01/04/microsoft_date_comparison_tweet/

[7] https://www.theregister.com/2022/01/03/exchange_servery2k22_flaw/

[8] https://www.theregister.com/2021/12/15/gao_nsa_microsoft/

[9] https://www.theregister.com/2021/12/15/chen_wince/

[10] https://www.theregister.com/2022/01/04/amd_ryzen_ces/

[11] https://www.qualcomm.com/news/releases/2021/12/01/qualcomm-expands-portfolio-snapdragon-8cx-gen-3-and-7c-gen-3-accelerate

[12] https://whitepapers.theregister.com/



Arthur the cat

In geology a pluton is an intrusive block that disrupts existing things, sometimes catastrophically. This seems similar.

Excuse my ignorance, but ...

Adair

is this relevant to anyone not running Windows on their machines, or does this mean we need to ensure we have user/admin control over the TPM module before purchasing the machine/motherboard?

Re: Excuse my ignorance, but ...

Doctor Syntax

Come to that, what's the advantage to anyone who is running Windows? Is it yet another weapon for Microsoft in their conflict of interest with their users?

Re: Excuse my ignorance, but ...

ThatOne

> what's the advantage to anyone who is running Windows?

Making sure you only run genuine, verified Microsoft-certified software - and nothing else . It's chilling.

I admit this can be an IT department's wish, but what does it spell for those who own their own computers, and, heaven forbid, want to use a non-Microsoft OS?

Re: Excuse my ignorance, but ...

s2bu

Or probably more DRM just to try and watch a damn movie!

Re: Excuse my ignorance, but ...

nematoad

"Making sure you only run genuine, verified Microsoft-certified software..."

My sister just bought herself an el-cheapo Asus laptop. When I got dragged in to set it up, I had to fight with something called Windows 'S' mode. Now not having used any MS stuff for over twenty years this was a bit of a shock. What was more of a shock was the error message spread across the screen complaining about an "un-verified" program and did I want to install it? Personally I wanted to un-install the whole bloody mess and put a decent OS on the damned thing but it wasn't my laptop so I was stuck and it took me a long time to get rid of 'S' mode so that I could get on and setup the laptop as requested. Time wasted and temper definitely frayed but I got there in the end.

Oh!

The 'unverfied' program I was warned about?

Something called"powershell.exe" No idea where that came from and I didn't install it as I had been warned off.

Thanks MS.

msknight

"Going beyond TPM, Microsoft suggested scenarios for the tech to provide greater visibility into the state of the platform with signals being reported back to Intune and Azure Attestation Service in the future." ... that needs clarification as to what it means for non-Windows users, or I won't be using it.

b0llchit

It is the prelude to not-your-computer computing. It is meant to prepare you to accept the overlords and pay them what they say they are owed (your money, thoughts, works and soul).

fidodogbreath

Indeed. From [1]Ars Technica :

"Microsoft already used Pluton to secure Xbox Ones and Azure Sphere microcontrollers against attacks that involve people with physical access opening device cases and performing hardware hacks that bypass security protections. Such hacks are usually carried out by device owners who want to run unauthorized games or programs for cheating."

[1] https://arstechnica.com/information-technology/2022/01/pluton-microsofts-new-security-chip-will-finally-be-put-to-the-test/

ThatOne

> or I won't be using it

Well, you eventually will, when the old CPUs not having this feature start getting difficult to source. Don't forget it's not some isolated opt-in feature, it's the future of computing: Welcome to The Walled Garden...

UCAP

Microsoft has also stated that the Pluton hardware will be updateable through Windows Update

So basically it is programmable. Another security hole opens up, thanks to Microsoft.

irony meter exploded

captain veg

So Microsoft realised a few years ago that it was congenitally unable to write secure code and turned to a brute hardware fix instead.

Now it wants the hardware to be programmable.

This looks like history repeating as farce. Reminds me of when, having failed to interest the world in stuffing desktop Windows on to phones they then tried to make everyone use a phone OS on their desktops.

-A.

Snake

Your BIOS is updatable, that is programmable, therefore you've ALWAYS had this form of vulnerability. If a BIOS can be protected enough that you do not seem worried about it during your course of normal computing operations then Pluton will be the same.

Not that I'd want to have it based upon their current description, mind you. But worrying about its security whilst accepting BIOS updates seems unfounded.

Charles 9

Different degree of pwnage. BIOS images often can't be updated through Windows and require booting to a single-user OS, plus obscurity means (1) there are a lot of different BIOS types to figure out, and (2) it's hard to figure out which one is appropriate for any given intrusion.

This Pluton looks to make it a SPOF.

nijam

> ... therefore you've ALWAYS had this form of vulnerability ...

And now you're going to have a second version of it.

Progammable is what you want

JoeCool

Otherwise an individual doesn't really own their HW anymore.

Isn't the alternative to give up control to "the central authority" ?

Not saying Pluton is solving a real problem or not, since there isn't enough technical info to evaluate it. But the minute they attach the tag "Consumer tech" or "Retail tech" there will be a religous war.

AnotherName

"Microsoft has also stated that the Pluton hardware will be updateable through Windows Update"

What could possibly go wrong! WU is not known to have broken anything ever...

Pluton

Anonymous Coward

The God of Money (& Hell).

So another play for.....

stewwy

World domination from Microsoft.

It's no longer "All your bases belong us"

More "Everything belong us''

If true...

Snake

Shouldn't we consider Intel's Management Engine on the same level? It's even running under Linux.

Re: If true...

Anonymous Coward

Yes

Re: If true...

A random security guy

Yeah, Intel is using minix. However, Intel is not used universally. MS is used in the cloud and on most desktops. It is several trillion dollars big.

But the question remains: what happens with Linux.

Re: If true...

ThatOne

> But the question remains: what happens with Linux.

I guess you'll be free to use the Windows Subsystem for Linux, as long as you have a genuine, verified Windows installation and don't mind the ads and the spying.

Re: If true...

wub

From what the article says, it appears to depend on whether the "OEM" whoever that might be for us white-boxers gets to decide whether to turn this thing on. If they come from AMD, Intel etc with TPM activated, WSL could end up our only choice for Linux...

...until the whole system gets hacked by some very clever sod.

Re: If true...

UCAP

Hacked in 3 ... 2 ... 1 ...

Television has proved that people will look at anything rather than each
other.
-- Ann Landers