Dell opts out of Microsoft's Pluton security for Windows
- Reference: 1646850609
- News link: https://www.theregister.co.uk/2022/03/09/dell_pluton_microsoft/
- Source link:
Dell won't include Microsoft's Pluton technology in most of its commercial PCs, telling The Register : "Pluton does not align with Dell's approach to hardware security and our most secure commercial PC requirements."
Microsoft launched to much fanfare its Pluton security layer for PCs in 2020 after developing it with Intel, AMD, and Qualcomm. Pluton effectively bakes a co-processor in silicon that securely stores encryption keys, credentials, and other sensitive information. The idea being that this data is kept close to the CPU cores, within the same processor package, thwarting attempts extract the secret info by, say, snooping an external bus.
[1]
It also allows Microsoft to define a base level of security features in the chips that Windows runs on. For instance, Pluton provides a Trusted Platform Module (TPM), a technology required by Windows 11.
[2]
[3]
The co-processor's origins trace back to the Xbox One gaming console in 2013, and later made it to Microsoft's Azure Sphere microcontroller for edge applications. But outside of homegrown hardware, Microsoft's still playing the waiting game.
Intel, for one, [4]has not implemented Pluton in any 12th-Gen Intel Core processors, code-named Alder Lake. These chips come with their own Intel-designed TPM support.
[5]
Dell laptops that are coming soon with 12th-Gen Intel Core processors will therefore not use Pluton for their TPMs. Their modules, we're told, are certified by the Trusted Computing Group, and satisfy the US federal [6]standard FIPS 140-2 set by NIST.
"As with all new technologies, we will continue to evaluate Pluton to see how it compares against existing TPM implementations in the future," Dell's spokeswoman said. Dell has its own additional security implemented at the hardware and software level to defend against attacks, she added.
Reading between the lines: Dell isn't shipping PCs with processors featuring Pluton, and so it's not in a position, or interested in being in a position, to be onboard with the tech.
Over to Lenovo
Lenovo told The Register its Intel-powered ThinkPads "will not support Microsoft Pluton at launch."
But ThinkPads introduced in January with AMD Ryzen 6000 processors will include Pluton as it's present in those AMD chips, though the feature will be disabled by default. AMD has provided an option for users to turn the feature on and off. Lenovo's ThinkPad X13s, which has Qualcomm's Arm-compatible Snapdragon 8cx Gen3 chip, includes Pluton.
[7]
HP declined to answer questions on its stand on Pluton, saying it doesn't comment on future or unannounced products.
Microsoft told The Register Pluton is a community effort with top silicon designers to develop a secure platform that can keep up with modern threats.
A spokesperson warned that lead times in semiconductors are long, giving as an example the drawn-out process to implement things like USB 4 in laptops. Typically hardware technologies take years to define before the chips are actually made and soldered to shipping computers. In other words, though Pluton was announced about a couple of years ago, don't expect it in silicon everywhere already.
"Microsoft and our partners are giving customers the flexibility and choice to configure Pluton to meet their specific needs. Microsoft is committed to working with partners and customers in the coming months and years to continue to bolster security with Pluton," the spokesperson said.
[8]For those worried about Microsoft's Pluton TPM chip: Lenovo won't even switch it on by default in latest ThinkPads
[9]Windows giant seeks Pluton-ic relationship with chipmaker: AMD first out of the gates with Microsoft's security processor
[10]Microsoft brings Trusted Platform Module functionality directly to CPUs under securo-silicon architecture Pluton
[11]AMD reminds everyone it's still doing Threadrippers
Specifically, Pluton can act as a TPM 2.0, and can also be used as an embedded security processor used for non-TPM scenarios to provide additional protections to a device.
"With Pluton, our partners have the choice and flexibility in offering Pluton with or without a third-party TPM," Microsoft's spokesperson said.
The big concern among users is the presence of a Microsoft chip in a PC, and the [12]concept of "chip-to-cloud security," which could help the software maker exert more control of systems across the entire stack. Pluton security features can be keep updated through Windows Update. ®
Get our [13]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YikxmkZzkcORwedU0iNsdQAAAEk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YikxmkZzkcORwedU0iNsdQAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YikxmkZzkcORwedU0iNsdQAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2022/03/02/microsoft_pluton_chip/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YikxmkZzkcORwedU0iNsdQAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://csrc.nist.gov/publications/detail/fips/140/2/final
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YikxmkZzkcORwedU0iNsdQAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/01/20/microsoft_amd_pluton_lenovo/
[9] https://www.theregister.com/2022/01/05/microsoft_pluton/
[10] https://www.theregister.com/2020/11/17/microsoft_pluton_cpu_hardware_security/
[11] https://www.theregister.com/2022/03/08/amds_ryzen_threadripper/
[12] https://www.microsoft.com/security/blog/2020/11/17/meet-the-microsoft-pluton-processor-the-security-chip-designed-for-the-future-of-windows-pcs/
[13] https://whitepapers.theregister.com/
So basically this is all about DRM?
No, DRM in the usual sense is only part of it. It's also about restricting what software you can run on your own computer, making that software more opaque and more difficult to replace, and limiting your ability to use third-party data services. The end goal is the same one Microsoft have always had: total end-to-end control of and visibility into everything everyone does on any computer anywhere, with the ability to monetise all of it for themselves.
Ahem... isn't
"...total end-to-end control of and visibility into everything everyone does on any computer anywhere, with the ability to monetise all of it for themselves..."
what Apple has been doing right from the start?
Absolutely despicable practice, but Microsoft didn't invent the stuff.
Borkzilla is all about DRM
Its a silicon feature not a vendor addon
How would dell opt in to using pluton security? Start fabbing their own custom intel chips with a pluton proceesor added?
@Robin Bradshaw - Re: Its a silicon feature not a vendor addon
If I'm not mistaking, Dell still has control of the firmware so it can activate this "feature" or not. Or make it opt-in for end-users.
Let's not forget, for a long time Dell was the only big PC manufacturer who was not afraid to offer Linux preinstalled on their PCs.
Re: @Robin Bradshaw - Its a silicon feature not a vendor addon
@AC "f I'm not mistaking, Dell still has control of the firmware so it can activate this "feature" or not. Or make it opt-in for end-users."
From article:-
"Reading between the lines: Dell isn't shipping PCs with processors featuring Pluton, and so it's not in a position, or interested in being in a position, to be onboard with the tech."
Dell can't activate what is not their as Pluton is not on the processors.
"The big concern among users is the presence of a Microsoft chip in a PC, and the concept of "chip-to-cloud security," which could help the software maker exert more control of systems across the entire stack."
Exactly. The purpose of Pluton, like the purpose of TPMs, is not primarily to increase the security of the computer owner's data. It's to transfer control of the computer and the data it processes away from the owner to third parties of the manufacturer's choosing. That might be themselves or their corporate partners or the media industry. Unsurprisingly, the people who buy computers prefer to have control of their own assets.
Thank god, someone's got some sense
"AMD Ryzen 6000 processors will include Pluton as it's present in those AMD chips, though the feature will be disabled by default . AMD has provided an option for users to turn the feature on and off."
Just as it should be. I just hope it doesn't add too much to the cost of AMD chips.
I also hope that the evil empire doesn't find a way to subvert it so that it is always on, if the PC has Windows installed, so that it prevents you from wiping the disk and installing a useful OS.
Re: Thank god, someone's got some sense
"AMD Ryzen 6000 processors will include Pluton as it's present in those AMD chips, though the feature will be disabled by default. AMD has provided an option for users to turn the feature on and off."
There are plenty of nefarious ways of turning on a capability that exists but is 'disabled by default'. It doesn't take much to add hardware that sniffs a register or a data-line waiting for a key-pattern that triggers turning on a hidden capability. It's basically a variant of malware traffic signalling techniques on networks: [1]MITRE: Traffic Signalling
You might not even need to add hardware: firmware running in a TPM (which could be distributed as an opaque, encrypted BLOB) can easily be programmed to do things on receipt of a magic pattern in what would otherwise be a legitimate datastream being processed.
This is why open firmware and open hardware is important.
[1] https://attack.mitre.org/techniques/T1205/
The issue
I have is that pluton can be updated (via windows update)
So its only a matter of time before the malware creators find a way of updating pluton themselves... and then baking that into an email attatchment.
If pluton was a 'burn it once' type device that cannot be altered from external software , then it maybe a good idea.
Until that point..... it sounds more like a m$ power grab than any 'security' for my PC
Oh and preventing linux from being installed unless the distro has a m$ supplied key(for a suitable price)
Re: The issue
Or indeed that Microsoft could presumably decide that for our own good they'll take even more control of our PCs to do whatever their beancounters decide would make them even more money.
What a coincidence...
I'll opt out of using "Microsoft security" in any sentence that doesn't involve snickering, giggles, or outright howls of derisive laughter.
Microsoft is to security what flame throwers are to icecream cones.