Recently I came across Microsoft Pluton while searching for a new laptop. Initially I thought it was like TPM and wouldn’t affect Linux. But the more I researched, the worse it got. According to them
Microsoft Pluton is a chip-to-cloud security technology that provides hardware-based root of trust, secure identity, secure attestation, and cryptographic services
Does it connect to Cloud irrespective of the OS I ran? If yes this could be a privacy nightmare.
Why aren’t more people talking about this? It been here at-least since the last two generation of CPUs from AMD (from my research worst offender) and Intel.
Isn’t this a privacy violation lawsuit waiting to happen? In what ways does this Microsoft Pluton chip affect people who use Linux and should I not buy a new Laptop?
Also what about manufactures like Framework? Are they also forced to work with this chips?
From where I am, used laptops are not worth it.
Likely because of this:
Emphasis mine. It’s an optional function, and this sounds like it’s targeted to businesses who either provide or have IT services. So like TPM, you can use it or not, and given the sharp rise in ransomware and other attacks, I can see why a business might want to use it.
How bad is it? I dunno. It seems to be so “noteworthy” that nobody is talking about it, and it sounds very optional.
I mean not to be a tin foil hat but they are not going to admit to negative side effects. Take issues with right to repair and how they fly under the radar. John Deere is a big offender that affects everyone and few will know. Your food supply should be noteworthy.
I appreciate your analogy, and I recognize that the numerous Linux kernel maintainers haven’t so much as made a peep about this in the last two years—plenty of other drama, but not that.
It could be that it has flown under everyone’s radar, or it could be that it’s not anything to worry about (yet?).
‘optional’ just like the functions Intel ME provides?
I can’t personally say. Beyond my knowledge.
Vendors are no longer actively implementing the pluton spec. It’s not in itself equivalent to Intel ME, whereas something like platform security processor (aka PSP - based on ARM TrustZone) could be considered a closer equivalent.
can you please explain in a little more depth? are you saying pluton is basically dead in the water and is likely to disappear from implementations in silicon in the near future?
Pluton capable hardware is present on a wide range of contemporary IHV offerings (requires TPM2 hw on the SoC) but OEMs selling devices with these don’t seem remotely interested in enabling it.
Vendor uptake has been minimal, and participating vendors seem to have changed their minds and stopped, though I don’t think this will affect hw implementation as that wasn’t really governed by Microsoft to begin with.