“Microsoft Pluton Hardware Security Coming to Our CPUs”: AMD, Intel, Qualcomm
anandtech.com
anandtech.com
Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-...
Disclaimer: I still work at MSFT but in a different org.
From a technical standpoint, Azure Sphere's OS was built on Linux. As far as I know, there isn't anything Windows specific to Pluton. Pluton was a separate (heavily-modified) ARM M4 core which we interfaced with from the main A7 core via a secure mailbox channel, which was again OS agnostic.
This kind of decision- to use an ARM core- seem pretty questionable. That's how things always were done, but it feels like another UEFI/FAT32 situation, dragging in old encumbering legacy baggage with big IP implications, when there are available other options (RISC-V).
It feels like this decision is being made literally one year too soon. Fixing the old, archaic in to place.
When the main core wanted to talk to the Azure Sphere cloud service (from Linux user land), it would go through a remote attestation process that involved Pluton. Pluton can securely track what software was booted on the main core (called "measure boot") and it basically sends a hash of that to the cloud to prove to the cloud what software is currently running.
So I imagine the chip-to-cloud thing they're talking about is this remote attestation protocol.
Also, it's possible the term "Pluton" has been expanded to refer to more than just the M4 chip we used in Azure Sphere.
oh dear
But the Pluton I know of didn't really have any writeable storage. It had some special ROM and fuses that it uses internally for its private keys but that's basically it.
- Was Pluton based on an RTOS or is it running on bare-metal on top of the M4? - Is the architecture on the i.MX8-based Sphere the same as the one on MT3620? - Does the Security Subsystem running on the Cortex-A's secure world have any relationship with Pluton? Is the Security Subsystem running on top of the Sphere's modified Linux kernel like the normal world is?
Thanks, cheers!
Hope that helps!
2. If the latter, "Every piece of software on an Azure Sphere device must be signed by Microsoft." what does the OS interface look like?
2. Pluton can check the signature of software before booting it on the A7 core.
Hope that helps!
On desktops and laptops, will this device have a hardwired user-presence sensor, like Yubikeys do?
Would this device be performance-oriented enough to, for example, terminate SSL? I gather TPMs can, but only unhelpfully slowly [1]
Would it be performance-oriented enough to perform disk encryption? What about memory encryption?
[1] https://blog.habets.se/2012/02/Benchmarking-TPM-backend-SSL....
I don’t think pluton was used for disk or memory encryption, in Azure Sphere but I believe the possibility was discussed.
I’m afraid I don’t have anything more than speculation for the rest.
That article explicitly states that it was designed originally for the xbox. I worry that going to be a very anti-consumer, anti-free-speech, DRM heavy chip that MS want to popularise as an alternative to the (still hated in some circles) TPM. Why else would they design it for the xbox, of all things? Is it aimed to stop speculative execution attacks on a cloud server, or provide Level 4 DRM to Widevine's as-yet-unannounced competitor?
How long until someone has a device which can go to Netflix, social networking, etc. but doesn't have a web browser on it that can load arbitrary pages, and it's impossible to jailbreak?
Since we have no freedom of speech within FAANG properties, that would be a considerable restriction of speech...
I do always find it wryly amusing when people who identify as being on the left see that the right are the only people who need defense using free speech laws, and then happily allow private industry to restrict speech since it doesn't impact them. The shoe could just as easily be on the other foot, and may well again be one day - principles matter.
To whom, though? Everybody is praising Apple for their (admittedly quite excellent) M1 hardware and no one seems to take issue with that either.
You cannot have truly open hardware as long as (software-) patents and IP exist, simple as that. Companies need to protect their investment, since the days of comparatively simple CPUs are over and a lot of "secret sauce" is actually software and licensed IP blocks.
Since patent holders are free to select who their licensee is, they'll always target the ones with the biggest margins (see for example [1]) so mainly consumer products and thus those won't be free (as in speech) anytime soon.
[1] https://www.bloomberg.com/news/articles/2020-10-20/nokia-see...
Pity all these laws end up spending most of their time enabling obscenity instead of political speech.
Why is it a free speech issue for a device to exist that can go to Twitter but doesn't host your blog for you?
Such a locked-down device wouldn't really be anything new, we already have Roku, Chromecast, Chromebook, and games consoles. They don't threaten the 'ordinary' PC market.
This has eaten away at the average person's computing freedom, ironically while providing them a ton more computing power and capability.
> They don't threaten the 'ordinary' PC market.
Not directly, but think about this:
* I know people who do not own a PC anymore, they just have tablet, phone, and TV. No need, apparently, but...
* This results in a ton of kids growing up without early exposure to general purpose computing
* This has been an increasing trend for quite some time now, and Pluton is just the next incarnation of Palladium, which tells us that Microsoft really does still see a completely captured market in their future. Linux plays a role, but in the embrace-and-extend sense; while WSL helps squeeze Linux out as a desktop OS down on the ground, Microsoft's ownership of Github cements it in the cloud.
I know, I know, old man yells at cloud, I don't expect this train to stop, I just want people to stop and think once in a while about where it might be going. It's OK to dream up worst-case scenarios and then strategize for how you might fend off that eventuality even if it's unlikely.
I agree that's a problem. It's possible to learn to code on an iPad, [0] but the system is generally closed to exploration.
[0] https://apps.apple.com/us/app/grasshopper-learn-to-code/id13...
That sounds like most of what you need to build a system that can enforce what executables you're allowed to load and prevent you from attaching a debugger.
That's a different use case (chip-to-cloud). It can also not prevent you from attaching a debugger when all you need to do is to go offline.
In fact, the whole point is that you can run anything without compromising the security of the data in the secure enclave. That's what Zero-Trust is all about.
If it goes into client chips, and someone uses it for DRM, that's awful.
I guess we'll see?
Isn't Microsoft already doing that on a default Windows installation?
Edit: Yes, SmartScreen, enabled by default, seems to send:
Hash, name and signature for executables. (Also hashes of urls you visit (though I guess only in Edge?))
If you really want to know the answer, here's the lead engineer explaining it en detail: https://www.youtube.com/watch?v=quLa6kzzra0
That's not something I want in my general-purpose computing device where I am the owner.
None of this stuff will change unless people vote with their wallets. Companies have the idea that nobody cares. I've actually heard "nobody cares about privacy and security" repeated as a mantra in multiple circles.
If nobody cares nobody cares.
Even if everyone is willing to spend an extra $100, a duopoly can ignore them and lose no money. That's not enough money to bootstrap a competitor desktop/laptop CPU.
Speaking of, I heard the librem phone just started shipping
The trouble is, (a) doing this is a bit of a giant PITA, and (b) companies never know that you're not there. Sony doesn't know, and doesn't care, that I don't buy their products because of their aggressive pro-DRM stance. I am one consumer, many sigma away from mu, and slowly but surely I look like an antiquated relic: streaming has been so successful, and Widevine so ubiquitous, that it's almost impossible to join the "normal world" without being subjected to (unwanted) DRM.
[1] https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
Consoles aren't general computing devices, though.
Apple disagrees with your idea of ownership, too ;) and so do the customers who Pluton is targeted at - https://www.microsoft.com/en-us/windowsforbusiness/windows10...
The whole project isn't targeted at end-users. It's IoT, businesses, hospitals, government agencies, utility companies, etc.
We need to stop seeing us (as private end users) as the centre of the world and start to acknowledge that there's hundreds of millions of PC devices out there that don't serve private end users. It's the security needs of these organisations that are addressed by this technology, not yours, not mine.
The unfortunate truth is that Windows is still the backbone of many government agencies, power plants, hospital IT, businesses and so on.
It's also a fact that most of these machines are not well managed, lack updates , aren't hardened or secured in any way and are targeted by cyber criminals on a daily basis; sometimes with grim consequences. It gets even worse when you look at IoT and the mess that manufacturers get us into (default passwords, unsecured data transfer, ...).
I see this chip in the same area as Intel's vPro, TPM 2.0, AMDs ASP (in their Ryzen PRO line), and so on; not necessarily aimed at end users (aside from the occasional buzzword) and more aimed towards businesses and government users (as part of their Zero-Trust initiative).
> It's the security needs of these organisations that are addressed by this technology, not yours, not mine.
It's perfectly fine to let a sysadmin lock down a computer to reduce what the end user can do.
None of these use cases or security benefits require taking power away from the sysadmin. And that's what the argument is about: not whether the end-user is losing control, but whether the sysadmin is losing control. With the obvious note that lots of home users are their own sysadmins.
> I see this chip in the same area as Intel's vPro, TPM 2.0, AMDs ASP (in their Ryzen PRO line), and so on; not necessarily aimed at end users (aside from the occasional buzzword) and more aimed towards businesses and government users (as part of their Zero-Trust initiative).
Those are basically fine, as long as they can be disabled when not needed.
But if I'm forced to give someone else special beyond-root access to my device for DRM purposes, that's not acceptable.
Yes, they do! That's the whole point of the product. Why would you even trust the sysadmin in the first place? The fact of the matter is that a lot of data leaks have been caused by insiders - either willingly or via social engineering.
This technology provides a method of closing this loophole and aims to enable users (not private people) to have a secure domain that not even someone with physical access to the system and all administrative privileges has access to.
Whether it works as advertised is another story of course, but the gist of it is that no one is to be trusted; especially not the sysadmin.
> With the obvious note that lots of home users are their own sysadmins.
Again - this is not primarily targeted at home users. Plus the vast majority of home users don't even know what administrating a system even means. And TBH - why should they? "It just works!" has been a very successful mantra for this one company what sells iPods and such... This might be hard to grasp for some greybeards, but hardware security by design is worth more than security cameras, NDAs, background checks and good work ethics.
> But if I'm forced to give someone else special beyond-root access to my device for DRM purposes, that's not acceptable.
And that's fine and you are free to not use these products then because they're not made for you anyway. This is not consumer level hardware (at least not yet).
You also start running into problems where more software and content may require such hardware.
These devices are not general computing devices (according to Apple), so in their mind that's fine. It also makes no difference to the customer since alternatives exist.
The fact that pretty much all other products in the smartphone and tablet market are inferior in terms of hardware, quality and software doesn't matter.
> You also start running into problems where more software and content may require such hardware.
So? If anything, this opens a market for software and hardware that doesn't require it, don't you think? For every Steam and Epic Game Store there's a Good Old Games [1] is what I'm saying. Just another great reason to support and use FOSS, no?
Yeah, well, if that's all it takes, then we'll probably not have any more "general computing devices" being sold in a few years. (Where did I hear that before?)
Whether it works as advertised is another story of course, but the gist of it is that no one is to be trusted; especially not the sysadmin.
Who exactly is the user in this scenario? Who exactly sets the rules that the pluton architecture should enforce here?
> And that's fine and you are free to not use these products then because they're not made for you anyway. This is not consumer level hardware (at least not yet).
I don't understand why you are so sure about this not being intended for consumer-level hardware. There are plenty of scenarios where locking consumers out of their own devices would be highly desireable from a business perspective - DRM being only one of them.
Consoles are absolutely general computing devices. Microsoft just uses DRM to prevent you from running non approved software.
David Cutler was called back from retirement to get Windows 10 booting on the Xbox One X.
Repeating a false statement doesn't make it true.
A general computation device is a device that manipulates data without detailed, step-by step control by human hand and is designed to be used for many different types of problems.
A gaming console is strictly not designed to be used for many different types problems. It's a piece of hardware designed to run a specific vendor-sanctioned class of video games and in some cases provide limited media playback capabilities.
It uses specially designed hardware for that purpose, which is different in many ways from general computer hardware (specialised SoCs, proprietary storage solutions, etc.).
Sure, it's perfectly possible to use a passenger jet as a demolition device for multi-storey buildings, but that doesn't mean that they're in same device class as demolition equipment. The type of a device derives from its intended use, not potential uses. That's why a nail gun isn't sold as a hunting weapon even though it ticks almost every box of being a firearm.
But if it is not aimed at end users, I am sure a simple switch will help. Somehow I doubt we will see it.
That's an amazing quote that should be preserved for posterity. ;-)
If the user attempts to modify the system, it will brick itself.
More to come - TPM required to connect to the Internet and access news sources without any ability to store information on our own devices. Followed by rewriting historical articles to properly "sanitize" content.
I've been yelling about that for years and years and very few people seem to get it. Free as in freedom got conflated with free as in beer years ago, and FOSS today is not much more than "waaah gimme free stuff!" It's not a gift culture. It's a "take culture."
Anyone who suggests any change to FOSS culture to remedy this problem gets shouted down. Any license that tries to remedy it gets attacked as "not OSI compliant" and restricting peoples' rights.
Meanwhile commercial closed source and SaaS vendors have the resources to leave FOSS and open ecosystems in the dust in terms of features and user experience. While the license purists yell about "restrictive licenses" taking away rights, the gravity of the walled gardens becomes more and more powerful.
The choice is between free and freedom.
It's very important, but it's not "everything".
> and without a good profitable business model FOSS can't afford the massive investment of time and effort required to bring a competitive user experience.
By that logic, most FOSS should not have existed at all.
> Making stuff work is only maybe 20% of the work required to build a product... sometimes less.
That's often true. It's certainly true for some of the software projects I maintain.
> Commercial closed source and SaaS vendors have the resources to leave FOSS and open ecosystems in the dust in terms of features and user experience
That's not possible even with infinite resources, because FOSS software is sometimes great, often good, and also often the only thing available.
1. Bluetooth; Audio especially, but all BT is flaky.
2. Low Latency audio; I have tried Jack on numerous machines and always find myself staring at high latency buffers because the kernel audio driver can't perform any better, and then there's how often it just ... goes silent without any trace in the logs.
3. Suspend and battery usage are, in general, still a decade behind the competition.
And, come to think of it, hibernation's been broken on my Windows install too lately.
For suspend there's been some regressions a few years back, but I use it all the time now on both Dell Latitude and Thinkpad X without any issue.
Battery usage is way better with Linux than with Windows, at least on the Latitude where I can easily compare with my Windows 10 using colleagues. It's not even close, and I also avoid the constant fan noise ;)
Now there's one thing to keep in mind: if you don't use a pre-installed Linux distro (which I don't, I use Debian stable) then you are the system integrator ;) No way around this.
But on well supported models like the Latitude and Thinkpad at least this integration is very easy: for me I just install the "tlp" (The Laptop Project) package, and because I only use SSD I aggressively idle the disk. This configuration I did years ago and simply reuse it. Done.
If the solution to making FOSS more competitive with non-FOSS is to make FOSS non-FOSS, well, that's not much of a solution.
It's not particularly practical to build a DRM scheme out of a Trusted Platform Module, notably because the key attestation the TPM provides audits a particular combination of boot stages, not a particular piece of hardware. DRM vendors don't care about you updating your firmware, but they do care about videos being locked to a particular authorized piece of hardware. If you had a TPM-based DRM, you'd deauthorize your video downloads by just updating your BIOS, while videos you passed from one person to another on the same OS version would play just fine.
I imagine Pluton is trying to be a competitor to Intel ME or AMD PSP, which are things you can use to isolate software running on shared hardware. For example, Intel ME provides hardware support for Intel Software Guard Extensions, which is used to isolate DRM from the host operating system. AMD has something similar with Secure Encrypted Virtualization, which uses the PSP to set up different memory-encrypted containers for each VM that higher security rings can't access. In this case, locking down PCs from arbitrary code, like an Xbox, isn't really on the menu. What they're looking to do is carve out space in Ring 3 that Ring 0 can't touch.
The Intel ME and AMD PSP, on the other hand, are proper nightmares. For that matter, so is any other "security co-processor" that operates as an unauditable black box below ring 0 (presumably this applies to both Apple's and Google's solutions).
From the article it also looks like Pluton will implement the TPM API, but I guess that's just to remain compatible.
Which is precisely what you would want if you were building a DRM scheme - you just aren't being imaginative enough. It's always important to keep in mind that bad actors are typically just as smart and capable as you are.
User hostile practices across the board benefit greatly from the ability to attest to the precise combination of binaries that were booted. Locked down devices are built upon that foundation - no custom ROMs, no jailbreaks, walled garden app stores, and DRM.
Unfortunately, those capabilities are a fundamental building block for securing devices in general. The same technology that can be used by an abusive manufacturer, publisher, or government to secure a device against the user can also be used by the user to secure the device against others. The key difference is in who holds the keys for the root of trust.
(To that end, some modern secure boot implementations manage to get this bit right by allowing you to specify your own set of public keys before locking down the UEFI interface with a password.)
edit: I think it is plainly incorrect to brush off fears about DRM deployment and device lock down. This technology was specifically invented for it, there is evidence and direct statements from manufacturers about this.
This chip is not here to protect you from compromised or malicious IoT devices, or to protect you from compromised or malicious cloud services.
This chip is here to protect the Microsoft cloud from compromised or malicious IoT devices. They would also like you to believe that the chip improves security in the cloud. In actuality it protects software running on your device from ... you. All this attestation stuff is great for DRM!
That poses a problem for marketing. They have to let it sound like it does something for you when it actually doesn't.
It's no surprise then that the marketing is basically a giant weasel word souffle with some buzzwords sprinkled on top, and a bit of name dropping.
He looked at me, with complete disbelief, saying "But why wouldn't you want your copy to be protected?" I asked him "Do you know what kind of protection this is?" to which he replied, "yes, it's a copy less likely to break".
After this incident, I started asking a lot of people if they are aware of what's special about their "copy protected" disks - and the more technical people knew it was an attempt to restrict copying, but the rest thought it was probably a good thing (it says protection, and its on the label, it must be good, or reasoning as such).
It was at that point that I started religiously using RMS style acronyms, like Digital Restriction Management, Copy Restriction, etc. and I recommend everyone does.
No. Pluton serves as an on-chip secure enclave for encryption keys and the like. This is unrelated to installing operating systems.
EDIT: s/access/r\/w & to the contents of/
If you mean access as in being able to arbitrarily read and write keys or data to/from it, then no, you won't be able to access it that way. After all that's the whole point - even physical access to the hardware won't enable you to extract information (keys, etc.) from it.
This means any data or firmware stored on the chip by Microsoft or any OEM (e.g. firmware encryption keys or device signatures) won't be accessible to consumers.
TPMs define interfaces, though that allow programs to access its capabilities, so there are ways to interact with the hardware (and those are documented as well so you can write applications or operating systems that support it).
To get an idea what the interface looks like, you can check out the documentation of the Windows API: https://docs.microsoft.com/en-us/windows/win32/secprov/win32...
There's also a list of some TPM commands available on the same site: https://docs.microsoft.com/en-us/windows/win32/secprov/addbl...
Whether vendors can use it to restrict such things, I don't think anyone can say right now, but I would guess and hope not. The TPM does not.
well at least it needs physical access.
I was keeping track of hacks for marketing material related to a security startup I was working on. The competition would have principally been smartphone-based authentication apps, both Android and iPhone.
In Azure Sphere, Windows is nowhere in sight. The device runs a Linux Kernel.
>Known Elements of the Palladium System:
> The system purports to stop viruses by preventing the running of malicious programs. The system will store personal data within an encrypted folder.
>The system will depend on hardware that has either a digital signature or a tracking number.
> The system will filter spam. The system has a personal information sharing agent called "My Man."
> The system will incorporate Digital Rights Management technologies for media files of all types (music, documents, e-mail communications). Additionally, the system purports to transmit data within the computer via encrypted paths
so are the trusted execution environments used by fTPMs?
>seems to have secret-management functionality for user-specified keys
AFAIK TPMs already have that functionality. random search: https://github.com/tpm2-software/tpm2-tools/blob/master/man/...
>biometrics, etc.
AFAIK some fingerprint readers already use trusted execution environments to handle authentication, so from a feature point of view there isn't really anything new here.
What's frightening is that - by design - the user will have little/no control or even awareness of what data is being sent or received.
Which means the OS still have full control over what it does send but the "thing" can attest that what the OS sends is valid and not made up.
AMD PSP for sure is. I think I might have heard something about Intel ME being on the PCH in some cases???
Anyway seems like the point is to make it a "more hardware" TPM rather than a firmware one – i.e. the key memory would only be accessible from fixed function crypto hardware blocks.
Coincidentally, this might mean that the embedded TPM would still work after me_cleaner destroys most of the ME firmware :)
CPUs with security modules controlled by MS? Who will guarantee it won't be abused against non MS systems and users?
With regards to the auditing need, can you audit a CPU down to the silicon level today?
And to your point about documentation vs implementation, it would not be difficult for anyone, to state one thing in the documentation and produce another thing, unless perhaps, you give access to the manufacturing facilities.
I'm reminded of Christopher Domas' excellent talk/s on finding undocumented X86 instructions, if there are any backdoors in a modern processor they'll probably under some hyper-obscure (register, stack etc.) state even if they did use an undocumented instruction.
I haven't seen evidence of this. Their OS is at least as user hostile as before and they desperately seek developers.
If I have a specific technical problem I have to slay hundreds of sales people before I find someone with real expertise.
That they aren't as dominant as before is probably due to the fact that they have few developers and need to regain some. Financially Office is probably the largest income and sure, the standard corporate AD solutions are wide spread. But their cloud tech seems to be restricted to very large companies and I haven't seen much of it.
WSL and .NET as open-source?
Their R&D budget in 2019 was twice that in 2010, meanwhile sales and marketing budget increased by 30%.
Their Productivity and Business Processes (which includes Office, Dynamics, ERP and LinkedIn) accounted for 1/3 of global sales revenue in 2019.
Sure, there are some things that have stayed the same in the last 10 years, but of all the FAANGS I would argue that MS is the company that changed the most in the last 10 years.
I hope they lose their investment.
I also hope all their hordes of fanboys wake up to reality now. Yes, the people that "<3 open source" and "<3 Linux" and gave you VS Code for free, will now own your CPU now and you have nothing to do about it. And then, if they change their mind and don't want you to run Linux, you won't run Linux.
It's like blaming America's analogue colour TV implementation (NTSC) when in fact PAL and SECAM haven't been invented yet (and NTSC is partially responsible for PAL even existing).
Honestly, Py2 was a PITA when handling raw data, it could corrupt your data if you don't know exactly what you are doing.
The goal was to separate (Unicode) text from binary data. It wasn't to UTF-16 though. In fact, you should just assume that text variables are encoded in Unicode points and not care whether it is UTF-16 or UTF-8 (and on Unix-like systems, it is definitely represented to UTF-8). If you are converting it into binary, at least you know what encoding is it: no "Oh no my Python code was broken on Windows/Unix" because even Py2 has already the UTF-16/UTF-8 OS split.
Instead they tried to split every function into a 'wide' (str) and a 'narrow' (bytes) version, like in Windows.
The whole idea of 'wide' strings is predicated on the idea that Unicode charpoints are only ever two bytes and that two bytes is all you ever need.
This obviously doesn't work in 2020, and the Python folks tried to roll back their broken by design code that has immediately turned into technical debt right out the gate, but the warts still exist. (Like having to choose whether you open files with 'w' or 'wb', etc. No other language does this stupid thing, I think.)