• DFX4509B@lemmy.org
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    2
    ·
    edit-2
    8 days ago

    In theory Pluton enforcement platform-wide, which also includes forced SecureBoot without the ability to install user-signed keys, as well as OTA updates for that super-TPM, could block alt OSes on PC though.

    Fortunately, Pluton never caught on and that hasn’t happened so far.

      • DFX4509B@lemmy.org
        link
        fedilink
        English
        arrow-up
        10
        ·
        edit-2
        8 days ago

        Forced SecureBoot with only MS keys and no way to install user-signed keys and no Linux shim would block non-Windows OSes from booting.

        Basically, Pluton functions similar to how mobile devices function in terms of locked bootloaders.

        AFAIK the only devices currently produced which actually use Pluton are Surface devices though, and if it’s not being implemented as intended, it’s just seen as a generic TPM by other OSes.

        For anyone wondering what Pluton is: https://learn.microsoft.com/en-us/windows/security/hardware-security/pluton/microsoft-pluton-security-processor

        Pluton as TPM: https://learn.microsoft.com/en-us/windows/security/hardware-security/pluton/pluton-as-tpm

      • cley_faye@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        8 days ago

        Proprietary hardware, like opaque bioses that can only be updated with signed, proprietary blobs? The bios that’s in charge of picking something to boot from from storage? The bios that can decide which bootloader is allowed through digital signatures? The signatures that are only valid if their public key is registered in the bios? The proprietary, opaque bios that decide which bootloader’s signature is valid through keys it can restrict?

        Yeah, it’s all coming together. Always has been. Joking aside, I’m still surprised this whole “fully locked bios” didn’t take off. And I’m glad for it.

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      7 days ago

      Fortunately, Pluton never caught on and that hasn’t happened so far.

      I’m confused. don’t all recent AMD and intel CPUs have pluton included? I remember such an AMD announcement from ryzen 6000 and onwards, and for intel too