Hacker News new | past | comments | ask | show | jobs | submit login

Microsoft doesn't need an "untamperable" kernel to force spying on users. Windows 10/11 has horrible invasive telemetry that can't be disabled, but no one has figured out how to modify the OS and strip it out, all the "solutions" involve temporarily disabling services or blocking network traffic. Is there actually some new capability here that points to future surveillance and censorship, or are you just fitting everything Microsoft does into a narrative where these things are just around the corner and waiting for the right technology? In my opinion the technology has been there for many years, it's just waiting for the US to go insane enough to implement massive censorship.



But you can install your own OS. You can't disable this tool via another OS.

Particularly now that heterogeneous computing is making it big, video decoding can easily just be made not to work unless this tech stack okays it--regardless of the OS.

This chip could all out disable other operating systems if they don't provide the spyware telemetry that Microsoft requires.


By "this tool" do you just mean the Pluton system in general or some specific thing? The attestation stuff is a software feature that would be disabled by booting another OS that doesn't support it. It needs the Pluton hardware to be possible, but the software side is in the OS not hardcoded on the chip.

Disabling other operating systems would be done by the BIOS if manufacturers locked down the configuration of existing secure boot functionality, doesn't need any new features.


If I'm not mistaken, "no one has figured out" is factually incorrect. https://ameliorated.info/ blocks nearly all OS network requests (and hopefully all OS telemetry) by physically removing the relevant files from the system (though this breaks UWP apps, .appx, and such), and disables Windows Update to prevent telemetry components from being reinstalled. I use it on a near-daily basis, and it works quite well in most cases, although having a separate admin account by default, not being able to create new accounts (they show black screens), and missing features (Action Center and notifications) do sting, and I'm worried about the lack of security updates. If you do choose to use it, https://git.ameliorated.info/Joe/amecs is important for configuring the system.




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: