Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

471–480 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#471

Earlier quoted context omitted.

Something like this produces a clean hdmi stream: ViewHD 2 Port 1x2 Powered HDMI 1... https://www.amazon.com/dp/B004F9LVXC?ref=ppx_pop_mob_ap_shar...

That page doesn't make any mention of HDCP stripping, and says it can only work up to 1080p anyway which isn't hardware protected to begin with. Where is the evidence this device strips HDCP?

I can’t remember where it was referenced from, but you can see in the reviews too that it strips HDCP. Good point on it not being 4k though.

Re: The GPU, not the TPM, is the root of hardware DRM

#472
post #469
post #403

Earlier quoted context omitted.

If they don't have a GPU that implements this then the decrypted material would be available to the OS, which is precisely what the streaming media platforms want to avoid.

It's because they don't trust the OS not to leak the decrypted bytes, but they could thanks to TPM (the OS would have to have a memory memory chunk not readable from admin/root etc). In this scenario the OS is part of the DRM.

Microsoft is extremely chill about admin-to-kernel privesc, so that's not a meaningful barrier.

Re: The GPU, not the TPM, is the root of hardware DRM

#473

Earlier quoted context omitted.

Video capture cards can be countered with encrypted video from GPU to monitor. That's why you can't screencap 4k Disney+ movies.

HDFury devices allow stripping of HDCP 2.2, and vast majority of users currently don't have HDCP 2.3 compatible monitors/TVs, so that's not an option yet.

I don't know if you need something as expensive as an HDFury. I know most $30 "4K upscalers" have a HDCP stripper built in.

edit: to further your point, though, I think most people's gaming monitors don't support HDCP _at all_. [citation needed]

Re: The GPU, not the TPM, is the root of hardware DRM

#474

Earlier quoted context omitted.

IIUI it's mostly a question of a mess of contractual language and incentives. Rightsholders license content, and in their licensing contracts they require a certain level of DRM for certain products. So streamers, etc, implement the DRM to comply with those contracts. Nobody at any level has an incentive or leverage to change the contracts, so the DRM continues.

That and also various principals are under the impression that DRM is possible, therefore they should implement it because it protects their IP, and protecting their IP is a fiduciary duty, therefore they must if they can.

> protecting their IP is a fiduciary duty,

This is not the case, unless we are talking about trade secrets, and in case of trade secrets, only applicable to board members and employees.

Re: The GPU, not the TPM, is the root of hardware DRM

#475
post #426

Suggestion for a compromise: Make it mandatory for TPM vendors to provide a user option to wipe all attestation keys and rebrand them as “embedded security keys” (and maybe promise to never use them for DRM, which per TFA nobody is anyway). I feel like untangling the attestation capability (which I do believe has non-user-hostile/non-zero-sum uses!) from the secure key storage one might ultimately help their adoption…

DRM is actually negative sum.

Re: The GPU, not the TPM, is the root of hardware DRM

#476
post #239
post #87

Earlier quoted context omitted.

This is the question I had about this. The reason this design works per the article is that the GPU memory is inaccessible to the OS, so the decrypted content cannot be stolen. With a unified memory architecture, is the shared GPU memory inaccessible to the CPU?

The GPU ultimately has to output unencrypted content, it will always be possible to steal unless we manage to implement drm in human eyes

human brains actually

Re: The GPU, not the TPM, is the root of hardware DRM

#477
post #426

Suggestion for a compromise: Make it mandatory for TPM vendors to provide a user option to wipe all attestation keys and rebrand them as “embedded security keys” (and maybe promise to never use them for DRM, which per TFA nobody is anyway). I feel like untangling the attestation capability (which I do believe has non-user-hostile/non-zero-sum uses!) from the secure key storage one might ultimately help their adoption…

DRM is actually negative sum.

I was talking about non-DRM use cases of attestation.

Re: The GPU, not the TPM, is the root of hardware DRM

#478
post #470
post #402

Earlier quoted context omitted.

Mandatory where? Most of the devices people are streaming video to these days aren't even PCs! Macs haven't had TPMs for a while now (I think Apple never really used it and dropped it even before the Apple Silicon switch), but of course they have their proprietary equivalent.

Mandatory to run windows, that's the topic of the article

Yes, but Windows isn't where the vast majority of people watch Netflix, so I don't see the incentive for media DRMs suddenly also making TPMs mandatory.

Re: The GPU, not the TPM, is the root of hardware DRM

#479
post #352

Earlier quoted context omitted.

So the idea is to ban the practice for smaller players without the scale to eat the costs? No thanks, an outright ban is necessary. This will not prevent manufacturers from doing business no matter how they may whine about it, and frankly if this does somehow kill their business it should

The idea is to make it almost completely commercially unviable to sell locked down DRM hardware to small players, and only somewhat harder for XYZ Healthcare to buy the multimillion dollar GE MRI machine unless the MRI is fully open and compliant (XYZ can borrow and amortize, but Joe can't do that to buy playstations and cars).

And of course, Joe then foots 2x the bill (denied by insurance, 'natch) when he is brought in to XYZ Healthcare managed hospital for a brain scan

Re: The GPU, not the TPM, is the root of hardware DRM

#480

Earlier quoted context omitted.

That and also various principals are under the impression that DRM is possible, therefore they should implement it because it protects their IP, and protecting their IP is a fiduciary duty, therefore they must if they can.

> protecting their IP is a fiduciary duty, This is not the case, unless we are talking about trade secrets, and in case of trade secrets, only applicable to board members and employees.

That's not how copyright works. The copyright owners want to maximize earnings, and the licensees/distributors also want to maximize earnings -- they are typically for-profit businesses, and as such they have a fiduciary duty to maximize earnings. If they think that DRM will help them, they'll want DRM.

Of course for music DRM has proven to be pointless. People want to stream music, not buy music, and preserving media across so many media obsolenscence events has been such a pain that streaming is the only manageable solution for most people -- consumers don't want to make and manage copies anymore.

The same should apply to movies and such, but maybe not -- it's not clear yet.

Post reply on HN