Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

101–110 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#101

Earlier quoted context omitted.

Modern dedicated cameras have far more dynamic range than any HDR TV in practice. The movies have to be recorded somehow :)

> The movies have to be recorded somehow :) I'd imagine they do this via huge (non-consumer level) cameras as well as by professional editors and graders who spend countless hours on the process. But that doesn't really contradict your point. I don't know. I've never seen a good screen recording but I don't download pirated films so perhaps I've never seen an instance of someone really trying to get it right.

The cameras you can buy used for a couple thousand dollars have essentially the same sensors as huge cinema cameras, if not better in this application assuming you'll take stills.

Professional editors and color graders have to lower the dynamic range, because there is basically nothing that can get as bright as, say, the sun, and because basically no display can sustain peak brightness over the screen, which introduces an EOTF transfer curves, reducing the peak brightness and thus dynamic range.

You're right about pirated films, but that's because they're typically recorded in a run of the mill cinema while it's playing, not in controlled conditions in front of a carefully calibrated screen-camera combination taking a photograph of every frame.

Re: The GPU, not the TPM, is the root of hardware DRM

#102
post #95

The author seems misinformed about the purpose of TPM to DRM schemes. The purpose of a TPM, in this case, is not to provide encryption, but instead to provide so-called ‘authenticity’. A TPM with its attestation capabilities can allow a remote validator to attest the operating system and system software you are running via the PCRs which are configured based on it, with Secure Boot preventing tampering. [1] Google tr…

I notice you said "can" and "if". Does DRM actually use the TPM or not?

Re: The GPU, not the TPM, is the root of hardware DRM

#103
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

> TPM provides no added security value for the vast majority of users[1]

Yes it does. The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed.

The vast majority of users aren't going to have the case opened and a special-purpose PCIe device installed to steal keys over DMA.

The vast majority of users aren't going to have a dTPM vulnerable to SPI sniffing as modern and not-so-modern processors have fTPM.

This is to provide some baseline level of protection of the user's data against theft and loss.

Are there attacks against TPM? Yep. In as much as there are attacks against SMS 2FA, but for the vast majority of people, SMS 2FA is an acceptable level of security.

If you're a CEO, well sure, you're going to want to do something better (TPM + PIN). I acknowledge that Windows 11 Home users don't have this specific option.

Everyone needs to level set on the type of attacks that are practical vs. involved and who the targets of those attacks are.

FDE (w/ TPM) is part of defense-in-depth. Even if imperfect, it's another layer of protection.

Re: The GPU, not the TPM, is the root of hardware DRM

#104
post #96

Earlier quoted context omitted.

Watermarking would require a separate version of each encoded file for each target device, which is not amenable to efficient CDN-ing. It's quite easy to grab the encrypted media files, as they go over the wire - do this from two devices and compare what you get. (you don't need to strip the DRM to see if the two files are identical)

They wouldn't necessarily need to serve different data to each client when they control the whole playback stack, they could get clever by including duplicate frame data with subtle differences and making each device key only able to decrypt one of the variants. Repeat that throughout a show to add additional bits to the signature until it's uniquely identifiable.

But they don't control the playback stack, once the attacker has the keys. The attacker brings their own stack, decrypting the data with their own software.

Re: The GPU, not the TPM, is the root of hardware DRM

#105

Earlier quoted context omitted.

Microsoft does sell operating systems (and user data from those operating systems). Those operating systems are typically bundled / installed by default on computers. It's in their best interests to have everyone using the "latest and greatest" for those features that weren't present (at least to the same extent) in prior versions.

This is rather contradictory. There's way less friction to selling Windows 11 licenses to existing hardware owners. Requiring a new PC only means fewer people will be running 11.

I'm not sure that a large % of people would pay for a Windows upgrade - most seem to see it as part of the computer they bought.

Re: The GPU, not the TPM, is the root of hardware DRM

#106

Earlier quoted context omitted.

Microsoft does sell operating systems (and user data from those operating systems). Those operating systems are typically bundled / installed by default on computers. It's in their best interests to have everyone using the "latest and greatest" for those features that weren't present (at least to the same extent) in prior versions.

This is rather contradictory. There's way less friction to selling Windows 11 licenses to existing hardware owners. Requiring a new PC only means fewer people will be running 11.

Not really. The get a cut on both ends, really. If they make you upgrade to keep using up to date Windows because of claimed security issues, they get additional sales they possibly wouldn't have otherwise.

I suspect Microsoft has numbers which suggest people rarely upgrade their OSes anymore; they're more likely to upgrade their hardware. Enthusiasts still will do whatever but these changes aren't targeting or caring about enthusiasts.

Re: The GPU, not the TPM, is the root of hardware DRM

#107
post #95

The author seems misinformed about the purpose of TPM to DRM schemes. The purpose of a TPM, in this case, is not to provide encryption, but instead to provide so-called ‘authenticity’. A TPM with its attestation capabilities can allow a remote validator to attest the operating system and system software you are running via the PCRs which are configured based on it, with Secure Boot preventing tampering. [1] Google tr…

I'm extremely familiar with the capabilities of TPMs (I've worked on deploying remote attestation services at multiple companies), but here's the thing - streaming vendors don't use TPM-based remote attestation. None of them. It doesn't happen. Could it happen? Yes, but it would buy almost nothing - remote attestation is something that's viable in enterprise environments where you can bind TPM identity to inventory entries, and not in the real world where you could just plug in a second TPM on a USB adapter and fake the measurements. And how would you prove the attestation came from the same device that has the reported GPU key? Remote attestation is only useful when bound to other hardware keys, and there's no way within current specs to perform binding between the TPM and the GPU - pirates could just pass the attestation query to another machine.

Re: The GPU, not the TPM, is the root of hardware DRM

#108

Earlier quoted context omitted.

Microsoft does sell operating systems (and user data from those operating systems). Those operating systems are typically bundled / installed by default on computers. It's in their best interests to have everyone using the "latest and greatest" for those features that weren't present (at least to the same extent) in prior versions.

This is rather contradictory. There's way less friction to selling Windows 11 licenses to existing hardware owners. Requiring a new PC only means fewer people will be running 11.

> This is rather contradictory.

Not necessarily. I'd bet that the fraction of $ microsoft makes from selling windows licenses _retail_ is a rounding error away from zero compared to what they get selling bulk/volume licenses to corporate / OEM.

It's in microsoft's interest to make sure that dell/hp/lenovo ... etc have reasons to keep buying licenses to put on the new computers they're selling.

I suspect that TPM is about making the PC less open than it traditionally has been. For the majority of people on this site, that's going to cause a deathly-allergic reaction. For the majority of the population, there's some security advantages to having windows manage device security from POST.

Re: The GPU, not the TPM, is the root of hardware DRM

#109
post #102
post #95

The author seems misinformed about the purpose of TPM to DRM schemes. The purpose of a TPM, in this case, is not to provide encryption, but instead to provide so-called ‘authenticity’. A TPM with its attestation capabilities can allow a remote validator to attest the operating system and system software you are running via the PCRs which are configured based on it, with Secure Boot preventing tampering. [1] Google tr…

I notice you said "can" and "if". Does DRM actually use the TPM or not?

Depends on your definition. If you count video game anti-cheating software as DRM, the answer is yes. Apart from that, I’ve only currently seen TPMs used as a hardware identifier (in the same way a monitor serial is) for software licensing. The capability does exist however.

Re: The GPU, not the TPM, is the root of hardware DRM

#110
post #82

Earlier quoted context omitted.

Microsoft makes Xbox and the Surface. They are one of the largest consumer hardware manufacturers in the space. Anyways Microsoft was clearly very irritated when everyone wanted to stick with Windows 7, perceiving that Windows 8 was worse in every way, and that Windows 10 wasn't a significant enough upgrade to justify the effort especially considering all the added telemetry they added to the product. It's very reaso…

> It's very reasonable, given this, that they would seek to force the upgrade cycle to occur where it clearly otherwise might not. How is restricting which machines can run Windows 11 "forcing an upgrade cycle" on the software? It's clearly doing the opposite, by making Windows 11 upgrades less likely. The real motivation people have for upgrading to Windows 11 is Windows 10 going out of support. And the EOL date is…

On the consumer front, sure, but there are large contractual buyers who have requirements for TPM presence and several software policy systems can enforce it.
Post reply on HN