Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

141–150 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#141
post #20

Earlier quoted context omitted.

The end goal is DRM all the way to the screen. No capture cards will be allowed. It's a cat and mouse game, but I wouldn't discount these efforts as a mere speed bump. Screen enforced DRM will make things much harder. A motivated individual with the right tools and hardware hacking know how may be able to jailbreak a screen to record stuff, but that's going to make things out of reach for most people.

With how good modern screens are, and how good cameras are (and how easy both are to hack), you could always play back the video and capture the photons through the air. There was something called Macrovision back in the VHS/DVD days that tried to defeat digital/analog conversion, and I'm sure visual techniques could be devised... But I imagine someone with a good OLED and a good mirrorless camera (or even a cell pho…

Probably would be better carefully tap into the signal lines to the LCD panel, and record and decode that data to then make a video. However if we assume that even the cable going to the panel is encrypted and the board on the panel is decrypting it. (although I have never messed with a panel like that). However it still has to got to drive the rows and columns of the display, so then data to column and row drivers is still in the open.

If we were to even assume the Column/Row drivers chips only accepted encrypted data they still have the individual traces coming out of them. The pitch of the traces is super tiny, but still possible to tap, but would be a massive pain, but still do able.

Although you can get devices that strip the encryption from an HDMI signal these days so it's kinda moot. So it's not exactly something anyone would need to do these days.

Re: The GPU, not the TPM, is the root of hardware DRM

#142
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

Microsoft doesn't sell hardware. Why would they be incentivized to make you buy new hardware? Unless you're alleging that their hardware partners pushed for it, in which case there would likely be logs of communications that are pretty illegal.

File deduplication would reduce disk space usage by 40% on a typical consumer laptop, and works well in Windows Server. The reason it is not enabled in client windows is because storage sells.

Re: The GPU, not the TPM, is the root of hardware DRM

#143
The author is correct in that media DRM is tied to GPU vendors on the field right now.

But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Environment_Integrity

This tech extended to browsers could easily mean that sites could refuse to serve you if your machine is running any bigcorp unapproved software. An easy example of that would be adblockers.

Unless we get lucky with secure world compromises like the Tegra X1 bootrom exploit[1] or get real good at passing legistlation that forces companies to give you all the private keys to your own machine, the future for personal computing is looking grim.

[0]: https://developer.android.com/google/play/integrity

[1]: https://github.com/fail0verflow/shofel2

Re: The GPU, not the TPM, is the root of hardware DRM

#144
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

hard disagree. All security requires a root of trust. If you don't have that, how can you ensure you're not running on a mailicious hypervisor, you've not loaded any bad drivers etc.

You can only guess, and badly at that.

Because we don't have it, that's why we get crap like kernel-level anti-cheat, various 'security' solutions made by companies of dubious reputation and technical ability, just because you refused to trust Microsoft.

And even if these companies are somehow not malicious, and can be trusted, they still often compromise the stability and security of the OS.

The amount of crap Riot's anti-cheat and Crowdstrike has caused is well documented.

It's the computer security equivalent of not trusting Big Pharma, and taking a random assortment of herbal medicine coming from god knows where, and containing god knows what.

Re: The GPU, not the TPM, is the root of hardware DRM

#145

I have to wonder A) What does DRM realistically accomplish for the media companies? And, B) How are these DRM schemes actually being defeated? I do occasionally don my pirate hat* and have never had an issue finding what I want at the quality I want within an hour of a episode/movie being released to streaming. That would seem to indicate that these efforts at DRM are actually failing to have any noticeable effect at…

> B) How are these DRM schemes actually being defeated? 1. Disable video hardware acceleration in browser (preferably FF) 2. Open OBS studio 3. Record screen while streaming service of your choice is running. Still works in modern OSs like Windows 10. You're technically not circumventing the DRM decryption routines when you do this since the pixels displayed on screen have already been decrypted (just like recording…

Netflix limits FF and Chrome on Windows to 1080p. On Linux it's even worse: 720p.

And up through Dec 2023, FF and Chrome on Windows were limited to 720p. That's right, it wasn't until 2024 that Netflix on Chrome on Windows supported 1080p... That's what, 15 years after 1080p monitors became common?

https://web.archive.org/web/20231229030336/https://help.netf...

https://help.netflix.com/en/node/23931

Re: The GPU, not the TPM, is the root of hardware DRM

#146
post #14

There’s some technical details missing here. I get decrypting the video on a gpu makes it harder to screen capture, but can’t you just still emulate the GPU in software or directly capture the digital video output? The GPU still has no unique hardware private key, right?

> The GPU still has no unique hardware private key, right?

GPU's have had unique hardware private keys and secure memory for a decade.

Re: The GPU, not the TPM, is the root of hardware DRM

#147
post #31
post #17

Earlier quoted context omitted.

The details don't seem clear, and I don't know that there's necessarily a unique key rather than stuff being batched, but basically yeah there's a cert chain back to a "trusted" source

how does the decryption key get into the GPU? are GPU's currently shipping preprogrammed with keys used in DRM?

Yes, every* card since the Kaby Lake iGPUs or Nvidia 1080 cards.

*To all intents and purposes, I'm sure there's some exceptions with no market share.

Re: The GPU, not the TPM, is the root of hardware DRM

#148
post #125
post #15

> GPU vendors have quietly deployed all of this technology Citation or technical details needed. Obviously it "makes sense" that for 4K HD content you "probably" want to offload the decoding into the GPU, but this is the first time I see this mentioned and there are no links to technical details. In contrast, TEE / TrustZone and even the recent AVF with pVM - these are well documented technologies.

It was a big deal when Vista was released, with coincided with a lot of generational change in home computers (Watching Blu-Ray on computer still seemed to be a thing to expect, HDMI with HDCP was introduced, etc). There was a lot of talk about protected media path in Vista, how it linked with HDCP, how it killed hardware accelerated audio (including causing considerable death blow to promises made by OpenAL), etc.

And Steve Jobs famously described it as a "bag of hurt"

Re: The GPU, not the TPM, is the root of hardware DRM

#149
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

Microsoft is just trying to match features with apple which does the sorts of things with the T2 chip. Home users probably don't care that much, but corporate users do.

That said, the root of all DRM is not the TPM or the GPU or whatever... it is hollywood.

Re: The GPU, not the TPM, is the root of hardware DRM

#150
But afaik the TPM (or fTPM if no chip is present) is used to establish and restrict trusted access to the replay-protected memory block that the GPU (or other) DRM chain services depend upon to do their thing.

IMHO the author does overrestrictively interpret the FSS statement to discredit them.

Post reply on HN