Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

161–170 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#161

Earlier quoted context omitted.

> The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. That's kind of the point. The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be de…

> That's kind of the point. The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be defeated by a simple password without any TPM. True, any preboot password method (even fully software) will be sufficient to preve…

No one wants a preboot password though.

TPM means the system can boot and then do face login or whatever using the user's password in exactly one place.

This is as much as most users will tolerate. And it also means Microsoft account recovery can work to unlock a forgotten password.

The whole point is Microsoft don't want user devices to ever be trivially bypassed, regardless of how unlikely that is (probably more likely then you think though).

These things are everywhere: they're used by small businesses, unsophisticated users etc. but the story which will be written if anything happens because the disk was imaged sometime will be "how this small business lost everything because of a stolen Windows laptop" and include a quote about how it wouldn't have happened on a MacBook.

Re: The GPU, not the TPM, is the root of hardware DRM

#163
Ah yes. DRM.

1. Companies offer service that people don't want to pay for, and blame piracy.

2. Someone realizes that they can eliminate piracy and make lots of money by offering good service.

3. Piracy slowly dies, because people prefer €5 monthly subscription over torrent.

4. Other companies catch up. The market gets fragmented. By the nature of the market, it becomes impossible for one company to offer clearly good service.

5. Piracy gets fashionable again because it's more accessible than having twenty €50 subscriptions, half of them with ads.

6. Companies offer service that people don't want to pay for, and blame piracy.

Re: The GPU, not the TPM, is the root of hardware DRM

#164
post #22

Earlier quoted context omitted.

People in power and people with money are who you need to convince..

And how are they best convinced? Besides personal benefits like bribes, public opinion (re-election) and consumer habits (company profitability) seem to matter significantly. Please do add the options that I am forgetting.

> public opinion (re-election)

No matter who is re-elected, there's a preset window for law & policy, which perhaps only public outrage (and opportunist politicians) can shift. Outrage is a high bar (may be perhaps outside of Twitter).

Re: The GPU, not the TPM, is the root of hardware DRM

#165

The author is correct in that media DRM is tied to GPU vendors on the field right now. But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Enviro…

> The author is correct in that media DRM is tied to GPU vendors on the field right now ... hardware backed DRM can be so much more invasive

I expect mjg59 to know what they're talking about but like you say, I wonder the same thing about the strength of (what you call) Media DRM v Hardware-backed DRM.

  GPU vendors have quietly deployed [hardware-based DRM] ... [which] works just fine on [boards] that [don't] have a TPM and will continue to do so.
Work fine? Even if a section of GPU's vRAM is out of the reach of the OS (here, to implement DRM), wouldn't TPM / DICE be needed to establish trust / measure GPU's firmware?

Re: The GPU, not the TPM, is the root of hardware DRM

#166
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

My guess is that the b2b sales of Windows outnumber b2c, if not in volume then certainly in revenue. Suddenly, enforcing company security policies centrally without the client (laptop) being able to change then and still attest to connect to the corporate VPN, becomes a feature. After all, it's not your computer, it's the company's. I think inTune already uses the TPM for that kind of stuff, so "install this before w…

But then you can already use tpm as a business. No need to force it upon end users.

Re: The GPU, not the TPM, is the root of hardware DRM

#167
post #158

Earlier quoted context omitted.

> The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. That's kind of the point. The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be de…

> The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be defeated by a simple password without any TPM. I've only met one person who's phone was stolen. They grabbed it while it was unlocked and within minutes aft…

At least they weren't logged into their banking apps.

Re: The GPU, not the TPM, is the root of hardware DRM

#168
post #126

I fully get the DRM hate. Now I don’t really follow the Windows world but I thought the goal of the newer TPM stuff was to be able to provide a trusted boot chain the way Apple does. I’m under the impression that some of the earlier versions allowed the TPM module to be a separate piece of hardware from the CPU and thus exposed an hardware attack path where someone could snoop or man in the middle. If you have a full…

Deploying some sort of TPM remote attestation for DRM requires every component from every vendor to play nice, so I don't think you'll ever see that rolled out for Windows.

I would guess that the actual push for TPM is to have 'better' BitLocker, and Passkey support.

In practice the default BitLocker+TPM configuration isn't that great (no user entropy/pin, dTPM is basically worthless).

I have no actual understanding for how TPM is involved for Windows Hello/WebAuthn/Passkey or whatever, but at a glance it would seem Biometrics without a TEE seems like a very weak link.

Re: The GPU, not the TPM, is the root of hardware DRM

#169
post #158

Earlier quoted context omitted.

> The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. That's kind of the point. The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be de…

> The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be defeated by a simple password without any TPM. I've only met one person who's phone was stolen. They grabbed it while it was unlocked and within minutes aft…

That's how it works now exactly because hardware security ("DRM") on phones is so good that grabbing phones whilst unlocked is the only way to beat it. For most of the history of phones, they would be pickpocketed or taken from bags, luggage, hotel rooms etc without you ever seeing the thief.

This is a huge upgrade, and nothing to sniff at. I also had someone try to grab my phone out of my hand and run off whilst walking on the streets in France. Unfortunately for him I can run extremely fast. Once he saw I was catching up and about to beat the crap out of him, he gently placed the phone on the road whilst running and gave it back to me. Before phone security got really good a guy like that would have been using the sneaky approach and then visiting a back room in a phone shop to reflash all the hardware IDs, but secure boots and the mobile security chips have got good enough that this is no longer feasible.

Re: The GPU, not the TPM, is the root of hardware DRM

#170
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

Microsoft doesn't sell hardware. Why would they be incentivized to make you buy new hardware? Unless you're alleging that their hardware partners pushed for it, in which case there would likely be logs of communications that are pretty illegal.

I don't think it's illegal for hardware partners to ask Microsoft to give users reasons to buy new hardware. And of course they do this, they always have. The Wintel alliance has always been a symbiotic relationship between Microsoft and the hardware OEMs:

- Hardware guys make cool new hardware that incentivizes PC sales.

- Windows guys add driver and OS support in a timely manner so apps can utilize it easily.

And sometimes the other way around:

- Windows guys add some cool new feature that incentivizes PC sales.

- Hardware guys drive down component costs to compensate for the OS getting bigger and slower.

The problem for the PC industry is that in the last ~15 years or so this virtuous circle has broken down. Outside of Apple the hardware guys stopped coming up with cool new features that would shift units outside of gaming GPU upgrades, and gaming has anyway been dominated by consoles for a long time exactly because they have hardware DRM that works so game developers prefer it (also gamers when they want multiplayer without wallhackers). Intel struggled and AMD didn't really pick up the slack in any major way. Even Apple has struggled here - other than their proprietary CPU designs and rolling back some Ive-isms by adding more ports again, a modern MacBook isn't substantially different than the models they were selling years ago.

So that leaves the software guys to drive sales. Unfortunately for the PC OEMs Microsoft has well and truly run out of steam here. Their best people all left the Windows team years ago, and Windows isn't even a top level division anymore, being weirdly split between the Office and Azure teams.

A big part of the stagnation is driven by the web. Nobody writes Windows apps anymore except games, so there's no progress to be had by adding new Windows APIs outside of DirectX. Meanwhile the web guys are shooting the PC industry in the face with a policy of never adding features unless it's supported on every piece of hardware from every vendor, more or less, which makes competitive differentiation impossible, so nobody even tries anymore. There is no web equivalent of a driver since the Netscape plugin API was killed. They also move incredibly slowly due to the desire to sandbox everything. In the 90s the success of Windows was driven by some wizard-level hackers but as PC hardware matured clever tricks stopped being an important differentiator, and monopoly profits made them fat and lazy. It's clear that Nadella has zero confidence in the Windows org(s) ability to execute, hence why in the post-Ballmer years the rest of Microsoft has systematically divorced itself from them.

So - no hardware innovation thanks to the web, no major CPU upgrades thanks to Intel/AMD, no software innovation thanks to Microsoft. The PC industry is stagnant and desperate. What have they got left? Well, they have TPMs (really, TPM v2 because TPM v1 was kinda botched). And Windows doesn't really need it, but if Microsoft ties Windows upgrades to TPMv2 they can use the treadmill of security/support expiring on Win10 to drive one last round of hardware replacements that can give the industry an injection of revenue that can then maybe be spent on finding new hardware features to drive upgrades, seeing as Microsoft can no longer do it.

There's nothing illegal in any of this - nobody is price setting and it's not much different to prior eras when new Windows versions required more RAM.

Post reply on HN