Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

191–200 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#191
post #158

Earlier quoted context omitted.

> The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be defeated by a simple password without any TPM. I've only met one person who's phone was stolen. They grabbed it while it was unlocked and within minutes aft…

That's how it works now exactly because hardware security ("DRM") on phones is so good that grabbing phones whilst unlocked is the only way to beat it. For most of the history of phones, they would be pickpocketed or taken from bags, luggage, hotel rooms etc without you ever seeing the thief. This is a huge upgrade, and nothing to sniff at. I also had someone try to grab my phone out of my hand and run off whilst wal…

[dead]

Re: The GPU, not the TPM, is the root of hardware DRM

#192

I have to wonder A) What does DRM realistically accomplish for the media companies? And, B) How are these DRM schemes actually being defeated? I do occasionally don my pirate hat* and have never had an issue finding what I want at the quality I want within an hour of a episode/movie being released to streaming. That would seem to indicate that these efforts at DRM are actually failing to have any noticeable effect at…

Piracy is just a convenient excuse.

DRM is really about control. It's a technical trick that thanks to DMCA anti-reverse engineering clauses becomes a legal trick to dictate exactly who and how can play the content, much tighter than what copyright and consumer laws allow by default.

For example, without DRM you couldn't effectively sell separate licenses for computer screens and TVs, because users could just connect their computer to a TV.

DRM allows negotiating everything about distribution, up to who pays who for having a button on the TV remote.

Those who control the DRM have a veto power over everything, and have it viciously enforced internationally thanks to it being tied to copyright.

Re: The GPU, not the TPM, is the root of hardware DRM

#193
post #161

Earlier quoted context omitted.

No one wants a preboot password though. TPM means the system can boot and then do face login or whatever using the user's password in exactly one place. This is as much as most users will tolerate. And it also means Microsoft account recovery can work to unlock a forgotten password. The whole point is Microsoft don't want user devices to ever be trivially bypassed, regardless of how unlikely that is (probably more li…

"No one wants a preboot password though" - really? Doesn't strike me as particularly inconvenient, especially given the relative rarity of actual bootups these days. I've been using bog-standard FDE for as long as I can remember. One extra password entry per bootup for almost-perfect security seems like great value to me.

Absolutely. You are an exception. Get your head outside and look around you instead of assuming.

Re: The GPU, not the TPM, is the root of hardware DRM

#194
post #178

Earlier quoted context omitted.

Such restrictions usually mean that you can't play games via Windows VM or on Linux directly. Additionally, there are cheats using video capture cards, which cannot practically be prevented.

Wait what? I don't game, so this is new to me. Do you have more info? That seems pretty cool.

There are cheats that give you more information than you should have. These typically require access to the game process's memory space.

If you're cheating with a video capture card, this likely means you're allowing a program to rewrite your inputs to more accurately target player models. You will likely be banned if you do this on the same machine via screen capture. A video capture card can process the information on a separate computer, e.g. location of enemies by searching for specific colours, then write into a virtual USB mouse on the gaming rig to keep the player's crosshair on the enemy model. I'm not sure about specifics, but this kind of cheat is almost undetectable; it is only really mitigated by the cost and effort involved to do it.

Players can add additional mitigations on top of this, like only activating aim assist while the shoot button is pressed, to make it entirely undetectable.

Re: The GPU, not the TPM, is the root of hardware DRM

#195
post #20

Earlier quoted context omitted.

The end goal is DRM all the way to the screen. No capture cards will be allowed. It's a cat and mouse game, but I wouldn't discount these efforts as a mere speed bump. Screen enforced DRM will make things much harder. A motivated individual with the right tools and hardware hacking know how may be able to jailbreak a screen to record stuff, but that's going to make things out of reach for most people.

It doesn't matter at all how out of reach it is for most people. As long as one kid in Russia can do it, the torrent is available for everyone in the world just as soon. This has already been shown with videogame DRM like Denuvo. It's so hard to crack that only a handful of people know how, and yet they end up racing eachother so eagerly every time a new game comes out that it's usually done in under 24 hours. Unless…

> This has already been shown with videogame DRM like Denuvo.

No it hasn’t.

> Everytime a new game comes out that it’s usable done in under 24 hours

This is not even remotely true and is not based in any kind of reality.

Re: The GPU, not the TPM, is the root of hardware DRM

#196

Earlier quoted context omitted.

> The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. That's kind of the point. The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be de…

> That's kind of the point. The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be defeated by a simple password without any TPM. True, any preboot password method (even fully software) will be sufficient to preve…

But it doesn't even do that. If I want to perform the "evil maid" attack why would I screw around with the bootloader? I'm just going to replace the entire device with something that captures the password & sends it to me remotely.

Re: The GPU, not the TPM, is the root of hardware DRM

#197

Earlier quoted context omitted.

Microsoft doesn't sell hardware. Why would they be incentivized to make you buy new hardware? Unless you're alleging that their hardware partners pushed for it, in which case there would likely be logs of communications that are pretty illegal.

The OS requires minimum hardware. To force users to upgrade their OS, discontinue the old OS, and make a new OS version, which has greater minimum hardware requirements. Now the user is buying your software again. They're also buying new hardware which benefits the PC maker. It's a mutually beneficial relationship that forces the user to both buy the software again, and buy new hardware. (You do pay for Windows when…

From my experience it's actually the opposite. The PC is sold with Windows on it, purchased by the OEM. The OEM then loads crapware on the new PC before delivery because crapware companies pay the OEM to load crapware. As a result, it'd actually cost more to buy the device without Windows.

I've only ever seen one piece of x86 hardware that was sold with or without Windows in my lifetime. It was $15 cheaper at the time to buy the Windows version and install Ubuntu myself.

Re: The GPU, not the TPM, is the root of hardware DRM

#198
post #103
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

> TPM provides no added security value for the vast majority of users[1] Yes it does. The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. The vast majority of users aren't going to have the case opened and a special-purpose PCIe device installed to steal keys over DMA. The vast majority of users aren't going to have a dTPM vulnerable to SPI s…

What is the argument here about the CIA / NSA or any other US Federal 3 letter agency? If your device is secured via TPM or some other scheme that relies on an industry to secure your device they aren't going to be doing "DIMM popping". They are just going to get the master keys from whomever issued them and use that bypass whatever they need to on the device.

Re: The GPU, not the TPM, is the root of hardware DRM

#199
post #103

Earlier quoted context omitted.

> TPM provides no added security value for the vast majority of users[1] Yes it does. The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. The vast majority of users aren't going to have the case opened and a special-purpose PCIe device installed to steal keys over DMA. The vast majority of users aren't going to have a dTPM vulnerable to SPI s…

> The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. That's kind of the point. The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be de…

> The vast majority of users aren't going to have their laptop stolen at all

The vast majority of homeowners aren't going to have a house fire. The vast majority of drivers aren't going to have an accident. Etc. etc. etc.

It's insurance.

> The current recommendation seems to be against SMS 2FA because the security of SMS really is that bad, so if you need 2FA, use an authenticator app or similar.

This is correct. But SMS 2FA is better than no 2FA. The attacks you speak of are targeted attacks, where the victim and phone number are known.

> Any snake oil can be painted as defense-in-depth.

It's not snake oil, however.

Re: The GPU, not the TPM, is the root of hardware DRM

#200

Earlier quoted context omitted.

> That's kind of the point. The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be defeated by a simple password without any TPM. True, any preboot password method (even fully software) will be sufficient to preve…

But it doesn't even do that. If I want to perform the "evil maid" attack why would I screw around with the bootloader? I'm just going to replace the entire device with something that captures the password & sends it to me remotely.

I'm not groking what you're saying. Replace what "entire device"?
Post reply on HN