Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

241–250 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#241
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

I'm convinced Microsoft is prepping to make Windows as locked down as the Xbox, so that they can have final approval over apps that run on the platform and skim the top off app sales.

Apple has shown that the game console model can work for non-gaming software, and Microsoft wants in on that third-party app cheddar.

Re: The GPU, not the TPM, is the root of hardware DRM

#242
post #103
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

> TPM provides no added security value for the vast majority of users[1] Yes it does. The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. The vast majority of users aren't going to have the case opened and a special-purpose PCIe device installed to steal keys over DMA. The vast majority of users aren't going to have a dTPM vulnerable to SPI s…

In my experience, FDE (Full Disk Encryption) is more of a hindrance than help to average users.

It just means that when something goes wrong, such as a forgotten password or a botched update, their data that would have otherwise been recoverable is now lost forever.

I'm not sure I know anyone who's had a computer stolen, but I know lots of people who have lost data.

Edit: I do know one person who had a computer stolen. It was a work laptop while they were in SF, and I'll concede that FDE probably does make more sense on a work-related computer. I was only arguing that it's more of a hindrance on personal devices that mostly stay in the owners home.

Re: The GPU, not the TPM, is the root of hardware DRM

#243

Earlier quoted context omitted.

IIUI it's mostly a question of a mess of contractual language and incentives. Rightsholders license content, and in their licensing contracts they require a certain level of DRM for certain products. So streamers, etc, implement the DRM to comply with those contracts. Nobody at any level has an incentive or leverage to change the contracts, so the DRM continues.

> IIUI If I understand incorrectly? (Jokes aside, though, I haven't been able to figure out what IIUI stands for.)

If I understand it?

Re: The GPU, not the TPM, is the root of hardware DRM

#244
post #103

Earlier quoted context omitted.

> TPM provides no added security value for the vast majority of users[1] Yes it does. The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. The vast majority of users aren't going to have the case opened and a special-purpose PCIe device installed to steal keys over DMA. The vast majority of users aren't going to have a dTPM vulnerable to SPI s…

In my experience, FDE (Full Disk Encryption) is more of a hindrance than help to average users. It just means that when something goes wrong, such as a forgotten password or a botched update, their data that would have otherwise been recoverable is now lost forever. I'm not sure I know anyone who's had a computer stolen, but I know lots of people who have lost data. Edit: I do know one person who had a computer stole…

Surely this is an issue for there not being an easy mechanism for backing up?

The proper solution should be secure by design and user friendly. We shouldn’t compromise the former for the latter.

Re: The GPU, not the TPM, is the root of hardware DRM

#245
post #103

Earlier quoted context omitted.

> TPM provides no added security value for the vast majority of users[1] Yes it does. The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. The vast majority of users aren't going to have the case opened and a special-purpose PCIe device installed to steal keys over DMA. The vast majority of users aren't going to have a dTPM vulnerable to SPI s…

In my experience, FDE (Full Disk Encryption) is more of a hindrance than help to average users. It just means that when something goes wrong, such as a forgotten password or a botched update, their data that would have otherwise been recoverable is now lost forever. I'm not sure I know anyone who's had a computer stolen, but I know lots of people who have lost data. Edit: I do know one person who had a computer stole…

I know of at least 10 instances of a company laptop being stolen. From the back of a car, from a coffee shop, from a hotel room, etc. It happens.

Knowing any data on it cannot be recovered by malicious actors can be very reassuring.

Re: The GPU, not the TPM, is the root of hardware DRM

#246
post #151

Earlier quoted context omitted.

Microsoft doesn't sell hardware. Why would they be incentivized to make you buy new hardware? Unless you're alleging that their hardware partners pushed for it, in which case there would likely be logs of communications that are pretty illegal.

Yes they do, XBox and Surface devices.

Xbox is irrelevant to TPM in Windows 11 (as are Microsoft keyboards and mice). Surface has a fairly small market share.

Re: The GPU, not the TPM, is the root of hardware DRM

#247
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

The TPM is a great thing, from Microsoft's perspective.

Because Microsoft have the Secure Boot code signing keys. And none of their users expect a "free software philosophy" that lets them use their own modified kernel, or DKMS to build new copies of kernel modules on demand - so you don't have to make users jump through any "machine owner key" hoops.

And a lot of your customers are big corporations who barely trust their own employees - and inexperienced users for whom forgotten passwords and suchlike are a big problem.

With the TPM, that corporation's shared PC at the reception desk can have an encrypted disk without all the receptionists needing to know the password, only their own passwords.

With the TPM you can remotely force a reboot to install updates, and the computer will fully boot afterwards - not get stuck at a disk encryption prompt. Ideal if your corporate work-from-home policy is for employees to remote desktop on a PC under their desk.

With the TPM, the PC can boot, unlock the disk and join wifi before any passwords have been entered - so a corporation's employees only need to remember their windows password, and if they forget it, helpdesk can reset it remotely. It's great for the user too, who doesn't lose their non-backed-up data.

With the TPM you can have a short, weak passcode to unlock your PC, without worrying about brute force attacks. That's great if you want a cell-phone-style experience - or if you find long passwords an inconvenience, rather than a badge of honour.

With the TPM a corporation can give a laptop to a service engineer, who'd really like to install some games to play when he's stuck in a hotel over night for a service call, and who has unsupervised physical access - secure in the knowledge it's very difficult for them to install unapproved software.

For a corporation that wants hardware-bound keys, the TPM is superior to things like Yubikeys, precisely because of its inflexibility. Why give people a second factor that keeps working when they move PCs and that's compatible with different platforms, if you never want them to move PCs or change platforms without going through you?

It just so happens that the majority of these only benefit large corporations and forgetful users, while most Linux users are quite happy remembering long unique disk encryption passwords thanks very much.

Re: The GPU, not the TPM, is the root of hardware DRM

#248
post #235

Earlier quoted context omitted.

Passwords are generally defeated by a hammer to the fingers. Repeat until password is extracted.

Knees probably better -- break my fingers and I can't give you my password

I didn't break your jaw, so you can still communicate.

Point taken though, start with the toes, it gives you more to work with if you have to progress up the leg.

Re: The GPU, not the TPM, is the root of hardware DRM

#249

Earlier quoted context omitted.

IIUI it's mostly a question of a mess of contractual language and incentives. Rightsholders license content, and in their licensing contracts they require a certain level of DRM for certain products. So streamers, etc, implement the DRM to comply with those contracts. Nobody at any level has an incentive or leverage to change the contracts, so the DRM continues.

> IIUI If I understand incorrectly? (Jokes aside, though, I haven't been able to figure out what IIUI stands for.)

[deleted]

Re: The GPU, not the TPM, is the root of hardware DRM

#250
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

Whatever their motivation is, disabling TPM from Bios is the safest way to avoid upgrading to Win11.
Post reply on HN