Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

281–290 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#281
post #14

There’s some technical details missing here. I get decrypting the video on a gpu makes it harder to screen capture, but can’t you just still emulate the GPU in software or directly capture the digital video output? The GPU still has no unique hardware private key, right?

> The GPU still has no unique hardware private key, right? GPU's have had unique hardware private keys and secure memory for a decade.

How does the remote streaming server know a key is an authentic hardware GPU that hasn't been compromised, and not something you just generated in software, to enable software level decryption of the media?

It seems like you'd need some central SSL like certificate authority to verify and revoke credentials that were universally implemented in the same way by all GPU manufacturers.... surely there is no such thing?

Re: The GPU, not the TPM, is the root of hardware DRM

#282

The top comment pretty much sums up everything that’s wrong with DRM: > Lest one get the impression that hardware DRM fairs any better than software: Even 4K/HDR versions of streaming media start making the rounds on pirate sites within a day or two of release. > As usual DRM fails to prevent piracy while hurting the experience of paying customers.

I remember the idea that DRM is not about controlling the viewers directly, but about controlling the makers of playback devices (both hardware, as in GPUs and TVs, and purely software). The point is not in making the bits uncopyable at all, but to prevent the makers of things like Roku or Chrome from making the access too easy, like skipping ads, let alone downloading.

Most viewers are not computer-savvy, even if they spend every day in an office facing a computer screen. If 90% of audience would know or bother to go no farther than the legal distribution channels, and won't be able to plainly download the high-res media in one click, the DRM has worked.

It suffices to make pirating inconvenient enough for the uninitiated, and let the advanced and determined minority pirate away, of course always threatened and stigmatized, to keep the operations low-key. A small amount of pirates, imho, only improves the profits, because they brag about having just seen the new hot thing in all its glory, and thus induce FOMO in their audience.

Of course the legally-buying, technology-naive audience is inconvenienced. But they know no better, and the whole point of control is, well, making people submit to what they rather won't, isn't it?

Re: The GPU, not the TPM, is the root of hardware DRM

#283

The author is correct in that media DRM is tied to GPU vendors on the field right now. But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Enviro…

If that ever happened I would nerd up on low level architectures. Get a job in a trusted company. Leak the keys.

The only worthy cause to apply my patience to.

Re: The GPU, not the TPM, is the root of hardware DRM

#284

I have to wonder A) What does DRM realistically accomplish for the media companies? And, B) How are these DRM schemes actually being defeated? I do occasionally don my pirate hat* and have never had an issue finding what I want at the quality I want within an hour of a episode/movie being released to streaming. That would seem to indicate that these efforts at DRM are actually failing to have any noticeable effect at…

It seems to have been a success. Prior to DRM, pirated material was much more common than paid streaming services. Now that has been reversed.

Now that streaming is commonplace it seems less necessary, but it was an essential stepping stone and an ongoing defense against piracy

Re: The GPU, not the TPM, is the root of hardware DRM

#285
post #18

Earlier quoted context omitted.

Capturing the digital video output is supposed to be prevented by HDCP encrypting the signal, but in practice that's pretty well broken. That is a (slowly) moving target though, each time they roll out a new HDMI version (e.g. for 4K) they get to enforce a new version of HDCP which needs to be broken all over again. I don't think the version of HDCP attached to HDMI 2.1 has been broken yet but that's kind of a moot p…

It's hilarious to imagine the meeting where they finally convinced themselves they could put worthwhile lasting encryption in consumer devices with a 10 year+ installation lifetime. What a complete and total waste of effort.

I suspect bad encryption still does exactly what they intend, because it means there is no simple one click solution built into an OS or browser to download streaming media for later watching or sharing with friends. For example, a lot of regular modern OSs have the ability to rip and share an unencrypted audio CD in a simple intuitive way with no shady pirate software to install.

It's a legal hurdle, not a technical one that prevents the 'above the board' software suppliers from adding this feature.

Pirates clearly are able to extract the 4K video and upload them to torrent sites, but the average media consumer would rather pay a netflix subscription fee that deal with the shady underworld of those sites with the virus installing and crypto mining popups, warning letters from your ISP, etc.

They've managed to make it hard enough that the number of people that do it is insignificant to their bottom line.

Re: The GPU, not the TPM, is the root of hardware DRM

#286
post #18
post #14

There’s some technical details missing here. I get decrypting the video on a gpu makes it harder to screen capture, but can’t you just still emulate the GPU in software or directly capture the digital video output? The GPU still has no unique hardware private key, right?

Capturing the digital video output is supposed to be prevented by HDCP encrypting the signal, but in practice that's pretty well broken. That is a (slowly) moving target though, each time they roll out a new HDMI version (e.g. for 4K) they get to enforce a new version of HDCP which needs to be broken all over again. I don't think the version of HDCP attached to HDMI 2.1 has been broken yet but that's kind of a moot p…

All the HDCPs are broken by those cheap Chinese splitters which downgrade it to 1.4 (allowed by the specs for some reason) and 1.4 is thoroughly broken. At least that was the case last I checked.

Re: The GPU, not the TPM, is the root of hardware DRM

#287
post #85

Earlier quoted context omitted.

You can get HDMI capture cards that do 4K30 HDR while removing HDCP for $20. Use Microsoft edge for playback (so you get 4K HDR). Stylish as addon to remove any player hud. Especially useful if you want to legitimately use copyrighted content but obviously can't just use a pirated version.

Which cards strip modern HDCP?

Something like this produces a clean hdmi stream:

ViewHD 2 Port 1x2 Powered HDMI 1... https://www.amazon.com/dp/B004F9LVXC?ref=ppx_pop_mob_ap_shar...

Re: The GPU, not the TPM, is the root of hardware DRM

#288
post #220

Earlier quoted context omitted.

The attacker must be able to fake any pre-boot drive unlock screen and OS login screen to look exactly as the user's real screens but accept any password. Legend goes that security oriented people will visually customize their machines with stickers (and their associated aging patina) and all kinds of digital cues on the different screens just to recognize if anything was changed. MS chose to impose TPM because it al…

> Legend goes that security oriented people will visually customize their machines with stickers (and their associated aging patina) and all kinds of digital cues on the different screens just to recognize if anything was changed. Maybe I am mistaken, but I feel that the people going to such lengths to ward off an attacker and the people who’d want to rely on fTPM with Bitlocker over FOSS full disk encryption with a…

> the people going to such lengths to ward off an attacker and the people who’d want to rely on fTPM with Bitlocker over FOSS full disk encryption with a dedicated passphrase are two entirely separate circles.

Bitlocker + PIN/password (hence my mention of a pre-boot password) is a good combination that isn't any worse than any "FOSS full disk encryption". Beyond the catchy titles of "Bitlocker hacked in 30s" is the reality that it takes just as many seconds to make it (to my knowledge) unhackable by setting a PIN or password.

Adding the (f)TPM improves the security because you don't just encrypt the data, you also tie it to that TPM, and can enforce TPM policies to place some limits on the decryption attempts.

> it is convenience, not security

It's convenience and (some) security by default. Not great security but good enough for most of those millions of Windows users. The security was the mandatory part, encrypting the storage by default. The convenience was added on top to get the buy-in for the security, otherwise people would complain or worse, disable the encryption. Whoever wants to remove that convenience and turn it into great security sets a PIN.

Re: The GPU, not the TPM, is the root of hardware DRM

#289
post #280

Earlier quoted context omitted.

There is no analogue loophole, that's like 15 years behind the curve. Cinavia closed that a long time ago and meant that licensed devices like Bluray players, even TVs, can detect cammed recordings even those cammed in movie theatres. Of course you can try to play them with hardware that doesn't follow the rules. But there's a finite number of vendors, so that isn't necessarily easy.

I’m confused, you’re saying the TV can tell if someone is pointing a camera at it? That seems highly doubtful.

It doesn't detect the act of recording live, it detects that a piece of media was obtained via recording. So, you can still point a camera at the screen and obtain a video file without any disruption to the original signal. However, that file won't play properly on Cinavia-enabled devices.

Re: The GPU, not the TPM, is the root of hardware DRM

#290

The author is correct in that media DRM is tied to GPU vendors on the field right now. But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Enviro…

If that ever happened I would nerd up on low level architectures. Get a job in a trusted company. Leak the keys. The only worthy cause to apply my patience to.

> If that ever happened I would nerd up on low level architectures. Get a job in a trusted company. Leak the keys.

> The only worthy cause to apply my patience to.

This already happened for smartphones.

Concerning your first claim: Did you attempt to get a job at such a company to leak the keys?

Concerning your second claim: Did you already invest lots of personal ressources for this cause?

Post reply on HN