Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

31–40 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#31
post #17
post #14

There’s some technical details missing here. I get decrypting the video on a gpu makes it harder to screen capture, but can’t you just still emulate the GPU in software or directly capture the digital video output? The GPU still has no unique hardware private key, right?

The details don't seem clear, and I don't know that there's necessarily a unique key rather than stuff being batched, but basically yeah there's a cert chain back to a "trusted" source

how does the decryption key get into the GPU?

are GPU's currently shipping preprogrammed with keys used in DRM?

Re: The GPU, not the TPM, is the root of hardware DRM

#32

I have to wonder A) What does DRM realistically accomplish for the media companies? And, B) How are these DRM schemes actually being defeated? I do occasionally don my pirate hat* and have never had an issue finding what I want at the quality I want within an hour of a episode/movie being released to streaming. That would seem to indicate that these efforts at DRM are actually failing to have any noticeable effect at…

The sort of person who can set up -arr daemons isn't going to really be on the radar of anyone pushing DRM. Those skills are so rare people will pay for them. The point is that there is a huge market of people who barely know what an internet is but want to watch media. As long as they can't figure out how to get pirated content up and running quickly then DRM is doing its job.

Pirated content represents a relatively small and motivated community. There'll always be something like it, so the question for rightsholders is how to manage the size and visibility of that community.

Re: The GPU, not the TPM, is the root of hardware DRM

#33

>The FSF's focus on TPMs here is not only technically wrong, it's indicative of a failure to understand what's actually happening in the industry. This sounds 100% on-brand for the FSF. The FSF's primary public-facing persona has peculiar computing habits so far removed from the mainstream that it's likely he has absolutely no clue how the real world works. In fact by his own statement he has to rely on volunteers to…

The FSF has turned into the crazy old aunt that insists you unplug the coffee pot after use in case it's bugged. It's taken me a long time to come around to the reality that they are holding Linux back at every juncture, probably still salty over the GNU/drama.

Modern TPM support in Linux and systemD now permits automatic disk unlock for LUKS encrypted volumes using a key stored in the TPM - some ~15 years after Windows could do it.

I wonder what the TPM support is like in the HURD - ha!

The only complaint I have about the TPM is there is no standardisation in connectors, pinout, or bus type when it's not soldered onto the board. I have three motherboards with plug-in TPMs and each required a different, unique part that was difficult to source.

Re: The GPU, not the TPM, is the root of hardware DRM

#34
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

If you're going to run Windows 11 anyway, why would Microsoft care if you do it on a new or older PC?

Re: The GPU, not the TPM, is the root of hardware DRM

#35
post #3

DMCA 1201 should be reversed and DRM itself should be illegal.

DRM shouldn't be illegal, but works protected by DRM should be ineligible for copyright protection unless a key is placed in escrow somewhere. Basically, rightsholders should be be able to choose enforceable legal protection or unbreakable technological protection, but not both. Copyright was supposed to be a two-way street, but DRM permanently barricades one lane.

That makes some sense, I'd say using DRM should void copyright completely, keys or not. I.e. if they want to go out of the way with invasive anti-user measures, they should lose any legal protection against copying of that stuff.

It should also drive home the idea that DRM will be broken anyway and they'll be just left with nothing, so let them stick to copyright itself without all that DRM garbage.

Re: The GPU, not the TPM, is the root of hardware DRM

#36
post #20

Earlier quoted context omitted.

The end goal is DRM all the way to the screen. No capture cards will be allowed. It's a cat and mouse game, but I wouldn't discount these efforts as a mere speed bump. Screen enforced DRM will make things much harder. A motivated individual with the right tools and hardware hacking know how may be able to jailbreak a screen to record stuff, but that's going to make things out of reach for most people.

With how good modern screens are, and how good cameras are (and how easy both are to hack), you could always play back the video and capture the photons through the air. There was something called Macrovision back in the VHS/DVD days that tried to defeat digital/analog conversion, and I'm sure visual techniques could be devised... But I imagine someone with a good OLED and a good mirrorless camera (or even a cell pho…

Especially when you add HDR to the mix, I think it's still extremely difficult to get a high quality screen recording, if only because it's so hard to get the exposure right.

Re: The GPU, not the TPM, is the root of hardware DRM

#37

I have to wonder A) What does DRM realistically accomplish for the media companies? And, B) How are these DRM schemes actually being defeated? I do occasionally don my pirate hat* and have never had an issue finding what I want at the quality I want within an hour of a episode/movie being released to streaming. That would seem to indicate that these efforts at DRM are actually failing to have any noticeable effect at…

> B) How are these DRM schemes actually being defeated?

1. Disable video hardware acceleration in browser (preferably FF)

2. Open OBS studio

3. Record screen while streaming service of your choice is running.

Still works in modern OSs like Windows 10.

You're technically not circumventing the DRM decryption routines when you do this since the pixels displayed on screen have already been decrypted (just like recording cable to VCR post-decryption), so the legality of it is towards the lighter grey end compared to ripping DVDs. IANAL though.

Re: The GPU, not the TPM, is the root of hardware DRM

#38
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

Microsoft doesn't sell hardware. Why would they be incentivized to make you buy new hardware? Unless you're alleging that their hardware partners pushed for it, in which case there would likely be logs of communications that are pretty illegal.

Re: The GPU, not the TPM, is the root of hardware DRM

#39
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

If you're going to run Windows 11 anyway, why would Microsoft care if you do it on a new or older PC?

Windows 10 to Windows 11 upgrades are free. You know what's not free? The Windows license on a brand new computer if it's bundled with Windows. And here's a friendly reminder that the vast majority of users don't know how to build their own computer and install an operating system, even if it truly has been made extremely simple nowadays.

Re: The GPU, not the TPM, is the root of hardware DRM

#40
2008, Protected Audio/Video Path (PAVP), https://www.anandtech.com/show/2622/2

  Movie studios wanted a way of securing the content between the time the AACS was decrypted and the HDCP encryption took over. Once the AACS was decrypted the encoded movie was sitting in main memory and could be intercepted by any other application.. The solution was to re-encrypt the data once it was pulled off the disc (I'm not kidding).. encryption would be done by the application.. The graphics driver would be able to pass along the encrypted data to the GPU, which would then decrypt and decode it in hardware and then the entire framebuffer would be HDCP encrypted by the GPU before sending it out over DVI/HDMI.
Post reply on HN