Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

301–310 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#301

The author is correct in that media DRM is tied to GPU vendors on the field right now. But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Enviro…

> the future for personal computing is looking grim

I don't know. They could lock up the hardware stack as much as they want, in the end it's pixels being pushed to arrays. It's extremely hard to prevent these pixels from being intercepted. You'll have pirate groups just going deep in the hardware (opening the monitors and soldering and hacking and whatnots) and eventually tap these.

As for personal usage: I've got hardware from the eigthies still working fine.

Instead of:

     movie2025-WEBRip1080p-x265.mp4
people shall download:

    movie2025-WEBRip1080p-DRMfree-x265.mp4
And people shall just play that on their DRM-free hardware, either brand new or old.

For example people can still buy brand new CRT (!) screens today. Not just CRT screens but also brand new CRT PCBs to drive either new or old CRTs. It's 2025 and people can still buy brand new CRTs. That's kinda rad.

And if worse comes to worse, if it's really impossible to go "tap" into the pixels being sent to a DRMed monitor (which I don't buy for a second), there's still the analog hole. Pirates are just going to use old (non DRMed) gear to rip, analog style, DRMed content and then they'll just process the result with some AI models to get it back to near perfection.

Heck, the day's probably not very far where I can use, say, two handcams from the 90s to film a movie at the movie theater and then use an AI model to give back a near pristine movie file (as in: one where it's impossible for the layman to discern from the original).

> This tech extended to browsers could easily mean that sites could refuse to serve you

That's already the case: some content is geo-blocked. People use a VPN or just fire up Frostwire or qbittorrent.

Even a Raspberry Pi 5 goes a long way: when are these going to play the DRM game and make the future look grim, instead of bright?

I don't doubt there are really deeply sick, evil, people out there thinking about how they can ruin of collective future but I also know that they'll encounter people who have systematically owned their sorry arses.

Re: The GPU, not the TPM, is the root of hardware DRM

#302
post #79

Earlier quoted context omitted.

Denuvo has pulled back into the lead lately, it's taking a very long time for cracks to appear, if they ever do. For example Dragons Dogma 2 came out in March and still hasn't been cracked. Avatar: Frontiers of Pandora hasn't been cracked for a full year.

Active player counts: Minecraft: ~185,000,000 World of Warcraft: ~7,250,000 Dragons Dogma 2: ~4000 This seems more along the lines of nobody bothers to crack games nobody wants to play.

there's only one person releasing cracks for modern denuvo and their last release was a year ago, and they're crazy

Re: The GPU, not the TPM, is the root of hardware DRM

#303
post #151

Earlier quoted context omitted.

Yes they do, XBox and Surface devices.

Xbox is irrelevant to TPM in Windows 11 (as are Microsoft keyboards and mice). Surface has a fairly small market share.

On the contrary, Windows 11 TPM requirements and Pluton security processor were originally designed for the XBox and piracy protection.

The size of market share is irrelevant, doesn't change the hard fact that Microsoft does indeed produce hardware.

Re: The GPU, not the TPM, is the root of hardware DRM

#304

Earlier quoted context omitted.

I think that's a misunderstanding of what the FSF stands for overall, though. The FSF can never be a diplomatic negotiator for the benefit of free software; they are idealists, even when it serves against their own interests. Their whole shtick is not settling for half-baked appeasements, and so they're destined to be a pariah of the tech industry at-large. Neither you nor me can stop them, it's entirely within their…

There's no misunderstanding on my part; it's why I said that their ignorance is totally on-brand. >more like the mainstream has abandoned free software. Indeed, because free software development is largely driven by ideological purity rather than feature parity. Mainstream users see Free Software people as irrelevant kooks, and thus easy to dismiss, which is why Free Software has so utterly failed as a movement. >You…

> Indeed, because free software development is largely driven by ideological purity rather than feature parity.

This "ideological purity" didn't come out of nothing, it came out of the very practical issue of who is in control. People forget that RMS came up with the whole thing because he wanted to fix a broken printer and was denied the source code that could help him fix the issue.

He wasn't siting in some ivory tower coming up with abstract philosophical questions, he was in some lab and had an actual practical problem he wanted to fix.

Re: The GPU, not the TPM, is the root of hardware DRM

#305

The author is correct in that media DRM is tied to GPU vendors on the field right now. But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Enviro…

I always said a hefty sales tax (50%? 100%? 200%?) on final sale of any product containing just a single Universal Machine which has artificial designs/locks that prevent the owner from replacing any and all firmware/software with versions he has authored, and/or which lacks complete enough documentation of design and interfaces that would enable a knowledgable and capable owner to author his own software/firmware. This should apply to PCs, phones, watches, microwaves, televisions, CPAP machines, automobiles, toasters... everything which contains a Universal Machine. Uncontrolled [by owner] Universal Machines are a national security concern which has the potential to turn grave at any moment.

Re: The GPU, not the TPM, is the root of hardware DRM

#306
post #254

Earlier quoted context omitted.

You're at an industry conference. I want the data on your laptop's hard drive. You leave your laptop in the hotel room. Which one is easier: 1. Go into your room and screw around with the boot loader to somehow give me unencrypted access to your laptop after you login next time. 2. Go into your room. Take your laptop. Put an identical looking laptop in place that runs software that boots and looks identical. Have it…

Have you been to an industry conference? So many laptops are covered in stickers, good luck recreating that.

I don't mean to disagree, but I think it's worth pointing out that with today's tech, it wouldn't be difficult for an attacker to also scan the stickers and print them out on sticker paper using a color printer, all in minutes. And the technology for doing that is only getting better. Just a thought.

Re: The GPU, not the TPM, is the root of hardware DRM

#307
post #199

Earlier quoted context omitted.

> The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. That's kind of the point. The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be de…

> The vast majority of users aren't going to have their laptop stolen at all The vast majority of homeowners aren't going to have a house fire. The vast majority of drivers aren't going to have an accident. Etc. etc. etc. It's insurance. > The current recommendation seems to be against SMS 2FA because the security of SMS really is that bad, so if you need 2FA, use an authenticator app or similar. This is correct. But…

> It's insurance.

It's rubbish. The circumstances that would make it even theoretically useful are rare and in practice it doesn't even work then. There is no reason to pay good money so you can be insured against alien abductions under a policy whose terms won't pay out even if you somehow actually get abducted by aliens.

> This is correct. But SMS 2FA is better than no 2FA.

The alternatives to SMS 2FA don't just include no 2FA, they also include any of the better 2FA alternatives to SMS.

Choosing SMS is like saying we should all bottle our urine in case we need something to drink later. There's juice and soda in the fridge and a tap full of water right over there, don't be crazy.

> The attacks you speak of are targeted attacks, where the victim and phone number are known.

How do you mean? Anyone who can snoop SMS gets a list of usernames and passwords from a data breach, tries them all against a hundred services, when that user exists on that service the service says "we sent SMS to your phone number at xxx-xxx-4578" so the attacker looks for any SMS code to any phone number ending in 4578 in the last ten seconds. Even if they don't have the phone number from the data breach, most commonly there is only one matching message, if there are two or three they just try all of them, and now they've compromised thousands of accounts on a hundred services because SMS is such rubbish.

On top of that, the targeted attacks also work against SMS. If you know the target's phone number you don't need to be able to capture every SMS to compromise them using SIM swapping or any of the other numerous vulnerabilities SMS 2FA is susceptible to.

> It's not snake oil, however.

It's a proposed solution with negligible or negative benefits over known alternatives. That's snake oil.

Re: The GPU, not the TPM, is the root of hardware DRM

#308

>The FSF's focus on TPMs here is not only technically wrong, it's indicative of a failure to understand what's actually happening in the industry. This sounds 100% on-brand for the FSF. The FSF's primary public-facing persona has peculiar computing habits so far removed from the mainstream that it's likely he has absolutely no clue how the real world works. In fact by his own statement he has to rely on volunteers to…

The FSF has turned into the crazy old aunt that insists you unplug the coffee pot after use in case it's bugged. It's taken me a long time to come around to the reality that they are holding Linux back at every juncture, probably still salty over the GNU/drama. Modern TPM support in Linux and systemD now permits automatic disk unlock for LUKS encrypted volumes using a key stored in the TPM - some ~15 years after Wind…

We have had "FDE" and secure boot with TPM in higher-than-commercial (defense) and the higher end of commercial settings for Linux, BSD, and illumos since TPM 1.2 was available, and I'd have to dig in some places to confirm but probably before Windows did in actual practice anywhere (let alone officially).

Yeah, Debian/Ubuntu, Fedora, etc didn't have this, but as the saying goes: you get what you pay for. Although enough of the Gentoo users (the real Gentoo users) have such a thing had it around that time too, if they wanted it (and they tend to put together what they want).

Some essential context: if you think the "Linux community" is elitist, wait until you see the niche commercial (and higher) players. I'm probably an example of such, to be fair.

Re: The GPU, not the TPM, is the root of hardware DRM

#309
post #92

Earlier quoted context omitted.

Requiring TPM can actually benefit multiplayer video games because it introduces a secure way to identify hardware being used by cheaters. Right now everything being used by games is easily spoofed by cheats so cheaters just need to get a new account to continue cheating after being banned.

then you just sit on the unencrypted pci bus and sniff the interesting stuff out of it (e.g. display lists) already some hacks doing this

Anti-cheats are already detecting DMA devices like this.

Re: The GPU, not the TPM, is the root of hardware DRM

#310
post #282

The top comment pretty much sums up everything that’s wrong with DRM: > Lest one get the impression that hardware DRM fairs any better than software: Even 4K/HDR versions of streaming media start making the rounds on pirate sites within a day or two of release. > As usual DRM fails to prevent piracy while hurting the experience of paying customers.

I remember the idea that DRM is not about controlling the viewers directly, but about controlling the makers of playback devices (both hardware, as in GPUs and TVs, and purely software). The point is not in making the bits uncopyable at all, but to prevent the makers of things like Roku or Chrome from making the access too easy, like skipping ads, let alone downloading. Most viewers are not computer-savvy, even if th…

The DRM doesn’t really make pirating any more inconvenient for the (pirate) consumers (they get e.g. an MKV file without any of it). If there was no DRM on the legal platforms, it would be easier for pirates to release new stuff, but just marginally so.

If there was no DRM, ordinary viewers would still choose Netflix over torrents, and perhaps some more tech-savvy users would choose it as well (since many do want to support film makers, but are opposed to DRM). It would still be as hard to create a “pirate Netflix” as it is now, because of legal threats and because it’s tricky to monetize it.

DRM literally serves no purpose outside of some corporate politics bullshit.

Post reply on HN