Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

321–330 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#321
post #85

Earlier quoted context omitted.

You can get HDMI capture cards that do 4K30 HDR while removing HDCP for $20. Use Microsoft edge for playback (so you get 4K HDR). Stylish as addon to remove any player hud. Especially useful if you want to legitimately use copyrighted content but obviously can't just use a pirated version.

Which cards strip modern HDCP?

https://aliexpress.com/item/1005003020587234.html

Re: The GPU, not the TPM, is the root of hardware DRM

#322
post #126

I fully get the DRM hate. Now I don’t really follow the Windows world but I thought the goal of the newer TPM stuff was to be able to provide a trusted boot chain the way Apple does. I’m under the impression that some of the earlier versions allowed the TPM module to be a separate piece of hardware from the CPU and thus exposed an hardware attack path where someone could snoop or man in the middle. If you have a full…

Deploying some sort of TPM remote attestation for DRM requires every component from every vendor to play nice, so I don't think you'll ever see that rolled out for Windows. I would guess that the actual push for TPM is to have 'better' BitLocker, and Passkey support. In practice the default BitLocker+TPM configuration isn't that great (no user entropy/pin, dTPM is basically worthless). I have no actual understanding…

I figured it’s more about ensuring the kernel and boot loading and OS are 100% unmodified by attackers/malware.

If that helps with bitlocker or passkeys or whatever that’s great. But I assume at its base it’s a pure integrity play.

I would think that would also let you know the public key stuff used to communicate with hardware authentication like a fingerprint reader is secure too, but I don’t know how that stuff works well enough to know if that’s true.

Re: The GPU, not the TPM, is the root of hardware DRM

#323

The author is correct in that media DRM is tied to GPU vendors on the field right now. But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Enviro…

I always said a hefty sales tax (50%? 100%? 200%?) on final sale of any product containing just a single Universal Machine which has artificial designs/locks that prevent the owner from replacing any and all firmware/software with versions he has authored, and/or which lacks complete enough documentation of design and interfaces that would enable a knowledgable and capable owner to author his own software/firmware. T…

Why not just prohibiting the practice? This isn't weed or alcohol.

Re: The GPU, not the TPM, is the root of hardware DRM

#324
post #20
post #12

Earlier quoted context omitted.

There's always an analog loophole. Even if the OS is unable to access the memory storing the decrypted data, you could always just plug the output of the machine into a capture card and capture the decrypted stream that way. I suppose some monitors and TVs have "features" to cryptographically handshake with the GPU and ensure a secure link, but at some point the data must be decrypted and decoded to be displayed. Thi…

The end goal is DRM all the way to the screen. No capture cards will be allowed. It's a cat and mouse game, but I wouldn't discount these efforts as a mere speed bump. Screen enforced DRM will make things much harder. A motivated individual with the right tools and hardware hacking know how may be able to jailbreak a screen to record stuff, but that's going to make things out of reach for most people.

I can always just not consume the media. I will never pay for that hot garbage anyhow.

DRM won't make me pay, it'll only take your trash out of my mindspace... which is probably a blessing anyway.

Re: The GPU, not the TPM, is the root of hardware DRM

#325
post #20

Earlier quoted context omitted.

The end goal is DRM all the way to the screen. No capture cards will be allowed. It's a cat and mouse game, but I wouldn't discount these efforts as a mere speed bump. Screen enforced DRM will make things much harder. A motivated individual with the right tools and hardware hacking know how may be able to jailbreak a screen to record stuff, but that's going to make things out of reach for most people.

With how good modern screens are, and how good cameras are (and how easy both are to hack), you could always play back the video and capture the photons through the air. There was something called Macrovision back in the VHS/DVD days that tried to defeat digital/analog conversion, and I'm sure visual techniques could be devised... But I imagine someone with a good OLED and a good mirrorless camera (or even a cell pho…

This works for me! Nobody needs more than 480i anyhow.

Re: The GPU, not the TPM, is the root of hardware DRM

#326

Earlier quoted context omitted.

The whole point of TPM is that the OS is not under the user control anymore. If you modify it thanks to remote attestation you can no longer prove that it is unmodified using the TPM.

Do they mean that no OS modification is necessary to read the decrypted media from memory?

Currently, no. But once (undetectable) OS modification is no longer possible, making the undecrypted media unreadable is just a few API restrictions away.

In Android phones for example you cannot screenshot banking apps. And if you root (modify the OS of) your phone, banking apps refuse to work.

Re: The GPU, not the TPM, is the root of hardware DRM

#327
post #103
post #26

> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare co…

> TPM provides no added security value for the vast majority of users[1] Yes it does. The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. The vast majority of users aren't going to have the case opened and a special-purpose PCIe device installed to steal keys over DMA. The vast majority of users aren't going to have a dTPM vulnerable to SPI s…

I agree. TPM defends against the most likely threat that typical users are facing. And, where users that are individually targeted, the theft/robbery will more often than not be designed to appear "random".

Because TPM sniffers are now at a material cost of about $15 and can be acquired for a price at under $200, more than a TPM is needed for data encryption, especially for users like a CEO. This is why a firm I used to work for encrypted the key that could unlock user data with both TPM plus Yubikey.

Re: The GPU, not the TPM, is the root of hardware DRM

#328

Earlier quoted context omitted.

In many cases, downloading torrents and watching on a laptop/PC has a better UX than using streaming services. For example, it's impossible to watch 4k content on popular streaming services if you use Linux, and even with macOS/Windows you need a specific combination of hardware + OS + browser, if a service even offers it.

To be fair, UX isn't only about the point of consumption. 4k torrents don't grow on trees (luckily, 1080p is good enough for my own tastes), and for old or less-popular movies, it's often tough to find seeders, or they all upload at 100 kbps or only have half the file or something dumb like that. (At least on the public trackers I'm aware of: I have no clue what goes on in the super-duper-exclusive private trackers t…

On private trackers you can sometimes even see 4k blurry remuxes up before the blueray is even available in your local area due to different release windows around the world.

As far as I’ve seen, they pretty much grow on trees as far as films are concerned. TV shows are a very different story though and outside of hugely popular series are far more inconsistent.

Re: The GPU, not the TPM, is the root of hardware DRM

#329
post #103

Earlier quoted context omitted.

> TPM provides no added security value for the vast majority of users[1] Yes it does. The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. The vast majority of users aren't going to have the case opened and a special-purpose PCIe device installed to steal keys over DMA. The vast majority of users aren't going to have a dTPM vulnerable to SPI s…

> The vast majority of users aren't going to have their laptop stolen by the CIA/NSA and have their DIMMs popped and cryofreezed. That's kind of the point. The vast majority of users aren't going to have their laptop stolen at all, if they do it will 99% of the time be by someone who only wants to wipe it and fence it, and attempts to access data are most likely to be by unsophisticated family members who would be de…

> vs. FDE with a boot key stored in some cloud service secured with the user's password instead of a TPM

Without secure boot (backed by TPM), I can boot a small USB device that has LEDs on it to indicate to me that the target system has been infected to send me a copy of the target's password, after I already imaged the disk (or when I have another team member steal it or take it by force later).

If there's a UEFI password to access UEFI settings, I can reset it in under 20 minutes with physical access. Some tamper-evident tape on the laptop casing may stop me if I haven't already had a resource intrude into the target's home/office to have some replacement tamper-evident sticker material ready. Very very few places, even some really smart ones, make use tamper-evident material. Glitter+glue tamper-evident seals are something I can't spoof though.

It's not that hard to get into a hotel room. Often enough if a business books a hotel for you it's because they want access to your laptop while you're at lunch with another employee who so kindly suggests to leave your backpack in the hotel room.

disclaimer: all above is fictional and for educational and entertainment purposes only

Re: The GPU, not the TPM, is the root of hardware DRM

#330

Earlier quoted context omitted.

You're at an industry conference. I want the data on your laptop's hard drive. You leave your laptop in the hotel room. Which one is easier: 1. Go into your room and screw around with the boot loader to somehow give me unencrypted access to your laptop after you login next time. 2. Go into your room. Take your laptop. Put an identical looking laptop in place that runs software that boots and looks identical. Have it…

Passwords are generally defeated by a hammer to the fingers. Repeat until password is extracted.

Your hammer is preempted by a teethed hollow point bullet to the face (in the hypothetical scenario, of course).
Post reply on HN