Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

341–350 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#341

Earlier quoted context omitted.

What advantage does this have over just criminalizing the underlying infringement regardless of DRM? Also, how does criminalizing it actually help anything, since the difficulty is in the scale of it happening and the difficulty of detecting it rather than the severity of the penalties, and imposing draconian penalties on random kids only turns the public against you?

I think it plays differently before a jury. Juries can easily understand copying files and could potentially invalidate. But it's different when lawyers get to move the conversation to scary hacker garble about technical skill and intent. Evidence of intent is the real value.

Juries are far less incompetent than they're made out to be, not least because both sides get to describe what's happening.

And you can't even get evidence of intent from this anyway because DRM circumvention tools don't actually come with a ski mask and a set of lockpicks. You install a tool called "video downloader" which supports a hundred sites and 10% of them have some kind of DRM which it automatically strips in the background, you may not even be aware that it's happening when you use it.

Re: The GPU, not the TPM, is the root of hardware DRM

#342

Earlier quoted context omitted.

I always said a hefty sales tax (50%? 100%? 200%?) on final sale of any product containing just a single Universal Machine which has artificial designs/locks that prevent the owner from replacing any and all firmware/software with versions he has authored, and/or which lacks complete enough documentation of design and interfaces that would enable a knowledgable and capable owner to author his own software/firmware. T…

Why not just prohibiting the practice? This isn't weed or alcohol.

Still allow for the multimillion dollar industrial dozen-megamachine makers.

Re: The GPU, not the TPM, is the root of hardware DRM

#343

Earlier quoted context omitted.

Despite the bad press it's received over the years, SGX is a very solid design and works pretty well. Some of the papers presenting breaks turned out to be quite misleading when I looked closely at them some years ago. If you want a general purpose TEE then you could do worse than play with it. Unfortunately it's not available on consumer hardware anymore, and in the cloud only Azure really supports it AFAIK. And you…

Amazon has their Nitro secure enclave system that's pretty easy to use. IIUC its based on isolating the code that runs it and in it onto one core set aside for just that, possibly just when it's needed. Having the SE be easy to use is a key thing. Not that the Nitro approach extends well to consumer hardware (it doesn't).

The problem with Nitro is that a TEE doesn't really work if the adversary makes your CPUs.

SGX works, conceptually, because of the division of labor between Intel and the people running the machines:

1. Intel can't break into your enclave even by subverting SGX, because it doesn't have access to the computers (isn't your cloud operator or network admin).

2. The people with access to the computer can't break into your enclave, because SGX blocks everyone except the enclave owner and Intel.

With Nitro, Apple's approach and a few others the logic becomes:

1. Amazon can't break into your enclave even if Nitro has a back door because Amazon don't have acces.... oh, wait.

SGX is conceptually sound because subverting it at the design level requires the CPU maker and the cloud operator to team up against you. This could happen, especially if you use a US cloud and the US government gets involved, but the bar is much higher. And of course you can always choose to run the hardware somewhere the USG can't get at it, requiring a coalition of those two governments or providers

Re: The GPU, not the TPM, is the root of hardware DRM

#344

Earlier quoted context omitted.

No, the GPUs have their own hardware RoT that measures the firmware. Modern GPUs are basically parallel computers with their own RAM, bootup sequence, BIOS, operating systems (drivers and firmware together are basically an OS), compiler toolchains, debuggers, sub-drivers and so on.

One which needs to be opened to users/owners instead of locked away. A price-doubling 100% sales tax on Universal Machines which lock owners out like with video cards (and their firmware), should make products which are not fundamentally significantly GNU-ideals friendy unaffordable to the average consumer (and therefore not economically viable anymore). Siemens can still sell their $5MM machine for $10MM to BASF or…

Good luck getting elected on such a platform. Totalitarian states can do that kind of thing, democracies not so much.

Re: The GPU, not the TPM, is the root of hardware DRM

#345
post #294

Earlier quoted context omitted.

It doesn't detect the act of recording live, it detects that a piece of media was obtained via recording. So, you can still point a camera at the screen and obtain a video file without any disruption to the original signal. However, that file won't play properly on Cinavia-enabled devices.

Any computer or phone can play it back I’m sure. It’s just an MP4 file. And with Airplay or an HDMI cable your TV can too?

Depends who makes your computer, phone or TV and the licensing etc. The tech is perfectly capable of stopping that. The device detects the Cinavia watermark and simply silences the audio after a few minutes.

I don't know whether streamers use it but it was widely deployed in the era when movie piracy revolved around making pirated Blurays. For instance the PS3 would silence the audio on a burned Bluray that had a theatre or TV cammed title protected by Cinavia on it.

A lot of this is about catching the fat head though. People who play videos using some hacked up VLC on Linux don't bother the studios, they're long tail and don't make a revenue impact. They're after the ordinary people who want to watch pirated stuff on a regular home cinema system.

Re: The GPU, not the TPM, is the root of hardware DRM

#346
i've done a lot of work with Arm TrustZone, OP-TEE, and Arm Trusted Firmware. it's really nice. in Arm, the TEE is user-supplied, not vendor-supplied, so it gives an isolated execution environment for any sensitive code you might want to put in there. hardware peripherals (tzc/spu) allow you to designate certain bus addresses or memory ranges as "secure" during the early firmware initialization, meaning Linux (or whatever OS you use) cannot read or write to them. furthermore, unlike a TPM, the TEE isn't running in parallel on a co-processor -- it only runs when Linux yields control (cooperative scheduling) so it provides functionality without wrestling away control.

Re: The GPU, not the TPM, is the root of hardware DRM

#347
post #322

Earlier quoted context omitted.

Deploying some sort of TPM remote attestation for DRM requires every component from every vendor to play nice, so I don't think you'll ever see that rolled out for Windows. I would guess that the actual push for TPM is to have 'better' BitLocker, and Passkey support. In practice the default BitLocker+TPM configuration isn't that great (no user entropy/pin, dTPM is basically worthless). I have no actual understanding…

I figured it’s more about ensuring the kernel and boot loading and OS are 100% unmodified by attackers/malware. If that helps with bitlocker or passkeys or whatever that’s great. But I assume at its base it’s a pure integrity play. I would think that would also let you know the public key stuff used to communicate with hardware authentication like a fingerprint reader is secure too, but I don’t know how that stuff wo…

TPM can measure the Secure Boot state for later reporting (attestation) but when it comes to DRM, that’s not a terribly interesting bit of information, knowing the firmware and kernel are valid, when the configuration of the OS and installed applications is really the important part.

As far as I know there’s no real scalable way for that to work in the Windows ecosystem.

Re: The GPU, not the TPM, is the root of hardware DRM

#349
post #192

I have to wonder A) What does DRM realistically accomplish for the media companies? And, B) How are these DRM schemes actually being defeated? I do occasionally don my pirate hat* and have never had an issue finding what I want at the quality I want within an hour of a episode/movie being released to streaming. That would seem to indicate that these efforts at DRM are actually failing to have any noticeable effect at…

Piracy is just a convenient excuse. DRM is really about control. It's a technical trick that thanks to DMCA anti-reverse engineering clauses becomes a legal trick to dictate exactly who and how can play the content, much tighter than what copyright and consumer laws allow by default. For example, without DRM you couldn't effectively sell separate licenses for computer screens and TVs, because users could just connect…

What are you talking about? You can connect your computer to a TV just fine. No, lost sales are not 'just a convenient excuse', the sales they lose to piracy are far more numerous than the ones they'd gain with this fictional system that relies on people being willing to throw away money for no reason. 'It's about control' is a favorite element of conspiracy theories but corresponds to no real-world corporate need.
Post reply on HN