Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

371–380 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#371
post #275

Earlier quoted context omitted.

Ultimately, DRM is untenable without users also being locked out of their own devices. Consequently pressure to support more effective DRM will always translate into pressure to restrict what users can do with their devices. Furthermore, the only defense against this is large open device market share: once closed devices comprise most of the market, DRM proponents can announce they'll stop supporting open devices, cr…

This is an FSF level understanding. Android devices are fully open and you can reflash them to whatever OS you want. Some remote servers won't give you service if you do that, but nothing is locking you out of your device . As Android dominates the global market, you already live in that world where most devices are open.

While I don't agree with the FSF on even close to everything regarding trusted computing, I think for a fair discussion you'd have to at least steelman their arguments here:

I think it's fair to assume that in a world in which almost every device supports attestation and makes it available to any service provider by default, without giving users an informed choice to say no or even informing them at all, service providers are much more likely to provide access exclusively to attestation-capable clients.

That, in turn, has obvious negative consequences for users with devices not supporting attestation (whether out of ideological choice, because it's a low cost device and the manufacturer can't afford the required audits and security guarantees etc.): Sure, these users will always be able to just refuse to transact with any service provider requiring attestation.

But think that through: We're not only talking about Netflix here. At what availability rates of attestation will decision makers at financial institutions decide that x% is good enough and exclude everybody else from online banking? What about e-signing contracts for doing business online? What about e-government services?

I am at the same time excited about the new possibilities attestation offers to users (in that they will be able to do things digitally that just weren't economically feasible for service providers, since they often have to cover the risks of doing so) as I am very wary of the negative externalities of a world in which attestation is just a bit too easy and ubiquitous.

In other words, the ideal amount of general purpose attestation availability is probably high, but significantly below 100% (or, put differently, the ideal amount of friction is non-zero). Heterogeneity of attestation providers can probably help a bit, but I'm wary of the inherent centralizing forces due to the technical and economical pragmatics of trusted computing.

Re: The GPU, not the TPM, is the root of hardware DRM

#372

Earlier quoted context omitted.

> the future for personal computing is looking grim I don't know. They could lock up the hardware stack as much as they want, in the end it's pixels being pushed to arrays. It's extremely hard to prevent these pixels from being intercepted. You'll have pirate groups just going deep in the hardware (opening the monitors and soldering and hacking and whatnots) and eventually tap these. As for personal usage: I've got h…

I'm not so optimistic. Yes, you can never "plug the analog hole" completely, but you can definitely lock stuff down to the point it's impractical for 95% of people. For instance, imagine some sort of audio / video fingerprint system that resides in Intel and/or nVidia's GPU drivers. Content gets played through the on-GPU HEVC / h.264 decoders already. Doesn't seem like a huge stretch to add a fingerprint authenticati…

I was thinking of someone hacking a capture device that sniffs the output matrix of a display in order to capture the video and has a line-in plugged into the drivers on the speaker. Way out of reach of most people, but only a very small number of people need to be have the wherewithal to do it to keep the pirate scene going, especially if they live in countries that don't care about your DRM laws. The analog hole exists so long as people don't have DRM directly implanted into their eyeballs.

Re: The GPU, not the TPM, is the root of hardware DRM

#373
DRM is a government sanctioned desecration, by corporations, of your private property rights, by its very definition.

Whether it’s in the GPU, CPU, TPM, or any other part of computing property you ostensibly own, is an utterly irrelevant distraction, the root is the unholy alliance of government and capital power.

Re: The GPU, not the TPM, is the root of hardware DRM

#374
post #316

Earlier quoted context omitted.

At least for HDCP, that's exactly how it works. From the HDCP 2.2 spec [1]: > Device Key Set. An HDCP Receiver has a Device Key Set, which consists of its corresponding Device Secret Keys along with the associated Public Key Certificate. > Public Key Certificate. Each HDCP Receiver is issued a Public Key Certificate signed by DCP LLC, and contains the Receiver ID and RSA public key corresponding to the HDCP Receiver.…

Thanks, that clarifies my confusion about how this could be realistically implemented. I couldn't see a practical way to verify every device on every connection via a central authority without massive scaling and reliability issues, but maintaining a small revocation list that can be cached everywhere media is distributed from seems quite practical.

FWIW, efficient revocation has been solved since the Bluray era using AACS subset difference trees.

Re: The GPU, not the TPM, is the root of hardware DRM

#375

Earlier quoted context omitted.

DRM has likely had a big impact in shifting the casual consumer conversation to "hey they're gonna start down on account sharing" from early-2000s style "here's a straight-up copy I made for you." And this helps prop up the "they'll get a Netflix account to binge the same three shows over and over" part of the business model. The cumulative monthly cost adds up but it feels cheaper than forking over a few hundred buc…

In many cases, downloading torrents and watching on a laptop/PC has a better UX than using streaming services. For example, it's impossible to watch 4k content on popular streaming services if you use Linux, and even with macOS/Windows you need a specific combination of hardware + OS + browser, if a service even offers it.

It has much better UX, but much worse accessibility.

You have to learn how to navigate an ever-dwindling list of trackers and probably a VPN, which is already too tall a hurdle for the overwhelming majority of people. Time is often worth the price of a 4K Roku and a subscription, even though that's still a technically inferior experience at the end of the day.

Piracy has two very hard problems: privacy and moderation. Moderation requires authority; authority requires trust; and trust relies on identification. I think we might be able to resolve this by replacing moderation with curation, but that's going to take a lot of ground-work that I'm too ADHD to do myself.

Re: The GPU, not the TPM, is the root of hardware DRM

#376

DRM is a government sanctioned desecration, by corporations, of your private property rights, by its very definition. Whether it’s in the GPU, CPU, TPM, or any other part of computing property you ostensibly own, is an utterly irrelevant distraction, the root is the unholy alliance of government and capital power.

No, if anything, the fact that governments allow businesses to only "license" you digital content, i.e. not give you the option to actually acquire property rights in it, is. DRM is just a technical implementation detail downstream of that.

Re: The GPU, not the TPM, is the root of hardware DRM

#377
post #275

Earlier quoted context omitted.

Ultimately, DRM is untenable without users also being locked out of their own devices. Consequently pressure to support more effective DRM will always translate into pressure to restrict what users can do with their devices. Furthermore, the only defense against this is large open device market share: once closed devices comprise most of the market, DRM proponents can announce they'll stop supporting open devices, cr…

This is an FSF level understanding. Android devices are fully open and you can reflash them to whatever OS you want. Some remote servers won't give you service if you do that, but nothing is locking you out of your device . As Android dominates the global market, you already live in that world where most devices are open.

>Some remote servers won't give you service if you do that

This is exactly my problem. Before ideas like this surfaced, the demarcation line between who controls what was purely based on ownership. The machine that I own acts only on my behalf and in my best interests, the server that you own does so for you (or atleast for PCs this has always been the case)

TPMs, attested bootchains and whatnot trample on this whole concept. It's like your very own hardware now comes with a built in Stasi agent that reports on your conduct whether you like it or not. It bothers me on a visceral level and I'm constantly wondering if it's just me.

Re: The GPU, not the TPM, is the root of hardware DRM

#378
post #350

Doesn't the article forgot to mention that TPM allow to do trusted boot and remote attestation ? It sounds like to me that could very well be used to make software DRM more efficient (by making sure you run a DRM friendly OS for example)

But so does a USB-connected security dongle. Does that make USB "complicit in enforcing DRM"?

TPMs are really just embedded Yubikeys. Unless your UEFI/BIOS "conspire" to supply them with boot measurements, and your OS in turn conspires with that to carry these measurements forward and provide them at the application layer, TPMs can't harm your freedom.

TPMs are a much more "freedom neutral" technology than people generally assume in these discussions.

Re: The GPU, not the TPM, is the root of hardware DRM

#379

The author is correct in that media DRM is tied to GPU vendors on the field right now. But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Enviro…

It's downright cyberpunk.

> sites could refuse to serve you if your machine is running any bigcorp unapproved software

This needs to be classified as discrimination.

Re: The GPU, not the TPM, is the root of hardware DRM

#380

The author is correct in that media DRM is tied to GPU vendors on the field right now. But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Enviro…

> The author is correct in that media DRM is tied to GPU vendors on the field right now ... hardware backed DRM can be so much more invasive I expect mjg59 to know what they're talking about but like you say, I wonder the same thing about the strength of (what you call) Media DRM v Hardware-backed DRM. GPU vendors have quietly deployed [hardware-based DRM] ... [which] works just fine on [boards] that [don't] have a T…

The GPU is a completely separate computer running proprietary software. "Operating systems" do not operate anything anymore. They are just some user app, to be sandboxed very far away from the real action.

https://youtu.be/36myc8wQhLo

Stallman warned everyone. Virtually nobody listened.

Post reply on HN