The author is correct in that media DRM is tied to GPU vendors on the field right now. But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Enviro…
I have trouble understanding your use of the term DRM. Media DRM makes sense: the copyright holders want to "manage" their rights digitally. How is that relevant to Play Integrity or WEI? Whose right is being protected or managed? If I have an Android without Play Integrity there are certain apps that will not run, but I don't see any rights being managed here: an app developer has the right to refuse service just li…
The GPU, not the TPM, is the root of hardware DRM
381–390 of 493 posts
Re: The GPU, not the TPM, is the root of hardware DRM
#382Earlier quoted context omitted.
I'm embarrassed to admit that I don't actually understand what a TPM does. My vague and probably incorrect impression is that it performs some sort of encrypted verification of firmware or hardware modules? Can anyone expand on what this does? My impression would be that this is not useful for most users, and would be much of a concern in industrial espionage situations. I have no confidence that I'm correct here.
It’s just a little cpu and some nonvolatile memory running a program. You can send it messages, and it will send back replies, but you cannot control which program is running on it. Of course this is vague enough that it could implement almost anything you want. What makes it a TPM is the protocol it answers to. The TPM has a hardware RNG, and you can just ask it for some random numbers. That’s very simple. You can h…
Re: The GPU, not the TPM, is the root of hardware DRM
#383Earlier quoted context omitted.
This is an FSF level understanding. Android devices are fully open and you can reflash them to whatever OS you want. Some remote servers won't give you service if you do that, but nothing is locking you out of your device . As Android dominates the global market, you already live in that world where most devices are open.
>Some remote servers won't give you service if you do that This is exactly my problem. Before ideas like this surfaced, the demarcation line between who controls what was purely based on ownership. The machine that I own acts only on my behalf and in my best interests, the server that you own does so for you (or atleast for PCs this has always been the case) TPMs, attested bootchains and whatnot trample on this whole…
Attestation is just a tool. It can be used for all kinds of things and doesn't privilege one side or another. The average app developer doesn't truly care what device you use, they just want to cut out abuse and fraud, which are real problems that do require effective solutions.
Ultimately, trade requires some certainty that both sides will act as they promise to act. Attestation is more important for individuals attesting to companies because individuals have so many more ways to hold companies to account if they break their agreements than technology, like the legal system, which is largely ineffective at enforcing rules against individuals due to cost.
Re: The GPU, not the TPM, is the root of hardware DRM
#384Earlier quoted context omitted.
Ultimately, DRM is untenable without users also being locked out of their own devices. Consequently pressure to support more effective DRM will always translate into pressure to restrict what users can do with their devices. Furthermore, the only defense against this is large open device market share: once closed devices comprise most of the market, DRM proponents can announce they'll stop supporting open devices, cr…
This is an FSF level understanding. Android devices are fully open and you can reflash them to whatever OS you want. Some remote servers won't give you service if you do that, but nothing is locking you out of your device . As Android dominates the global market, you already live in that world where most devices are open.
It doesn't matter. Those devices fail hardware remote attestation.
> Some remote servers won't give you service if you do that, but nothing is locking you out of your device.
The device's purpose is to be used. If it can't be used without giving up things like banks and private communications, it won't be used.
Device is not locked, it just turns into a paperweight if you actually unlock it.
> As Android dominates the global market, you already live in that world where most devices are open.
Wanna know what else dominates the global market? WhatsApp. In many regions of the world, without their services, you are ostracized.
Re: The GPU, not the TPM, is the root of hardware DRM
#385Earlier quoted context omitted.
This is an FSF level understanding. Android devices are fully open and you can reflash them to whatever OS you want. Some remote servers won't give you service if you do that, but nothing is locking you out of your device . As Android dominates the global market, you already live in that world where most devices are open.
>Some remote servers won't give you service if you do that This is exactly my problem. Before ideas like this surfaced, the demarcation line between who controls what was purely based on ownership. The machine that I own acts only on my behalf and in my best interests, the server that you own does so for you (or atleast for PCs this has always been the case) TPMs, attested bootchains and whatnot trample on this whole…
It's not just you.
It disgusts me so deeply I wish computers had never been invented. A wonderful technology with infinite potential, capable of reshaping the world. Reduced to this sorry state just to protect vested interests. They used to empower us. Now they are the tools of our oppression.
Re: The GPU, not the TPM, is the root of hardware DRM
#386Re: The GPU, not the TPM, is the root of hardware DRM
#387Doesn't the article forgot to mention that TPM allow to do trusted boot and remote attestation ? It sounds like to me that could very well be used to make software DRM more efficient (by making sure you run a DRM friendly OS for example)
But so does a USB-connected security dongle. Does that make USB "complicit in enforcing DRM"? TPMs are really just embedded Yubikeys. Unless your UEFI/BIOS "conspire" to supply them with boot measurements, and your OS in turn conspires with that to carry these measurements forward and provide them at the application layer, TPMs can't harm your freedom. TPMs are a much more "freedom neutral" technology than people gen…
Re: The GPU, not the TPM, is the root of hardware DRM
#388Earlier quoted context omitted.
It's hilarious to imagine the meeting where they finally convinced themselves they could put worthwhile lasting encryption in consumer devices with a 10 year+ installation lifetime. What a complete and total waste of effort.
I suspect bad encryption still does exactly what they intend, because it means there is no simple one click solution built into an OS or browser to download streaming media for later watching or sharing with friends. For example, a lot of regular modern OSs have the ability to rip and share an unencrypted audio CD in a simple intuitive way with no shady pirate software to install. It's a legal hurdle, not a technical…
[1] https://torrentfreak.com/could-piracy-help-netflix-win-the-s... [2] https://www.indy100.com/celebrities/sydney-sweeney-pirating-... [3] https://arstechnica.com/gadgets/2024/10/nfl-player-illegally...
Re: The GPU, not the TPM, is the root of hardware DRM
#389>The FSF's focus on TPMs here is not only technically wrong, it's indicative of a failure to understand what's actually happening in the industry. This sounds 100% on-brand for the FSF. The FSF's primary public-facing persona has peculiar computing habits so far removed from the mainstream that it's likely he has absolutely no clue how the real world works. In fact by his own statement he has to rely on volunteers to…
I mean, open source advocacy already includes both business-friendly convenience-focused pragmatists and social-friendly, principled advocates of digital freedom who were essentially turned off by RMS's personality and/or approach.
Taken together, their work seems like it sets a reasonable ceiling on what FSF-- or any freedom-based organization-- could achieve.
If I'm wrong I'd like to know what exactly the FSF could have achieved in your opinion that's above that ceiling, as well as the tactics they'd have use to get there.
Re: The GPU, not the TPM, is the root of hardware DRM
#390The embedded politics of the “t” in “tpm” and “tee” are super interesting and revealing. They are “trusted” only from the perspective of the developer; to the user, they represent the complete lack of trust.