Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

381–390 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#381
post #227

The author is correct in that media DRM is tied to GPU vendors on the field right now. But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Enviro…

I have trouble understanding your use of the term DRM. Media DRM makes sense: the copyright holders want to "manage" their rights digitally. How is that relevant to Play Integrity or WEI? Whose right is being protected or managed? If I have an Android without Play Integrity there are certain apps that will not run, but I don't see any rights being managed here: an app developer has the right to refuse service just li…

It's not about "rights". It's about power. It's about turning you into a serf in their digital fiefdom. A perpetual consumer.

Re: The GPU, not the TPM, is the root of hardware DRM

#382
post #226

Earlier quoted context omitted.

I'm embarrassed to admit that I don't actually understand what a TPM does. My vague and probably incorrect impression is that it performs some sort of encrypted verification of firmware or hardware modules? Can anyone expand on what this does? My impression would be that this is not useful for most users, and would be much of a concern in industrial espionage situations. I have no confidence that I'm correct here.

It’s just a little cpu and some nonvolatile memory running a program. You can send it messages, and it will send back replies, but you cannot control which program is running on it. Of course this is vague enough that it could implement almost anything you want. What makes it a TPM is the protocol it answers to. The TPM has a hardware RNG, and you can just ask it for some random numbers. That’s very simple. You can h…

This was a really useful explanation, thank you.

Re: The GPU, not the TPM, is the root of hardware DRM

#383

Earlier quoted context omitted.

This is an FSF level understanding. Android devices are fully open and you can reflash them to whatever OS you want. Some remote servers won't give you service if you do that, but nothing is locking you out of your device . As Android dominates the global market, you already live in that world where most devices are open.

>Some remote servers won't give you service if you do that This is exactly my problem. Before ideas like this surfaced, the demarcation line between who controls what was purely based on ownership. The machine that I own acts only on my behalf and in my best interests, the server that you own does so for you (or atleast for PCs this has always been the case) TPMs, attested bootchains and whatnot trample on this whole…

It's not just you but what people who hate remote attestation tend to forget is that it's a sword that cuts in both directions. Servers can remotely attest to you, not just the other way around. Signal is an example of an app that demands a remote attestation from the server before uploading your sensitive data.

Attestation is just a tool. It can be used for all kinds of things and doesn't privilege one side or another. The average app developer doesn't truly care what device you use, they just want to cut out abuse and fraud, which are real problems that do require effective solutions.

Ultimately, trade requires some certainty that both sides will act as they promise to act. Attestation is more important for individuals attesting to companies because individuals have so many more ways to hold companies to account if they break their agreements than technology, like the legal system, which is largely ineffective at enforcing rules against individuals due to cost.

Re: The GPU, not the TPM, is the root of hardware DRM

#384
post #275

Earlier quoted context omitted.

Ultimately, DRM is untenable without users also being locked out of their own devices. Consequently pressure to support more effective DRM will always translate into pressure to restrict what users can do with their devices. Furthermore, the only defense against this is large open device market share: once closed devices comprise most of the market, DRM proponents can announce they'll stop supporting open devices, cr…

This is an FSF level understanding. Android devices are fully open and you can reflash them to whatever OS you want. Some remote servers won't give you service if you do that, but nothing is locking you out of your device . As Android dominates the global market, you already live in that world where most devices are open.

> Android devices are fully open and you can reflash them to whatever OS you want.

It doesn't matter. Those devices fail hardware remote attestation.

> Some remote servers won't give you service if you do that, but nothing is locking you out of your device.

The device's purpose is to be used. If it can't be used without giving up things like banks and private communications, it won't be used.

Device is not locked, it just turns into a paperweight if you actually unlock it.

> As Android dominates the global market, you already live in that world where most devices are open.

Wanna know what else dominates the global market? WhatsApp. In many regions of the world, without their services, you are ostracized.

Re: The GPU, not the TPM, is the root of hardware DRM

#385

Earlier quoted context omitted.

This is an FSF level understanding. Android devices are fully open and you can reflash them to whatever OS you want. Some remote servers won't give you service if you do that, but nothing is locking you out of your device . As Android dominates the global market, you already live in that world where most devices are open.

>Some remote servers won't give you service if you do that This is exactly my problem. Before ideas like this surfaced, the demarcation line between who controls what was purely based on ownership. The machine that I own acts only on my behalf and in my best interests, the server that you own does so for you (or atleast for PCs this has always been the case) TPMs, attested bootchains and whatnot trample on this whole…

> It bothers me on a visceral level and I'm constantly wondering if it's just me.

It's not just you.

It disgusts me so deeply I wish computers had never been invented. A wonderful technology with infinite potential, capable of reshaping the world. Reduced to this sorry state just to protect vested interests. They used to empower us. Now they are the tools of our oppression.

Re: The GPU, not the TPM, is the root of hardware DRM

#387
post #378
post #350

Doesn't the article forgot to mention that TPM allow to do trusted boot and remote attestation ? It sounds like to me that could very well be used to make software DRM more efficient (by making sure you run a DRM friendly OS for example)

But so does a USB-connected security dongle. Does that make USB "complicit in enforcing DRM"? TPMs are really just embedded Yubikeys. Unless your UEFI/BIOS "conspire" to supply them with boot measurements, and your OS in turn conspires with that to carry these measurements forward and provide them at the application layer, TPMs can't harm your freedom. TPMs are a much more "freedom neutral" technology than people gen…

The TPMs are already provided with boot and OS measurements for secure boot purpose which would allow DRM to confirm you use an approved OS kernel, so I guess the computer is already conspiring. And the conspiracy could be enforced by videos distributors in exchange for the privilege of having HD content.

Re: The GPU, not the TPM, is the root of hardware DRM

#388
post #285

Earlier quoted context omitted.

It's hilarious to imagine the meeting where they finally convinced themselves they could put worthwhile lasting encryption in consumer devices with a 10 year+ installation lifetime. What a complete and total waste of effort.

I suspect bad encryption still does exactly what they intend, because it means there is no simple one click solution built into an OS or browser to download streaming media for later watching or sharing with friends. For example, a lot of regular modern OSs have the ability to rip and share an unencrypted audio CD in a simple intuitive way with no shady pirate software to install. It's a legal hurdle, not a technical…

Torrenting hasn't been the most popular form of piracy for a while: many subscribe to a couple streaming services and use pirate streaming sites to fill in the gaps [1]. This is so prevalent that even entertainment industry talent use pirate sites for both series [2] and sports [3]. Takedowns mean that sites change from year to year but FMHY-style curation makes casual piracy easy: one can always find a site with 1080p content (unsure about the bitrate though) and great UX.

[1] https://torrentfreak.com/could-piracy-help-netflix-win-the-s... [2] https://www.indy100.com/celebrities/sydney-sweeney-pirating-... [3] https://arstechnica.com/gadgets/2024/10/nfl-player-illegally...

Re: The GPU, not the TPM, is the root of hardware DRM

#389

>The FSF's focus on TPMs here is not only technically wrong, it's indicative of a failure to understand what's actually happening in the industry. This sounds 100% on-brand for the FSF. The FSF's primary public-facing persona has peculiar computing habits so far removed from the mainstream that it's likely he has absolutely no clue how the real world works. In fact by his own statement he has to rely on volunteers to…

> It's disappointing to me because the FSF could be so much more influential today

I mean, open source advocacy already includes both business-friendly convenience-focused pragmatists and social-friendly, principled advocates of digital freedom who were essentially turned off by RMS's personality and/or approach.

Taken together, their work seems like it sets a reasonable ceiling on what FSF-- or any freedom-based organization-- could achieve.

If I'm wrong I'd like to know what exactly the FSF could have achieved in your opinion that's above that ceiling, as well as the tactics they'd have use to get there.

Re: The GPU, not the TPM, is the root of hardware DRM

#390
post #386

The embedded politics of the “t” in “tpm” and “tee” are super interesting and revealing. They are “trusted” only from the perspective of the developer; to the user, they represent the complete lack of trust.

On the contrary, it gives me various ways to determine that my laptop is in a trustworthy state before I type a password into it, and it makes it possible for Signal to verify that the server it's communicating with hasn't been tampered with. It can be used in ways that hurt the user, but it can also be used in ways that benefit them.
Post reply on HN