Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

411–420 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#411
post #371

Earlier quoted context omitted.

This is an FSF level understanding. Android devices are fully open and you can reflash them to whatever OS you want. Some remote servers won't give you service if you do that, but nothing is locking you out of your device . As Android dominates the global market, you already live in that world where most devices are open.

While I don't agree with the FSF on even close to everything regarding trusted computing, I think for a fair discussion you'd have to at least steelman their arguments here: I think it's fair to assume that in a world in which almost every device supports attestation and makes it available to any service provider by default, without giving users an informed choice to say no or even informing them at all , service pro…

The ideal amount of attestation on a general purpose computer which is owned by me is zero. Any nonzero amount implies that control of the device has not actually been turned over to me. It implies not only the slippery slope to which you refer but also things about back doors and opportunity for dystopian political regimes and much more.

When it comes to financial or legal matters (and this includes online banking) a small dedicated hardware element for signing fingerprints is all that's ever been required. Anything more is an overreach.

Re: The GPU, not the TPM, is the root of hardware DRM

#412

Earlier quoted context omitted.

> the future for personal computing is looking grim I don't know. They could lock up the hardware stack as much as they want, in the end it's pixels being pushed to arrays. It's extremely hard to prevent these pixels from being intercepted. You'll have pirate groups just going deep in the hardware (opening the monitors and soldering and hacking and whatnots) and eventually tap these. As for personal usage: I've got h…

We're not concerned about DRM because it will (or won't) stop us from redistributing and playing content. The stated goal of DRM (blocking copyright infringement), and DRM's general failure to meet that goal, is the least interesting part of the story. We're concerned about DRM because what it does accomplish. DRM creates a vertically-integrated market wherein every layer of the stack is authoritatively controlled by…

> I can mix the audio so that dialogue is actually audible.

How are you doing that?

Re: The GPU, not the TPM, is the root of hardware DRM

#413
post #371

Earlier quoted context omitted.

While I don't agree with the FSF on even close to everything regarding trusted computing, I think for a fair discussion you'd have to at least steelman their arguments here: I think it's fair to assume that in a world in which almost every device supports attestation and makes it available to any service provider by default, without giving users an informed choice to say no or even informing them at all , service pro…

The ideal amount of attestation on a general purpose computer which is owned by me is zero. Any nonzero amount implies that control of the device has not actually been turned over to me. It implies not only the slippery slope to which you refer but also things about back doors and opportunity for dystopian political regimes and much more. When it comes to financial or legal matters (and this includes online banking)…

> back doors and opportunity for dystopian political regimes

No, this is a misunderstanding of what a TPM is.

A TPM is a secure element inside your computer, similar to the chip running your credit and debit card. That's it. Without you using it (i.e. your OS or an application you installed asking it to do something), it's exactly as dangerous as a blank chip card in your house that you don't use and didn't open any account for.

If you don't want anybody to talk to it, don't install applications or OSes on your computer that do things you don't want. You have full control over that! Not running software that's not acting in your own best interests is generally good practice anyway, TPM or no TPM.

> [...] a small dedicated hardware element for signing fingerprints is all that's ever been required [...]

You might be happy to hear that that's exactly what a TPM is, then!

Re: The GPU, not the TPM, is the root of hardware DRM

#414
post #407

Earlier quoted context omitted.

>Some remote servers won't give you service if you do that This is exactly my problem. Before ideas like this surfaced, the demarcation line between who controls what was purely based on ownership. The machine that I own acts only on my behalf and in my best interests, the server that you own does so for you (or atleast for PCs this has always been the case) TPMs, attested bootchains and whatnot trample on this whole…

Fully agreed on attested bootchains. General-purpose level OS-wide attestation is indeed a blight on open computing: It's ineffective because it implies a gigantic trusted code base (what are the odds that the entire Windows kernel is completely free of vulnerabilities?), and conversely it does tie you to somebody else's more or less arbitrary kernel build. Almost complete disagree on TPMs. A better comparison than a…

By that same logic evil is not inherent to attested bootchains either. When used to verify that the computer loaded the OS that the end user expected it is a very powerful security tool. It is only bad when the keys aren't under the control of the device owner.

Re: The GPU, not the TPM, is the root of hardware DRM

#415
post #32

I have to wonder A) What does DRM realistically accomplish for the media companies? And, B) How are these DRM schemes actually being defeated? I do occasionally don my pirate hat* and have never had an issue finding what I want at the quality I want within an hour of a episode/movie being released to streaming. That would seem to indicate that these efforts at DRM are actually failing to have any noticeable effect at…

The sort of person who can set up -arr daemons isn't going to really be on the radar of anyone pushing DRM. Those skills are so rare people will pay for them. The point is that there is a huge market of people who barely know what an internet is but want to watch media. As long as they can't figure out how to get pirated content up and running quickly then DRM is doing its job. Pirated content represents a relatively…

> Those skills are so rare people will pay for them.

People will pay you to move dirt from one side of a lot to the other side.

Re: The GPU, not the TPM, is the root of hardware DRM

#416
post #407

Earlier quoted context omitted.

Fully agreed on attested bootchains. General-purpose level OS-wide attestation is indeed a blight on open computing: It's ineffective because it implies a gigantic trusted code base (what are the odds that the entire Windows kernel is completely free of vulnerabilities?), and conversely it does tie you to somebody else's more or less arbitrary kernel build. Almost complete disagree on TPMs. A better comparison than a…

By that same logic evil is not inherent to attested bootchains either. When used to verify that the computer loaded the OS that the end user expected it is a very powerful security tool. It is only bad when the keys aren't under the control of the device owner.

You're mixing up the authentication and attestation parts of secure boot here.

You can absolutely install Linux, run secure boot (e.g. to protect you against "evil maid attack"), use your TPM to store your SSH keys, and live a happy and attestation-free life.

You can also do other things, but if you don't want to, why would you?

Re: The GPU, not the TPM, is the root of hardware DRM

#417
post #413

Earlier quoted context omitted.

The ideal amount of attestation on a general purpose computer which is owned by me is zero. Any nonzero amount implies that control of the device has not actually been turned over to me. It implies not only the slippery slope to which you refer but also things about back doors and opportunity for dystopian political regimes and much more. When it comes to financial or legal matters (and this includes online banking)…

> back doors and opportunity for dystopian political regimes No, this is a misunderstanding of what a TPM is. A TPM is a secure element inside your computer, similar to the chip running your credit and debit card. That's it. Without you using it (i.e. your OS or an application you installed asking it to do something), it's exactly as dangerous as a blank chip card in your house that you don't use and didn't open any…

I am fully aware of what a TPM is. I was speaking about trusted computing - ie the "general purpose attestation capability" that you referred to above.

As you say, a TPM alone can't do much of anything and doesn't pose much of a threat. Of course expanding the acronym - Trusted Platform Module - is a bit of a giveaway. They were always fully intended to serve as the root of trust for much more nefarious things.

Re: The GPU, not the TPM, is the root of hardware DRM

#418
post #404

Earlier quoted context omitted.

One way I might handle this would be to have a TPM on the GPU itself. Then you can move the GPU about all you like, and it will work. The GPU would have to implement an API and protocol that allows the DRM site to do attestation via software running on the CPU, but that seems doable. The other way would be accept that the GPU that the content is to be played on might not be the same as the device on which the TPM exi…

Why do any of this rather than just have the GPU prove its identity to the streaming platform? You're adding a lot of complexity for no obvious gain.

Well of course. My comment was about how TPMs could be used but how still you were correct that TPMs aren't the FSF's enemy. I was exploring that space to further show that.

Re: The GPU, not the TPM, is the root of hardware DRM

#419
post #371

Earlier quoted context omitted.

While I don't agree with the FSF on even close to everything regarding trusted computing, I think for a fair discussion you'd have to at least steelman their arguments here: I think it's fair to assume that in a world in which almost every device supports attestation and makes it available to any service provider by default, without giving users an informed choice to say no or even informing them at all , service pro…

The ideal amount of attestation on a general purpose computer which is owned by me is zero. Any nonzero amount implies that control of the device has not actually been turned over to me. It implies not only the slippery slope to which you refer but also things about back doors and opportunity for dystopian political regimes and much more. When it comes to financial or legal matters (and this includes online banking)…

You think there's no value in your laptop being able to attest its state to your phone in order to give you confidence it hasn't been tampered with? That's something that would be entirely under your control.

Re: The GPU, not the TPM, is the root of hardware DRM

#420
post #413

Earlier quoted context omitted.

> back doors and opportunity for dystopian political regimes No, this is a misunderstanding of what a TPM is. A TPM is a secure element inside your computer, similar to the chip running your credit and debit card. That's it. Without you using it (i.e. your OS or an application you installed asking it to do something), it's exactly as dangerous as a blank chip card in your house that you don't use and didn't open any…

I am fully aware of what a TPM is. I was speaking about trusted computing - ie the "general purpose attestation capability" that you referred to above. As you say, a TPM alone can't do much of anything and doesn't pose much of a threat. Of course expanding the acronym - Trusted Platform Module - is a bit of a giveaway. They were always fully intended to serve as the root of trust for much more nefarious things.

People keep saying that, yet the only thing I’ve ever seen TPMs used for is full disk encryption and user authentication.

Conversely, DRM is alive and well on almost universally TPM-less devices.

By the way, all of your comments in this thread end up dead – I had to vouch for them to be able to answer. Not sure what’s up with that.

Post reply on HN