Live data from Hacker News

The GPU, not the TPM, is the root of hardware DRM

mjg59.dreamwidth.org

61–70 of 493 posts

Re: The GPU, not the TPM, is the root of hardware DRM

#61
post #20
post #12

Earlier quoted context omitted.

There's always an analog loophole. Even if the OS is unable to access the memory storing the decrypted data, you could always just plug the output of the machine into a capture card and capture the decrypted stream that way. I suppose some monitors and TVs have "features" to cryptographically handshake with the GPU and ensure a secure link, but at some point the data must be decrypted and decoded to be displayed. Thi…

The end goal is DRM all the way to the screen. No capture cards will be allowed. It's a cat and mouse game, but I wouldn't discount these efforts as a mere speed bump. Screen enforced DRM will make things much harder. A motivated individual with the right tools and hardware hacking know how may be able to jailbreak a screen to record stuff, but that's going to make things out of reach for most people.

It doesn't matter at all how out of reach it is for most people. As long as one kid in Russia can do it, the torrent is available for everyone in the world just as soon.

This has already been shown with videogame DRM like Denuvo. It's so hard to crack that only a handful of people know how, and yet they end up racing eachother so eagerly every time a new game comes out that it's usually done in under 24 hours. Unless you can beat "so secure that only a handful of people in the world can crack it" the situation will always be the same.

Re: The GPU, not the TPM, is the root of hardware DRM

#62

>The FSF's focus on TPMs here is not only technically wrong, it's indicative of a failure to understand what's actually happening in the industry. This sounds 100% on-brand for the FSF. The FSF's primary public-facing persona has peculiar computing habits so far removed from the mainstream that it's likely he has absolutely no clue how the real world works. In fact by his own statement he has to rely on volunteers to…

The FSF has turned into the crazy old aunt that insists you unplug the coffee pot after use in case it's bugged. It's taken me a long time to come around to the reality that they are holding Linux back at every juncture, probably still salty over the GNU/drama. Modern TPM support in Linux and systemD now permits automatic disk unlock for LUKS encrypted volumes using a key stored in the TPM - some ~15 years after Wind…

While I broadly agree, I think it’s worth pointing out that they have made some compromises for practicality, the inclusion of MP3 software before patents had expired comes to mind.

Re: The GPU, not the TPM, is the root of hardware DRM

#63
post #23
post #15

> GPU vendors have quietly deployed all of this technology Citation or technical details needed. Obviously it "makes sense" that for 4K HD content you "probably" want to offload the decoding into the GPU, but this is the first time I see this mentioned and there are no links to technical details. In contrast, TEE / TrustZone and even the recent AVF with pVM - these are well documented technologies.

The Playready docs make it clear the implementation is either in TEE or implemented in GPU hardware, and x86 has no TEE, so. You can easily find driver changelogs describing it being enabled for different hardware generations.

> x86 has no TEE

Is Intel ME TEE-enough for DRM?

Re: The GPU, not the TPM, is the root of hardware DRM

#64

I have to wonder A) What does DRM realistically accomplish for the media companies? And, B) How are these DRM schemes actually being defeated? I do occasionally don my pirate hat* and have never had an issue finding what I want at the quality I want within an hour of a episode/movie being released to streaming. That would seem to indicate that these efforts at DRM are actually failing to have any noticeable effect at…

They hate "losing" money more than they enjoy making it. It's worthwhile to mention that Hollywood was and still is a cartel system.

Re: The GPU, not the TPM, is the root of hardware DRM

#65
post #54
post #47

Earlier quoted context omitted.

Yeah, but pirate groups are getting the original streaming service's compression without re-encoding (so-called "WEB-DL"), even of 4k content. There's a weaker link somewhere.

WV L1 Keys/ PR SL 3000 keys require breaking into the TEE to steal those decryption keys. Ever wondered why netflix 4k web-dls take a while for less popular shows? Netfliy monitors these more tightly apparently and blacklist keys that are used to download. Then the group needs to buy some new device, the old one is burned.

It's true that known-compromised keys get revoked, but it's possible to avoid them knowing you've compromised a particular device.

Re: The GPU, not the TPM, is the root of hardware DRM

#66

I have to wonder A) What does DRM realistically accomplish for the media companies? And, B) How are these DRM schemes actually being defeated? I do occasionally don my pirate hat* and have never had an issue finding what I want at the quality I want within an hour of a episode/movie being released to streaming. That would seem to indicate that these efforts at DRM are actually failing to have any noticeable effect at…

> A) What does DRM realistically accomplish for the media companies? Control publishing rights, platforms, software and hardware that is used for the consumption of said media. The publishers control the DRM, which then needs to be licensed by television makers, software writers, and such things. Then that gives them control over how is it presented, how it is sold, how it is consumed and it forces everybody to agree…

> It is a power thing. They want to have power over other businesses. DRM laws help them do that.

This is the argument for repealing them, which is why you rarely see them making it out loud.

Instead they come up with some rubbish about making it marginally more difficult (spoiler: it's still easier to pirate stuff than use legal services and the only thing actually preventing everyone from doing it is that some people want to follow the law). So it's good to knock those fake arguments down when you see them and leave no excuse to keep the bad laws that ought to be repealed.

Accepting their actual motivation like it's a legitimate reason to keep those laws is like saying the reason we should keep doing the stuff Snowden revealed is so the intelligence agencies can spy on the elected officials regulating the intelligence agencies.

Re: The GPU, not the TPM, is the root of hardware DRM

#67

Earlier quoted context omitted.

With how good modern screens are, and how good cameras are (and how easy both are to hack), you could always play back the video and capture the photons through the air. There was something called Macrovision back in the VHS/DVD days that tried to defeat digital/analog conversion, and I'm sure visual techniques could be devised... But I imagine someone with a good OLED and a good mirrorless camera (or even a cell pho…

Especially when you add HDR to the mix, I think it's still extremely difficult to get a high quality screen recording, if only because it's so hard to get the exposure right.

Modern dedicated cameras have far more dynamic range than any HDR TV in practice. The movies have to be recorded somehow :)

Re: The GPU, not the TPM, is the root of hardware DRM

#68
post #14

There’s some technical details missing here. I get decrypting the video on a gpu makes it harder to screen capture, but can’t you just still emulate the GPU in software or directly capture the digital video output? The GPU still has no unique hardware private key, right?

Yes, you can get around it by playing the video in a virtual machine and capturing it from the host. For widevine videos playing in browser it is also as trivial as disabling hardware acceleration from the browser's settings.

But doesn't this limit you to 1080p?

Re: The GPU, not the TPM, is the root of hardware DRM

#69

Earlier quoted context omitted.

Microsoft doesn't sell hardware. Why would they be incentivized to make you buy new hardware? Unless you're alleging that their hardware partners pushed for it, in which case there would likely be logs of communications that are pretty illegal.

They don't sell hardware, but they get paid when their hardware partners sell you a new laptop with Windows on it.

Ok, so the theory is that Microsoft is after the revenue from Windows 11 licenses? And the way they're achieving this is by forcing people who want to upgrade from Windows 10 to buy a new machine rather than install Windows 11 on their existing machines? If that was the motivation, there's a far more direct option available. Just charge for the upgrade.

For this theory to work, it would have to be that there's a significant population that a) wants to run Windows 11 instead of Windows 10; b) will buy a new computer to do that; c) would not pay the price of an OEM license for a version upgrade.

Re: The GPU, not the TPM, is the root of hardware DRM

#70
post #18
post #14

There’s some technical details missing here. I get decrypting the video on a gpu makes it harder to screen capture, but can’t you just still emulate the GPU in software or directly capture the digital video output? The GPU still has no unique hardware private key, right?

Capturing the digital video output is supposed to be prevented by HDCP encrypting the signal, but in practice that's pretty well broken. That is a (slowly) moving target though, each time they roll out a new HDMI version (e.g. for 4K) they get to enforce a new version of HDCP which needs to be broken all over again. I don't think the version of HDCP attached to HDMI 2.1 has been broken yet but that's kind of a moot p…

It's hilarious to imagine the meeting where they finally convinced themselves they could put worthwhile lasting encryption in consumer devices with a 10 year+ installation lifetime.

What a complete and total waste of effort.

Post reply on HN