13 ms·
The GPU, not the TPM, is the root of hardware DRM
- kittikitti 2y agoIf you go deep enough down the rabbit hole, it becomes very clear why a TPM is necessary.
- stackghost 2y ago>The FSF's focus on TPMs here is not only technically wrong, it's indicative of a failure to understand what's actually happening in the industry. This sounds 100% on-brand for the FSF. The FSF's primary public-facing persona has peculiar computing habits so far removed from the mainstream that it's likely he has absolutely no clue how the real world works. In fact by his own statement he has to rely on volunteers to update his website. It's disappointing to me because the FSF could be so much more influential today, but the cult of personality around RMS has really destroyed their public credibility among "normies", the most important demographic to convince. When the FSF finally realizes that a political organization such as theirs needs a public face with charisma and social skills, it will be too late.
- _yb2s 2y ago“Normies” are never going to care about the stuff the FSF is interested in. I don’t think you can extract the philosophy from the eccentric personalities that created it, they’re one in the same.
- stackghost 2y agoNormies are who you need to convince if you want to effect social change. If the FSF sticks to their current mission of preaching to the choir, they'll remain about as relevant as they are today, which isn't a lot.
- zb3 2y agoPeople in power and people with money are who you need to convince..
- stackghost 2y agoEating junk from your toenails on camera doesn't convince those people either.
- talldayo 2y agoNor has rational discussion, either.
- solarkraft 2y agoAnd how are they best convinced? Besides personal benefits like bribes, public opinion (re-election) and consumer habits (company profitability) seem to matter significantly. Please do add the options that I am forgetting.
- ignoramous 2y ago> public opinion (re-election) No matter who is re-elected, there's a preset window for law & policy, which perhaps only public outrage (and opportunist politicians) can shift. Outrage is a high bar (may be perhaps outside of Twitter).
- chii 2y agobut those in power, at least in the west, is somewhat subservient to the population as a whole (via voting - wallet or ballot).
- solarkraft 2y agoIf you believe that normies deserve computing freedom (this doesn’t seem to entirely be consensus in the scene), it ought to be a goal to explain the benefits of it in a way that they will understand. Some may still not care, but my experience is that a good part actually does. If nothing else this is good leverage to influence change for one‘s own interest.
- roenxi 2y agoThe benefits are incomprehensible to "normies" and they have no power to effect change. They're just going to use whatever software gets put in front of them. All the progress - which has been substantial, free software is basically everywhere and does everything - has come from highly motivated and technical individuals who are anything but normal. That follows a basic pattern for any effective change, normal people pretty much always just whinge and achieve nothing. They're lucky to even be allowed the pittance of political power that is voting, historically speaking.
- _yb2s 2y agoMost people just want to be able to access media easily with no effort- which they already can do with cheap streaming subscriptions. They have no interest in owning the rights to use it forever, or in downloading or copying it. They wouldn't want to take the time to figure out how to do that, even if they legally could when they can already just click and play. I think if you want people to care, you need to find a real world case where they are being blocked from doing something they really want to do- the abstract philosophical arguments about freedom are total non-starters. Possibly an alternative media supplier that was fundamentally less hassle, faster, and more reliable because it didn't have these systems could get people to switch. But good luck getting the digital rights owners to let you put their content on your platform. Or maybe convince people they can get higher quality media that way. I have a newish Mac with an amazing HDR screen, but few of the streaming sites are willing to stream the HDR content to my device.
- talldayo 2y agoI think that's a misunderstanding of what the FSF stands for overall, though. The FSF can never be a diplomatic negotiator for the benefit of free software; they are idealists, even when it serves against their own interests. Their whole shtick is not settling for half-baked appeasements, and so they're destined to be a pariah of the tech industry at-large. Neither you nor me can stop them, it's entirely within their right to advocate and for practice simpler software. The statement criticized by the OP certainly seems warranted, but it's less endemic of the FSF removing itself from the mainstream and more like the mainstream has abandoned free software. > The FSF's primary public-facing persona has peculiar computing habits You know, the FSF would probably argue that our computing habits are the peculiar one. And unless you can tell me about the code your iPhone runs in detail, they're probably (albeit begrudgingly) correct.
- stackghost 2y agoThere's no misunderstanding on my part; it's why I said that their ignorance is totally on-brand. >more like the mainstream has abandoned free software. Indeed, because free software development is largely driven by ideological purity rather than feature parity. Mainstream users see Free Software people as irrelevant kooks, and thus easy to dismiss, which is why Free Software has so utterly failed as a movement. >You know, the FSF would probably argue that our computing habits are the peculiar one. I'm sure flat-earthers feel that my belief that earth is an oblate spheroid is peculiar, too. Of what relevance is that to anyone? >And unless you can tell me about the code your iPhone runs in detail, they're probably (albeit begrudgingly) correct. We'll have to agree to disagree. The emacs developers don't even understand how large chunks of emacs work (per emacs-devel), for example. There's too much software out there for one person to keep in their head. This is not a reasonable heuristic.
- BlueTemplar 2y agoThe flat earthers are the people dismissing the concerns of the FSF though. (The Earth being round doesn't directly matter in practice to most people. It does have inevitable consequences though.) Or perhaps a better example is anthropogenic climate change : here too the implications are extremely inconvenient for most people, so denial is rampant.
- likeabatterycar 2y agoThe FSF has turned into the crazy old aunt that insists you unplug the coffee pot after use in case it's bugged. It's taken me a long time to come around to the reality that they are holding Linux back at every juncture, probably still salty over the GNU/drama. Modern TPM support in Linux and systemD now permits automatic disk unlock for LUKS encrypted volumes using a key stored in the TPM - some ~15 years after Windows could do it. I wonder what the TPM support is like in the HURD - ha! The only complaint I have about the TPM is there is no standardisation in connectors, pinout, or bus type when it's not soldered onto the board. I have three motherboards with plug-in TPMs and each required a different, unique part that was difficult to source.
- solarkraft 2y agoWhile I broadly agree, I think it’s worth pointing out that they have made some compromises for practicality, the inclusion of MP3 software before patents had expired comes to mind.
- devops99 2y agoWe have had "FDE" and secure boot with TPM in higher-than-commercial (defense) and the higher end of commercial settings for Linux, BSD, and illumos since TPM 1.2 was available, and I'd have to dig in some places to confirm but probably before Windows did in actual practice anywhere (let alone officially). Yeah, Debian/Ubuntu, Fedora, etc didn't have this, but as the saying goes: you get what you pay for. Although enough of the Gentoo users (the real Gentoo users) have such a thing had it around that time too, if they wanted it (and they tend to put together what they want). Some essential context: if you think the "Linux community" is elitist, wait until you see the niche commercial (and higher) players. I'm probably an example of such, to be fair.
- devops99 2y ago> there is no standardisation in connectors, pinout, or bus type when it's not soldered onto the board. I have three motherboards with plug-in TPMs and each required a different, unique part that was difficult to source. This should be prohibited by commercial law.
- WeylandYutani 2y agoNormal people watch Netflix on a smart TV. Or their phone. Hell the only reason why I turn on my computer these days is for videogames. I wonder if the decline of the desktop has someone worried at Microsoft.
- pjmlp 2y agoIt certainly has, and they have repented themselves of killing Windows Phone, turns out that when one wants to push stuff like AI and XBox ecosystem, having 10% market share is way better than not having none at all. Then again, they have been so busy with Azure and XBox profits, that Windows development has turned into a mess, of GUI teams fighting for resources, while the apps division couldn't care less, now filled with people that grown up using UNIX instead of Windows, and see Web UIs everywhere. Hence why Windows might be my main desktop, yet I eventually returned into Web/distributed computing world, disappointed with how UWP/WinRT development turned out.
- theandrewbailey 2y agoIt's been very clear to me for many years that the FSF is staffed by a bunch of out-of-touch boomers who believe that Microsoft is the end-all be-all of evil tech. That was probably true 30 years ago, but from their rhetoric, they've ignored how the computing landscape has changed. Namely, the ways smartphones are walled gardens that screw over people, often in the same ways Microsoft has. I've heard them mention in passing that Apple, Google, and Facebook are bad, but the volume of material directed at Microsoft overwhelms anything else. To the FSF, if it doesn't happen on a PC, its not a priority. It still amazes me that they're hurt over Linux stealing their GNU name/tools/momentum, but hardly a word is written about how Google stole Linux to make Android, and how the Android ecosystem is a complete betrayal of free software's values.
- jancsika 2y ago> It's disappointing to me because the FSF could be so much more influential today I mean, open source advocacy already includes both business-friendly convenience-focused pragmatists and social-friendly, principled advocates of digital freedom who were essentially turned off by RMS's personality and/or approach. Taken together, their work seems like it sets a reasonable ceiling on what FSF-- or any freedom-based organization-- could achieve. If I'm wrong I'd like to know what exactly the FSF could have achieved in your opinion that's above that ceiling, as well as the tactics they'd have use to get there.
- shmerl 2y agoDMCA 1201 should be reversed and DRM itself should be illegal.
- CamperBob2 2y agoDRM shouldn't be illegal, but works protected by DRM should be ineligible for copyright protection unless a key is placed in escrow somewhere. Basically, rightsholders should be be able to choose enforceable legal protection or unbreakable technological protection, but not both. Copyright was supposed to be a two-way street, but DRM permanently barricades one lane.
- shmerl 2y agoThat makes some sense, I'd say using DRM should void copyright completely, keys or not. I.e. if they want to go out of the way with invasive anti-user measures, they should lose any legal protection against copying of that stuff. It should also drive home the idea that DRM will be broken anyway and they'll be just left with nothing, so let them stick to copyright itself without all that DRM garbage.
- snvzz 2y ago>should be be able to choose enforceable legal protection or unbreakable technological protection No. The latter would effectively mean rightsholders make their own laws, rather than follow the law. DRM should simply be abolished, as it interferes with the premise of copyright: To grow the public domain.
- p0w3n3d 2y agoyeah, 105 years later we finally have a disney's a mickey mouse, but they still put the ears in every gadget to prolong it as a trademark. TBH I can see now how the conglomerates created by buying smaller studios by big fish start owning everything. They've divided the market by themselves, and now they are rising their prices. Meanwhile I cannot make a screenshot of my favourite cartoon to create a meme, because of "copy protection". But I have right to do it you now? It's written in law in my country (Poland) that I can have small pieces recorded down, screenshotted etc, as long as I am doing some creative work on it, or just keep it to myself. THIS IS THE LAW HERE. And it's being ignored.
- MadnessASAP 2y agoI have to wonder A) What does DRM realistically accomplish for the media companies? And, B) How are these DRM schemes actually being defeated? I do occasionally don my pirate hat* and have never had an issue finding what I want at the quality I want within an hour of a episode/movie being released to streaming. That would seem to indicate that these efforts at DRM are actually failing to have any noticeable effect at all. [*] Jellyfin & and the -arr daemons are far more usable and stable then wading through the various streaming services interfaces, so I'll download episodes even though I do actually pay for the streaming services.
- jsheard 2y ago> How are these DRM schemes actually being defeated? Stripping the more advanced forms of DRM usually relies on compromised device keys which can and will be revoked if it becomes known that they've leaked, so the details are deliberately kept very quiet. If you've ever experienced a device suddenly losing the ability to play 4K Netflix, it may have been because its keys were revoked.
- majormajor 2y agoDRM has likely had a big impact in shifting the casual consumer conversation to "hey they're gonna start down on account sharing" from early-2000s style "here's a straight-up copy I made for you." And this helps prop up the "they'll get a Netflix account to binge the same three shows over and over" part of the business model. The cumulative monthly cost adds up but it feels cheaper than forking over a few hundred bucks for a few box sets + buying a disc player. None of the hurdles stop 100% of people. But every hurdle causes some people to stop bothering.
- watermelon0 2y agoIn many cases, downloading torrents and watching on a laptop/PC has a better UX than using streaming services. For example, it's impossible to watch 4k content on popular streaming services if you use Linux, and even with macOS/Windows you need a specific combination of hardware + OS + browser, if a service even offers it.
- userbinator 2y ago[flagged]
- _yb2s 2y agoThere’s some technical details missing here. I get decrypting the video on a gpu makes it harder to screen capture, but can’t you just still emulate the GPU in software or directly capture the digital video output? The GPU still has no unique hardware private key, right?
- mjg59 2y agoThe details don't seem clear, and I don't know that there's necessarily a unique key rather than stuff being batched, but basically yeah there's a cert chain back to a "trusted" source
- elthjan 2y agohow does the decryption key get into the GPU? are GPU's currently shipping preprogrammed with keys used in DRM?
- jsheard 2y agoCapturing the digital video output is supposed to be prevented by HDCP encrypting the signal, but in practice that's pretty well broken. That is a (slowly) moving target though, each time they roll out a new HDMI version (e.g. for 4K) they get to enforce a new version of HDCP which needs to be broken all over again. I don't think the version of HDCP attached to HDMI 2.1 has been broken yet but that's kind of a moot point because no current video formats require more than HDMI 2.0.
- zb3 2y ago> GPU vendors have quietly deployed all of this technology Citation or technical details needed. Obviously it "makes sense" that for 4K HD content you "probably" want to offload the decoding into the GPU, but this is the first time I see this mentioned and there are no links to technical details. In contrast, TEE / TrustZone and even the recent AVF with pVM - these are well documented technologies.
- zb3 2y agoIntegrated GPUs exist. Wouldn't it make more sense that the "high value" content should not be exposed to any external GPU? Then we can treat those integrated ones as part of the "TEE". That's my speculation, waiting for details.
- saxonww 2y agoThis is the question I had about this. The reason this design works per the article is that the GPU memory is inaccessible to the OS, so the decrypted content cannot be stolen. With a unified memory architecture, is the shared GPU memory inaccessible to the CPU?
- mjg59 2y agoYes, the memory controller can simply deny accesses to specific areas from the CPU while still permitting them from the GPU.
- __m 2y agoThe GPU ultimately has to output unencrypted content, it will always be possible to steal unless we manage to implement drm in human eyes
- anticensor 2y agohuman brains actually
- tuetuopay 2y ago
- osy 2y ago> I'm going to be honest here and say that I don't know what Microsoft's actual motivation for requiring a TPM in Windows 11 is. It is quite obvious: to force people to buy a new PC. TPM provides no added security value for the vast majority of users[1] but it is a convenient hardware that has only started to become standard (fTPM) in PCs built in the last ~8 years so it provides an excuse for Microsoft to declare computers older than that (which can run Windows 10) obsolete using "security" as an easy scapegoat. [1]: https://gist.github.com/osy/45e612345376a65c56d0678834535166 https://gist.github.com/osy/45e612345376a65c56d0678834535166
- deleted 2y ago[deleted]
- santoshalper 2y agoIf you're going to run Windows 11 anyway, why would Microsoft care if you do it on a new or older PC?
- quikthrowaway 2y agoWindows 10 to Windows 11 upgrades are free. You know what's not free? The Windows license on a brand new computer if it's bundled with Windows. And here's a friendly reminder that the vast majority of users don't know how to build their own computer and install an operating system, even if it truly has been made extremely simple nowadays.
- z3phyr 2y agoMost of the people using Microsoft have OEM licence. When people buy new hardware, people are buying a new license of Windows as well.
- jasomill 2y agoCustomers are typically unhappy when Microsoft refuses to fix critical bugs that only arise when running Windows on older hardware. To the average user, "Windows installs without error and hardware appears to work" = "Microsoft supports running Windows on this hardware", even if the hardware is EOL and requires drivers that haven't been updated since Windows Vista.
- transpute 2y ago2008, Protected Audio/Video Path (PAVP), https://www.anandtech.com/show/2622/2 https://www.anandtech.com/show/2622/2 Movie studios wanted a way of securing the content between the time the AACS was decrypted and the HDCP encryption took over. Once the AACS was decrypted the encoded movie was sitting in main memory and could be intercepted by any other application.. The solution was to re-encrypt the data once it was pulled off the disc (I'm not kidding).. encryption would be done by the application.. The graphics driver would be able to pass along the encrypted data to the GPU, which would then decrypt and decode it in hardware and then the entire framebuffer would be HDCP encrypted by the GPU before sending it out over DVI/HDMI.
- deleted 2y ago[deleted]
- ChuckMcM 2y agoThis is a much more accurate statement than the hate on the TPM. As the article describes, it is the GPU that has its own separate memory space that it can show on the screen without the CPU being involved at all. I expect next generation workarounds will involve virtual GPUs.
- Retr0id 2y agoA virtual GPU is useless if it's not provisioned with the relevant key material.
- mike_hearn 2y agoIf that worked it'd have been done over a decade ago. The remote server is handshaking cryptographically with the GPU itself, which identifies itself using certificates and keys tied at the factory. You can't emulate such a GPU unless you find a way to steal the keys.
- ntqvm 2y agoThe author seems misinformed about the purpose of TPM to DRM schemes. The purpose of a TPM, in this case, is not to provide encryption, but instead to provide so-called ‘authenticity’. A TPM with its attestation capabilities can allow a remote validator to attest the operating system and system software you are running via the PCRs which are configured based on it, with Secure Boot preventing tampering. [1] Google tried to implement APIs to plug this into the Chrome browser, which was later abandoned after backlash. [2] In this case, the TPM can allow services like Netflix or Hulu to validate the hardware and software you are currently running, which provides the base for a hardware DRM implementation as stated in the article. Don’t be surprised if your non-standard OS isn’t allowed to play back content due to its remote validation failing if this is implemented. TPMs also have a unique, cryptographically verifiable identifier that is burnt into the chip and can be read from software. This allows for essentially a unique ID for each computer that is not able to be forged, as it is signed by the TPM manufacturer (in most cases Intel/AMD as TPMs on consumer hardware are usually emulated on the CPUs TEE). If you were around for the Pentium III serial controversy, this is a very similar issue. It's already used as the primary method of banning users on certain online video games, but I wouldn’t be surprised to see it expand to services requiring it to prove you aren’t a “bot” or similar if it gets wider adoption. There is a great article going more into detail about the implications of TPM to privacy from several years ago, which was the basis for this reply. [3] [1]: https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/iot-dps/concepts-tpm-attestation.md https://github.com/MicrosoftDocs/azure-docs/blob/main/articl... [2]: https://github.com/explainers-by-googlers/Web-Environment-Integrity/blob/main/explainer.md https://github.com/explainers-by-googlers/Web-Environment-In... [3]: https://secret.club/2021/06/28/windows11-tpms.html https://secret.club/2021/06/28/windows11-tpms.html
- wmf 2y agoI notice you said "can" and "if". Does DRM actually use the TPM or not?
- ntqvm 2y agoDepends on your definition. If you count video game anti-cheating software as DRM, the answer is yes. Apart from that, I’ve only currently seen TPMs used as a hardware identifier (in the same way a monitor serial is) for software licensing. The capability does exist however.
- MBCook 2y agoI fully get the DRM hate. Now I don’t really follow the Windows world but I thought the goal of the newer TPM stuff was to be able to provide a trusted boot chain the way Apple does. I’m under the impression that some of the earlier versions allowed the TPM module to be a separate piece of hardware from the CPU and thus exposed an hardware attack path where someone could snoop or man in the middle. If you have a full trusted chain you can certainly use that to ensure that the DRM isn’t being tampered with. But I kind of doubt that’s the main reason behind all of it. There are enough good reasons they may want better security on the hardware outside of that it seems justifiable that they might push it. I’m not arguing it’s good or bad, I just don’t think it’s 100% about DRM and the rest is a smoke screen.
- yakaccount4 2y agoDeploying some sort of TPM remote attestation for DRM requires every component from every vendor to play nice, so I don't think you'll ever see that rolled out for Windows. I would guess that the actual push for TPM is to have 'better' BitLocker, and Passkey support. In practice the default BitLocker+TPM configuration isn't that great (no user entropy/pin, dTPM is basically worthless). I have no actual understanding for how TPM is involved for Windows Hello/WebAuthn/Passkey or whatever, but at a glance it would seem Biometrics without a TEE seems like a very weak link.
- MBCook 2y agoI figured it’s more about ensuring the kernel and boot loading and OS are 100% unmodified by attackers/malware. If that helps with bitlocker or passkeys or whatever that’s great. But I assume at its base it’s a pure integrity play. I would think that would also let you know the public key stuff used to communicate with hardware authentication like a fingerprint reader is secure too, but I don’t know how that stuff works well enough to know if that’s true.
- davidczech 2y agoTPM can measure the Secure Boot state for later reporting (attestation) but when it comes to DRM, that’s not a terribly interesting bit of information, knowing the firmware and kernel are valid, when the configuration of the OS and installed applications is really the important part. As far as I know there’s no real scalable way for that to work in the Windows ecosystem.
- cryptonector 2y ago> Now, TPMs are sometimes referred to as a TEE, and in a way they are. However, they're fixed function - you can't run arbitrary code on the TPM, you only have whatever functionality it provides. But TPMs do have the ability to decrypt data using keys that are tied to the TPM, so isn't this sufficient? Well, no. First, the TPM can't communicate with the GPU. The OS could push encrypted material to it, and it would get plaintext material back. But the entire point of this exercise was to avoid the decrypted version of the stream from ever being visible to the OS, so this would be pointless. And rather more fundamentally, TPMs are slow. I don't think there's a TPM on the market that could decrypt a 1080p stream in realtime, let alone a 4K one. As to the first point... the TPM can't communicate with the GPU, but maybe the GPU could communicate with the TPM. The way that would happen is that the GPU would talk to the TPM directly, using `TPM2_StartAuthSession()` to start an encrypted session with the TPM then it would use `TPM2_ActivateCredential()` or `TPM2_Import()`/`TPM2_Load()`/`TPM2_RSA_Decrypt()` to decrypt a symmetric session key that the GPU would then use to decrypt the stream. I.e., the GPU would do the bulk crypto, but the TPM would do the key transport / key exchange. That also addresses the second point: the TPM being slow is not a big deal because you'd only need it to do something slow once when starting the video playback. Of course, the GPU could just include TPM-like features to get the same effect, which really proves the point which is that: > The FSF's focus on TPMs here is not only technically wrong, it's indicative of a failure to understand what's actually happening in the industry. While the FSF has been focusing on TPMs, GPU vendors have quietly deployed all of this technology without the FSF complaining at all. Microsoft has enthusiastically participated in making hardware DRM on Windows possible, and user freedoms have suffered as a result, but Playready hardware-based DRM works just fine on hardware that doesn't have a TPM and will continue to do so. Pretty much. All the DRM functionality can be in the GPU, and there might not even be a standard API like TPM 2.0 that anyone could use, so the result is even worse than if the GPUs used TPMs to implement DRM. Though, if one were implementing DRM in the GPU or in the display monitor (why not) then the TPM 2.0 MakeCredential/ActivateCredential protocol is a very good fit, so one might as well use that, and even embed a TPM in the GPU and/or the monitor. If you do the bulk decryption in the monitor then the user doesn't even get to screenscrape (eavesdrop on) the connection between the GPU and the monitor. One could even implement just a small portion of TPM 2.0 -- everything needed to establish an encrypted session (`TPM2_CreatePrimary()` and `TPM2_StartAuthSession()`, but also `TPM2_FlushContext()`) and `TPM2_ActivateCredential()`, and maybe a bit more if attestation is required (`TPM2_Quote()` and `TPM2_CreateLoaded()`). What would one attest? I think one would use a platform certificate and its key as the signing key for a TPM2_Quote()-based attestation. The point would be to prove that the device is a legitimate GPU or monitor made by an approved vendor. If you dislike DRM then TPMs are not the enemy. Particularly the TPM on any server or laptop is not the enemy. TPMs in GPUs or monitors might be, but Windows 11 requiring a TPM on the box has nothing to do with that, and again, the GPU/monitor could implement the ActivateCredential protocol internally w/o a TPM anyways.
- no_time 2y agoThe author is correct in that media DRM is tied to GPU vendors on the field right now. But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Environment_Integrity https://en.m.wikipedia.org/wiki/Web_Environment_Integrity This tech extended to browsers could easily mean that sites could refuse to serve you if your machine is running any bigcorp unapproved software. An easy example of that would be adblockers. Unless we get lucky with secure world compromises like the Tegra X1 bootrom exploit[1] or get real good at passing legistlation that forces companies to give you all the private keys to your own machine, the future for personal computing is looking grim. [0]: https://developer.android.com/google/play/integrity https://developer.android.com/google/play/integrity [1]: https://github.com/fail0verflow/shofel2 https://github.com/fail0verflow/shofel2
- ignoramous 2y ago> The author is correct in that media DRM is tied to GPU vendors on the field right now ... hardware backed DRM can be so much more invasive I expect mjg59 to know what they're talking about but like you say, I wonder the same thing about the strength of (what you call) Media DRM v Hardware-backed DRM. GPU vendors have quietly deployed [hardware-based DRM] ... [which] works just fine on [boards] that [don't] have a TPM and will continue to do so. Work fine? Even if a section of GPU's vRAM is out of the reach of the OS (here, to implement DRM), wouldn't TPM / DICE be needed to establish trust / measure GPU's firmware?
- mike_hearn 2y agoNo, the GPUs have their own hardware RoT that measures the firmware. Modern GPUs are basically parallel computers with their own RAM, bootup sequence, BIOS, operating systems (drivers and firmware together are basically an OS), compiler toolchains, debuggers, sub-drivers and so on.
- rustcleaner 2y ago
- PeterStuer 2y agoBut afaik the TPM (or fTPM if no chip is present) is used to establish and restrict trusted access to the replay-protected memory block that the GPU (or other) DRM chain services depend upon to do their thing. IMHO the author does overrestrictively interpret the FSS statement to discredit them.
- mike_hearn 2y agoNo, TPM isn't involved with PAVP at any point. Matthew is correct about how it works. This is a typical case where social activists are light years behind the curve and don't really know what they're talking about at all.
- deleted 2y ago[deleted]
- anal_reactor 2y agoAh yes. DRM. 1. Companies offer service that people don't want to pay for, and blame piracy. 2. Someone realizes that they can eliminate piracy and make lots of money by offering good service. 3. Piracy slowly dies, because people prefer €5 monthly subscription over torrent. 4. Other companies catch up. The market gets fragmented. By the nature of the market, it becomes impossible for one company to offer clearly good service. 5. Piracy gets fashionable again because it's more accessible than having twenty €50 subscriptions, half of them with ads. 6. Companies offer service that people don't want to pay for, and blame piracy.
- p0w3n3d 2y agoyou've nailed it
- DoctorOetker 2y ago7. People blame FSF for not ridding them of evil as they walk through the valley of death.
- notpushkin 2y agoThe top comment pretty much sums up everything that’s wrong with DRM: > Lest one get the impression that hardware DRM fairs any better than software: Even 4K/HDR versions of streaming media start making the rounds on pirate sites within a day or two of release. > As usual DRM fails to prevent piracy while hurting the experience of paying customers.
- deleted 2y ago[deleted]
- Karellen 2y agoOnly one of the purposes of DRM is to prevent piracy. There are others. One of which is to prevent mainstream media player manufacturers from making a hardware or software player which can skip region coding/studio tags/anti-piracy tags/trailers/random adverts. Or even from having a generic "skip 30s" feature. You want to legitimately be able to play our stuff so you can sell millions of units of your player to unsophisticated consumers? Agree to these terms, and this fee schedule, or you don't get a key to play them. Fuck us over, and we'll revoke your key. Lol.
- nine_k 2y agoI remember the idea that DRM is not about controlling the viewers directly, but about controlling the makers of playback devices (both hardware, as in GPUs and TVs, and purely software). The point is not in making the bits uncopyable at all, but to prevent the makers of things like Roku or Chrome from making the access too easy, like skipping ads, let alone downloading. Most viewers are not computer-savvy, even if they spend every day in an office facing a computer screen. If 90% of audience would know or bother to go no farther than the legal distribution channels, and won't be able to plainly download the high-res media in one click, the DRM has worked. It suffices to make pirating inconvenient enough for the uninitiated, and let the advanced and determined minority pirate away, of course always threatened and stigmatized, to keep the operations low-key. A small amount of pirates, imho, only improves the profits, because they brag about having just seen the new hot thing in all its glory, and thus induce FOMO in their audience. Of course the legally-buying, technology-naive audience is inconvenienced. But they know no better, and the whole point of control is, well, making people submit to what they rather won't, isn't it?
- deleted 2y ago[deleted]
- 1vuio0pswjnm7 2y agoIs it possible that some of the readers FSF is targeting may not be using a dedicated GPU.
- mjg59 2y agoI'm not sure what they'd be displaying their streaming media on if they're not using one?
- woodrowbarlow 2y agoi've done a lot of work with Arm TrustZone, OP-TEE, and Arm Trusted Firmware. it's really nice. in Arm, the TEE is user-supplied, not vendor-supplied, so it gives an isolated execution environment for any sensitive code you might want to put in there. hardware peripherals (tzc/spu) allow you to designate certain bus addresses or memory ranges as "secure" during the early firmware initialization, meaning Linux (or whatever OS you use) cannot read or write to them. furthermore, unlike a TPM, the TEE isn't running in parallel on a co-processor -- it only runs when Linux yields control (cooperative scheduling) so it provides functionality without wrestling away control.
- lxgr 2y agoTEE is nice, but it's a pretty different use case all around, and the two are actually quite complementary: TEE is effectively an execution environment below ring 0, together with some hardware isolation as you mention. But by itself, solutions based on it can't hold any trusted key material, so can't be used in attestation contexts. TPMs and other types of secure enclaves or secure elements include secure storage and can come pre-loaded with external root of trust keys, which allows attestation (and by extension trusted computing use cases), but also completely local useful things like enforcing a PIN retry limit on usage of a hardware-stored SSH key. But since TPMs are by design self-contained and don't have any input or output capabilities, mediating user access via a TEE and some minimal OS providing a user confirmation UI can be very powerful (for example so that malware can't lock you out of your own SSH keys by just entering the PIN incorrectly repeatedly).
- deleted 2y ago[deleted]
- forty 2y agoDoesn't the article forgot to mention that TPM allow to do trusted boot and remote attestation ? It sounds like to me that could very well be used to make software DRM more efficient (by making sure you run a DRM friendly OS for example)
- lxgr 2y agoBut so does a USB-connected security dongle. Does that make USB "complicit in enforcing DRM"? TPMs are really just embedded Yubikeys. Unless your UEFI/BIOS "conspire" to supply them with boot measurements, and your OS in turn conspires with that to carry these measurements forward and provide them at the application layer, TPMs can't harm your freedom. TPMs are a much more "freedom neutral" technology than people generally assume in these discussions.
- forty 2y agoThe TPMs are already provided with boot and OS measurements for secure boot purpose which would allow DRM to confirm you use an approved OS kernel, so I guess the computer is already conspiring. And the conspiracy could be enforced by videos distributors in exchange for the privilege of having HD content.
- mjg59 2y agoIt could, but why? They've come up with a solution that avoids having to place any trust in the OS at all, so why introduce additional complexity and fragility?
- forty 2y agoI don't know, maybe because not everyone has the right GPU with DRM, while the TPM is conveniently mandatory? :)
- lxgr 2y agoMandatory where? Most of the devices people are streaming video to these days aren't even PCs! Macs haven't had TPMs for a while now (I think Apple never really used it and dropped it even before the Apple Silicon switch), but of course they have their proprietary equivalent.
- cannabis_sam 2y agoDRM is a government sanctioned desecration, by corporations, of your private property rights, by its very definition. Whether it’s in the GPU, CPU, TPM, or any other part of computing property you ostensibly own, is an utterly irrelevant distraction, the root is the unholy alliance of government and capital power.
- lxgr 2y agoNo, if anything, the fact that governments allow businesses to only "license" you digital content, i.e. not give you the option to actually acquire property rights in it, is. DRM is just a technical implementation detail downstream of that.
- _2d30 2y ago> the root is the unholy alliance of government and capital power. And Labor too, don't forget! https://www.backstage.com/magazine/article/sag-aftra-back-anti-piracy-measure-58915/ https://www.backstage.com/magazine/article/sag-aftra-back-an...
- mnot 2y agoThe embedded politics of the “t” in “tpm” and “tee” are super interesting and revealing. They are “trusted” only from the perspective of the developer; to the user, they represent the complete lack of trust.
- mjg59 2y agoOn the contrary, it gives me various ways to determine that my laptop is in a trustworthy state before I type a password into it, and it makes it possible for Signal to verify that the server it's communicating with hasn't been tampered with. It can be used in ways that hurt the user, but it can also be used in ways that benefit them.
- deleted 2y ago[deleted]
- lxgr 2y agoSuggestion for a compromise: Make it mandatory for TPM vendors to provide a user option to wipe all attestation keys and rebrand them as “embedded security keys” (and maybe promise to never use them for DRM, which per TFA nobody is anyway). I feel like untangling the attestation capability (which I do believe has non-user-hostile/non-zero-sum uses!) from the secure key storage one might ultimately help their adoption.
- anticensor 2y agoDRM is actually negative sum.
- lxgr 2y agoI was talking about non-DRM use cases of attestation.