Slashdot Log In
DRM Based on Trusted Computing Chips
Posted by
ScuttleMonkey
on Sun Feb 19, 2006 07:22 AM
from the never-saw-it-coming dept.
from the never-saw-it-coming dept.
An anonymous reader writes "We've always know that Trusted Computing is really about DRM, but computer makers always denied it. Now that their Trusted Computing chips are standard on most new PCs, they've decided to come clean. According to Information Week, Lenovo has demonstrated a Thinkpad with built-in Microsoft and Adobe DRM that uses a Trusted Computing chip with a fingerprint sensor. Even worse: 'The system is also aimed at tracking who reads a document and when, because the chip can report back every access attempt. If you access the file, your fingerprint is recorded.'"
Related Stories
[+]
Trusted Computing Rollout Hits the Desktop 520 comments
Alsee writes "Previously appearing in a few rare laptops, ExtremeTech reports on the first major computer manufacturer making a full scale Trusted Computing rollout. Samsung will now install the Phoenix Core Managed Environment (cME) BIOS in every computer they make. Previous Slashdot reports on this BIOS include Phoenix Bios to Incorporate DRM and Microsoft Taking Over the BIOS."
[+]
Trusted Computing 241 comments
derrickoswald writes "John Walker, one of the founders of Autodesk, has posted The Digital Imprimatur, a monograph on technologies such as the Trusted Computing initiative.
Some of the prognostications and conclusions reached may not be palatable to Slashdot readers."
[+]
BBC on DRM and Trusted Computing 227 comments
distantbody writes "This BBC article by Bill Thompson is balanced and concise on the issues of DRM and 'Trusted Computing,' and offers some insights as to why such systems are the wrong path to follow for consumers and businesses alike. From the the article: 'We need to ensure that trusted computing remains under the control of the users and is not used to take away the freedoms we enjoy today ... the flexibility of copyright law is something that should be embraced and not taken away.'"
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading ... Please wait.

Sweet (Score:5, Funny)
Oh no, I can hear them cry (Score:5, Insightful)
What next?
I would sell my soul for total control over you. Or something like that. What has come of the world that corporate greed has taken over from the free harmonious society? I would love to say everyone will just scrap computers and move onto other ventures (like going outside) but that is the Utopian view. In reality the Orwellian scenario us coming upon us. It won't be long now people.
What is sad about this is they are touting the "legitimite" uses of making sure software is unmodified and doesn't contain root kits and protecting sensitive data from attackers. I find it funny that SHA1SUM and gpg --checksig tells me when my download isn't what the author intended. Cryptoloop (and a tonne of other software) keeps my files highly secure and safe from prying eyes even if they do steal my disks.
There are no legitimite uses for this technology that can't already be accomplished today. There are only evil uses!
Re:Oh no, I can hear them cry (Score:5, Interesting)
Don't act like it's news. Microsoft already changed it's license agreement. Now, for all you folks who like to upgrade your computers, a new motherboard means you need to buy a new copy of windows for a new license. [aviransplace.com] Yep! Windows MAY NOT be transferred between different PC's and changing out the motherboard constitutes a new PC according to Microsoft now. In fact, according to a Technet Community Chat [microsoft.com], replacing a DEFECTIVE Motherboard still requires a new license! As they said: .i have a system i sold, mainboard is to handle a 3.2 processor but originally sold it with 2.4 with promise of upgradeability to 3.2, though main board works fine with 2.4 it does not with 3.2, is this considered a failed mainboard
"Q: k guys, my question is
A: This is still considered an upgrade if the motherboard is changed. You might want to try using the latest BIOS for the motherboard. If it still doesn't support the 3.2 GHz CPU and you replace the motherboard then you'll have to sell them a new OS." - Microsoft Technet Community Chat
Quite a bit of fun, no?
Re:Oh no, I can hear them cry (Score:5, Informative)
Re:Oh no, I can hear them cry (Score:5, Insightful)
IBM, Dell etc. are not the evil ones here, neither is MS. Its the *AAs who don't care about destroying the universal computer.
Oh god, you are so fucking wrong it actually hurts to read this.
DRM is all about controlling applications -- music and video are just the high-profile stuff. Applications spread/use data, if you are going to control data, you must control applications. TCPA hardware decides which code gets to run, and what it can access... and it does it behind walls of encryption to ensure that *you* can't see what is executing. IBM, Dell etc etc all have massive hard-ons for this hardware because *THEY WILL CONTROL WHAT YOU DO WITH YOUR PC*. They will broker the CPU, memory, hard disc, sound/gfx card on your machine to the RIAA/MPAA members, or just anyone they feel like. You will have no say in the matter. They can install software on your computer without you ever knowing about it, and you will not be able to remove it or disable any undesirable features because your computer will not be "trusted" anymore.
In addition, it will allow them to take GPLed software like the Linux kernel and make it de facto proprietary... simply because the hardware will not "trust" the binary unless it is signed by Dell/Intel/IBM etc etc. So your GPL source is worthless in that world -- you can't modify it... hell, you can't even recompile it yourself without modification, because the result won't work as it did.
Re:Oh no, I can hear them cry (Score:5, Insightful)
And now we see why v3 of the GPL has provisions to prevent this.
OBjoke (Score:5, Funny)
Does your PC have Trusted Computing? (Score:5, Informative)
*THIS* is what FOSS is all about. (Score:5, Insightful)
Re:*THIS* is what FOSS is all about. (Score:5, Insightful)
You won't even be able to use your OSS tools on a "trusted computing" platform. That's the whole point.
This new scheme is aimed explicitely at locking out any software from vendors that don't lick the RIAA/MPAA's collective bottoms.
getting out of computing? (Score:5, Insightful)
Re:getting out of computing? (Score:5, Interesting)
Fortunately, we don't need firearms for this. We can stop using and recomending DRM capable hardware and we can halt software development for it. We must be very vocal in our opposition to this. We may may be few, but I am sure this audience is more influential than the average.
RMS's Nightmare is Coming (Score:5, Informative)
Ah! I see a new profitable market! Fake Thumbs! (Score:5, Insightful)
Steve
There is much truth in what you say (Score:5, Informative)
The problem with fingerprints is that it's inherently a very insecure way of authentication for two reasons:
Firstly, you can't change it if it leaks out. A password or a credit card number can be easily changed and the damage minimised in case of an information leak. Doing this with a fingerprint is much harder.
Secondly, the fingerprint is very hard to keep secret. Your body has this annoying ability to leave copies of your identification token all over the place, very easy for anyone to pick up. If you were worried about the ability to scan proximity tags (RFID), then you should be really scared about the use of fingerprints as authentication tokens.
If you don't believe me how easy it is to pick up, read this [schneier.com] about how to make a copy of ones fingerprint using common household items.
I truly hate this crap, the companies will pay! (Score:5, Insightful)
I have the right to use my computer to whatever I feel like and it is of no concern to anyone but me. If the companies disagrees with this they can take a hike for all that I care.
All this will contribute to - is to further alienate Linux and users of alternate operating systems and demean our hard efforts to get legal DVD-playback software etc. for our chosen platforms. I am so put down by this Ill probably never run anything with DRM on it again just for the opposition of it. I will not purchase DRM enabled mp3-players, I will NOT purchase DRM harddisks or any hardware with DRM on it.
If I am forced to do it because of the fact that every hardware producer is forced by Microsoft to do so... I will do anything I can in my power to make sure that my system will be rid of such hardware, modding, jacking, compiling - I really dont care. Its my hardware and NO one shall take that right away from me! No one shall control my software or my computers or what I will be doing with them.
I fully and completely agree with the companies about piracy, I dont support piracy in any way. That said - I also support my own freedom to chose, and past experience shows us that businesses will always do whats best for them FIRST before the customers, the customers are just milking-cows to them - which is fair enough if you give us what we pay for. When you decide to mess with our hardware and deprecate our already paid for services and hardware - then I am putting my foot down and say - Enough already!
All this will probably further feed a grassroot "linux-like" organization that will form an alternate OS that will NOT conform to DRM - even if by law (god forbid it goes that far). DRM and control of customers hardware is a CRIME against the public!
I don't trust my computer (Score:5, Insightful)
It's nice to know that the content industry now trusts my computer and lets it play its crappy movies. The problem is, I don't trust it anymore. I won't trust it with my data, I won't trust it with my files, I won't trust it with my time.
At least until I find a way to make MY computer MINE again.
Until now, I was a good citizen. I bought my music. I bought my movies. I bought my games. My reward was a rootkit, DVDs that don't play on my equipment and software that crippled my system.
Sorry, but I don't trust your computers. And I will do whatever it takes to make my computers mine again!
Re:Biased article? (Score:5, Insightful)
So, while the current incarnation may seem ok, things are only a few steps from being really bad and invasive. Couple this with the DMCA, and half the things we take for granted with computers now could be taken away, and it will be illegal to 'break' things to get those abilities back.
Re:Right but...Change is good (Score:5, Informative)
Change is not always good. Why do I want to pay for equipment that I will not own?
These "TRUSTED" machines are untrust worthly. You will not be able to control what runs on them. Some one else will decide if you can use your own equipment. Just like the lies with HDTV and HMDI. It is about setting up toll booths deep in your own pockets.
Re:Biased article? (Score:5, Insightful)
Bullshit they wouldn't. The software companies realise they have a product that never gets old, never wears out and will perform the task it was purchased to do until hell freezes over unless they find a way of breaking it. Software companies have been trying to find ways of making software wear out for decades so they can rake a continuous income from their customers the way other manufacturers do. They use product activation to tie the non-wearing software to the fragile hardware for example, but their customers hate them for it.
The customer wants to buy a tool and use it forever, or until they no longer have a use for it, whichever comes first. We know damn well when they're being scammed, and want nothing to do with this license once and pay forever crap. We've tolerated buying the same product over and over again because we accepted we were paying for new features and improvements.
The cost of production of each copy of a program is nil, so the only controllable cost variable for a producer of software is the cost of development, the development of those features and improvements we've been paying for. If they can get away with using this DRM garbage to artificially obsolete programs, they won't need to keep improving the software, they'll have their continuous income without the cost of development. Say goodbye to software innovation.
Re:Biased article? (Score:5, Insightful)
Now comes interesting Tidbit Number two...
The article mentions "My fingerprint results in Access Denied, but the person who wrote it gets into the [document]." Right... So what if they want ME to be able to get in, but not my coworker? How do they acquire MY credentials to allow me in? How secure is this acquisition? Already things like PK Encryption require chains of custody and KNOWN Public Keys to have the proper security. When you get into the extremely-high levels of security, it gets somewhat complex. But now there is a certificate associated with my fingerprint?
Overall, while they claim "Makes it easier", from a security standpoint, I actually see a lot of room for complication, error, and massive breaches of security. And as the article points out: Do you REALLY trust Microsoft to not have security holes? One "Oops" and suddenly the document that you need -ME- to be able to read is not at all accessible by me, but who knows who instead.
And what kind of "Oops" does it take? Gee... Spoofed email of a Public Key maybe? Social Engineering of a phone call to claim to be me, and give them a false cert fingerprint? And of course if I use Linux, I'm {censored} out of luck. If Linux will even RUN on the systems anymore, since Microsoft doesn't sign it to be trusted.
Re:Biased article? (Score:5, Insightful)
I don't believe that for a second. They are responding to arm-twisting by Microsoft and Adobe (,etc.) and working *against* customer interests. Consumers have no interest in DRM at all. The question on manufactures' minds is how much DRM they can shove down consumers' throats before they balk and stop buying. They are counting on consumers being either too ignorant or too passive or too apathetic -- until it's too late.
Re:What about the customer? (Score:5, Insightful)
Bingo!
The customers and the consumers are not the same. The customer is the corporation who wants to lock up its data. The consumer is the person to whom the corporation wishes to grant access to that data.
Yes, lots of consumers are also customers of the hardware manufacturers but the corporations are larger customers and their voice is louder. If you dont want this stuff in a computer that you are buying then you need to let those manufacturers know about it. Buy something else and send them a copy of the receipt with a note explaining why you didnt buy their hardware.
Re:Amazingly shortsighted (Score:5, Insightful)
Keeping corporate proprietary info secure
Or, keeping an internal memo that reveals the company has broken laws etc. secret. DRM of this kind (and on emails, something else they want to implement) makes it very difficult for whistleblowers to collect evidence and expose a company that should rightly be exposed.
The effects of DRM are certainly chilling. Also, as far as trade secrets go, there are laws designed to protect those. DRM will only ever be (ab)used to hide things that shouldn't be hidden and to strip away fair use rights. The media companies weren't able to do it through the law courts, so they sneak in fair-use crippling measures by the back door.
Other and better ways to protect your stuff exist (Score:5, Insightful)
So would you, if you were a software company, trust Microsoft? Would you, if you were a mainboard manufacturer, trust Intel? Would you, if you were a chip producer, trust Infinion?
There are other ways to protect your intellectual property. Open Source encryption mechanisms, the source code of which you can read, audit and evaluate, and even adjust to your security needs.