Coursey on Palladium
lrose writes "Check out this story over at ZDNet -- Microsoft is developing a secure operating system to be combined with hardware doing public key cryptography. The DRM aspect reminds me of something I read about an imaginary day in the not-too-distant future, where you can no longer install Linux on your own box because you don't have the necessary rights." Coursey's column is quite interesting, bringing a lot more of the backstory behind Palladium into public view. While geeks have been following and worrying about the TCPA, Microsoft has been working to spin the story with assorted columnists and journalists, so that when it broke it would be in the context that Steven Levy bought into hook, line and sinker: a scheme to protect you rather than one to prevent you from using your computer in unapproved ways.
Not worth a story of its own, but Robert Cringeley brags in this week's column that Palladium is the Microsoft attempt to replace TCP/IP that he was predicting a year ago.
What I'm listening to now on Pandora...
TCPA / Palladium Frequently Asked Questions
Version 0.1 26 June 2002
Ross Anderson
1. What are TCPA and Palladium?
TCPA stands for the Trusted Computing Platform Alliance (TCPA), an initiative led by Intel. Their website is here. Their stated goal is `a new computing platform for the next century that will provide for improved trust in the PC platform.' Palladium appears to be a Microsoft version which will be rolled out in future versions of Windows, will build on TCPA hardware, and will add some extra features. The Palladium announcement appears to have been provoked by a paper I presented on the security issues relating to open source and free software at a conference on Open Source Software Economics in Toulouse on the 20th June. This paper criticised TCPA as anticompetitive. This has been amply confirmed by new revelations over the past few days.
For the rest:
TCPA/Palladium FAQ
Last time I checked you couldn't circumvent fair use. By building a device that prevents fair use, this Trusted Computing group is creating a device that by its very nature defies the very statutes that the Supreme Court has said are legal!
Specifically there are limits to Copyrights in the following scenarios:
LIMITATIONS ON THE EXCLUSIVE RIGHTS
The copyright owner's exclusive rights are subject to a number of exceptions and limitations that give others the right to make limited use of a copyrighted work. Major exceptions and limitations are outlined in this section.
Ideas
Copyright protects only against the unauthorized taking of a protected work's "expression." It does not extend to the work's ideas, procedures, processes, systems, methods of operation, concepts, principles, or discoveries.
Facts
A work's facts are not protected by copyright, even if the author spent large amounts of time, effort, and money discovering those facts. Copyright protects originality, not effort or "sweat of the brow."
Independent Creation
A copyright owner has no recourse against another person who, working independently, creates an exact duplicate of the copyrighted work. The independent creation of a similar work or even an exact duplicate does not violate any of the copyright owner's exclusive rights.
Fair Use
The "fair use" of a copyrighted work, including use for purposes such as criticism, comment, news reporting, teaching, scholarship, or research, is not an infringement of copyright. Copyright owners are, by law, deemed to consent to fair use of their works by others.
The Copyright Act does not define fair use. Instead, whether a use is fair use is determined by balancing these factors:
* The purpose and character of the use.
* The nature of the copyrighted work.
* The amount and substantiality of the portion used in relation to the copyrighted work as a whole.
* The effect of the use on the potential market for, or value of, the copyrighted work.
But nothing in this specification speaks of how you will still be able to maintain your fair use rights. If they build it, people should proactively sue them because its a rights violation for it to exist at all.
Two more reasons:
You have to remember that this is the same company that used the ominous variable "NSA_KEY" in some of its security software...
Not that I believe the NSA was responsible of this particular blunder... =)
The right to offend is far more important than the right not to be offended. (Rowan Atkinson)
A digital rights management operating system protects rights-managed data, such as downloaded content, from access by untrusted programs while the data is loaded into memory or on a page file as a result of the execution of a trusted application that accesses the memory. To protect the rights-managed data resident in memory, the digital rights management operating system refuses to load an untrusted program into memory while the trusted application is executing or removes the data from memory before loading the untrusted program. If the untrusted program executes at the operating system level, such as a debugger, the digital rights management operating system renounces a trusted identity created for it by the computer processor when the computer was booted. To protect the rights-managed data on the page file, the digital rights management operating system prohibits raw access to the page file, or erases the data from the page file before allowing such access. Alternatively, the digital rights management operating system can encrypt the rights-managed data prior to writing it to the page file. The digital rights management operating system also limits the functions the user can perform on the rights-managed data and the trusted application, and can provide a trusted clock used in place of the standard computer clock.