Slashdot Mirror


Stopping Palladium?

jbwiv asks: "I've seen many articles/posts/opinions stating that Microsoft's Palladium could put an end to Open Source as we know it, thereby stealing away most of what I enjoy and appreciate about computers. With the big two (Intel, AMD) actively developing Palladium architectures, I'd like to get involved in the effort to combat it. However, I haven't found any person or group actively working to stop Palladium; plenty people are bitching, but no one seems to be doing much about it. Who can one contact regarding this, and are there any groups already involved? What other steps might be taken? It would seem that such an affront to our way of life would be met with more vocal and mobile opposition."

18 of 99 comments (clear)

  1. Hmm... by ThorGod · · Score: 2, Insightful

    Buy a Mac, Sun, etc? I'd imagine those architectures won't be instating Palladium.

    Or am I going to have to go back to my handy-dandy etch-a-sketch?

    --
    PS: I don't reply to ACs.
  2. First we have to know what it is! by infohord · · Score: 3, Insightful

    There has been alot of talk on this subject, almost all of it speculation. Do we have any concrete ideas about how it will stop open source? No we don't. We can only speculate (be like the x-box, secure hw, closed specifications). Short version, know thie enemy. We don't even know if it is the enemy.

  3. Doesn't Palladium has a place? by burnsy · · Score: 2, Insightful
    Say I am an employer who doesn't want my employees's computers to be security risks or I am a parent who doesn't want my kids running software (or visiting chat rooms) behind by back.

    Doesn't Palladium meet my needs? Doesn't Palladium have a place?

  4. Stop it *how*, exactly? by Jerf · · Score: 3, Insightful

    Unlike the CBDTPA, DMCA, UCITA, and other laws, we can't lobby against Palladium. We can't (and shouldn't!) lobby to have it banned at the federal level. It's a Microsoft product. If they want to make it, they will.

    All you can do is not buy it, and exercise your free speech to try to convince as many other people as possible to not buy into either.

    What more is there to do? Am I missing something?

    If you're looking for action to take, lobby against the CBDTPA, let your representatives know how you feel on these issues, and focus on the legal problems. Microsoft is perfectly free to offer Palladium if they want to, because as sucky as it is, it's not actually being mandated by law. (Yet. Re: CBDTPA, lest ye hurry to accuse me of paranoia.) Palladium is going to happen. (Since the first incarnation will be horrid, it may not even be worth worrying about; the market may well write it out of existance.)

    1. Re:Stop it *how*, exactly? by Monkelectric · · Score: 5, Insightful
      All you can do is not buy it, and exercise your free speech to try to convince as many other people as possible to not buy into either.

      You've got it man :) As an "independent artist" I cant *WAIT* for Paladium -- when the new Brittany album won't play in your daughters CD player, when you cant load your tunes onto your mp3 player to exercise, I'll be there giving away mp3s and selling cheap unprotected cds :)

      If the music industry screws up this DRM stuff, they really will deal customers right into the arms of independents (mostly smaller labels). Here's how I see the breakdown:

      DRM albums start coming out that have to be used on the PC, they can't be used on MP3 players (maybe secure ones), or on regular CD players (because if they could, we could rip the data). (Possibly they release a new format entirely). RIAA dangles some new format cookie in front of consumers "New music format delivers extra fidelity, new unreleased Beetles tracks in this format only!" (Really, they want you to buy all your old albums again)

      People realize it doesn't matter how many times you buy the white album, it was still recorded on analog equipment and 70db DNR sounds just as shitty at 32 bits as it does at 16 (DNR of a 16 bit cd is 96db). Same goes for even newly recorded albums, because the most accurate A/D converter on the market riight now and for the forseable future is ~120db (and just try to get 120db DNR out of a mic, its not possible). Consumers go FUCK THIS, meanwhile some "hackers" (good guys) figure out how to kill the watermark in the data, they release watermark tools, we have another DECSS on our hands, but the cat is out of the bag.

      Audio warez groups start to form using the illicit tools. They beg/borrow/steal albums, rip them and release mp3s or Oggs. Pirated mp3s start to have *MORE* value then actual cds, you can play them wherever you want, load them onto an mp3 player; you don't have to hassle with restrictions. RIAA tries to halt this by getting a few people sent to jail. Various free so and so campaigns pop up, further polarizing the community. RIAA tries some kind of attack on the internet itself it buys legislation to allow it to install filtering routers, live monitoring of ISPs. Government supports this because they want draconian control over the internet... for awhile P2P becomes a whack-a-mole game, but people become fed up with the instability this causes and the fact that legitimate transfers are being killed, and the RIAA gives up, leaving just the various 3 letter agencies using the equipment.

      RIAA persists and albums sales grind to a halt. RIAA blames this on music pirates, but the hassle over DRM forced consumers to find music elsewhere. Consumers find they are paying less money for [independent] music with more content and a wider variety. Independent labels and artists flourish. The giant media corporations are severely damaged and the glory days for the media industry are over. Some big stars persist but music becomes fragmented. New internet businesses pop up which help artists distribute and sell their music by producing professional cds and helping artists promote (like mp3.com but less bastardly). As these companies flourish all but a few are put out of business by consolidation and they BECOME just as bastardly as the current crop of mega-corps, and in 30 years our kids are having this same discussion.

      (and HOPEFULLY rap turns out to be just a fad) :D

      --

      Religion is a gateway psychosis. -- Dave Foley

  5. It's truly amazing... by stubear · · Score: 3, Insightful

    ...how one day you people rail against the RIAA's attempts to shut down P2P, claiming that P2P has other uses than intellectual property theft. On the very same day, and quite often in the same thread, you can argue that Palladium is "evil" and it must die, regardless of the other uses of the technology to secure systems against unauthorized software such as viruses, worms and trojans. You have absolutely no concept what Palladium is but you have no problems condemning the technology. Either make up your mind of STFU. Enough of the hypocrisy.

    1. Re:It's truly amazing... by Chexsum · · Score: 1, Insightful

      Ummm, you are lost. theres no hypocrisy in wanting to stop people from destroying files on your computer and wanting to stop the technology which will enable this to happen more easilly.

      Palladium will not stop Virii/Trojans/Worms/Bugs or help with Security unless it stops all programs from functioning properly. A Virus/Worm/Trojan are programs which exploit a bug and Microsoft technologies and products are full of bugs at all times.

      Youd have to be clueless or a troll to say what you just said. Locking up a Windows computer with Microsofts keys is what Palladium is about. =)

      Hitler returns.

      --
      Pixels keep you awake!
    2. Re:It's truly amazing... by Dalcius · · Score: 3, Insightful

      I try not to take pop shots at people and concentrate on their arguments, but I will this time. How in the hell did you of all people get a base score of 2?

      Here it is, point by point.

      ---
      ...how one day you people rail against the RIAA's attempts to shut down P2P, claiming that P2P has other uses than intellectual property theft.

      Why, yes, it does. For instance, sharing free music and providing better methods for downloading certain types of files, such as those hosted on fileplanet.com, which is notoriously slow. P2P technologies, as they are developed, will also help the internet in general as medium-end computers become powerful enough to run servers. Mainframes are no longer needed, nor are high powered server clusters for many tasks. P2P is here to stay in at least some of the market, and in the future, it might take over much more. Developing it and letting it continue without DDOS attacks from some techno-weenie at the RIAA is a Good Thing (TM).

      ---
      On the very same day, and quite often in the same thread, you can argue that Palladium is "evil" and it must die,

      What this has to do with the RIAA and P2P has escaped me.

      ---
      regardless of the other uses of the technology to secure systems against unauthorized software such as viruses, worms and trojans.

      Microsoft will stop this by only allowing "authorized programs" to run. User authorization is pointless -- besides bugs (fairly attributable to Microsoft holes) and some poor "features", this is how things work now: the user must choose to run the code.

      However, if the user does not authorize it, someone else must. If you care to claim that Microsoft isn't going to be that body, I'd love to hear a feasible argument. If Microsoft controls this, that gives them control over your entire computer regarding what you can and can not do. They have proven in the past that they'll abuse power to push people out of their market. No reason to assume they won't now.

      If someone else gets it, the point still stands that that is too much power in the hands of one entity. Feel free to move to China if you prefer this scheme, I don't think many of us will mind.

      ---
      You have absolutely no concept what Palladium is

      Well, frankly, nobody knows exactly, Microsoft won't tell us much about it. But what they have said can be put through logical analysis, and the results are Not Good, including what I posted above.

      ---
      Either make up your mind of STFU. Enough of the hypocrisy.

      Again, can you enlighten us all how arguing against vigilante DDOS and cracking attacks on private networks relates to condemning a system that will wrench control of a user's computer from them?

      --
      ~Dalcius
      Rome wasn't burnt in a day.
  6. Best way to stop Palladium by sl956 · · Score: 3, Insightful


    Repeat after me : We will not win a lobbying/PR war. period.

    So let them (Microsoft, Intel, AMD, RIAA, MPAA) try to please Hollywood : if Joe User has a true alternative to the annoyances of Palladium, he will switch in no time.

    What about :
    - GNU/Linux instead of Palladium Windows
    - A PowerPC G4 based PC instead of a Palladium Intel/AMD based one
    - ogg/mp3 and divx instead of Palladium cds and dvds
    - P2P instead of Palladium Amazon

    Yes, Joe User prefers Windows/Intel/DVD/Amazon for now. But the choice will be very different when he will be annoyed by palladium every time he wants to listen to music or watch a movie.
    Just be patient : they're working for us. And in the meantime, you can help to improve the alternative (hint, hint.)

    Obligatory disclaimer : I'm not advocating the use of P2P as a means of avoiding buying music/movies. I'm just saying that if Hollywood impose unfair licencing terms, Joe User will switch to P2P, be it legal or not.

    1. Re:Best way to stop Palladium by sl956 · · Score: 3, Insightful

      I don't understand why you think the end user will be annoyed by palladiun.
      Good question, simple answer : fair use. In order to be effective, Palladium has to deny fair use.

      Here is a list of things any end user can do now which should become impossible with palladium-enabled PCs and media :
      - copy a cd to a tape in order to listen to it in his car
      - use legally licenced music/movie/software after a processor upgrade
      - lend a cd/dvd to a friend
      - play a home-made song/movie
      - burn backups
      - and so on

  7. Look by PaddyM · · Score: 3, Insightful

    It only matters if people support it. For instance, I download most of my music from video game fan sites. Are those composers going to suddenly start producing music using palladium technologies? It's a possibility. But if they don't, then I still get to play the music. So don't support anyone who uses Palladium as a means to protect their copyright.

    1. Re:Look by kcelery · · Score: 2, Insightful

      With good marketing these Palladium machines will run everywhere. Just think about why people port Linux to XBOX. Because it is subsidized. This will happen to the Palladiums. MS will make a lot of money selling Palladium-exclusive programs, song, video etc. So MS can afford subsidizing. The real pain in the ass is, when you want to buy a nice software for you task but found that program only on the Palladium platform and nowhereelse. By that time, do you think the open-source community will face another big new challenge ? I know of no song-writer, singer refusing the Palladium idea.

  8. Plans and Countermeasures by bwt · · Score: 5, Insightful

    This is the method that the opposition will try:
    1) Make some CPUs implement opt-in DRM
    2) Make all CPUs implement opt-in DRM
    3) Make some CPUs implement opt-out DRM
    4) Make all CPUs implement opt-out DRM
    5) Make some CPUs implement mandatory DRM
    6) Make all CPUs implement mandatory DRM

    We have to fight at every step. The key to fighting during the "some" steps will be economic and technical (early adopters must be punished) and the key to avoiding the all steps will be political.

    I believe that our best opportunity is during step one. We need to be prepared to make END USERS who accept DRM suffer. This may be somewhat unnatural for us to do, but if we do that, the market will take care of the rest.

    Here are a couple of ideas:
    A) Open source licences should actively exclude installation on DRM *capable* hardware.
    B) Open source tools must inhibit interoperability with DRM enabled hardware. "I'm sorry, but your machine does not meet the minimum requirements to view this web page"
    C) At work, try to influence procurement policy:
    - "DRM is for playing games and watching movies, do we really want our employees doing that?"
    - "Some software breaks when you use that - let's keep our options open"
    - "Palladium will worsen our lock-in to MS products, do we want that?"
    - "When somebody cracks it, and they will, we'll get viruses we can't remove"

    1. Re:Plans and Countermeasures by vsurfer · · Score: 2, Insightful

      Sounds like a two-front combination of "Plans and Countermeasures" mentioned above perhaps, and the below suggestions:

      What about :
      - GNU/Linux instead of Palladium Windows
      - A PowerPC G4 based PC instead of a Palladium Intel/AMD based one
      - ogg/mp3 and divx instead of Palladium cds and dvds
      - P2P instead of Palladium Amazon

      Yes, Joe User prefers Windows/Intel/DVD/Amazon for now. But the choice will be very different when he will be annoyed by palladium every time he wants to listen to music or watch a movie.
      Just be patient : they're working for us. And in the meantime, you can help to improve the alternative (hint, hint.)
      ----------------------
      And keep on trying to make the barrier to entry less daunting to those on the outside who are willing to experiment--make dual booting easy--but who want to take their time to learn about Linux, not have to take a CS course before they can understand how to get their soundcards working.

      The more uptake in the regular world, the more the word will spread.

      PS. Also this:

      http://www.eweek.com/article2/0,3959,543317,00.a sp

      (Apple/IBM team up on 64 bit Power4 architecture.)

      or even this as food for thought about compatible hardware that exists now.

      http://www.linuxjournal.com/article.php?sid=5610
      ----
      Gotta walk the penguin, I mean dog.

      --
      vsurfer
    2. Re:Plans and Countermeasures by oren · · Score: 2, Insightful

      Open source tools must inhibit interoperability with DRM enabled hardware. "I'm sorry, but your machine does not meet the minimum requirements to view this web page"

      Nah, too radical. It is better to do the following: allow free use of the software on non-DRM platforms, and charge money for it - even a measly 1$/month, paid once a year - for anyone using it on a DRM platform.

      This would drive the point home for anyone considering to purchase DRM platforms - a taste of how things would be if DRM really catches on. These 1$/month would add up very fast (count the number of packages on the minimal Debian install for example).

  9. Re:HOW will Paladium kill Open Source??? by Anonymous Coward · · Score: 1, Insightful

    I think this is very straight forward, but is hard to see because it attacks open source from lots of different angles.

    When the media companies require you to have a player for their content, the only choices will be closed solutions so they can trust that their data does not get stolen.
    to be able to trust the application, you need to trust the underlying operating system.
    palladium enabled hardware (dvd drives etc.) will require a trusted operating system too.
    it won't work without a trusted operating system.
    parts of the web won't work without palladium being enabled. buisness on the web wants security. palladium tries to offer them that.

    by choosing open source, you are restricting what you can do with your computer.
    open source has a market with non geeks because it can offer comparible functionality at a lower cost of ownership.
    Now consumers will get the mindset "you get what you pay for".

    a lot of the reason open source is where it is today is that people use it. they use it because it's not much harder to use than commerical products and it's a lot cheaper. with palladium, that incentive leaves.

  10. Easy way to fight it.. by ksemlerK · · Score: 3, Insightful

    :start
    ;
    Lack of consumer demand creates lack of money. Lack of money creates lack of development. Lack of development creates lack of production. Lack of production creates lack of product. Lack of product creates lack of intrest. Lack of intrest creates lack of consumer demand.
    ;
    GOTO start

    If you really want to fight it, the simplest way to go about it is to get it known on the net to Joe User. If enough people are aware of the scheme that MS, Intel, and AMD are planning, people will not want to purchase it, and will even make a concious effort to make sure that thier new computers do not come with this so-called "enhancement".

    When the big three realize that there is no customer base for a product like this, production of Pallidium will cease.

  11. For those of you who don't get it yet... by marm · · Score: 3, Insightful

    ...here's a quick rundown on what I think is Microsoft's strategy with Palladium: it's quite beautiful actually in its cunning, and it's going to be difficult to formulate a solid response to it. It has absolutely nothing to do with stopping Open Source software from running on PCs, as this would be blatantly anti-competitive and PC manufacturers would run away screaming from it. It's more subtle than that. Instead, it is all about the age-old Microsoft tradition of decommoditization of formats and protocols that we learnt so much about from the 1998 Halloween documents, taking this low-ethics strategy one step further.

    Media companies have known as long as almost any of us that the public at large want downloadable digital media - music, films, TV-on-demand. With the growth of broadband and PC ownership this has now become impossible for them to ignore. However, the explosion of P2P networks has also shown Big Media that without effective copy-protection, their content is soon available to anyone and everyone that wants it, without paying them. The media companies see this as a threat, as they think it will cut into their bottom line. From their point of view I think that's a reasonable assumption to make. It doesn't matter whether or not you agree with this or whether this is in fact the truth: the truth is irrelevant. The only thing that matters here is how the media companies see it, because they are the ones with almost all the content the public wants, and they have very deep pockets.

    We've already seen the media companies and their surrogates make attempts at addressing this perceived threat on their own: witness PressPlay, LiquidAudio, SDMI, several CD copy-protection mechanisms and all sorts of other schemes. The trouble is that the media industry is still fairly clueless about the Internet and its users, and lacks the clout to force these schemes on the public, so all of them have so far fallen flat on their face, or have been cracked in no time at all, reducing their copy-protection effectiveness to zero.

    Enter Microsoft and Palladium. Palladium is, in essence, a system which allows Microsoft to verify, through the use of hardware-assisted and hardened strong cryptography, that the PC that Windows is running on does not have any peculiar software or hardware attached that could divert and record an unencrypted digital signal - that is, the PC has a secure, verifiable digital path.

    This is how it works: Each PC has a unique public/private keypair stored on the processor itself, in addition to Microsoft's public key. When Palladium is enabled, the hardware will refuse to run an operating system that is not signed by Microsoft's private key, and then the operating system will refuse to load hardware drivers that have not also been signed by Microsoft, effectively removing any possibility for diverting the unencrypted digital stream. When you download Palladium-protected content, it is encrypted using the client machine's unique public key, so it will only play back on the machine with the corresponding private key. Your access to the content is completely dictated by Microsoft, and because of the verifiable software and hardware in the client machine, there's precisely nothing you can do about it - at least, barring Microsoft's usual quota of bugs, but expect Microsoft to be quite meticulous here. You'll almost certainly always be able to turn Palladium off, but then you won't be able to play Palladium-protected content - you won't have access to the private key stored on the CPU that can decrypt the content. It absolutely will not stop you from listening or watching to unencrypted content, not on its own, anyway, and Microsoft is too smart to cut off its own air supply.

    Microsoft can do this when the media companies failed because they have such total dominance over the whole client PC market and its architecture. Witness how they have already got Intel and AMD onboard to do the hardware side of things. Much of the software required to do this is already in Windows: driver signing, for instance, has been there since Windows 2000, although optional, and encrypted digital rights management has been in Windows Media Player for some time now too. It's plain Microsoft has been planning this for a while and has been doing the whole 'How to boil a frog' thing - i.e., slowly, bit-by-bit, all the time spinning it their own way.

    The media companies will love it: finally they get their secure digital path and can start distributing all their content over the internet, whilst screwing the public out of their fair use rights. No new laws have had to be paid for, although the DMCA and similar laws worldwide will help keep attempted cracking of the system to a minimum. They can gradually start phasing out CDs so that, in ten years time, Palladium-protected content is the only digital content you can get.

    Microsoft loves it because it gives them total control over the whole PC - they can dictate to hardware manufacturers exactly what they can and cannot produce, because if they don't listen, they don't get their drivers signed and the hardware won't run with Windows.

    Once they have a good lead in the amount of content produced for Windows Media/Palladium systems, it gives them an enormous amount of leverage in consumer media products: music players, TV, cable, you name it. Everything media-related will be subject to Microsoft's whims, because without Microsoft's approval, your hardware won't be able to play any content.

    It gives them complete control over what will probably eventually be the media industry's main form of distribution, which will earn them billions. Better still, with downloadable digital content becoming more and more important, it will be a major body-blow to Linux and Open Source - Microsoft will never sign a Linux distribution's kernel so that it can run in Palladium mode, so Palladium-protected content will never ever play in Linux. This will put an enormous dent in Linux's chances as an OS for the desktop - none of the media industry's output will play, and as CD/DVD supply gradually dries up over time, it will put Linux on the retreat back into its server homeland.

    You can bet that eventually Apple will cave in too, assuming Windows Media protected by Palladium becomes dominant. They simply won't have any choice but to side with Microsoft and implement Palladium, because otherwise the supply of available content will dry up, unless there's a revolution in independent, free media. Mac-heads should get on board the anti-Palladium train now, because if you don't, Apple will be just as vulnerable to Microsoft as the rest of us. You simply don't have the desktop share to matter on your own, unfortunately, but together we might.

    It is a domesday scenario for desktop Linux, and pretty ugly for consumer electronics manufacturers, PC peripheral manufacturers, Apple and other non-PC hardware makers, not forgetting of course the public at large. What can be done?

    Well, there's six things that I can think off the top of my head:

    1. Nothing. If Linux/Mac desktop usage can grow quickly enough, then the media companies may be unable to ignore this market. They withhold their media because there is no secure distribution system for it, P2P networks and MP3/Ogg thrive, and we're back to square one. It's possible that P2P networks with a very wide range of freely available media may cause Palladium-protected media to be DOA anyway. I wouldn't want to put all my eggs in this basket though.
    2. Crack it. Always a possibility, and if it comes to pass, then I expect some of the best minds in the world to work at this. There are a few potential areas of attack: getting the unique private key off the CPU and stored elsewhere for decryption when not in Palladium mode. Cryptographic attacks on the Windows Media carrier format, which have already had some success on previous versions. Tricking the hardware into booting an unsigned OS when in Palladium mode. Tricking Windows into loading an unsigned driver (to me this sounds the most promising, given Microsoft's notoriously poor code safety). Any others?
    3. Build an alternative secure digital distribution system that does not shut out Linux and does not give total control to Microsoft. Why not have something simple, like an external decoder/sound card/video output box that accepts crypto smartcards and that the OS only has to send encrypted data to? Why bother getting the OS involved in the decryption process at all? I think this is the most promising of all the options, because the media companies aren't going to give up their requirements for a secure digital distribution system, and they will probably appreciate a system that they control rather than Microsoft. Let's cut Microsoft's air supply off before Palladium gets a foothold and they start doing really nasty things to us. It still involves taking away fair use rights, and this sickens me, but it may be the only way. Palladium does this anyway, so it may come down to simply choosing the lesser of two evils.
    4. Revolutionize the free media. A nice idea, and something to aim for long-term, but unlikely to happen in the short-term. Big Media is just too powerful at the moment.
    5. Discredit Palladium. It worked for Intel's Pentium III serial numbers, it might work now. Invasion of privacy. Your fair use rights being taken away. On the other hand, Microsoft's PR is second-to-none. It'll be difficult, but we should give it a go.
    6. Indict Microsoft for anti-competitive behaviour. Leveraging the desktop monopoly to gain control of digital media? Sound sort-of familiar? I think Palladium is anti-competitive, and from my point of view it's a cut-and-shut case. Microsoft is more careful about these things these days though - Palladium doesn't immediately exclude Real or Quicktime or anyone else for that matter aside from Linux/Open Source, although in practise it probably would. Worth looking into, but with Bush in the White House.... difficult.

    I don't think the war is lost yet, but we need to start fighting. Microsoft has come up with a spectacularly shrewd bit of corporate strategy, and we need an equally good response - very soon.