Slashdot Mirror


Questions for a Lecture on Microsoft's Palladium?

An anonymous reader asks: "Microsoft is going to be giving a lecture on Palladium for my Computer and Network Security class at MIT this Thursday. We're told that it's going to be the most technically detailed lecture publically given to date, and that we should be armed with questions as a result. Any suggestions from the Slashdot crowd? What technical details have you been dying to know about Palladium?" It would be interesting to hear back from someone who is planning on attending this. For those who wish they were, but can't for one reason or another, what would you have asked by proxy?

18 of 568 comments (clear)

  1. Question for MIT students/faculty by Longinus · · Score: 5, Interesting

    Are there any plans to have this webcasted via audio or video, or at the vary least transcripted for our analytical pleasure?

    MIT's page makes no mention of any intention to do this, and seeing how it will apparently be the "most technically detailed lecture publically given to date," I think that the public would benefit greatly from such a service.

  2. An obvious question from the /. crowd by Drunken+Coward · · Score: 5, Interesting

    Maybe it isn't as technical as you want the questions to be, but I'm interested in the answer:

    Can open source software and Palladium coexist?

    --
    Have you been stalked by Seth today?
    1. Re:An obvious question from the /. crowd by GigsVT · · Score: 5, Interesting

      Or:

      Can a system of DRM be devloped that does not rely on security through obscurity at any level, or a crippling of general purpose computers?

      --
      I've had enough abrasive sigs. Kittens are cute and fuzzy.
  3. Target Consumers? by magnum3065 · · Score: 5, Interesting

    I'm curious who Microsoft expects to be the target customer base for this software, do they expect home users, or businesses. Will this be used in general across an office, or possibly only for machines that require high security (e.g. servers with remote access)? It seems that the average home user wouldn't want to be troubled with some of the new security features, and since technologies of questionable legality (mp3, divx, etc.) are becoming popular in the main-stream now, many people would actually be opposed to some of the new security measures. So, since Microsoft has typically targetted an average home user with their products, do they expect to win over the home user market for this new product, or do they simply plan on a small user-base that requires a more substantial amount of security at first, then try to make the system more wide-spread among consumers later?

  4. Re:Wha is the point behind Palladium? by djmagee · · Score: 5, Interesting

    This is what I want to know. How does MS plan to get people to buy into this? How are computer manufacturers going to react when they have fewer, more expensive options for building their computers. And what would make the average consumer see in it? How many people are really that worried about people reading their documents that they'd be willing to give up things like copying CD's, burning mixes, etc...

  5. Corporate liability by paranoic · · Score: 5, Interesting

    Will Microsoft assume liability for when Palladium breaks, or are they going to hide behind some shrink-wrap/click-through agreement that says that they (Microsoft) can't be held liable for anything?

  6. Will there be backdoors? by carlmenezes · · Score: 5, Interesting

    You talk about Palladium being trusted and secure computing. Are there any provisions for backdoors so any content generated by the "secure" technologies can be monitored? If so, how secure will these backdoors be from malicious hackers?

    --
    Find a job you like and you will never work a day in your life.
  7. What if i dont want it? by redback · · Score: 5, Interesting

    What options are likely to exist for people that do not wish to use Palladium?

  8. Re:What's in it for consumers? by Jucius+Maximus · · Score: 5, Interesting
    "More of a basic business question, but didn't anyone learn from Intel's ill-fated processor serial number "feature" in the Pentium III, or the Div-X movie fiasco? Why would consumers want this at all, and why will they choose it over other alternatives?"

    Or conversely, "Why does Microsoft believe that Palladium will earn a positive cash flow for the company, satisfy return on investment, etc, in the long run?

    Essentially, "what's in it for YOU?" This could reveal some interesting information about their long term strategy and core motives.

  9. Re:Demand? by TellarHK · · Score: 5, Interesting

    What do you mean "playing with nothing less than the death of the general purpose processor", they're openly -banking- on it. Microsoft has wanted to kill off the idea of the "Personal Computer" ever since they realized being a monopoly and letting other people work with the same hardware, building on their software layer was going to be a losing gamble in the long run.

    They want to lock everything down and help the industry along back to the era of computing devices, rather than flexible, expandable, personal computers. This new "Freestyle" media center is just the beginning if you think about it. You can't -buy- a Windows Media Center license, you have to buy the software installed on a Microsoft-approved machine. Unless the software industry as a whole fights back against this push, we'll see the death of PC's within the next 10-15 years and the rise of a more fragmented, more expensive series of black boxes.

    Why should Microsoft include DirectX in a PC when they have Xbox? Why allow people to build whitebox machines and risk them installing someone else's OS on it when they can tear the PC apart and make multiple "appliances" that conveniently link together bit by bit in order to become what people want? Snap your internet module into your media module, then connect your IO module and run the whole thing on WindowsCE 2010.

    Call me paranoid, but I'm really afraid they'll find a way to make this profitable for the whole industry and completely kill the hobbyist when it comes to the new gear down the road.

  10. A line of Questions by Sylver+Dragon · · Score: 5, Interesting

    1. Will it be possible, as a home user, to create and digitally sign a creative piece of work? Such as, a home movie?

    2. What ramifications will this have on digital content created before the introduction of Palladium? Will it still play?

    3. Will the information necessary to create a Palladium enabled viewer be available to public? Or will we only be able to use Windows Media Player to play Palladium enabled content? What are the projected licesing costs for a company that wishes to create a viewer that is able to view Palladium enabled content?

    4. Will hardware that requires a signature be able to run content that does not have one? (if yes) Will this then mean that any software that pre-dates the hardware must be upgraded? (if no) Then how will this system differentiate between a desired, older, program, and a virus?

    --
    Necessity is the mother of invention.
    Laziness is the father.
  11. Comment removed by account_deleted · · Score: 5, Interesting

    Comment removed based on user account deletion

  12. I think a lot of you are missing the point... by Lethyos · · Score: 5, Interesting

    "Microsoft is evil, blah blah blah..."

    Now that's out of the way, let me remind you that there's a lot of truth to this often repeated statement. Palladium is, in a lot of ways, a cool, if horribly unoriginal technology (the concept of making software dependent on the presence of hardware to run has existed since dongles).

    Regardless of how cool, funny, or "weak" it is as many of you claim, Palladium has two purposes. 1) Palladium is meant to make other deep-pocketed interests happy (more money for MS). 2) defeat any and all competition to Microsoft products.

    It's very clear: Microsoft has the say-so in what code gets to execute on a Palladium-tainted computer. What code do you think will be allowed to execute?

    You will argue: "It will be cracked." "We can stick with old computers." "This will not be accepted by businesses/consumers." But those arguments are either irrelevant or fall flat on their faces.

    First of all, I agree. It will be cracked without a doubt. But do 99% of the users out there know how to use such cracks to free themselves? Do any of you crackers out there realize how complex this system is?

    Second, we cannot stick with old computers. This is evident by the fact that there are hordes of users out there running 1GHz processors with half a gigabyte of RAM for the purposes of checking their email. Plus, software will always get more sophisticated and people will always want higher framerates, and so on. New computers will be purchased.

    Last, of course consumers and businesses will buy up Palladium hardware! This is, without a doubt, the most absurd assumption anyone can make! "People don't want another DivX!" "People don't want to give up their rights!" Bullshit. People do not even know what their rights are. Not to forget that marketing spins already exist that are meant to convince people that they are getting something (increased security) when they are having something taken away. (Apologize to the guy who coined that phrase.)

    Palladium is very real, and it is a very real threat. It will be adopted if it is allowed to continue. Even if we educate the public, it will press on (after all, users running Windows left and right, despite superior alternatives)? Sadly, I have no suggestions on how to deal with it... but we must certainly not take it as a laughing matter.

    --
    Why bother.
  13. Re:What's in it for consumers? by yorgasor · · Score: 5, Interesting

    Are you really trying to just obsolete all your old software so everyone is forced to upgrade to your latest and greatest OS & computers just to be able to make basic transactions on the internet?

    --
    Looking for a computer support specialist for your small business? Check out
  14. Re:No, don't do that under any circumstances! by SiliconEntity · · Score: 5, Interesting

    What kind of data recovery plans will exist if I buy $1000 dollars worth of digital music that is tied to my processor, only to have my processor get fried in a power surge? Will there be any way to recover my investment, or is it lost? If so, what's to prevent hackers from using that recovery mechanism? If not, how can this be a benefit to customers?

    Microsoft hasn't said how this would work, and it is certainly a good question. But I don't agree with your implication that it is somehow an unsolvable problem or indicates that Palladium must be weak.

    The related TCPA scheme did have a proposal for how to deal with this. The idea is that your crypto chip has a key in it that encrypts all this data. You can get it to export this key in a "blob" that can only be decrypted by the manufacturer. (Actually the key is exported in two parts, one in the clear and one in the blob, that have to be XOR'd together to recover the real key.)

    If your crypto chip dies, you buy a new computer or motherboard with a new chip. You send the backed-up blob and the new chip identifier to the manufacturer, who decrypts the blob data and re-encrypts it for the new chip, and sends it back to you. You then enter this into the new chip, along with the other half of the key, and presto, your new chip is initialized with the same key that was in the old one. So your new computer can read the data that was locked to the old computer.

    This is all done in such a way that neither you nor the manufacturer ever sees the crypto key, so the data is still protected.

    Now, this is pretty cumbersome, and maybe Microsoft will come out with something better. If this is really going to be a detailed technical presentation, this would be an excellent question to ask. Just don't assume they can't answer it!

  15. Re:Ramifications for Independent Content by spitzak · · Score: 5, Interesting
    You don't seem to understand the question.

    If there is a player that plays unencrypted content, then it is possible to copy movies. It only needs to be copied once, perhaps by a hacker with hardware modifications, or by pointing a video camera at the screen, and then can be played everywhere.

    If only encryped content can be played, then it does not matter if some hacker makes a copy, it cannot be played on most people's machines. Every single machine would have to be hacked to enable it to play some new player that allowed unencrypted content. The security to IP is enormously greater with such a system, ie hundreds of millions of times more secure, so much greater that the drive to enforce this system will completely squash any morals or promises by a few people at MicroSoft.

    But how will parents send grandma their videos of their baby? The answer is they won't, and they will forget the fact that there was once a time when a recording could be removed from one device and put into another. Or more likely they will be able to do it with a live connection through a trusted 1:1 connection from their camera to grandma's desktop.

    Nobody will be able to record music, make movies, and possibly even publish text without a license from a media conglomerate.

    I believe this is going to happen if these schemes are not stopped now.

  16. A good attack question! by Alsee · · Score: 5, Interesting

    Won't Palladium delay the release of critical security patches, leaving computers vulerable to attack?

    This question should probably be saved until some of the groundwork for it has been already been covered. Here's the basis for it...

    Palladium programs and any Palladium data can only be used on a trusted nub ("nub" basicly means kernal). Any changes to the nub are going to have to be submitted for approval as a new trusted nub. How long will this approval process take?

    I think they plan an "independant" body to certify/sign a nub as trusted. If so point out this will massively delay the release of their security fixes.

    If Microsoft plans to do their own certification that their nub is trustworthy then point out that they are leveraging their 90+% marketshare to create a monopoly on trusted nubs and all commercial use of Palladium.

    -

    --
    - - You can't take something off the Internet! That's like trying to take pee out of a swimming pool.
  17. Can an interpreted language run under Palladium? by Scarblac · · Score: 5, Interesting

    Say I write something in an interpreted language, Python, Perl, Java, whatever.

    The interpreter binary that runs the code is signed, totally officially Palladium-fine.

    Then I can write any Python code that does whatever, can't I? You can't sign the ASCII source code.

    I conclude that any language interpreter, or any application that has any sort of scripting language (say IE, Outlook, Word) can't have any means of breaking out of DRM in the language or it won't be certified. This is unbelievably crippling.

    --
    I believe posters are recognized by their sig. So I made one.