Slashdot Mirror


AMI Introduces 'Trusted Computing' BIOS

An anonymous reader writes "American Megatrends announced its 'trusted computing' Palladium BIOS on Jan 6. It seems that the encrypted BIOS' integrity will be verified by a special chip or flash ROM, and will in turn verify the 'authenticity, integrity and privacy' of the boot loader and the operating system. Does that mean such machines may refuse to boot any other non-'trusted' OS? After all, the list of supporting corporations include AMD, Intel, IBM, and HP, of whom we heard quite favourable statements about Linux (just for example -- *BSDs will be equally affected) so far."

617 comments

  1. The Inquirer has more info by dudeX · · Score: 2, Informative

    If you read the Inquirer www.theinquirer.net , they cover this announcement.

    A representative from AMI explains some of the ideas behind the Trusted Computing initiave.

    1. Re:The Inquirer has more info by grumpygrodyguy · · Score: 3, Insightful

      I will never buy one of these systems in my lifetime.

      --
      The government has a defect: it's potentially democratic. Corporations have no defect: they're pure tyrannies. -Chomsky
    2. Re:The Inquirer has more info by SlowGenius · · Score: 1

      Agreed. In fact, I think this is a great time to start boycotting ALL AMI-based systems. (Maybe Intel, too... Big Brother really needs to be kept in place with a few good bitch-slaps now and then.)

      --
      Listen to what I say, not what I mean...
    3. Re:The Inquirer has more info by Superkind · · Score: 1

      Sooner or later you simply don't have a choice anymore. All the talk about boycotting AMI (or whatever other company) is so damn useless. People who know enough about Palladium & Co to know that they don't want it are a minority. The rest just hears the marketing divisions' talk--they think it's actually good for them. Who care's if you buy it? Nobody does.

      --
      (In desperate search for a cool /. sig.)
    4. Re:The Inquirer has more info by kien · · Score: 2

      I will. Then I'll crack the everloving shit out of it. The angst that I'll feel about giving my money to any company that supports this kind of crap will (hopefully) be replaced by joy when I (or others) prove what an utterly futile concept 'Trusted Computing' really is.

      --K.

      --
      Sig: Bad people happen. Try to avoid being one of them.
    5. Re:The Inquirer has more info by Anonymous Coward · · Score: 0

      That is why the people will never have any rights in the fucking country, because of all the fuckheads that think like you. I think we should just support Iraq and North Korea. Shit we are on our way to adopting their government. When will people pull their heads out of thier asses????????

      Your just a minority that has a clue... boo hoo hoo...

      I be sheep and I be following the "s" "m" "r" "t" ones.

    6. Re:The Inquirer has more info by j3ss · · Score: 1

      I predict that six years from now we will all be downloading hacked BIOS images to flash our computers with to disable this technology.

    7. Re:The Inquirer has more info by daniel23 · · Score: 1

      > I predict that six years from now we will all be downloading hacked BIOS images to flash our computers with to disable this technology.

      Agreed. And - we'll have learned to distinguish American hardware ("trusted") from Chinese ("real").

      Real in more than one sense. 'cause except from some core countries - (fanatically dedicated to 'free' trade/liberty/new world order and consequently banning the import of foreign stuff, this group is also kown as the "u"-countries, us, uk, uganda) - the rest of the world more or less agreed to avoid those "constant alert" systems.
      With China (PRC + Taiwan + HK + Sgp + Huaqiao in Malaysia and elsewhere) controlling 60 - 70% of the hardware business, actually producing half of the American-style boards as well, that decision wasn't hard to be done.

      And us outlanders don't miss much, that Indian "Roq" Dual-Mode BIOS has quite frequent updates and - except for some of the pr0n stuff - emulates pretty well.

      Some things have changed, though, hackers theese days learn Hindi or Tamil in their spare times :-}

      --
      605413? Yes, it's a prime.
    8. Re:The Inquirer has more info by Superkind · · Score: 1

      Did I make any statement on my opinion? I like this TCPA and/or Palladium stuff as much as anybody here. But take a look at the facts. You got a DVD drive/player? The hardware industrie already tries to dictate what content you can consume. TCPA is just a step further down the road. Open your eyes.

      --
      (In desperate search for a cool /. sig.)
    9. Re:The Inquirer has more info by Superkind · · Score: 1
      Unfortunately your BIOS won't let you flash it. If you rip the chip out and replace it with an EPROM your new BIOS won't be verified correctly and your computer won't even boot. Great job. :)

      Non-flashable BIOS? Not a myth. I got one of the last Pioneer DVD-ROMs that let you flash the BIOS. Newer ones stick with whatever region code you "teach" them by playing DVDs.

      --
      (In desperate search for a cool /. sig.)
    10. Re:The Inquirer has more info by Anonymous Coward · · Score: 0

      I predict that BIOS chips will no longer be flashable.

    11. Re:The Inquirer has more info by SerpentMage · · Score: 2

      Yeah but my DVD drive is code less.....

      They are very popular here in Europe!

      The point is that the consumer chose DVD drives without encryption built in.

      --

      "You can't make a race horse of a pig"
      "No," said Samuel, "but you can make very fast pig"
    12. Re:The Inquirer has more info by Anonymous Coward · · Score: 0

      That's fine, but this is why Linux will take over. And if you think you won't be able to use Linux on your PC you are greatly mistaken.

  2. War on terror by Anonymous Coward · · Score: 5, Funny

    This will go a long way towards the war on terror. Terrorists wont be able to install and use unauthorized OS's. This could potentially save thousands of lives.

    1. Re:War on terror by GeekWithGuns · · Score: 2, Funny

      <sarcasm theme="following from previous post">

      By "War on terror" you are talking about Bill Gates' war on terror right? He is quite "terrorized" by the though of people being able to choose their software vendor based on the merits of the product and not by what is forced down there throat. If you run something other than the latest version of M$ Window$ "the terrorists have won".

      </sarcasm>

      --
      [End of diatribe. We now return you to your regularly scheduled programming...] - Larry Wall in Configure from the perl
    2. Re:War on terror by Anonymous Coward · · Score: 5, Insightful

      Just like it is so difficult to buy a PC from a major vendor that does not already have Windows, they will also eventually try to make it impossible to buy one that does not have DRM on it which only allows you to run a policed DRM OS, read: Microsoft Windows.

      Fight this all the way. Intel didn't get it when they put the ID on their chips until we decided not to buy it. In the same vein, AMD won't get it that we don't want DRM until we (unfortunately, since I actually like them) tell them to go to hell.

    3. Re:War on terror by nmg · · Score: 1

      He is quite "terrorized" by the though of people being able to choose their software vendor based on the merits of the product and not by what is forced down there throat.

      Why is it that people cannot do this right now?

    4. Re:War on terror by Henry+V+.009 · · Score: 4, Offtopic

      I think the slashdot moderators misunderstand the mechanics of slashdot meme creation. It all starts out with some inane, yet generally applicable, statement getting modded up to 5. It's read by tens thousands of slashdoters who imprint the idea on their psyche. From then on, there is usually at least one, but possibly several, posters who feel the need to update the comment for each new article--really the comment has gone beyond a simple joke for these poor souls, it becomes almost a mystical experience each time they post. I imagine it's almost like they are communing with their god. Simply the way the brain works. Christianity and Islam and Judaism all started out the same way. You start off with some nut with an seemingly inexplicable ability to influence large groups of people to do idiotic things, and suddenly you have a beowulf cluster of hot grits getting poured all over a dead BSD system. In soviet Russia, of course, it's the other way around.

      What I'm trying to say, I guess, is that memes are powerful things. So use your mod points for interesting and thought provoking posts relevant to the subject at hand. You don't have to mod a lot of stuff down, but show some restraint in modding junk up.

      I mean, do we really want the second coming to occur during in some long post about Natalie Portman and the basalt content of her nude body?

    5. Re:War on terror by UberLord · · Score: 1

      I mean, do we really want the second coming to occur during in some long post about Natalie Portman and the basalt content of her nude body? I'm an atheist. So lets talk about the asthetic appeal of Natalie ;)

    6. Re:War on terror by Anonymous Coward · · Score: 0
      If you:
      • smoke pot
      • drive a SUV
      • don't recycle
      • use Microsoft products
      then you can be financing the terrorists in Saudi Arabia, Pakistan and even helping Saddam make weapons of mass destruction!

      --
      "the CIA is saying that Saddam Hussein has 'Bioterrorism labs on wheels' down there in Bagdad. Well, we also have those here in New York City -- only they're called 'food vending carts'."
      David Letterman
    7. Re:War on terror by Anonymous Coward · · Score: 0

      Thank You, George W. Shithead

    8. Re:War on terror by Henry+V+.009 · · Score: 1

      It would be wise to start with a common point of reference. I would point out, however, that atheists are as vulnerable to memes as the rest of humankind--the few pounds of gray matter we all carry around above the neck seems to act as a single point of failure. These days--as opposed to a few hundred years ago when being an atheist actually meant something--it's almost rare to meet an atheist who has arrived at the viewpoint because of a genuinely skeptical temperament. I think that the problem was communism. Communism was a cult in a lot of ways--reasons for both its initial success and eventual collapse--and it made atheism popular for the masses. Personally, if atheism gets any more popular, I'll be in the mood for a revival.

    9. Re:War on terror by ReelOddeeo · · Score: 5, Insightful

      Just like it is so difficult to buy a PC from a major vendor that does not already have Windows, they will also eventually try to make it impossible to buy one that does not have DRM on it which only allows you to run a policed DRM OS, read: Microsoft Windows.

      Given the current number of non-US governments (various South-American, Japan, Germany, UK ?, Malyasia, China, Tiwan, South Korea, Isreal, Pakastian, probably others I've forgotten in the frequent Linux Today announcements) jumping on the open source bandwagon...

      Given the Chinese governments' interest in developing their own microprocessors (Dragon? recently on Slashdot)...

      I don't think that the forces of evil can force every PC everywhere to have DRM.

      As long as some PC's can freely run any software, there will always be ways to defeat DRM. Or said differently, without total control, they control nothing.

      Given that there will always be somebody powerful enough that doesn't want DRM, or at least, wants Free software, the DRM folks will never get total control.

      --

      Those who would give up liberty in exchange for security and DRM should switch to Microsoft Palladium!
    10. Re:War on terror by DickBreath · · Score: 1

      >> I mean, do we really want the second coming to occur during in some long post about Natalie Portman and the basalt content of her nude body?

      >I'm an atheist. So lets talk about the asthetic appeal of Natalie ;)

      There is none, so let's not.

      --

      I'll see your senator, and I'll raise you two judges.
    11. Re:War on terror by operagost · · Score: 0, Troll

      Humanism is the religion of the atheist, and one's mind- the product of social programming- the god. The atheist thinks he is superior intellectually and spiritually free, but merely has bowed down before his own ego.

      --

      Gamingmuseum.com: Give your 3D accelerator a rest.
    12. Re:War on terror by ArsonSmith · · Score: 3, Insightful

      sure they can, that is what Billy boy is trying to stop with this new inititive.

      --
      Paying taxes to buy civilization is like paying a hooker to buy love.
    13. Re:War on terror by W32.Klez.H · · Score: 0

      yeah, you tried to be funny, it didn't work, but I won't hold it against you too much.

    14. Re:War on terror by The+Bungi · · Score: 1, Funny

      "+5, Funny"???

      He didn't add a smiley... did anyone stop to think he might have been serious?

      Here's mine: =)

    15. Re:War on terror by Anonymous Coward · · Score: 0

      Second coming, Natalie Portman, and nude body in the same sentance. Really, I don't think he was talking religion here.

    16. Re:War on terror by Anonymous Coward · · Score: 0

      No Problem, William J. Cocksucker

    17. Re:War on terror by Anonymous Coward · · Score: 0

      As long as some PC's can freely run any software, there will always be ways to defeat DRM. Or said differently, without total control, they control nothing.

      Well said. Well said. Well said. Mod this guy up.

    18. Re:War on terror by Narcissus · · Score: 1

      Just a small correction for you: it's AMI doing this, not AMD. I, too, am a big fan of AMD, but I don't really care too much who writes my BIOS.

    19. Re:War on terror by killmenow · · Score: 1
      I mean, do we really want the second coming to occur during in some long post about Natalie Portman and the basalt content of her nude body?
      coming...Natalie Portman...nude body...must...focus...hmmm...Natalie...baby...

      What was it you were saying?
    20. Re:War on terror by Anonymous Coward · · Score: 0

      At least on Fark they embrace their cliches not shun them and moderate them into oblivion. Slashdot isn't any fun anymore. Posting humorous comments about BSD dying and Natalie Portman being naked and petrified just gets you modded down as a troll these days. Bring back embedded HTML in the comments section, bring back the image tags so we can post funny photoshopped images. Make Slashdot FUN AGAIN FUCKERS! Bah, time to go read fark again.

    21. Re:War on terror by yourmom16 · · Score: 1

      If you are talking about the cpuid on the itenium processors you should know only 1 of the 4 CPUID registers contains the serial numbers. The others contain info about the processors manufacturer, and features and stuff, which are more useful than harmful.

      --
      "We have got to make Stan understand the importance of voting, because he'll definitely vote for our guy." - South Park
    22. Re:War on terror by kien · · Score: 3, Insightful
      As long as some PC's can freely run any software, there will always be ways to defeat DRM. Or said differently, without total control, they control nothing.

      Right on. And even if you live in the US... remember that there are such things as soldering irons and oscilloscopes. Hey, you mastered Linux right? Comparatively speaking, the laws of Ohm and Kirchoff are n00b material. Even an AOL luser could learn! (Ok, that might be stretching things.) :)

      --K.
      --
      Sig: Bad people happen. Try to avoid being one of them.
    23. Re:War on terror by Anonymous Coward · · Score: 0

      Humanism is the religion of the atheist, and one's mind- the product of social programming- the god. The atheist thinks he is superior intellectually and spiritually free, but merely has bowed down before his own ego.

      Yes, know please pass the donation tray.

      and...fuck you.

    24. Re:War on terror by Anonymous Coward · · Score: 0

      in soviet russia God communes with YOU!

    25. Re:War on terror by oPless · · Score: 3, Funny
      QUOTE:

      I mean, do we really want the second coming to occur during in some long post about Natalie Portman and the basalt content of her nude body?


      Ohhh, excuse me, while reading that, I just come - twice. - Does that count?
    26. Re:War on terror by DunbarTheInept · · Score: 3, Insightful

      Humanism is the religion of the atheist

      To transform this trolling post into a truthful statement, replace the words, "the" and "the", as follows: "Humanism is a religion of some atheists."

      Thank you.
      --

      Don't label something "offtopic" unless you know the topic well enough to tell what's on topic.

    27. Re:War on terror by geekee · · Score: 2

      There's nothing in the article that claims you can't run a non-trusted OS using their BIOS. It simply tells the system what it found.

      --
      Vote for Pedro
    28. Re:War on terror by geekee · · Score: 3, Insightful

      Ahh, if you don't want DRM, don't run DRM based software. The hardware only does what the software tells it too do. There is nothing in the atricle claiming the BIOS will refuse to boot non trusted OS software.

      --
      Vote for Pedro
    29. Re:War on terror by Anonymous Coward · · Score: 0

      Yes, now they will be able to install a flavour of MS etc and then use the hardware crptography whenever they like... and I can assure you that they will find a way of adjusting the hardware so that it runs a different key that MS, NSA, CIA or FBI don't have.

      At that point the terrist has won as his/her system is now completely encrypted for secret communications. Add a dash of PGP on top of that, and it will take months to crack the keys with the current systems, long enough to allow a Terrorist to attack any location within that time frame.

    30. Re:War on terror by Anonymous Coward · · Score: 0

      I know that and you know that, but there would be no Slashdot without the hilariously uninformed fear mongering.

    31. Re:War on terror by Master+of+Transhuman · · Score: 1

      While reading a short sentence, you came - twice?

      I'm glad I am NOT your girlfriend...

      --
      Richard Steven Hack - This sig is TOO GODDAMN SHORT TO DO ANYTHING USEFUL WITH! MORONS!
    32. Re:War on terror by Justus · · Score: 1

      Ironically, you're merely continuing another meme with your post; every time someone posts a rehash of an old joke, there's inevitably a few posts that talk about how old the joke is and how we should all stop posting about it.

      Of course, this is merely part of the complaining-about-people-who-complain-about-old-jo kes meme, so it's all rather pointless.

    33. Re:War on terror by Goldsmith · · Score: 0

      I don't know, I'm teaching an electronics lab right now, and there are a whole bunch of budding EEs and CEs who don't seem to get it.

    34. Re:War on terror by kien · · Score: 2

      That's scary and perhaps indicative of a larger problem. What keeps you from flunking the students that don't "get it"?

      The issue of a teacher's ability to inspire curiosity in the student is also relevant to your statement (although I don't mean to imply that you are a bad teacher). Might make for a good Ask Slashdot discussion.

      --K.

      --
      Sig: Bad people happen. Try to avoid being one of them.
    35. Re:War on terror by Billly+Gates · · Score: 2
      Thats not the point.

      If Linux can not be installed without modified hardware in %97 of the worlds computers then its DEAD!

      Sure you may be able to play with it by getting your soldering iron but Linux will fail in the marketplace and many opensource developers will abandon it. They will write there software for Windows and it will not be GPL since the .NET eula forbids it.

      If you do not have %100 control of your system then you do not own it. These words are from Jack Valentini and not myself.

      Bill Gates will own %97 of the worlds computers and there is shit you can do about it.

      Linux will be a mac only project in the future or will turn into Xenix aka SCO OpenServer which requires a special set of hardware to run reliably. Special non drm hardware will be needed to run linux so this is why I am convinced it will die a SCO like death.

      Its pretty sad when macintoshes are considered less proprietary then x86 ones.

    36. Re:War on terror by kien · · Score: 2
      No need to panic.
      If Linux can not be installed without modified hardware in %97 of the worlds computers then its DEAD!

      That's a valid point. If 97% of the world's computer users adopt the BOHICA attitude, then I'll leave them to their fate. But anyone challenging my ownership of my computer will hit the brick wall that is my will. My optimistic, idealistic, and perhaps naive gut instinct is that they will just stop buying PCs that can't perform all of the functions that they're used to.

      If you do not have %100 control of your system then you do not own it. These words are from Jack Valentini and not myself.

      I'm having a hard time understanding your point. I have 100% control of my systems and...ummm, Jack's an ass.

      Bill Gates will own %97 of the worlds computers and there is shit you can do about it.

      And this has been proven...how?

      Linux will be a mac only project in the future or will turn into Xenix aka SCO OpenServer which requires a special set of hardware to run reliably. Special non drm hardware will be needed to run linux so this is why I am convinced it will die a SCO like death.

      Fair enough. That's your prediction of the future. Here's my bet: People like you will continue to espouse the philosophy that it's hopeless to resist. People like me will invalidate people like you by making the people that bent you over irrelevant.

      --K.
      --
      Sig: Bad people happen. Try to avoid being one of them.
    37. Re:War on terror by YE · · Score: 1

      Yeah, sure, given the Chinese' Communist Party long history in providing even more freedom to their citizens, I'm sure all they want from open source software is freedom and battling the forces of evil.

      And not some absurd thing like embedding government-trusted-information-only deep in the OS.

      Do you really thing that the Chinese government will release the sources of their modifications? They have violated all kinds of international laws on many occasions, but you believe the GPL will shine a light in their hearts and they will magically start to heed it?

      Your post expresses the absurd notion that a corporation wanting to deny you access to a pirated Britney Spears single is much, much more evil than a government wanting to throw you into jail for criticizing it.

      The inherent advantages and disadvantages of OSS make it as good a vehicle for tyranny and cenzorship as it might be for freedom.

    38. Re:War on terror by Cally · · Score: 2
      >I don't think that the forces of evil can force
      >every PC everywhere to have DRM.

      But they don't have to. Consider what will happen if every PC sold with Windows - not just home systems, but corporate desktops too - are unable ever to boot a Free OS. For those enterprises or homes to switch away from Windows, they will be forced to replace all their hardware. And you can guess how likely that is.

      Consider then that PC manufacturers will have the choice of producing "Untrusted" mobos / BIOS - but that they'll have to do so *as well as* producing Palladium-crippled products (as the vast majority of their customers, in America and Europe anyway, will be buying same.) OK, some niche companies may offer unrestricted hardware for specialised vertical markets, such as those governments you mentioned. How many of these boxes do you think will be in PC World, Dixons, or whatever the US equivalent of these High St chains are?

      Palladium is a brilliant strategy from the Microsoft "World Domination" playbook. No wonder they're backing it so strongly. As far as the general public are concerned it's a pure win - it's only those of us in the Free/Open/ *nix communities who have the slightest idea why this will be such a catastrophic technology.

      --
      "None are more hopelessly enslaved than those who falsely believe they are free." -- Goethe
    39. Re:War on terror by brightertimes · · Score: 1

      Hey Keien,

      Right on! Im sat here reading these post's on slashdot, and I don't know whether to laugh or cry.

      Now as for DRM being in every computer NO.. NO.. NO!!

      Doesnt work like that.

      What it means is that you will be able to run a non DRM operating system, but you may not be able to run some DRM software, openoffice will never ever be DRM encumbered. If office is then fine, but will you really miss it?

      Also lets look at DVD'S. Region protection and DeCss etc, I could go into almost anystore today and buy a DVD player and un-region lock it in a matter of seconds. Most players come default with overrides.

      Thirdly, remember last year when they were going to put DRM in hard drives and a big portion of the slashdot crowd were going to boycott IBM and the other manufacturers who were going to do this dastardly deed? Well, it hasn't happened yet, nor likely will it. See, there is more to the world than the us, china and japan and korea and all the other counteries which build harddrives are not going to go along with this because it's just as profitable not to!

      Think lik-sang! Yeah ok.. so they had a bit of trouble, but how popular were they? Because (in some ways) went against the grain of what the electronics companies (sony etc) wanted and provided what people want.

      DRM will not take a stranglehold, just like they closed napster, kazaa and overnet appeared. When and if they go down? Another will pop up.

      Trust me folks, there isnt anything to worry about.

    40. Re:War on terror by m_frankie_h · · Score: 1

      AMD ~= AMI

    41. Re:War on terror by m_frankie_h · · Score: 1

      Oops, I mean !=.

      The article is about AMI (American Megatrends), not AMD (
      (Advanced Micro Devices, IIRC)

    42. Re:War on terror by Hellkitten · · Score: 2

      There's nothing in the article that claims you can't run a non-trusted OS using their BIOS. It simply tells the system what it found.

      There is going to be one problem though, with dual booting a trusted OS and an untrusted one

      For the chain of trust to work the bootloader has to be trusted, and you can be sure that the provider of the most used trusted bootloader (ms) will make sure it won't load linux (even when TCPA is disabled)

      This means that you'll have to buy a third party trusted bootloader that can load linux and windows, or keep switching boot devices in the bios. And who do you think is going to buy any company that even talks about selling a custom trusted bootloader?

      I think at the least this means goodbye to painless multibooting, yet another reason to dump windows once and for all.

      --
      - We are the slashdot. Resistance is futile. Prepare to be moderated -
    43. Re:War on terror by itsnotthenetwork · · Score: 1

      Speaking of the CPU ID. Have you noticed that the newer BIOS's don't have the option to disable that anymore ?

    44. Re:War on terror by Fig,+formerly+A.C. · · Score: 2

      When I took my EE labs, it was amazing how many people just didn't get it. Then again, the professors insisted on teaching Ohm's Law with calculus instead of algebra, which makes it harder to grasp the basic concepts at work.

      --
      Murphy was an optimist.
    45. Re:War on terror by jandrese · · Score: 2

      What crappy P3 bioses are you getting anyway? I've never seen a P3 bios that didn't include an option to disable the CPUID. Heck, in almost all cases, it is off by default. Not that it matters, since Intel didn't put it in the P4, the CPUID is dead. Nobody uses it.

      --

      I read the internet for the articles.
    46. Re:War on terror by hesiod · · Score: 1

      > if you don't want DRM, don't run DRM based software

      I have wondered a bit about this point. Admittedly, I haven't read even a small percentage of all info on DRM, but I was under the impression that DRM would ask if you wanted to run the untrusted software, warning you that it isn't signed. This is quite a bit different than refusing to run the software, so assuming I am correct in this, you have created a simplisticly enlightened answer that I think is best.

      (ooh, long words I didn't need to use!)

    47. Re:War on terror by nmg · · Score: 1

      Once again, how can he make people stop? If you don't want this BIOS or whatever, don't buy it.

    48. Re:War on terror by Anonymous Coward · · Score: 0

      The so-called war against terror (as CNN is tempted to call it) now serves as the reason behind everything, eh?

    49. Re:War on terror by ArsonSmith · · Score: 2

      I think you are missing the point of market choice. The choice is to buy one or the other not one or none.

      saying you can either buy bios with this in it or you can not buy any bios is not a market choice.

      if they find a way to make sure no one is allowed to make/market bios without drm/palladium in it then you no longer have a real choice.

      --
      Paying taxes to buy civilization is like paying a hooker to buy love.
    50. Re:War on terror by oPless · · Score: 2

      c'mon, like it's Natalie Portman!

    51. Re:War on terror by Anonymous Coward · · Score: 0

      I don't understand the Department of Justice nor the indifference of the consumer who cannot choose anything Bill Gates does not want. Do they really think it is for security reasons that these mesasures are being implemented? Bill and DOJ are the real terrorists. They terrorize all of those whose money is spent on software they cannot use. Now are trying to eliminate competition. Palladium (and everything that looks like it) is a shame to America, and to what it means to be free. Free only to to what Bill wants. How can we have come to this point?

  3. Not this time around... by Kjella · · Score: 5, Interesting

    Does that mean such machines may refuse to boot any other non-'trusted' OS?

    I'm pretty sure it won't. For now it'll just not have a trusted signature, so no access to Palladium-protected content. But I'm pretty sure that's the bait of a bait&switch operation...

    Kjella

    --
    Live today, because you never know what tomorrow brings
    1. Re:Not this time around... by briancnorton · · Score: 4, Interesting

      Palladium as I understand it has NO APPLICATION for content protection. It's not a DRM system. It's a security function so that your hardware knows what it's doing. It will provide a level of security between applications, the OS, and hardware. You should never know that it's there.

      --

      People who think they know everything really piss off those of us that actually do.

    2. Re:Not this time around... by Em+Ellel · · Score: 1

      So why can't I write my own BIOS (or mod some other BIOS) that will provide a known good signature regardless of the OS booted?

      --
      RelevantElephants: A Somatic WebComic...
    3. Re:Not this time around... by micromoog · · Score: 5, Insightful
      You should never know that it's there.

      Provided you only use Palladium-approved hardware. And applications. And operating system. And you don't want to make your own software. Or MP3's.

    4. Re:Not this time around... by KDan · · Score: 2, Interesting

      Well, you just know it won't take long for Palladium to be used for DRM purposes, so I keep my hopes that it won't take too long for people to find ways around these Palladium chips. I'm thinking of people like demo-makers and such, who know how to push hardware beyond its limits. After all, if you can get a DOS screen to display 32-bit colour gradient bars, you can probably also get a Palladium chip to authorize an OS that it shouldn't... And if those people fail on the software side, there's always the mod chip makers in Asia :-)

      In any case, I hope I won't be the only one who will refuse to buy a computer with a Palladium BIOS.

      Daniel

      --
      Carpe Diem
    5. Re:Not this time around... by phurley · · Score: 1
      I do not disagree that the current documentation for Palladium shows that it does not provide public unique key information (on top of which DRM could be tied to a particular machine). But the core technologies would allow a trusted identity process do just that and then you could use Palladium to support content protection.

      --
      Home Automation & Linux -- now I know I'm a geek
    6. Re:Not this time around... by 7-Vodka · · Score: 2

      why has this been modded up? palladium is ALL ABOUT DRM and content control.

      --

      Liberty.

    7. Re:Not this time around... by Anonymous Coward · · Score: 0

      "It's a security function so that your hardware knows what it's doing. It will provide a level of security between applications, the OS, and hardware."
      Are you listening to yourself right now?!?

      "You should never know that it's there."
      Yeah, until it tells you that since you tried loading Linux, you can no longer use your machine.

      Oh, and by the way, the police are on their way.

    8. Re:Not this time around... by Tom7 · · Score: 4, Interesting

      Uh, then I think you understand. Palladium is designed essentially to prevent you from using debugging hardware or software to circumvent copy-control mechanisms. It is a key ingredient in the enslavement of the media consumer. What do you think it's for, and how do current OS techniques not address that?

    9. Re:Not this time around... by briancnorton · · Score: 2

      And where did you find this out? Point me somewhere that says this? Read the documentation, dont jump to conclusions.

      --

      People who think they know everything really piss off those of us that actually do.

    10. Re:Not this time around... by Anonymous Coward · · Score: 0

      What if I don't "log on to the internet" from home? Can't I still infect myself with an 'unauthorized' OS? This is really scary. They should have engineered it bester.

    11. Re:Not this time around... by Anonymous+CowWord · · Score: 1

      Palladium as I understand it has NO APPLICATION for content protection. It's not a DRM system. It's a security function so that your hardware knows what it's doing.

      Ideally, yes, you are correct. However, how long before its turns into a tool for enforcing DRM?

      If palladium is a "security" feature, why not make it make it optional? As a user, it is MY system, if I choose to leave it insecure, so be it. And if other sites won't let me go to them or place secure orders or whatever, to hell with em. I should have the right to choose, not the people whom I buy hardware/software from.

      --


      Disclaimer: My opinions are my own and do not, in any way, reflect the opinions of my employer or university.
    12. Re:Not this time around... by theLOUDroom · · Score: 5, Interesting

      Palladium as I understand it has NO APPLICATION for content protection. It's not a DRM system.

      You clearly don't understand it at all then.
      Ask youself "Why do they need to add special hardware?" Everything you're saying it's for can be done via software.
      The point of Palladium is that you will not longer have "root" access to your own machine. The system is only going to trust "trusted" programs, but there's no way for you to decide if a program is trusted or not, is there? You don't get access to the key, this way the OS can stop you from running a program which copies that DRM-protected music file in the Palladium protected part of your hard disk onto a CDR. It pretty obvious that this system was designed for DRM.

      --
      Life is too short to proofread.
    13. Re:Not this time around... by geekopus · · Score: 5, Interesting

      Then again, there's that guy (Lucky Green) that has filed for a patent specifically to stop microsoft from using Palladium for DRM.

      It's so crazy, it just might work......

    14. Re:Not this time around... by Anonymous Coward · · Score: 0

      Palladium as I understand it has NO APPLICATION for content protection. ... You should never know that it's there.

      You're either lying or ignorant. Which is it?

    15. Re:Not this time around... by BigBir3d · · Score: 2
      The encrypted "trusted" software can compare against an online database and see if the OS you booted is trusted or not for whatever operation is going to be attempted.

      What if my computer is not online? This would most likely be because of security reasons... but it would be LESS safe to be offline...?
    16. Re:Not this time around... by Chazmyrr · · Score: 1

      Palladium will go through. Trusted Computing will happen. It doesn't matter whether its used for DRM or not. It will happen because it provides an increased level of security and accountability for business computing.

      For example, biometric authentication is basically worthless at the moment. It's all too easy to spoof, vulnerable to replay attacks, vulnerable to hardware modifications, etc. If you set up a trusted system that only accepts known hardware and software, biometrics gets a lot closer to being a reality.

      As an individual, I'm not happy about trusted computing because I see all the ways it can be abused.

      As a developer/sysadmin, I'm looking forward to incorporating this into our applications. No more password reset calls. No more trying to remember 15 different strong passwords without writing them down. A big fat raise because my boss won't have to remember all his passwords without writing them down.

      Trusted Computing inside a business makes sense.

    17. Re:Not this time around... by doorbot.com · · Score: 1

      What do you think it's for, and how do current OS techniques not address that?

      But isn't one of the "advantages" of Palladium that your friendly neighborhood viruses can no longer run and erase your MP3s/JPGs/etc, because they are not "trusted" code? I'm not sure how that will relate to unsigned VB scripts. It's designed to protect the consumer from themselves... and legislate what (Microsoft's, I assume) programmers could not implement properly.

      Your point about current OSes addressing the techniques is defintely valid. Perhaps a Palladium developer could respond here, if their browser will allow it...

    18. Re:Not this time around... by Anonymous Coward · · Score: 0

      If you do not know it is there, there is no point in it being there. It is added because it is supposed to achieve something. That something, whatever it is, *will* be noticable in some way.

    19. Re:Not this time around... by Anonymous Coward · · Score: 0

      Excuse me, but I do not see how Palladium removes the need for a password.

      Palladium proves to the server that the client *machine* is trustworthy. A password proves something else: that the user of the computer is who he says he is.

      So you will still get password reset calls. You will still be forced to remember those passwords. And you may just get fired because when your bosses CPU burns, he can no longer read the encrypted porn on his (perfectly fine) harddisk.

      But it sure makes sense - it will make the powerful even more powerful and the weak even more weak. It sure makes sense if you are powerful.

    20. Re:Not this time around... by SN74S181 · · Score: 0, Flamebait

      The point of Palladium is that you will not longer have "root" access to your own machine.

      What a pitiful, poorly thought out metaphor.

      You already don't have "root" access to your own machine, unless you can hand code assembly language and know the registers and other particulars of your particular architecture.

      Have you done a walk-through of the machine code in your bios? And any bios extensions loaded at boot time from ROMs on expansion cards like your video hardware?

      How about the embedded controller machine code in your hard drive?

      If not, you don't have "root" access and you'd better get crackin'.

    21. Re:Not this time around... by geekee · · Score: 2

      Your comment was somewhat intelligent until you switched into slashdot-speak with the bait and switch comment. You should have stopped after the 1st sentence.

      --
      Vote for Pedro
    22. Re:Not this time around... by lamontg · · Score: 2

      Palladium does have an application for content protection.

      Palladium is all about certifying through a bootstrapping procedure that your turing machine is in an approved state. It certifies that your BIOS has not been tampered with, then it certifies that your O/S has not been tampered with, then it will go on to certify that your applications have not been tampered with. Then your applications will be able to certify to a remote entity that your computer is in a known state. That means that a remote content service can stream audio or video to you and know that at least for the digital part of the circuit you have not made any attacks on their DRM. A remote content provider will be able to feel certain that you haven't loaded a device driver which intercepts audio to the speakers and instead rips it to disk (for example).

      Of course you could still be capturing the analog audio or VGA output of your sound/video card. I assume that what they would like to do there is have DRM chips in all computer speakers and monitors and in all television sets and go digital and encrypted all the way to those units. Then palladium could easily certify that you were using a DRM-enabled monitor or speakers to the remote content provider.

      A bit scarier possibility is that they want to have all content watermarked and then force you to be inable to run your soundcard or videocard on a an O/S which doesn't have DRM enabled. Of course the only way this would work would be if it was legislated and if all sound and video cards were forced to be manufactured so that they would no longer work with non-DRM O/S. The music industry would really like this since it would start to close the loophole where anyone can figure out how to rip an mp3 and put it up and everyone can download it. They want it pretty badly. On the other side though, it would create a pretty interesting lawsuit (IANAL: Restraint of Trade?) by the companies (RedHat, IBM, Amazon, etc) who are invested heavily in Linux.

      But as long as you can take an analog signal, rip it to mp3, share it with the world, and play it on a linux or freebsd box even it if is digitally watermarked, the RIAA will keep lobbying congress with schemes to try to make you stop doing that.
      They have three choices: to attack the creation of the mp3, to attack the file sharing and to attack the playback on the linux/freebsd box.

      I've already outlined what they want to do to start attack the creation of mp3s and divx's using Palladium and having digitally encrypted signals to your speakers/monitor. However at some point it has to go to analog, so there needs to be an digital to analog converter in there somewhere. One thing that the RIAA has tried to get into law is putting DRM in all DAC/ADCs. This attempt got nowhere, and I expect that future attempts will get nowhere as well since the effect on the entire semiconductor industry would be huge.

      The next attack is against file sharing, and here we see the issues that have been recently raised over vigilante hacking. They've managed to legally shut down networks like napster, but they seem to be stymied when it comes to decentralized networks like gnutella. They don't seem to be able to go after individual file sharers. They don't seem to be having enough success trying to disrupt file sharing networks. So they're looking for legal grounds to just hack in to people's machines and remove the mp3s. There could be some interesting escalating warfare in this area in the near future.

      The third attack is against being able to play mp3s and divx's on machines running palladium-uncertified (and therefore modifiable) operating systems. I really see this as being the area most open to attack. The problem is that RedHat and IBM and Amazon will fight to keep linux running on cheap commodity hardware, but they don't care much about your ability to playback mp3s on linux. They could always arrive at a compromise which allowed them to run their servers on linux, but which denied you the ability to playback mp3s and divx's. One easy first step would be to legally mandate that sound cards would only work with palladium-enabled operating systems. Most companies like amazon wouldn't care since they don't put soundcards in any of their servers anyway. And the option could be left open for a RedHat or IBM to produce a palladium-certified linux operating system which would allow sound cards to work in a controlled DRM environment. I don't know what they would do with divx playback on video cards.

      Anyway, the RIAA/MPAA want very badly to stop internet file sharing, and Palladium is definitely one way to try to do it. It will be interesting to see if Palladium will actually accomplish this goal and what abilities of consumers (and open source developers) will get compromised along the way...

    23. Re:Not this time around... by AKnightCowboy · · Score: 1
      As a developer/sysadmin, I'm looking forward to incorporating this into our applications. No more password reset calls. No more trying to remember 15 different strong passwords without writing them down. A big fat raise because my boss won't have to remember all his passwords without writing them down.

      But there are already ways to do that without having 15 different passwords. RSA's SecurID or Smart cards and PKI (ick) are just a couple ways. If you're writing applications it's not that hard to call the SecurID authentication routines through their API. No more password resets, no more 15 different passwords, just a token and a pin. I don't need "trusted computing" to make this happen, I already use it.

    24. Re:Not this time around... by theLOUDroom · · Score: 3, Interesting

      First off, there are fundamental flaws with biometric authenticaion systems that can't be solved. For example: Your fingerprints are not secret, you leave them all over the place, nor are they replacable once someone manages to get a copy of them.

      Second, you don't need palladium to do any of those things you want to do as a developer /sysadmin. The only thing palladium gives you, that you couldn't do before is a protected area of the machine that you know/hope the owner of the machine can't access. (And you can only get access to that area if MS likes what you're doing.) Anything else you think palladium gives you either has been or can be implemented without it. Go ahead and give me one other thing that palladium does that can't be implemented purely in software.

      Finally, "trusted computing" does not make business sense. It doesn't make business sense because it doesn't make business sense to be forced to rely on a single vendor for anything. With palladium, it becomes trivial to make software fixes, addons, etc. only work when made by the one company who's OS has control of the palladium hardware. It doesn't make business sense to give up control over your computers.

      Trusted computing is a marketing term and is very misleading. Palladium doesn't make your system hackerproof, protect you from email viruses, or add "accountability".

      --
      Life is too short to proofread.
    25. Re:Not this time around... by wan23 · · Score: 1

      I don't understand how anyone expects this to work. Maybe if they had tried this five years ago it could have gotten somewhere, but do they really expect the millions of so-called pirates to give up their ability to use their computers the way they want? Any company that wants to do business only with "trusted" computers will find that a good percentage of their customers are using older MS operating systems, or, even better, switched to something supported by a community of developers who don't consider users to be inherently untrustworthy.

    26. Re:Not this time around... by Hobbex · · Score: 3, Insightful


      How many of the recent big viruses have been binary programs? Nearly all the viruses are macros and scripts infecting installed applications (and those are already supposed to be sandboxed). Nearly all remote cracks are by buffer overflows which means the code runs as if it were part of the attacked application, which presumably is signed. Nearly all computers that are broken into are used only as zombies for DoS attacks - something that requires only normal, installed, user applications.

      Taking away users control of their computers can only make the situation worse - soon, even those of us who normally know how to protect ourselves will be beyond hope.

    27. Re:Not this time around... by bloo9298 · · Score: 1

      Their stuff has a keypair as well as a certificate for that keypair issued by AMI (presumably). If you can't sign messages using a private key that you can prove to be good (the certificate), then no-one will believe you. You can't keep sending out old messages. Those kinds of replay attacks will be prevented with nonces.

    28. Re:Not this time around... by Anonymous Coward · · Score: 0

      You forget that using Palladium for DRM has been patented by someone other than Microsoft.

    29. Re:Not this time around... by Anonymous Coward · · Score: 0

      And what happens when someone cuts off your arm to get your fingerprint? Much faster than trying to find a fingerprint from a mug.

      Then there's the eye ofcourse, but you'd regret missing an eye or two even more.

    30. Re:Not this time around... by platypus · · Score: 2

      Palladium will go through. Trusted Computing will happen. It doesn't matter whether its used for DRM or not. It will happen because it provides an increased level of security and accountability for business computing.

      For example, biometric authentication is basically worthless at the moment. It's all too easy to spoof, vulnerable to replay attacks, vulnerable to hardware modifications, etc. If you set up a trusted system that only accepts known hardware and software, biometrics gets a lot closer to being a reality.

      Note: The following is not meant anti-USA, just a statement of facts!

      I hope you live in the US of A. Because everyone else in the world will gain a shit by a trusted computed which will only run software which is signed by a key which the american three letter agencies surely have.

      If echelon has told the non-US of A states anything, it is that industrial espionage happens even between so-called allies. Since a lot of the IT-infrastructure is from US companies, the effect is that this all gives just a false impression of security, in effect weakening the systems if there has been put any trust in this palladium thingy.

      Oh, and if terrorists can acquire weapons of mass destruction, they also might be able to get the their software signed. It's just a matter of financial resources and ruthlessness.

    31. Re:Not this time around... by platypus · · Score: 2

      They could always arrive at a compromise which allowed them to run their servers on linux, but which denied you the ability to playback mp3s and divx's.

      Hmm, if they got that through, this would be a really impressing political hack. What if I want to record my own compositions to an mp3?
      I'm with you that this is the wet dream of RIAA/MPAA dudes, but I think the possibility of that dream come true is the same as with some of my dreams concerning Mrs. Jennifer Lopez and her three twin sisters.

      One easy first step would be to legally mandate that sound cards would only work with palladium-enabled operating systems.

      It's simple to build a quite advance soundcard with a DAC, so there we are back to your second point (semiconductor industry). Or write an audio-CDROM which plays in any player - no soundcard involved. As soon as they try to get the consumers to buy DRM-enabled HiFi-equipment their it's-all-for-the-security bubble will burst (look how trivial it is to disable macrovision on nearly all el-cheapo DVD-players).

      All in all, DRM is a step in the right direction for "them", but I think they will never really reach their goal, just make some things more inconvinient. It's quite scary that they still try.

    32. Re:Not this time around... by ShadowDrake · · Score: 1

      Isn't a large part of the problem still the basic trojan horse? Signing systems can't PRACTICALLY (operative word) defend against those. They can:

      1. Offer the user a chance to approve unsigned code, which he will likely get in the habit of doing for the legitimate but unsigned code out there (will there be a signature for my copy of Railroad Tycoon on 360k floppies?), in which case a user may be easily tricked into running the trojan, and we're no better off.

      or

      2. Refuse all unsigned code. Application base evaporates. Many, many users refuse to upgrade because custom apps or even older apps (or competing apps that mysteriously aren't certified) break.

      --
      It's just like a fascist dictatorship, without the punctual rail service!
    33. Re:Not this time around... by Dasein · · Score: 1
      No, but people I trust do this all the time. With palladium in place the good work these people would be in danger.


      However, I don't think for a minute that all the clone MB manufacturers will make it impossible to boot an unsigned OS. I mean, most have setting that allow you to use processors whose frequency multipliers has been unlocked.

      --
      You are not a beautiful or unique snowflake -- but you could be if you got off your ass.
    34. Re:Not this time around... by BigBir3d · · Score: 1

      ahhh... ok.

      thanks for the info.

    35. Re:Not this time around... by Anonymous Coward · · Score: 0

      You ought to do some reading on trusted computing, especially the TCPA (www.trustedcomputing.org). IBM is a founder-member of the TCPA, and not some sort of opponent of the idea. Linux isn't especially relevant to trusted computing either, except to the extent that making a trusted version of Linux would be extremely difficult, owing to the lack of a single, trusted source.

    36. Re:Not this time around... by Anonymous Coward · · Score: 0

      So.. the obvious question -
      we all know that Mozilla can pose as different browser/OS configs (yea, I know, a simple ID string reply to a query) So ...

      How do we have linux give the "right" answer to the palladium query? (definition of "right" answer for this application would be "in the database of trusted systems")

      How much time before the hack is out, and will it be on the Newsgroups, peer to peers networks, or a website first?

    37. Re:Not this time around... by briancnorton · · Score: 2
      I can see a million good uses for this system that have nothing to do with DRM. The stated purpose is to prevent malicious code executing in one part of a system from affecting malicious changes in another part. Tell me how to do that in software? The anti-virus companies have been trying to figure that out for years. On a corporate level, a trusted network would open up a whole new world of groupware possibilities and could prevent many server attacks.

      The system is only going to trust "trusted" programs, but there's no way for you to decide if a program is trusted or not, is there?

      How do you know? The spec isnt released much less an implementation. Why wouldnt they give the system administrator the ability to trust software? Even microsoft isnt stupid enough to think that they can stop people from writing their own software. They arent moving to make everything have a mandatory digital signiture, or tie software to a user. TCPA (dont know about palladium, but they are different) does not record Personally identifiable information, and your identity on a network or on a workstation is a different throwaway alias for evey transaction. Without personally identifiable information, DRM is non-existant.

      All that said, some slashdotters have come up with some interesting takes on how this type of system could facilitate DRM as a trusted layer. While I am willing to concede that point, I dont think that even Microsoft has that kind of market clout. And if they did, thats another whole round of anti-trust action on them. I can see why it looks like they are trying to move computers towards something that resembles an Xbox, but I dont think thats what it is.

      finally, for a group that criticizes MS about security nonstop, there sure is a lot of closed minded drivel about big brother computing. MS is less of a monopoly than you think it is.

      --

      People who think they know everything really piss off those of us that actually do.

    38. Re:Not this time around... by Chester+K · · Score: 2
      The point of Palladium is that you will not longer have "root" access to your own machine.


      I know I'll never buy a PC like that. No matter what kind of "cool" applications it has. Even if it means I have to stay with my current computer as it fades into obsolescence. There's a line in the sand that I won't cross, and being deemed too untrustworthy to use my own computer to its full potential is over that line.

      I can only hope that other techies feel strongly enough about the issue to vote with their wallets similarly. If Palladium sufficiently disgusts the early adopter market, it won't have the momentum to propel it into the mass market, and then from there, into ubiquity. It happened with Divx, hopefully lightning will strike twice. And most importantly, it'll give Microsoft and other supporters of Palladium a nice stark reminder that their customers, the people they make profit from, are the end-users, not the content cartels.
      --

      NO CARRIER
    39. Re:Not this time around... by visualight · · Score: 3, Informative

      And where did you find this out? Point me somewhere that says this? Read the documentation, dont jump to conclusions.



      Okay, you should of followed your own advice. This is from an interview with John Manferdelli, general manager of the Windows business unit that is building Palladium.



      PressPass: How will Palladium differ from digital rights management (DRM)?

      Manferdelli: First off, Palladium will not require DRM, and DRM will not require Palladium. Palladium is a great complementary technology to the DRM solutions of tomorrow, but the two are separate technologies.



      Also, after reading all of the official MS "documentation" you should read this reaction from the Register.



      --
      Samsung took back my unlocked bootloader because Google wants me to rent movies. They're both evil.
    40. Re:Not this time around... by vrmlguy · · Score: 3, Informative
      The stated purpose is to prevent malicious code executing in one part of a system from affecting malicious changes in another part.
      You seem to be misunderstanding the meaning of the term "trusted system".
      --
      Nothing for 6-digit uids?
    41. Re:Not this time around... by iNub · · Score: 1

      So now we know, without a doubt, that TCPA is either good or bad.

      --
      "The image is a dream. The beauty is real. Can you see the difference?" -- Richard Bach, Illusions
    42. Re:Not this time around... by Anonymous Coward · · Score: 0
      Looking up the hash for Windows under Linux won't necessarily get you a key to the "content". If it did, the content server would require a challenge/response type authetication.

      The other option is that the software on your PC could have a key encrypted in it, like DVD players have a CSS key encrypted in them (*cough* Xing *cough*).

    43. Re:Not this time around... by Alsee · · Score: 2

      So now we know, without a doubt, that TCPA is either good or bad.

      And the article told you exactly how to figure out which. Here's what it said...

      The key questions to ask are who has control, and what kind of control they have. Depending on the answers to those questions, a "trusted" system might be either good or bad.

      Who has control? Whoever has the cryptographic keys to sign "trusted" code. While Palladium *may* allow you to make up your own keys those keys are pretty much worthless. Pretty much anything you can do with "your own keys" you could have done without palladium anyway. All of the important keys will be held by Microsoft and other corporations.

      So that means Palladium is good for Microsoft and other corporations and bad for the owner of the computer.

      kind of control they have

      They get pretty much total control. The owner of the computer loses pretty much all control over his own machine. That's pretty bad.

      -

      --
      - - You can't take something off the Internet! That's like trying to take pee out of a swimming pool.
    44. Re:Not this time around... by hesiod · · Score: 1

      Setup:
      Original poster said, Palladium is ALL about DRM

      The reply basically said "get your head out of your ass, Palladium is not DRM" ...

      Then you "call his bluff" by reinforcing his own arguments?
      Palladium will not require DRM, and DRM will not require Palladium

      I'm not trying to be an ass (haha, of course I am, that's why I'm on /.) but some people need to read a little closer before insulting others. To strengthen this point, I will probably later find out that I misunderstood the post and just made myself look stupid. Alas, such is my life.

    45. Re:Not this time around... by lamontg · · Score: 2

      I didn't say that IBM is opposed to TCPA. I'm saying that IBM is in favor of linux running on cheap commodity hardware. Where TCPA starts to interfere with linux running on cheap commodity hardware (if the RIAA/MPAA actually gets some traction) is where IBMs position on TCPA will get very interesting.

      And I've tried to describe why TCPA is relevant to linux if hardware ever started to mandate trusted operating systems. If you don't understand that relationship, I don't know how I can help you.

      And developing a trusted version of Linux would be easy in theory, all it takes is a RedHat or IBM to setup a single trusted source.

    46. Re:Not this time around... by apweiler · · Score: 1

      What if I want to record my own compositions to an mp3?
      Go ahead - on a 'trusted' system. Because that will be able to verify that it *is* your own composition, with some sort of watermark technology. And, of course, to publish your creation, you'll have to register it with the RIAA to be encrypted and signed so it'll play on everyone's Palladium PC.

      dreams concerning Mrs. Jennifer Lopez and her three twin sisters.
      Wouldn't that be quadruplets? (Sorry couldn't resist...) Not that I find JLO too impressive.

      Or write an audio-CDROM which plays in any player - no soundcard involved.
      But only possible on a trusted computer and if you have the appropriate permissions/rights (in their wet-dreams scenario, of course).

  4. What isnt stated by briancnorton · · Score: 3, Informative

    If you have a palladium processor and palladium motherboard, hard drive whatever, you arent going to be limited to a palladium enabled OS, you just wont be able to use the benefits of a palladium trusted environment. So said microsoft anyhow.

    --

    People who think they know everything really piss off those of us that actually do.

    1. Re:What isnt stated by Anonymous Coward · · Score: 5, Funny

      One of the key benefits of Palladium, of course, being a PC that boots up! People will really embrace Palladium's "booting PC" feature when compared to the "non-booting PC" features of the competition!

    2. Re:What isnt stated by Syphonius · · Score: 3, Insightful

      What benefits? Best I can tell, trusted computing provides me, a consumer, no benefits over what exist today. It does, however, provide many benefits to large corporations and media control companies.

      So 'trusted' here means that the companies can finally trust 'all us thieves' with 'their' media property.

      Explain to me again, why on earth would I want any machine like this as a general computing platform?

    3. Re:What isnt stated by nmg · · Score: 1

      Good point. Perhaps with the advent of a truly secure mechanism, companies will be more interested in developing/investing in better compression/transmission technologies, whereas now they might be put off by the rampant piracy.

      This will be a good thing for those of us who don't steal our entertainment.

    4. Re:What isnt stated by Anonymous Coward · · Score: 0
      If a TCPA/Palladium system is widespread media companies can sell digital content that they can rest assured isnt likely to be spread like clap in a dirty whore house.

      In the fictional case media companies will jump at the chance to sell to a new market.

      So you're saying media companies are now trying to pander dirty whores on the general public?!?! Oh the horrors!! Won't somebody PLEASE think of the children!!!

    5. Re:What isnt stated by harlows_monkeys · · Score: 5, Informative
      What benefits? Best I can tell, trusted computing provides me, a consumer, no benefits over what exist today

      How about better online games? Consider MMORPGs. To prevent cheating, they have to do various things server-side that would actually make more sense from a resource allocation point of view to do on the client.

      For example, DAoC has to handle stealth on the server, calculating who should be able to see a stealthed character, and only sending that character's positions to clients that should see him, so that people with DAoC's equivalent of ShowEQ won't see them. However, those people can still see people who are hiding behind trees or hills or buildings--it would be too much work for the server to do the visibility calculations for everyone.

      With a trusted client, they could just send the data on everyone in the area, and trust the client to not show what the player is not supposed to see.

      Or how about monster AI? The monsters could be a lot smarter if they could run the AI on the client, instead of on the server.

    6. Re:What isnt stated by (H)elix1 · · Score: 2

      If you have a palladium processor and palladium motherboard, hard drive whatever, you arent going to be limited to a palladium enabled OS, you just wont be able to use the benefits of a palladium trusted environment.

      True... but I voted with my wallet when Intel added the ID to the CPU. I'll do the same this time too. I know if all my options are 'palladium' only for a bit, I'll spend the cash on other hardware components and wait for the market to 'correct' the problem. I may not get a choice, but as one of those early market adapters that spend more than they should I won't make the jump for the first cut... The current generation of CPU's will have a couple years faithful service in front of them.

    7. Re:What isnt stated by SN74S181 · · Score: 1

      How did this ignorant comment get modded up? I read at +2 to try to block out stuff like this.

    8. Re:What isnt stated by PhrackCreak · · Score: 1

      You've never really programmed an online game have you? There are reasons to have a trusted client, but your examples are poor choices.

      I do not know what 'stealh' mode is on the viewer, but if you can get away with not sending information down the wire, by all means do it. Network bandwidth consumption can be a huge gating factor in playability.

      Next, all decisions must come from the server. Outside of just a handful of cases, you do not want 10000 clients simultaneously deciding what the AI should be doing. State decisions and updates have to happen on the server. The client is just another input device.

      --
      - You don't know how to maintain a station wagon either!
    9. Re:What isnt stated by NewWaveNet · · Score: 1
      But they are never going to sell lots of digital media until something like this comes into play. Its too risky. One file slips out and bamo - no one is paying for it anymore.


      Please tell me you realize that not everyone will pirate it? Some people still believe in the value of intellectual property.
    10. Re:What isnt stated by Anonymous Coward · · Score: 0

      How did it get modded up? It got modded "Funny", not "Informative". Please take the stick out and learn to enjoy life.

    11. Re:What isnt stated by incom · · Score: 1

      That's all well and good, but I woudn't want to sacrifice my freedom to let mmorpgs save money. Now for video game consoles this is actually practical, but keep it away from my PC.

      --
      True genius is grasping a situation like a peice of fruit, and peircing it just right so that it drains dry.
    12. Re:What isnt stated by cosyne · · Score: 2

      Of course, if the Palladium OS is anything like XP, it won't have very many advantages over a non-booting PC, except for turing electricity into heat and noise.
      (I only say this cause i'm tired of people asking me why they can't {print/surf the web/access files/type/use the mouse} with XP.)

    13. Re:What isnt stated by Anonymous Coward · · Score: 1, Funny

      I'm gald you don't think your posts are worth reading either.

    14. Re:What isnt stated by geekee · · Score: 2

      How is Palladium a problem for you, unless you want to pirate copyrighted media? You won't get the media online without Palladium, so your options are Palladium based media, or no media. Palladium doesn't affect any media currently available, such as cds or mp3s.

      --
      Vote for Pedro
    15. Re:What isnt stated by DarkZero · · Score: 2

      If a TCPA/Palladium system is widespread media companies can sell digital content that they can rest assured isnt likely to be spread like clap in a dirty whore house.

      Ooooooh! I get it now! It turns my computer into a $1000 spare satellite receiver without the Tivo functionality! Why didn't anyone tell me this? I'm fucking thrilled now!

    16. Re:What isnt stated by DarkZero · · Score: 2

      How about better online games? Consider MMORPGs. To prevent cheating, they have to do various things server-side that would actually make more sense from a resource allocation point of view to do on the client.

      Console online games like Phantasy Star Online provide an environment where the client cannot see or modify the code that goes through the machine, but they still have huge problems with cheating, and for the same reason that a Palladium-enabled PC would (at least from my understanding). You can modify the software and hardware all you want, locking them up in every way that you can think of, but eventually it will be hacked. You can only lock down a set of circuit boards and wires that are located in the consumer's home to a certain degree. With enough time and energy, people will eventually get past the lock down, and those people are usually the ones that are crafty enough to cheat like a pro and spread the wonders of hacked accounts and instantly created uber items clear across the game and into the hands of people that will not be pleased when the game developer takes their stuff from them.

      Bottom line, there is simply no way to completely lock down an MMORPG. Cheating in an MMORPG is like a big, warm apple pie. Regardless of whether it's being sliced up for a million people or a few hundred, they always manage to eat the entire pie, and the only difference is the amount of it that each person shares. Either you get a lot of people cheating a little bit or a little bit of people cheating a lot, but either way, the users figure out how to give you a huge cheating problem.

    17. Re:What isnt stated by mmol_6453 · · Score: 2

      One file slips out and bamo - no one is paying for it anymore.

      Except of course for the people who want to listen to the recording at digital quality, or who want to grab an entire collection of songs.

      Or, heck, even just to put in CD players. There's gotta be a reason they still sell cassette players, and I don't think it's just because you can easily record to cassettes.

      And yet, we're still forgetting that you lose, assuming your using good equipment, very little quality by recording audio to a tape, then digitally recording that content back to a computer, preferably at a higher sampling rate, but into a non-DRM'd file.

      I can see two possible downfalls to this: DRM-enabled machines may refuse to record data without DRM-enabling the media in your name, or law gets passed that air is a digital media as evidenced by (specially funded) research into quantum mechanics and computing.

      --
      What's this Submit thingy do?
    18. Re:What isnt stated by Anonymous Coward · · Score: 0

      So you want to cripple your computer so you can play some fucking waste of time online game? Nice.

    19. Re:What isnt stated by Anonymous Coward · · Score: 0

      That certainly compensates for the complete loss of control over hardware I own. Whew!

    20. Re:What isnt stated by (H)elix1 · · Score: 2

      How is Palladium a problem for you, unless you want to pirate copyrighted media?

      I'm not worried about MP3's... I don't need a 4ghz CPU for that (grin). I am worried about my old software and stuff I create working, however. My legit Office 97 still works fine for me. Think Microsoft will sign that app so it runs on x64 version of Windows Palladium? How about half-life mods? (or Starcraft II whenever it happens)

      How about my legit Windows 98SE, stripped down to a lean mean gaming OS? Maybe it will still work on the new hardware, perhaps not. The fact that I worry about it means my cash will stay in my wallet until my fears are put to rest. That means I WON'T be shelling out mad cash for the Palladium kits when they hit the market. That's AMD's Opteron to put a face on what I am talking about. As a side note, the CPU id was one of the straws that got me to switch to the Athlon.

      As for media - I just don't buy or listen to that much music or movies. I could really give a rat's ass about what corruption they do to keep their precious out of the evil copyright violators. Mess with my hardware, its personal....

    21. Re:What isnt stated by sholden · · Score: 2

      It wouldn't be difficult to allocate the processing for a given mob to a client's PC. In the background the PC would also be sending commands to the server for the mob as well as for the player.

      If the PC disconnects or crashes the missing command would alert the server which would then allocate the mob to another client, or allocate it back to the server itself. This bit would be difficult, since having mobs lag with random clients would be *bad* (though I guess the player who would have been killed in the lag but wasn't because the mobs were also lagged would like it. :)

      In current online games that's not worthwhile. You can't trust the client so that stops it fast. If you could trust the client there wouldn't be any benefit until the overhead of allocating mobs and the extra traffic generated outweighed the cost of doingt he processing locally. For current games, it wouldn't of course.

      But doing so would allow more complicated AI on fixed server power.

      Take a stupid example, of a chess server. Say it has thousands and thousands of players at once, all playing against the computer. The server doesn't have enough grunt for massive searching of the board space. However, Johhny has connected on his PVII which has lots of grunt, especially considering it is only drawing a chess board at the moment. The server could get the client to run the AI - the board state is already at the client after all.

      More than that, Freddy could connect using his dumb terminal and start a GrandMastersAreCrap level game. The server doesn't have enough grunt, and Freddy doesn't either. but Johhny is playing on Beginners, his PC is basically idle. The board state of a chess game is *really* small so the server gets Johnny's machine to do the grunt work for Freddy's AI opponent.

      As for getting away with not sending info down the wire, the problem of course is that working out the info isn't required might be too difficult, especially if you are using realistic lighting and stuff. You don't always have the CPU to trade off against the bandwidth...

    22. Re:What isnt stated by StillaCoward · · Score: 1

      {snicker}

      Surely you see that you've just totally eliminated the need for any online connectivity.

      Chess is a two player game. Your model has both players controlled locally. So what we have is a local chess application. We sure can't make any of those without TCPA!

      About the only benefit I can see is you can be sure that the high scores sent to the central server are have not be tampered with....

    23. Re:What isnt stated by sholden · · Score: 2

      It was a very simple example of how processing can be moved to some other client...

      If you want to do with a MMORPG you (as I said, but you were too dumb to read I guess) could farm off AI computation for the mobs.

      Effectively instead of having the mobs be executed in the server you treat them like players, running as seperate processes which can be moved to other machines, communicating with the server like players do.

      Basically distributed computing of the game state

    24. Re:What isnt stated by Anonymous Coward · · Score: 0

      That was really funny. You pwn3d him good.

    25. Re:What isnt stated by Anonymous Coward · · Score: 0

      I'm afraid you're too dumb to realize that allocating non-determinant AI to the client is stupid, prone to abuse that no "trusted environment" can remove, and more or less self-defeating for the purposes of providing increased realism to a game.

    26. Re:What isnt stated by sholden · · Score: 2
      I'm afraid you're too dumb to realize that allocating non-determinant AI to the client is stupid, prone to abuse that no "trusted environment" can remove, and more or less self-defeating for the purposes of providing increased realism to a game.

      Did I say non-determinant? The AI for a mob in a MMORPG can be determinate, since the game state will be so varied no one will notice... Of course that'd beside the point, since it'll work fine for non-dteerminate anyway.

      As for prone to abuse, the whole dicussion is about why a trusted client might be useful to the user. Hence the assumption is the trusted client is truly trusted. Arguing it isn't is pointless because the topic is "IF 'trusted clients' existed, what benefit could they have".
  5. Been there done that....... by MegaHamsterX · · Score: 1

    Yes, TiVo is trying to play this game with their series 2 and DirectTiVo, it works against most people, except those who have no fear of dead hardware :-)

  6. And how long before... by Anonymous Coward · · Score: 5, Interesting

    ...the first "trusted" bootsector virus appears?

    1. Re:And how long before... by jagripino · · Score: 0

      Just wait until Microsoft releases its next OS :-)

    2. Re:And how long before... by Chocolate+Teapot · · Score: 0

      "Windows not found. Swipe any credit card to continue"

      --
      Modest doubt is called the beacon of the wise. - William Shakespeare
    3. Re:And how long before... by Anonymous Coward · · Score: 0

      please mod parent up. This is much funny than the other post.

      _-~satarmanapaya@hotmail.com~-_

    4. Re:And how long before... by doorbot.com · · Score: 4, Interesting

      But this is exactly the problem... if a virus manages to pass as a trusted program, then Palladium merely reverts back to the system we have today (except as a consumer you have less control over your own property). Viruses can still wreak havoc, etc. Once the trust is broken by one app, the whole system collapses.

    5. Re:And how long before... by DarkZero · · Score: 2

      But this is exactly the problem... if a virus manages to pass as a trusted program, then Palladium merely reverts back to the system we have today (except as a consumer you have less control over your own property). Viruses can still wreak havoc, etc. Once the trust is broken by one app, the whole system collapses.

      I don't understand this logic at all. If a virus can act like a trusted program and other viruses that can act like a trusted program will stem from that, why can't a version of Linux or just a media player for Windows incorporate the same hack of the trusted computing platform that the viruses use?

    6. Re:And how long before... by Anonymous Coward · · Score: 0

      This is a brilliant angle and it's safe to say that we'll see it again.

    7. Re:And how long before... by be-fan · · Score: 2

      Because a lot of us are getting to the age where "going legit" seems like an attractive proposition. We would rather not run illegal software as our main environment. Besides, the Linux devs are respectable hackers, not a bunch of virus weenies.

      --
      A deep unwavering belief is a sure sign you're missing something...
  7. before eveyone gets all worked up by Anonymous Coward · · Score: 0

    how much do you want to be that there are jumpers that will let you bypass this thing?

    or if there's not. It's a simple check, shouldn't be too hard to force it. Mod chips for our PC's are going to be mainstream soon! (ugh)

    1. Re:before eveyone gets all worked up by stratjakt · · Score: 4, Insightful

      Jumpers?

      The whole thing will be a BIOS option, just like the P3 serial number was.

      This thing will probably stay in the corporate/military domain forever. I see a ton of added complexity to the OS that Joe User wouldn't deal with.

      There's a potential for abuse in pretty much any new technology, but I can also see when and where a 'trusted OS' will be a huge step forward.

      'Untrusted' hardware will exist so long as there's a market for it. I see no reason to get too worked up over it.

      --
      I don't need no instructions to know how to rock!!!!
    2. Re:before eveyone gets all worked up by Anonymous Coward · · Score: 0

      'Untrusted' hardware will exist so long as there's a market for it.

      and for as long as it's legal.

    3. Re:before eveyone gets all worked up by Anonymous Coward · · Score: 0

      The whole thing will be a BIOS option, just like the P3 serial number was.


      Wow, a BIOS option to disable to BIOS! How cool is that?

      If you read the release it said it would do the integrity checks "As soon as the computer is turned on." Dunno, but seriously there can't be a boot option to disable checking BIOS integrity because that's done before the BIOS does anything.

      Here's the order:

      Power on
      TPM check's the BIOS integrity
      BIOS checks OS integrity

      So you might be able to turn off checking the OS integrity in the BIOS but it appears that the BIOS itself is always checked. Otherwise it could be trojanned to never check the OS integrity and then what good would it be?

    4. Re:before eveyone gets all worked up by Qrlx · · Score: 2

      There's a potential for abuse in pretty much any new technology, but I can also see when and where a 'trusted OS' will be a huge step forward.

      Isn't one of .NET's selling points that is puts and end to .DLL Hell? And isnt' the way it accomplishes this by rolling all versions of a dll into one big dll, then letting the app specify that it needs, say, MDAC 2.5 to function.

      Coincidentally, wasn't the MDAC vulnerability the one where Microsoft's solution was to remove Microsoft's name from the list of trusted entities? (Because, even though you upgraded the MDAC components on your computer, a malicious app could have the old, vulnerable, yet signed-by-MS MDAC components in its codebase and silently install them if Microsoft is "trusted.")

      I don't think we'll be seeing "trusted OS" from Microsoft anytime soon. Well, it might carry the label trusted but there will be all the standard disclaimers that if hackers exploit known bugs that's not their problem.

      Maybe the trick is to get a independent third party to sign off that something can be trusted. Otherwise it's kind of like Arthur Anderson's audit of Arthur Anderson turning up no irregularities.

      Of course, the other reason to fear the "trusted OS" is: how can I run my own code on that puppy, without spending $$$ to get a digital seal of approval from MS or AMI or whoever. (Or get the approved development software suite) Thus taking computers out of the realm of the hobbyist once and for all. There's a lot of geeks who are going to fight to keep that from happening, and hack it if it does happen.

      OTOH, maybe it's not that far off; CSS anyone? Having to buy the rights to the key so you can make a DVD player is pretty much the same thing, isn't it

      How come my arrow keys aren't working anymore? Is that a Mozilla thing??

    5. Re:before eveyone gets all worked up by stratjakt · · Score: 2, Interesting

      Who says the trusted OS has to come from MSFT?

      Maybe I'm going to sign a linux kernel, and only add my own signature to my trusted list. Now nothing will run on my machine that I haven't signed.

      I understand all the knee-jerk 'the sky is falling' reactions - this is slashdot, after all - but can't anyone see the benefit of knowing that next time Eunice the Twit in accounting opens a "hilarious" e-mail, she won't bring every machine in the network to a halt?

      --
      I don't need no instructions to know how to rock!!!!
    6. Re:before eveyone gets all worked up by theLOUDroom · · Score: 3, Insightful

      'Untrusted' hardware will exist so long as there's a market for it. I see no reason to get too worked up over it.

      Right, because the PC market is governed by pure capitalism. There are no monopolies out there abusing their power and causing the market to do things it wouldn't otherwise do. Good, I guess there's no reason to be worried at all. (shudder)

      --
      Life is too short to proofread.
    7. Re:before eveyone gets all worked up by sqlrob · · Score: 3, Insightful

      And illegalizing drugs eliminated that market quite effectively.

    8. Re:before eveyone gets all worked up by TCaptain · · Score: 2
      but can't anyone see the benefit of knowing that next time Eunice the Twit in accounting opens a "hilarious" e-mail, she won't bring every machine in the network to a halt?

      The problem is that this solution WILL NOT STOP THIS FROM HAPPENING...a macro virus runs from a "trusted" executable...in other words, if you have Palladium, Outlook is a trusted app...you get a macro virus that makes Outlook do a lot of shitty stuff...Palladium won't stop it.

      --
      "I'm not a procrastinator, I'm temporally challenged"
    9. Re:before eveyone gets all worked up by Anonymous Coward · · Score: 1, Informative

      but who authorizes the signature ? and it will need to be resigned everytime you recompile. A verisign certificate is not a cheap thing, I am sure that the OS certificate will be a BIG EXPENSE as well.

    10. Re:before eveyone gets all worked up by hachete · · Score: 1

      If it's so damned trustworthy, why won't the TCPA consortium tell us who they are?

      mm?

      --
      Patriotism is a virtue of the vicious
    11. Re:before eveyone gets all worked up by ebresie · · Score: 1

      Is the premise though that when you receive something in Outlook, the document must also be signed and verified by Outlook which verifies with Palladium, then the chip?

      If the message is not from a trusted receipiant that you know, then it wouldn't be trusted and treated as an untrusted message.

      Is the idea that only trusted receipiants and applications will be able to execute functions like send something to every person in your address book?

      Although the added complexity of maintaining all this trusted information might cause the whole thing to bloat everything to no end...or am I misunderstanding here?

      --

      Eric B
      ebresie@gmail.com
    12. Re:before eveyone gets all worked up by Anonymous Coward · · Score: 0
      Of course, the other reason to fear the "trusted OS" is: how can I run my own code on that puppy, without spending $$$ to get a digital seal of approval from MS or AMI or whoever. (Or get the approved development software suite) Thus taking computers out of the realm of the hobbyist once and for all. There's a lot of geeks who are going to fight to keep that from happening, and hack it if it does happen.

      Hell, not just geeks, what about Academia? How do you teach computer science with your hands tied behind your back and your hood welded shut on the PC? They're computers for cripes sake not consumer information appliances. You input commands and it returns results. When the actual computer itself becomes so cumbersome that you can't accomplish simple functions like programming it yourself without getting some seal of approval for your code then people are just going to stop buying that hardware. So I guess we'll need to switch to Sparcs or Macs. :-)

    13. Re:before eveyone gets all worked up by zcat_NZ · · Score: 1

      Duh! If only signed content can be run, the virus will simply sign itself using -your- key before it forwards itself to everyone on your address book.

      And yes; this will work. Automated signing will be an enabled-by-default feature of Outlook for the same reason blindly-running-untrusted-code was and still is..

      --
      455fe10422ca29c4933f95052b792ab2
    14. Re:before eveyone gets all worked up by yerricde · · Score: 1

      There are no monopolies out there abusing their power and causing the market to do things it wouldn't otherwise do.

      I understand that you intended that as sarcasm, but actually, with all the inroads the GNU/Linux system is making in Europe, you might be closer to right than you think.

      --
      Will I retire or break 10K?
    15. Re:before eveyone gets all worked up by Anonymous Coward · · Score: 0

      hey man, I heard you got some new "mobos" in....IF you know what I'm sayin'???

    16. Re:before eveyone gets all worked up by Billly+Gates · · Score: 3
      ...and what if your email you recieved from grandma requires pallidium or what about your excel spreadsheets from the office? What now?

      "'Untrusted' hardware will exist so long as there's a market for it. I see no reason to get too worked up over it.

      There will be no market for it. Why would an OEM install hardware that disrupts most "innovative" OS and office software maker that brings them all of there profits!

      Linux makes up %2 of the market!

      If joe six pack buys a "Free" pc yet can not bring "trusted" word docs home from work or have the latest and greatest XP Media edition to watch all the new hollywood hits or visit porn sites that are "protected" then he will return it. Return == lost profits. I bet Microsoft is blackmailing all the motherboard makers and threatening to throw them out of bussiness if they do not include drm oops I mean pallidium. Porn sites already encrypt alot of there video's into WMV files and I noticed that they also use javascript to prevent copying and pasting pics from there site to your computers. Like the vcr's before them they will drive the market and Microsoft and Hollywood will join them.



      The average ignorant joe will demand it and will be forced on everyone. If oracle pisses off Ms then bam they can not develop on Windows. If borland wants to write .net software, BAM out of bussiness. This is very scary. What will stop ms from making every software writer in existance sign non compete licenses in order to be signed? If this happens then Microsoft will run unopposed in every software catagory they want to get into. Noone can compete because ms will take the right for them to be signed away.

      We all should be worried and worked up about it. If the apps require it then it will be everywhere.

    17. Re:before eveyone gets all worked up by sqlrob · · Score: 2

      Yeah, except it'll probably be in e-mail.

      How long would it take you to get a Dish or DirectTV card that lets you get all channels? You could probably find a dealer in what, 10 minutes?

  8. *BSD by Anonymous Coward · · Score: 0, Offtopic
    *BSDs will be equally affected

    Does this mean that *BSD is dying?

  9. No it doesn't. by Kickasso · · Score: 4, Informative

    If it's true to spec, it will load anything. Just not in the trusted mode.

  10. Comment removed by account_deleted · · Score: 5, Interesting

    Comment removed based on user account deletion

  11. Not necessarily for the masses by Arcturax · · Score: 5, Insightful

    This could as easily be for military computers as well as the great unwashed. So I don't think we will be seeing these in home PC's just yet.

    Not only that we don't know yet what OS they will work with. So lets not start doomsaying until the first of these are out and there is proof they refuse to run certain operating systems.

    --

    --Won't that be grand? Computers and the programs will start thinking and the people will stop. - Dr. Walter Gibbs
    1. Re:Not necessarily for the masses by sphealey · · Score: 4, Insightful
      Not only that we don't know yet what OS they will work with. So lets not start doomsaying until the first of these are out and there is proof they refuse to run certain operating systems.
      Well, the problem is that the "embrace and extend" and "stealth networking" marketing techniques use the time when the victim, I mean the consumer and compeititon, is waiting to see what happens to lock everything in place and preempt any other course of action. So that may not be the best approach in this case.

      sPh

    2. Re:Not necessarily for the masses by Czernobog · · Score: 1

      >> This could as easily be for military computers as well as the great unwashed...

      The military already has Palladium installed. It's called "Shoot on Sight".

      --
      /. Where the truth
    3. Re:Not necessarily for the masses by karmawarrior · · Score: 2
      I wrote a fairly long essay on the potential consequences of Palladium here. I think it's important to consider that whether people intend for these technologies to only be used by a small subset of computer users with specific security interests, it is almost certain that the current paranoia exhibited by the entertainment industry will make its use compulsory.

      People need to get motivated.

      --
      KMSMA (WWBD?)
    4. Re:Not necessarily for the masses by Anonymous Coward · · Score: 0

      Finally, a sane person!

    5. Re:Not necessarily for the masses by dpbsmith · · Score: 3, Informative

      Plus, it's always possible that "the first of these" will come out running any OS; then the upgrade that is necessary to correct serious bugs will turn out to have the unadvertised side effect of locking out other OS'es; and only then will people notice that it said that might happen in fine-print legalese twenty pages down in the EULA.

      There's a lot of precedent for this. (Ask anyone who took advantage of the upgrade deal on their REB1100 eBook device, for example). Its predecessor, the Rocket eBook let you download your own content into the device. The REB1100 was only advertised as allowing the download of purchased content, but actually permitted download of personal content too. Then a "stealth" upgrade removed that feature.

    6. Re:Not necessarily for the masses by Anonymous Coward · · Score: 0

      Q. Do you believe in god?

      A. No. But I believe in the higher power of artillery.

    7. Re:Not necessarily for the masses by Slackrat · · Score: 1

      Given that any old OS can be booted, would it be possible to load an OS that would then create a virtual machine which would execute code and, more importantly, emulate the functionality of the encryption chip?

      The Palladium and TCPA designs all seem to rely on a secure piece of hardware which would do secure hash id of the currently loaded OS. By emulating this chip in software, one could send responses to id-challenges as one wished, identifying as one OS, when really virtually running another.

      I suppose a hidden key in the BIOS itself might invalidate my method. What do you think?

    8. Re:Not necessarily for the masses by DickBreath · · Score: 2

      The authentication that happens occurs differently than most people imagine. The BIOS create a hardware verified hash or signature, which is stored in a piece of memory that is hardware protected from being written to more than once per cold boot. Apps that are trusted run in a seperate, hardware protected area of memory and with special CPU instructions. Then that software checks the hash held in the memory, and compares that against an internal/online database of acceptable versions.

      So are you saying that...

      I could flash my BIOS with a doctored version. It doesn't write ANYTHING to this write-once area. Later, my boot.local script writes one of the acceptable known values to this area. Now my modified Bochs software that cooperates with new Kernel features, can run Windows Media Player in the special memory area reserved for trusted applications. Since they will see the correct value in the write-once area, they will assume they are on a trusted version of Bochs. Therefore WMA will go ahead and decode highly sensitive protected information, such as Buffy The Vampire Slayer?

      Or perhaps you are saying that with suitable hardware hackery, this write-once area could be overlayed with ordinary RAM? Perhaps a custom XILINX job directly on the CPU bus or somesuch? Where is the write-once memory? Something must protect it? Is it NOT in the regular DIMMs? On the microprocessor? Where? Wherever it is, it can be subverted with volume-production mod-chips. Perhaps a device that plugs into the CPU socket, and then the CPU plugs into it. Or perhaps a special "large" DIMM board with extra chips? This write-once memory must be somewhere? Protected by something?

      Or perhaps, given the volume of and competition between motherboard makers, someone will make a board that perfectly emulates this, except with an easy way to defeat the write-once feature? Sort of how my new Christmas APEX DVD player allowed me to easily turn off Macrovision by pressing 8 4 2 1 on the remote to get a secret menu.

      --

      I'll see your senator, and I'll raise you two judges.
    9. Re:Not necessarily for the masses by DickBreath · · Score: 2

      The Palladium and TCPA designs all seem to rely on a secure piece of hardware which would do secure hash id of the currently loaded OS. By emulating this chip in software, one could send responses to id-challenges as one wished, identifying as one OS, when really virtually running another.

      One TCPA design feature that would prevent Bochs from emulating it would be if the chip were tamperproof and had a private key in it with which it could sign anything requested. A trusted application, like Windows Media Player, after passing all other trust checks, even on Bochs, could then ask this motherboard chip to sign something. The public key would be known to everyone, so the signature could be verified that it came from this tamperproof chip. In fact, every chip could have a different private key, which itself is signed by a secret master key whose private part is NOT on the chip, but whose public part is well known. Now Bochs can't emulate that.

      But maybe a new kernel module could supply a new /dev/tcpa device where you write something, and read back a signed version. Then Bocks could go through this mechanism and still get it signed by the real hardware.

      Trying to think like a DRM designer for a moment, there must be a way to prevent Bochs from emulating the fritz chip.

      --

      I'll see your senator, and I'll raise you two judges.
    10. Re:Not necessarily for the masses by phr2 · · Score: 2
      A trusted application, like Windows Media Player, after passing all other trust checks, even on Bochs, could then ask this motherboard chip to sign something. The public key would be known to everyone, so the signature could be verified that it came from this tamperproof chip. In fact, every chip could have a different private key, which itself is signed by a secret master key whose private part is NOT on the chip, but whose public part is well known. Now Bochs can't emulate that.
      But what stops someone from modifying the code to bypass the signature check, just like just about every other copy protection scheme gets cracked and bypassed?
    11. Re:Not necessarily for the masses by Anonymous Coward · · Score: 1, Interesting

      "It is perfectly acceptable for a TCPA system running a TCPA software to reject Windows signatures as invalid while accepting a specialized version of say MacOS X or FreeBSD."

      And if you think that you'll be able to run your trusty older versions of Windows, such as (ick) Windows 9x, or even newer, more modern (and musch more usefull) Windows 2000 in the trusted mode, you're likely to be in for a big suprise.

      This can be used to screw far more people than just Linux/BSD/other alternative users over. Just one more way to force you to "upgrade".

    12. Re:Not necessarily for the masses by isorox · · Score: 2

      Not only that we don't know yet what OS they will work with. So lets not start doomsaying until the first of these are out and there is proof they refuse to run certain operating systems.

      I was bored one day, so I created isoroxOS v0.01, to learn about x86 assembly, try to get a thing displayed on the screen, and have fun. I did it because I can.

      I then put in the floppy disk, and rebooted. Machine POSTed, then suddenly

      AWOOOGAH AWOOOGAH AWOOOGAH AWOOOGAH AWOOOGAH AWOOOGAH

      Back in 1991, Linux wasnt an OS, it was a guy playing arround with getting something working on his computer. I dont care if it supports every OS imaginable, it wont support the one I might write in 4 months time.

    13. Re:Not necessarily for the masses by MntlChaos · · Score: 1

      why won't you be able to see the hash? something has to enable the programs to verify that hash. Just write a program that sort of has its own debugger to check the hash and record the value there. Distribute said program to others. Voila. lots of good hashes to use

    14. Re:Not necessarily for the masses by evilpenguin · · Score: 2

      If I were running a business, the notion that I would have to expose all my systems to an outside key server for "validation" and that some third party (I don't care how "trustworthy") would be able to disable my software or systems would be totally unacceptable. I will *never* buy "Trusted COmputing Architecture" enabled hardware for anything, ever. Even if it means I stay with the technology I have right now.

    15. Re:Not necessarily for the masses by Anonymous Coward · · Score: 0

      Yup, you can indeed bypass Palladium in such a way.

      Keep this in mind though... Soldering chips on a motherboard is not something my gandma could do and also not something the vast majority of the market would do. Keep in mind that one of the main reasons Palladium will be used is to allow RIAA companies, amongst others, to distribute their media "safely" to grand mothers that paid for it. So they probably don't care (right now) about people that are willing to take the risk of frying their PC.

      Palladium is not the revolution of revolutions in protection. It's just the next logical step to make things harder. I guess the next logical step after that would be to implant some chip inside everyone and call each other Palladiumnites(R) or sometin.

      Would you be willing to fiddle with THAT chip? Maybe it depends on where they put it...

    16. Re:Not necessarily for the masses by netsharc · · Score: 2

      Considering the doctored BIOS would not be checked by the real BIOS and rejected when it doesn't meet some requirements.. I suppose the MB makers can encrypt the BIOS with their private key, with the public key to decrypt it inside the BIOS, what then? (It would be a sorry bloated state indeed when features added to a BIOS include a PGP-decryptor)..

      I suppose it would end with mod-chips, or a RAM-"emulator" that plugs itself into the DIMM-socket, so when the decrypted BIOS is stored there, that BIOS is overwritten with a cracked BIOS.. aah what a crazy future. :)

      --
      What time is it/will be over there? Check with my iPhone app!
    17. Re:Not necessarily for the masses by Rysc · · Score: 1

      "Keep this in mind though... Soldering chips on a motherboard is not something my gandma could do and also not something the vast majority of the market would do. Keep in mind that one of the main reasons Palladium will be used is to allow RIAA companies, amongst others, to distribute their media "safely" to grand mothers that paid for it. So they probably don't care (right now) about people that are willing to take the risk of frying their PC."

      Not to mention: Coming soon, DMCA-backed lawsuits claiming that nullifying Palladium is circumventing copyright protections. It wont even get to court, most of the time, because sane people don't like multimillion dollar battles against beefy media lawyers.

      What? Freedom? Never heard of it.

      --
      I want my Cowboyneal
    18. Re:Not necessarily for the masses by 0111+1110 · · Score: 1

      This is also my question. I haven't seen it answered yet in this thread. I can only suppose the hope is that the original binary will have nearly unbreakable encryption. Because once the binary is decrypted on an older non-palladium system, crackers can have at the source with a good hex editor and pull out all the palladium hooks. Then it should run on on non-trusted systems (and trusted ones too I think). Note that this only has to be done once per app. I guess if the encryption is sufficiently good it could be unbreakable with current computers.

      --
      Quite an experience to live in fear, isn't it? That's what it is to be a slave.
    19. Re:Not necessarily for the masses by Anonymous Coward · · Score: 0

      Easy. The hardware waits one second before telling you "yes, the hash is valid", or "no, the hash is invalid". With a 160 or 256 bit hash, you'll be waiting a while to find the right answer by brute force. :(

    20. Re:Not necessarily for the masses by Kanasta · · Score: 2

      'a piece of memory that is hardware protected from being written to more than once per cold boot'

      Kinda reminds me of the pentium ID that 'could not be switched on without rebooting'

    21. Re:Not necessarily for the masses by cesarcardoso · · Score: 1

      It is perfectly acceptable for a TCPA system running a TCPA software to reject Windows signatures as invalid while accepting a specialized version of say MacOS X or FreeBSD.

      So an TCPA'ed Mac can be programmed to run only TCPA'ed MacOS X?

      --
      Cesar Cardoso can be found at cesar at zyakannazio dot eti dot br (or at least I believe so)
    22. Re:Not necessarily for the masses by MntlChaos · · Score: 1

      Easy. The hardware waits one second before telling you "yes, the hash is valid", or "no, the hash is invalid". With a 160 or 256 bit hash, you'll be waiting a while to find the right answer by brute force. :( riiight. one word: multithreading.

  12. digital signature? by Penguin+Follower · · Score: 2, Insightful

    It seems that the encrypted BIOS' integrity will be verified by a special chip or flash ROM, and will in turn verify the 'authenticity, integrity and privacy' of the boot loader and the operating system.

    Going by the above statement, one could interpret it as meaning you need a digitally signed bootloader... is this going to be a problem? (OSS that is).

    1. Re:digital signature? by CoolVibe · · Score: 2
      No of course not. We OSS folk can just abandon IA32 alltogether and hack along on our nifty new Apple powerbooks running either Mac OS X, Net/OpenBSD or Linux.

      Rip Mix 'n Burn anyone?

    2. Re:digital signature? by MikeDX · · Score: 4, Funny

      The promise has been made that the user, or at least the OEM, can add trusted signers.

      So does this mean I can remove the microsoft signatures to prevent any microsoft code being run at all? :) Gimme!

  13. Yeah, so I'm offtopic by Chocolate+Teapot · · Score: 5, Funny

    "American Megatrends" appears to be an anagram of "reincarnated smegma". Just felt the urge to share that,

    --
    Modest doubt is called the beacon of the wise. - William Shakespeare
    1. Re:Yeah, so I'm offtopic by Cinnibar+CP · · Score: 2

      Dim Game Scanner Rate?

      Sounds like a hidden way to inflate fees based on scanning the games you've pirated.

    2. Re:Yeah, so I'm offtopic by Ed+Random · · Score: 1

      Hrm... "Slashdot Community" -> "AC dimly mouths snot"... Coincidence?

      --
      -- Gxis! Ed.
    3. Re:Yeah, so I'm offtopic by Anonymous Coward · · Score: 0

      Hey, "Slashdot Moderators" -> "Fucking cocksuckers"! This anagram thing is great!

    4. Re:Yeah, so I'm offtopic by Anonymous Coward · · Score: 0

      Hey, "Slashdot Moderators" -> "Fucking cocksuckers"! This anagram thing is great!

      There's no "f" in "Slashdot Moderators" ... Wait a minute ...
    5. Re:Yeah, so I'm offtopic by Anonymous Coward · · Score: 0

      "American Megatrends" appears to be an anagram of "reincarnated smegma". Just felt the urge to share that

      It also contains the word American. I don't think I want to trust it.

  14. Can it boot "Non-Trusted OS's"? by wazzzup · · Score: 2

    From what I understand, yes but I may be mistaken since I'm working from a hazy memory here. I believe it can be turned off just like DRM. I would imagine that Windows (later versions) probably won't run without it turned on.

    Of course, it entirely feasible that one could be running a Linux distro that has jumped through all of the hoops to become certified "trusted".

    1. Re:Can it boot "Non-Trusted OS's"? by Satoshi+Harada · · Score: 1

      ...Or we can just all make our own 'Open-Source' BIOS. I can see it now...

      ``FreeBIOS - The Open Alternative''

      Hmm..and now that they've tipped us off, we can use the head start they've given us to our advantage!

      --
      Error: .Sig fault
    2. Re:Can it boot "Non-Trusted OS's"? by Nicolai+Haehnle · · Score: 2, Informative

      You mean like http://www.linuxbios.org/? ;)

    3. Re:Can it boot "Non-Trusted OS's"? by Satoshi+Harada · · Score: 1

      Aw, man! They stole my idea *already*! :)

      --
      Error: .Sig fault
  15. Q: One BIOS only? by 4of12 · · Score: 3

    So, with my limited understanding, I think of this thing running the BIOS through a one-way hash and comparing it to what's written in stone on NVRAM.

    Doesn't this mean that you cannot upgrade the BIOS?

    Or, that any "upgradeability" is tantamount to leaving a door open to unauthorized "upgrades" to the BIOS?

    TIA.

    --
    "Provided by the management for your protection."
  16. Trusted (Controlled by someone else) computing by COredneck · · Score: 1

    You buy a computer with your hard earned cash but yet, you cannot take full advantage of it since it is controlled by someone else.

    To add insult to injury, you pay for the privilege of being abused (controlled). What a wonderful deal, NOT !

    AMI can take their Trusted (controlled) computing and shove it where the sun don't shine.

    1. Re:Trusted (Controlled by someone else) computing by stratjakt · · Score: 1

      No, you as the system admin build a list of who you 'trust' and who you dont, much like SSL. There's no central signing authority. You can compile your own code and sign it. You can remove microsoft from the list of trusted signers. You can shut the whole damn thing off as a BIOS option. You can trust 'anyone' or nobody.

      --
      I don't need no instructions to know how to rock!!!!
    2. Re:Trusted (Controlled by someone else) computing by Anonymous Coward · · Score: 0

      Well this is how 'content' provider see computing.
      For Too Big(tm) corporation a computer is just a
      TV where users can buy thers stuffs.

      -The real Bob

  17. This is so sickening by Anonymous Coward · · Score: 0

    I pray no one will buy this crap.

  18. Where is the benefit? by Penguin2212 · · Score: 0

    Why would such protection be necessary? And who stands to benefit from this?

  19. Trusted to do what? by TheSHAD0W · · Score: 5, Insightful

    The original Palladium spec calls for a trusted machine to only allow trusted access by trusted operating systems. This means Palladium-encrypted code won't run except under a Palladium-rated OS. If the OS isn't trusted, then no Palladium-enabled programs can run.

    This will mean that WINE will be useless for many future Windows apps, especially those dealing with multimedia. It also means future versions of Windows will be written specifically to defeat applications like VMware, so as to not violate the security.

    These are bad, though they don't prevent one from booting a non-Palladium-enabled OS and using alternative applications. What I keep worrying about is the TCPA *2.0* specification. The original spec allows an alternative to a "trusted" platform, but future specs may require a PC boot a Palladium-enabled OS -- or none at all.

    1. Re:Trusted to do what? by pointym5 · · Score: 2
      to defeat applications like VMware
      The VMWare machine would have to be Palladium enabled; it's virtual BIOS would have to do all the same things. That would probably be difficult only in so far as it'd be hard to keep the chipset-level secrets.
    2. Re:Trusted to do what? by I'm+a+racist. · · Score: 2

      Let's start the countdown to the release of a "dePalladium"-enabled distro (of your chosen OS). Do you really think that this won't get hacked (somehow), within a few months or less?

      Just a few seconds of thought reveals two methods of defeating this sort of thing, in order to make your machine/OS seem "trusted". There's the possibility of having the operating system spoof the tokens that are supposed to come from the bios (while the bios is really running in "untrusted" mode). Worst case scenario, someone will start producing mods that bypass the hardware level security altogether (afterall, it may be something as simple as some flash ROM). As for running Palladium enabled software, that may only require breaking the Palladium encryption scheme (and we all know how well this sort of encryption has held up under scrutiny in the past).

      If you've got some cash to burn, give this a shot. Buy this board, load up your Palladium shit. Make sure it boots okay. Then shutdown, physically yank/destroy the Palladium chip, and restart. Since this is first generation stuff, a decent designer might go for high fault tolerance in the interface to this piece of hardware. If there wasn't good communication between members of the design team, the BIOS may not realize that the Palladium hardware is gone.

      Of course, any such work would be a possible DMCA violation and an EULA violation (among other bullshit legal transgressions).

      --


      Down with Saudi Arabia!!!
    3. Re:Trusted to do what? by Anonymous Coward · · Score: 0

      dmca :-(

    4. Re:Trusted to do what? by TheSHAD0W · · Score: 2

      Actually no; not only would VMware have to be Palladium-enabled, but the OS it was booted under would need to be as well. Otherwise, the hardware wouldn't allow the program access to the encryption hardware.

    5. Re:Trusted to do what? by TheSHAD0W · · Score: 2

      > Do you really think that this won't get hacked
      > (somehow), within a few months or less?

      The Palladium specification is actually very strong, and is designed to prevent "class breaks"; or, in other words, if you broke the key on one computer, it wouldn't affect the security on all the other machines out there. It's an open spec; if you want to examine the security, take a looksie.

      The first Palladium-enabled PCs will have separate encryption processors for dealing with trusted source. Future PCs will have that encryption built right into the CPU, and yanking it won't be an option. Further, when a program or OS is "trusted", it's not only signed but can also be encrypted, to prevent reverse-engineering; physically yanking/destroying the Palladium hardware would prevent the OS and programs from being accessed entirely.

    6. Re:Trusted to do what? by geekee · · Score: 2

      Did you consider that palladium is just 1 more feature that wine needs to support? It's like any other change MS makes to Windows that wine must support. In this case however, linux must support palladium as well, so someone should start working on that. palladium will be very useful for linux. Not including it will limit the multimedia content available while using linux.

      --
      Vote for Pedro
    7. Re:Trusted to do what? by I'm+a+racist. · · Score: 1

      I haven't read the spec (nor do I expect to look at it any time soon). It may be very well-concieved (as these things go), but there's a fundamental flaw...

      I, as the owner, have access to every last bit of the machine. Therefore, it can never be totally secure (from the MS/Big-Brother perspective).

      You mention the topic of class breaks... if I control the hardware, there's no need to break anything. That key is stored somewhere, for validation purposes, all I need to do is read (and decrypt; the encryption only needs to be broken once) or replace that key (hence, the mod-chip market). This is not that different from what's going on with X-Box modding nowadays (Disclamer: I'm not involved in the mod community, so I may be talking out of my ass.).

      As for the encryption... either they ship encrypted binaries for trusted computers only, in which case they can be decrypted, because all instances of said binaries use the same encryption. Or, they encrypt and subsequently decrypt the data at two points along the pipeline, on the fly, from the hard-drive/RAM to the execution register (which seems like a rather assinine thing to do anyway). In this case, the original binaries are unencrypted, so if your OS thinks it's trusted, it will encrypt, move, decrypt, and execute the instructions.

      As I stated in my first post, it shouldn't be exceptionally hard to trick the OS into thinking that it's trusted. As I see it, the biggest flaw in this system is that it passes its trust along blindly. Once the BIOS is trusted, it can pass it's trust down the chain, all the way to the application level (and the trustworthiness doesn't seem to degrade along the way). Thus, "full privledges" are granted to every actor in the scenario, thereby giving any actor the ability to subvert the whole system (ie. you can defeat this in either the hardware or the software).

      Yet another disclaimer: I have never been involved in serious computer security or encryption/trust schemes, so (again) I may be talking out of my ass.

      --


      Down with Saudi Arabia!!!
    8. Re:Trusted to do what? by TheSHAD0W · · Score: 3, Informative

      Palladium and open-source are pretty close to mutually exclusive. One COULD make a trusted *ix distribution, but either (1) the Palladium key would be held only by the distributor, and anyone writing patches would have to run the OS in untrusted mode, or (2) the Palladium key would be publically available -- and therefore no one would write trusted apps for it, for what would be the point? I do not know whether one could generate a working key from out of the blue, either.

    9. Re:Trusted to do what? by TheSHAD0W · · Score: 3, Insightful



      The X-Box is designed like that first class of Palladium chips, and security has been bypassed by placing a mod-chip in the data path of the key access. As I said before, in future implementations the crypto hardware will be inside the CPU chip, so there won't be a line to tap.

      You are correct the key is stored somewhere; but it's not anywhere it can be read. It's kept where a separate crypto processor can use it to validate signatures and decrypt code, but the PC has no access to it. Reading the key would involve physically opening and tapping into the chip, which is a practical impossibility for you or me. Such an effort might be worthwhile if reading the key would result in breaking the entire Palladium system, but as I said, the system is designed to thwart class breaks.

      You picture the processor decrypting code and storing it in main memory, but in fact the decrypted code is only stored locally. Again, on the first implementations, this code might be intercepted while it's on the bus between the crypto chip and the CPU, in the future it'll be impossible.

      As for "tricking the OS into thinking it's trusted"... Nope. The machine won't boot without trusted code, period. The BIOS is signed and trusted. It'll shut down the crypto processor and boot a non-trusted OS (at least in current specs), but from that point no trusted software can run. It will check the signature on a trusted OS and boot that; if the OS is modified, the signature will no longer match, and the OS won't boot.

      TCPA/Palladium is an extremely elegant, hardy, and EVIL system. It worries me greatly.

    10. Re:Trusted to do what? by Anonymous Coward · · Score: 0

      You could make your own keys and use it like Tripwire to guarantee that you haven't been root-kitted.

    11. Re:Trusted to do what? by grantm · · Score: 1
      future versions of Windows will be written specifically to defeat applications like VMware

      Microsoft's sales and marketing people actually make heavy use of VMware in their demo suites.

    12. Re:Trusted to do what? by hokanomono · · Score: 1
      Reading the key would involve physically opening and tapping into the chip, which is a practical impossibility for you or me. Such an effort might be worthwhile if reading the key would result in breaking the entire Palladium system, but as I said, the system is designed to thwart class breaks.

      Isn't it possible to emulate the hardware, if you have the key? As long as you have a computer where you can run your own programs (i.e. not all software has to be trusted), you could use the key to build an emulator that can run a trusted application, get the decrypted code, get other copyrighted decrypted data, which the system was to protect.

      Of course we would have a legal trouble similar to the DeCSS related thing. So maybe distributing the key will be illegal. A bigger problem might arise if possesion of hardware which allows you to run your own (self compiled) OS becomes illegal. Never underestimate the foolery of lawmakers, however i think there is still a long way.

      --
      This sig is a true statement, but I cannot prove it.
    13. Re:Trusted to do what? by CTho9305 · · Score: 2

      I may just be missing something - but presumably Windows programs would make an API call to get authentication... what stops wine from faking this? Is there some sort of privately signed, publically verified key that needs to be used that wouldn't be possible to obtain?

    14. Re:Trusted to do what? by TheSHAD0W · · Score: 2

      You are correct, sir; if you obtained one key, you could write an emulator that would operate using that key. Or you could clone Palladium hardware containing that key.

      It wouldn't last, though, I'm afraid...

      Once someone had gotten wind you'd cloned that particular key (and there might be several ways they could find out; multiple installations of software using that key, for instance), that key would be disallowed for future software registrations. It would mean you could no longer update your OS, and new installs of software couldn't be done, either.

      Evil, I say. Evil.

    15. Re:Trusted to do what? by 0111+1110 · · Score: 1

      How does this prevent someone from decrypting a copy of an application just *once* on their own system and then copying this data to a non-palladium system where they can go in with a hex editor and remove all of the source code hooks that interface with palladium features, so that the app is basically converted into a pre-palladium version, one that doesn't know anything about "trust"? Once the apps are cracked and converted to pre-palladium status, they could even be run on Windows1984 as long as the OS allows non-trusted apps to run. So for crackers, it seems that decrypting the original binary would be the toughest part. While the bios could perhaps verify the integrity of all previous versions of windows, I don't see how it could verify the hash of every single app that might be cracked.

      --
      Quite an experience to live in fear, isn't it? That's what it is to be a slave.
    16. Re:Trusted to do what? by Anonymous Coward · · Score: 0

      "in future implementations the crypto hardware will be inside the CPU chip, so there won't be a line to tap."

      If that becomes true for Intel/AMD, then by that time I'm sure there will be a chinese chip for sale that doesn't have that crap.

  20. Seat of Trust is infinite regression by DakotaSandstone · · Score: 1
    This is just another attempt to make a definitive, final "seat of trust" for computing. Only now, it's in proprietray X86 assembly code that OEM's pay tens of thousands of dollars for.

    Also, conceptually, this will still not solve the trust issue, as someone could still open up their case and replace their BIOS chip.

    Most of us build our "seats of trust" on human relationships, like our family and friends. Oh, and these guys, too.

    --
    Nothing is so smiple that it can't get screwed up.
    1. Re:Seat of Trust is infinite regression by SupahVee · · Score: 5, Insightful

      Also, conceptually, this will still not solve the trust issue, as someone could still open up their case and replace their BIOS chip.

      Ever tried to replace a BIOS that is soldered directly to the board? if so, please let me know how it went. :-)

      --
      "See, we plan ahead! That way, we never have to do anything now."
    2. Re:Seat of Trust is infinite regression by DakotaSandstone · · Score: 1
      Actually, I have, but thankfully that was a work-releated thing. It went OK.

      The problem is not the average Joe trying to do something like this. In fact, most average Joes would have no interest in trying to defeat a trusted computing scheme.

      The problem is the smart guy in the basement with a soldering gun and a lot of pent up rage against society.

      --
      Nothing is so smiple that it can't get screwed up.
    3. Re:Seat of Trust is infinite regression by Anonymous Coward · · Score: 0

      Did just that. I have desoldered the BIOS (surface mounted PLCC 32) on my compaq and soldered in a surface mounted socket and reinsert the chip that I have desoldered. I am trying on that machine right now BTW.

      So it would appear that it is easier than trying to find a BIOS chip that would work for your hardware. Trust me, I still can't find a BIOS for my particular acient compaq that supports a celeron processor.

    4. Re:Seat of Trust is infinite regression by Anonymous Coward · · Score: 0

      I bet you can't shoot a jump shot either.

    5. Re:Seat of Trust is infinite regression by Jester99 · · Score: 2

      Ever tried to replace a BIOS that is soldered directly to the board? if so, please let me know how it went

      Yup. First I yanked out the old board, then I popped in the new one. :)

      Tada, new BIOS.

  21. so what does this mean? by csguy314 · · Score: 2

    Will there be hardware produced that is locked to specific operating systems?
    Will it not be able to bot multiple operating systems?
    I know those companies mentioned have supported GNU/Linux so I doubt they will start making strictly windows only hardware. But what are the immediate effects we can expect to see when this becomes a little more prevalent?
    And what will be the long term effects? Will I be able to boot the Hurd when it's released?

    --
    This is left as an exercise for the reader.
    1. Re:so what does this mean? by Anonymous Coward · · Score: 0

      Will I be able to boot the Hurd when it's released?

      I wouldn't worry about that until version 4.0 of the Palladium spec is out. The Hurd might be ready by then.

  22. Comment removed by account_deleted · · Score: 5, Informative

    Comment removed based on user account deletion

  23. Congratulations, AMI by SupahVee · · Score: 3, Interesting

    You've just lost one customer, from this point forward, no matter how difficult it may be for me to find other products, I will not buy ANY hardware that contains a BIOS made made by your company.

    WHile this may not seem like a big deal, I _am_ in the market for a new system, and have a decent budget to do it with.

    --
    "See, we plan ahead! That way, we never have to do anything now."
    1. Re:Congratulations, AMI by Arcturax · · Score: 2

      Can't buy from Phoenix either by this logic because they demanded that the Phoenix browser change its name.

      --

      --Won't that be grand? Computers and the programs will start thinking and the people will stop. - Dr. Walter Gibbs
    2. Re:Congratulations, AMI by Mongo222 · · Score: 1

      Make that at least two. If this kind of thinking becomes accepted by the population, as opposed to the companies trying to ram it down our throats, I'm going to stop buying computers. Maybe it's time to learn to weld or take up wood working?

    3. Re:Congratulations, AMI by poot_rootbeer · · Score: 1


      It's NOT a big deal. AMI doesn't care whether you buy a PC with an AMI BIOS or not. They realize that most people are not knee-jerk alarmists.

    4. Re:Congratulations, AMI by Anonymous Coward · · Score: 0

      Well, since only OEMs and mainboard manufacturers are truly "customers" of AMI, AMI will not see this as a loss of a customer. Instead, it is up to the motherboard vendor/OEM to choose this option to put into their BIOS or not. AMI doesn't force this option (or any BIOS option) on anyone.

      Instead of boycotting all AMI BIOS-based motherboard/systems, you should find out which vendors are including this (or any other unwanted options) in their BIOSes and boycott them.

    5. Re:Congratulations, AMI by jkujawa · · Score: 2

      I trust my BIOS.

      It's called OpenFirmware, and it's been in every mac since the original iMac.

    6. Re:Congratulations, AMI by jawtheshark · · Score: 1

      Not knee jerking alarmists? Recall the P-III CPU-ID...

      --
      Ahhh...the great dumpster continuum. Many a free computer will be found there. -- sowth (748135)
    7. Re:Congratulations, AMI by DickBreath · · Score: 3, Informative

      I trust my BIOS. It's called OpenFirmware, and it's been in every mac since the original iMac.

      Open Firmware predates the iMac. OF was not an iMac innovation.

      Open Firmware has been in Macs since about 1995. The first Mac PowerPC's model 6100, 7100, 8100 used NuBus ran Mac OS 7.1 and did not have Open Firmware. The next round of Macs did away with NuBus in favor of PCI and had Open Firmware -- in 1995. All subsequent Macs (many many models) have had Open Firmware, including the iMac.

      --

      I'll see your senator, and I'll raise you two judges.
    8. Re:Congratulations, AMI by lostindenver · · Score: 1

      Another one that will not By I guess I might have to by a MAC. Open Bios is sounding better. At leat I dont have to worry about my Sun Systems YET.

    9. Re:Congratulations, AMI by Anonymous Coward · · Score: 0


      That was pretty funny, too.

    10. Re:Congratulations, AMI by Anonymous Coward · · Score: 0
      Open Firmware predates the iMac. OF was not an iMac innovation.

      Wasn't even an Apple innovation. I have a sparcstation 4 from 1994 here in my office that runs OF.

  24. Yes. by Kickasso · · Score: 2, Insightful

    No lilo/grub/whatever for you! Unless distro vendors will somehow manage to sign their binaries. For dual-boot you'll need to resort to diskettes or other such sillyness.

  25. How is this interesting? by Anonymous Coward · · Score: 0

    This is a total troll.

    1. Re:How is this interesting? by pkwijibo · · Score: 0, Offtopic

      It is supposed to be funny jackass. Notice the funny flag? You know, haha funny?

    2. Re:How is this interesting? by Anonymous Coward · · Score: 0

      Funny != Interesting, so point stands.

    3. Re:How is this interesting? by Anonymous Coward · · Score: 0

      I bet the guy is not laughing now that his AC post was modded +5. That's gotta sting a bit.

    4. Re:How is this interesting? by PunchMonkey · · Score: 1

      No... *That* was a funny post. *Your* post was a troll... and come to think of it.... this probably is too. MOD ME DOWN -1 TROLL.

      --
      I'll have something intelligent to add one of these days...
    5. Re:How is this interesting? by Anonymous Coward · · Score: 0
      I bet the guy is not laughing now that his AC post was modded +5. That's gotta sting a bit.

      Not even a little. I don't want +5, Funny comments associated with my account.

    6. Re:How is this interesting? by Anonymous Coward · · Score: 0

      The fact that anything is "flagged" as funny by the socially stunted children around this place means absolutely nothing in the real world.

  26. Maybe I am dense... by gosand · · Score: 5, Interesting
    Am I just stupid? How come I don't really see the benefit of this? Sure, the BIOS checks to see that the OS and hardware are "trusted", but what does this really buy you? So it says: OK, we have an official copy of Windows XP installed. Does this mean that the system is now secure? Hardly. What would something like this, even if it worked flawlessly, protect the user from?


    I honestly don't understand the value (or perceived value) in having this.

    --

    My beliefs do not require that you agree with them.

    1. Re:Maybe I am dense... by MrWa · · Score: 5, Insightful
      So it says: OK, we have an official copy of Windows XP installed. Does this mean that the system is now secure? Hardly. What would something like this, even if it worked flawlessly, protect the user from?

      No, you aren't dense...just fooled by the doublespeak that Microsoft and the like use when describing this type of Digital Restriction Mechanisms. You aren't supposed to trust the hardware or software - this system is not being created to protect the user from anything. The intent is to protect developers (of software or media) from the users.

      Think of it as a way for Microsoft to write an OS - however buggy and insecure you like - and, supposedly, have the ability to run programs and display media with the knowledge that it is secure from being manipulated or used by the user in a way that Microsoft does not want.

    2. Re:Maybe I am dense... by pmz · · Score: 2

      OK, we have an official copy of Windows XP installed.

      Even better, it says: OK, we have an official known configuration of Windows XP installed. Bugs intact and certified!

      How hard would it be for a cracker to determine the relatively small set of official known configurations out there, develop a new type of port scanner or whatever, and attack away? Finding ways of getting scripts or whatever to execute within the "trusted" environment will be a fun weekend project for many many curious (perhaps mischievous) people out there.

      Seriously, the philosophy of sticking to signed code means that the patch cycle really has to slow down. How does Microsoft actually keep track of the signatures of Win XP OEM vs. Win XP OEM + a single patch (or any number of patches)? Sounds like a problem of exponential growth to me.

    3. Re:Maybe I am dense... by dazed-n-confused · · Score: 2

      You aren't supposed to trust the hardware or software - this system is not being created to protect the user from anything. The intent is to protect developers (of software or media) from the users.

      See Ross Anderson's TCPA/Palladium FAQ if you really want to know what's going on.

    4. Re:Maybe I am dense... by StupidHelpDeskGuy · · Score: 1

      What would something like this, even if it worked flawlessly, protect the user from? Freedom.

  27. read for yourself by greechneb · · Score: 2
    From the Trusted computing website:

    Is the TPM based platform limited to a particular operating system or microprocessor?

    No. The TCPA specification is designed to be platform and OS agnostic. The TCPA specification is not limited to a specific platform, OS or CPU.

    The specifications are available for download free from trustedcomputing.org - Any linux distro should be able to take advantage of them.

    Its up to you to decide if you want to trust it or not, but that's what their website states.

    1. Re:read for yourself by Prior+Restraint · · Score: 2

      The TCPA specification is designed to be platform and OS agnostic.

      My concern about this statement is the implicit assumption that the specification will be faithfully followed.

    2. Re:read for yourself by Anonymous Coward · · Score: 0
      The specifications are available for download free from trustedcomputing.org [trustedcomputing.org] - Any linux distro should be able to take advantage of them.

      Yes, one would definitely like to take advantage of them :-)

  28. AMI Introduces 'Trusted Computing' BIOS by Anonymous Coward · · Score: 0

    AMI Introduces 'Trusted Computing' BIOS!!! more like celda

  29. I hate to say it by jayhawk88 · · Score: 3, Funny

    ...but does this mean *BSD really is dying, and all those trolls have been right all along?

    1. Re:I hate to say it by Mithy · · Score: 2

      Hardly. NetBSD is toaster-compatible, so we'll just stop buying x86 junk.

      --

      --
      "This isn't the post you're looking for. Move along."
  30. Supply and Demand by Badgerman · · Score: 2

    Well, we may get the supply - but will there be demand? Somehow I'm not so sure on that.

    Besides, how much unbreakable security now lies broken? If Palladium does become a hot fad, it's going to cool down quickly when people find cracks/workarounds - as you know they will.

    --
    "The Sage treasures Unity and measures all things by it" - Lao Tzu
    1. Re:Supply and Demand by Anonymous Coward · · Score: 0

      Supply and Demand rules only works in real
      market where
      monopolies are not present.

    2. Re:Supply and Demand by egoff · · Score: 1

      Demand for Microsoft products isn't a function of demand, but rather of strong marketing and a powerful brand. What normal consumer wouldn't want to buy a computer thats "100% more secure" to stop all those "nasty computer viruses these days"?

  31. Comment removed by account_deleted · · Score: 4, Interesting

    Comment removed based on user account deletion

  32. I was thinking more on the lines of by Anonymous Coward · · Score: 0

    Raping-his-mom funny, but maybe that's just me.

    1. Re:I was thinking more on the lines of by Anonymous Coward · · Score: 0

      It's just you.

  33. It will enable you to get DRMed content. by Kickasso · · Score: 5, Informative

    That's it. A remote site can know whether or not you're running a trusted (IOW "unhackable") OS/apps. If you do, they'll send you decryption keys for playback and be reasonably sure you won't intercept them, store them permanently etc.

    1. Re:It will enable you to get DRMed content. by UberLord · · Score: 1

      I'm sure someone will come up with a way of making a computer VCR that sits between the PC and monitor.

      Unless of course, they invent monitors that can decrypt an encrypted signal :(

    2. Re:It will enable you to get DRMed content. by Anonymous Coward · · Score: 0

      "Unless of course, they invent monitors that can decrypt an encrypted signal :("

      there are monitors out that use USB to connect to the computer. You could easily have encryption from the pc to the monitor with that sort of setup.

      spooky

    3. Re:It will enable you to get DRMed content. by isorox · · Score: 1

      iso@isorox:~$ ethereal

    4. Re:It will enable you to get DRMed content. by Anonymous Coward · · Score: 0

      ...be reasonably sure you won't intercept them, store them permanently etc.

      Unless you do a man-in-the-middle on yourself with an "untrusted" box. Oops, the whole system just broke down.

    5. Re:It will enable you to get DRMed content. by Alsee · · Score: 2
      I'm sure someone will come up with a way of making a computer VCR that sits between the PC and monitor.
      Unless of course, they invent monitors that can decrypt an encrypted signal :(


      Well DUH. That is already part of Palladium. (PDF FILE)

      Page 6: New Security Features

      4. Secure Input/Output: user input (i.e. mouse, keyboard)/output (i.e. monitor) are encrypted and thus cannot be sniffed or spoofed


      Even people who know Palladium is evil generally don't realize just how evil it is. You need Palladium certified and encrypted mouse, keyboard, monitor, soundcard, video card, network card, probably the even the freaking parallel port and game port.

      -

      --
      - - You can't take something off the Internet! That's like trying to take pee out of a swimming pool.
    6. Re:It will enable you to get DRMed content. by Anonymous Coward · · Score: 0

      Yay! :-D

  34. Trust whom? by bytesmythe · · Score: 5, Interesting

    Just follow this little (hypothetical) chain of events:

    1) BIOS on new motherboard will only go into "Palladium-mode" if you're booting a "trusted" OS. For the time being, you can still run linux, but it won't have access to any "Palladium" features.

    2) If you're running a "trusted" OS (eg. MS Windows UY [Up Yours]), the OS can hit the 'Net and automatically download and apply updates to itself. At some point, it could quite easily detect the BIOS on your system and apply an update so that...

    3) The BIOS will no longer boot non-trusted systems. Also...

    4) The OS could download a new protocol stack that could render it inoperable with other protocols. An entire new Internet based on the MSOY/BO (Microsoft Ownz You/Bend Over) protocol could spring up almost over night. MS-only network services, online shopping, etc.

    Is any of this likely to happen? I don't know. But it would be possible, and I'm not sure I trust Microsoft not to try it. Even if Open Source doesn't relegate MS to the /dev/null of the computing industry, the OS community is going to need each other to maintain a DRM-free computing zone. Open source, open protocols, open formats, open beer.

    --
    bytesmythe
    Hypocrisy is the resin that holds the plywood of society together.
    -- Scott Meyer
    1. Re:Trust whom? by slide-rule · · Score: 1

      Your hypotheticals 1,2,3 are enough to worry someone that dual-boots. (i.e., myself on one of my home systems). However, I'm not sure that point 4 would happen quite so suddenly. A new "MSOY/BO" protocol wouldn't be understood magically by non-MS systems (i.e., Unix running Apache servers, etc.). Now, it might cause the final schism between those that use MS and those that do not, but I wonder, what with all the complete b*llsh*t we put up with since the 'net turned commercial and branded, would that be a bad thing? At any rate, your points got me thinking. Thanks for that. =)

    2. Re:Trust whom? by aburnsio.com · · Score: 2
      4) The OS could download a new protocol stack that could render it inoperable with other protocols. An entire new Internet based on the MSOY/BO (Microsoft Ownz You/Bend Over) protocol could spring up almost over night. MS-only network services, online shopping, etc.

      Yes, they could do that. They could also hire their own mercenary army to take over the Justice Department (to back up the lobbyists ;-). But will they?

      They've been walking the fine line between the legal and the illegal for many years now, sometimes crossing over it. Creating a MS-only web protocol and forcing everyone to use it would almost certainly be a very flagrant and obvious restraint on free trade and thus illegal under both federal and state statutes. Not illegal as in "we're doing to make you put Java in your OS" illegal, but illegal as in "even the politicians you gave big money to are starting to denounce you." Public opinion can be finiky, but once you get on the bad side in a democracy, and enough people hate you, you're doomed. This is the lesson of the Robber Barons of olden times and the response of the Progressive Movement.

      Look at Hailstorm. They had to back down because of such issues. They've also had trouble with Passport adoption because, surprise surprise, not everyone wants to share their customer information with Microsoft.

      It's become almost a proverb not to underestimate Microsoft. But it's also foolish to overestimate them; as big as they are, they're still only a small drop in a very big corporate ocean, and an even smaller drop in the realm of global goverments.

    3. Re:Trust whom? by jafac · · Score: 2

      A bazillion kajillion internet routers better understand how to parse and deal with MSOY/BO. . . overnight? Don't think so. . .

      --

      These are my friends, See how they glisten. See this one shine, how he smiles in the light.
    4. Re:Trust whom? by Anonymous Coward · · Score: 0

      What they need Palladium for in order to make MSOY/BO-only OS?

    5. Re:Trust whom? by bytesmythe · · Score: 2
      A bazillion kajillion internet routers better understand how to parse and deal with MSOY/BO. . . overnight?


      Routers don't have to... The system could still use TCP/IP for it's main communication and put an extra encrypted layer on top that only a Palladium-based system could interpret.

      --
      bytesmythe
      Hypocrisy is the resin that holds the plywood of society together.
      -- Scott Meyer
    6. Re:Trust whom? by Anonymous Coward · · Score: 0

      A while ago, I thought of how a worm could successfully take over the internet and KEEP IT.
      It's one thing to contaminate 50% of the nodes at some point in time, but it's quite another to keep control of the system over time.
      One approach consists in not being detected. Historically that hasn't worked very well, despite sloppy admins.
      The other approach is to do what the parent describes: All infected computers start to communicate through MSOY/BO overnight. If done right, this puts the admin in a situation where he can either:
      - remove the worm, and lose the ability to communicate with XX% of the net, or
      - keep the worm, which seems to be otherwise harmless, as a "temporary" solution, to keep things working.

      Of course, this approach works best if there is no system diversity to speak of.

      Well, now I have to find yet another totally novel idea to take over the net.

    7. Re:Trust whom? by be-fan · · Score: 2

      Yes, they could do that. They could also hire their own mercenary army to take over the Justice Department (to back up the lobbyists ;-). But will they?
      >>>>>
      Does it matter? Do you want the monkey holding the gun, whether or not it will shoot?

      --
      A deep unwavering belief is a sure sign you're missing something...
    8. Re:Trust whom? by ddimas · · Score: 1

      Sorry, I'm very INSULTED about this whole trusted computing initiative. Basicly, what Microsoft, Intel, and the media providers are saying is that I am a criminal, but I can be trusted with this CRIPPLED system. Please feel free to correct me if I'm wrong.

  35. This along with CPRM by tres3 · · Score: 1

    These are things that we should try to keep everyone we know from buying. Hopefully it will go the way CPRM (for IDE drives) went. Yes I know its still there but the manufacturers are a little bit gun shy about introducing in a public fashion because of the uproar that they caused last time. I know slashdotters are pretty tech savy people but let's try to educate the rest of the world. A disaster would be if they ended up being silently shipped for a little while, until they attained critical mass, and then someone threw the switch and disabled our boxen (or at least the boxes that have their freedom still intact).

    1. Re:This along with CPRM by Anonymous Coward · · Score: 0

      regarding TCPA being silently shipped, see this comment from
      http://www.cl.cam.ac.uk/%7Erja14/tcpa-faq.ht ml

      (and i recommend everyone read the article in full):

      21. When is this going to hit the streets?

      It has. The specification was published in 2000. Atmel is already selling a Fritz chip, and although you need to sign a non-disclosure agreement to get a data sheet, you have been able to buy it installed in the IBM Thinkpad series of laptops since May 2002. Some of the existing features in Windows XP and the X-Box are TCPA features: for example, if you change your PC configuration more than a little, you have to reregister all your software with Redmond. Also, since Windows 2000, Microsoft has been working on certifying all device drivers: if you try to load an unsigned driver, XP will complain. There is also growing US government interest in the technical standardisation process. The train is rolling.

      The timing of Palladium is less certain. There appears to be a power struggle going on between Microsoft and Intel; Palladium will also run on competing hardware from suppliers such as Wave Systems, and applications written to run on top of vanilla TCPA will need to be rewritten to run on Palladium. This seems a play to ensure that the secure computing platform of the future is controlled by Microsoft alone. It might also be a tactic to deter other companies from trying to develop software platforms based on TCPA. Intel and AMD appear to plan for the second generation of TCPA functionality to be provided in the main processor for free. This might provide higher security, but would enable them to control developments rather than Microsoft.

      I do know that the Palladium announcement was brought forward by over a month after I presented a paper at a conference on Open Source Software Economics on the 20th June. This paper criticised TCPA as anticompetitive, as amply confirmed by new revelations since.

  36. Slow death of general use computer by Drew4president · · Score: 2, Insightful

    I've heard predictions that as the price of computers drop, the general use PC will be replaced with many specialized computers that do specific things like play media, run office type applications, E-mail etc. They can be user-friendly, but are not as flexible as a PC. I think we are already seeing this a little with TIVO, PS2, x-box, some of the net-appliances.... I think most PC enthusiasts won't want to accept this, but non-technical people might. And these products will lend themselves more toward a trusted-computing model

    1. Re:Slow death of general use computer by Anonymous Coward · · Score: 0

      Yes, more spending on vendor-controllable platforms.

      The PC revolution was at least partly (mostly) built by drones stating they need to mimic what systems are at the office and spending massive fortune 500 payroll dollars on them, directly or indirectly; except now, they feel comfortable and the novelty is gone. The PC market drops precipitously and the number of dumb user boxes rise.

    2. Re:Slow death of general use computer by Anonymous Coward · · Score: 0

      You've got to remember that *most* of the people using computers now don't really *use* their computer. Most (people here on slashdot excepted) are using their systems as a sort of interactive television. They get their AOL account and use/accept what is "pushed" to them through that account. They don't perform even basic upkeep of the o/s, they never upgrade anything. The computer, for them, is just another appliance. This paladium thing will be great for them -- it will insure they will never truly use their system, never get away from Mother's (Microsoft's) apron strings. I really believe most people using a computer has no true concept of "operating system". Windows is all they know. It is expected; it is what "the computer" is.

  37. Another Monopoly? by Renraku · · Score: 2

    I guess Microsoft gets sole control of the 'trusted' keystring. Anyone else using it without paying them 'licencing' fees for it will be in violation of th DMCA. So sure, you can have Linux on your computer, but doing so will be illegal because our friends at Microsoft will refuse to sell out their keystring to make Linux legally bootable. Brilliant. If you can't out-compete someone, change the standard to tighten your monopoly.

    --
    Job? I don't have time to get a job! Who will sit around and bitch about being broke and unemployed then?
  38. Can you say.... by Anonymous Coward · · Score: 0

    Can you say www.apple.com/switch ???

  39. Re:awesome technology by Anonymous Coward · · Score: 0

    "The BIOS then verifies the authenticity and integrity of the OS loader and the OS kernel and then passes the integrity tokens that say the PC is a "trusted entity" to the operating system."

    What a load of crap. WTF problem does this actually address other then the fact that it would keep the M$ monopoly alive.

    AMI SUCKS...

  40. BIOS features by erroneus · · Score: 4, Interesting

    I think this reminds me of the situation with the CPU IDs in the Intel Pentium processors. I have yet to see a BIOS supporting such processors without the ability to disable the serial number.

    I suspect that the "trusted computing" features will be similar it its ability to disable such things. It will be required of virtually every motherboard manufacturer who wants to compete. I can't imagine hardware manufacturers being pressured into making a palladium only system.

    1. Re:BIOS features by Anonymous Coward · · Score: 0

      The order goes:

      TPM check's the BIOS integrity
      BIOS checks OS integrity
      Boot up.

      So, there could be a switch in the BIOS to not check the OS integrity....but the million dollar question is where is the switch that makes TPM not check the BIOS. Can't be too easy to find otherwise the whole system is useless (easily cracked). Huh. Anyone got a clue?

    2. Re:BIOS features by FreeUser · · Score: 3, Interesting

      I think this reminds me of the situation with the CPU IDs in the Intel Pentium processors. I have yet to see a BIOS supporting such processors without the ability to disable the serial number.

      Yes, but Intel CPUs allows software to reenable the serial number at whim, so even though you've turned it off the BIOS, MS Spyware is still able to read it and stamp in onto every video library file you make, or even view, if it so desires.

      The BIOS setting was a public relations gesture, with no real substance, and no protection for the consumer from exactly the sorts of abuses the public outcry against the feature engendered in the first place.

      I suspect that the "trusted computing" features will be similar it its ability to disable such things. It will be required of virtually every motherboard manufacturer who wants to compete. I can't imagine hardware manufacturers being pressured into making a palladium only system.

      I suspect you're right ... it will be very like the CPU ID. You'll be able to turn it off in BIOS, and Microsoft SpyOS (or Real Networks SpyViewer for Linux) will turn it right back on again, right behind your back.

      Worse, as another noted quite insightfully, Version 2 may not allow non-compliant OSes to boot at all. Goodbye FreeBSD, goodbye GNU/Linux, goodbye Free Software, goodbye Freedom. At least in the western world ... China, Taiwan, and India will likely find a very receptive market in the rest of the world to a non-Palladium platform still capable of running GNU/Linux or FreeBSD ... and the Palladium/DRM infected nations (USA, Australia, perhaps Europe) will be relegated to a technological backwater before the century is even half gone.

      --
      The Future of Human Evolution: Autonomy
  41. War on Consumers by UberLord · · Score: 1, Troll

    This will go a long way towards the war on Open Source. Consumers won't be able to install and use unauthorized OS's. This could potentially save thousands of dollars.

    1. Re:War on Consumers by SN74S181 · · Score: 2

      Don't be alarmist. This will go a long way towards people being able to download and view 'DRM-required' media content. If you install an 'untrusted' OS on the computer, it will work fine, but DRM-required media content won't play on it.

      The whole thrust of this is that all-layer security must be implemented down to the BIOS level for the whole 'trusted hard/software' scheme to work.

      It's shocking how flames of ignorance are fanned here in this supposedly tech-aware community purely so some FUD can be manufactured.

  42. Ahem. by labratuk · · Score: 3, Insightful

    That's one type of motherboard I won't be buying.

    --
    Malike Bamiyi wanted my assistance.
    1. Re:Ahem. by geekoid · · Score: 2

      Please write them and tell them why. keepo it sort and to the point. ENcourage otyhers to do the same.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    2. Re:Ahem. by jsantala · · Score: 1

      Exactly, who's forcing you to buy a motherboard with such a BIOS? Just don't buy it, problem solved. There will always be other options, its not like MS Watch is the only option anymore is it?

  43. In The Land Of The Elves... by Anonymous Coward · · Score: 0

    Encrypted Chips are found in mystery cookies.

    1. Re:In The Land Of The Elves... by Anonymous Coward · · Score: 0

      Who's that bitch?
      People you don't know
      Me and Timbaland been hot since twenty years ago
      What the dealio?
      Now what the drilly, yo
      If you wanna battle then (nigga) let me know
      Holla, gotta feel me son
      Let me throw you some
      People here I come
      Now sweat me when I'm done
      We got the radio shook like we got a gun

    2. Re:In The Land Of The Elves... by IcyHotStuntazerlicio · · Score: 1

      Lay down flip it and reverse it. I gotta work ya.

    3. Re:In The Land Of The Elves... by Anonymous Coward · · Score: 0

      My meme's anger management counselor can beat your meme's assertiveness trainer.

  44. Trusted OS? by mustangdavis · · Score: 2

    Great .... so how determines which OSes are "trusted" (and how much of a kick back do "they" get)?

    But even more importantly, whay happens if my board dies and I have to load the disk into another machine to get the data off of it ( ... and lets say that I only have 1 windows machine and one linux machine ...)

    ... and what happens if you try to boot a "non trusted" OS ... is it like an ATM and does it eat your hard drive?

    What is the point of this??? If ou have access to the hard ware, you can steal what is on the disk!!! Do what Nike would do if they were a computer compnay: Just mount it!


    Just my $0.02 cents .... but I expect change this time!


    1. Re:Trusted OS? by Theatetus · · Score: 2
      so how determines which OSes are "trusted" (and how much of a kick back do "they" get)?

      Well, under this proposal, you (or your sysadmin) get to decide which OSes are "trusted". And I doubt you would get much of a kickback.

      ... and what happens if you try to boot a "non trusted" OS ... is it like an ATM and does it eat your hard drive?

      It boots into untrusted mode; you don't get the "features" of "Trusted Computing" (tm)

      What is the point of this???

      As I understand it, to have hardware-level enforcement of "safe" memory management to make sure that a signed application can only have its data affected by another signed application. I don't see why people want that in hardware, but that is, at least, the supposed reason.

      --
      All's true that is mistrusted
    2. Re:Trusted OS? by mustangdavis · · Score: 1



      ... I was joking .... it was supposed to be funny

      I'll try harder next time :)

  45. That guy on the side of the road... by mrwonton · · Score: 1

    may have been right! And to think, I ignored his "The End Is Near" Sign. =P

    --
    Not more than you need, just more than you want
  46. Contradiction by Anonymous Coward · · Score: 0

    Does that mean such machines may refuse to boot any other non-'trusted' OS?
    After all, the list of supporting corporations include ...
    of whom we heard quite favourable statements about Linux

    I sometimes wonder if 'Slashdot editors' get paid enough.

  47. Psh, who gives a shit? by Anonymous Coward · · Score: 0

    Regardless of whether or not Palladium will lock you in to running specific approved operating systems (not likely if they actually come through on what they originally said), computer sales are sliding as we speak. By the time Palladium-enabled hardware becomes available on the consumer market, virtually every household able to afford a computer will have one already. From my personal experience with most family folks, a computer is more of an appliance than anything else to them, so I doubt they'll fork out another $2-3k on some new machine when what they have already does everything they want. Same reason why you still see old cars from the past two decades being driven around. Sure, they don't have all the spiffy new features of the latest-and-greatest range of cars, but they get passengers from point A to B, and that's all they care about.

    The only market I see this making any impact on is PC-based boxes that are used in a tivo-like capacity (ala WinXP media center edition), since those aren't very widespread right now but slowly catching on.

    1. Re:Psh, who gives a shit? by stratjakt · · Score: 1

      But 'family folks' aren't the target of this. Business/military/government workstations are. A large corporation just might replace some or all of it's more crucial systems for the promise that they'll never lose another week or two of productivity because some nitwit in accounting opened an e-mail that read "I love you".

      --
      I don't need no instructions to know how to rock!!!!
  48. Give credit where credit is due by Anonymous Coward · · Score: 0

    That's from my journal (here).

    I wholeheartedly support making this information more public, but I'd like to have the sympathy for my plight. Michael is a prick and a hypocrite, and if he could get over the tension between him and that psychotic fruitcake Seth, they'd have a wonderful relationship.

    Also, if you crapflood with my stuff, that won't be cool.

  49. boo by Anonymous Coward · · Score: 0

    First it was jocks saying my penis is bigger than your penis, now it will be geeks saying my bios is better than your bios.

  50. Major oversight...... by MegaHamsterX · · Score: 2, Interesting

    I just thought about this a bit more and...
    Say someone is running a certain email program
    and a 12 year old writes a script to exploit this mail program
    his exploit does nothing more than pad the kernel with garbage
    The original hapless individual shuts his computer down
    When he powers it up the next day, it refuses to boot as the kernel has been modified
    since his hard disk is encrypted he can't retrieve any of his data from the system, nor can the tech he brought it to...
    So he smiles, reinstalls and rebuilds all the work he just lost, as a backup isn't anything he ever thought of making.

    Give this a year or two and we'll see IBM make a push to bring reliable, centrally maintained machines into workplaces.

    1. Re:Major oversight...... by Anonymous Coward · · Score: 0

      Well, duh. This is a simple one. The OS just has to not let you change the kernel! Windows has that cool (and I'm sure foolproof) thing where it won't let you modify system files.

    2. Re:Major oversight...... by MegaHamsterX · · Score: 1

      Heheh....Man that is a good one, you had me rolling on the ground in painful laughter.

    3. Re:Major oversight...... by spitzak · · Score: 2
      Yikes! This is extremely serious threat, I think.

      The chances that every single piece of data that Palladium will check in order to get to a working state will be correctly protected from change by a non-Palladium approved program is virtually zero. It would be easy to make a virus that can render any Palladium machine into a doorstop.

    4. Re:Major oversight...... by Anonymous Coward · · Score: 0

      I hope virus writers wait until there a good quantity of Palladium boxen shipped, the better to make the point.

  51. The BIOS verifies itself? by redfenix · · Score: 5, Insightful



    BIOS starts...addressing the TPM chip that verifies the authenticity of the BIOS.

    What good is it for the BIOS to verify itself?
    If it's not authentic (i.e. compromised), would it really bother to address the TPM chip at all?

    --
    "It's a very tangled subsystem." --Windows kernel guru
    1. Re:The BIOS verifies itself? by Anonymous Coward · · Score: 0

      What good is it for the BIOS to verify itself? If it's not authentic (i.e. compromised), would it really bother to address the TPM chip at all?

      It's the TPM chip that verifies the authenticity of the BIOS. If it's not valid, the TPM chip won't allow the boot process to proceed.

      As you say, software checking itself wouldn't do any good, so that's why it's implemented in hardware.

  52. Re:Q: One BIOS only? - no. by phr2 · · Score: 2

    No. It just means the bios would have to be digitally signed by a trusted party.

  53. For every higher wall, there's a taller ladder.... by Anonymous Coward · · Score: 0

    'nuff said....

  54. evil!!! by Anonymous Coward · · Score: 0

    AMIBIOS8 features a revolutionary Windows-based development environment, Visual eBIOS, and number of tools and utilities to ease and speed BIOS project development.


    omg, the BIOs is made in a windows enviroment.......what is this world coming to!??!?!?! But does this mean we can buy (or kazaa) BIOS development tools? *grin*

  55. Comment removed by account_deleted · · Score: 5, Interesting

    Comment removed based on user account deletion

  56. Read the patent here by jhantin · · Score: 4, Interesting

    According to US patent 6,327,652 that is indeed correct-- unsigned code simply doesn't get any access to secured data, and may not even be allowed to run on the same desktop as signed code. If the boot sector doesn't pass the BIOS's signature check, it's not given access to the machine private key, and therefore can neither unlock locally stored encrypted content nor pose as a trusted system to other machines on the net. The only bait-and-switch here is the possibility of a concerted push by software or content producers to require a trusted runtime. One minor wrinkle is that this will require boot-selector programs like LILO to either be code-signed or be unable to properly boot signed operating systems.

    --
    ...when you're writing a game...tweak the difficulty of "Easy" to something [your mother] can cope with. -- onion2k
  57. Comment removed by account_deleted · · Score: 4, Insightful

    Comment removed based on user account deletion

  58. Makes sense... by shepd · · Score: 2

    Companies like PC Chips have stolen their BIOSes in the past... this is a perfect way to protect their code while gaining support from developers.

    Good move, I say.

    --
    If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
  59. this is wrong.. by Machine9 · · Score: 1
    ...in so many ways I cannot even begin to describe them.

    this is IT people, this is every nightmare you've ever had about losing your personal freedom, coming true.

    First, they'll control your computers, next your entire life.

    paranoid? maybe, but I really, REALLY cannot accept that ANYBODY, OTHER THAN ME, can tell my computer what os to boot or programs to run... this is an outrage.

    I thought palladium was far off, and might not happen, and now it has.

    what can we do? any groups campaigning against this we can join etc?

  60. Misarrangement Aced by Hell+O'World · · Score: 2

    AKA
    Demarcates Renaming

  61. Tell them what you think! by Tom7 · · Score: 5, Interesting

    I told AMI (link in the article: marketing@ami.com) that I don't think of this as a "feature". Computer manufacturers have backed down on much less invasive technologies (Pentium III's unique ID, for instance) before; I'm still a little bit hopeful that with all the competition in the mainboard scene we might be able to convince manufacturers not to adopt consumer-hostile technology like this.

    1. Re:Tell them what you think! by DickBreath · · Score: 3, Interesting

      I'm still a little bit hopeful that with all the competition in the mainboard scene we might be able to convince manufacturers not to adopt consumer-hostile technology like this.

      I got a new DVD player for Christmas. An APEX 3201. So far, I love it. I just eject the tray, press 8 4 2 1 on the remote, and get a secret menu. From here I can choose whether or not I would prefer Macrovision, and which region I would like, or can select All regions. (Sort of like asking, would you like to be kicked in the balls or not?)

      (Hint to stupid moderators: this post is NOT offtopic!)

      --

      I'll see your senator, and I'll raise you two judges.
    2. Re:Tell them what you think! by Kanasta · · Score: 3, Interesting

      AFAIK, the PIII ID is still there, and a while back AMD said they'd add it to theirs, tho I can't remember if we convinced them not to...

  62. LinuxBIOS by niconico · · Score: 1

    Can LinuxBIOS be an alternative ?
    http://www.acl.lanl.gov/linuxbios/index.html

    1. Re:LinuxBIOS by Nonillion · · Score: 1

      Don't be so sure, LinuxBIOS will probally fall into the same problem as DeCSS code..

      --
      "I bow to no man" - Riddick
  63. So it may not boot alternate OSes? by StevenMaurer · · Score: 2

    (just for example -- *BSDs will be equally affected) so far.

    So does this mean BSD is dying yet?

    (sorry, had to)

    1. Re:So it may not boot alternate OSes? by Graspee_Leemoor · · Score: 1

      "Often the only difference between +1 Funny and -1 Troll is whether the moderator was smart enough to get the joke." ...And whether the same joke had already been posted multiple times above.

      graspee

  64. Implications? by fearincontrol · · Score: 1

    What kind of implications does this have for pirated software? Are we going to see validity checks for OS software?
    Forgive my ignorance, it's too close to some companies' attempts to have 'validation' chips for music and DVDs, etc.
    Fear is control

  65. BUT FOR HOW LONG!?!?!?!?! by Eric_Cartman_South_P · · Score: 5, Insightful
    Just like all of those new DRM enabled CD's are true to the CD spec?

    The minute Palladium is up and running on these boxes, watch for manufacturers to go "WinModem" only: meaning BIOS's that only boot Windoze.

    Want to boot FreeBSD, so you played around with the BIOS? DMCA days "Go Directly To Jail, Do Not Pass SourceForge, Do Not Collect $200"

    1. Re:BUT FOR HOW LONG!?!?!?!?! by VistaBoy · · Score: 2

      Nah, I always figured that SourceForge was more like Free Parking than Go...oh well.

      I mean, it IS sort of like "Free Parking" for aspiring open-source developers who need bandwidth to hold their files and website...

    2. Re:BUT FOR HOW LONG!?!?!?!?! by GalionTheElf · · Score: 1

      How do you collect $200 from SourceForge? Free money is always appreciated *g*

      --
      I'm going over here and I don't know why!
    3. Re:BUT FOR HOW LONG!?!?!?!?! by Anne+Thwacks · · Score: 5, Funny

      Hold on ... If it boots windows, why would anyone trust it?

      --
      Sent from my ASR33 using ASCII
  66. Windows incompatibility by Ilan+Volow · · Score: 3, Funny

    If it can only run operating systems that can be trusted, how the hell am I going to be able to get it work with Windows?

    --
    Ergonomica Auctorita Illico!
    1. Re:Windows incompatibility by IXI · · Score: 1

      There would be no way if "Trusted Computing" meant trusted from the users point of view.

      --
      He saw some dirty arabs and fired. Too bad it was just some friendly kurds, BBC reporters and his fellow cowboys.
    2. Re:Windows incompatibility by Anonymous Coward · · Score: 0

      MOD this Up. As funny + insightful

  67. Comment removed by account_deleted · · Score: 2

    Comment removed based on user account deletion

  68. USB readable DIMM by deanpole · · Score: 1

    If anyone is good with FPGA's and wants a project,
    I could really use a DIMM which is USB
    readable to hack this Palladium stuff.

  69. Right... by Kjella · · Score: 2

    Palladium as I understand it has NO APPLICATION for content protection. It's not a DRM system. It's a security function so that your hardware knows what it's doing. It will provide a level of security between applications, the OS, and hardware.

    So that level of security won't allow a trusted application, say WMP, running on a trusted OS, say Windows, running on trusted hardware, say a DRM-enabled soundcard, to control what you do with those .wma files? Right. I'm impressed. This is the second +5 Troll I've seen from you :p

    Kjella

    --
    Live today, because you never know what tomorrow brings
    1. Re:Right... by fwr · · Score: 3, Funny

      Amazingly, it only takes six Microsoft employees to product +5 posts. Think about it!

    2. Re:Right... by micromoog · · Score: 2

      On the other hand, it would only take 5 employees that are good with math. Or 4 that are good with math and karma.

    3. Re:Right... by Virtex · · Score: 2

      Nah. You're forgetting about the lone moderator who will mark the post "-1 troll". The 6th Microsoft employee will have to be there to counter it.

      --
      For every post, there is an equal and opposite re-post.
  70. How to break it. by Kickasso · · Score: 1
    Install a hax0red memory module. The beast loads the bootloader...calculates the checksum...issues the trust token...then the memory content is magically replaced with a different bootloader. Insta-Palladium-enabled-Linux!

    Don't quote me on this though. I did read the spec, but I'm not quite sure I fully understand it.

    1. Re:How to break it. by Anonymous Coward · · Score: 0

      Except for the "Chassis Intrusion" log created by the Palladium-POST.

      You could chip your computer in order to make it run Linux, but equally Microsoft could make Windows WOUBO (We Own You Bend/Over - catchy name!) refuse to load ever again.

  71. buy now? by Anonymous Coward · · Score: 0

    Does this mean that I need to buy a small stash of motherboards and CPUs that are on the shelves right now? Before all new motherboards refuse to boot if you want to avoid all of Microsoft's products?

    1. Re:buy now? by IXI · · Score: 1

      It means, that you may have to replace the BIOS as well.

      --
      He saw some dirty arabs and fired. Too bad it was just some friendly kurds, BBC reporters and his fellow cowboys.
  72. PC Hardware Standards will Fork by HighOrbit · · Score: 2, Interesting

    I think there might end up being "Windows PCs" that will have motherboards that support the Palladium standard and then "other PC's" that won't. When you want to build a box for linux or BSD or whatever else, you'll have to buy the "other" hardware instead of Windows hardware. If there is enough profit in it, somebody will make it.

    1. Re:PC Hardware Standards will Fork by tzanger · · Score: 2

      I think there might end up being "Windows PCs" that will have motherboards that support the Palladium standard and then "other PC's" that won't. When you want to build a box for linux or BSD or whatever else, you'll have to buy the "other" hardware instead of Windows hardware. If there is enough profit in it, somebody will make it.

      That's not far fetched -- all you'd need was a new BIOS. The LinuxBIOS guys make special deals with their vendors to get what they want. I mean if you have a (potential) customer who wants to buy a thousand systems wouldn't you shave a bit off the price if they didn't want BIOS chips?

      Now LinuxBIOS is highly specialized -- I have been toying with it to get my dauphin orasis boards booting it -- it's NOT ready for primetime or even for most linux hackers, but if there's a vendor who buys a non-TPCA'd BIOS and puts them in non-TPCA'd mobos, I don't think there's much to stop them, especially if there are plenty of people out there who are nonplussed about this whole situation.

    2. Re:PC Hardware Standards will Fork by Lussarn · · Score: 2

      Fortunaly Linux and *BSD runs on most >=32bit hardware so that shouldn't be a problem.

  73. end of independant developers by cdn-programmer · · Score: 1

    If this takes off it will mean the end of independant developers. Simply stated, you can have a trusted OS and a trusted application but if some untrusted programmer is allowed to access the restricted hardware then the security is blown.

    This means that such a system can only allow programs written by trusted programmers and we all know this means that M$ programmers will be able to write code but you and I won't be allowed to.

    Looks like the end of our careers guys.

    1. Re:end of independant developers by Anonymous Coward · · Score: 0

      .net apps won't require anything, they're inherently trusted. So you'd better get those .net skills up to par if you want to live in the Post-Palladium World[tm]. (I imagine Java will be similar, but I have this strange feeling that it's just not going to be all that well supported in Windows. ;))

      What's that? You don't want to? Better be ready to fork over enough cash to get your binaries signed!

  74. DRM DRM DRM by rutledjw · · Score: 3, Interesting
    I keep hearing that this is NOT just about DRM but for all applications. Really? What software vendor is going to implement any of the TPCA features EXCEPT for the media industry?

    Is Oracle, BEA, IBM or any of the OSS projects going to do this? For what? What value is brought by wasting time and money implementing a strategy that has little or no benefit to the customer?

    Bah, this is a scarcely concealed attempt to appease the media giants (the people who FUND RIAA). Lack of customer interest will likely cause this to fail.

    • Companies implement TPCA at cost $X
    • Customers don't want / use
    • Competitor undercuts companies implementing TPCA because they don't waste their $$$ on it
    • TPCA meets it appropriate fate

    But what do I know? My company (who's in a "budget crunch") burns enough cash to single-handedly cause global warming, and we're profitable. Whatever, I'm going back to Oz where things make sense...

    --

    Computer Science is Applied Philosophy
    1. Re:DRM DRM DRM by geekoid · · Score: 2

      Can I get a job at your company?

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    2. Re:DRM DRM DRM by anto · · Score: 1

      OSS projects (and Oracle etc) *could* massivly benifit from more securable hardware - they kernel could tell the system to not run any code with privlages x unless it happenes to be signed by the distributions key or *my* personal key. Overnight we could kill the script kiddies off.

      However we need to be *really* careful that we dont end up with no access to our hardware when *we* want it. There will be companies that will push it too far - we need to activly 'educate' and punish them when they do - after the first $10million in lost revenue they *might* start to get the point.

    3. Re:DRM DRM DRM by Anonymous Coward · · Score: 0

      How many games companies do you think actaully *want* Safedisk and buddies on the CDs they ship? Not the publishers, but the software houses themselves?

      Very, very few of them.

      If you hang around on forums moderated by people who actually developed the game, rather than publisher-appointed PR zombies, then you'll quickly find that game CD copy protection is hated by a lot of software houses because of the hassle it causes them and their customers.

      But they still include it - because they have to. Publishers force them to include it because that is the only way they can get insurance: it is the insurance industry that has forced virtually every publisher, and by extension every software house they publish for, to mandate flakey, pointless copy protection.

      How long do you think it'll be before the insurance industry gets wind of the fact that you can have this so-called "trusted" software on a "trusted" OS? And how long before they say "either you use XYZ or we double your premiums or cancel your insurance".

      *THAT* is the real killer here - even if a lot of companies don't want it, fairly soon they are not going to have any choice in the matter.

    4. Re:DRM DRM DRM by 4of12 · · Score: 2

      Lack of customer interest will likely cause this to fail.

      Depends on the customer.

      Many of `em will probably click on the icon to listen to some song over a TCPA enshackled device for a few minutes for some amount of credit card payment or putting up with some unavoidable ad-ware.

      Certainly some fiercely independent geeks and paranoid folks from the general population will be disillusioned with what ??AA wants to ram down their throats, but most sheep are docile.

      The upshot is that there will be a divergence between "entertainment devices" and general purpose computers. People buying servers don't want someone else controlling their computers.

      While it's clear that consumers are not keen on this idea, if "the frog is boiled slowly" they might gradually buy into the scheme without knowing the full implications of what they're getting into.

      As a consumer, though, I'd like a sword to cut both ways. With all this built-in technical protection for large copyright owners, as a consumer I'd like to exercise the same level of control over information about me: medical records, cross-correlations between my name and my SSN, etc.

      If consumers would push their legislators on this front for privacy protection, then perhaps we'd enlist the direct marketers as a force againts the RIAA and MPAA and membership of the TCPA would wither.

      --
      "Provided by the management for your protection."
  75. Re:Can you say..PPC Chips? by alfredo · · Score: 5, Insightful

    I run OSX and Linux on PPC machines. I do not miss the world of the paranoids in Redmond.

    I don't need a 4 gig chip to type a paper or Photoshop a picture of Rumsfeld and a goat.

    Frame rate for games? Got my PS2 for that.

    --
    photosMy Photostream
  76. Helloooo! by Anonymous Coward · · Score: 1, Funny

    "Provided you only use Palladium-approved hardware. And applications. And operating system. And you don't want to make your own software. Or MP3's."

    Only a terrorist would NOT want Palladium. And playing MP3s contributes to the Axis of Evil and terrorism.

    1. Re:Helloooo! by Fulcrum+of+Evil · · Score: 2

      playing MP3s contributes to the Axis of Evil and terrorism.

      Provided it's Britney Spears.

      --
      "We returned the General to El Salvador, or maybe Guatemala, it's difficult to tell from 10,000 feet"
  77. BIOS that only boots Windoze by Kickasso · · Score: 1

    are possible right now, with no TCPA and stuff. But somehow they're not very popular.

  78. Hah! by Chocolate+Teapot · · Score: 1

    mandating arse creme

    --
    Modest doubt is called the beacon of the wise. - William Shakespeare
    1. Re:Hah! by Anonymous Coward · · Score: 0

      It's always bottoms with you Americans, isn't it?

    2. Re:Hah! by Abcd1234 · · Score: 2

      Okay, that was friggin' hilarious. :)

    3. Re:Hah! by ralphclark · · Score: 2

      Right on! Its the occasional thread like this what makes it worth coming back here every night. Here's another thread that's a hoot

    4. Re:Hah! by ralphclark · · Score: 2

      Trust me, you need to browse that thread at a threshold of or lower to see all the funny stuff...I've just read it again and I'm still laughing now :o))

  79. A possible use scenario by Nicolai+Haehnle · · Score: 1

    Please bear in mind that what follows is all hypothetical. It's an idea how a hardware-based "trust" platform can be used by "consumers" for their own good.

    Imagine you want to go into an internet cafe to check out your mail. You have to enter your account information (username and password) using a computer that you do not control physically. This means - on current day platforms - that the computer might work against you without your knowledge - you can't really trust it. For all you know, there might be a keylogger on the computer, or some other software that could allow somebody to read your mail without you noticing it. This is a problem, and it could be solved with a hardware solution.

    You need a small device that _you_ control physically (a smartcard?) that can connect to the computer and perform a trust handshake checking whether the computer runs an operating system that you trust (Windows, Linux, *BSD, it doesn't matter - you should get to decide). It'll give you an okay signal if the test passes. If it does, you can be very sure that the computer you are using doesn't work against you. IOW, you can be very sure no keylogger or similar is installed.

    Obviously this is a hypothetical idea, and I'd be really surprised if that was what the big players of the TCPA had in mind. But it shows that the technology behind the TCPA isn't all evil, it's the people who use it. (Yes, that should have been a no-brainer)

    1. Re:A possible use scenario by platypus · · Score: 2

      I think it's more likely that cybercafes of the future mostly have many WLAN access points.
      Or that nearly any public place has WLAN, and cybercafes will cease to exist. No Palladium needed, encrypted communcation is enough.

    2. Re:A possible use scenario by j3ss · · Score: 1

      Why would this be any harder to fool than it is to fool an antivirus scanner with a polymorphic virus? What I am saying is that there are some really smart people out there who would find ways around things like this just like people find ways around firewalls and intrusion detection systems. Everything can be exploited, nothing is 100% secure.

    3. Re:A possible use scenario by Nicolai+Haehnle · · Score: 1

      It is harder to fool than an antivirus scanner because it is based on a whitelist (i.e. operating systems you trust) instead of a blacklist (i.e. list of [virus] signatures that you don't trust) like an antivirus scanner.

      Anyway you're right, nothing is 100% secure. The sad thing is that operating systems could get a lot more secure in general without any change to the hardware - which is just more evidence that the TCPA is worried about a different kind of security than most normal people are worried about.

  80. This is anti-capitolist by zaqattack911 · · Score: 2

    Again and again MS has accused the Open Source movement as being anti-capitolist.

    But the more I heard about Palladium, and "Trusted" applications, and creating a standard that forces palladium on consumers.

    The more I realise the strategy of protecting the corperation from the consumer is what's to blame.

    Again and again laws are created that assume all consumers are criminals, and that companies need to be protected by the government.

    I guess you have to ask yourself.... is capitolism failing us? Or is the spirit of capitolism gone, and it is we that have failed capitolism?

    --zuchini
    (No I'm not a communist)

    1. Re:This is anti-capitolist by Anonymous Coward · · Score: 0

      It's 'capitalist', retard.

    2. Re:This is anti-capitolist by klanza · · Score: 1

      Learn to spell "capitalist". Sheesh.

    3. Re:This is anti-capitolist by Anonymous Coward · · Score: 0

      Are you referring to the record company Capitol?

    4. Re:This is anti-capitolist by Anonymous Coward · · Score: 0

      I'd say you are more of a "commanist" ;-)

  81. I wonder... by glrotate · · Score: 1, Troll

    if your mother had been killed by a terrorist if you would joke about it so casually?

    1. Re:I wonder... by program21 · · Score: 1

      Look at the joke, it's about how the government is so far-reaching in the 'war on terror', and how 'untrusted OSs' support terror. If there was ANY connection between an untrusted OS and terrorism, you may have a point, but there's not. Leave it as what it is, a joke.

      --
      This has been a test. Had this been a real emergency, we would have fled in terror and you would not have been informed.
    2. Re:I wonder... by dillon_rinker · · Score: 3, Insightful

      No. I'd make the same remark, but it would be a bitter sarcastic remark instead of a humorous sarcastic remark.

    3. Re:I wonder... by Anonymous Coward · · Score: 0

      Stuff your sanctimony up your ass, Nazi Bootboy.

    4. Re:I wonder... by Anonymous Coward · · Score: 0

      I keep my mother safe from George Bush and Dick Cheney, so I have no worries about terrorism.
      Your mother I keep in a petri dish.

    5. Re:I wonder... by hoggoth · · Score: 1

      > if your mother had been killed by a terrorist if you would joke about it so casually?

      Ok, troll, just how would stopping the use of 'untrusted Operating Systems' have saved his mother?
      I imagine he would not only have made this joke but would be actively protesting such stupid "security" measures in place of meaningful security that may have saved his mother.

      --
      - For the complete works of Shakespeare: cat /dev/random (may take some time)
  82. Just lost a customer by Nonillion · · Score: 1

    It's now official, I will never buy another motherboard with AMI bios!!

    On the otherhand I'm finished with consumer grade computer hardware.

    --
    "I bow to no man" - Riddick
  83. Please Forget by Alien54 · · Score: 2, Funny
    You should never know that it's there. Provided you only use Palladium-approved hardware. And applications. And operating system. And you don't want to make your own software. Or MP3's.

    Please forget that you ever read this story. Pay no attentiion to the man behind the curtain.

    This information is provided on a need to know basis, and we are the one who determine if you need to know it.

    Whenever you try to even think of this story, your mind will be obscured by pr0n instead.

    Have a nice day.

    --
    "It is a greater offense to steal men's labor, than their clothes"
    1. Re:Please Forget by Anonymous Coward · · Score: 0

      Whenever you try to even think of this story, your mind will be obscured by pr0n instead.

      Please provide ample free pr0n to pr0n-input@myserver.com, I wish to be obscured

    2. Re:Please Forget by hesiod · · Score: 1

      > your mind will be obscured by pr0n instead. ... and how is that any different than any other day?

  84. Foolish mortal! by Anonymous Coward · · Score: 1, Funny

    ... flash memory that contains the "TPM" ...

    You cannot contain The Phantom Menace! (tm)

    1. Re:Foolish mortal! by Anonymous Coward · · Score: 0
      Dear Captain Unfunny,

      Die.

  85. Let me know... by ackthpt · · Score: 1
    "Trusted Computing" Palladium

    Let me know when they have a patch which bypasses this flaw.

    Thank goodness for the filthy old untrustworthy BIOS on my current motherboard.

    --

    A feeling of having made the same mistake before: Deja Foobar
  86. Black boxes by vidnet · · Score: 5, Funny
    These new "features" scare me. From what I gather, it's a roll of duct tape to further seal the black box computer. I've never liked devices that function according to ye olde proprietary model:

    1. Input
    2...499. None of your your damn business
    500. Output

    "Trusted computing", hah! Sure, the apps might trust each other and the system, but I won't!

    1. Re:Black boxes by Anonymous Coward · · Score: 1, Funny

      1. Input
      2...499. None of your your damn business
      500. Output
      501. ???
      502. PROFIT!

    2. Re:Black boxes by frankie · · Score: 2
      "Trusted computing", hah! Sure, the apps might trust each other and the system, but I won't!

      Well in Soviet Russia, the system won't trust you!

      Oh wait. That's not Russia, that's the USA. Oops, my bad.

      Say, have you noticed a whole lot of people with goatees recently?

    3. Re:Black boxes by Tarrio · · Score: 1

      You're wrong, sir. This is ye olde proprietary model:

      1. Input
      2. ???
      3. OUTPUT!

  87. What does trusted mean? by chrysrobyn · · Score: 2

    Just what does "trusted" mean.

    Now wait a sec, I'm not being antagonistic or stupid.

    Typically, "trusted" means something along the lines of "here's some code, I trust that you'll do the right thing". When the hardware people and software people get together, you really can have that happen. Software can go get a video stream and save it in such a manner that it can only be played in a trusted manner.

    I'm not a hardware vendor. But I do know some tricks. Some college kids with a few oscilloscopes and fast FPGAs are going to go after that 300-500MHz system buss (really, only the address lines, which move 2-16x slower matter) and tweak with the hardware. Suddenly, you have the hardware that thinks it's trusted, but on occasion is able to write data where it doesn't think it is. Maybe you detect it, maybe you don't.

    In order for consumers to do this, it must be transparent. Performance must be equal or imperceptably lesser. What this means with current hardware is an encrypted file on the hard drive gets decrypted and temporarily dumped to memory -- WHICH CANNOT BE TRUSTED -- and then played on the hardware.

    Follow this example with any other application of "trust". Any time data leaves a chip, observation is trivial. Capture is trivial. Fiddling with it and making it still look authentic is harder, but possible.

    Is this going to stop video pirating? No, all you need is one person who can capture the stream. Audio pirating? No, we'll still get that one person to capture the stream. Account numbers? Now there's the rub. A good programmer will be able to keep all that stuff on chip. Except when an OS gets busy and swaps data off chip (encrypting it beforehand? can you imagine an encrypt/decrypt function in a context switch?). But, maybe context switching is blocked when you have private data (context switching blocked while you type in your password? multithreads are so pervasive and important to performance).

    This is going to do three things:

    1) Stop casual pirating. You know, the kind of person who says "Can I borrow your copy of Starcraft, I want to see if it's good enough to buy".

    2) Fair use. Archiving data for which a licence is legal, current and paid for.

    3) Make consumers really notice when a system comes along that gives them rights. Sheep don't notice when rights get taken away slowly. When they suddenly get a pile of them, it matters.

  88. why use this.. by Anonymous Coward · · Score: 0

    when even one of the original authors of the spec has serious concerns about it: tcpa concerns

  89. Trusted Computing by evenprime · · Score: 4, Informative
    Everyone on /. seems to be thinking about the potential for this to be used in DRM or religious wars about OS. Those are valid concerns. It is worth pointing out, though, that this BIOS has the potential to be used for less nefarious purposes; i.e. trusted hardware systems can be part of trusted platforms, which most security practitioners believe to be more secure. The idea of trusted hardware has been around at least as long as the Orange Book has existed. Specifically, it said:
    No computer system can be considered truly secure if the basic hardware and software mechanisms that enforce the security policy are themselves subject to unauthorized modification or subversion.
    Now, whether or not trusted systems actually are more secure is a different issue.
    --

    "Weapons should be hardy rather than decorative" - Miyamoto Musashi
    I think that goes for OS's too
    1. Re:Trusted Computing by JoeBuck · · Score: 3, Informative

      Right, but the military (the authors of the Orange Book) are operating from similar assumptions as Hollywood: the operator of the machine is considered an untrustworthy person whose behavior must be carefully controlled. In this context, he or she must be prevented from bypassing operating system checks. Military multi-level security is also a form of DRM, and seeks to restrict even the most "trusted" users. And this may be entirely appropriate in many circumstances.

      The question is whether the purchaser of a machine is entitled to the equivalent of root or administrator privilege on the machine he or she owns, or whether the true administrator of the machine will live in Redmond or Washingon DC or Hollywood.

  90. Like Phoenix is any better?? by Reziac · · Score: 2

    Phoenix (and remember, they ate Award too) is hardly any better (not to mention their product is miles buggier than AMI at its worst). They're the ones who pioneered the concept of advertising in the BIOS.

    In fact, a couple years ago Phoenix was throwing around the idea of an internet app in the BIOS that would auto-download both advertising and BIOS/OS updates (now, what if an update includes the latest upgrade to CIH??)

    I hate this "trusted BIOS" idea, and it appalls me that it comes from AMI, which until now had been a sensible company. Unfortunately, the alternatives are likely to be worse.

    --
    ~REZ~ #43301. Who'd fake being me anyway?
  91. Why not just use a compact flash or similar? by ink · · Score: 1

    There are variations such as this: http://prices.cclcomputers.co.uk/specs/backup/usbd rive.htm that actually use "real" RAM and a battery to maintain state, if it's critical that it not be flash-RAM.

    --
    The wheel is turning, but the hamster is dead.
    1. Re:Why not just use a compact flash or similar? by Anonymous Coward · · Score: 0

      I don't think you get it. The poster to whom you are replying is talking about a memory bus probe that connects to another computer's USB port.

  92. Another step backwards, slower booting PC's!! by Anonymous Coward · · Score: 0

    As soon as the PC powers on, AMIBIOS starts a fairly complex process. The BIOS boot block addresses the TPM chip that verifies the BIOS authenticity itself. Then BIOS proceeds to verify the authenticity and integrity of the OS loader and OS kernel. Finally BIOS passes the integrity tokens, that identify that PC as a trusted entity, to the OS.

    And just how long is this "fairly complex" process going to take? Just when PC BIOS's were started to get faster, it's time to take a giant step back. Maybe we could go back to the manadotory RAM check too.

  93. Wrong end of telescope, guys! by xyote · · Score: 1

    It's the end applications that counts. *It* won't run unless it's running on a trusted operating system which in turn won't run unless it's booted by a trusted boot loader which in turn won't run unless it's on trusted hardware. As long as there are enough applications that don't require this trusted environment then there will continue to be a use for Linux. Don't give up the apps! Free the apps!

  94. Not long by Anonymous Coward · · Score: 0

    It'll even have it's own installer: fdisk /mbr

  95. evil by mao+che+minh · · Score: 5, Insightful
    Realize first that this technology is being billed as "trusted computing". Then realize that it is Microsoft Corporation pushing it. This should ring out ALARM YOU IDIOT! by itself. I'm not saying this because I am some kind of "Microsoft basher", as fat nerds like to call us sensible techie folk. I am saying it because there is no other truth.

    Microsoft is not interested in your security. Microsoft doesn't even much care about their own security, as long as the license is already paid for. They only want to make money and lock you into long term deals. The massive and drastic tactics by Microsoft to lock consumers into their platform indefinately is because there is actual competition (Linux, and an invigorated Macintosh) now. It is so plainly obvious that it stuns the senses.

    History should already be telling the world never to trust anything from Microsoft.

  96. no worries by Anonymous Coward · · Score: 0

    computer, mobo & chip manufactures are not interested in limiting the number of uses for their hardware.

    they are interested in gaining the ability for evil media industry DRM systems to run on it increasing their hardware sales.

    no worries, they won't be preventing you from running a different OS on the box. it'll only prevent other OSes from having access to DRM features so that they won't be able to use DRM protected content.

  97. It's a great time to by a sweet non-Palladium sys by lildogie · · Score: 1

    When I recently bought a laptop, the thought crossed my mind several times: This could be my last free-as-in-speech system.

    As long as 1.7 GHZ is a decent speed for Linux-type software, I'll be able to run any software I like, even after the commodity PC's start dis-trust-ing me.

    I prefer to have my computer to be a slave to me, not the other way around ;-)

  98. If our worst nightmare comes true... by hkmwbz · · Score: 5, Interesting
    There will always be ways to crack protection mechanisms. I don't know what this new BIOS will mean, but it seems most people here fear that this is another step towards not having control of your own system.

    Well, I am worried about the development too, but at the same time, I think we must realize that no matter what they throw at us, someone will crack the protection.

    Ultimately, the entertainment industry will only be able to control individuals who allow themselves to be controlled.

    The rest of us will actively seek solutions that remove us from the evil claws of "Digital Rights Management", or rather "Consumer Ass Ramming" as it should really be called.

    They can encrypt and protect all they want, but someone will come through. Someone will work constantly on giving us our rights back - even if it means doing so illegally.

    If it becomes illegal to have control over one's own system and play off whatever one pleases, I will stand in line to break the law. Constantly. The more they try to control me, the more I will break laws.

    I am not saying that people's concerns about violated rights to control one's own system is not justified. I am just saying that we will prevail in the end. With the incredible amount of brainpower available to those with a liberal mind, the entertainment industry may win over the sheep who do not realize what is happening, but they will not get the ones that don't want to be ass-rammed.

    Sorry for the rant, but hopefully someone else agrees that the fight is far from over, and no matter what they tro to do, we will continue to fight...

    --
    Clever signature text goes here.
    1. Re:If our worst nightmare comes true... by 9jack9 · · Score: 1

      DMCA, go to jail.

    2. Re:If our worst nightmare comes true... by dusanv · · Score: 4, Insightful

      Ultimately, the entertainment industry will only be able to control individuals who allow themselves to be controlled.

      Sure. And the rest of us are going to legally become criminals for hacking our own machines (see: DMCA). Wanna go to jail? I'll be dead before I put out a penny for any type of hardware that contains DRM. Go milk someone else...

    3. Re:If our worst nightmare comes true... by Anonymous Coward · · Score: 0
      I think we must realize that no matter what they throw at us, someone will crack the protection.

      You are correct, someone will crack the protection.

      But what if cracking the protection involves removing layers of your CPU so you can hook up a logic analyzer to internal data paths?

      What if the system is designed so that class-level breaks are not possible? ("Not possible" meaning "not likely with cryptographic confidence.")

      Well, then if you can afford the hardware and you have the design expertise to break the system, you can do so - you'll get the key to your own system, but you won't get some class-wide key that someone else can use. You won't be able to sell modification chips that undermine the protection because all critical data paths are internal to the CPU. You will be able to manufacture replacement processors that include "slightly broken" hashing algorithms, but you'll need access to a fab plant, which might cost hundreds of millions of dollars and is an easy target for litigation.

      What if they implement such a system? You'll be able to crack it, sure, but it will takes tens of thousands of dollars, hundreds of man-hours and much EE expertise - for each separate machine sold. You won't be able to buy some "mod chip" because any "mod chip" would be a full CPU, like what AMD or Intel produces, and there are only a handful of factories that can produce those.

      What if they know what they're doing? Then cracking your DRM-enabled system will be difficult and expensive enough that you might not even bother.

    4. Re:If our worst nightmare comes true... by Grishnakh · · Score: 3, Interesting

      You will be able to manufacture replacement processors that include "slightly broken" hashing algorithms, but you'll need access to a fab plant, which might cost hundreds of millions of dollars and is an easy target for litigation.

      The litigation would be easy to get around by building it in a foreign country. Wouldn't it be ironic if China became the only place you could get a processor which gives you the freedom to run whichever OS you want?

    5. Re:If our worst nightmare comes true... by hkmwbz · · Score: 3, Interesting
      If someone can make money from selling "unprotected" chips, they will probably do so. If it is illegal that's fine, because it just means that it will be done by organized criminals instead. We will all be organized criminals, in fact. And I won't hesitate for a second.

      Can you stop drugs, child porn and other illegal things? No, it is still being manufactured because there is a demand for it. And even though some are busted, you will never get even a tiny part of the people doing it. My guess is that drug and child porn busting is just for show, so the police can justify their funds and pretend that they are actually making a huge difference.

      The corporation whores in our governments will naturally call us "terrorists" and compare us to drug abusers and child pornographers, but that is a small price to pay for freedom.

      They can call me what they will, but if they make it illegal to do what I want with my own equipment, then so be it. I will be a criminal, big time. In fact, I will probably spend considerable resources to spread the word about illegal chips and do whatever I can to work against the government.

      No, I know it's not that easy, but someone will do most likely it because there will be big money in it.

      --
      Clever signature text goes here.
  99. Does this mean my soundcard needs palladium as... by digital+photo · · Score: 1

    So does this mean that my SoundCard will need Palladium as well?

    Reasoning being that quite a few, if not all, expansion cards have their own BIOS which gets executed at startup to "mingle" on the pci/isa/etc bus.

    And... what's to prevent someone from writing a wrapper for Palladium which allows arbitrary code to be executed from within Palladium authenticated code?

  100. My Thoughts on the whole thing. by sickboy_macosX · · Score: 2, Funny

    *knocking on door* "Hello" "Yeah my name is Agent X and this is Agent Y we are from Microsoft's Anti Piracy Unit" "Well what do you want" "We Understand you ware watching Back Door Anal Sluts 9 on your parents computer" "You Guys are fucked up" "Can We see your computer sir" (Realizing they had made a mistake while looking over the computer's contents because the man is a Buhdist) Just proving that nothing is fool proof, and shit happens.

    --
    --- /* In Soviet Russia, the Mac OS X kernel panics you! */
  101. Fraud??? by Anonymous Coward · · Score: 0

    Intrastructure paid for by the largest fraud in US history, "the dot-com's"; can anybody say bankruptcy.

  102. Don't lose sight of the purpose by JoeBuck · · Score: 5, Interesting

    This technology is intended to support the TCPA 1.0 specification for "trusted computing". What "trusted computing" is supposed to mean is that if a file has a label on it saying "don't copy me", then it is in principle impossible for the user to copy the file (other than in the ways permitted by the digital "rights" management label).

    Once you understand this, you'll see that the purpose is quite clear: of course boxes equipped with this BIOS will refuse to boot Linux. That's the whole point; they will be intended only to boot operating systems that strictly support DRM. Each machine will have unique "integrity tokens" which can be used as digital signatures, so that everything you do on the machine (create a document, contact a web site) can be traced. Since you'll have to pay for your downloads on a credit card, this can all be cross-correlated. The integrity tokens will be digitally signed by the manufacturer, so that any action taken on the net by the owner of one of these beauties can, at least, be traced to the original purchaser of the machine. Secret, DMCA-protected protocols will assure that only "trusted computers" can connect to their web sites.

    Now, of course, initial implementations of this concept are likely to have flaws that can be exploited by crackers (example: find some way to write a program that replaces the "trusted" OS with a BSD or Linux kernel; reprogram the flash chip to disable checks), but I fear that they will get it right eventually.

    At some point, then, the net will bifurcate: there will be a world of glorified DVD players calling themselves computers interacting with restricted network sites, and a world of general-purpose computers interacting with sites that follow standard protocols. Attempts to outlaw the "free world" will not succeed because it will do too much damage, but those who participate in the "free world" will be viewed with suspicion, called pirates, etc. ISPs might be pressured into refusing to connect with "untrusted" machines.

    After five years or so, though, I expect the whole thing to fall apart, because countries that don't go along with this brain damage will acquire a technological lead, as the US enters an era where computer science is treated the way that the USSR treated science: dangerous state secrets not to be shared.

    1. Re:Don't lose sight of the purpose by Anne+Thwacks · · Score: 2
      of course boxes equipped with this BIOS will refuse to boot Linux.

      If it can't boot linux, its not a general purpose machine. The computer sells because "one size fits all". That is why PCs outsell Suns, Macs, etc - it does everything.

      If the Palladium machine wont run a load of software, then Lusers will return them as defective.

      Hell, if it wont run NetBSD, it probably isnt even a computer - Its well known: NetBSD runs on everything, including toasters.

      --
      Sent from my ASR33 using ASCII
  103. The need will drive the market by MrJerryNormandinSir · · Score: 1

    When no one buys computers with palladium and no money is made then things will go back to how they were.

    I'm sure we will have sources for Mother boards from
    Asia that do not use this.

    Intel and AMI will only hurt thier own business.

    I will never buy a box with this.

  104. -1, Redundant by M.C.+Hampster · · Score: 1

    This joke is older than SOVIET RUSSIA.

    --
    Forget the whales - save the babies.
  105. My take. by Anonymous+Freak · · Score: 5, Interesting

    Okay, my take, based on working knowledge of 'trusted' computing and hardware design (I used to be a support enginner in Intel's server division,) is as follows:

    'Trusted computing' relies on the fact that every component is known to be secure. Of course 'secure' is a cagey term, but in this case, it means that the end application knows that nothing is interfering with it. The uses vary, from DRM to financial transactions, to other uses we haven't thought of. But, there are three main pieces in a trusted system:

    1. The hardware. The hardware needs to be 'trusted' in that we are certain that there is no hardware tampering or eavesdropping going on (of course, this applies only the the internals of the computer, a packet sniffer, or even a keyboard monitor, would be external, and ouside the scope of monitoring,) and to make sure that the machine is the machine it's supposed to be. This really started with Intel's Pentium III adding a processor serial number. The point of that (as with Palladium) was that each machine could be positively identified. If you had previously made that computer 'trusted', then set it so that only trusted machines could perform a said transaction, we could guarantee that the end user is who he says he is, from a hardware standpoint. This new BIOS is much the same way. Each board with this BIOS will be able to say "Yes, I am the motherboard that was here when this software was installed, so yes, I am the same computer." Obviously, this has implications for hardware failure, even moreso than Windows XP's activation problems.

    2. The OS. The OS must have support for trusted computing. It must be able to partition off the 'trusted' applications from the untrusted ones. It must be able to encrypt the contents of the drive, and only allow trusted applications to access protected data, and only allow trusted applications to access the 'trusted' part of memory. (So as to disallow one program from sniffing the program files, memory, or data transport streams of a protected application.) This would probably see alot of use by multiplayer online games, as they could make certain that no third-party applications that reside on the game-running-PC could be used to cheat. (As with some of the 'god map' programs for Everquest.) Again, this does not protect the data stream once it leaves the computer, an encrypted network connection would be required. Obviously, for the OS parts to work, users must log in to the system with a username and password at least. Biometric security would be better, so as to more certainly guarantee that the user is who he says he is.

    3. Applications. The entire purpose of 'trusted computing' is the applications. Applications that need to know that the user is who he says he is, and that is done by both the OS and the hardware. As with the game example above, other uses are financial transactions (for example, you could set it so that only your computer has access to your bank account records, so that even if someone stole your hard drive, and your username and password, they still wouldn't be able to get at your data,) and DRM. It makes a perfect DRM vehicle, as now the labels can enforce the one-computer rule. A downloaded file would refuse to play without the original application, OS, and hardware.

    The question is if these systems can boot a non-trusted OS? Of course they can! You won't be able to use trusted features (for example, your bank's online account access wouldn't work,) but you could use it just fine for applications that don't use MS' Palladium. Just like the Pentium III's serial number could be disabled, and all you lost was access to the (very few) programs that required it.

    --
    Another non-functioning site was "uncertainty.microsoft.com."
    The purpose of that site was not known.
    1. Re:My take. by j7953 · · Score: 2
      As with the game example above, other uses are financial transactions (for example, you could set it so that only your computer has access to your bank account records, so that even if someone stole your hard drive, and your username and password, they still wouldn't be able to get at your data,)

      Huh? If someone can steal my hard drive, I assume he could just as well simply steal my whole computer.

      --
      Sig (appended to the end of comments I post, 54 chars)
    2. Re:My take. by dryeo · · Score: 1

      It must be able to encrypt the contents of the drive, and only allow trusted applications to access protected data, and only allow trusted applications to access the 'trusted' part of memory

      So no one can take your drive and read it? This is going to make law enforcement people happy.
      Seems to me there is going to have to be a backdoor into the system incase a terrorist uses palladium and the department of homeland security wants to read the drive without the computer
      Dave

      --
      https://en.wikipedia.org/wiki/Inverted_totalitarianism
    3. Re:My take. by Flakeloaf · · Score: 2

      Right you are. All the hardware in my computer was made by Apple. Only Apple wrote the software that runs on my box, and my computer never cr$*@)__!!!!!

      NO CARRIER

      --

      Am I the only one who heard Roxette to sing "I'm gonna get blitzed for some sex"?

    4. Re:My take. by KidSock · · Score: 2

      Finally, someone with a more rational viewpoint. No one disputes the consumer-unfriendly motivations behind TCPA but quite frankly I don't see anything fundamentally wrong with it. They want to secure the machine so that nodes can communicate securely. What is wrong with that? Yes, you will not be able to rip that audio stream. Yes, you will not be able to boot that bootleg copy of Windows. So what? If you want to get into a philosophical argument about that YOU WILL LOOSE. I think TCPA would be GOOD for users because you will have the option to do much more significant things. Do you feel confortable buying things on-line? I cringe every time I punch in my credit card number. Wonder why PayPal is not FDIC insured? All of the negative arguments assume that activating TCPA would be *mandatory*. This is NOT true. It's CBDTPA that mandates securing devices capable of playing or recording copyrighted material. THAT's what you need to look out for. Not TCPA. TCPA is just being pushed because it is a prerequisite. Let's get TCPA and punt CBDTPA and educate people that they should not be fooled by a "Bait and Switch".

    5. Re:My take. by ces · · Score: 2

      Let me add my perspective as someone who has worked in IT for a computer security company.

      Nothing in any of the products announced so far precludes the TPM from being a removable smart card. Now there are problems with the TPM being a removable part for some security purposes so ideally the BIOS should support a combination of a TPM on the motheboard and a TPM in the form of a smart card.

      Now I know some of you are wondering what the use of this beyond DRM could possibly be. Consider the following scenarios:

      Client desktop lockdown. You can prevent users from booting an unauthorized OS, installing unauthorized software, provide more secure authentication mechanisms, etc. This is presuming the IT department is able to set what is authorized rather than the vendor.

      Enhanced server security. You can provide a VERY trustworthy CA or kerberos server. You could use this as a very secure form of tripwire as well. Checksum doesn't match? The program doesn't even run. Another use would be ensuring all clients are authorized this would be very useful with things like financial or HR databases. Again this is assuming the IT department has some say in what is authorized.

      --
      Happy Fun Ball is for external use only.
    6. Re:My take. by Anonymous+Freak · · Score: 1
      Huh? If someone can steal my hard drive, I assume he could just as well simply steal my whole computer.


      Yes, that example doesn't hold up too well for a conventional desktop (even less so for a laptop.) But, what about a server? That rack mounted server is really hard to get out (and so big that someone would probably notice it,) but that hot swap drive is easy. Just pop it out, stick it in your pocket.
      --
      Another non-functioning site was "uncertainty.microsoft.com."
      The purpose of that site was not known.
    7. Re:My take. by Anonymous Coward · · Score: 0

      Shaddup troll!

      - The rest of Slashdot

    8. Re:My take. by j7953 · · Score: 2
      But, what about a server? That rack mounted server is really hard to get out (and so big that someone would probably notice it,) but that hot swap drive is easy.

      Good point. However, you probably wouldn't use a server for identifying the person using an online service (like an online banking account) because servers usually aren't associated with individual persons.

      --
      Sig (appended to the end of comments I post, 54 chars)
  106. No Big Deal, Right? by 9jack9 · · Score: 4, Interesting
    For those of you consider this is no big deal, consider the following.

    Let's say the Microsoft Watch is a big success. Go ahead and laugh. They've got the bucks to seed these sorts of things into the marketplace for years. Eventually something will stick. If not the Watch then the MS Clock or the MS Hairdryer or the MS Refrigerator, or something.

    Now, let's say you, as a geek, have reprogrammed the thing so that it runs FreeWatch, the oss embedded watch OS that does all the cool stuff you want it to.

    The next version of the MS Watch is Trusted. It only runs approved software. It only runs approved services. And if it doesn't recognize the os and the software, it just doesn't run. Of course, approved means approved by Microsoft, or by the Watch Software Consortium. And they'll be happy to add FreeWatch, for $500 million and a 25% cut of the profits.

    If you don't think that's the way it will work, think again, very carefully. It isn't Trusted to Microsoft until it's utterly predictable. It will only run MS-approved software. It will only display MS colors. Once it's utterly predictable, then support costs go down, service fees go up, and 3. Profit!

    Now, extend that to the PC platform. Microsoft's stated goal is for computers to be as predictible as kitchen appliances. That means they run exactly the way it runs. Support costs go down, service fees go up. Paladium, TCPA, DMCA, DRM, it's all the same. It is to give you absolutely reliable computing. To end hacking, cracking, viruses, tinkering, end-user encryption, and everything else most geeks hold near and dear. And incidently, to put the hands of the electronics and entertainment industries into your wallet, forever.

    If you think this is unlikely, as yourself, why is the membership list of the TCPA secret?

    Maybe you still don't agree with me. Maybe I'm wrong. I really hope so. But perhaps it's worth keeping an eye on things.

    1. Re:No Big Deal, Right? by sheldon · · Score: 2

      Maybe you still don't agree with me. Maybe I'm wrong. I really hope so. But perhaps it's worth keeping an eye on things.

      And maybe I have a fire breathing dragon in my garage.

      I better go check on my car.

    2. Re:No Big Deal, Right? by nochops · · Score: 1

      You may be right, but I fail to see the problem here.

      Yeah, it would be really neato to have a watch/computer that can run any OS, or a real computer that can run any OS, but why are you expecting it to?

      If Microsoft develops the hardware, why would anyone expect anything other than a Microsoft OS to run on it?

      I think we've been spoiled for years by this. Ever since the IBM clones people have this idea that the hardware must let you run whatever you want on it, and this is fundamentally wrong.

      Look at Apple if you doubt me. Until OSX, Macs only ran MacOS out of the box. You wouldn't dream of complaining to Apple if you couldn't boot Debian, right? Why would you have any expectation that apple would design it's hardware with anything but MacOS in mind?

      If you don't like the hardware, make your own, just like the Agenda VR3. There wasn't a PDA that ran Linux out of the box available at the time, and these folks were tired of duct-tape workarounds that get Linux running on a PDA, so they just designed their own hardware, and made it run Linux out of the box.

      Please remember that hardware developers have absolutely no obligation to make sure that their hardware will allow *whatever* to run on it, even more so if the hardware developer is also the software developer.

      This may be bad for us, and take away lots of the "neato" geek factor that is OSS, but in my book the hardware developers are becoming the scapegoat on this one.

      --
      "A terrorist is someone who has a bomb but doesn't have an air force." -William Blum
    3. Re:No Big Deal, Right? by cranos · · Score: 2

      Microsoft will not be developing the hardware for palladium, its partners in crime will. And just what is wrong with the assumption that you should be able to run what you like on the hardware you purchase. Just because Apple has chosen to go down the route of "You must use our hardware to use our software" doesn't mean the rest of us have to get stuck with it.

      We've had more than fifteen years of build your own and I sure as hell don't want to go back to the bad old days of being locked into one software/hardware platform.

    4. Re:No Big Deal, Right? by Dark+Lord+Seth · · Score: 2
      Let's say the Microsoft Watch is a big success. Go ahead and laugh. They've got the bucks to seed these sorts of things into the marketplace for years. Eventually something will stick. If not the Watch then the MS Clock or the MS Hairdryer or the MS Refrigerator, or something.

      Now that would actually rock! MS, while delivering shitty software, provides EXCELLENT hardware, such as their optical mice which actually rock perfectly under both Win32 and Linux. Besides, who else wouldn't want a Microsoft Vibrator, ("When do you want to orgasm today?") a Microsoft Macintosh, (16 million colour, 1600x1200 full screen AA kernel dumps!) Microsoft VGA cards, Microsoft Assault Rifles ("Are you sure you want to fire this weapon? Really?") and of course Microsoft Soy Beans!

    5. Re:No Big Deal, Right? by hiero · · Score: 2, Funny

      Microsoft Soy Beans... is PEOPLE!!

    6. Re:No Big Deal, Right? by nochops · · Score: 1

      Well, OK then.

      You've got a whole bunch of companies to add to your shit list, then.

      Add Motorola, Nokia, Ericsson because you can't run Linux on your mobile phone.

      You can add Ford, Chevy, Honda, and Toyota because you can't run Wnidows on your car's ECM.

      You can even add the contractor who built your house because it can't handle the stress of long term elephant storage.

      The fact is, just because you bought the hardware, doesn't mean that the manufacturer has any obligation to support you in your quest to get *whatever* working on it.

      I wouldn't expect Apple to support me when I try to install Windows on my Mac any more than I'd expect Microsoft to support me when I try to install Linux on my X-Box.

      Don't get me wrong here. I'm not saying that it's wrong to try to install *whatever* on a particular piece of hardware. I'm simply saying that if the hardware wasn't designed with *whatever* in mind, it's wrong to expect the manufacturer to support you when you try to install *whatever*.

      --
      "A terrorist is someone who has a bomb but doesn't have an air force." -William Blum
    7. Re:No Big Deal, Right? by cranos · · Score: 2

      God why would you want Windows on your cars on-board anyway, aside from that, I sort of see your point, however with Palladium, we are not just talking about not providing support for a use we are now activly vetting what can and cannot be used on the system, to the point that we have to go through approved channels before our software would be allowed to work. This gives who ever owns those channels a huge amount of power. This is what I oppose.

      What MS is proposing is a system where by they get to say who gets to play in the grounds. We hardly let our own governments decide this, let alone a private corperation with a history of dodgy dealings. Taking it to an extreme it could turn into some sort of Tax, in order to get the information you need to write Palladium compliant software you have to pay so much per app. Or even worse, you have to go through a long and ardeuous vetting period where you are judged by your competitor of all people on whether your software is secure.

      Well thats my rant for the day.

    8. Re:No Big Deal, Right? by nochops · · Score: 2

      You're right. Good point. Nuff said.

      --
      "A terrorist is someone who has a bomb but doesn't have an air force." -William Blum
  107. AMI is *NOT* the bad guy here by Anonymous Coward · · Score: 1, Insightful

    Ok, reading through all of these posts, there seems to be a lot of agreement that people just don't like TCPA or Palladium (which, are not the same thing). But we can't fault AMI for adding this (or any) feature to their BIOS.

    1) TCPA is not a technology that AMI has developed on their own. It is a movement by several large companies in the computer industry. AMI sees this as an upcoming technology that it needs to develop for or else get left behind. As far as AMI is concern, this is really no different than adding support for ATA hard drives larger than 137GB.

    2) Just because AMI supports a feature/technology, doesn't mean that OEMs and motherbard manufacturers are going to use that technology. I'm sure that AMI supports Serial ATA, but if a motherboard vendor doesn't need it, it doesn't get included into their BIOS build.

    3) AMI cannot force this (or any BIOS feature) on it's customers (OEMs/IHVs/etc). If I am a motherboard manufacturer, and I wan't features X and Y but not Z, I don't get Z. Period. I have the final say as to what goes into my BIOS.

    If you a really concerned that this will limit your choices, bring it up with the OEMs and motherboard vendors. Push them *NOT* to use this feature of their BIOS. Only buy boards for which this feature was not included or can be disabled. Don't fault AMI for trying to stay current with industry initiatives, no matter how they are perceived by the public.

  108. So, what systems are still usable by RCO · · Score: 1

    Ok, So now AMI is on board with many of the processor manufacturers. I have to admit that while I think I understand the basics of the palladium issues, I haven't spent a lot of time researching it. So the question now becomes, what systems are going to be left in the near future that are not getting on this bandwagon? Or are the average geeks going to have to deal with only old technology or mortgage everything we own to get the really high end equipment that doesn't use this technology?

    Another small issue I see is when someone decides to write a driver which accesses a piece of hardward for an unsigned OS which bypasses the palladium crap in the BIOS. I have a feeling the legal precident is about to be set for this issue in the Lexmark case discussed earlier today. I think this could have some serious rammifications for the open source world that tends to work with the latest OS they can put their hands on.

    my $.002 (inflation is a 8!7(#)

    --
    'And all the monkeys aren't in the zoo Every day you meet quite a few...'
  109. Re:awesome technology by mdielmann · · Score: 2, Funny

    Excellent. Now it will take longer to boot up than it does to crash. Well, that race is finally over.

    --
    Sure I'm paranoid, but am I paranoid enough?
  110. Nothing to worry about... by Eric+Damron · · Score: 3, Funny

    Hey I just got a prototype of the trusted computing BIOS. It's not so bad. As far as I can tell I can do all the things that I use to.

    No one is controlling my hardware but me. I still worry about the way that Microsoft is &$^^ *$(#@) ()%)$! but other than that it's not too bad.

    Oh yeah and I still have concerns about how the government is )^%$ $^*** $#*%$ &^. (&$# %$*@% (^% . But I'm sure we'll be able to stop that.

    We do need to watch the entertainment industry also because they're still trying to #@*^ %#^ &$ (&$%)*%.

    Yep these new BIOS are nothing to worry about.

    --
    The race isn't always to the swift... but that's the way to bet!
  111. Re:your sig by Anonymous Coward · · Score: 0

    beta is greek

  112. If it's a 'Trusted Computer'... by Anonvmous+Coward · · Score: 2

    ... then how come I feel like I can't trust it to do what I want?

  113. If this is typical AMI... by tkrotchko · · Score: 2

    You'll hit at startup and turn it off.

    --
    You were mistaken. Which is odd, since memory shouldn't be a problem for you
  114. What's the worst that can happen? by HuguesT · · Score: 1

    Ambitious way to start a post...

    OK, so let's for a moment suppose the following:

    - H/W manufacturers and MS are in cahoot and agree to put together hardware that:

    * Only boots certain O/Ses (Windows)
    * Only allows certain kind of files to play
    * Only allows certain applications to run
    * all of the above controlled by very few companies with very conservative agendas.

    Isn't it relatively obvious that this isn't going to fly? Isn't that plan a brilliant blueprint to get rid of Intel, Microsoft, AMD, HPQ and whatnot
    in one fell swoop?

    I for one will just not buy a piece of hardware that limits me in my choices. I am absolutely not at all a pirate, a terrorist or a virus writer, all my files are rightfully owned and within the bounds of fair use. I do not appreciate the `guilty until proven innocent' connotations of these new `technologies'.

    Clearly I'd rather pay more to continue to enjoy my freedom (Apple anyone?). Other less enlightened manufacturers and software vendors can shoot themselves in the foot if they want.

    Somehow the recent debacles concerning for example

    - Software copy protection mechanisms that prevent normal play (NWN anyone?)
    - Rightfully purchased CD that won't play so that people return to them to store.
    - Unhackable games console that don't sell

    give me grounds for cautious optimism. We shall see.

  115. "cyber-isolationism" by knowbody · · Score: 1

    A meme that's been floating around for a while is that the rest of the world is pursuing open source & open hardware...we all know that.

    But to put a new twist on an old idea, imagine this: suppose DRM/Palladium becomes law in the USA (to fight terror)...it will be effectively "cyber-isolationism"...The USA already has different electronic standards for everything else...it would not be surprising for networking too.

  116. My apologies for the grammers. by geekoid · · Score: 2

    Yikes, that was bad.

    How about:
    Please write them and tell them why. keep it short and to the point. Encourage others to do the same.

    My fingers are cold.

    --
    The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
  117. At least. by Anonymous Coward · · Score: 0

    No, it would be less casual, but a lot more funny.

  118. h.o.l.y..s.h.i.t. by Anonymous Coward · · Score: 0

    Michael didn't make a stupid comment. What a surprise!

  119. Why not get Linux and BSD Trusted by ebresie · · Score: 1

    Okay...why can't someone out there just take the necessary steps to make Linux and related OS capable of handling the necessary TCPA related requirements.

    The specs seem to be available at

    http://www.trustedcomputing.org/

    What specifically prevents this?

    Heck...can't Redhat, IBM, HP, etc do whatever is necessary to become trusted?

    As I understand, on the computer is the AMI chip, with a subsystem that sits on top of the chip and interacts with the chip. If a trusted resource is to be used, then it has to make the necessary requests to the OS which in turn interacts with the chip. Is this right? In the case of M$, this is Palladium. Why not make an OpenPalladium or whatever? Is openpalladium.org available? :-)

    --

    Eric B
    ebresie@gmail.com
  120. I *guess* you're being ironic by tkrotchko · · Score: 4, Insightful

    "One file slips out and bamo - no one is paying for it anymore."

    Well, high-quality digital media with no copy protection has been sold for over 15 years and the people selling it made record profits last year.

    Its called the "compact disk". Perhaps you've heard of it? Phillips invented it, and it turns out that not only can you make copies for under five cents, you can compress them digitally to make files to store on any device.

    It may catch on.

    --
    You were mistaken. Which is odd, since memory shouldn't be a problem for you
    1. Re:I *guess* you're being ironic by 0111+1110 · · Score: 1

      Its called the "compact disk". Perhaps you've heard of it? Phillips invented it

      Fast forward to 2010 when CDs are about as common as 8-track tapes. What is invented can be un-invented. Once DRM has proven itself, CDs will be dropped. Only solid state DRM enabled digital media will be supported. And of course all digital content will "time-out" every 30 days if not refreshed by the content provider. Non-DRM hardware will be terrorist machines that don't work with the new content anyway.

      --
      Quite an experience to live in fear, isn't it? That's what it is to be a slave.
    2. Re:I *guess* you're being ironic by platypus · · Score: 2

      Fast forward to 2010 when CDs are about as common as 8-track tapes.

      Rewind to 2006, in an effort to give consumers an incencitive to buy the new DRM Hifis, CDs are getting rarer everyday, but not many consumers do have a DRMed DVD-audio player.
      Suddenly someone figures that it's possible to capture the analog sound, reconvert it to digital data and that this makes it possible to again use the old non-DRM equipment. This recoded files pop up all over the 'net because people don't want to throw away their portable mp3 players, HiFis, car cd players and whatnot.

      The rest is history (in 2010).

    3. Re:I *guess* you're being ironic by geekee · · Score: 2

      Which is exactly why the RIAA refuses to sell digital content without DRM. They made that mistake once with CDs.

      --
      Vote for Pedro
  121. Oh I get it! by Anonymous Coward · · Score: 0

    So if I give up all my digital rights, I get to watch movies on my PC and play geeky games. Oh, and check my email from anyway.

    Now it all makes sense. I mean, I can't do any of that now, right?

  122. INTEL AT FAULT TOO? by Atari-X · · Score: 1

    But isn't INTEL also going to be placing DRM in there chips also?

  123. It doesn't... by Kjella · · Score: 3, Informative

    It just sends a wake-up call to the TPM chip. "Hey can you take a look at me and tell me I'm clean?" The TPM chip is still the top-level.

    --
    Live today, because you never know what tomorrow brings
    1. Re:It doesn't... by redfenix · · Score: 1

      So what happens if it doesn't send the wake-up call?

      --
      "It's a very tangled subsystem." --Windows kernel guru
    2. Re:It doesn't... by Anonymous Coward · · Score: 0
      So what happens if it doesn't send the wake-up call?

      Your trusted computing stuff doesn't work and you can't take advantage of all that DRM goodness? :-)

  124. I still don't get it by Ernest · · Score: 1

    Viruses have never had to corrupt/attack the BIOS before to get in to the system. I get the feeling this would be far to cumbersum to do. What would be the point ? The OS is easier to attack as it has far more entry points.

    So what is actually the point in securing the BIOS in this way ? The only virus this system would prevent is the boot block virus (great!).

    OSes now a day are so complex that there is just _NO_ way to have them 100% secure without constant (daily) updates.
    MS isn't about to offer that, so why are they promoting this ?

    No, this is not, and has never been, meant to protect the user agains viruses/crackers.

    --
    Ernest J.W. ter Kuile
  125. 2007 Turn Over... by Anonymous Coward · · Score: 0

    Where does this fit, or does it in the 2007 digital TV turnover.

  126. Electronic Terrorism ? by Anonymous Coward · · Score: 0

    So, if this means that that 'external' people can modify/restrict me from doing things with my computer that I could do in the past, then it sounds like a denial of service attack with a long lead time.

    This sounds like another opening shot from corporate organisations preparing to wage electronic warfare against their customers.

    The smart thing is that the lead time for this is so long, and the possibilities of this vulnerability are as yet so vague, people won't twig to the problem until it is firmly entrenched.

    This is just plain bad ! Just because it's being sponsored by large corporate organisations does not mean that it is either good or benign.

  127. Two possible uses... by lynx_user_abroad · · Score: 2, Interesting
    This technology is designed to address the general problem "How do I know that I can trust what is running on the computer?".

    You can use this technology to verify, for example, that some software (for example, DVD viewing software) you want to run has not been altered by a virus to perform functions other than those you choose. Functions like spyware, worm propagation, etc.

    The down side is that it enables anyone else to perform the same verification. This could be used (again, for example) by the MPAA to ensure that the DVD viewing software you want to run has not been altered (by you) to perform functions other than those they choose. Functions like allowing the movie to be saved as a file or played on a non-compliant display device.

    The fear is that eventually content providers will refuse to offer any content to your general-purpose computing device unless you allow them to verify the software you are running on it. Which will, by economic necessity, require that you be running one of a very limited set of "approved" configurations to get the approval you would need. In essence, your "general-purpose computing device" will need to become a "single purpose computing device". Digital content marketers are probably drooling over the thought of some souped-up Windows system which plays DVD's and Digital Audio and games (and what not) and never lets anyone pirate the content. Instead, it will likely become something more like: Insert the DVD-Player CDROM and reboot to turn your PC into a DVD player, insert the Digital Audio Player CDROM and reboot to turn your PC into a Digital Audio player...

    But the fear is misplaced. The real use is not in protecting digital content, but rather in allowing someone who doesn't own a piece of hardware to reliably use the processing power of that piece of hardware.

    In reality, however, none of this will come to pass. The world of hardware is nowhere near as clean as the software world. Hardware designers have to make all kinds of assumptions, like assuming that the clock is accurate, assuming that supply voltage remains within spec, assuming at no one tied that patricular bus line to Vcc at the exaxt instant when the "failed" result was being relayed, etc. As soon as there is a hint that someone, somewhere has hacked their hardware enough to create a untrustable trusted system, no content provider will will accept any trusted system as trustable ever again.

    Game over.

    --

    The thing about things we don't know is we often don't know we don't know them.

  128. It's all about the money by Anonymous Coward · · Score: 0

    I can't imagine hardware manufacturers being pressured into making a palladium only system.

    Sure they can be. A decade or so ago, we had a choice of operating systems on new PC desktops, remember? Once Microsoft introduced discounts to manufacturers who only offered Windows or DOS, the choices disappeared.

    As soon as Microsoft starts offering significant discounts on Palladium-only Windows licenses, manufacturers and consumers alike will snap up these "trusted" machines just to save a few bucks. Naturally, most consumers won't realize what they're giving up until it's too late.

    I never cease to be amazed what the public will sacrifice for the benefit of lower prices.

  129. Comment removed by account_deleted · · Score: 2

    Comment removed based on user account deletion

  130. And there was much rejoicing at Apple... by Tumbleweed · · Score: 2

    Time to change that 'sell' rating for Apple stock to 'buybuybuy!' :)

    1. Re:And there was much rejoicing at Apple... by geekee · · Score: 2

      And their was much rejoicing at Apple until they found out they couldn't get any online media, This was particularly problematic after dvd rentals were replaced by online rentals. Apple lost even more market share and went out of business. Open source palladium was written for linux, which promptly took pver the number 2 spot.

      --
      Vote for Pedro
    2. Re:And there was much rejoicing at Apple... by Tumbleweed · · Score: 2

      If you think online rentals are going to be replacing DVD rentals anytime in the foreseeable future, you're off your rocker. The bandwidth needed for that isn't available for the vast majority of people int he U.S., much less in most of the world.

      It's a nice dream, though. Keep thinking those happy thoughts!

  131. Security through obscurity...squared by Anonymous Coward · · Score: 0

    One of the first laws of security is that any information you give someone is theirs to play with. Public/private encryption works only because you do not send the mastery key -- a man in the middle attack can still decode all the information by picking up the transmitted public key, however. This applies to hardware DRM as well.

    Somewhere, somehow, inside your computer, an authentication method happens. It's in your computer. In your house. Yes, right there, under your desk. They've given you all the information you need, it just needs to be extracted.

    Someday, a computer will need a mod chip to work properly. You'll pay $10 for a chip, replace one currently on your mobo with it, and voila. All applications are suddenly and mysteriously trusted. Hardware manufacturers will claim their system works except for "rogue" users, the same ones who were pirating software in the first place.

    Good emulators will also still work. The OS will say "Am I running in trusted mode?" and the emulator will say "Well of course, silly!" Then the emulator will begin to snicker, then break down giggling uncontrollably as the OS bounces happily off to deal with its not-as-trustworthy-as-it-thinks content.

  132. So, I can't boot to Knoppix anymore? by Anonymous Coward · · Score: 0

    Just last night I had a problem on my system that I solved (partially, anyway) by booting to my handy-dandy Knoppix CD.

    It sounds like this will no longer be possible because my Knoppix CD's boot sector will no longer be authorized.

  133. Comment removed by account_deleted · · Score: 2

    Comment removed based on user account deletion

  134. Re:your sig [OT] by redfenix · · Score: 1

    Good point. I got it from a quote somewhere and didn't really think about it. Thanks. =)

    --
    "It's a very tangled subsystem." --Windows kernel guru
  135. List of Features by Anonymous Coward · · Score: 0

    Some good info http://www.cl.cam.ac.uk/~rja14/tcpa-faq.html

    Essentially, Palladium permanently installs back-orffice on my computer, and prevents me from running programs without it.
    So that a more indepth psychological profile can be built than what my shrink is capable of, so that I can be sold icecubes no matter where I live.
    Don't we pay taxes to protect ourselves from people like this.

    1. Re:List of Features by Anonymous Coward · · Score: 0

      hormone therapy for all

  136. Comment removed by account_deleted · · Score: 2

    Comment removed based on user account deletion

  137. You missed! by Chocolate+Teapot · · Score: 1

    Dunno. I'm English.

    --
    Modest doubt is called the beacon of the wise. - William Shakespeare
    1. Re:You missed! by TrollBurger · · Score: 1

      That was a Faulty Towers joke. You missed it. Thankyou for playing.

  138. How about a driver monopoly? by Anonymous Coward · · Score: 0

    I strongly suspect that Microsoft is trying to regain their driver monopoly. They can do that if they encrypt all CPU hardware communication.

    Strong encryption will make it extremely hard to write alternative drivers, and laws such as DMCA make it illegal to create and more importantly distribute them.

    So the OS itself is not at risk, just its communication with everything around it (network, harddisk, video, audio, ...).

    Their technical term for this is "cutting off the air supply", and I fear it is what they will be trying to do to us.

  139. moron trustdead buy o-s by Anonymous Coward · · Score: 0

    you must get IT buy now?

    look for: va.msn.net, ticker: (VAST)?

    vast array of payper liesense stock markup FUDgePackers, if you ask US.

  140. Turn it off? by Anonymous Coward · · Score: 0

    Well, as long as there's an option to turn off the "trusted computing" features like you could with the PIII's serial number in the BIOS, what's the big deal? I sincerely hope this isn't some stupid move to appease the obsolete recording and motion picture industries. The computing industry probably dwarves their revenues. That's be like tire manufacturers forcing auto makers to do something against their will. Duh.

  141. Read the TCPA / Palladium FAQ by vinsci · · Score: 5, Informative
    Ross Andersson at the University of Cambridge has written an excellent introduction to TCPA / Palladium, which explains both sides of the story.

    Read it here: http://www.cl.cam.ac.uk/%7Erja14/tcpa-faq.html

    The two last sections are worth repeating here:

    24. So why is this called `Trusted Computing'? I don't see why I should trust it at all!

    It's almost an in-joke. In the US Department of Defense, a `trusted system or component' is defined as `one which can break the security policy'. This might seem counter-intuitive at first, but just stop to think about it. The mail guard or firewall that stands between a Secret and a Top Secret system can - if it fails - break the security policy that mail should only ever flow from Secret to Top Secret, but never in the other direction. It is therefore trusted to enforce the information flow policy.

    Or take a civilian example: suppose you trust your doctor to keep your medical records private. This means that he has access to your records, so he could leak them to the press if he were careless or malicious. You don't trust me to keep your medical records, because I don't have them; regardless of whether I like you or hate you, I can't do anything to affect your policy that your medical records should be confidential. Your doctor can, though; and the fact that he is in a position to harm you is really what is meant (at a system level) when you say that you trust him. You may have a warm feeling about him, or you may just have to trust him because he is the only doctor on the island where you live; no matter, the DoD definition strips away these fuzzy, emotional aspects of `trust' (that can confuse people).

    Remember during the late 1990s, as people debated government control over cryptography, Al Gore proposed a `Trusted Third Party' - a service that would keep a copy of your decryption key safe, just in case you (or the FBI, or the NSA) ever needed it. The name was derided as the sort of marketing exercise that saw the Russian colony of East Germany called a `Democratic Republic'. But it really does chime with DoD thinking. A Trusted Third Party is a third party that can break your security policy.

    25. So a `Trusted Computer' is one that can break my security?

    Now you've got it.

    --

    Trusted Computing FAQ | Free Dawit Isaak!
    1. Re:Read the TCPA / Palladium FAQ by jpmorgan · · Score: 2

      which explains both sides of the story It might explain both sides of the story, but it does it with a heavy bias against TCPA/Palladium. Your suggestion that this is a balanced presentation is somewhat disingenious.

    2. Re:Read the TCPA / Palladium FAQ by Anonymous Coward · · Score: 0

      I don't see how it is POSSIBLE to not sound biased against tcpa/palladium after you understand the facts (not just reading that article, mind you). The whole concept is so frightening that anyone with even a base understanding of what is going on should be against it.

    3. Re:Read the TCPA / Palladium FAQ by Anonymous Coward · · Score: 0

      So, what happens to all the stuff you paid for when you upgrade your computer (or just Mobo)?

    4. Re:Read the TCPA / Palladium FAQ by vinsci · · Score: 3, Informative
      So who is Ross Anderson? He is at Cambridge University, UK. From his homepage:

      I lead the security group at the laboratory, where I hold a faculty post as Reader in Security Engineering.

      I don't think Andersson is, as you suggest, biased against TCPA / Palladium and certainly not "heavily biased" (see Bill Arbaugh's comment below). His analysis does however point out very serious consequences of the TCPA / Palladium infrastructure. The consequences are what they are, Anderson just made a very good job in formulating them.

      He is far from alone in his view on TCPA / Palladium. In fact, Bill Arbaugh, one of the inventors of TCPA (US patent 6,185,678 here), has second thoughts. His comment on Anderson begins:

      We are all aware of the criticisms that the TCPA has received. Ross Anderson did a good job of explaining the problems in an abstract fashion, but I felt that there were some things left out (Privacy concerns).

      By the way, trustedcomputing.org does not allow the general public to view the member list anymore. You can however see one list of 170+ member companies in Lucky Green's presentation below (links from http://www.cypherpunks.to/:

      The slides from Lucky Green's DEFCON X talk, Trusted Computing Platform Alliance: The mother(board) of all Big Brothers, are now available in the following formats:

      Other resources with much information are:

      --

      Trusted Computing FAQ | Free Dawit Isaak!
    5. Re:Read the TCPA / Palladium FAQ by vinsci · · Score: 3, Informative
      Oops, the links to Lucky Green's presentation were obviously wrong; here are the correct links:

      The slides from Lucky Green's DEFCON X talk, Trusted Computing Platform Alliance: The mother(board) of all Big Brothers, are now available in the following formats:
      --

      Trusted Computing FAQ | Free Dawit Isaak!
    6. Re:Read the TCPA / Palladium FAQ by swv3752 · · Score: 2

      It is balanced as it gives the bias on the other side compared to most other pieces of info.

      --
      Just a Tuna in the Sea of Life
    7. Re:Read the TCPA / Palladium FAQ by Anonymous Coward · · Score: 0

      It will all melt in a pile of goo.

  142. The Legend of BIOS: Megatrend's Mask by Mirkon · · Score: 1

    Maybe AMI should hawk some "trusted computing" products to Nintendo, to stop themselves from stealing The Legend of Zelda's Triforce as their corporate logo.

    --
    Glog!
  143. Apple? by Anonymous Coward · · Score: 0

    By the way, this is where the Apple fans say "nya nya, Macs will never have this trusted computing garbage." Then we wait 6 months and suddenly Apple rolls it out in their next firmware update and their iLife apps all require it to work. hahaha.

  144. Comment removed by account_deleted · · Score: 3, Informative

    Comment removed based on user account deletion

  145. You modders are horrible by cp5i6 · · Score: 1

    I see alot of crap being modded up to 4-5 and alot of them are just stupid comments that really aren't informative. Like 92392409 various comments about ..

    "what's the point of this it adds no security.."

    and you have a modder come along and be like

    "oh look at that.. he sounds like he said somethign 34293049203 people have said so I'm going to mod this to 5 because I find it interesting"

    Anyhow all you guys do is bitch... Bitch this bitch that.. everything is BITCH BITCH BITCH.
    linux runs perfectly fine on a 386 ... and I assure you .. you won't have ANY problems with the new palladium bios on yer good ol' 386 running debian. You know what?... you can even use a brand new p4 3.2 Ghz too in case the 386 is running too slowly for your tastes.. Guess what... no paladium bios on that either.

  146. Kazaa by Anonymous Coward · · Score: 0

    A Gui, and a front end for kaazaa would fix all of this...

  147. Why is this so hard to understand? by theLOUDroom · · Score: 1

    What a pitiful, poorly thought out metaphor.

    Come on. Is that all you've got? What a condescending, pointless statement.

    You already don't have "root" access to your own machine, unless you can hand code assembly language and know the registers and other particulars of your particular architecture.

    Haven't you ever heard of "root" before.
    Root access means full read/write permissions as well as hardware permissions. It's not the same thing as having performed a full code review on the entire system.
    My point is not very complex, why don't you try and understand it?
    I can read from and write to anywhere in memory or disk in my machine. The controller in my hard drive does what I want it to.
    I could write machine code and access the registers if I wanted to. I have access to them. Yes, I could use that access if I wanted to, but not using that access is not the same thing as not having it, understand?

    --
    Life is too short to proofread.
    1. Re:Why is this so hard to understand? by SN74S181 · · Score: 1

      "Root" means hardware permissions?

      You mean, when that script kiddie roots my box, not only do I have to worry about becoming a DDOS zombie, he's gonna head on over and start yanking out drives and SIMMs??

  148. Safe Guards by Anonymous Coward · · Score: 0

    Seems like it's a way to remove safe guards that is inherent with goverment.

  149. GPL BIOS baby! by neomuzic · · Score: 1

    Here comes the next step to GPL software--more gpl hardware. Generic chip with specs to meet your board and flashed with GPL software

    --
    -NM
  150. I forsee... by Windcatcher · · Score: 2

    Web sites popping up that list non-DRM, non-"we won't trust our users", non-encrypt-everything-except-power-and-ground equipment.

    And the Ministry of Justice sending out the Thought Police to shut these "subversive, terrorist" sites down.

    TCPA 2.5: the MS "Embrace and extend" version. Lock out non-TCPA hardware, both forcing users to switch and ALL hardware vendors (who wish to stay in business) to switch faster.

    In all seriousness, we will all need to know where to buy equipment that won't restrict our computing when the hardware vendors start to fold.

  151. Great Attitude :-\ by Anonymous Coward · · Score: 0

    Those who agree with what you said--what are they?

  152. This may be a dumb question but.... by Anonymous Coward · · Score: 0

    could this mean that MS will make their OS's only boot if Palladium is detected?

    1. Re:This may be a dumb question but.... by Anonymous Coward · · Score: 0

      LOL

      Maybe.

      It just looks like the beginings of another media giant with the foresight of monopoly laws, an MS has little to do with it.

  153. Is this the beginning of the end?

    Out of all the systems I own (20~) 90% of them have an AM BIOS

    After reading this I will buy them no more - But it's food for though

    If Microsoft REALLY announced trusted computing - What would people do?

    My fear is this: Nothing

  154. Palladium is no practical help against viruses by Tom7 · · Score: 4, Interesting

    > But isn't one of the "advantages" of Palladium that your friendly neighborhood viruses can no longer run and erase your
    > MP3s/JPGs/etc, because they are not "trusted" code? I'm not sure how that will relate to unsigned VB scripts. It's designed
    > to protect the consumer from themselves... and legislate what (Microsoft's, I assume) programmers could not implement
    > properly.

    No, Palladium won't help with that. Most viruses and trojans today are just memory resident processes like any other. There is no easy way to separate a "good" program from a "virus" program. (Seriously, how would it? And how would it be able to tell if a "good" program had an exploitable backdoor or buffer-overflow in it?) It's true that palladium might protect you against, say, boot sector viruses, but there are ways a properly implemented operating system can do this, too.

    We already have all the hardware we need to provide computer security (namely, protected memory). Palladium's only purpose is removing the ability for users to inspect and modify their own computers (in an attempt to make DRM schemes fly), so don't listen to what they tell you!

  155. You mean I'll finally be able to trust. . . by kfg · · Score: 2

    my computer to reject spam, viruses, spyware, do what I tell it to, not do what I don't tell it to and not worry about it "phoning home" to my software and "content" suppliers without my express permission?

    Cool!

    KFG

  156. LinuxBIOS by jasondlee · · Score: 1

    If we're unlucky enough to get saddled with a machine with this on it, can't we just put LinuxBIOS on there and move on? I'm not really up on BIOS in general and LinuxBIOS in particular, but it makes sense to me.

    --
    jason
    Have a good day?! Impossible! I'm at work!
  157. Two questions by Anonymous Coward · · Score: 1, Insightful

    1) Is this "Fawlty Towers Joke Week" or something?

    2) Am I correct in thinking that a "Fawlty Towers joke" is a dim-witted non sequitur followed up by an indignant denunciation of the person who failed to recognize the "Fawlty Towers joke"?

    1. Re:Two questions by TrollBurger · · Score: 1

      Wow. Someone has their thinking cap on today.

      1) I have no idea. I don't run this place (fortunately or unfortunately). A Faulty Towers week would at least be a change to all the fucking Soviet Russia jokes and other useless non-humour that makes this place what it isn't today. The only problem with that is, most of the americans wouldn't even know where it's coming from.

      2) The aforementioned 'It's always bottoms..' is not a random dim-witted non-sequitur, it is a line by Basil Faulty to 'The Americans' who were repeatedly telling Basil to kick the chef's "arse". I thought that post was actually very funny because it was in reply to a post about "mandating arse creme" (also funny). I laughed.

      You sound arrogant enough to be an american, and as such, it doesn't surprise me that you didn't 'get' it. It doesn't surprise me that you think its a dim witted remark, and it shouldn't surprise you that labelling my comment an "indignant denunciation" makes me chuckle. It was a throwaway post, a little similar to YOU FAIL IT! Just relax, ok. I meant nothing of it.

    2. Re:Two questions by Anonymous Coward · · Score: 0

      And the fact that the FT line was posted by an American (me), only heightens the comedic impact of the responses.

  158. What I see coming by dacarr · · Score: 2

    I predict that AMI will have an option to turn Palladium verification off, much to the chagrin of DMCA fans. If they don't, people who know better (IE, not your typical luser) will start bitching about how palladium won't allow them to overclock their hardware, or run their favorite video card, or run Linux - and if AMI just doesn't budge on implementing such a feature, they'll watch their marketshare fall as geeks, hackers of any color hat, and generally more advanced users move over to hardware that doesn't restrict them from doing what they need or want to do with their computer.

    --
    This sig no verb.
  159. here we go again slashdotters not reading by linuxislandsucks · · Score: 1

    If you did a search of slashdot you would have found a 2 month old article about a project at darpa to produce an opensource BIOs that has the saem funcitonality and allows booting inlinux using Pallidium techniques..

    Does anybody remember what they read at this palce or are we all gasping for lack of oxygen to brain cells?

    Sometimes I acutally wonder about the posters onthis site..

    --
    Don't Tread on OpenSource
  160. Re:Can you say..PPC Chips? by pmz · · Score: 3, Interesting

    PPC

    Don't forget SPARC! It is also an open alternative to Wintel with a good selection of excellent operating systems: Solaris, Linux, and *BSD.

    We all should embrace PowerPC, SPARC, MIPS, and other well-known and easily licensed brands of ISAs. These--as long as Congress doesn't screw everything up--will be the path forward when Microsoft, Intel, et. al. try to shove TCPA down everyone's throats.

    Also, it certainly doesn't hurt that Sun, SGI, IBM (RS/6000), and Apple all produce really good hardware that lasts into the secondary markets. It isn't hard to find ten-year-old examples of each of these brands still serving useful purposes throughout server rooms and hobbyist desktops all over the world.

    When the Wintel-brainwashed masses find themselves backed into an alley with the only exit closing rapidly, we can say to them, "We have the way out!" (imagine Microsoft reeling at the bitter taste of their own words:)

  161. It -can- be turned off! by ansak · · Score: 1

    Didn't anyone notice the white paper referenced in AMI's press release? I think a lot of the paranoia coming out on this issue is there because unless you load that white-paper and look for the word "disabled" you might miss the fact that the TCPA feature can be turned off.
    Believe me, I was as concerned as the next nerd that two or three computer purchases down the line from now would no longer be able to run Linux, but as I read it, backwards compatibility (something hardware and firmware wonks live and die on) dictates that it must be as easy to turn OFF as ON. If we're adults, let not panic, for goodness' sake! Big Brother may be watching, but he won't be preventing us from loading goodthinkful OS's of our choice on our own boxes even after TCPA arrives. At least not before we're forced to visit Room 101 (still under construction apparently).

    --
    Still hoping for Gentle Treatment...
  162. What this actually means.... by Anonymous Coward · · Score: 0

    ...Is Ill be able to make a fortune selling 'cracked' bios chips to people who don't want crippleware MoBos....

  163. Comment removed by account_deleted · · Score: 2

    Comment removed based on user account deletion

  164. Comment removed by account_deleted · · Score: 2

    Comment removed based on user account deletion

  165. Full circle by KurdtX · · Score: 2

    Wow, Computers are really coming full circle...

    Macs get a UNIX (based) core
    *NIX Windows emulation wins in court
    Windows hardware becomes propetary

    Wow, now what can Slashdot possibly bash Macs for? (or are you just going to mod down their user's posts?)

    --

    Kurdt
    I'm not anti-social. Just pro-technology.
  166. Second coming? by roesti · · Score: 1
    I mean, do we really want the second coming to occur during in some long post about Natalie Portman and the basalt content of her nude body?

    If the post had pictures, nobody here would notice the second coming. In fact, how would any of us know that the second coming hasn't already happened while we've been surfing the Web?

  167. No, you won't by vinsci · · Score: 2
    You mean I'll finally be able to trust. . . my computer to reject spam, viruses, spyware, do what I tell it to, not do what I don't tell it to and not worry about it "phoning home" to my software and "content" suppliers without my express permission?

    Wrong on all accounts, unfortunately. TCPA / Palladium is not a solution to those problems, and in some cases is exactly the opposite to what you would like. Read the FAQ, to see why.

    --

    Trusted Computing FAQ | Free Dawit Isaak!
  168. ....if it works! by hughk · · Score: 2
    The BIOS validates the system to be booted and any BIOS updates by the use of signatures. However, once the system is installed, it has control - full control. Now if the software is well written, only a small part of the software actually has that control and everything else sees only a part of the system (compatmentalisation).

    It is clear that this is a good idea, but Microsoft has never been that good with the concept of least privilege. That is, if you find one hole, the protection system is defeated until patched. Once penetrated, any auto updates can be blocked.

    Of course, if it is well implemented, the security reference monitor can be used to protect DRM so that it is impossible to access DRM protected media except through DRM as you suggest.

    There are also advantages, because it would make systems more secure, but then you depend on the vendo producing good code.

    --
    See my journal, I write things there
  169. The reasons why I don't like Palladium by Decameron81 · · Score: 1

    Palladium by Microsoft will bring me to the new era of secure computing. Why on earth would I trust Microsoft as much as to let them choose what program is or isn't secure for my computer? Why on earth can't I have the right to decide what is secure or isn't secure to ME on MY box?

    The only possible answer to this question is: "nobody cares about you, but we need to know you won't be doing stuff we don't want you to do on your box". SECURE TO THEM, and this is not something hard to see. They don't trust me because to their eyes I'm a potential pirate, a potential criminal and competitor, and I don't wanna buy stuff from people that wants to put their interests before my interests. It's as simple as that.

    Someone pointed out that palladium could prevent people from cheating in online games... yes that's true. But you know, you could as well prevent people from stealing by putting them in prison before they do so too. The WHOLE concept behind this is WRONG. I don't want such a technology to stop me from having the best of my computer experience in ANY way. Even if it means not being able to run a few of the programs I have in my box now. I simply have NO INTEREST IN PALLADIUM. And it's clear that what Palladium has to offer means nothing for most of us, cos if it was worth something, Microsoft would write it in capital letters instead of talking about a generic concept such as "secure computing".

    Palladium, where one entity has the right to choose what is and what isn't secure, could end up going against the concept of innovation, and I don't want to run such a risk. Imagine where we would be now if some really brilliant people in the past weren't able to innovate because of some stupid Palladium-like system?

    Just my thoughts, sorry it sounded like a rant, but I really think there's a point where we have to stop accepting what we don't like and fight for what we wish things were like. Microsoft has let me down so many times, and I'm still using it, but not for long if it goes on like this.

    Decameron

    --
    diegoT
  170. MOD PARENT UP JUST TO PISS HIM OFF by Anonymous Coward · · Score: 0

    err, no wait..

  171. Did I *really*. . . . by kfg · · Score: 1

    have to include that in tags? :)

    Nice faq by the way. Thanks for pointing it out.

    Did you know you can still get Z80's? Maybe it's time to stock up.

    KFG

  172. It's funny because it's true. by Anonymous Coward · · Score: 0

    And not just because talking about memes automatically makes you look smart.

    "Can you imagine a beowulf cluster of people that don't communicate through cliches? Me neither."

  173. Thank you, and I would like to add... by Anonymous Coward · · Score: 0

    WILL SOMEBODY PLEASE THINK OF THE CHILDREN??!?

    Thank you again. That is all.
    oo_oo-ooo_ooo-oo_oo

  174. Only X86? by di0s · · Score: 1

    Suddenly, I feel like "Thinking Different".

  175. Government could require you to register... by Tiger+Smile · · Score: 1

    ...your computer. That's where this could easily lead. Like an ID for your point of access to information, so that people are trust you on the net. Why not. It would be a direct usage tax on those planning on using the internet.

    If there was a system like this in place on all computers I'm sure there is a chance that it will be talked about in some circles.

    Personally I really hope not.

    -- James Dornan

    --
    -- Prepared at the direction of, or to be sent to Legal Counsel, in anticipation of litigation. Attorney Client Pri
  176. There shouldn't be a problem with non-trusted OSs by autopr0n · · Score: 2

    Just non-trusted boot-loaders. A non-trusted OS would simply have some restrictions placed on it's access to the hardware, at a hardware level. So, for example, you wouldn't be able to play DRM'd videos or whatnot on a linux box, not matter how hard you tried. But you'd still be able to boot.

    --
    autopr0n is like, down and stuff.
  177. Fear. Uncertainty. Doubt. Keep up the good work by B.D.Mills · · Score: 2

    The parent post is one example of the way we can render "trusted" computing stillborn. Keep spreading the FUD. Remember that the only thing that is needed for evil to triumph is for good men to do nothing.

    --

    The only thing necessary for the triumph of evil is for good men to do nothing. - Edmund Burke
    1. Re:Fear. Uncertainty. Doubt. Keep up the good work by moncyb · · Score: 2

      How is this FUD? It may be the fear part, but if you have been following the actions of MS for at least the past decade, you'd be certain that they will do something like this. There is no doubt!

  178. OSX, Palladium, x86 by barfarf · · Score: 1

    This really makes me wonder - and I may be completely off-base on my understanding of this here, so please excuse me if this is kind of whacked...

    But since this initiative is to make sure that users aren't using a particular hardware/software combination in a way that the copyright holder or software manufacturer doesn't want, would Palladium hypothetically, for instance, give Apple the power to keep users from putting OS X on a non-apple branded x86 pc? Or could it be used to prevent other OSs to be installed on an x86-based mac?

  179. Re-Seating Chip is Job Opportunity by Lucius+Sour · · Score: 1

    This could be quite a sideline for some of us. Maybe we should be grateful to these short-sighted companies giving us another cash-in-hand source of income. If thay make modding mobos illegal then EVERYONE will want me to mod their boxen. I can just see my new Lexus....

    --

    Hands up everyone who refuses to obey orders.

  180. TCPA != Palladium by Chris+Colohan · · Score: 3, Informative

    PLEASE go and read about both TCPA and Palladium before flaming them. They are NOT the same thing. Really.

    Both TCPA and Palladium are ways of achieving "trusted computing", which is the ability for a program to run in an environment where the program knows (and can certify to people other than the computer's owner) that no other unwanted software is monitoring or modifying its actions. But how they are implemented is quite different.

    TCPA uses a secure boot process. The BIOS verifies that the boot block is trusted; the boot block verifies that the os kernel is trusted; the kernel then verifies the trust level of specific applications; etc. This is what this BIOS implements. The main feature of TCPA (in my mind) is HARDWARE SIMPLICITY -- all that is needed is a small extension to the BIOS which modifies the boot process.

    Palladium is from Microsoft, and it shows. Palladium is designed to start up in already running copy of pretty-much-unmodified Windows. Loading the Palladium subsystem (now known as a nexus) is supposed to be fairly easy, sort of like loading a device driver. But to get this ability they PAY with hardware complexity -- the CPU itself has to be changed so that the address space of the nexus can be partitioned, so it is not visible to or under the control of the main Windows kernel. This is one of many reasons why you don't see any Palladium enhanced systems in the real world yet -- Intel (or AMD) has not yet started selling a chip which supports what Microsoft needs to make Palladium work. A main design goal in Palladium seems to be "don't mess with Windows, we don't want to break legacy code".

  181. creators != RIAA by juan2074 · · Score: 1
    . . . in violation of the creators wishes.

    Please don't assume the wishes of the record companies match those of the actual creators. Even in cases where the creators wanted their music freely shared (like the Grateful Dead, for example), the record companies did not like it.

    To date, I know of no music that has been created by the RIAA.

  182. Sketchy on details but by einhverfr · · Score: 2

    I would assume that since this a module, it could be disabled in the BIOS settings (of course AMI wants to sell BIOS-tech ;-) to motherboard mfgr's, so they will want to support the wide variety of OS's.

    The result would be that Windows Palladium would be able to detect whether this was enabled or disabled and respond accordingly but one could still run Linux.

    --

    LedgerSMB: Open source Accounting/ERP
  183. Re:Second coming?-Word play. by Anonymous Coward · · Score: 0

    "If the post had pictures, nobody here would notice the second coming. In fact, how would any of us know that the second coming hasn't already happened while we've been surfing the Web?"

    The first does tend to be a distraction.

  184. slashdotters should make up their minds by geekee · · Score: 2

    I find it interesting that slashdotters complain that the RIAA is trying to hang on to an old business model, and then in the next breath complain that DRM limits their freedom. Make up your minds, either accept no legal online music from the RIAA or accept DRM, because you can't have both. People have shown they aren't trustworthy with unprotected digital media.

    --
    Vote for Pedro
  185. Authenticated BIOS simply shuts off TCPA support by yerricde · · Score: 1

    If it's not valid, the TPM chip won't allow the boot process to proceed.

    That's not what I perceived when I read a couple TCPA and Palladium white papers. Under current plans, if the BIOS has been "compromised", the TPM chip will shut itself off and get the heck out of the way. However, TCPA apps won't load.

    --
    Will I retire or break 10K?
  186. I wrote AMI and this is their response by LittleLebowskiUrbanA · · Score: 4, Informative

    Thank you for taking time to contact us here at AMI. We are sorry to hear
    of your decision to not seek out an AMI solution for your next purchase.
    While we respect your right to make that decision we would like to take a
    minute to underline some relevant points about our announcement that were
    not adequately conveyed in the "article" posted on Slashdot. We urge you to
    please give us a minute of your time to fully understand what AMI is
    offering and thus be able to make a fully informed decision.

    It must be noted that AMI has not announced support for Palladium. Palladium
    is an initiative by an OS entity that is slated for the future. To be
    honest, though we do know about it, AMI has not begun any development
    related to it. At this point we have not made any decisions on support
    either.

    TCPA does not equal Palladium. While certainly there is some future
    development overlap between the two, TCPA is being introduced by OEM's as a
    security option to protect systems through hardware and firmware. This
    feature is completely optional to our customers (OEM's, ODM's, CM's and
    other system builders) that they may choose to make it available or not
    depending on the needs of their market. We have had requests from a number
    of customers for this technology.

    Regarding the limitations of a system with TCPA I would offer the link below
    to the public specification for further information on compatibility with
    different OS's, and hardware. Based on that spec we can tell you that it
    does not limit the ability to run Linux (or any other open source solution).

    As a smaller company itself, AMI has always supported innovation and
    creativity as these have been our main tools in competing against much
    larger companies in our industry. We would not do anything that in our
    minds would damage our credibility or reputation for world class BIOS
    solutions and will carefully evaluate this type of feedback when it does
    come time to examine any future technologies. We would also like to
    recommend that anyone who is opposed to a Palladium-type solution in the
    future, please make that known to OEM's and system builders. As they are
    our customers, we definitely listen to them in terms of what they (and
    hopefully their customers) will want in future BIOS.

    Thank you again for your time in contacting us and we hope that this and
    some of the links below will shed some light on AMI's plans.

    LINKS

    Original Articles on theinquirer.net

    http://www.theinquirer.net/?article=7089
    http:/ /www.theinquirer.net/?article=7103

    AMI TCPA module Whitepaper
    http://www.ami.com/support/doc/TCPA_wh itepaper.pdf

    TCPA Website

    Basically wrote them and told them I wouldn't be buying from them from now on. I would reckon this looks like the company is receiving a bit of angry emails from people who build their own computers and/or are involved in the computer industry.
    Maybe they're worried about what WE think!? Nahhh...

  187. The only war worth fighting by Anonymous Coward · · Score: 0

    I must say, we must fight this all the way. If we don't who knows what the world might end up like. George Orwell was right on target, but I think about twenty years off. I want to sent props out too, to the people who elected of Senator Fritz Hollings of South Carolina. Heh.

  188. Can't it be disabled? by phorm · · Score: 2

    Except that one of the key things Microsoft et al have been saying is that the DRM features in the OS can be disabled - so basically it is just to prevent backdoor hacker apps from getting into your system - somewhat like a hardware (more global) Zone-Alarm. Of course, I don't believe for a second that MS won't try and make some of it impossible to disable, or at least very difficult.

    But then, if somebody can get an X-box to run linux... I'm fairly sure some of the whiz kids out there will figure out how to hack DRM hardware

    1. Re:Can't it be disabled? by Seahawk · · Score: 1

      Linux on xbox only works on modded xboxes - this would be the same on the first generation of palladium - "just" replace the bios.

      But when the palladium stuff starts to be implemented in your CPU, you start to have a problem with this solution!

    2. Re:Can't it be disabled? by Alsee · · Score: 2

      Except that one of the key things Microsoft et al have been saying

      What Microsoft looks like the are saying and what they are REALLY saying are two entirely different things.

      so basically it is just to prevent backdoor hacker apps from getting into your system

      Wrong. Palladium will not stop backdoor hacker apps from getting into your system. Microsoft has admitted this. What it DOES do is prevent them from "stealing*" files. They are still perfectly free to 0wn your computer. They can run anything they like and wipe your entire harddrive at will.

      * Stealing: they can steal your music files from you. Palladium will support moving files from one computer to another, but it enforces wiping the original in the process so that only one copy exists at a time. Normally a hacker who wants to "steal" your music would just copy it. Palladium just forces him to actually take it away from you in the process.

      What Palladium DOES is prvent the hacker from stealing from the company that sold the music to you. They got paid for one copy, and only one copy exists. Unless you want to pay for a new copy. It just makes sure that if both you and the thief have a copy that someone (you) has paid for both copies.

      Palladium does not protect the computer owner. Trusted computing has nothing to do with YOU trusting it. It is all about protecting the companies that sell you stuff, and about THEM not trusting YOU.

      -

      --
      - - You can't take something off the Internet! That's like trying to take pee out of a swimming pool.
  189. probably not that bad by g4dget · · Score: 2
    I suspect that it simply won't enable "protected" functions of the computer: cryptographic keys and the like that you need in order to play/access content that is subject to DRM.

    That would still be annoying as hell, but you wouldn't lose any functionality over what you get now; it would just become harder and harder to access things like the next generation of digital audio/video and Windows media from Linux--at least if the big studios and record companies get their way.

    Overall, though, I still think that this will just flop: no hardware or software vendor really needs the hassle or additional support costs that result from this.

  190. Huh?! by kweg · · Score: 1

    So if I don't trust Windows it won't boot? Oh well I guess I'll have to swich to Linux ;-)

  191. I don't get it.. by Splab · · Score: 1

    Ok, so they got "trusted" computing.. who gives a damn. I just became proud owner of red hat 8.0 and I like it, it isn't good enough yet to be handed over to my mom, but that day isn't all that far off. If the community (linux) refuses to adapt DRM in its OS _and_ the install procedure of linux gets even easier to do (theres some naste questions of partitioning and thats a nogo with older generations, you might argue that windows has same questions, thats true, but their machine was bundled..) then theres not gonna be a DRM bios.
    Also people seems to be forgetting the what is really driving the markets. It's games, musik, movies and some companies. (generely the need for speed)(illeagal stuff imo is the main factor *uff*)
    At some point the avarege no brain gamer is going to realise that he has to _pay_ for his music, games and movies, that day he is going to shop for new OS _without_ drm. I think if the linux community refuses to adapt this "technology" everybody is sooner or later going to come to the other side of the pawn (is that the word?) and do it linux style. We can only hope that more game makers are following the UT2003 approach and distributes linux versioins.

    Microsoft keep digging that hole youre almost readdy for the burial.

  192. MOD PARENT UP by Anonymous Coward · · Score: 0

    Those are perfectly valid points.

  193. Trusted Computing=Anti Competitive? by JHandey · · Score: 1

    If they make it so computers can only run on a preset number of "trusted" operating systems... that pretty much kills any new OS development on future hardware. Is that legal?

  194. Heard of DVDs? by GoofyBoy · · Score: 2

    Aren't they delivering digital media right to your computer?

    And I believe they are popular and selling like hotcakes.

    --
    The surprise isn't how often we make bad choices; the surprise is how seldom they defeat us.
  195. The point he's trying to make is... by Anonymous Coward · · Score: 0

    If they're making record profits without DRM, why do they think they need it?

    Do they really think music will be more popular if its more restricted?

    Something doesn't quite make sense.

  196. Comment removed by account_deleted · · Score: 2

    Comment removed based on user account deletion

  197. But "proven" means more... by tkrotchko · · Score: 2

    Proven means more than "it technically works". Its more like "will consumers embrace this technology" and "will it make me more money"?

    The answer to the 2nd is critical.

    DiVX worked technically (actually, considering what the RIAA/MPAA wants, its pretty tame, really), but consumers stayed away in droves. So it was dropped.

    What's changed in the last 3 years that makes anyone think consumers will embrace DRM any more today than yesterday?

    The RIAA and MPAA can threaten to withhold their content, but if they wont' sell content, then they're a non-factor in the decision.

    --
    You were mistaken. Which is odd, since memory shouldn't be a problem for you
  198. Re:Can you say..PPC Chips? by voodoo1man · · Score: 1
    Frame rate for games? Got my PS2 for that.

    Now, which Japanese owned mega-conglomerate is it that supports the DMCA, trusted computing, and RIAA's antics all at the same time?

    The hypocrisy of open source groupies and wannabes dumping Windows because they don't like Microsoft's political actions and then loudly proclaiming how great their new gaming console/DVD-player is never ceases to amaze me. Compared to the Gamecube and PS2, Windows is really "open".

    --

    In the great CONS chain of life, you can either be the CAR or be in the CDR.

  199. Re:awesome technology by Anonymous Coward · · Score: 0

    "a fairly long and complex process"...

    Seems to me we've been headed that way all along. My TRS-80 in 1981 would boot off floppy in about 15 seconds... my first 386 took at least a minute... and now with Win2K my 1Ghz box takes even *longer* to boot. So now we'll introduce encryption, and make it a "long and complex process"...

    Geez, I just can't wait for my Palladium 27.9Ghz PC that takes 10 minutes to boot! :-\

  200. The "trusted computing" initiative... by Anonymous Coward · · Score: 0

    ... brought to you by the company that tells you to "not trust" active-X downloads from themselves... in fact, just check the "dont trust content from Microsoft" box.

    Trust us, believe everything that we say. Check the box that stops you from trusting us. Trust us. No, wait, don't... no... oh geez. :-)

  201. Palladium Drive... by g0at · · Score: 1

    Yes, this is off topic, but I get a personal guffaw out of the ironies of capitalism...:

    This Palladium stuff is about big companies ($) trying to control the users under the guise of empowering the users, and squealing like female piggies when things don't work in their favour.

    I find it amusing how today, the Ottawa Senators hockey team has filed for bankruptcy protection because they can't afford to pay their players obscene salaries ($). Yet, general NHL institution screams like a female piggy about the lack of attendance and how it's the fans who need to throw in their $ and support to make it all work.

    The amusing thing is that the address of the Corel Centre (where the Senators play) is on Palladium Drive in Ottawa.

    I detect a similar stench wafting from two corners...

    -b

    (trivia: as the arena was being built -- prior to Corel's buying out the name -- the facility was called the Palladium, in keeping with the Senators' roman theme. The roadway still retains its original name.)

  202. Not so fast by vinsci · · Score: 3, Informative
    At least two companies have started working on a TCPA-compliant version of GNU/Linux.

    So, is there a problem? Yes, there is. You can't modify the kernel. If you try, it will not be trusted by the TCPA chip and so no application running on that kernel can gain access to any feature, media or application that requires TCPA. Certifying a Linux kernel (or any other OS) as TCPA-compliant is expensive and you would need to do it for every modification of the kernel. What value is the GPL if you can't use the source to create your own kernel?

    Ross Anderson's TCPA / Palladium FAQ has a more detailed discussion (excerpt from section 18):

    [TCPA hardware is referred to as the "Fritz chip" in the FAQ]

    TCPA will undermine the General Public License (GPL), under which many free and open source software products are distributed. The GPL is designed to prevent the fruits of communal voluntary labour being hijacked by private companies for profit. Anyone can use and modify software distributed under this licence, but if you distribute a modified copy, you must make it available to the world, together with the source code so that other people can make subsequent modifications of their own.

    At least two companies have started work on a TCPA-enhanced version of GNU/linux. This will involve tidying up the code and removing a number of features. To get a certificate from the TCPA corsortium, the sponsor will then have to submit the pruned code to an evaluation lab, together with a mass of documentation showing why various known attacks on the code don't work. (The evaluation is at level E3 - expensive enough to keep out the free software community, yet lax enough for most commercial software vendors to have a chance to get their lousy code through.) Although the modified program will be covered by the GPL, and the source code will be free to everyone, it will not make full use of the TCPA features unless you have a certificate for it that is specific to the Fritz chip on your own machine. That is what will cost you money (if not at first, then eventually).

    You will still be free to make modifications to the modified code, but you won't be able to get a certificate that gets you into the TCPA system. Something similar happens with the linux supplied by Sony for the Playstation 2; the console's copy protection mechanisms prevent you from running an altered binary, and from using a number of the hardware features. Even if a philanthropist does a not-for-profit secure GNU/linux, the resulting product would not really be a GPL version of a TCPA operating system, but a proprietary operating system that the philanthropist could give away free. (There is still the question of who would pay for the user certificates.)

    People believed that the GPL made it impossible for a company to come along and steal code that was the result of community effort. This helped make people willing to give up their spare time to write free software for the communal benefit. But TCPA changes that. Once the majority of PCs on the market are TCPA-enabled, the GPL won't work as intended. The benefit for Microsoft is not that this will destroy free software directly. The point is this: once people realise that even GPL'led software can be hijacked for commercial purposes, idealistic young programmers will be much less motivated to write free software.

    --

    Trusted Computing FAQ | Free Dawit Isaak!
  203. Re:Can you say..PPC Chips? by gotr00t · · Score: 1

    You do know that Sony does endorse Open Source to an extent. They do offer a distribution of Linux for their PS2 console, so you can't really say such a thing.

  204. My 2 cents by crown_whore · · Score: 1
    Frankly I'm uncomfortable giving a kind of information away where a badge would have to have subpoenaed. I can understand wanting to check for services and media (but not preference, use or content). Anyways many countries that have adopted the UN charter (Article 12), this very thing is illegal and has been for 50 years.

    This doesn't sound viable. Given the choice, I would vote, buy, etc. to avoid setting this precedent.

  205. In Republikan Amerika by Anonymous Coward · · Score: 0

    Your government moderates YOU!

  206. Re:Can you say..PPC Chips? by voodoo1man · · Score: 1
    Yes I can.

    Offering a crippled version of Linux (since the hardware/bootloader is intentionally handicapped, and the kit comes with a restrictive EULA) to push sales by a few thousand extra units (and apparently boost their PR image among unwitting techies and open-source groupies) doesn't undo Sony's current corporate policies.

    --

    In the great CONS chain of life, you can either be the CAR or be in the CDR.

  207. Then you'll see 2 types of PC by Baki · · Score: 2
    What I keep worrying about is the TCPA *2.0* specification. The original spec allows an alternative to a "trusted" platform, but future specs may require a PC boot a Palladium-enabled OS -- or none at all.


    Since there is a large and fully legitimate market for other operating systems (PC-UNIX variants, novell, Linux) which is already being used on a large scale by large business as well, it is impossible that there won't be any PC's that run non "trusted" platforms.


    You'll just see a divide in the PC architecture: one for "trusted", i.e. windows-only PC's, one for the rest (just as there are Apples and PC's today).

  208. Maybe Gigabyte's Dual BIOS could fit here by joeflies · · Score: 3, Informative

    Gigabyte offers mobos that support two bios copies. It's there to provide BIOS failover (not that I've ever, ever had a problem with BIOS failing), but perhaps it could be adapted to allow dual-boot bios between Palladium and non-Palladium OSs. Tom's hardware explains Gigabyte Dual Bios

    1. Re:Maybe Gigabyte's Dual BIOS could fit here by kcb93x · · Score: 1

      Maybe *nix/BSD/other GPL/LGPL OS should have it's *own* BIOS, to work alongside Palladium? Have something like a boot menu, except selecting the BIOS to boot from (which would potentially launch into it's own OS selction menu?)

      --
      There are 4 boxes to use in the defense of liberty: soap, ballot, jury, ammo. Use in that order. Starting now.
  209. Same old story, different name by Aerick · · Score: 1

    Last time I checked, Microsoft had never created a piece of software that someone hadn't hacked. Security holes have been found in every operating system from the oldest version of windows to the latest version of OpenBSD.
    That being said, I don't believe that suddenly, with a help of a single new chip, all of Microsoft's software security problems will be resolved by a "magic chip" that proves that the software is secure.
    As I understand the technology so far, software must be declared secure by a central reviewing agency. Once this has been done, any security flaw in the software can be exploited, just like usual.
    I don't think any single fancy chip is going to stop the computer community of the world from breaking through Microsoft's attempt at world computer domination.
    And hey, If I'm wrong, I can always resort to the notepad and printing press.

  210. Power of Technology by Anonymous Coward · · Score: 0

    Hmm.. so we have progressed enough with technology to do the BI (Biological Impossibility => Fuck Oneself) Of course, in Soviet Russia, the same happens :)

  211. Time to switch to Apple by rribeiro · · Score: 1

    If I dont have an alternative to this so called "trustworthy" hw, thats what Ill do...

  212. Hurray for Open BIOs by Anonymous Coward · · Score: 0

    FUCK AMI.

  213. simple extension by Aerick · · Score: 1

    I believe the end result will turn out much like M$'s present ActiveX signaturs work; in most cases, if you dont pay to have your control signed, standard settings block it. Seeing as my mom can't change her desktop wallpaper, I dont see the common consumer knowing any better.

    Microsoft has been easing us into acceptance for a long time now. People are simply starting to take notice.

  214. Heretic you!.. by Anonymous Coward · · Score: 0
    Are ytou trying to imply that Linux is viral!?..

    ;op

  215. Maybe not ever by Peyote+Pekka · · Score: 1
    Actually there are quite a few discrepancies and vagueries with Palladium. Similar ones existed with MS-Passport but the FTC finally forced them to quit lying about MS-Passport. (Notice, except for a small attempt to smear Liberty Alliance, how quiet it's been since August?) Since Palladium seems to be full of contradictory claims, it's quite possible that the FTC will pull the plug on that line of bull also.

    Even if Palladium eventually dries up and blows away it's serving as a good distraction: either Windows is being dropped from .Net or .Net is being dropped from Windows.

    Stay focused on standards, interoperability, and development.

  216. Diabolical! by moyix · · Score: 1

    They're replacing all his dangerous speech with perl code! The fiends must be stopped!

  217. On the subject of trusted chains by jago25_98 · · Score: 1

    Source -> Middle Computer 1 -> Middle Computer 2 -> Destination

    All 4 sections of the chain are a liability.

    So, LAN Topography = ?
    and Internet = ??

    Please remember the issue of the chain effect!

    - Effectively this makes ISPs *extremely* powerful (as if they aren't already?)

    - Security tends to be an inconvenience, I expect this will amount to little more when attempting to crack it and use it.

    - Specialised hardware isn't actually required to do this? In thoery could do it by examining the way hardware reacts to various things, no 2 computers being the same. Far fetched or inefficient?

    - on the idea of protecting music:
    We can still copy things, I can re-route my speakers into my minidisc. I the worst I can try to learn the song on my guitar and re-record :p But, how do you stop that? And how do you justify it...? The record industry was a special situation like newspapers and cotton industry were in a long time before. The Luddites would be proud of the RIAA.

  218. Microsoft, Palladium and Lilo by trezor · · Score: 1

    Does this mean that Microsoft by introducing Palladium for the first time ever, actually manages to kill dual-boot systems? Like its been trying ever since bootmenus appeared?

    Now, I donnu about the rest of you, but in my system that would mean the end of Win32, not Linux!

    --
    Not Buzzword 2.0 compliant. Please speak english.
  219. And it won't delay the boot... by Anonymous Coward · · Score: 0

    Prominently mentioned in the AMI letter is the fact that this feature will not significantly delay the boot process and thus insure that the boot process will still be fast enough to comply with the relevant standards (I forget the acronym).
    I wonder why this is so important. Aren't the times that we had to reboot 10 times a day way behind us now, even for Windows systems???

  220. CIA anyone? by trezor · · Score: 1

    Not to be all paranoid or anti-USA (Im only anti-Bush), but here goes.

    As far as I can tell, the TCPA/Palladium schema is beeing developed by americans in the USA. And we all know that your goverment does not accept secure encryption, unless they have a backdoor. (Think PGP and export guys)

    So this platform would be entirely unsecure and transparent. It would be impossible to protect your content from the USA-goverment. Your privacy gone void! And as a sideeffect, all of the western world using palladium is now open to the US goverment as well...

    And what if the keys/backdoors got leeked? Palladium rendered unsecure worldwide in .. what? 15 minutes tops!

    This sounds like flamebait, I know, but it isnt meant as flamebait. Anyway, I wouldn't "trust" it, and so should noone else.

    --
    Not Buzzword 2.0 compliant. Please speak english.
  221. some association by GnuPengwyn · · Score: 1

    think "win" . . . "winMODEM, winBIOS" maybe, throw it through the window? na, just remember, if it says win don't buy it. don't sell it. don't use it. don't support it. don't give it away. just destroy it. (or desolder it)

    --
    Love Music? Got a Band? Are you a Label? http://garageradio.com
  222. Great by Anonymous Coward · · Score: 0

    Now we have to solder mod chips into PCs to be able to program :-)

    Btw. PC modding becomes a totally new meaning this way.

  223. How bad DRM is? by Anonymous Coward · · Score: 0

    Let's face it... most of us are bright enough to keep their private data off their "trusted" computers. What we are really worried about is losing the privilege to use pirated software and play pirated digital media. I admit, most of my software/music i own is pirated. This is because things are just too darn expensive. I'd have spent a FORTUNE if i had bought all those things. Just to make something clear... i like linux. I like perl, shell programming etc. But i really like windows as my desktop OS and no, i'm not gonna pay for it. I use pirated windows (and other software) because I CAN. Now, if we were to lose this privilege... what would become of windows? Office? Would you pay $500-600 for a really complex and feature-packed office suite if you're going to use about 2% of its abilities? If you're a home-user, I think not. I believe that today, this "cheaper" software product is losing ground to more expensive one because most people can use the pirated version on their home computers and who's gonna play around with some cheap or free app if you're not going to buy it whether it's expensive or cheap. If DRM would put an end to pirated software, I believe that software industry would actually thrive and end-users would get more cheaper or free (beer and speech) software of greater quality. What would become of microsoft? Major platforms will always run linux hardware unless the US of A government manages somehow to clobber it with DMCA. I think many users will switch to linux and gnu/open source software which won't spy on us. Either that, or we'll see some major changes in licencing and pricing.

    1. Re:How bad DRM is? by ironfroggy · · Score: 1

      Speak for yourself. What I am worried about is DRM getting in the way of my legal activities, and that's a fact.

    2. Re:How bad DRM is? by that+_evil+_gleek · · Score: 1

      Its a result of you and the many like you. Don't mean to be harsh, just accurate.
      Steve Balmer described Microsoft's philosophy for dealing with IBM in the '80's, how IBM was the bear and you had to ride the bear, or you'd be under the bear.
      Now, Microsoft is the bear, and it's smarter than the average bear -- in the sense, that is very clever, only time will tell if it's wise.
      By pirating Microsoft products, you were effectively promoting Microsoft products as standard. I don't believe its really been about O.S. It was about WORD, the .doc format and those people who sneer when you don't want to take doc files from them , and sneer when you don't give to them those .doc files. And what influence those people (may) have. So, you bought into it, rather than fight it, and now they're going to to lock it up with you still inside.
      Potentially, they could shoot themselves in the foot, but as they know they have a history of their products achieving dominance by the old #1 fumbling, they are aware that it could happen to them.

      Consider these two questions: If a man is starving and he steals bread -- is it wrong? vs if a man is starving and he walks past free bread, walks past the all you an all you can eat buffet, because he needs to keep money for beer money, and breaks into someone's house and steals the premium, gourmet grub -- is it wrong?
      We live in a capitalistic society: what gets money thrives, what doesn't dies. When someone with money, could have bought the latest windows game but bought linux , says more than an on-line registery, on any post to *.advocacy. That's when the 'business-types' started to notice, and the nontechs started to notice. Then, later , when debian and mandrake made installing linux mac-easy installing linux started to be confused with using linux, by some anyway.

  224. Re:Can you say..PPC Chips? by cesarcardoso · · Score: 1

    These--as long as Congress doesn't screw everything up

    Put the terrorist-of-the-day name on it ("TCPA or terrorists") and the US Congress WILL screw it up - requiring TCPA on hardware, or banning non-TCPA wares from selling in the US, or else. And Motorola, IBM, Sun, SGI are US companies, probably they doesn't want to find themselves in trouble with the US Gov't.

    --
    Cesar Cardoso can be found at cesar at zyakannazio dot eti dot br (or at least I believe so)
  225. Do I control authentication or "they" ? by SailFly · · Score: 1

    If I do, then this could be a surefire way to prevent boot sector corruption (since the BIOS won't allow it unless *I* allow).
    If "they" control it, then I'll always be performing some kind of authentication myself by calling 1-800...
    As far as I see it, this could be a great step in protecting my systems...or a major pain...

  226. How bad is it? by kcb93x · · Score: 1
    Yes, me as well, and also the fact that I PAID for the hardware, so therefore I should decide what is and isn't "trusted."

    NOT what Microsoft (or whoever else makes the decision) what I can and cannot run.

    --
    There are 4 boxes to use in the defense of liberty: soap, ballot, jury, ammo. Use in that order. Starting now.
  227. OT: your sig by Hellkitten · · Score: 1

    Shouldnt you append an "In Soviet Russia" to that?

    --
    - We are the slashdot. Resistance is futile. Prepare to be moderated -
    1. Re:OT: your sig by Anonymous Coward · · Score: 0

      In Soviet Russia beowulf clusters imagine themselves!

  228. I disagree, partly. by Irvu · · Score: 2

    It is true that there exists a large bevy of non-us governments out there supporting linux but that may not be enough. Consider first off that many of these governments (such as China) have their own interests in controlling computer use. To some if not all of then DRM may be a viable alternative.

    Now consider the fact that their support of Linux is mainly an opposition to Microsoft more than an embracement of "the people's needs". For China and other countries Linux is a proven way to get into the high-tech world and one that is significantly cheaper than any other. For Germany it was a way to have "their own" operating system, one that they could trust for security reasons. I must have missed the UK announcement because last time I checked their e-government portal was still Windows/MacOS only.

    Now Consider this. There is nothing in the DRM standard that forbids you from producing your own operating system. In order for it to work howevber you must have it certified. So what's to stop someone like IBM from producing their own "official" GNU/Linux distribution. This distribution could be shipped to the users in the form of precompiled binaries, and updated just like Microsoft's. The system is robust, full featured and, because of all the work that other people have done, IBM (or whoever) can sell it for a nominal licencing fee and still make a profit.

    I may just be waxing paranoid but I see this as one possible way for linux to be co-opted. Yes it is still free and GNU licenced but you need the "official copy" in order to run it. For other countries this may be a win. China has already shown their willingness to produce their own official OS (and chips). Countries like Peru might not mind this so much so long as the system is cheaper. And, if the U.S. and other major markets go this way the small "emerging countries" may have no real choice.

  229. Comment removed by account_deleted · · Score: 2

    Comment removed based on user account deletion

  230. Re: Not storage, snooping. by deanpole · · Score: 1

    Offline storage is not my concern. I want a memory module that looks just like a normal one so Palladium can't reject it. When the computer is up and running I want a second computer to snoop on the memory of the first. USB seems like the easiest option, but firewire would be fine too.

    I wonder if their north bridge will encrypt main memory. Will they shuffle the address too, to scatter the contents? I suspect that timing constraints will drastically constrain their cypher quality.

    In reality this is much easier implemented as a bus mastering PCI card, unless new bridge chips limit bus masters' memory access. They must or Paladium would be incompatible with existing cards, instead requiring new ones that cyrpographically authenticate. Even still each card can snoop on the PCI transfers of others.

    My speculation is that their TCPA BIOS is still a long way from a "trustworthy" computer. I can break into any computer I have physical access to.

  231. Clarification of Palladium BIOS by jeske · · Score: 1

    Disclaimer: This is of course only my interpretation of the information I've read about Palladium. I did not write the BIOS, and neither did you. :)

    The palladium BIOS in question is not claimed to only boot signed operating systems. It merely claims to provide the "trusted system/user verification" only to signed trusted operating systems.

    For example, if a company was providing Rights Managed content to your machine, it would first verify if your machine was trusted. If you had booted Linux on your Palladium enabled machine, then Linux (potentially) wouldn't have access to the "trusted system verification" and the company/website would not provide the rights managed content for fear that the rights management would be compromised.

    Of course, it's not a long jump from here to there, so watch out.

  232. Wrongo. by Kickasso · · Score: 1

    The playback keys are encrypted to the session key. Your box-in-the-middle can't get it.

  233. Re:IN SOVIET RUSSIA computers have to trust you .. by IXI · · Score: 0, Offtopic

    Oh, wait, that's not Soviet Russia, that's the status quo. So it must read "IN SOVIET RUSSIA you have to trust the computer". But that's exactly what M$'s "Trusted Computing" means ...


    Who's that stupid moro^H^Hderator who modded that `troll'?

    --
    He saw some dirty arabs and fired. Too bad it was just some friendly kurds, BBC reporters and his fellow cowboys.
  234. Re:awesome technology by Anonymous Coward · · Score: 0

    Parent post plagiarized from http://msbetas.net/news/news_item.asp?NewsID=182.

  235. Last Post! by alpg · · Score: 0

    Despite the best efforts of a quantum bigfoot drive (yes I know everyone
    told me they suck, now I know they were right) 2.1.109ac1 is now available
    -- Alan Cox announcing Linux 2.1.109ac1

    - this post brought to you by the Automated Last Post Generator...