Slashdot Mirror


Microsoft To Demo 'Palladium' At WinHEC

1010011010 writes "According to Microsoft Watch, Microsoft will be demonstrating Palladium (also known as 'Next-Generation Secure Computing Base') at WinHEC in May in New Orleans. The 'trusted root' is now called the 'Nexus' by Microsoft. Developers wishing to write 'Nexus-aware' applications will apparently have to pay a licensing fee to do so. The product manager for Palladium, Mario Juarez, says, 'It's important to note that nexus-aware applications will not hinder any apps or anything else running in the regular Windows environment.' I'm sure you can all hear the word 'yet' at the end of that sentence. There's talk of phasing in Palladium, starting with Longhorn Server in 2005. I wonder how Microsoft will convince consumers that loss of control is a good thing, and how long the convincing will take. I, for one, am already planning to transition my company away from Microsoft software. Hopefully that won't get messed up by and dumb mandatory-palladium legislation from the Fritz types."

13 of 359 comments (clear)

  1. The fees! by alpharoid · · Score: 5, Insightful

    I don't like the part about the fees. Palladium does seem to have one strong point in making its applications hard to exploit (even the badly-written ones).

    So won't this hurt Linux and Open Source software in general? High fees would keep Microsoft's good competitors (Apache, for instance) away from Palladium, and then we'd have all the unbearable boasting about how IIS is more secure.

    That would be a cheap trick... but one to expect.

    1. Re:The fees! by NewbieProgrammerMan · · Score: 3, Insightful

      If anything, I think the fees would drive more people to develop their software on free platforms.

      Damn straight. The only reason I haven't dropped Win2k on my main desktop in favor of Linux is that I still develop some software that only runs on Win32 (and I don't feel like being hassled with WINE). It looks to me like Microsoft is going to try and latch onto my wallet just for developing software for their platform, so the incentive to drop all my Windows-specific work is getting pretty significant.

      --
      [b.belong('us') for b in bases if b.owner() == 'you']
  2. Security by Axel2001 · · Score: 5, Insightful

    While the idea of the technology isn't really all that bad, I question the intent of Microsoft in creating Palladium. If the technology is adapted in its "pure" form, Microsoft will be able to determine what you can and cannot do on your own personal computer - and they will make consumers pay for this "technology." It would be like adding the extra "feature" to an automobile that you can drive only to certain places - and charging more for this "technology." Where can you go today?

    1. Re:Security by enomar · · Score: 3, Insightful

      Working with your analogy, I guess the theory is to provide a car that can't be driven on dangerous bridges. This is surely a good thing, but like you say, MS should not be the one deciding what bridges are bad, especially when they require a fee to evaluate your bridge.

      Couldn't the decision be based on a non-biased group or even a public voting system? What is stopping the OSS community from writing their own version of paladium? I guess there might be some hardware issues to iron out, but I'm no expert...

      --

      :wq
  3. people love "security"... a bit too much... by gasgesgos · · Score: 4, Insightful

    I wonder how Microsoft will convince consumers that loss of control is a good thing, and how long the convincing will take


    The government's already convinced people that loss of control in the name of "fighting evil" is wonderful, and that it should be accepted openly.

    Hopefully people don't follow suit with Palladium, or pretty soon, the government will see that regulation of a person's own computer can be done easily and effectively.

    solution: we all start using Linux (or in some cases, use Linux more) and move to Canada (or in some cases, stay there)





    note: entire solution does not apply outside of US or Canada, your mileage may vary, see dealer for details, sweepstakes ends 11/05/72. Linux portion of solution applies to all humans, again, see dealer for details.

  4. 2005 by Unregistered · · Score: 3, Insightful

    That gives us about 2 yrs to get linux ready to take over. Can we? Because if not, it will be vary bad. This is our chance. Once people are tied into palladium, they're stuck.

  5. why doesn't everyone.... by UniverseIsADoughnut · · Score: 3, Insightful

    ... Just sit back and wait and see what MS does. If you just take it for what it says now there isn't much of anything to go nuts over. Yes maybe something will come up that makes it Evil, though with something like this what one considers evil others consider good. If It turns out to be just as MS says it is going to be, what do you have to fear? You don't like the paying? sure that might not be so great, but then again this is most likely going to apply to major windows apps. You know the kind written by companies that people go out and buy. So adding a few cents to the price won't matter to anyone. I don't think anyone is going to go and pay to have there Hello World app 'Next-Generation Secure Computing Base' certified.

    If your afraid of how it works or don't like it don't use it, don't use windows. With just what MS has said most all of what people go on about has no bases and is just stuff from tin foil hat people. Yes MS has done bad things. Maybe they will with this. But give them a chance with it, let them screw up before you chastise them.

    1. Re:why doesn't everyone.... by mao+che+minh · · Score: 5, Insightful
      Why doesn't everyone just sit back and wait and see what MS does?

      Because we already know what Microsoft will do: employ whatever tactics neccassary to insure their continued monopoly status and success - even if it means eliminating the private ownership of data as we know it. The rabid MS bashing going on isn't a sign of premature paranoia, rather, it is the natural reaction of those that have studied the company's history.

    2. Re:why doesn't everyone.... by ATMAvatar · · Score: 4, Insightful

      But give them a chance with it, let them screw up before you chastise them.

      Given one of the features in Palladium is supposed to allow for remote deletion of files by Microsoft, I'll have to decline giving them the chance to screw up. I see 2 major problems with this:

      1. I don't trust Microsoft with this power. Should I run software Microsoft doesn't like, what's to stop it from deleting the software?

      2. With Microsoft's famous security in software, coupled with this new feature, how long do you think it will take for a person to crack into a Microsoft server and issue commands to thousands of computers to delete files? Palladium may be designed to only run trusted programs to issue these commands, but I can't imagine gaining trusted access being much more difficult than grabbing administrater or root privledges on a machine.

      Sure, you could set up your firewall to block the remote deletion commands, if you know what port it's using. I have philosophical issues with using firewalls to protect myself from the programs running on my computer, as opposed to protecting myself from outside threats, though. I'd much prefer not putting Palladium on my system. The risk is much too great, especially if I were to screw up configuring things to block this "feature"(and I'm hardly a good sysadmin).

      --
      "They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety."
  6. Missed the Point. by torre · · Score: 4, Insightful

    The poster has missed the point and has confused two seperate issues into one. (DMR and machine security). If the poster had actually read the microsoft link from his own link he would have come up with the following quote"

    " "Palladium" will not require digital rights management technology, and DRM will not require "Palladium." "

    DMR is not the focus of Palladium (at least intially.... I say this with a grain of salt as you never know what they future will hold), but rather a seperate microsoft initiative spearheaded by the windowsmedia group and the Office group. I would be far more concerned about what these groups do than what Microsoft has outlined for Palladium.

    Palladium is (or at least what is hoped, again i say this with a grain of salt, we'll only really know once the deliverables are shown) a combination of two big ideas. The first is to provide a system in which a user can trust stuff and allow it to run with sensitive information (eg, user data) and provide a sandbox where they can run stuff that they don't trust and know it won't do anything of consequence.

    The second is to bring the PC hardware/Software to a more sofistated level, bringing up the bar as it would to what is now held by some of the mainframes. This serves two fold a purpose, one to weed out old hardware and hardware manufacturers that people keep using over and over that perhaps just don't have proper drivers which haul down the machine. Secondly, give greater credibility to the Wintel platform in all they're little political/business/OSS/User heart battles. At the end of the day, any time a user/admin/whomever sees something not function correctly (eg, system crash, failed performance of hardware eg... scanner won't scan) the first impulse is to blame Windows reguardless what caused the problem. I'm all for the improvement of the overall improvement of windows as any system that is improved makes a cost saving in both time and money at the end of the day.

    There has been much speculation as to what Pallium will actually be. Most of it has been nonsense runned off by people with FUD as they're agenda. Little is known about what exactly will Pallium eventually encompase.... But what I do know is this. If it turns out that user restrictions are placed and people suddenly stop beind able to do certain things... then Microsoft will get a hit to they're bottom line and OS's like Linux and Mac OSX will suddenly have a massive inflow.

    Give the public a little credit... The market doesn't have an absolute hold on them and if windows doesn't suit they're needs they'll jump off as though the ship is on fire. It's not like there aren't other capable alternatives. If there wasn't windows would have been regulated long time ago just like the telcos. But do you really think microsoft would alient people that much (or abolish competition for that matter) to be able to hurt themselves? I think not.

  7. thoughts.. by Dave_bsr · · Score: 4, Insightful

    The first thing i thought was: "So, it starts."

    Then I read some comments. You gotta pay to write software for windows. What crap! They have the desktop computer section by the balls, and they keep squeezing for more money.

    But the more they squeeze, the more people get sick and leave. So in part, I welcome this. Maybe a few more people will get the idea and switch to something freer....something that ends with "ix" ... It keeps getting better all the time.

    --


    Who is this Anonymous Coward character, how does he post so much, and why is he always such a whore?
  8. Here's how - by FFtrDale · · Score: 4, Insightful
    They've been doing it for years. Neal Stephenson said it best in In the Beginning Was the Command Line":
    Buyer: "Can't you see that everyone is buying station wagons?"
    One place to find it is http://bang.dhs.org/be/beginning.html

    There are several other places to find it; I just googled it again. And get a dead-tree version for your Dad, too (that's where mine went).

    --
    Think, write, think, edit, think...then post.
  9. Re:Mandatory access control for all! by ewhac · · Score: 5, Insightful

    Well, here's a message for you: [your computer is] shared with all the people who write software for your computer. That's right, software has owners and when their software is on your computer they think they should have a say over how it is controlled.

    They are wrong.

    My home is "shared" with a Nerf arrow launcher, a Sonicare toothbrush, a Panasonic TV set, and a Revere tea kettle (among other things). Neither Nerf, Sonicare, Panasonic, or Revere have the right to enter my home and tell me how I can or can't use these articles. Why? Because they gave up all rights and claims to those articles when they sold them to me.

    Yet, somehow, software vendors have gotten it into their minds that they not only have the right to impose constraints and restrictions on their customers post-sale, they think this is normal, even a positive thing. They are utterly incapable of seeing the yawning inconsistency between what they claim is happening (a "license" to use the software) and what is actually happening (a cash-for-goods sale).

    If we were to presume the software vendors are correct in their beliefs -- if we were to accept that a retail marketplace seller can impose restrictions on a buyer with little more than a shrinkwrap "agreement" -- then lawful innovation becomes impossible. The TV show Junkyard Wars would be illegal, as all the articles in that junkyard would have been obtained under contractual restrictions forbidding their use for anything other than what the vendor deemed proper. Using an old camping tent as a parachute for your rocket would land you in prison, because the vendor only granted permission for it to be used for outdoor camping activities. Likewise, using the Unreal engine as a basis for architectural walk-through simulations would get you carted away.

    Thus, the analogy must be deemed to fail. There is no "sharing" going on here, because the software was sold to end users. Once sold, the end user gets final say over how it's used. Any other interpretation raises caveat emptor to unreasonable levels. I should not have to take Lawrence Lessig with me every time I go shopping at Fry's.

    Besides, the computer industry got plenty vigorous and prosperous without these restrictions. No one has yet presented a convincing argument why that should change.

    Schwab