Slashdot Mirror


Microsoft To Demo 'Palladium' At WinHEC

1010011010 writes "According to Microsoft Watch, Microsoft will be demonstrating Palladium (also known as 'Next-Generation Secure Computing Base') at WinHEC in May in New Orleans. The 'trusted root' is now called the 'Nexus' by Microsoft. Developers wishing to write 'Nexus-aware' applications will apparently have to pay a licensing fee to do so. The product manager for Palladium, Mario Juarez, says, 'It's important to note that nexus-aware applications will not hinder any apps or anything else running in the regular Windows environment.' I'm sure you can all hear the word 'yet' at the end of that sentence. There's talk of phasing in Palladium, starting with Longhorn Server in 2005. I wonder how Microsoft will convince consumers that loss of control is a good thing, and how long the convincing will take. I, for one, am already planning to transition my company away from Microsoft software. Hopefully that won't get messed up by and dumb mandatory-palladium legislation from the Fritz types."

72 of 359 comments (clear)

  1. Did somebody say warez? by shogun · · Score: 5, Funny

    Let me be the first to point out the irony of someone called Juarez being in charge of an anti-piracy system.

    1. Re:Did somebody say warez? by BluRBD!E · · Score: 2, Funny

      Erm...actually juarez is an adaptation used by the "elite" to make fun of ignorant new commers to the warez scene. For example, say I'm "elite" and sitting in a main distribution irc channel and some newbie comes in saying "HEY GUYS! GOT ANY WAREZ!?!?!?!" I may respond with "NAH WE AINT GOT ANY JUAREZ!!!!!!" Or at least something to that effect.

  2. No one can tell you what the Nexus is by burgburgburg · · Score: 4, Funny
    You have to experience it for yourself.

    Oh, and it does the opposite of setting you free.

    1. Re:No one can tell you what the Nexus is by Poeir · · Score: 5, Funny

      If I didn't say this, someone else would.

      Morpheus: I know exactly what you mean. Let me tell you why you're here. You're here because you know something. What you know you can't explain. But you feel it. You've felt it your entire life. That there's something wrong with the world. You don't know what it is, but it's there, like a splinter in your mind driving you mad. It is this feeling that has brought you to me. Do you know what I'm talking about?

      Neo: The Nexus?

      Morpheus: Do you want to know what IT is? The Nexus is everywhere. It is all around us, even now in this very room. You can see it when you look out your window or when you turn on your television. You can feel it when you go to work, when you go to church, when you pay your taxes. It is the world that has been pulled over your eyes to blind you from the truth.

      Neo: What truth?

      Morpheus: That you are a slave, Neo. Like everyone else you were born into bondage, born into a prison that you cannot smell or taste or touch. A prison for your mind. Unfortunately, no one can be told what the Nexus. is. You have to see it for yourself. This is your last chance.

      --
      Sigs are like bumper stickers.
    2. Re:No one can tell you what the Nexus is by kfx · · Score: 3, Funny
      the nexus is happiness - if happiness was like a blanket


      A very thick, very wet blanket... And uncle Bill will tuck you in with plenty of cozy cinderblocks to hold it down...
    3. Re:No one can tell you what the Nexus is by DShard · · Score: 2, Funny

      This blatent disregard of Paramounts copyrights is exactly why everyone NEEDS microsoft to fix computers from enabling us to abuse material, such as the screenplay quoted here. You obviously did not give a second thought of how that careless quoting used to illustrate your point actually dilutes the owners product (ie the screenplay, movie, soundtrack, Jean-luc action figures, your personal DVD collection, LCARS, Whoopie Goldberg, use of the term "Engage", things that have to do with space, bad scripts, and any reference to "Q" including and not limited to "Quit this listing of dribble")

      Further, I hereby copyright this and all derivitive posts, and sanction the Nexus to come and save my interests because my business model is one that disenfranchises me from my customer. My intention is to get everyone who uses my product to hate me because I use the term customer and thief interchangably. Your viewing of this material and not having nexus on your system proves that final point.

  3. How to convince people loss of control is good by speedfreak_5 · · Score: 5, Funny

    "I wonder how Microsoft will convince consumers that loss of control is a good thing, and how long the convincing will take."

    Tell them if they don't they'll be supporting terrorism.

    --
    Why yes I am paranoid! Thanks for asking!
    1. Re:How to convince people loss of control is good by Anonymous Coward · · Score: 5, Funny
      Shopkeeper: Take this computer, but beware: Windows carries a terrible curse.

      Customer: Ooooh, that's bad.

      Shopkeeper: But it comes with a free Media Player!

      Customer: That's good!

      Shopkeeper: The Media Player is also cursed.

      Customer: That's bad.

      Shopkeeper: But you get your choice of a free downloadable movie!

      Customer: That's good!

      Shopkeeper: The movies contain Digital Rights Management technology.

      Customer: [stares]

      Shopkeeper: That's bad.

      Customer: Can I go now?

    2. Re:How to convince people loss of control is good by ReelOddeeo · · Score: 2, Insightful

      "I wonder how Microsoft will convince consumers that loss of control is a good thing, and how long the convincing will take."

      Since when does Microsoft have to convince anyone of anything?

      Joe Fourpack will just buy his Dell with Palladium preinstalled. No convincing required.

      The price is right. It's secure, right? It's from Microsoft, so it must be high quality? It's got shiny graphics, so it must be high quality?

      --

      Those who would give up liberty in exchange for security and DRM should switch to Microsoft Palladium!
  4. Another Microsoft Moment by Taliesan999 · · Score: 5, Funny

    After having bought MS Visual Studio C# .Net, not realising that the "Standard" version doesn't play with non MS databases, I can't wait for the day when my OS/Computer refuses to let me use MySQL via ODBC because the drivers aren't signed/Palladium compatiable. I'll be so happy to be secure and safe from subversive and dangerous open source technolgies.

    1. Re:Another Microsoft Moment by drizuid · · Score: 2, Insightful

      That's a good point, my college gave copies of vistual studio .NET pro to compsci students free (MSDNAA) So I wasn't aware of that problem. For the price you have to pay for either standard or pro, you figure it would at least work as you expect it to.

    2. Re:Another Microsoft Moment by tshak · · Score: 5, Informative

      .NET plays with any database just fine via Native drivers, OLE/DB, or ODBC. AFAIK the issue is that VS.NET doesn't fully support non MSSQL DB's within it's Server Explorer - a feature that I have never found too useful anyway.

      --

      There is no longer anything that can be done with computers that is nontrivial and clearly legal. -- Paul Phillips
    3. Re:Another Microsoft Moment by torre · · Score: 4, Informative
      After having bought MS Visual Studio C# .Net, not realising that the "Standard" version doesn't play with non MS databases, I can't wait for the day when my OS/Computer refuses to let me use MySQL via ODBC because the drivers aren't signed/Palladium compatiable. I'll be so happy to be secure and safe from subversive and dangerous open source technolgies.

      Uh... No. VS.Net only ships with Microsoft data drivers, but there is nothing stopping you from installing mySql server Oracle and any other database that has an ODBC driver (and there's a lot of them so i'm not going to link them all in here!).

    4. Re:Another Microsoft Moment by Taliesan999 · · Score: 2, Informative

      Actually there is, while ycan use an ODBC driver with C# at a programmatic level, the IDE happily tells you that only Access and SQL Server are supported when you attempt to use the IDE's tools to access the datasource, link it with controls etc. This is Visual Studio .Net Standard btw.

  5. damn by lingqi · · Score: 4, Funny

    One day I will boot up WinPalidumb and a ghostly image of Whoppie Goldberg will lure me to this place of pure happiness.

    Of course, being cool as I am I will realize that it's all fake and as harsh as real life^H^Hnux is, that's where we belong...

    And I will bring back William Shatner; possibly saving (enter)price(line)?

    *ducks*

    --

    My life in the land of the rising sun.

  6. Unsure by drizuid · · Score: 3, Interesting

    I think right now, they are so unsure of where they are going with this that the show really doesn't matter. Since the testing began, i've seen rumors of home versions and the like. The final product will most likely dramatically change from what is shown at the show.

    1. Re:Unsure by scott1853 · · Score: 2, Funny

      Let me give you the rundown on the demo.

      1.) Attach scanner
      2.) Wait for BSOD
      3.) Convince everyone that's what its suppose to do now because Windows was able to detect it was an evil scanner sent to cause you enormous grief by not being WHQL certified.

  7. The fees! by alpharoid · · Score: 5, Insightful

    I don't like the part about the fees. Palladium does seem to have one strong point in making its applications hard to exploit (even the badly-written ones).

    So won't this hurt Linux and Open Source software in general? High fees would keep Microsoft's good competitors (Apache, for instance) away from Palladium, and then we'd have all the unbearable boasting about how IIS is more secure.

    That would be a cheap trick... but one to expect.

    1. Re:The fees! by Gortbusters.org · · Score: 4, Interesting

      If anything, I think the fees would drive more people to develop their software on free platforms.

      If you sell a hardware platform with your application, then the cost of the operating system is in your cost of goods and services for producing your app. I think this is one of the major arguments of Linux + Java. Though my disclaimer is that I'm not a product manager ;)

      --
      --------
      Free your mind.
    2. Re:The fees! by NewbieProgrammerMan · · Score: 3, Insightful

      If anything, I think the fees would drive more people to develop their software on free platforms.

      Damn straight. The only reason I haven't dropped Win2k on my main desktop in favor of Linux is that I still develop some software that only runs on Win32 (and I don't feel like being hassled with WINE). It looks to me like Microsoft is going to try and latch onto my wallet just for developing software for their platform, so the incentive to drop all my Windows-specific work is getting pretty significant.

      --
      [b.belong('us') for b in bases if b.owner() == 'you']
    3. Re:The fees! by Billly+Gates · · Score: 2, Insightful

      But your arguements are rational and make sense.

      Bussineses unfortunately like the idea of drm and anti-piracy.

      I can see it now.

      If they only write their programs for Windows they can lay off the mac version team and get rid of piracy all together! They can kill 2 birds with 1 stone. Adobe is even looking at canceling their mac versionsn to cut costs. Lets join palladium! The fee will pay for itself.

      Sigh.

      Palladium was designed for Microsoft and software publishers. Not consumers and the core market will probably eat this up.

    4. Re:The fees! by Jezral · · Score: 3, Interesting

      "If you sell a hardware platform with your application"

      Isn't this exactly what Apple is doing?

      MacOS only runs on Apple hardware (yes yes, I know you can fake it), which can kept it pretty low compared to Windows which works on any x86 platform.

      Now Windows will be locked to hardware as well...

      Is MS pulling another Apple out their sleeves?

      -- Tino Didriksen / ProjectJJ.dk

  8. Nexus?! by C0LDFusion · · Score: 5, Funny

    And when Nexus gets to version 6, will it be physically and emotionally indistinguishable from a human being? Will we have to hire Blade Runners to keep Tyrell Corpo...I mean, Microsoft's crazed creations off earth?

    Nexus v.6: I want more life, fucker.
    Bill Gates: Sorry. Planned obsolescence is a bitch.

    --
    Only in slashdot are posts of solidarity modded at -1 Redundant, while posts of antagonism are modded as -1 Flamebait.
  9. Security by Axel2001 · · Score: 5, Insightful

    While the idea of the technology isn't really all that bad, I question the intent of Microsoft in creating Palladium. If the technology is adapted in its "pure" form, Microsoft will be able to determine what you can and cannot do on your own personal computer - and they will make consumers pay for this "technology." It would be like adding the extra "feature" to an automobile that you can drive only to certain places - and charging more for this "technology." Where can you go today?

    1. Re:Security by enomar · · Score: 3, Insightful

      Working with your analogy, I guess the theory is to provide a car that can't be driven on dangerous bridges. This is surely a good thing, but like you say, MS should not be the one deciding what bridges are bad, especially when they require a fee to evaluate your bridge.

      Couldn't the decision be based on a non-biased group or even a public voting system? What is stopping the OSS community from writing their own version of paladium? I guess there might be some hardware issues to iron out, but I'm no expert...

      --

      :wq
    2. Re:Security by ftobin · · Score: 4, Funny

      Where can you go today?

      Freedom is slavery.

  10. people love "security"... a bit too much... by gasgesgos · · Score: 4, Insightful

    I wonder how Microsoft will convince consumers that loss of control is a good thing, and how long the convincing will take


    The government's already convinced people that loss of control in the name of "fighting evil" is wonderful, and that it should be accepted openly.

    Hopefully people don't follow suit with Palladium, or pretty soon, the government will see that regulation of a person's own computer can be done easily and effectively.

    solution: we all start using Linux (or in some cases, use Linux more) and move to Canada (or in some cases, stay there)





    note: entire solution does not apply outside of US or Canada, your mileage may vary, see dealer for details, sweepstakes ends 11/05/72. Linux portion of solution applies to all humans, again, see dealer for details.

  11. 2005 by Unregistered · · Score: 3, Insightful

    That gives us about 2 yrs to get linux ready to take over. Can we? Because if not, it will be vary bad. This is our chance. Once people are tied into palladium, they're stuck.

  12. Surreal by mao+che+minh · · Score: 4, Interesting
    It is surreal how easily Microsoft is able to employ such blatant and souless cash grabs without sounding off alarms in the business sector. Microsoft is free to employ monopoly induced moves into various markets, orchestrate forced upgrade procedures, raise prices while limiting support, and engineer horrible licensing schemes without any fear of fall out.

    Now MS can candidly tell consumers how they intend on outright controlling all of your data and even charge developers for the "privilage" of being able to conform.

    I just can't see how so many pointy-hairs can examine Microsoft and it's products and decide that it would a good idea to spend so much money on it. Microsoft sales people are truly adept at their trade.

    1. Re:Surreal by Dr.+Bent · · Score: 2, Insightful
      Microsoft sales people are truly adept at their trade.

      That's exactly the point. Microsoft is a company based on marketing, not engineering. That's why they almost always hire new college grads as programmers...anyone with any actual development experience would see right through all the marketing hype and realize how much thier products suck.

      Actually, I would argue that Sun has the exact opposite problem. Love it or hate it, Java has made a huge impact on the software industry, but Sun has been thus far unable to greatly profit from it because they're all engineering and no marketing. If Sun recruited some of those evil, undead marketing gurus over at Microsoft, they could make a killing. If Microsoft hired some lab-rat engineers over at Sun (and actually gave them some resources), they might actually be able to deliver on 1/10 of the shit they promise....

  13. why doesn't everyone.... by UniverseIsADoughnut · · Score: 3, Insightful

    ... Just sit back and wait and see what MS does. If you just take it for what it says now there isn't much of anything to go nuts over. Yes maybe something will come up that makes it Evil, though with something like this what one considers evil others consider good. If It turns out to be just as MS says it is going to be, what do you have to fear? You don't like the paying? sure that might not be so great, but then again this is most likely going to apply to major windows apps. You know the kind written by companies that people go out and buy. So adding a few cents to the price won't matter to anyone. I don't think anyone is going to go and pay to have there Hello World app 'Next-Generation Secure Computing Base' certified.

    If your afraid of how it works or don't like it don't use it, don't use windows. With just what MS has said most all of what people go on about has no bases and is just stuff from tin foil hat people. Yes MS has done bad things. Maybe they will with this. But give them a chance with it, let them screw up before you chastise them.

    1. Re:why doesn't everyone.... by mao+che+minh · · Score: 5, Insightful
      Why doesn't everyone just sit back and wait and see what MS does?

      Because we already know what Microsoft will do: employ whatever tactics neccassary to insure their continued monopoly status and success - even if it means eliminating the private ownership of data as we know it. The rabid MS bashing going on isn't a sign of premature paranoia, rather, it is the natural reaction of those that have studied the company's history.

    2. Re:why doesn't everyone.... by ATMAvatar · · Score: 4, Insightful

      But give them a chance with it, let them screw up before you chastise them.

      Given one of the features in Palladium is supposed to allow for remote deletion of files by Microsoft, I'll have to decline giving them the chance to screw up. I see 2 major problems with this:

      1. I don't trust Microsoft with this power. Should I run software Microsoft doesn't like, what's to stop it from deleting the software?

      2. With Microsoft's famous security in software, coupled with this new feature, how long do you think it will take for a person to crack into a Microsoft server and issue commands to thousands of computers to delete files? Palladium may be designed to only run trusted programs to issue these commands, but I can't imagine gaining trusted access being much more difficult than grabbing administrater or root privledges on a machine.

      Sure, you could set up your firewall to block the remote deletion commands, if you know what port it's using. I have philosophical issues with using firewalls to protect myself from the programs running on my computer, as opposed to protecting myself from outside threats, though. I'd much prefer not putting Palladium on my system. The risk is much too great, especially if I were to screw up configuring things to block this "feature"(and I'm hardly a good sysadmin).

      --
      "They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety."
  14. Hmm by ATMAvatar · · Score: 2, Interesting

    Developers wishing to write 'Nexus-aware' applications will apparently have to pay a licensing fee to do so.

    And, I suppose it will only be a matter of time before Palladium dictates that only Nexus-aware programs will run. Nice business model.

    --
    "They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety."
  15. Mandatory access control for all! by QuantumG · · Score: 2, Flamebait
    wow, this is the second post on Slashdot today where I'm mentioned mandatory access control. For those not in the know, consider a mainframe computer in a military installation. Clearly it makes no sense to go about classifying documents as "Restricted", "Secret" and "Top Secret" if the people with the clearance to read those documents have the discressional control to go and reclassify them at some lower level. The shared computer's operating system has the job of making sure only those who are authorized can access these documents.

    Microsoft is taking the control out of users hands for just the same reason (and for anyone in denial, try to log in as "Administrator" on a WinXP machine). It wouldn't make sense for anyone to be able to bypass the mandatory access controls on a military mainframe, and if they can they have to be very very trusted.

    I hear you out there! Screaming that your home computer isn't a shared, let alone military, machine. Well, here's a message for you: it's shared with all the people who write software for your computer. That's right, software has owners and when their software is on your computer they think they should have a say over how it is controlled. For better or worse, your choice to share your computer with the owners of this software is what is driving this effort.

    Not that sharing is bad. It makes sense to share. You have the choice of who you share your computer with. I've chosen to share my computer with people who have similar views to me on what is a fair. These people write software that they license under so called "liberal" licenses -- the GPL and the BSD licenses for starters.

    --
    How we know is more important than what we know.
    1. Re:Mandatory access control for all! by ewhac · · Score: 5, Insightful

      Well, here's a message for you: [your computer is] shared with all the people who write software for your computer. That's right, software has owners and when their software is on your computer they think they should have a say over how it is controlled.

      They are wrong.

      My home is "shared" with a Nerf arrow launcher, a Sonicare toothbrush, a Panasonic TV set, and a Revere tea kettle (among other things). Neither Nerf, Sonicare, Panasonic, or Revere have the right to enter my home and tell me how I can or can't use these articles. Why? Because they gave up all rights and claims to those articles when they sold them to me.

      Yet, somehow, software vendors have gotten it into their minds that they not only have the right to impose constraints and restrictions on their customers post-sale, they think this is normal, even a positive thing. They are utterly incapable of seeing the yawning inconsistency between what they claim is happening (a "license" to use the software) and what is actually happening (a cash-for-goods sale).

      If we were to presume the software vendors are correct in their beliefs -- if we were to accept that a retail marketplace seller can impose restrictions on a buyer with little more than a shrinkwrap "agreement" -- then lawful innovation becomes impossible. The TV show Junkyard Wars would be illegal, as all the articles in that junkyard would have been obtained under contractual restrictions forbidding their use for anything other than what the vendor deemed proper. Using an old camping tent as a parachute for your rocket would land you in prison, because the vendor only granted permission for it to be used for outdoor camping activities. Likewise, using the Unreal engine as a basis for architectural walk-through simulations would get you carted away.

      Thus, the analogy must be deemed to fail. There is no "sharing" going on here, because the software was sold to end users. Once sold, the end user gets final say over how it's used. Any other interpretation raises caveat emptor to unreasonable levels. I should not have to take Lawrence Lessig with me every time I go shopping at Fry's.

      Besides, the computer industry got plenty vigorous and prosperous without these restrictions. No one has yet presented a convincing argument why that should change.

      Schwab

  16. What i want to know by Anonymous Coward · · Score: 2, Funny

    This seems to me like pretty clear trademark dilution of the Lexus-Nexus trademark. I don't know what "Lexus-Nexus" means, but i know it's what comes to mind when someone says "Nexus-aware."

    Anyone agree or disagree on that?

  17. Re:Microsoft To Demo 'Palladium' At WinHEC?? by Anonymous Coward · · Score: 5, Funny

    This reminds me of the time MS decided to demo Win98... I think the conversation went something like:

    demo guy: Well, Bill. You just hook up the scanner and Windows will automatically find and install the drivers for it.

    Bill: That's great!

    demo guy: Yes. It is one of the great features of Windo- Oh, boy. That's not supposed to happen.

    *BSOD appears on a 3 story screen*

    *audience laughs*

    */me shudders after thoughts of the future run through my head*

    I can see it now...

    demo guy: You plug in your printer and WindowsPA automagically detects it and installs the printer drivers.

    Bill: That's great!

    demo guy: Yes. It is one of the great features of Win- Oh, boy. That's not supposed to happen...

    *BSOD fills 3 story screen*

    BSOD: All you data are belong to Microsoft.

    *Audience laughs*

    */me laughs becasue /me is using Gentoo Linux!*

  18. Re:About now... by JebusIsLord · · Score: 3, Interesting

    Okay, I'll bite. IN THEORY, that is in a perfect world, the idea of programs/documents needing authentication is a good idea. It would be great for administering desktops in an office environment for example. That is if I (as the admin) get to control the authentication server. IN PRACTICE, i see this as a move towards a closed development model (not as in closed-source, as in closed dev like consoles for instance where everyone needs to go through nintendo/sony/MS to publish software) where MS controls access. I could be wrong though, and the idea that we could finally stop idiot employees/customers etc from installing gator or emailing out confidential information by mistake is a nice one.

    --
    Jeremy
  19. In the tradition offollowing with the "leader".... by Mattygfunk1 · · Score: 4, Funny
    ... I am arranging a group on SourceForge to bring "trusted computing" to linux!

    One of our developers has already approached RMS but apparently he mumbled something about "GNU/trusted computing" before the developer hung up the phone.

    ________
    Open source hosting @ $3 / Month - Cheap Web Site Hosting

  20. Wait a sec.... by dethl · · Score: 2, Interesting

    Shouldn't this story be in the "Your Rights Online" page? Considering that clicking on Pallidum's EULA will be just like signing your soul over to the devil....I'll take an open source solution thank you very much.

    --
    "Some fight for law. Some fight for justice. What will you fight for? One day, you will see."
  21. Missed the Point. by torre · · Score: 4, Insightful

    The poster has missed the point and has confused two seperate issues into one. (DMR and machine security). If the poster had actually read the microsoft link from his own link he would have come up with the following quote"

    " "Palladium" will not require digital rights management technology, and DRM will not require "Palladium." "

    DMR is not the focus of Palladium (at least intially.... I say this with a grain of salt as you never know what they future will hold), but rather a seperate microsoft initiative spearheaded by the windowsmedia group and the Office group. I would be far more concerned about what these groups do than what Microsoft has outlined for Palladium.

    Palladium is (or at least what is hoped, again i say this with a grain of salt, we'll only really know once the deliverables are shown) a combination of two big ideas. The first is to provide a system in which a user can trust stuff and allow it to run with sensitive information (eg, user data) and provide a sandbox where they can run stuff that they don't trust and know it won't do anything of consequence.

    The second is to bring the PC hardware/Software to a more sofistated level, bringing up the bar as it would to what is now held by some of the mainframes. This serves two fold a purpose, one to weed out old hardware and hardware manufacturers that people keep using over and over that perhaps just don't have proper drivers which haul down the machine. Secondly, give greater credibility to the Wintel platform in all they're little political/business/OSS/User heart battles. At the end of the day, any time a user/admin/whomever sees something not function correctly (eg, system crash, failed performance of hardware eg... scanner won't scan) the first impulse is to blame Windows reguardless what caused the problem. I'm all for the improvement of the overall improvement of windows as any system that is improved makes a cost saving in both time and money at the end of the day.

    There has been much speculation as to what Pallium will actually be. Most of it has been nonsense runned off by people with FUD as they're agenda. Little is known about what exactly will Pallium eventually encompase.... But what I do know is this. If it turns out that user restrictions are placed and people suddenly stop beind able to do certain things... then Microsoft will get a hit to they're bottom line and OS's like Linux and Mac OSX will suddenly have a massive inflow.

    Give the public a little credit... The market doesn't have an absolute hold on them and if windows doesn't suit they're needs they'll jump off as though the ship is on fire. It's not like there aren't other capable alternatives. If there wasn't windows would have been regulated long time ago just like the telcos. But do you really think microsoft would alient people that much (or abolish competition for that matter) to be able to hurt themselves? I think not.

    1. Re:Missed the Point. by SiliconEntity · · Score: 2, Interesting

      No offense bud, but take some care with your typing, okay? Between "Pallium" and "DMR" it's hard to figure out what you're saying.

      And while you're right that Palladium is not the same as DRM, I've heard Manferdelli (the Microsoft manager) talk, and he very frankly admitted that the original motivation for the project was to support DRM. Then they realized they could generalize it and do a lot more with it.

      I also disagree that Palladium provides a sandbox. Palladium applications can still be pretty damaging. They can delete all your files, or whatever, just like apps today. What Palladium does allow is that an application can encrypt its data and be confident that no one else can decrypt it. So you do gain a certain amount of security in that way. Palladium-aware apps can protect themselves in ways that old-style programs cannot. But there's no sandbox per se.

      Your final point is right, if Microsoft really did turn this into the fascist nightmare that people are describing, they'd lose market share like crazy. Nobody is that committed to Microsoft. The fact is, Microsoft is petrified of losing customers - that's the only way they've managed to stay on top. They'll do anything, anything, to increase market share.

      The whole point of Palladium is to try to find a compromise between the requirements of the media companies to allow PCs to be used to download movies and such, and the demands of end users to have control over their computers. Technically, Palladium achieves this - where users give up control, it is done voluntarily and in exchange for being allowed to download legal multimedia content. But that hasn't quelled the FUD.

    2. Re:Missed the Point. by Anonymous Coward · · Score: 3, Interesting

      The first is to provide a system in which a user can trust stuff and allow it to run with sensitive information (eg, user data) and provide a sandbox where they can run stuff that they don't trust and know it won't do anything of consequence.

      That doesn't require hardware support. You can already do this in multi-user systems (including WinNT/XP/2K) by creating a new unprivileged user and executing code as that user. If every user could create sub-users with limited privileges, the system would be protected from untrusted code (capability-based operating systems basically have this feature built in, but they're not popular yet). Java and .Net can do this too (running untrusted code in a sandbox). And I've seen an option in the WinXP "Run as a different user" dialog, something like "run as this user, but prevent the program from executing harmful code" (although there's no explanation about what this actually does).

      This serves two fold a purpose, one to weed out old hardware and hardware manufacturers that people keep using over and over that perhaps just don't have proper drivers which haul down the machine

      Windows already has support for signed drivers to prevent this exact situation. Microsoft has a compatibility lab which will test and certify drivers, to make sure they won't bring down the machine (among other things).

      Secondly, give greater credibility to the Wintel platform in all they're little political/business/OSS/User heart battles. At the end of the day, any time a user/admin/whomever sees something not function correctly (eg, system crash, failed performance of hardware eg... scanner won't scan) the first impulse is to blame Windows reguardless what caused the problem.

      This doesn't make much sense. Windows already has driver signing, and the driver name is displayed (or logged) when it crashes. But it doesn't really matter - most users will blame all their computer problems on Windows, Microsoft, or the computer itself. And the majority of users won't know what Palladium is (even if their computer supports it), or why this should stop them from blaming their problems on Windows.

    3. Re:Missed the Point. by torre · · Score: 3, Interesting
      No offence taken.... I should have run it through a spell checker before submitting... and for that I should be apologizing to the slashdot at large for having to read my obvious spelling mistakes!

      However, I think I need to clarify my points, as I was making broad claims and you've picked up at least one that needs clarification.
      I also disagree that Palladium provides a sandbox. Palladium applications can still be pretty damaging. They can delete all your files, or whatever, just like apps today. What Palladium does allow is that an application can encrypt its data and be confident that no one else can decrypt it. So you do gain a certain amount of security in that way. Palladium-aware apps can protect themselves in ways that old-style programs cannot. But there's no sandbox per se.

      By sandbox I mean that non trusted code work under regular windows with presumably tighter restrictions (providing the default sandbox) and trusted code run in a freer app space. I do realize that a trusted app would have full control over its space ultimately have potential to create damage This ultimately then begs the question can you really trust a trusted app? On its defence (slightly), anyone willing to pay a license fee to become certified *should be* more trustworthy than some virus writer as they've got to cough up some cash make themselves apear secure!

      I admit my def is not a true sandbox and a poor term to describe what I meant. But if that's not what is delivered (or at least some other variant that has obvious measures of secure/insecure code execution then the end users just won't get it) then they're not going to be any major credibility in the short run as to the whole push.

      And while you're right that Palladium is not the same as DRM, I've heard Manferdelli (the Microsoft manager) talk, and he very frankly admitted that the original motivation for the project was to support DRM. Then they realized they could generalize it and do a lot more with it.

      Now, I totally agree with you.... Palladium is a totally different beast then what was initially announced. Goes to show that the consumer still has some power over big companies and not the other way around. However, I must point out that in the end it doesn't matter what was the original idea was, it's what delivered that counts. Simple example, Microsoft was going to release the next generation help system having spent over 1/2 billion into the project. It was going to revolutionize how help is provided. It got canned. Bits and pieces of it pop up in office in the form of SmartTags and other things.. Apple also had a similar thing going before that... OpenDoc if I'm not mistaken.... got canned. An on the subject on failures, remember Microsoft Bob? It was suppose to revolutionize computers to beginners... that got canned after lack of consumer interest.

      My long winded point (and I apologise for that) is that Microsoft can say what they want when they want it about it, but the reality is they won't release something that's going to hurt them (well much). Case in point, windows media even with it's DRM is relatively popular (cough even though it has divx to help with some of those numbers). And God knows why they're IM is so popular but they've capitalized on it and are making a "hip" integrated add-on (3 degrees) for it.

      Anyhow.... The best policy when speaking about Palladium is to wait and see.... We really don't know the particulars which only lead to more speculation. A charge that can be directly aimed at Microsoft for leaving it so vague at times leaving ramped speculation impossible to avoid.

      Btw... I hope my response is a tad better.... I'm working late and such my writing skills are simply not there right now...

  22. Good Thing by IchBinEinPenguin · · Score: 3, Interesting

    I wonder how Microsoft will convince consumers that loss of control is a good thing, and how long the convincing will take.

    I must have forgotten when they convinced me that Clippy was a Good Thing before forcing^H^H^H^H^H^H^Hintroducing it.

    Seriously, do you really think they're going to even try to convince us? What's the point of having a monopoly if you can't (ab)use it?

  23. how will this protect from viruses ? by wotevah · · Score: 4, Interesting
    I am just wondering how signing all the executables will protect anyone from viruses. Most viruses today are macro or scripted.

    It's worth nothing that the behemoth apps (Outlook, Word, Excel etc) are signed, they will probably keep their embedded superscripting features, so viruses will still happily run on them.

    I am curious about buffer overflows. Stack checks are not infallible, code is not read-only and and I can't imagine the palladium system checking the signature for each 4k block as it runs (since if decent encryption is used it will be quite expensive in CPU time). So, will we have signed apps that might still have such bugs ?

    1. Re:how will this protect from viruses ? by torre · · Score: 4, Informative
      am just wondering how signing all the executables will protect anyone from viruses. Most viruses today are macro or scripted. It's worth nothing that the behemoth apps (Outlook, Word, Excel etc) are signed, they will probably keep their embedded superscripting features, so viruses will still happily run on them.

      Simple... suddenly secure Office apps will use .Net which runs the macros in a sandbox outside the secure zone. It has been on the drawing box for quite some time. Office 2003 will offer the first steps to .Net integration wich will ultimately add more security and control over these dumb macro exploits.

      But the more obvious step would be to prohit you from manually launching such a script in the first place. Which is a step up. I've personally witnessed Computer Science Master and PHD students who should know better open up arbitrary code sent to them via email. Goes to show that sometimes even the knowledgeful are just as dumb as the users they often mock.

    2. Re:how will this protect from viruses ? by SiliconEntity · · Score: 3, Informative

      I am just wondering how signing all the executables will protect anyone from viruses. Most viruses today are macro or scripted.

      First, Palladium doesn't sign all the executables. As the article takes pains to mention, all the old Windows programs will still run. What Palladium does provide is "attestation", meaning that the secure hardware can report a hash of the secure part of the application to a remote server. That server can then decide based on the hash whether to trust the app.

      As far as viruses, I think you're right that macro viruses wouldn't be stopped. The one advantage is that the scope of the damage might be limited, as any "sensitive" data on your computer could be encrypted using the Palladium hardware. So you could still get an email virus, but it couldn't access your bank account data.

  24. Re:Big Brother is Watching..... by vvikram · · Score: 3, Funny


    I dont have anything to hide....

    except probably your username?:)

  25. Re:About now... by 3141 · · Score: 2, Interesting

    I agree with your fears, but even your best-case scenario sounds like a pain for perhaps 70% of computer users.

    The risks far outweigh the benefits from a company that has shown itself repeatedly to be untrustworthy.

    The comment about preventing employees installing software is misleading. NTFS and Unix permissions can prevent this (though it's tricky to get the balance on NTFS if people actually have to use the computer for more than a few specific tasks. I have been called out several times to fix people's new XP systems that will only run programs as the Administrator. Ironically enough, Microsoft games seem to be the worst offenders.

    Regarding emailing out confidential information - that's a total red herring. If people have the ability to send email without physical human monitoring, the best you can have is a keyword search. Palladium would do nothing to prevent people leaking information, unless it was by preventing them installing an email client (which again is something that can be handled by permissions.)

  26. thoughts.. by Dave_bsr · · Score: 4, Insightful

    The first thing i thought was: "So, it starts."

    Then I read some comments. You gotta pay to write software for windows. What crap! They have the desktop computer section by the balls, and they keep squeezing for more money.

    But the more they squeeze, the more people get sick and leave. So in part, I welcome this. Maybe a few more people will get the idea and switch to something freer....something that ends with "ix" ... It keeps getting better all the time.

    --


    Who is this Anonymous Coward character, how does he post so much, and why is he always such a whore?
  27. Wish this was a joke... by inkswamp · · Score: 3, Funny

    I wonder how Microsoft will convince consumers that loss of control is a good thing, and how long the convincing will take.

    Oh that's easy! All you have to do is convince everyone that having control over your computer just helps terrorists.

    Sigh. Now if only I were kidding.

    --
    --Rick "If it isn't broken, take it apart and find out why."
  28. Here's how - by FFtrDale · · Score: 4, Insightful
    They've been doing it for years. Neal Stephenson said it best in In the Beginning Was the Command Line":
    Buyer: "Can't you see that everyone is buying station wagons?"
    One place to find it is http://bang.dhs.org/be/beginning.html

    There are several other places to find it; I just googled it again. And get a dead-tree version for your Dad, too (that's where mine went).

    --
    Think, write, think, edit, think...then post.
  29. Palladium... by StriderA · · Score: 2, Funny

    Anyone else see this story title and immediatly think of a giant Palladium RPG session inside microsoft? Who knows, maybe it's just me. :)

    --
    "When will this FP stuff stop?" "After the great growing..." "The great growing?" "Yea, when people grow up."
  30. I can see both sides of the DRM war by zapp · · Score: 3, Interesting

    While I love my mp3s, downloading free images, music videos, tv shows, even copying a DVD to divx here and there ;) ... I can see both sides to the conflict.

    I was always one of the people saying the Internet would revolutionize the world... that Information should be free, etc etc. And that's what it comes down to... the real world is based on selling goods, trading services, etc. These goods and services are of limited quantity, so they have value. Media on the Internet can be copied infinitelly, and thus has no value.

    I am stepping out on a limb here, but is it possible the dot.com boom of the late 90's failed because of people trying to charge for things that were inherently worthless? What if your wallpapers.com website sold quality wallpaper images, but that were signed and could only be used by the person who bought it. (think: When I buy a painting to put on my wall, I can't send a copy to all my friends for free, can I? Isn't it the _same thing_??)

    So there's the problem. Do you want the benefits of a media-rich world, where people can actually make MONEY, and succeed, and continue? How many GOOD sites have shut down because of lack of revenue?

    Would it be worth it, if it were properly implemented and restricted, to put such a system in place to give the internet an actual economy?

    --
    no comment
  31. Those where the days... by sokkelih · · Score: 2, Funny

    Why dont you people bash Microsoft anymore? It used to be so much fun.=)

  32. Speaking of mispronounciations... by Randolpho · · Score: 2, Funny

    ... am I the only one who sees "WinHEC" and reads it as "WineHQ"?

    'Cause I really did. I was all "What? Microsoft is embracing Wine? No wh-hay!" ;-)

    --
    "Times have not become more violent. They have just become more televised."
    -Marilyn Manson
  33. I was thinking by Comster · · Score: 2, Interesting

    ...that similar to the Xbox, which I hear is a sort of initial version of the Palladium/hardware security that we will be seeing... What will happen if this huge target does get cracked? Would it make it even more vulnerable than a target that is expected to be broken into every once in a while?

  34. hm why? by Richard_at_work · · Score: 2, Insightful

    , for one, am already planning to transition my company away from Microsoft software

    But this sort of thing is brilliant for companies, as it cuts down on the damage a employee can do on their PC. It also restricts what data a sour employee can walk out of your company with.

    I for one would like to be able to see a OpenSource application that works like a central repository and customises documents via steganograpghy whenever an employee checks out a sensative document. Then leaks can be tracked down to who checked the document out, and investigations proceed from there.

  35. Yoink by Renraku · · Score: 2, Funny

    In a press release addressed to the world from Bill Gates... "Hello citizens of the world. I would just like to congratulate all the owners of our Palladium-enabled operating system! You won't have to worry about viruses -- they won't run on your system. You won't have to worry about those nasty games such as Anarchy Online or Doom 3, either. We are only going to allow our operating system to run our software. Some of you have asked about the exclusion of 'Minesweeper' from this version of Windows. To be blunt, Minesweeper takes so much time and effort to produce, that we've decided to sell it as a separate product. That will be another $500, per computer, per user. That covers one year worth of updates. It will also require a CD-key and server verification! Once again, I'd like to thank the U.S. Government for helping us out, and you the people for voting with your dollars. Its clear that all the software manufacturers EXCEPT for Microsoft haven't lived up to your standards, so you'll never have to deal with them again!"

    --
    Job? I don't have time to get a job! Who will sit around and bitch about being broke and unemployed then?
  36. Re:Microsoft To Demo 'Palladium' At WinHEC?? by Zakabog · · Score: 2, Interesting

    Sad thing is, they laugh because BSOD's happen all the time. If they never happened they would look at the BSOD thinking "What's that? Never saw that before." but instead they laugh thinking "Hah I get like 3 of those a day it's so funny." Why do people think it's normal for a computer to crash every day? Then they go out and spend like $1,000 at best buy upgrading 2 things because their 1.5 ghz computer is too slow (which explains the crashing, of course...) and they needed a 3 GHz P4. And when that fails to fix any problems I get a phone call at around 9AM asking me to fix the computer :-/

  37. How'bout them Apples? by mrklin · · Score: 2, Insightful
    > I wonder how Microsoft will convince consumers that loss of control is a good thing.

    Apple did it and it has only 5% of the market. Let that be a lesson.

    (Disclaimer: Well, not really considering I have swtiched may laptop to an iBook and am loving the BSD-based little thing.)

  38. Can you say "Na�ve"? by nmg196 · · Score: 2, Insightful

    I love the way that everyone is just flaming Microsoft, without any knowledge at all of what Palladium is or what the Nexus is or what the implications are of the system. I'm glad I'm not an open source sheep...

    Nick...

  39. Same Sh*t, Different Hardware by ahodgkinson · · Score: 2, Insightful

    IBM and Intel, and a few other hardware manufacturers, probably with support from Microsoft, tried something similar back in 2000.

    Then it was called Content Protection for Recordable Media (CPRM). This was hardware based system that encrypted the data on hard disks. The idea was that they would sell hard disks with hardware based encryption and key management. The goal was to provide a platform for DRM. One description can be found at The Register.

    There was a lot of noise in the press for a couple of months after the announcements as the public opposition was voiced. Then the initiative quietly died.

    It's not surprising that CPRM dissapeared, since no one could force you to use CRPM based hardware. Why would customers go out and upgrade/replace their perfectly good hard disks with something that imposes (to the ordinary user) complex and difficult to understand restrictions? Particularly when when normal unrestricted hard disks would still to be available.

    I suspect (and hope) that Palladium will suffer a similar fate. Most people resist forced upgrades. Over the years, Microsoft has tarnished its reputation by continualy forcing users to upgrade. As the Windows cost/ownership hassle has increased, the minority of non-upgraders has grown and now includes even a few major corporations. Worse, it's also caused some previously loyal customers to switch to Unix and Linux.

    With Palladium, the upgrade will require a new Palladium enabled PC, not just more memory and a faster CPU. This, combined with the restrictions, will make people even more reluctant. If Microsoft actually forces the upgrade, say by discontinuing support and sales of previous Windows versions, they risk a customer revolt. Microsoft realizes this (as evidenced by the recent Palladium name changes and smoke and mirrors announcements) and is treading cautiously.

    • Note: I wonder if the real motive is to stop piracy of MS Office. Microsoft have managed to get most of the world hooked on Office and if they could get all the pirate copy owners to pay up, they'd have a pretty nice revenue stream.

    My personal belief is that DRM is an unreachable utopia. It only takes one person to crack an instance of DRM protected media or indeed the DRM system itself. Once this has happened, then there's nothing anyone can do, technically or legally, to stop distribution of the unprotected digital content. Given the financial incentives there are plenty of clever minds willing to devote a lot of energy to cracking DRM systems. I'm not saying this is legal/moral, I'm just pointing out that it's inevitable that DRM systems will be attacked.

    In the end, forcing copy protection schemes on users doesn't solve the problem and just ends up annoying the users. Examples of failed DRM are all around us: DVD's, Adobe's e-books, etc. Remember 'dongles'? They failed too. As Bruce Schneier says, encryption doesn't stop anyone, it only slows them down.

    Alan Hodgkinson

    --
    ---- It won't be as bad as you fear or as good as you hope, but it will take twice as long as you plan.
  40. Palladium and anti-virus by sheriff_p · · Score: 2, Informative

    I wrote what I consider to be a fairly informative article on Palladium and the impact on the anti-virus industry here:

    http://www.virusbtn.com/magazine/archives/200209/p alladium.xml

    Summary:

    - It's foolish to expect it'll stop viruses
    - Microsoft will have the anti-virus industry by the short and curlies
    - Microsoft PR is impressively ... uh ... PR-ish ;-)

    --
    Score:-1, Funny
  41. "I wonder how Microsoft will convince..." by Joey7F · · Score: 2, Funny

    "I wonder how Microsoft will convince consumers that loss of control is a good thing, and how long the convincing will take. "

    Not long. A glimpse from the future...

    Microsoft Windows XP2 makes your favorite operating system even more user friendly.

    Tired of viruses, spyware, and popup ads that aren't from Microsoft? So are we, so XP2 utilizes a brand new technology called Palladium. You can now be confident that only Microsoft tested, and approved programs can run on your computer.

    Security is a good thing (TM)

    Back to the present...

    --Joey

  42. Darn! by turgid · · Score: 2, Funny

    I darn you to WinHEC, a Fate Worse than Death!

  43. Fritz types? by _pruegel_ · · Score: 2, Informative

    Yeah, I know, OT but English is not my mother tongue. I thought, Fritz was some reference to the Germans but this does not really make sense here, does it? What does "Fritz types" mean?

  44. BSOD Frequency by Latent+Heat · · Score: 2, Interesting
    The BSOD problem is usually in the application inasmuch as Windows doesn't just die on its own. An application makes a call on a NULL object pointer inside a thread . . . and well, you get the idea. I know, I run apps like this -- my own, when they are being debugged. Of course one has the darndest time fixing such a bug because the program always crashes inside one or another Windows call where a debugger or trace statements do not go, and if you do this enough times, Windows BSOD's.

    I run Windows 98 for weeks on end (Web surfing, compiling programs, testing compiled programs) with hardly a BSOD, and when I do get BSOD's they are mostly attributable to something I did to an application during development, which I can track down with a lot of gnashing of teeth.

    If you are BSODing 3 times a day, it is some or another software you are running. Yeah, yeah, it is Windows' fault because there is very little defensive programming (validation of parameters of API calls) inside Windows, but it has to be some application that is doing it.

    1. Re:BSOD Frequency by Ivan+Raikov · · Score: 2, Funny

      If you are BSODing 3 times a day, it is some or another software you are running.

      That's the problem right there, running an application, even a small one. I have found Windows to be extremely stable if you simply don't mess with it by running applications. But users insist on doing just that, poking and prodding, clicking and dragging, making demands on the OS, and then they're surprised when the thing crashes and blame Microsoft. Same thing with viruses, users running things, and clicking on things, and displaying things with executable content, busy, busy, busy subverting the function of what is otherwise a very stable operating system.

  45. MS will ace this demo. by MongooseCN · · Score: 2, Funny

    The goal of Palladium is to prevent users from running certain software on their system, and as we all know MS Operating Systems are great at preventing things from running.

    Is Palladium suppose to carry over to things off the computer? Because I know many businesses that wouldn't run if they used Windows.