DRM Based on Trusted Computing Chips
An anonymous reader writes "We've always know that Trusted Computing is really about DRM, but computer makers always denied it. Now that their Trusted Computing chips are standard on most new PCs, they've decided to come clean. According to Information Week, Lenovo has demonstrated a Thinkpad with built-in Microsoft and Adobe DRM that uses a Trusted Computing chip with a fingerprint sensor. Even worse: 'The system is also aimed at tracking who reads a document and when, because the chip can report back every access attempt. If you access the file, your fingerprint is recorded.'"
I want one !!!!!!!!
Oh, come on. Drop the bias. This is technology aimed towards businesses. People who have truly sensitive information and need to be able to track who sees it. It's not targetted at warez-kiddies, movie downloaders or porn magnets. Sure, it will be used in that capacity sooner or later, but the hardware manufacturers are responding to a perceived customer requirement.
This and the plan to put a camera in every house...
What next?
I would sell my soul for total control over you. Or something like that. What has come of the world that corporate greed has taken over from the free harmonious society? I would love to say everyone will just scrap computers and move onto other ventures (like going outside) but that is the Utopian view. In reality the Orwellian scenario us coming upon us. It won't be long now people.
What is sad about this is they are touting the "legitimite" uses of making sure software is unmodified and doesn't contain root kits and protecting sensitive data from attackers. I find it funny that SHA1SUM and gpg --checksig tells me when my download isn't what the author intended. Cryptoloop (and a tonne of other software) keeps my files highly secure and safe from prying eyes even if they do steal my disks.
There are no legitimite uses for this technology that can't already be accomplished today. There are only evil uses!
I drink to make other people interesting!
In Soviet Russia, the documents report back when you read them! Oh, wait...
Tell your friends about xenu.net
You can find a list of known Trusted Platform Module (TPM) manufacturers and implementations from the TPM Matrix
The CB App. What's your 20?
A while back processor serial numbers were added as a feature but I've yet to see a system where the ability to read the it was enabled. Trusted Computing is potentially 100x more intrusive so I don't think it's going far in cases where the user is the one who decides what system to purchase.
Is it just me, or is anyone else thinking, "The way the industry is going towards Orwellian dystopian dreams, I might just want to get out of computing"?
~/ssh slashdot.org ssh: connect to host slashdot.org port 22: too many beers
Ultimately I think a lot of this DRM technology - specifically remote attestation - is going to result in me changing my habits in one minor regard - I'll be putting the wireless router on top of my desk, rather than under, with the ports facing me so I can easily unplug my computer. In the majority of cases, problem solved.
--Ryvar
He warned us long ago. Of course, even now the masses will fail to be alarmed. "It's only a demo." Etc. "Boil 'em slow, they'll never know." Oh well.
How would this sort of thing affect something like VMWare? If the O/S needs to be booted up on a trusted platform surely you won't be able to install it on a virtual machine. If the virtual machine can fool the O/S into thinking it's running on a trusted platform, doesn't that mean that you can get around the trusted component?
Trust goes both ways. Software and hardware industry now keep treating software and hardware for consumers as if it's a privilage to buy, and assumes that none of customers can be trusted as owners of a product.
I'm just disgusted that companies are putting on a smile and trying to gain consumers' "trust," yet none trusts consumers. However when consumers do not trust companies by removing DRM, consumers quickly become criminals, and are called pirates and thieves. While companies abuse the consumers' trust and play market share or monopoly or pricing/licensing games, companies are just looking out for the economy/artists/share holder's best interest.
There is no such thing as "trusted" computing. No one trust anyone here. This shouldn't be called "trusted computing." This should be called "Untrustful Consumers Computing."
"Don't let fools fool you. They are the clever ones."
You could do that now with current, older hardware. The business, company or organisation using this technology to identify their employees would not be in control of it. The hardware and software companies will be, as well as anyone else they're in league with.
How long until you can buy a fake thumb with Elvis Presley's print on it? :)
Steve
A work that expires before its copyright never enters the public domain and thus enjoys eternal copyright protection.
That's OK. It doesn't trust you.
Stasis is death. Embrace change.
(it's what I'm doing)
start sticking with free software and hardware that supports and preferably sponsors free software. change vendors if your vendor goes treacherous-computing direction. import/smuggle hardware is tcpa is mandated by legislation, while writing a letter to your legislator saying that tcpa is a restriction on free trade and outright nazism. because it is.
It's better to be the foot on the boot than the face on the pavement. ~~ tkx Kadin2048
I really hate the way DRM and hardware DRM now gets fully integrated into our own lawfully purchased computers.
I have the right to use my computer to whatever I feel like and it is of no concern to anyone but me. If the companies disagrees with this they can take a hike for all that I care.
All this will contribute to - is to further alienate Linux and users of alternate operating systems and demean our hard efforts to get legal DVD-playback software etc. for our chosen platforms. I am so put down by this Ill probably never run anything with DRM on it again just for the opposition of it. I will not purchase DRM enabled mp3-players, I will NOT purchase DRM harddisks or any hardware with DRM on it.
If I am forced to do it because of the fact that every hardware producer is forced by Microsoft to do so... I will do anything I can in my power to make sure that my system will be rid of such hardware, modding, jacking, compiling - I really dont care. Its my hardware and NO one shall take that right away from me! No one shall control my software or my computers or what I will be doing with them.
I fully and completely agree with the companies about piracy, I dont support piracy in any way. That said - I also support my own freedom to chose, and past experience shows us that businesses will always do whats best for them FIRST before the customers, the customers are just milking-cows to them - which is fair enough if you give us what we pay for. When you decide to mess with our hardware and deprecate our already paid for services and hardware - then I am putting my foot down and say - Enough already!
All this will probably further feed a grassroot "linux-like" organization that will form an alternate OS that will NOT conform to DRM - even if by law (god forbid it goes that far). DRM and control of customers hardware is a CRIME against the public!
What this world is coming to - is for you and me to decide.
Keeping corporate proprietary info secure
Or, keeping an internal memo that reveals the company has broken laws etc. secret. DRM of this kind (and on emails, something else they want to implement) makes it very difficult for whistleblowers to collect evidence and expose a company that should rightly be exposed.
The effects of DRM are certainly chilling. Also, as far as trade secrets go, there are laws designed to protect those. DRM will only ever be (ab)used to hide things that shouldn't be hidden and to strip away fair use rights. The media companies weren't able to do it through the law courts, so they sneak in fair-use crippling measures by the back door.
I am NaN
It never ceases to amaze me how slashdotters can't see pas their own noses on things like DRM. There are people with legitimate security needs that don't give a rat's ass about your pirated copy of Brittany Spears. Keeping corporate proprietary info secure is a MUCH bigger deal than preventing you from watching pirated movies.
...).
If I *did* have a legitimate security need, I wouldn't trust this; it's almost certainly backdoored (because I can imagine certain law enforcement agencies could be quite pissed if it wasn't - imagine some criminal using TPM hardware to encrypt their data such that it's password-protected, can only be accessed on that computer with an untampered OS, and erases itself after three consecutive wrong passwords). And if it is, there's no guarantee that someone won't get access to the backdoor who you don't trust with your data (criminals, one of your competitors,
Change is not always good. Why do I want to pay for equipment that I will not own?
These "TRUSTED" machines are untrust worthly. You will not be able to control what runs on them. Some one else will decide if you can use your own equipment. Just like the lies with HDTV and HMDI. It is about setting up toll booths deep in your own pockets.
I konw, I'm a bad citizen, and I certainly don't smile now.
It's nice to know that the content industry now trusts my computer and lets it play its crappy movies. The problem is, I don't trust it anymore. I won't trust it with my data, I won't trust it with my files, I won't trust it with my time.
At least until I find a way to make MY computer MINE again.
Until now, I was a good citizen. I bought my music. I bought my movies. I bought my games. My reward was a rootkit, DVDs that don't play on my equipment and software that crippled my system.
Sorry, but I don't trust your computers. And I will do whatever it takes to make my computers mine again!
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
The problem with fingerprints is that it's inherently a very insecure way of authentication for two reasons:
Firstly, you can't change it if it leaks out. A password or a credit card number can be easily changed and the damage minimised in case of an information leak. Doing this with a fingerprint is much harder.
Secondly, the fingerprint is very hard to keep secret. Your body has this annoying ability to leave copies of your identification token all over the place, very easy for anyone to pick up. If you were worried about the ability to scan proximity tags (RFID), then you should be really scared about the use of fingerprints as authentication tokens.
If you don't believe me how easy it is to pick up, read this about how to make a copy of ones fingerprint using common household items.
With DRM comes one problem for you as a company: You have to trust the DRM manufacturer completely. And I mean completely. They will not allow you to snoop into their protection mechanism. Trust it or get lost.
So would you, if you were a software company, trust Microsoft? Would you, if you were a mainboard manufacturer, trust Intel? Would you, if you were a chip producer, trust Infinion?
There are other ways to protect your intellectual property. Open Source encryption mechanisms, the source code of which you can read, audit and evaluate, and even adjust to your security needs.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
More and more the computing industry is coming off as a racket. Every time I buy something digital I'm forced to pay for crap that I don't want. 6-in-1 card reader? Who gives a shit? Fingerprint sensor. I don't give a fuck. It's like buying a toaster with a built in Pez dispenser. Only, nowadays, you can't find a fucking toaster without the Pez dispenser.
WTF?
You're missing a lot of details about this software. It's closed source, and a violation of the DMCA to reverse engineer it. That means writing an open source version of the encryption/decryption tools is going to be a nightmare.
Second, running it at the OS level instead of the hardware level of the built-in features of the Intel CPU's is going to really slow it down: that will probably hurt performance a lot of open source versions of the Trusted Computing tools, even if they're legally created.
Third, the next logical stage of Trusted Computing is hardware locking: motherboards that won't load unsigned boot loaders, or won't access DVD drives or hard drives without being authenticated with Trusted Computing licenses to be held by OS distributions or DVD drive and software vendors. This can be used to block open source operating systems from even booting, or to prevent Trusted Computing managed DVD drives from being able to read DVD's that have Trusted Computing signed DVD's in them without a Trusted Computing signed media player.
It's very nasty, and it's at the core of why Microsoft and Hollywood are collaborating so well in this project.
All a reasonable person needs to do is carve a single finger shape out of wood, complete with finger prints, and then cast rubber in the shape. Then, label it "Anonymous Password".
Then, tie one to every computer in the building.
Now, make up another finger, with a different design, and label it "Admin". Distribute it only to admins (note that changing fingers will be required as you hire and fire).
Then, for each specific user group, manufacture a set of rubber fingers, and label them accordingly. Now distribute the fingers on a keychain...
Correct Horse Battery Staple: 72 bits of entropy. Enter "Correct H" into google. When it generates the phrase, that's
The one thats signed by the creator , that cant be removed, deleted or changed without the fingerprint of the creator. All its going to take is a a hundred or so companies having to buy 50 or so new thinkpads because they cant remove the trusted virus to cause a real big stink and forever doom trusted computing
I trust Microsoft as far as I could comfortably spit a dead rat
You mean that we can create more artificail scarcity, that will create more artificial markets where people trade more virtual goods. All that while adding near to zero worth on the real markets out there.
We really need to get out of those pyramids. Not create more.
Rethinking email