3 ms·
> Hardware DRM systems ("trusted computing") are inherently controlled by remote corporations; at the end of the day someone has to certify hardware-bound keys,
by yholio 5y ago
> Hardware DRM systems ("trusted computing") are inherently controlled by remote corporations; at the end of the day someone has to certify hardware-bound keys, and someone has to revoke leaked keys.
And that is not bad technology in itself to have, the question is who gets to sign, and it's a political one. There exist in principle an acceptable threshold that various small OS vendors and Linux/*BSD distributions can pass and virus authors cannot, while allowing for some sort of hardware three finger salute that enables custom self signed roots for organizations and developers that can handle them safely, i.e. a special use case not required by the majority of the population who simply trusts a vendor.
I don't claim the Microsoft tech allows these (most likely not), but I believe these are the correct demands and criticism we should make, approach it as a political issue.
Fighting ideologically against a technology and ignoring the larger political objectives is foolhardy. If the technology delivers value, some vendor will bundle it with pretty pink buttons and corner the market, forcing you to use it too because every body else does and you have no other option. It's how we ended up with solid blocks of DRM from Apple in the hands of billions of consumers that won't even allow you to run your own choice of software, let alone alter the operating system.
I just removed a crypto-miner malware from an IT-illiterate friend's windows computer. There are great many people in this category. If we can't fix their computers by flipping a TPM switch that ensures some level of platform integrity, they will simply go out and buy an Apple device, "because it works better". That's their subjective view, good luck teaching them to value software freedom and learn good security practices.
- betterunix2 5y ago"If the technology delivers value" The technology does not deliver value for users. It has always been intended to benefit Microsoft and their media partners, with a bit of window-dressing meant to trick users into believing that they somehow gain from it. This is possible only because the current market for personal computers has almost no meaningful competition. "I just removed a crypto-miner malware from an IT-illiterate friend's windows computer" ...and malware authors will use DRM systems like this to make it harder to detect their malware. Instead of, "Hm, CRYPTOMINER.EXE is spinning the CPU" it will be "Something seems to be spinning the CPU but the platform DRM is preventing me from figuring out what is happening." "some level of platform integrity" Except that this system does not ensure platform integrity. Sure, firmware and bootloader signing can protect against malware or at least give users the ability to reset their system to a good state, but we are talking about a DRM system and that is a very different story. Of course, Microsoft's track record on bootloader security is mixed. They have been willing to allow major Linux distros to get a signed "shim" that can be used to bootstrap grub, but they also made a deliberate and arbitrary decision to forbid vendors of ARM systems from allowing users to disable secure boot. The result is that users who want to run their own bootloader, with whatever risk that entails, have less choice in hardware and are forced to spend more. So while UEFI was generally a win for end user security, it came with a strategic effort by Microsoft to exert greater control over user devices -- something which only benefits Microsoft and which was done only as part of their long-term effort to sell DRM to media companies. The end of all this will be a world where everything looks like the "mobile" ecosystem or video game consoles -- users will not be allowed to run any software that Microsoft did not approve of unless they pay 4-5x more for a computer that has fewer restrictions. Sure, it will make life harder for malware writers -- assuming the approved software does not have tons of exploits -- but it will also mean that Microsoft's interests never get challenged. The only reason anyone will be allowed to run Libreoffice will be competition authorities, and in all likelihood software will be made available based on a user's region (so EU users get to run Libreoffice, but not US users). It will be a net negative for users and for the next generation of developers, who, rather than learning by staying up late with their own computers, will at best only be able to program on their school's computers and only if they are in a wealthy enough school district.