5 ms·
TPM/measured boot can provide proof that a DRM stack is in place.
by dmm 3y ago
TPM/measured boot can provide proof that a DRM stack is in place.
- deleted 3y ago[deleted]
- mjg59 3y agoIn an abstract sense, yes, but were anyone to do that in a widely deployed manner there are fairly easy and cheap ways to circumvent it.
- immibis 3y agoSuch as?
- mjg59 3y agoSuch as plugging in a TPM after boot and programming the PCRs however you want
- Nextgrid 3y agoTo be fair, firmware-based TPMs which are part of the CPU/SoC should be invulnerable to that? However, TPM-backed DRM on general-purpose OSes is impossible in the current world and is fear-mongering. The TPM can attest to a remote party that you've booted a certain OS, but this OS would need to maintain that chain of trust all the way for it to be effective. That's impossible due to the number of device drivers (which need kernel-level access by design) and various other privileged components a general-purpose OS requires (security software, etc), not to mention the attack surface of all that. For a hypothetical TPM-backed DRM to work, you'd need Netflix to ship you an entire OS image that you can boot (which the TPM will prove to them that you've booted), and that OS image needs to magically have all the drivers for every potential PC their customers might have, and you need to convince people to reboot their machine every time they want to watch it. This is all unnecessary considering the current status-quo of DRM is good enough, Widewine does not require a TPM and relies entirely on security by obscurity and it's considered good enough by the industry.
- mjg59 3y agofTPMs are invulnerable to interposing attacks, but if you add a second TPM and program it as Windows (eg) would and redirect all remote attestation requests to that, the remote site has no way to know that this has happened.
- Nextgrid 3y agoMy understanding is that TPMs have vendor-embedded certificates/keys, so I guess eventually all discrete TPMs' keys will no longer be accepted by remotely-attestable services to protect against this attack - fTPM will be the only way. This is all theory though - workable TPM-backed DRM would require so much vendor cooperation, secure programming and break legitimate use-cases that it won't happen any time soon on conventional hardware. It would be cheaper for the media industry to just sell streaming boxes or exclusively target more locked-down platforms (iOS, Android) than try to make it work on generic Windows PCs.
- Mindwipe 3y agoOr just use the existing hardware security features that don't let the OS see what's in the relevant video memory at all. But as you say, that's a much, much smaller attack surface than trying to validate the OS.
- immibis 3y ago> However, TPM-backed DRM on general-purpose OSes is impossible in the current world and is fear-mongering. The TPM can attest to a remote party that you've booted a certain OS, but this OS would need to maintain that chain of trust all the way for it to be effective Why don't you think that can work? Windows already limits drivers to ones signed by Microsoft - or else you have to be in "test mode" where - among other things - DRM-protected video playback is disabled! And Windows already contains a "protected media path" component which protects encrypted DRMed video data. Sure, there will probably be bugs in a drivers sometimes allowing for a signing bypass and then a DRM bypass if the DRM is done in software. Once they're discovered, those drivers will be blacklisted, and yes, that will mean you can't use that hardware. And the masses will blame the pirates.
- aseipp 3y agoUsing a TPM for remote attestation of device state is basically worthless in the generic PC UEFI world because there is pretty much unlimited surface area for holes to leverage, from motherboards that falsely report secure boot states to firmware bypasses to using your own TPM to just exploiting a vulnerable kernel driver that has a valid windows codesigning signature. In practice places that want "attestation-like" functionality, like Riot do for anti-cheat, just load mandatory kernel modules instead and require e.g. Type 1 hypervisor-based security in Windows to be enabled. Or they just obfuscate everything and run blobs. These can still be bypassed but it's still difficult and in contrast fully controlled by their software stack, which is more usable for them for more players. It's good enough, in other words.