4 ms·
You've described DRM; this is exactly why a lot of people are wary of TPMs.
by sillystuff 3y ago
You've described DRM; this is exactly why a lot of people are wary of TPMs.
- lxgr 3y agoNo, DRM is safeguarding other people's keys on your device. There's more applications of trusted computing and TPMs than that; one of them is using it to safeguard your own keys.
- sillystuff 3y ago> DRM is safeguarding other people's keys on your device. I think you misread the GP. Your definition of DRM is exactly what GP described as his use of the TPM. >>I sell a device. There are lots of them in hands. You still aren’t getting my device key off of it. Yes, you can use that device all you like, but you aren’t going to clone it and make more. What the GP describes is not safeguarding the nominal owner of the devices' keys. GP is restricting the nominal owner of the device on behalf of himself as the manufacturer. This is leveraging the TPM for DRM. Other possible less nefarious uses of the TPM are irrelevant to this point.
- lxgr 3y agoOh, I indeed read that as "I [re]sell a device". In the case of them selling devices with embedded non-extractable keys, it could really be DRM. Or something else! Payment cards work like that – they hold keys that nobody is supposed to be able to duplicate; certainly not third-parties, but also not the legitimate account-/cardholder. There are plenty of uses for trusted computing other than DRM; they're just usually not as disruptive/frustrating to legitimate customers as DRM (and as a result are not as contentious), so they don't get as much attention.
- zlg_codes 3y agoWhat moral right do they have to put data on devices you own? TPMs jeopardize the ownership of a device. Consumer devices are already sold where you can't (easily) inspect or change anything. Even a user-controlled TPM can be used as storage for keys used to usurp control of the device. The existence of IME and PSP enables manufacturers to have more control over computing devices than the people who buy and operate them. There is no moral defense for sabotaging ownership.
- jon-wood 3y agoI genuinely wish things were this binary. I’m a hacker (using the original definition) at heart, I want to turn random devices I own into other things, which would be so much easier if it weren’t for encrypted storage and signed boot chains. That’s all very well until you start talking about hardware that does things like providing video of the inside of someone’s home. I’m still behind being able to modify them and use them as you please, but if you do so that should be self-evident, because otherwise *someone else* can do so, and you won’t know until video appears on the internet if you walking back from the shower. TPMs don’t necessarily mean that you can’t modify a device you’ve bought, it just means that things like the API key which connected it to the backend will be invalidated and you’ll have to set the device up some other way. That’s a safety mechanism, and even I want it to be present in hardware I buy. Likewise I don’t want someone to be able to take a doorbell from the front of my house, extract my wifi credentials from it, and pivot from that to compromising the entire network. I’m sure some people will say “well just don’t have those things”, and I’m inclined to agree, despite having worked on such devices I’m not sure they’re actually hugely useful to most people. People are buying them though, they’re in the wild, let’s make them as secure as possible.
- patrakov 3y agoLet me reply item-by-item. > No, DRM is safeguarding other people's keys on your device. Correct - in this case, safeguarding mainly means making sure that the nominal owner of the device does not extract the keys. > There's more applications of trusted computing and TPMs than that Correct > one of them is using it to safeguard your own keys. Questionable - needs a definition of safeguarding. Making sure that the keys cannot be backed up would be a strange definition.
- matheusmoreira 3y agoIt's all about who owns the keys. If we own the keys, the technology empowers us. If they own the keys, the technology oppresses us.