8 ms·
The author is correct in that media DRM is tied to GPU vendors on the field right now. But hardware backed DRM can be so much more invasive beyond that. I have
by no_time 2y ago
The author is correct in that media DRM is tied to GPU vendors on the field right now.
But hardware backed DRM can be so much more invasive beyond that. I have no doubts the long term goal of MS is to have a Windows version of Play Integrity.[0] So total control over everything that happens on your device. Just to give an example of what could happen if this becomes reality: https://en.m.wikipedia.org/wiki/Web_Environment_Integrity https://en.m.wikipedia.org/wiki/Web_Environment_Integrity
This tech extended to browsers could easily mean that sites could refuse to serve you if your machine is running any bigcorp unapproved software. An easy example of that would be adblockers.
Unless we get lucky with secure world compromises like the Tegra X1 bootrom exploit[1] or get real good at passing legistlation that forces companies to give you all the private keys to your own machine, the future for personal computing is looking grim.
[0]: https://developer.android.com/google/play/integrity https://developer.android.com/google/play/integrity
[1]: https://github.com/fail0verflow/shofel2 https://github.com/fail0verflow/shofel2
- matheusmoreira 2y agoIt's downright cyberpunk. > sites could refuse to serve you if your machine is running any bigcorp unapproved software This needs to be classified as discrimination.
- account42 2y agoIt should be classified as discrimination but the same thing is already reality with mobile apps.
- ignoramous 2y ago> The author is correct in that media DRM is tied to GPU vendors on the field right now ... hardware backed DRM can be so much more invasive I expect mjg59 to know what they're talking about but like you say, I wonder the same thing about the strength of (what you call) Media DRM v Hardware-backed DRM. GPU vendors have quietly deployed [hardware-based DRM] ... [which] works just fine on [boards] that [don't] have a TPM and will continue to do so. Work fine? Even if a section of GPU's vRAM is out of the reach of the OS (here, to implement DRM), wouldn't TPM / DICE be needed to establish trust / measure GPU's firmware?
- mike_hearn 2y agoNo, the GPUs have their own hardware RoT that measures the firmware. Modern GPUs are basically parallel computers with their own RAM, bootup sequence, BIOS, operating systems (drivers and firmware together are basically an OS), compiler toolchains, debuggers, sub-drivers and so on.
- rustcleaner 2y agoOne which needs to be opened to users/owners instead of locked away. A price-doubling 100% sales tax on Universal Machines which lock owners out like with video cards (and their firmware), should make products which are not fundamentally significantly GNU-ideals friendy unaffordable to the average consumer (and therefore not economically viable anymore). Siemens can still sell their $5MM machine for $10MM to BASF or whatever, because BASF can afford to borrow double to pay the tax, but Cletus and Dorothy will not be buying sony playstations and apple iphones because $2,000+ isn't worth it.
- mike_hearn 2y agoGood luck getting elected on such a platform. Totalitarian states can do that kind of thing, democracies not so much.
- deleted 2y ago[deleted]
- matheusmoreira 2y agoThe GPU is a completely separate computer running proprietary software. "Operating systems" do not operate anything anymore. They are just some user app, to be sandboxed very far away from the real action. https://youtu.be/36myc8wQhLo https://youtu.be/36myc8wQhLo Stallman warned everyone. Virtually nobody listened.
- fc417fc802 2y ago> "Operating systems" do not operate anything anymore. Not entirely fair. There is still a kernel and a privileged userspace layer. That hasn't changed. The OS implements a common API that abstracts over ISAs and other finnicky hardware details that are under constant short term churn. It's just that peripherals themselves have become so incredibly complex that many of them now require their own embedded systems in order to operate. The hardware was always a black box it's just that now it contains an entire embedded OS.
- kccqzy 2y agoI have trouble understanding your use of the term DRM. Media DRM makes sense: the copyright holders want to "manage" their rights digitally. How is that relevant to Play Integrity or WEI? Whose right is being protected or managed? If I have an Android without Play Integrity there are certain apps that will not run, but I don't see any rights being managed here: an app developer has the right to refuse service just like I have the right to refuse running an app. In fact I see no relationship between DRM and Play Integrity other than a tenuous connection that both are about controlling what a user cannot do on their device. If this is what you mean, then you have made the same mistake as FSF by conflating unrelated technologies.
- ethbr1 2y agoUltimately, DRM is untenable without users also being locked out of their own devices. Consequently pressure to support more effective DRM will always translate into pressure to restrict what users can do with their devices. Furthermore, the only defense against this is large open device market share: once closed devices comprise most of the market, DRM proponents can announce they'll stop supporting open devices, creating a downward spiral that further decreases the availability of open devices. And then we live in a future that's fucked.
- mike_hearn 2y agoThis is an FSF level understanding. Android devices are fully open and you can reflash them to whatever OS you want. Some remote servers won't give you service if you do that, but nothing is locking you out of your device. As Android dominates the global market, you already live in that world where most devices are open.
- lxgr 2y agoWhile I don't agree with the FSF on even close to everything regarding trusted computing, I think for a fair discussion you'd have to at least steelman their arguments here: I think it's fair to assume that in a world in which almost every device supports attestation and makes it available to any service provider by default, without giving users an informed choice to say no or even informing them at all, service providers are much more likely to provide access exclusively to attestation-capable clients. That, in turn, has obvious negative consequences for users with devices not supporting attestation (whether out of ideological choice, because it's a low cost device and the manufacturer can't afford the required audits and security guarantees etc.): Sure, these users will always be able to just refuse to transact with any service provider requiring attestation. But think that through: We're not only talking about Netflix here. At what availability rates of attestation will decision makers at financial institutions decide that x% is good enough and exclude everybody else from online banking? What about e-signing contracts for doing business online? What about e-government services? I am at the same time excited about the new possibilities attestation offers to users (in that they will be able to do things digitally that just weren't economically feasible for service providers, since they often have to cover the risks of doing so) as I am very wary of the negative externalities of a world in which attestation is just a bit too easy and ubiquitous. In other words, the ideal amount of general purpose attestation availability is probably high, but significantly below 100% (or, put differently, the ideal amount of friction is non-zero). Heterogeneity of attestation providers can probably help a bit, but I'm wary of the inherent centralizing forces due to the technical and economical pragmatics of trusted computing.
- urronglol 2y agoIf that ever happened I would nerd up on low level architectures. Get a job in a trusted company. Leak the keys. The only worthy cause to apply my patience to.
- aleph_minus_one 2y ago> If that ever happened I would nerd up on low level architectures. Get a job in a trusted company. Leak the keys. > The only worthy cause to apply my patience to. This already happened for smartphones. Concerning your first claim: Did you attempt to get a job at such a company to leak the keys? Concerning your second claim: Did you already invest lots of personal ressources for this cause?
- badsectoracula 2y ago> This already happened for smartphones. Sadly even in tech many people do not seem to see smartphones as real computers.
- Semaphor 2y agoNot GP, and don’t have their patience anyway. But while I see them as real computers, they aren’t any that I enjoy using, so I care relatively little for them.
- aleph_minus_one 2y ago> But while I see them as real computers, they aren’t any that I enjoy using, so I care relatively little for them. If you/people were brutally willing to crack them open, the "enjoyability" of using them for "hacker-minded people" could be improved insanely.
- Semaphor 2y agoNo, because they’d still lack a physical keyboard and a large screen ;)
- TacticalCoder 2y ago> the future for personal computing is looking grim I don't know. They could lock up the hardware stack as much as they want, in the end it's pixels being pushed to arrays. It's extremely hard to prevent these pixels from being intercepted. You'll have pirate groups just going deep in the hardware (opening the monitors and soldering and hacking and whatnots) and eventually tap these. As for personal usage: I've got hardware from the eigthies still working fine. Instead of: movie2025-WEBRip1080p-x265.mp4 people shall download: movie2025-WEBRip1080p-DRMfree-x265.mp4 And people shall just play that on their DRM-free hardware, either brand new or old. For example people can still buy brand new CRT (!) screens today. Not just CRT screens but also brand new CRT PCBs to drive either new or old CRTs. It's 2025 and people can still buy brand new CRTs. That's kinda rad. And if worse comes to worse, if it's really impossible to go "tap" into the pixels being sent to a DRMed monitor (which I don't buy for a second), there's still the analog hole. Pirates are just going to use old (non DRMed) gear to rip, analog style, DRMed content and then they'll just process the result with some AI models to get it back to near perfection. Heck, the day's probably not very far where I can use, say, two handcams from the 90s to film a movie at the movie theater and then use an AI model to give back a near pristine movie file (as in: one where it's impossible for the layman to discern from the original). > This tech extended to browsers could easily mean that sites could refuse to serve you That's already the case: some content is geo-blocked. People use a VPN or just fire up Frostwire or qbittorrent. Even a Raspberry Pi 5 goes a long way: when are these going to play the DRM game and make the future look grim, instead of bright? I don't doubt there are really deeply sick, evil, people out there thinking about how they can ruin of collective future but I also know that they'll encounter people who have systematically owned their sorry arses.
- stonogo 2y agoThe issue isn't preventing piracy, it is defending GPU market segmentation. In the old days you could flash Quadro firmware to Geforce cards and unlock features or modify clocks. The common thread is artificial scarcity.
- slt2021 2y agoit is price discrimination. How to sell the same GPU hardware at different prices based on consumer's wallet: 1. cheaper price for gamers only for games 2. maximum price for crypto/AI bros
- rustcleaner 2y agoI always said a hefty sales tax (50%? 100%? 200%?) on final sale of any product containing just a single Universal Machine which has artificial designs/locks that prevent the owner from replacing any and all firmware/software with versions he has authored, and/or which lacks complete enough documentation of design and interfaces that would enable a knowledgable and capable owner to author his own software/firmware. This should apply to PCs, phones, watches, microwaves, televisions, CPAP machines, automobiles, toasters... everything which contains a Universal Machine. Uncontrolled [by owner] Universal Machines are a national security concern which has the potential to turn grave at any moment.
- braiamp 2y agoWhy not just prohibiting the practice? This isn't weed or alcohol.
- rustcleaner 2y agoStill allow for the multimillion dollar industrial dozen-megamachine makers.
- advael 2y agoSo the idea is to ban the practice for smaller players without the scale to eat the costs? No thanks, an outright ban is necessary. This will not prevent manufacturers from doing business no matter how they may whine about it, and frankly if this does somehow kill their business it should
- rustcleaner 2y agoThe idea is to make it almost completely commercially unviable to sell locked down DRM hardware to small players, and only somewhat harder for XYZ Healthcare to buy the multimillion dollar GE MRI machine unless the MRI is fully open and compliant (XYZ can borrow and amortize, but Joe can't do that to buy playstations and cars).
- causi 2y agoThis is why it's so important to have local copies of things you value. Movies, shows, games, Youtube channels, everything.
- DoctorOetker 2y agoConsider a benevolent cryptographer, who is able to break modern asymmetric cryptography, but refuses to use it for petty personal gain, and is fully aware of the dangers of publishing it (why this cryptographer put it in dead man's switches instead, with recipients randomized over nearly all power blocs, political groups, companies, ...) The cryptographer never implemented it on daily compute devices. Perhaps this cryptographer would be willing to risk a low communication round release of private keys corresponding to public keys in ROM or burnt in eFuses etc... but only if the public key dump is sufficiently large and encompassing. From the perspective of the cryptographer we are all whining wankers, and we should just collect all the public keys as a wishlist. The cryptographer care naught about "liberating" hour long advertisements for the militaries or intelligence agencies etc. The cryptographer does wish sovereign compute to fellow humans, a primordial requisite for effective democracy. ==== While I understand the average programmer would ascribe an incredibly low probability to the above, the absolute absence of such a comprehensive public key dump is not in proportion to the probability considered.