5 ms·
ARM Launches Hollywood Approved Anti-Piracy Processor
- simias 13y agoIt was discussed here 6 hours ago: https://news.ycombinator.com/item?id=5817984 https://news.ycombinator.com/item?id=5817984
- daker 13y agoSorry about that!
- deleted 13y ago[deleted]
- Zigurd 13y agoAin't it great how "trusted computing" is never about trusting you? And how the applications of trusted computing are never about, say, preventing your medical records from being spread around to people you don't know about?
- timthorn 13y agoBut it can be about you trusting your device. And the applications of trusted computing are absolutely about preventing medical records from being compromised, but that's not a sexy headline in the same way that DRM is.
- tptacek 13y agoIt is interesting to consider how content protection and platform security can be two sides of the same coin; how systems that keep code you write from snatching video frames from The Avengers can (often are) the same as the ones that keep malicious code on your device from stealing your credit card.
- Zigurd 13y agoExcept that when you allow a third party to put code in a trusted element, it's Big Brother Inside. It's like installing someone else's security camera in your house. Odious.
- tptacek 13y agoI wonder if the rootkit developers feel the same way, since the technology we're talking about (TZ) is designed to stop them as well.
- betterunix 13y agoIs there some reason to think that a rootkit could not use this technology? Do you have details about this system (which, to my knowledge, are proprietary) that leads you to be believe it is something other than a way to reduce user control of their own devices (which could be a good thing for a rootkit)?
- tptacek 13y agoIt's a video decoding block that works with TrustZone. TZ is well-documented and conceptually very simple.
- betterunix 13y agoI have not been able to find anything other than marketing material; maybe I am just looking in the wrong places. Can you provide a link to some technical details?
- tptacek 13y agoWere you not looking on Google? http://lmgtfy.com/?q=trustzone+arm http://lmgtfy.com/?q=trustzone+arm Read the first PDF on that page.
- 13y ago
- Zigurd 13y agoReally? Are there any real-world examples?
- tptacek 13y agoYes: the Intel TPM / Secure Boot system's design goal is to stop rootkits, but is also used by vendors to load secure video decoding code.
- Zigurd 13y agoThat's an odd meaning of "secure."
- tptacek 13y agoI'm sorry that engineering terminology isn't invariably compatible with your politics.
- Zigurd 13y agoThe post above referred to patient control over medical records using trusted elements. Is there a real-world case where any bureaucracy has yielded control of individuals' documents to those individuals through the use of trusted computing? Anywhere? In any subject matter? Is there any case where I can submit a documents and then be assured that i can revoke access? Anyone? Bueller?
- tptacek 13y agoYes, there is, since "trusted computing" mostly refers to the idea of locking your running OS down so that attackers can't persist code that alters it. Which makes your clumsy "Bueller" thing all the funnier: it's like you literally can't imagine that hardware should be any more secure than an 80386.
- betterunix 13y ago"Yes: the Intel TPM / Secure Boot system's design goal is to stop rootkits" Why would you need any cryptography to do this? I have a computer that uses a much simpler, equally effective, and easier-to-use approach: the boot sector cannot be overwritten unless the system is rebooted in a special mode (and the OS cannot be booted in that mode). At least for personal computing, that is far better than a system that forces people to rely on a trusted third party to decide what software they can run.
- shmerl 13y agoYou can't trust a device which has DRM.
- tptacek 13y ago"But you can't trust a device on which the video decoder silicon understands the TZ bits".
- shmerl 13y agoIn the case where you have no control over the decoder while using the system. Is it clearer now? If you have control - then it's a non issue. Same as TPM can be used for something useful, but can be used for reducing user's control.
- tptacek 13y agoYes, you have control.
- shmerl 13y agoIf you have control (and can disable applying this to video decoding), what is the point for the DRM lobby to push for this thing? Their usual idea is to take control away.
- tptacek 13y agoThis is a video decoder IP block that is simply compatible with the security architecture of the rest of the system. The only reason you think "the DRM lobby" is pushing for it is because Torrentfreak wrote that. Torrentfreak is a laughable source of technical content.
- shmerl 13y agoSo you are implying that it's not related to encryption of the video?
- kunai 13y agoRelevant xkcd: http://xkcd.com/129/ http://xkcd.com/129/
- kyle_martin1 13y agoAnd now it's our turn to break the DRM!
- tptacek 13y agoBy which Torrentfreak means "a video decoding IP block that is aware of TrustZone, which is fundamental security functionality for the whole ARM platform". Actually, no, that's not what Torrentfreak means, because Torrentfreak has no idea what the hell any of those terms mean.
- shmerl 13y agoAnother DRM idiocy shoved onto the oblivious consumers. Users should know to avoid these GPUs now.
- tptacek 13y agoIt's not a GPU.
- shmerl 13y agoWhat is it exactly? An optional chip that you can unplug? It comes as one package in the GPU.
- tptacek 13y agoIt's a video decoder IP block; it's one of a large number of IP blocks you can assemble like lego pieces to design an ARM system.
- shmerl 13y agoBut you (as a user) can't make it optional, once it's there, right?
- tptacek 13y agoWhat exactly do you think this piece of technology does? I'm having trouble articulating how optional it is. I think you might think this is something that infects your operating system and watches your keystrokes.
- shmerl 13y agoAllows using an encrypted video stream not accessible to the user without any means of disabling this obscuring?
- MichaelGG 13y agoAs tptacek points out, there's not much of a story here, this is just platform security. It does puzzle me why there is so much marketing and fuss around it though, as if a common source of leaks was "mobile video". As if somehow everyone in the world would turn into a source because they have Netflix on a Samsung phone. It's bizarre. An effective anti-piracy system is a watermark detection routine embedded into the video decoder, so that you can't use hardware acceleration if the device detects the video isn't licensed.