Motherboard Forums


Reply
Thread Tools Display Modes

Intel corp: The computer *OWNER* is the *ENEMY* and we must designour TCM chips to protect against him.

 
 
ultimauw@live.com
Guest
Posts: n/a
 
      01-08-2009, 09:28 AM
http://it.slashdot.org/article.pl?sid=09/01/06/2132247

(notice that they call the locked down execution part "TXT". I don't
trust anyone who has to resort to [W][O][R][D][G][A][M][E][S] to try
to sneak stuff like this under the public radar.

From the same page http://it.slashdot.org/comments.pl?s...7&cid=26351915
I am a programmer, and in particular I have studied the Trusted
Platform Technical Specification documentation. All 332 pages of dense
technicaleese. There is one particular page I would like to cite. In
the TCPA Main TCG Architecture v1_1b.pdf on page 277 the documentation
comes right out and announces the fact it is designed to be secure
against "rogue Owners".

You are either mistaken, or you're full of crap. The chip is in fact
designed to lock the computer against the owner. Yes, locks that are
designed to protect the computer against it's owner will also prevent
outside attackers from doing things that the owner himself is
forbidden to do. However that is incidental. A hostile Trusted
Computing system trying to lock computers against their owners is
fundamentally different than a system designed to secure computers for
the owner.

If you really do believe that this is solely intended for the benefit
of the owner, perhaps you could answer some questions for me.

Why the absolute refusal to implement the EFF's Owner Override
proposal? It would give the owner full control of his own computer
while still securing against remote attacks. You could even secure
against local attackers (other than the owner) by placing adding some
sort of Owner Authentication element to the Override system.

Or how about my proposal? I merely want a printed copy of the master
key to my own computer. I merely want the option to buy a computer
that comes with a printed copy of my master key. (Technical note: I am
referring to the PrivEK key, and having the option to export the RSK
key encrypted to the PrivEK would be beneficial for ease and security
reasons.) Go ahead, explain to why I am absolutely forbidden to know
the master key to my own computer. Go ahead and explain why they
absolutely refuse to PERMIT anyone to manufacture any compatible Trust
Chip that permits the owner to know their own master key.

And best of all, explain to me all of the documented systems and plans
to REVOKE and (for all practical purposes) brick any chip if they ever
detect that you have learned the master key locked inside you
computer, if you ever learn the master key to control your own
computer, if they ever detect that you have the power and control to
override any DRM system based on the chip.

And don't even try the line about how this revocation system is "not
part of the chip itself". The chip was explicitly designed to secure
the computer against the owner, the chip was explicitly designed to to
support that revocation system, and the chip's technical documentation
and design specification explicitly mention this revocation system.

The design specs endlessly list all of the things that the owner MUST
be forbidden to be able to do, all of the things the owner MUST be
forbidden to know, the specification even has a section that mandates
that any owner's data under "non-migable keys" MUST be effectively
impossible to back up and MUST be irretrievably lost if the chip ever
dies.

And on and on and on. Yes, the chip was explicitly designed to
consider the owner to be the enemy. The chip is explicitly designed to
be secure against "attacks" by the owner. Yes, the current generation
of chips are relatively vulnerable to physical attack - by the owner
or by a hostile attacker. However it is fundamentally designed to lock
against the owner, there is a supplemental specification on how to
increase the physical security against the owner and how to certify
hardware as possessing stronger anti-owner physical security, and
there is mention in the CHIP speck itself and in supplemental
specifications on how to revoke and lock-out any chip where an owner
does manage to gain local override control over his own computer.

Yes, there are some people working on Trusted Computing with the
intent of securing your computer for you, of protecting you against
remote attackers. However that does not change the fact that the
system is indeed designed to lock computers against the owner, that it
is indeed designed explicitly for DRM support, that it is explicitly
designed to be hostile to the owner, it does not change the fact that
they COULD design a pro-owner system to secure your computer for you
without these anti-owner aspects, but that they refuse to permit any
compatible pro-owner chip that does not also impose these anti-owner
DRM style enforcement systems as well.

-
 
Reply With Quote
 
 
 
 
johns
Guest
Posts: n/a
 
      01-09-2009, 10:41 PM
> without these anti-owner aspects, but that they refuse to permit any
> compatible pro-owner chip that does not also impose these anti-owner
> DRM style enforcement systems as well.


Maybe we are all sick and tired of Computer Assholes.
I know the secondary school teachers are. Undergrad
university programs most certainly are. Governer Palin
got a taste of it. Every pervert out there has a computer.
My Bank knows more about me than I even remember,
or care to remember. In my job I see this security crap
every single day, and it never stops coming. I am
surrounded by THE ENEMY, and I am waging a mighty
battle. I will win too. Lock 'em down ! I see the Feds
are taking fingerprints every time an employee sits
down. If I get my way, it'll include mugshots. All you
sheepherders out there will need to put your pants on.

johns
 
Reply With Quote
 
Adam Russell
Guest
Posts: n/a
 
      01-11-2009, 10:36 PM
Neither link worked for me.

<> wrote in message
news:229607e1-0b2f-4fe0-86a8-...
> http://it.slashdot.org/article.pl?sid=09/01/06/2132247
>
> (notice that they call the locked down execution part "TXT". I don't
> trust anyone who has to resort to [W][O][R][D][G][A][M][E][S] to try
> to sneak stuff like this under the public radar.
>
> From the same page
> http://it.slashdot.org/comments.pl?s...7&cid=26351915
> I am a programmer, and in particular I have studied the Trusted
> Platform Technical Specification documentation. All 332 pages of dense
> technicaleese. There is one particular page I would like to cite. In
> the TCPA Main TCG Architecture v1_1b.pdf on page 277 the documentation
> comes right out and announces the fact it is designed to be secure
> against "rogue Owners".
>
> You are either mistaken, or you're full of crap. The chip is in fact
> designed to lock the computer against the owner. Yes, locks that are
> designed to protect the computer against it's owner will also prevent
> outside attackers from doing things that the owner himself is
> forbidden to do. However that is incidental. A hostile Trusted
> Computing system trying to lock computers against their owners is
> fundamentally different than a system designed to secure computers for
> the owner.
>
> If you really do believe that this is solely intended for the benefit
> of the owner, perhaps you could answer some questions for me.
>
> Why the absolute refusal to implement the EFF's Owner Override
> proposal? It would give the owner full control of his own computer
> while still securing against remote attacks. You could even secure
> against local attackers (other than the owner) by placing adding some
> sort of Owner Authentication element to the Override system.
>
> Or how about my proposal? I merely want a printed copy of the master
> key to my own computer. I merely want the option to buy a computer
> that comes with a printed copy of my master key. (Technical note: I am
> referring to the PrivEK key, and having the option to export the RSK
> key encrypted to the PrivEK would be beneficial for ease and security
> reasons.) Go ahead, explain to why I am absolutely forbidden to know
> the master key to my own computer. Go ahead and explain why they
> absolutely refuse to PERMIT anyone to manufacture any compatible Trust
> Chip that permits the owner to know their own master key.
>
> And best of all, explain to me all of the documented systems and plans
> to REVOKE and (for all practical purposes) brick any chip if they ever
> detect that you have learned the master key locked inside you
> computer, if you ever learn the master key to control your own
> computer, if they ever detect that you have the power and control to
> override any DRM system based on the chip.
>
> And don't even try the line about how this revocation system is "not
> part of the chip itself". The chip was explicitly designed to secure
> the computer against the owner, the chip was explicitly designed to to
> support that revocation system, and the chip's technical documentation
> and design specification explicitly mention this revocation system.
>
> The design specs endlessly list all of the things that the owner MUST
> be forbidden to be able to do, all of the things the owner MUST be
> forbidden to know, the specification even has a section that mandates
> that any owner's data under "non-migable keys" MUST be effectively
> impossible to back up and MUST be irretrievably lost if the chip ever
> dies.
>
> And on and on and on. Yes, the chip was explicitly designed to
> consider the owner to be the enemy. The chip is explicitly designed to
> be secure against "attacks" by the owner. Yes, the current generation
> of chips are relatively vulnerable to physical attack - by the owner
> or by a hostile attacker. However it is fundamentally designed to lock
> against the owner, there is a supplemental specification on how to
> increase the physical security against the owner and how to certify
> hardware as possessing stronger anti-owner physical security, and
> there is mention in the CHIP speck itself and in supplemental
> specifications on how to revoke and lock-out any chip where an owner
> does manage to gain local override control over his own computer.
>
> Yes, there are some people working on Trusted Computing with the
> intent of securing your computer for you, of protecting you against
> remote attackers. However that does not change the fact that the
> system is indeed designed to lock computers against the owner, that it
> is indeed designed explicitly for DRM support, that it is explicitly
> designed to be hostile to the owner, it does not change the fact that
> they COULD design a pro-owner system to secure your computer for you
> without these anti-owner aspects, but that they refuse to permit any
> compatible pro-owner chip that does not also impose these anti-owner
> DRM style enforcement systems as well.
>
> -


 
Reply With Quote
 
Justin
Guest
Posts: n/a
 
      02-01-2009, 03:31 AM
johns wrote:
>> without these anti-owner aspects, but that they refuse to permit any
>> compatible pro-owner chip that does not also impose these anti-owner
>> DRM style enforcement systems as well.

>
> Maybe we are all sick and tired of Computer Assholes.

....

>
> johns


Can't one just get a Core 2 Duo without vPro?
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off



All times are GMT. The time now is 07:07 AM.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44