@_msw_ It's the bad key management and deceptive sales practices around multimedia content that most people hate.
DRM that stopped Google from reading everyone's email would be immensely popular.
@_msw_ Confidential computing is rooted in Trusted computing, not DRM, and bears little resemblance to modern content protection in either objective or design.
But even if it was intended for DRM, that's OK too. Everyone actually loves DRM - when they control the keys.
@blitzclone@0xdbug You'd still be reliant on the CPU vendor to publish the DRTM module. And microcode. And the BIOS FSP. And probably more I'm forgetting about.
@d_olex@Harvesterify Most of those PCRs are for the MLE. Sealing would need a PCR that PPAM can safely use that isn't polluted by other measurements that can change on reboot or update. Remote attestation works either way, but I don't know if local sealing is compatible with current PCR usage.
@d_olex Only for secrets bound to the PCRs holding those measurements, hence my question. I'm too lazy to go look up which PCRs are used by bitlocker and PPAM.
@snare Having the flexibility to get into a position I can't is cheating. So is being injury free or younger than me. How do all these cheaters live with themselves?
@d_olex Lots of things are detectable if you actually check the measurements. Does anyone? The most common workaround for the fragility of local attestation has been to just skip it.
@deviantollam Combined, there are over 35,000 city/state/county government agencies in the US. If they each collect one per day, it would take under 2 years.
@Dave_Maynor You're also going to need the expiration date, but I don't recall the laptops I bought online last year needing anything else. First time purchasing from that retailer too (direct from manufacturer). Caveat: the laptops were shipped to the billing address.
@_markel___@i_zubair_khan Sort of. If it's only one chip, and it can be determined which specific part is broken, that chip could likely be revoked.
But if the cost per key extraction is low, the lag on detection and revocation would be a significant issue.
@halvarflake Because by the time you've hired an engineering team to build and operate the software stack that wasn't included with the custom hardware, it's no longer a retail-level investment.
@ohunt@dinodaizovi@taviso To a reasonable approximation, every signed firmware binary, on every computer and device you own, was compiled on a developer's laptop.
"Build systems" in many cases are not more secure than developer devices. They are developer devices.
@mjg59 As a practical matter, vendors aren't going to do this unless someone is paying for it.
Open Compute has not made a ton of progress on ownership transfer but they strike me as the most likely path to influencing vendors in this direction.