What I don't really understand is how this could be used to stop piracy. Sure, you could stop recording on a machine with Intel Management Engine, but wouldn't pirates simply use a computer without Intel Management Engine to rip media?
Unless the media becomes impossible to consume without Intel Management Engine (sounds unlikely, how would you explain that to customers), how does it prevent anything?
> the media becomes impossible to consume without Intel Management Engine
That's why Intel management keeps greenlighting this project. Intel thinks that it if it can convince content producers to distribute media as blobs encrypted with Intel's public key (and maybe, say, Samsung's or Apple's), then we can transition to a world where consumer video files do work on most consumer hardware, but can't be decrypted outside the protected media path and ripped.
There's no reason this scheme can't work. OEMs and content producers just haven't been able to cooperate well enough to piece it together yet. Once they do, game over, except for the analog hole.
This scheme also has the side effect of creating a "moat" around existing OEMs. Sure, a new player can begin fabricating new CPUs, but existing media files won't be encrypted for these CPUs. It is literally a conspiracy against the public.
Dan would later learn that there was a time when anyone could have debugging tools. There were even free debugging tools available on CD or downloadable over the net. But ordinary users started using them to bypass copyright monitors, and eventually a judge ruled that this had become their principal use in actual practice. This meant they were illegal; the debuggers' developers were sent to prison.
In our universe, the "debugging tools" that could defeat this scheme are ones that can depackage an Intel chip and read its EEPROM directly. What do you even use for that, a scanning electron microscope?
Part of me really wants to go into full libertarian cryptoanarchist mode to enable a safe way of doing anonymous Kickstarters for someone to buy that SEM and crack any new DRM that's being thrown at us.
But then I remind myself of this[0] and I realize we'd be probably fighting our own future. Our world is going downhill because it's too uncoordinated, not too coordinated.
But coordination only works when you have 51% or more of the force on the side of the people doing the coordinating, and when you haven’t come up with some brilliant trick to make coordination impossible.
The second one first. In the links post before last, I wrote:
> The latest development in the brave new post-Bitcoin world is crypto-equity. At this point I’ve gone from wanting to praise these inventors as bold libertarian heroes to wanting to drag them in front of a blackboard and making them write a hundred times “I WILL NOT CALL UP THAT WHICH I CANNOT PUT DOWN”
A couple people asked me what I meant, and I didn’t have the background then to explain. Well, this post is the background. People are using the contingent stupidity of our current government to replace lots of human interaction with mechanisms that cannot be coordinated even in principle. I totally understand why all these things are good right now when most of what our government does is stupid and unnecessary. But there is going to come a time when – after one too many bioweapon or nanotech or nuclear incidents – we, as a civilization, are going to wish we hadn’t established untraceable and unstoppable ways of selling products.
It's a pretty big hole, and it's practically impossible to seal. Which is why I don't think we'll ever see "game over" for piracy, no matter how advanced DRM technology becomes.
At this point, I think censoring the internet is the only way for the movies/music industry to win. Sadly this isn't so far fetched.
> it's practically impossible to seal [the analog hole]
It's easier than you think. Look at Macrovision. Look at the EURion constellation. All you have to do is make your secure video path emit some kind of signal not immediately apparent to human eyes. In a post-general-purpose-computing world, you can just make consumer-grade devices respect these signals and refuse to record and make professional-grade equipment both insanely expensive and specifically traceable.
I agree, but my point is this - If you can see it or hear it, then you can record it. Sure, the recording device you'll need in the future might be insanely expensive/rare/illegal, but there's also a lot of money in piracy.
More importantly, why would software be required to engage in all activity by piping through such a hardware interface. I would expect that open source alternatives and virtualization could easily bypass its necessity.
At first glance, dumping the contents of any source media, or capturing network streams properly, should readily provide the raw, unencrypted content data, which is then decoded by an application that has been implemented without use of those particular hardware features.
The goal is that the decoding is done by trusted hardware, not by software keys. So you can run VMs and open source, but they won't have the keys to decrypt the content.
Same deal with HDCP, where PCIe is treated as an unsafe bus, so data goes encrypted from the kernel to the GPU to the display device (something like that).
It's also why sometimes people have trouble watching Netflix or so on, because some part fails. Apple TV + Toshiba TV at my parents' has this problem maybe 1/10 times we try to play.
But you're right that encrypting a million end user devices is pointless if there is even one unencrypted point. No doubt hardware companies, movie companies, and Netflix are already wetting themselves with the prospect of having no unencrypted holes left. Still seems highly unlikely to actually work - piracy finds a way.
Worst comes to worst, pirates will just start modifying legit HD screens to scan image directly from pixels (or pixel controllers) and record audio straight from the digital output and/or speaker hardware.
You can't prevent movies being ripped off without actually DRM-ing human brains. Otherwise there always has to be an unencrypted channel that goes to our eyes and ears.
The goal of DRM is not to kill piracy 100% and anything else is abject failure, it's to raise the cost of engaging in piracy to the point where just buying the movie seems easier and cheaper.
You can say that, but the fact that they do things like HDCP (normal users aren't going to do multi gigabit/s raw captures) would speak otherwise. Engaging in piracy is as simple as a search and download. Unless this tech works 100%, piracy will always remain that easy.
The idea is if only a handful of professionals are uploading high quality rips, then it becomes feasible for law enforcement to investigate and take them down. Sort of like professional DVD pirates where they have actual pressing plants. If everyone is uploading stuff from home, it's harder.
Regardless, they didn't stop at HDCP. Check out Cinavia for an interesting approach to closing the analogue hole.
> the contents of any source media...should readily provide the raw, unencrypted content data
Once this crap becomes ubiquitous, why would companies ship unencrypted bits at all? They could send files encrypted with all the major OEM "protected content" keys. If you're running on non-supported hardware, well, sucks to be you, pirate. I imagine it's rather difficult to extract the private key from DRM hardware.
They already did that, twice. First with DVD which used a weak scrambling scheme that was defeated, then with BluRay which used strong encryption, but people were able to extract the keys. The problem with that scheme is that once any one key leaks, you can't do anything about it, especially not if the key is burned in your CPU. You can't expect everyone to go buy a new Intel CPU each time someone manages to extract a private key.
DVD encryption was the same strength as BluRay, cryptographically. The difference between them are twofold:
1) For DVDs there were only a handful of player keys, like less than 30 if I recall correctly. Once they were all leaked the system was broken forever. AACS as used on BluRay has so many keys and such efficient revocation that each player can have its own key.
2) The BluRay designers realised that AACS by itself was insufficient because it takes time to revoke a key, and if they leak faster than they can be revoked the total quantity doesn't matter much. So they did BD+ as well, which is basically a kind of band-aid to detect emulators using stolen keys.
BluRay security has definitely been more effective than DVD security, especially in its earlier days, but the leak of the HDCP master key was pretty fatal, and eventually (all proprietary) emulators got good enough that BD+ programs couldn't really tell them apart from legit licensed players.
The DRM on the PS3 lasted from 2006 until at least 2010 - and even today, as I understand it, online play is disabled if you refuse a patch that closes the jailbreak security bugs. Perhaps effective DRM is possible, it's just taking a lot of practice.
What's more, in the past media distribution was on physical disks and players weren't on the internet, so software couldn't be upgraded. The future is obviously in downloads and streaming, which will enable a bunch of new things.
Key rotation will be much simpler as vendors can just issue a compulsory automatic upgrade. As a different download can be prepared for every customer, there's no need for keys to be shared by multiple customers. Every download can be watermarked so anything that does get out can be traced to a particular downloader.
So I don't think the failures of the past indicate it's impossible for DRM to ever work.
Unless the media becomes impossible to consume without Intel Management Engine (sounds unlikely, how would you explain that to customers), how does it prevent anything?