All of lore.kernel.org
 help / color / mirror / Atom feed
From: Robert Millan <rmh@aybabtu.com>
To: The development of GRUB 2 <grub-devel@gnu.org>
Subject: Re: about smartcards (Re: TPM support status ?)
Date: Thu, 20 Aug 2009 22:30:29 +0200	[thread overview]
Message-ID: <20090820203029.GB28050@thorin> (raw)
In-Reply-To: <4A8DADF3.8040109@own-hero.net>

On Thu, Aug 20, 2009 at 10:11:31PM +0200, decoder wrote:
> Robert Millan wrote:
>>> This is wrong. Smartcards of course have a an interface to interact 
>>> with  them.
>>>     
>>
>> Yes, but it's usually just a button or similar.  It doesn't behave like a
>> computer.
>>   
> What I meant is the software interface. There are crypto protocols to  
> interact with a smartcard and they are similar to the TPM protocols.

Ok, I guess we're losing the big picture.  Maybe I should explain what I
have in mind.

We provide free software.  Software which comes with the freedom to modify,
among others.  We want all users to be able to enjoy this freedom.

In order for free software to be usable by everyone, we need it to be a valid
replacement for proprietary software.  For example, if proprietary software
can read a book, we want free software to be able to read this book too.

HOWEVER, when this proprietary software is being authenticated by a TPM, it
can gain ability to open files that free software cannot.  This scheme can
also be used against other proprietary programs, but it can't be used to
favour free software, simply because it would render it unmodifiable (hence
not free anymore).

So, my concern is that TPM makes it possible for certain parties to ban free
browsers, free document viewers, free media players, etc, from accessing
certain files, websites, or resources in general.

My concern is NOT about people using authentication mechanisms.  Smartcards,
fingerprints, passwords, whatever.  I don't care what they're used for.  I
just care that users can use free software and retain the freedom to
modify it.

>> No, you can't.  What you can do is use the smartcard for authentication
>> in a computer that has been previously rigged against its user.  In this
>> case it is the computer which implements DRM, not the card.
>>   
> The TPM module itself does not implement DRM either... It provides the  
> necessary crypto routines, a smartcard does so too.

It's completely different.  A smartcard can't be used by a third party to
coerce you into installing a specific program.  A TPM can be.

>>   "Either you use this TPM to certify you're running Crippleware Reader
>>    2.0 or you can't read this book"
>>   
> You can use a smartcard as well for that purpose. Crippleware Reader 2.0  
> can cryptographically make sure that the smartcard is attached, and  
> refuse to work otherwise.

I don't care if Crippleware Reader refuses to work.  It's a non-free
application, so refusing to work is not to be unexpected.

However, if I use a free reader, this reader can do everything Crippleware
can do, and more.  We can have it send data to a smartcard, have it signed,
then send it to anyone else, etc.  The smartcard has no way to tell if it's
dealing with the non-free program or not.

> And you can make the Smartcard a requirement  
> to read the book.

Without a TPM, the smartcard can be a requirement to *decrypt* the book.  Once
it's decrypted, I can do anything I like with it, like printing, modifiing,
etc, as long as I'm allowed by law (see "fair use doctrine").

-- 
Robert Millan

  The DRM opt-in fallacy: "Your data belongs to us. We will decide when (and
  how) you may access your data; but nobody's threatening your freedom: we
  still allow you to remove your data and not access it at all."



  parent reply	other threads:[~2009-08-20 20:30 UTC|newest]

Thread overview: 83+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-08-19 11:00 TPM support status ? Emmanuel Fleury
2009-08-19 11:51 ` Vladimir 'phcoder' Serbinenko
2009-08-19 12:25   ` Michael Gorven
2009-08-19 12:42     ` Vladimir 'phcoder' Serbinenko
2009-08-19 13:24       ` Michael Gorven
2009-08-19 13:48         ` Vladimir 'phcoder' Serbinenko
2009-08-19 19:49           ` Michael Gorven
2009-08-19 20:13             ` Vladimir 'phcoder' Serbinenko
2009-08-19 14:01         ` Robert Millan
2009-08-19 19:53           ` Michael Gorven
2009-08-19 20:15             ` Vladimir 'phcoder' Serbinenko
2009-08-20 16:17             ` Robert Millan
2009-08-19 14:10         ` Robert Millan
2009-08-19 15:44         ` Isaac Dupree
2009-08-19 17:20           ` Vladimir 'phcoder' Serbinenko
2009-08-19 17:25           ` Duboucher Thomas
2009-08-19 17:39             ` Isaac Dupree
2009-08-19 18:01             ` Vladimir 'phcoder' Serbinenko
2009-08-19 18:36               ` Duboucher Thomas
2009-08-19 18:48                 ` Vladimir 'phcoder' Serbinenko
2009-08-19 20:13                   ` Michael Gorven
2009-08-19 20:25                     ` Vladimir 'phcoder' Serbinenko
2009-08-20  7:38                       ` Michael Gorven
2009-08-20 10:15                         ` Vladimir 'phcoder' Serbinenko
2009-08-20 10:22                           ` Michael Gorven
2009-08-20 10:29                             ` Vladimir 'phcoder' Serbinenko
2009-08-20 16:36                               ` Duboucher Thomas
2009-08-19 20:03               ` Michael Gorven
2009-08-19 20:18                 ` Vladimir 'phcoder' Serbinenko
2009-08-19 14:42     ` Robert Millan
2009-08-19 20:16       ` Michael Gorven
2009-08-19 20:27         ` Vladimir 'phcoder' Serbinenko
2009-08-19 20:33           ` Michael Gorven
2009-08-19 20:34             ` Vladimir 'phcoder' Serbinenko
2009-08-19 20:45           ` Duboucher Thomas
2009-08-20 16:09           ` Robert Millan
2009-08-20 16:17             ` Michael Gorven
2009-08-20 16:13           ` Robert Millan
2009-08-19 14:34 ` Robert Millan
2009-08-19 16:33 ` Duboucher Thomas
2009-08-19 17:04   ` Vladimir 'phcoder' Serbinenko
2009-08-19 18:13     ` Duboucher Thomas
2009-08-19 18:37       ` Vladimir 'phcoder' Serbinenko
2009-08-19 19:16         ` Duboucher Thomas
2009-08-19 19:28           ` Vladimir 'phcoder' Serbinenko
2009-08-19 20:13             ` Duboucher Thomas
2009-08-19 20:22               ` Vladimir 'phcoder' Serbinenko
2009-08-19 20:37                 ` Duboucher Thomas
2009-08-19 20:42                   ` Michal Suchanek
2009-08-19 20:57                     ` Duboucher Thomas
2009-08-19 21:00                       ` Vladimir 'phcoder' Serbinenko
2009-08-19 21:07                         ` Duboucher Thomas
2009-08-19 23:39                         ` Michal Suchanek
2009-08-19 20:44                   ` Vladimir 'phcoder' Serbinenko
2009-08-20  7:40                     ` Michael Gorven
2009-08-20 10:19                       ` Vladimir 'phcoder' Serbinenko
2009-08-19 19:21         ` Michal Suchanek
2009-08-20  7:41           ` Michael Gorven
2009-08-20  7:49             ` Michal Suchanek
2009-08-20  7:52               ` Michael Gorven
2009-08-20  7:59                 ` Michal Suchanek
2009-08-20  8:07                   ` Michael Gorven
2009-08-20  8:20                     ` Michal Suchanek
2009-08-20  8:33                       ` Michael Gorven
2009-08-20 10:21                         ` Vladimir 'phcoder' Serbinenko
2009-08-20 10:58                         ` Michal Suchanek
2009-08-20 11:15                           ` Michael Gorven
2009-08-20 11:24                             ` Vladimir 'phcoder' Serbinenko
2009-08-20 11:38                               ` Michal Suchanek
2009-08-20 13:06                                 ` Vladimir 'phcoder' Serbinenko
2009-08-20 16:31                           ` Duboucher Thomas
2009-08-20 17:47                             ` about smartcards (Re: TPM support status ?) Robert Millan
2009-08-20 18:35                               ` decoder
2009-08-20 19:48                                 ` Vladimir 'phcoder' Serbinenko
2009-08-20 20:02                                 ` Robert Millan
2009-08-20 20:11                                   ` decoder
2009-08-20 20:24                                     ` Vladimir 'phcoder' Serbinenko
2009-08-20 20:30                                     ` Robert Millan [this message]
2009-08-20 20:16                             ` TPM support status ? Vladimir 'phcoder' Serbinenko
2009-08-20 17:50                           ` Duboucher Thomas
2009-08-21 11:42                             ` Michal Suchanek
2009-08-20 16:48             ` Robert Millan
2009-08-20 16:20   ` Robert Millan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20090820203029.GB28050@thorin \
    --to=rmh@aybabtu.com \
    --cc=grub-devel@gnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.