From: Theodore Tso <tytso@mit.edu>
To: "Cihula, Joseph" <joseph.cihula@intel.com>,
James Morris <jmorris@namei.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"mingo@elte.hu" <mingo@elte.hu>,
"arjan@linux.intel.com" <arjan@linux.intel.com>,
"hpa@zytor.com" <hpa@zytor.com>,
"andi@firstfloor.org" <andi@firstfloor.org>,
"chrisw@sous-sol.org" <chrisw@sous-sol.org>,
"jbeulich@novell.com" <jbeulich@novell.com>,
"peterm@redhat.com" <peterm@redhat.com>,
"Wei, Gang" <gang.wei@intel.com>,
"Wang, Shane" <shane.wang@intel.com>, John Gilmore <gnu@toad.com>
Subject: Re: [RFC v3][PATCH 2/2] intel_txt: Intel(R) TXT and tboot kernel support
Date: Fri, 15 May 2009 08:26:44 -0400 [thread overview]
Message-ID: <20090515122644.GA9173@mit.edu> (raw)
In-Reply-To: <20090515120748.GF6816@mit.edu>
BTW, see this slide set:
http://invisiblethingslab.com/resources/bh09dc/Attacking%20Intel%20TXT%20-%20slides.pdf
For more details about why a TCPA-style solution (referred to in the
slide set as a Static Root of Trust Measurement) doesn't really work
for widespread consumer-usable DRM, where as a Dynamic Root of Trust
Measurement (DRTM) scheme, such as provided by TXT, makes this be a
much more tractable solution.
Also see their early results for attacking TXT via bugs in the SMM
Bios. The one thing which is not discussed much in this slide decks
is the hardware implemented features which lock out the Host OS from
being able to read or modify memory used by the trusted code running
in the secure VM (which must be locked into memory) once the SENTER
instruction is given.
Obviously, yes, it's all under the user's control --- you don't have
to boot a TXT VM image. On the other hand, you don't have to have
access to your on-line banking, medical records, or watch a movie from
Hollywood, and in the future, it might be that running TXT is the only
way to do that. (The argument that it's always under the user's
control is a standard line used by people defending DRM --- after all,
you don't have to listen to the protected music, or watch the
protected movie. It shifts the ground from the question societal
question of "is DRM good for society", to a user freedom question,
which is always true --- of course, user's are also free to boycott
purchases of hardware that enable DRM; that is also their choice.)
- Ted
next prev parent reply other threads:[~2009-05-15 12:29 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-05-08 4:49 [RFC v3][PATCH 2/2] intel_txt: Intel(R) TXT and tboot kernel support Joseph Cihula
2009-05-08 6:53 ` Andrew Morton
2009-05-29 1:02 ` Cihula, Joseph
2009-05-08 9:57 ` Ingo Molnar
2009-05-12 5:26 ` Cihula, Joseph
2009-05-12 9:45 ` Ingo Molnar
2009-05-12 9:55 ` Andi Kleen
2009-05-12 21:01 ` Theodore Tso
2009-05-14 15:52 ` Heinz Diehl
2009-05-15 0:17 ` James Morris
2009-05-15 1:45 ` Cihula, Joseph
2009-05-15 1:51 ` Joe Perches
2009-05-15 2:49 ` Cihula, Joseph
2009-05-28 1:12 ` James Morris
2009-05-15 12:07 ` Theodore Tso
2009-05-15 12:26 ` Theodore Tso [this message]
2009-05-24 19:42 ` Pavel Machek
2009-05-24 19:42 ` Pavel Machek
[not found] ` <E1M8kJQ-0000W3-TE@fencepost.gnu.org>
2009-05-26 2:31 ` Theodore Tso
[not found] ` <E1M9Mig-0003Q4-S1@fencepost.gnu.org>
2009-05-29 9:47 ` Pavel Machek
2009-05-19 20:30 ` Pavel Machek
2009-05-22 16:59 ` H. Peter Anvin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20090515122644.GA9173@mit.edu \
--to=tytso@mit.edu \
--cc=andi@firstfloor.org \
--cc=arjan@linux.intel.com \
--cc=chrisw@sous-sol.org \
--cc=gang.wei@intel.com \
--cc=gnu@toad.com \
--cc=hpa@zytor.com \
--cc=jbeulich@novell.com \
--cc=jmorris@namei.org \
--cc=joseph.cihula@intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@elte.hu \
--cc=peterm@redhat.com \
--cc=shane.wang@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox