• On BNET: Bag a raise in a recession
June 25, 2008 4:00 AM PDT

Whatever happened to Microsoft's DRM plan?

by Elinor Mills
  • Font size
  • Print
  • 31 comments

Updated 12:00 p.m. Thursday with additional Trusted computing Group comment.

Early this decade, Microsoft weathered unrelenting criticism over a controversial set of technologies known as Palladium, which the company envisioned as creating a kind of secure vault to store passwords or medical records.

Academics warned it could "support remote censorship" and blacklists, likening Palladium to the Soviet Union's efforts to register typewriters and fax machines. Privacy activists predicted it would hand Microsoft "an unprecedented level of control" over the world, and free software doyen Richard Stallman solemnly dubbed it "treacherous computing."

security graphic

It worked, kind of. Microsoft retreated by doing what any large bureaucracy tends to do in response to such a kerfuffle: it gave its problem a new name. Palladium became the awkwardly-titled Next-Generation Secure Computing Base, or NGSCB, (and the group Microsoft coalesced around the initiative changed its name from Trusted Computing Platform Alliance to Trusted Computing Group) and critics mostly moved on to worry about the recording industry and other threats to digital liberties instead.

Since then, the NGSCB--once derided as "nagscab"--has existed in an odd kind of technological purgatory. One report in 2004 said that Microsoft has "killed" NGSCB, which the company quickly denied later the same day. CNET News.com published a story in 2005 quoting Microsoft as saying NGSCB was "still coming."

After six years, the supposed world-striding colossus of a technology that once sparked so much fuss (one reviewer said it might become "either Santa or Satan") is much diminished. NGSCB never did live up to its early promise--or what critics would have said was its early threat as a digital rights management tool that would restrict how people consume content on their PCs and lock them into one vendor.

"It has changed from something that was very revolutionary and grandiose into something much more modest," said Andrew Jaquith, a senior analyst at Yankee Group.

And then came BitLocker
NGSCB does live on, manifesting itself in a Microsoft technology called BitLocker, a Microsoft spokesman confirmed.

BitLocker, Microsoft's only product to come from the Trusted Computing effort, is a feature in Windows Vista Enterprise, Vista Ultimate, and Windows Server 2008 that encrypts the disk drive to protect against data theft or exposure if the computer is lost or stolen. (Trusted Computing should not be confused with Trustworthy Computing, which is Microsoft's effort to improve the security of its own products and is largely considered to be successful.)

While it is useful, BitLocker hasn't taken the computing world by storm yet, or even been enough to justify upgrades to Vista, said Rob Helm of Directions on Microsoft.

"BitLocker hasn't been the rage anybody expected, although there is a strong case for using that feature on laptops," he said. In addition, plenty of third-party products--many offering whole disk encryption--exist.

Bruce Schneier, crypto researcher, author, and chief security technology officer of BT, was one of the more vocal critics when Microsoft first unveiled its Trusted Computing plans in 2002. In 2005, he was still beating the drum, writing that Microsoft was attempting to stall, and possibly get Vista exempted from a best practices document for the Trusted Computing Group that addressed many of the critics' concerns.

The Best Practices Principles (PDF), which was written in 2003 and eventually published in 2005, gives consumers some control over disabling the functionality, allows devices to support multiple users, adds privacy protections, and calls for interoperability and portability of data.

"We were concerned that users were able to opt in and not be controlled from above," said Susan Landau, a distinguished engineer at Sun Microsystems who worked on the Best Practices document after Sun joined the Trusted Computing Group. Sun was not a member of the Trusted Computing Platform Alliance.

"The public criticism certainly created pressure," especially when it conflicted with consumer privacy guidelines in Europe and elsewhere, she said.

"I think it's interesting that the (Trusted Computing Group) technology is continuing, but the big DRM push, so far, has not happened," Landau said.

Putting trust in a module
The centerpiece of the Trusted Computing Group is the Trusted Platform Module, a microcontroller that stores keys, passwords, and digital certificates in a secure, isolated area. They are widely distributed in computers from Dell, Fujitsu, Gateway, Hewlett-Packard, Intel, Lenovo, Toshiba, and others, but most people don't even know they are there. BitLocker makes use of the Trusted Platform Module.

Microsoft has "convinced a lot of hardware manufacturers to put the chips in computers and they're in a lot of computers, but they're not doing anything," Schneier said. "The question is what are they going to do with the chips? How is Dell feeling these days?"

A Dell spokesman did not return a call seeking comment. Even Scott Rotondo, president of the Trusted Computing Group, acknowledges that the Trusted Platform Modules need more applications.

"A lot of them haven't been utilized fully and in some cases not at all," said Rotondo, who works as a senior staff engineer in Solaris Security Technologies at Sun. "The supporting infrastructure has been slow to materialize."

"It stands to reason that there might be frustration on the part of hardware manufacturers," Rotondo said, likening it to a "chicken and egg situation."

"We need to really make use of these things before the hardware manufacturers get tired and take them away," he added.

Trusted Platform Modules "have not yet fulfilled their potential, but Microsoft and other companies are working on it," the Microsoft representative said.

A Trusted Computing Group spokeswoman said on Wednesday that the organization is not focused on DRM and that applications that use the TPM include secure e-mail, multifactor authentication, password management, and single sign-on. The group is also working to extend the concepts of hardware-based security to storage, network security, and mobile devices, she said.

While initial concerns about misuse of the technologies slowed down the group's efforts, people see legitimate uses for the technology, and digital rights management could be among them, Rotondo said. However, any digital rights management systems would have to maintain a proper balance between the rights of the content owner and the rights of the consumer, he said.

Where Microsoft failed in doing that, Apple has succeeded, according to Paul Saffo, a Silicon Valley-based technology forecaster.

"The biggest thing that has changed in the last five years is iTunes and the iPhone," he said. "The companies got their protection and the consumers got the right to purchase individual songs at a price that was less than the cost of the album."

Don't discount Microsoft just yet, warns Ross Anderson, a security engineering professor at the University of Cambridge's Computer Lab and an early critic of the Trusted Computing Platform Alliance.

Asked if the world has been spared a Microsoft digital rights management machine, Anderson responded in an e-mail: "Wrong--WMP (Windows Media Player) and the surrounding stuff that MS hopes will enable it to do to the HDTV market what Apple did for MP3s."

Saffo joked: "It's like a horror movie; they'll be back."

(CNET News.com's Declan McCullagh contributed to this report.)

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Add a Comment (Log in or register) (31 Comments)
  • prev
  • 1
  • next
by Penguinisto June 25, 2008 7:04 AM PDT
So, when the MSFT flack says it'll be like iTunes ("what Apple did for mp3's"), did he mean that it'll be drop-easy to circumvent (like iTunes-purchased music is)? Personally, I think most of what MSFT envisioned died off for two reasons: First, a lot of it died like WinFS did... technically too tangled - even for MSFT - to make workable. The second can be seen as a parallel in Zune. First they tried the ultra-restrictive stuff, then saw that the buying public avoided the product specifically because of draconian measures that treated them like criminals. If MSFT is smart, they'll limit it to as little as they absolutely have to in order to satisfy basic security, and ditch the rest. Of course, this is MSFT, whose customers are no longer the users, but the media conglomerates.
Reply to this comment
by catch23 June 25, 2008 7:53 AM PDT
MS does not DRM stuff. Nor does Apple.
Both offer DRM technology that the owners (well... or copyright holders) of material may apply to their content. It is those folks, not MS, that decides what DRM is attached to the content, what the restrictions are, or how easy you can get around it.
That goes for music, video, or documents, whatever. MS doesn't force you to use Bitlocker. You, the end owner of that HD, makes that choice.

You could argue that Apple and MS are 'enablers' or 'conspirators' in this whole DRM train wreck, but they are not the ones calling the shots
Reply to this comment
by Penguinisto June 25, 2008 8:56 AM PDT
Actually, yes they do. The Zune has (had?) specific DRM built into it that no one can point to a media conglomerate and say "Hey - they asked for this". Also, Palladium came out and was marketed long before the RIAA/MPAA were clamoring for it. Finally, while apple is pushing DRM back (getting media companies to actually agree to sell DRM-less tracks on iTMS), Microsoft is pimping DRM for all its worth on their offerings.
by catch23 June 25, 2008 9:53 AM PDT
Penguinisto, what are you talking about?
Zune has a different DRM (technically), but it offers the very same capabilities as Plays for sure and FairPlay. It is no different, and only attempts to lock you into a Zune instead of locking you into iTunes.
They are the very same beast.
Palladium was more about securing the system and corporate documents. people had been asking for that for a long time.
And again, it was up to the end user (or corporate IT) to use them. MS doesn't DRM anything the owner doesn't want.
by Penguinisto June 25, 2008 1:45 PM PDT
It has DRM. You claimed that "MS does not DRM stuff", when the Zune clearly did exactly that. Your ball...
by Mystakill June 26, 2008 8:25 AM PDT
In addition to Zune, Microsoft also wraps DRM on *everything* distributed on the Xbox Live Marketplace (XBLM), including free items. Anyone with a sizable investment in XBLM content who has replaced an Xbox 360 either has or will eventually experience this most draconian of Microsoft DRM schemes. Those who share a 360 with family, friends, roommates, etc. will run into this sooner because only the purchasing account can access XBLM content on a replacement 360, and only when that account is logged in to Xbox Live.

Having been through four dead 360s (two RRoDs, a dead refurb replacement and a flaky launch system), my family's been locked out of DRM-ed XBLM content for ~6 months in the past couple of years. MS announced an online rights management/transfer tool, to be made available this month, but it's the 26th and they've been suspiciously quiet on this subject since last month.
by ballmerisanape June 25, 2008 8:23 AM PDT
It's in a quiet cell down in the Microsoft dungeon.... right across from Plays For Sure...
Reply to this comment
by catch23 June 25, 2008 8:36 AM PDT
I'm not sure I understand. Plays For Sure is still in heavy use, by content providers like
Rhapsody To Go, Napster To Go, Ruckus Network(to name a few)
and hardware makers like
Archos,Cingular,Creative Labs,iriver,Nokia,Philips,Samsung,Sonos,Sony,Toshiba(again, to name a few)
It doesn't seem to be 'down' anywhere...
by Penguinisto June 25, 2008 8:53 AM PDT
catch23 - you confuse contractual obligations (and the fact that the folks you mentioned have no other choice considering the money and time they put into it) with popularity. ;)
by catch23 June 25, 2008 9:58 AM PDT
Sorry Penguinisto, you simply ignore peoples choices, when someone chooses something you don't like.
Too bad. As FireFox has shown, you make a better product, people will use it. Unfortunately folks like you just whine endlessly when people choose the best solution made my MS...
by Penguinisto June 25, 2008 1:35 PM PDT
Nice try, but you fail it: DRM is a result of contractual obligations with media corps and time/money spent, which has zero to do with popularity. If you want to sit and claim that DRM is popular, please, let 'er rip... it'll be funny to hear the derisive laughter that follows as you try to justify it.
by WJeansonne June 25, 2008 9:07 AM PDT
Stallman is an avowed Socialist. Why even give him a voice with an issue involving e-commerce or capitalism. Anything the capitalist establishment does to protect its property, Stallman would be sure to reject. And as a reminder, this is the founder of the Free Open Source Sofware movement, in case any of you newbies out there are new to the open source model are unaware of it. :-) Hence, he is your leader, lol!
Reply to this comment
by MSSlayer June 25, 2008 9:46 AM PDT
Idiotic as always. The GPL is all about property protection. You can throw words like socialism around if you like and only your fellow shill retards will agree with you, but no one else gives you any credibility at all. Since F/OSS is a billion dollar industry your comments are even more stupid than usual.
by cnetcensorssuck June 25, 2008 1:14 PM PDT
Imbecile!
by Penguinisto June 25, 2008 1:37 PM PDT
Ah, the MSFT astroturf crowd is out in force today... where's Dan? PS: Richard Stallman (and Eben Moglen) did something quite beautiful - they used the law to force freely-given software to remain open and freely-given. Sucks that MSFT can't grok that, or make the concept fit into their decaying business model, doesn't it?
by johnsin June 25, 2008 9:24 AM PDT
I agree, DRM is a mandate that is handed down and or put in place by the content provider/owner. The distributor usually has to adapt a DRM in order to get the license to distribute the content. The only "weird case" of this is will Apple. Since they had their own hardware line.. (like sony).. they pushed for their own DRM.. that way they married the content to their own hardware by using the momentum and leverage of the Labels.. Which was genius.
Reply to this comment
by Penguinisto June 25, 2008 1:42 PM PDT
Even weirder - Apple takes a rather lax view of DRM (as evidenced by an increase in DRM-less music at iTMS, the fact that they haven't litigated against Psystar yet, etc etc...)
by amy.licious June 25, 2008 11:30 AM PDT
idk how top management peeps @ software cos like microsoft made the ludicrous decision to get involved with the music and film industry's problems to begin with?? unrequested 3rd hand software can't solve the probs of the 21st century entertainment industry ~ the only one who can solve these probs is the entertainment industry ~ the cost for their solutions shd be in and on their products and balance sheets and not on unrequested 3rd hand software vendors'
Reply to this comment
by wzrobin June 25, 2008 12:01 PM PDT
Because microsoft, like intel, is betting large on the idea of a HTPC being the central irreplacable home appliance in the future. Might work, might now, we'll see.

What they should have done was continue having a media center version of windows that had the os level drm, but offer a version where you don't have to get microsoft's permission for your hardware to execute a command for people who don't want os level DRM.

But they got greedy, because there long term hope is to make it much more difficult to change software vendors, as stated in one of the articles above, their own goal is to make it too expensive to move away from them in order to preserve their monopoly.
Reply to this comment
by kojacked June 25, 2008 12:53 PM PDT
THUD. That's the sound of all of the FUD people purported about Vista's DRM being so teriible and how that was Microsoft's fault hitting the floor.
Reply to this comment
by DrtyDogg June 25, 2008 1:22 PM PDT
people will still say it.
by Penguinisto June 25, 2008 1:39 PM PDT
Actually, what you heard was the Zune sales figures falling flat on their face. Or it could've been the sound of developers in Redmond fainting in abject disbelief as even their strongest attempts at DRM turned out to be worse than worthless (and indeed - hindered the legit customer more than it ever did the pirate).
by kojacked June 25, 2008 8:43 PM PDT
Peng, I wish you would make up you mind. You've gone on and on in the past about how Vista is DRM laden and now you say the DRM is worthless. If it's worthless then why would it matter if it was DRM laden? Silly Peng; trix are for kids...

How did it exactly hinder legit customers? I buy non-DRM MP3s from Amazon and Vista lets me do what I want with it. I buy DRM tracks from Yahoo and the CONTENT PROVIDER dictates the restriction that Vista enforces. It's YOUR choice on what kind of music you want to buy not Vista's. You might wanna read that a couple of times. Trolls tend to have a hard time accepting reality.
by GrandDuc114 June 25, 2008 1:28 PM PDT
Elinor, I thought you knew better! Microsoft didn't direct the TCG. It was founded by IBM after IBM, HP and others created the first TPM and realized that it wouldn't be accepted by the industry unless ownership of the intellectual property was open. Microsoft had to be convinced to adopt it for anything. Palladium was a renegade program, and it took a lot of jawboning to bring Microsoft back into the fold.

You've mixed all these different things together. The DRM issue, as the TCG spokesperson said, is really outside the scope of what the organization does. TPMs are currently installed on tens of millions of notebooks, but have not been activated on most. When they are, they tend to be used for user-to-client tasks like authentication (when paired with a fingerprint reader), file and folder encryption (through simple apps; BitLocker could be considered an app in this category, but applying to a whole drive), and password management. Some of the more ambitious projects of the TCG, whose membership consists of pretty much everybody in the computer industry, have not come to fruition, primarily because they involve cooperation on a grand scale, and all the necessary players have not been able to achieve that. For example, Public Key Infrastructure (PKI) requires that parties potentially unknown to each other agree to trust a third party. Who should it be? Verisign? Visa? So, in recent years, the TCG has scaled back its ambitions to things that might be done within a single entity, like Trusted Network Connect (TNC), that allows an IT department to manage mobile clients attaching to a network, determining whether the hardware is authorized, the software load is right and up to date, and the person operating the machine has permission to connect.

I think you let your sources lead you down a primrose path and didn't do enough reporting for this article.

Best regards,

Roger Kay
Endpoint Technologies Associates
Reply to this comment
by inachu June 25, 2008 6:08 PM PDT
If we are trusted that well in the near future does that mean we will still have to have that GAME CD in the tray that is mandatory to play?
Reply to this comment
by skswave June 25, 2008 6:45 PM PDT
The Trusted Platform Module is one of the best tools for any enterprise who wishes to increase the security of their network, Reduce the cost to manage the network and improve user satisfaction. Imagine a world where you open your PC Swipe your fingerprint (that never leaves your PC) and then your PC logs you into the services you need to do your job. The TPM is an authentication device that is compatible with all of an enterprises current networking equipment. As a simple policy statement put all of the KEYS for the enterprise's soft certificates into hardware. This simple action assures the neither a user, an admin, or malware can steal the secret keys on an authorized PC. These tools work today and can be deployed on a full enterprise basis. All of the major VPN and Wireless suppliers support the TPM securing thier access keys on Windows PCs.

Lost in the concern about managing content securly, which requires so much more than securing keys, is the discussion of the need to manage access to all of these wonderful internet services. Roger states the point very clearly above.
Focus on the death of userid and password. It is time to send it on the same path as the 5.25 floppy and the serial port mice (and they'll be easier to throw away) A vendor neutral, Industry standard, globally deployed, common mechanism for securly managing keys is of tremendous benefit to all of us and to all of our kids.
So turn on the TPMs, Secure your network Keys, Stop typing in passwords and lets secure the network.

Key benefits of using hardware to secure the keys
Only authorized PCs on your network.
Authentication Keys can't leave the platform they can be deleted but they will never leave
Works with standard networking solutions out of the box but you have to read the manual
Multiple keys from multiple parties can be stored on a single TPM the Owner of the PC is in charge not the owner of the key. (the owner of the key just knows there are no copies of the keys)
Everybody has a TPM your customers, your users, your vendors, your goverment, your regulators...... Imagine the healthcare system with an interoperable authentication scheme. Imagine your healthcare system without common networking like ethernet.


Thanks for your time

Steven Sprague
CEO
Wave Systems Corp.
Member of the trusted computing group
Reply to this comment
by fredfoobar June 25, 2008 7:06 PM PDT
The sad part about TPM is that it is unnecessary. Any security application that uses TPM can be done just as well without it, and applications that supposedly "can't" be done without TPM (such as Trusted Network Connect) really can be done just as well without TPM. That is, how does a particular network know that a mobile client isn't just acting like it has a TPM? Just read Bruce Schneier's writings on security, and you'll understand what "don't trust the client" really means.
Reply to this comment
by ssidner June 26, 2008 1:44 PM PDT
I am deep into financial cryptography and sit on several financial cryptography standards committee. TPM chips are very much on the minds of anyone in this space, in both PCs and mobile devices. While they may not be used not, they will be. They offer the key cryptographic primitives required for authentication and key distribution, the two hardest problems we face. When critical mass is reached, they will be critical to solving the security mess called The Internet.
Reply to this comment
by fredfoobar June 27, 2008 7:10 AM PDT
ssidner: How would TPM help with authentication? Do you mean that TPM is there to simply crunch the numbers to verify (using public-key encryption) a signed document from someone *else*? Or do you mean the TPM contains information that only it knows and cannot be changed, so that someone else on the Internet can authenticate *you*?

In the first case, in which the TPM is used only for performing mathematical calculations to authenticate someone else, it is unnecessary; we already have software to do that, and it is Free as in Free Speech (so many security-expert eyes have looked at the source code already to ensure that it is secure). Sure, TPM may make the calculations slightly faster (being implemented in hardware), but we still don't *need* it, and it doesn't solve any problem.

In the second case, in which the TPM is used to authenticate *you*, well, how would the remote person identify you in the first place? You would have to give out your identity somehow already, say your public key if you use public-key cryptography. Then how would TPM help in this situation? And how can that *not* be done in software already?

You said that TPM "offer[s] the key cryptographic primitives for ... key distribution". What do you mean by that? Key distribution can be and already *is* done without TPM. I fail to see how TPM is necessary.

So no, I don't accept your implicit conclusion that it will solve "the security mess called The Internet". The reliance on TPM is flawed because it requires that we trust the clients, that we assume that everyone is actually using the TPM the way it is designed (remember that the TPM is just hardware, and it takes software between the TPM and the network to make the whole thing work, and if this software is Windows it is almost guaranteed to be buggy in its implementation, or at least most security-minded people would not trust it as they cannot inspect its inner workings to verify that it works as advertised--security through obscurity is false security), but in reality you cannot trust the clients. Read up on Bruce Schneier's works to understand this.
Reply to this comment
by fredfoobar June 27, 2008 7:12 AM PDT
Thanks a lot, Cnet, for turning my paragraph-formatted comment into one big blob.
Let's see if it takes the HTML "br" tag.
by fredfoobar August 7, 2008 11:57 PM PDT
Hmmm, it looks like Cnet fixed their comment system, so now it shows comments as they were written instead of as blobs of text. Good job, Cnet!
(31 Comments)
  • prev
  • 1
  • next
advertisement

S.F. hacker space: Heaven for the DIY set?

The Noisebridge hacker space offers sewing and Mandarin classes, soldering workshops, Internet-controlled front door access, and a server room with no door.
• Photos: Circuits, code, community

The browser battles go on and on

roundup From Firefox to IE and from Chrome to Opera and Safari, there's no sitting still for browser makers looking to keep their products fresh and competitive.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right