Can you trust "trusted computing"?

TechRepublic

COMMENTARY--The PR about trusted computing is that it will enable more secure data storage, online business practices, and online commerce transactions, all while protecting privacy and individual rights. Our opinion columnist begs to differ on that last part.

The necessity of providing adequate security for computers and networks while maintaining full functionality is a familiar one to today's IT professionals. There must be free and easy access to resources by authorised users and ONLY by authorised users. Of course, with every security measure comes a certain overhead. Having a lock on a physical door necessitates having and safeguarding keys, which in turn necessitates the making and management of keys and a backup plan for lost keysâ€"or, more closely related to passwords and encryption, giving out the combination to the lock and ensuring that only the right people have that combination.

While it's a lot easier to have no lock, just a door that can be opened and entered, that isn't very secure for the storage of valuables. It's the same with securing a network. Whether it's a firewall that snoops through packets before allowing passage, or encrypting/decrypting files, or even just passwords on user accounts, there's a time delay and a requirement to manage the details of the process.

But consider what would happen if there were a second lock on the door that only the police or a neighborhood association representative could open. Consider also that this third party had "your" lock mastered to accept their key too. What kind of agreement would it take for you to feel confident that this third party would not walk into your house at any time and check your belongings against your receipts to make sure that you bought them? What kind of agreement would it take for you to believe that this third party would always be available to open the door upon your request? How about: None! There is no agreement that any rational person would accept in these situations. And yet, that is exactly what is planned for your computer(s).

Some definitions
TCPA (Trusted Computing Platform Alliance): Formed by Compaq, HP, IBM, Intel, and Microsoft, this alliance was formed to work on "creating a new computing platform for the next century that will provide for improved trust in the PC platform." This organisation gave rise to TCG.

TCG (Trusted Computing Group): This is an "industry standards body" that will "develop and promote open industry standard specifications for trusted computing hardware building blocks and software interfaces across multiple platforms, including PCs, servers, PDAs, and digital phones. This will enable more secure data storage, online business practices, and online commerce transactions while protecting privacy and individual rights." (Clearly, the word "trust" is defined in a special and unusual way here; the standard layman's definition is not accurate.)

Palladium: Microsoft's implementation of TCPA/TCG standards. Palladium is Microsoft's code name for an evolutionary set of features for the Windows operating system. A Microsoft press release says, "Combined with a new breed of hardware and applications, these features will give individuals and groups of users greater data security, personal privacy, and system integrity."

NGSCB (Next Generation Secure Computing Base): This is merely the new name for Palladium. It is harder to pronounce ("enscub"), which is possibly a deterrent to discussing it.

"Fritz" chip: Named after U.S. Senator Fritz Hollings, the main proponent of enabling (requiring?) "TC" standards as the law of the land in the United States. (To avoid confusion in this article, both TCPA and TCG will be lumped under the term "TC." It's mostly a cosmetic difference, anyway.)

In a nutshell
What happens with TC is this: Most of the larger and many of the smaller makers of hardware and software will begin producing chips and applications that mutually support a TC standard that includes requiring digital signatures for every file opened on a computer. A computer with an enabled Fritz chip will take control of the machine right from boot-up. At every stage of the boot process, the TC-coded Fritz chip will check and verify compliance with TC standards, from BIOS to starting up services and devices. There will be a table stored internally with a list of TC-approved hardware, and if a device is not present on that list, it might as well not be on the Hardware Compatibility List. All software must have an approved digital signature and an unexpired/non-revoked serial number, or it will not start up. Any "significant changes" to the state of the machine (new hardware or applications) will require going online and recertifying those changes even if those changes are all in TC-compliance.

You will have only two boot results possible: Either a computer that has passed examination by a resident intruder or a machine that will not even work until it's reregistered and passes an online examination. If it passes, a software-based watchdog will take the leash after the boot is completed. If it doesn't pass, someone will know exactly who you are and why your machine is out of compliance.

Depending upon the exact definition of "significant changes," this could amount to an insane Admin overhead level just to get a PC up and running after replacing a NIC. If nothing else, you'll have to "flash" frequently to update the approved hardware list or face failure to boot even after making NO changes at all.

Consider that any system does occasionally get things just a little tiny bit wrong. Hope that this isn't just one more complication when a mission-critical server starts chugging badly and needs attention. "The five nines" (99.999 percent reliability or <5.2 minutes downtime per year) could become a nostalgic memory. At this point, it's not clear exactly what effect the Fritz chip and TC standards will have on hot-swapping server components or hot-plugging USB/FireWire devices. One could hope that changing the state of the machine a bit after the boot sequence wouldn't gum things up. One would also expect that since a major motive behind TCPA was to enforce DRM (digital rights management), that any perceived possible "sidestep" would sound the shutdown alarm in the Trusted OS.

Advertisement

Talkback 4 comments

    George Orwell's 1984 was a tad ...Keith Styles (An irate user) -- 15/10/03

    George Orwell's 1984 was a tad early, but my god, it's well under way if we allow this nonsense to propagate.

    here comes the m$ concept of s ...The Supreme Fool. -- 15/10/03

    here comes the m$ concept of secure - something that they are paid to remotely control through the fee for the licance. the concept of another, forign, entity having any authority on my pc is not acceptable. i have worked hard to get my pc and it's respective gateway semi-secured, and i dont want m$ stuffing it up.

    fact: microsoft does not understand security.

    NO: I noted with interest tha ...Anonymous -- 16/10/03

    NO: I noted with interest that in the related stories there was a heading "IS Microsoft Trustworthy". My experience from the night of the 15th Oct 03 tells me that a lot of companies still have to earn the trust of consumers, Microsoft included.
    My Experience: I purchased a new computer for my daughter with Windows XP Home installed. Given all the holes found in XP, I wanted to download and burn the various partches to a CD so the new computer would be reasonably secure before she went back on the WEB. I am running a trial full version of a very popular firewall. All the features are fully operational including the Privacy section. Microsoft does not like this type of program as it stops them from access your computer for information through COOKIES. We are told that most cookies are benign.
    The actions I followed were I went to the MS Technet page and did a search for all the patches for XP. I proceeded to go to the first link and went through to the page where the download link presided. When I clicked on the download link the next screen was an eye opener. It said "You are not authorised to view this page" and "You might not have permission to view this directory or page using the credentials you supplied". I did not know I had supplied any credentials. I had an aspect in the firewall program blocking 3rd, i say again, 3rd party cookies. As soon as I unblocked the 3rd party cookie option I can download the files. SO Microsoft is using cookies to retrieve information from your computer without your knowledge. Is Microsoft allowed to HACK into computers with impunity? They may only "hack in" when you go to their site BUT how many of the world's computer users are having to go to their site to retrieve patches to plug holes in the dike. I did not have fill in a box with my details in order to download the XP Patches.
    I hope this raises other people's awwareness that cookies from Microsoft are NOT benign and they for one are not to be trusted. What about our privacy. There is federal legislation in Australia supposely to protect our privacy. You cannot take or do things by stealth.

    The Firewall Anonymous -- 01/05/07

    I would love to know what was the firewall you were using!

Add your opinion

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Jacquelyn Holt G'Day USA: Aussie start-ups head to America
    The G'Day USA: Australia Week campaign today announced the finalists for the Innovation Shoot Out event, which will see eight Australian technology start-ups travel to San Francisco in January 2010 to demonstrate the commercial viability of their products in the US.
  • Array All I want for Xmas is Telstra pricing
    Five consecutive days without broadband has led me to what seemed at the time to be an act of desperation: contemplating signing up for Telstra's 100Mbps cable modem service.
  • Array Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • More blogs »

Tags

Back to top

Featured