[52061] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

RE: TPM & disk crypto

daemon@ATHENA.MIT.EDU (Kuehn, Ulrich)
Thu Oct 12 09:43:50 2006

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Tue, 10 Oct 2006 18:28:46 +0200
in-reply-to: <452B243A.5090802@echeque.com>
From: "Kuehn, Ulrich" <Ulrich.Kuehn@telekom.de>
To: <jamesd@echeque.com>, <cryptography@metzdowd.com>

> From: James A. Donald [mailto:jamesd@echeque.com]=20
> Sent: Dienstag, 10. Oktober 2006 06:40
>=20
> What we want is that a bank client can prove to the bank it=20
> is the real client, and not trojaned.  What the evil guys at=20
> RIAA want is that their music player can prove it is their=20
> real music player, and not hacked by the end user. Having a=20
> system that will only boot up in a known state is going to=20
> lead to legions of unhappy customers who find their system=20
> does not come up at all.
>=20

Who is "we"? In the case of my own system I payed for (so speaking for =
myself) I would like to have such a mechanism to have the system prove =
to me before login that it is not tampered with. The TCG approach does =
not provide this. Oh, and predetermined means that the machine admin can =
declare to which known state the system is going to boot.=20

>From a company point of view it might be interesting to make sure the =
employees have systems that come up to a predetermined state, or not at =
all, so when infected this turns up at next boot so that the admin can =
fix it.
Here the TCG approach would also be helpful as the remote attestation =
against a central server (or a number of them) can help.=20

And for the RIAA guys, they have no business on the machine I did pay =
for (!), as long as I do not infringe their copyright. Assumed innocent =
until proven guilty! On the other hand, there has been an infamous =
record company that miserably failed  to ensure their components on =
consumers' computers are _not_ a security risk.=20

Ulrich

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post