[extropy-chat] FWD (SK) RFC: copy protection report

Eugen Leitl eugen at leitl.org
Thu Dec 1 17:44:55 UTC 2005


On Thu, Dec 01, 2005 at 09:24:12AM -0800, Adrian Tymes wrote:

> And even then, expect to be cracked eventually.  The fundamental
> problem is, your software is operating on the user's computer, which is

Assuming, it's not palladium-plated, or nagscabbed. The XBox
key was only snarfed because bus traffic was in clear. If
the lane between CPU and chipset is encrypted, or if the key
resides within the CPU itself and executes cypher the 
user never sees plain in the first place. Debuggers and
emulators are useless, because they a) never see plain b)
don't know the secret which the executable is keyed to. 
Exploits *could* still work, but not necessarily.

Of course this means "your" computer is no longer yours, and
by default doesn't trust you and keeps secrets from you. 
I'm sure they'll try selling you real estate in Brooklyn, next.

> completely under the user's control.  You're not shipping a black box

Don't act too paranoid, but they're changing it *right now*.

-- 
Eugen* Leitl <a href="http://leitl.org">leitl</a>
______________________________________________________________
ICBM: 48.07100, 11.36820            http://www.leitl.org
8B29F6BE: 099D 78BA 2FD3 B014 B08A  7779 75B0 2443 8B29 F6BE
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
URL: <http://lists.extropy.org/pipermail/extropy-chat/attachments/20051201/8b1188e5/attachment.bin>


More information about the extropy-chat mailing list