What does it mean? It's some form of DRM pitch?
What does it mean? It's some form of DRM pitch?
Plenty of room for backdoors and other shenanigans in there. Which kind of undermines the entire claim...
Here's a blog post with some details: https://blog.jms.id.au/2015/07/openpower-firmware-stack/
The BMC firmware we're currently working on at IBM (based off some work by Facebook) is at https://github.com/openbmc/openbmc.
[Disclosure: IBM Power Systems. Opinions my own.]
To use CAs as an analogy. Intel, and most chip manufactures, when they describe DRM, they mean generalized consumer DRM, so basically how your browser or OS comes with a list of CAs pre-installed. The DRM pitch here is the ability to write your own DRM, e.g. like having your own internal CA.
This has a use case. DRM can be useful for things like governments and companies. While dangerous from a civil liberty perspective on consumer hardware, it's perfectly reasonable for an organization to want a DRM solution that they control entirely. As an example such a solution could prevent the IT guy (re: Snowden) from stealing your files.
It's a BS claim. IBM has only developed one CPU for high-assurance security:
https://domino.research.ibm.com/library/cyberdig.nsf/papers/...
POWER is an insecure processor like the rest. The software on it will likewise have the same problems as the rest. The difference they're advertising is that there's more open code. This reduces the unknowns for users, gives them more control over their own boxes, and improves security a bit. There's still black boxes in there including one I didn't know about per one commenter in this thread. You can trust the hardware and any firmware left about as much as you can trust IBM's management in that division. Yeah, it gave me pause too.
So, let's change it to "less DRM" and "more open than x86." If you want an open ISA, looked at RISC-V or SPARC (esp Leon3 or OpenSPARC T2). If you want a more secure ISA, look at crash-safe.org, Cambridge's CHERI processor (also open), System/38 (still exists), or even old Burroughs B5000 from 1961. In such light, "Open"POWER is neither truly open nor secure even if better than x86.
There are other architectures that could be candidates for an owner-controllable system (see https://www.raptorengineering.com/TALOS/op_twbx86.php for a review of some other alternatives), but POWER8 is currently the one that can be competitive with x86-64 and could realistically build today.
So, I think it's a misleading label. "Secure" workstation has a meaning that goes way back. In isolation, it has an established meaning. They should just say open and/or DRM-free as that's intended meaning.