Even windows secure boot doesn't provide protection against a targeted attack, but conceivably a combination of EFI secure boot and a bug-free well implemented OS (heh) could provide enough protection for DRM on video content, basic enterprise computing (with non-hostile users), etc.
I still think none of this crap really belongs on the client; it is however an awesome fit on the server, which is an area people haven't really explored enough.
They need to make the value spread between pirate and legit as wide as possible, but rather than making better DRM (to make pirated sw less useful, but also make legit software less useful), IMO they should just focus on making legit software fundamentally more useful when legitimately licensed. I know Steam essentially got me to stop pirating games by integrating their social features, easy library management, etc. Mac App Store sort of does that for most Mac software, too. But there's also the issue of price point -- even if I bought every game I wanted, that's probably <$1000/yr. It's easy to consume >$1000/yr in movies/tv, music, and "internet content", and even easier to pirate, with less value on top of the raw content.
Agreed. I remember reading an IBM research paper about combining TPM and virtualization on the server, and getting excited about the possibilities. I wonder what happened to that project.
EDIT: found it! http://domino.watson.ibm.com/library/cyberdig.nsf/papers/442...
Intel also had some demo stuff, but the problem is Intel's security software group was kind of a revolving door spinning at a 3-6 month rotational speed.