ARM Launches Hollywood Approved Anti-Piracy Processor
torrentfreak.com
torrentfreak.com
Actually, no, that's not what Torrentfreak means, because Torrentfreak has no idea what the hell any of those terms mean.
An effective anti-piracy system is a watermark detection routine embedded into the video decoder, so that you can't use hardware acceleration if the device detects the video isn't licensed.
http://lmgtfy.com/?q=trustzone+arm
Read the first PDF on that page.
What's the preferred approach amongst this audience to defend against malware on their platforms?
Make hiding software hard, make reimaging the system easy.
1. Reduce the attack surface, i.e. total LOC. My base system is super small. More complex things can be run on top of it (e.g. via chroot), but the system I boot into is only about 16MB. With some effort, it could be shrunk to about 1/4 of that size.
2. Use only open source software; and refine your methods for searching through code for suspicious things. There's no shortage of open source solutions and folks right here on HN (e.g. Russ Cox) have been kind enough to share some decent methods for efficiently searching through code.
3. Boot from read-only external media, use a memory disk for the root filesystem and use tmpfs for all writable directories/partitions. This way boot times are fast and consistent, more so than with harddisk drives. And with the rootfs in memory, you can remove the external media after booting, freeing up the USB or SD card port for other things. It's very easy to replicate (clone, image, whatever you choose to call it) this system and transfer it to more external media. It takes only a short time to compile from scratch, even on underpowered computers. There is no "software installation". You insert the media and boot. That's it. You get the same pristine system every time you boot.
To anyone who injects doubt and insinuates that such an approach to evading malware as betterunix suggests is infeasible or unachievable: I'm happy to prove you wrong.
Why would you need any cryptography to do this? I have a computer that uses a much simpler, equally effective, and easier-to-use approach: the boot sector cannot be overwritten unless the system is rebooted in a special mode (and the OS cannot be booted in that mode). At least for personal computing, that is far better than a system that forces people to rely on a trusted third party to decide what software they can run.
Is there a real-world case where any bureaucracy has yielded control of individuals' documents to those individuals through the use of trusted computing? Anywhere? In any subject matter? Is there any case where I can submit a documents and then be assured that i can revoke access? Anyone? Bueller?
This is a silly invention for media executives that do not understand (1) their customers or (2) those dedicated to pirating their content.