838 karma · joined August 9, 2011
Never
I've also seen this on a 2020 Intel MacBook Air. I assumed it was a Big Sur issue but had never tried it on Catalina.
Sniffing from the command line did pick up the correct channel: https://unix.stackexchange.com/a/49317/36875
Just that much should be terrifying for anyone who's read The Three-Body Problem and its sequels.
... if you need to circumvent a DRM for personal use, you are now liable for criminal penalties. Traditionally, for many jurisdictions, circumventing DRM is typically reserved for civil penalties. Criminal penalties implies that the government would foot the bill for enforcement. In civil cases, it is typically rights holders that go after individuals."
Except that here's the actual text:
> Each [7] Party [US/SG/MX/NZ/PE/JP/BN/AU/CL/MY propose: shall] [CA propose: may] provide for criminal procedures and penalties to be applied where any person is found to have engaged willfully and for purposes of commercial advantage or financial gain in any of the above activities.
That doesn't sound like "if you need to circumvent a DRM for personal use, you are now liable for criminal penalties" to me.
Creating key hierarchies under the SRK that can be duplicated or moved is actually very clearly specified in the TPM 2.0 spec, and is at least partially meant for exactly this sort of recovery process. The seed that's used to derive the SRK itself will still never leave the TPM, so any keys that are in a separate hierarchy under the SRK (instead of the imported base key) are still secure.
https://www.trustedcomputinggroup.org/resources/tpm_20_libra...
EDIT: I misread the article on how the bug was actually handled, and that it was fixed five years after it was reported, not that it took five years to apply the patch. However, it still is easier for the library maintainers to use a workaround than to patch the browser itself, especially when legacy versions still need to be supported.