Skip to main content
One Key to Rule Them All

So, “Can you trust a convicted monopolist?”

It was that man with the red hat and the big beard speaking, Alan Cox, Lead Linux Kernel Developer at Net Project’s ‘Trusted Computing Master class’ in London last Thursday.

What was being discussed was a vision of the future involving a new kind of hardware, cryptographic chips, which when incorporated into a Personal Computer, will permit only approved and validated software to run against ‘Trusted Information’. This new architecture, specified by the Trusted Computing Alliance of Intel, HP, Microsoft and IBM is fast becoming a reality and represents a fundamental component of Microsoft’s plans for the future of the Windows Operating System.

While a new framework of trust is essential, if this industry is to move forward and create a real foundation for an information economy, many people have concerns over digital rights management (DRM) and the ability to control access to software through licensing enforcement. “Inconvenient if the software controlling a life support machine expires”, says Alan Cox, suggesting that we need to think very seriously about the legislation that while protecting intellectual property, allows companies to switch-off software “Without due process and legal review”.

But while DRM is an important piece of the trusted computing puzzle, the largest part involves the question of who determines trust. With on-chip processors and greater protection, who owns the keys and who says what can and cannot be executed on a device? Will it be Microsoft with its new Palladium architecture and if so, asks Cox, “Even if I trust Microsoft, what about all the people they work with? This is a big deal in places like China and Saudi Arabia”.

Key ownership is everything”, says Cox and borrowing from Lord of the Rings, added: “One Key to rule them all and in the darkness bind them.”

But perhaps we’ve got it wrong. Certainly, since I wrote my last column on Microsoft’s Palladium strategy in CW360, I have revised my own opinions after spending some time with their security team and speaking with both Mike Nash, their vice president of security and John Manferdelli, the General Manager of the Windows Trusted Platform Technologies.

It was Manferdelli’s job to argue Microsoft’s corner against Alan Cox and he painted a rather different picture of Microsoft’s plans for trusted computing than those that many people suspect they might have.

Listen” he said, “Palladium is about machine integrity” and not about Microsoft controlling the keys to everyone else’s content. “We’re reluctant to depend on what we don’t trust and today’s PCs were not designed with security as a priority”.

Simply stated, Palladium, like the license management in Windows Media Player, is a concept that can be turned on or off by the user. It offers a secure execution environment but according to Manferdelli, the four important ‘Trust’ elements to consider when it’s turned on are:

• You know who or what it is and it’s not an impostor
• You know its state and it has been properly initialised
• You know that it can’t be tampered with
• You know that your communications with it are private and tamper proof

Palladium appears to represent a way of escape from many of the risks that surround today’s computing and it can only work with the commitment of the entire industry, towards the development of a new trusted computing architecture. And yes, there are many issues to be resolved where trusted relationships and keys are concerned but I don’t have a feel for some kind of sinister plot involving Palladium, Microsoft and the entertainment industry.

If we’re honest, the industry is in a huge mess of its own making and times are likely to become worse before they become better, as each month sets a new record of security breaches in one form or another. As I write this column, I can see an attempt to scan my own system from the Internet and I would much prefer a future without spam and the constant risk of information theft. If, as Manferdelli suggests, Palladium offers an answer, then that’s fine by me and if the Open Source community can do better, then let market forces decide on what the shape of trusted computing will be in five years. It has to be better than an atmosphere of little or no trust at all, which is what we have today.


Popular posts from this blog

Mainframe to Mobile

Not one of us has a clue what the world will look like in five years’ time, yet we are all preparing for that future – As  computing power has become embedded in everything from our cars and our telephones to our financial markets, technological complexity has eclipsed our ability to comprehend it’s bigger picture impact on the shape of tomorrow.

Our intuition has been formed by a set of experiences and ideas about how things worked during a time when changes were incremental and somewhat predictable. In March 1953. there were only 53 kilobytes of high-speed RAM on the entire planet.

Today, more than 80 per cent of the value of FTSE 500* firms is ‘now dark matter’: the intangible secret recipe of success; the physical stuff companies own and their wages bill accounts for less than 20 per cent: a reversal of the pattern that once prevailed in the 1970s. Very soon, Everything at scale in this world will be managed by algorithms and data and there’s a need for effective platforms for ma…
The Mandate of Heaven

eGov Monitor Version

“Parliament”, said my distinguished friend “has always leaked like a sieve”.

I’m researching the thorny issue of ‘Confidence in Public Sector Computing’ and we were discussing the dangers presented by the Internet. In his opinion, information security is an oxymoron, which has no place being discussed in a Parliament built upon the uninterrupted flow of information of every kind, from the politically sensitive to the most salacious and mundane.

With the threat of war hanging over us, I asked if MPs should be more aware of the risks that surround this new communications medium? More importantly, shouldn’t the same policies and precautions that any business might use to protect itself and its staff, be available to MPs?

What concerns me is that my well-respected friend mostly considers security in terms of guns, gates and guards. He now uses the Internet almost as much as he uses the telephone and the Fax machine and yet the growing collective t…

Civilisational Data Mining

It’s a new expression I haven’t heard before. ‘Civilisational data mining.’

Let me start by putting it in some context. Every character, you or I have typed into the Google search engine or Facebook over the last decade, means something, to someone or perhaps ‘something,’ if it’s an algorithm.

In May 2014, journalists revealed that the United States National Security Agency, the NSA, was recording and archiving every single cell-phone conversation that took place in the Bahamas. In the process they managed to transform a significant proportion of a society’s day to day interactions into unstructured data; valuable information which can of course be analysed, correlated and transformed for whatever purpose the intelligence agency deems fit.

And today, I read that a GOP-hired data company in the United States has ‘leaked’ personal information, preferences and voting intentions on… wait for it… 198 million US citizens.

Within another decade or so, the cost of sequencing the human genome …