
Dr. Ross Anderson of the University of Cambridge has released an excellent andalarming paperon theTrusted Platform Computing Alliance, a three year old consortium founded by Compaq, IBM, HP, Intel, and Microsoft that aims to introduce into the PC industry foundational architectural changes equivalent to what MS just announced with Palladium. In fact, there was quite a bit of griping about the lack of technical detail in Monday’s press coverage of MS’s Palladium initiative. Well, if you want more meat, then you have to go to thesource.
Anderson’s paper actually covers a bit more than just the TCPA, and it’s a must-read. Anderson first takes up the topic of the relative security of “open” versus “closed” approaches to systems-level security. He next uses the TCPA as a real-world example–complete with an ire-raising run-down on how the TCPA will work–to illustrate the importance of the seemingly esoteric arguments that he has just laid out. In the latter part of the paper, Anderson attempts to assess the economic and social impact of the TCPA, concluding that the alliance is not about privacy and secure commerce but about handing an unprecedented level of control over what we watch, read, and hear to a small cartel of copyright and patent holders. Everyone who’s interested in retaining some semblance of our (rapidly shrinking) offline civil liberties in the online world should download this paper now and read the last five pages or so.
One of the more intriguing parts of the paper addresses the inconsistency between the extensive DRM capabilities implicit in Palladium/TCPA and the alliance members’ public opposition to Hollywood on this very issue. (Also, witness MS’s furious backpedaling on the issue of DRM in Palladium in the MSNBC piece: first, they called it the DRM OS, and now their spokesperson characterizes that name as “monumentally stupid.”) Anderson argues as follows:





