04.23.09

Gemini version available ♊︎

The Bill Gates “Security as a Lock-in”: Thy Name is TPM?

Posted in Bill Gates, GNU/Linux, IBM, Kernel, Microsoft, Security, Windows at 3:15 am by Dr. Roy Schestowitz

Ogg Theora
Introduction to “Trusted Computing”:

Summary: Microsoft uses the Windows zombies disaster to promote computing whose operation can be controlled by remote authorities

BASED ON A MEMO that we shall publish one day in the future, Bill Gates intended to use “security” as a lock-in mechanism. It is very common — not just when it comes to Microsoft for that matter — to use “security” as an excuse for seizing greater control. We saw it when comes to OOXML very recently.

It’s no exaggeration to say that Microsoft totally dropped the ball when it comes to security. According to the following new report which stems from Microsoft friend and pusher for software patents in Europe (namely Finjan [1, 2, 3, 4, 5, 6]), even governments are severely impacted by this.

Botnet ‘ensnares government PCs’

[...]

The Cabinet Office would not give details of what the compromised machines had been instructed to do, nor the names of the different government departments that had been infiltrated.

This one particular report mentions Windows, but many similar reports so characteristically do not; they must be too shy. And here we have another new report from a security conference where Microsoft proposes ineffective cure for a disease it created. Microsoft uses this catastrophe to promote TPM, which would have many devastating effects.

Regarding this article, says one person:

The most successful security model would be to deny all Windows computers connection to the Internet. There, all done. No more viruses, no more spam, no more bot nets.

Another says that “this stuff is scary” and the last message explains what Microsoft could be up to.

I don’t mind TPM as long as *I* get to control it. I’ll even be willing to *permit* it to participate in Microsoft’s chain of trust, as long as I can also use it to boot my own OS that *I* trust.

Prediction… As soon as new PCs come with TPM that trusts only Microsoft, we’ll see just how trustworthy that whole business/software model is. It’ll either get cracked, or the market will head in the other direction. It isn’t just Freedom-Heads here, it’s also companies that want to control their own images. Customer-controlled TPM is good for them as well as me. Microsoft-controlled TPM is good only for Microsoft.

As we showed before, IBM may be trying to do the same thing to Linux, so we are appending some information below.
_______
[1] IBM Brings Trusted Computing to Linux

The architecture involves the “Trusted Platform Module” (TPM) chip that provides hardware storage of private keys, making it impossible for hackers to spoof computer systems. Any attempts to hack into the system would change the system code, which could be easily detected. By adding a new feature to Linux, the research team has successfully performed security checks that go above and beyond checking the first few steps in powering on the system, the feature designed by TCG. The new solution validates the operating system kernel and all application software running on the system.      

[2] Cisco, Microsoft, Others Get Together On Security

Microsoft, Cisco Systems and the open-standards Trusted Computing Group each developed their own NAC approaches, which use a variety of software and hardware to boost network security.

[3] Why the world needs openness, not interoperability.

This NAC/NAP lovefest would be laughable if it weren’t such a kick-in-the-teeth to the rest of the industry, enterprise IT, and all Internet users. A Cisco/Microsoft oligopoly stalls implementation, stifles innovation, and makes the network less secure. In this way, Cisco and Microsoft are standing in the way of progress.

[4] Trusted Or Treacherous Computing?

Microsoft describes how to revoke rights to render based on ‘who the user is, where the user is located, what type of computing device or other playback device the user is using, what rendering application is calling the copy protection system, the date, the time, etc.’ Someuch for Microsoft’s you-should-have-control assurances.

[5] The Future of Trusted Linux Computing

TC With User Freedom At Helm. The idea of TC in the Linux world is actually a fairly reasonable one. Providing a root-locked, buttoned down environment that system administrators will be able to control the security of the controlled network and those workstations within it.

With the absence of proprietary code in the mix, users will indeed, find themselves more inclined to trust their own administrators to make the best choices under such a controlled environment.

[6] Root-locked Linux for the masses

Eddie Bleasdale, open source evangelist and the man behind NetProject, has a new plan. Secure, managed desktop computing: Linux for the non-techies.

At the heart of the Trusted Computing Project is a £200 black box, about the size of those funny little Mac boxes, running a root-locked Ubuntu distribution. The user pays an annual fee of £50 for secure support from a proper Linux geek.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

DecorWhat Else is New


  1. Links 30/05/2023: Orc 0.4.34 and Another Rust Crisis

    Links for the day



  2. Links 30/05/2023: Nitrux 2.8.1 and HypoPG 1.4.0

    Links for the day



  3. Gemini Links 30/05/2023: Bubble Version 3.0

    Links for the day



  4. Links 30/05/2023: LibreOffice 7.6 in Review and More Digital Restrictions (DRM) From HP

    Links for the day



  5. Gemini Links 30/05/2023: Curl Still Missing the Point?

    Links for the day



  6. IRC Proceedings: Monday, May 29, 2023

    IRC logs for Monday, May 29, 2023



  7. MS (Mark Shuttleworth) as a Microsoft Salesperson

    Canonical isn’t working for GNU/Linux or for Ubuntu; it’s working for “business partners” (WSL was all along about promoting Windows)



  8. First Speaker in Event for GNU at 40 Called for Resignation/Removal of GNU's Founder

    It’s good that the FSF prepares an event to celebrate GNU’s 40th anniversary, but readers told us that the speakers list is unsavoury, especially the first one (a key participant in the relentless campaign of defamation against the person who started both GNU and the FSF; the "FSFE" isn't even permitted to use that name)



  9. When Jokes Became 'Rude' (or Disingenuously Misinterpreted by the 'Cancel Mob')

    A new and more detailed explanation of what the wordplay around "pleasure card" actually meant



  10. Site Updates and Plans Ahead

    A quick look at or a roundup of what we've been up to, what we plan to publish in the future, what topics we shall focus on very soon, and progress moving to Alpine Linux



  11. Links 29/05/2023: Snap and PipeWire Plans as Vendor Lock-in

    Links for the day



  12. Gemini Links 29/05/2023: GNU/Linux Pains and More

    Links for the day



  13. Links 29/05/2023: Election in Fedora, Unifont 15.0.04

    Links for the day



  14. Gemini Links 29/05/2023: Rosy Crow 1.1.1 and Smolver 1.2.1 Released

    Links for the day



  15. IRC Proceedings: Sunday, May 28, 2023

    IRC logs for Sunday, May 28, 2023



  16. Daniel Stenberg Knows Almost Nothing About Gemini and He's Likely Just Protecting His Turf (HTTP/S)

    The man behind Curl, Daniel Stenberg, criticises Gemini; but it's not clear if he even bothered trying it (except very briefly) or just read some inaccurate, one-sided blurbs about it



  17. Links 29/05/2023: Videos Catchup and Gemini FUD

    Links for the day



  18. Links 28/05/2023: Linux 6.4 RC4 and MX Linux 23 Beta

    Links for the day



  19. Gemini Links 28/05/2023: Itanium Day, GNUnet DHT, and More

    Links for the day



  20. Links 28/05/2023: eGates System Collapses, More High TCO Stories (Microsoft Windows)

    Links for the day



  21. IRC Proceedings: Saturday, May 27, 2023

    IRC logs for Saturday, May 27, 2023



  22. No More Twitter, Mastodon, and Diaspora for Tux Machines (Goodbye to Social Control Media)

    People would benefit from mass abandonment of such pseudo-social pseudo-media.



  23. Links 28/05/2023: New Wine and More

    Links for the day



  24. Links 27/05/2023: Plans Made for GNU's 40th Anniversary

    Links for the day



  25. Social Control Media Needs to be Purged and We Need to Convince Others to Quit It Too (to Protect Ourselves as Individuals and as a Society)

    With the Tux Machines anniversary (19 years) just days away we seriously consider abandoning all social control media accounts of that site, including Mastodon and Diaspora; social control networks do far more harm than good and they’ve gotten a lot worse over time



  26. Anonymously Travelling: Still Feasible?

    The short story is that in the UK it's still possible to travel anonymously by bus, tram, and train (even with shades, hat and mask/s on), but how long for? Or how much longer have we got before this too gets banned under the false guise of "protecting us" (or "smart"/"modern")?



  27. With EUIPO in Focus, and Even an EU Kangaroo Tribunal, EPO Corruption (and Cross-Pollination With This EU Agency) Becomes a Major Liability/Risk to the EU

    With the UPC days away (an illegal and unconstitutional kangaroo court system, tied to the European Union in spite of critical deficiencies) it’s curious to see EPO scandals of corruption spilling over to the European Union already



  28. European Patent Office (EPO) Management Not Supported by the EPO's Applicants, So Why Is It Still There?

    This third translation in the batch is an article similar to the prior one, but the text is a bit different (“Patente ohne Wert”)



  29. EPO Applicants Complain That Patent Quality Sank and EPO Management Isn't Listening (Nor Caring)

    SUEPO has just released 3 translations of new articles in German (here is the first of the batch); the following is the second of the three (“Kritik am Europäischen Patentamt – Patente ohne Wert?”)



  30. German Media About Industry Patent Quality Charter (IPQC) and the European Patent Office (EPO)

    SUEPO has just released 3 translations of new articles in German; this is the first of the three (“Industrie kritisiert Europäisches Patentamt”)


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts