• [^] # Re: Trusted computing = remote attestation= windows drm obligatoire

    Posté par . En réponse à la dépêche TCPA/TPM : la déferlante silencieuse. Évalué à 2.

    Quelles sont tes sources ?
    Je te donne les miennes:
    http://www.google.fr/search?q=site:trustedcomputinggroup.org(...)
    Tu y trouveras un document IBM de 2004 comment il est possible aujourd'hui de faire du remote attestation pour des web services !
    https://www.trustedcomputinggroup.org/news/articles/rc23363.(...)

    How we measure: A measurement is
    implemented as the computation of the
    160bit result of a SHA1 hash function (fin-
    gerprint) applied to the file that contains
    data or executables loaded into the run-
    time. The slightest difference in a data file
    will generate a distinguished fingerprint
    and, hence, variations in programs (e.g., due
    to viruses or Trojan horses) are easily de-
    tected by differing measurement values.

    Si tu stockes l'identifiant de chaque élément de la config matérielle dans un des files cité ci-dessus, alors ces identifiants seront hashés par le TPM.


    the
    attested system returns its current list of
    measurements (in the order they where col-
    lected) and a quote from its TPM including
    the random number RN. The TPM will
    quote its PCR registers by signing them
    with a 2048bit RSA signature key

    Contrairement à ce que tu prétends dans de nombreux messages, ce n'est pas un hash de tous les hash qui est envoyé. Mais bien chacun des hash, donc il est possible d'identifier chaque élément séparément.

    dans
    https://www.trustedcomputinggroup.org/specs/bestpractices/Be(...)
    a significant portion of the providers of a particular
    service could use their market clout (the fact that they constitute a majority of
    providers of that particular type of service) to essentially force the use of TCG
    technology. As a consequence, users who do not choose to employ TCG technology
    would be essentially unable to access that service.
    10
    The TCG believes that such
    behaviors are inappropriate uses of the TCG technology. The use of coercion
    to effectively force the use of the TCG-enabled capabilities is not an
    appropriate use of TCG technology. However, preventing potentially coercive and
    anticompetitive behavior is outside the scope of TCG.

    Tu es plus royaliste que le roi: meme TCG avoue officiellement que la remote attestation à des fins de bloquer les utilisateurs de certaines configurations est rendue possible !
    Hors sans puce de type TPM, cette horreur est impossible !