October 15, 2003

When automated trust goes wrong, we will all suffer

One session from Digital ID World was on trusted computing. Cory Doctorow gave an impassioned and rapid-fire defence of the balance between fair use and content creator rights. The core was an attack on remote attestation, and in particular a recap of the recent EFF paper on the provision of an “owner over-ride” to allow fake attestations. The clearly spoken (if somewhat stiff-mannered) Peter Biddle from Microsoft avoided head-on engagement on the issue.

To me, both missed the biggest issue, and the one that would really gather political attention in a way that fair use doesn’t. If NGSCB takes off, some time around 2008 we can look forward to MSBlast.NGSCB, which will take advantage of some “trusted” (but flawed) code, and generally causes mayhem by reproducing fast (totally trusted, remember!) and will be hard to squash.

Remote attestation is, in the awkward new terminology, a homeland security problem.

Posted by Martin Geddes at 10:54 PM
Trackback Pings

TrackBack URL for this entry:
http://www.telepocalypse.net/cgi-sys/cgiwrap/mgeddes/MT/mt-tb.cgi/19.

Comments
No comments.
Please enter your comment below. Your comment will not appear immediately -- they all go for pre-approval by me because of the volume of spam I receive.







Remember personal info?