RE: [RFC v3][PATCH 2/2] intel_txt: Intel(R) TXT and tboot kernelsupport

From: Cihula, Joseph
Date: Thu May 14 2009 - 21:45:44 EST


> From: James Morris [mailto:jmorris@xxxxxxxxx]
> Sent: Thursday, May 14, 2009 5:18 PM
>
> On Tue, 12 May 2009, Theodore Tso wrote:
>
> > So we should expect a certain amount of controversy and people
> > lobbying to resist the acceptance of this patch.
>
> FWIW, here's my response to an earlier private enquiry from John on the
> topic:
>
> I'd prefer discussion to be public, so I don't mind leaving more
> detailed discussion to that.
>
> There has been considerable discussion on the issue, following Linus'
> statement (which I'm sure you're aware of):
>
> http://marc.info/?l=linux-kernel&m=105115686114064&w=2
>
> My position is similar -- people can decide for themselves whether they
> want to use DRM technology. I'm also confident that technical measures
> taken to prevent real freedom will always be broken (when have they ever
> not been?)
>
> I also feel there may be genuinely useful applications of some of the
> technology (e.g. sealing disk encryption keys in the TPM a la
> BitLocker).
>
>
> I'm fairly neutral on the technology itself and feel that "market
> pressure" from users as well as local regulatory policy (e.g. anti-trust
> laws) should determine how the technology is used, rather than the views
> of a few kernel hackers.
>
>
> - James
> --
> James Morris
> <jmorris@xxxxxxxxx>

For a balanced view on Trusted Computing, people should also read David Safford's (IBM) rebuttal whitepaper at: http://www.research.ibm.com/gsal/tcpa/tcpa_rebuttal.pdf.

As James points out, there has been a lot written, argued, and debated about Trusted Computing and I would encourage those who are concerned about it to read the discussions and then look at the documentation and presentations on Intel(R) Trusted Execution Technology (Intel(R) TXT). Any technology can be used for good or bad, but Intel has tried to ensure that users have control of TXT.

I would also encourage those who are concerned about these patches to look at the Linux code and tboot code to satisfy themselves that it is providing exactly what we have claimed.

Joe
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/