"Palladium" and TCPA

Graham Murray graham at barnowl.demon.co.uk
Fri, 28 Jun 2002 20:45:41 +0100


Ross Anderson <Ross.Anderson@cl.cam.ac.uk> writes:

> You can be sure that M$ and friends will use whatever pressures they can
> to ensure that they escape legal liability for bugs. You can also be sure
> that Palladium won't solve problems like viruses and spam. These are
> application issues rather than O/S problems.

So should DRM be an application rather than OS issue. Would it not be
a better idea to have some form of (strong) encryption[1] on files,
have no technical mechanism for restricting copying them, but have to
"prove" that you are authorised (to whatever level) before the
application will decrypt the file?

[1] This would have be orders of magnitude stronger than CSS.