Five Great Reasons to Adopt Trusted Computing

Trusted Computing is perhaps one of the mostmore for the administrator than the employee,
misunderstood (willfully misunderstood, to be frankhowever. The TNC, Trusted Network Connect, has a
about it) emergent technologies for computer security.whole bunch of protocols defined around IF-MAP,
The misunderstanding starts from Wikipedia's entriesInterface For Metadata Access Protocol, that allows
on Trusted Computing, and continues through hundredsclients to be queried as to their state, and for other
of articles and blogs. There are, of course, validnetwork devices to talk amongst themselves about
objections on the basis of that it is a closed chip, andthe state of the network. Although designed for the
although it could be implemented using Open Sourcecorporate network, in a home environment it could for
software who is to say that there are no hiddeninstance detect someone hacking your networked
backdoors in the implementation. However, a similartoaster and close down sufficient services to stop
argument can be made for just about any computeryour toaster frying the rest of your house.
system available, so if you can get past that mental4. Digital Rights Management
block, here are five great reasons to get excited aboutOh look, I said the bogey word, DRM, that sends
Trusted Computing.opponents of Trusted Computing into fit of indignation.
1. Trusted Computing-based Full Disk EncryptionHowever, the fact of the matter is that media
There are a number of free (TrueCrypt being thecompanies want to deliver content over the network
most well-known) and paid-for software-only solutionsto you, but don't want you doing what you want with it,
to realising full disk encryption, but recently there hasas they've spent a good deal of money making the
been a lot made of the Evil Maid attack, where a PCcontent. Trusted Computing and the Trusted Platform
left alone in a hotel room is booted off an externalModule in your network-connected set-top box, and
drive in order to steal the password. However, Joannayou have a system that has the potential to fulfil the
Rutkowska from Invisible Things Labs has described"better than free" mantra, like iTunes has done for
how Microsoft's BitLocker full disk encryption solutionmusic.
may be easily enhanced so that the user can easily5. Mobile phone security
see that their computer has been hacked. If this EvilCurrently, some cell phones like the BlackBerry have
Maid attack is not a major concern, the Trustedexcellent security, ones like the iPhone claim they have,
Computing Group has defined the Opal specificationand yet more have little or none. However, Trusted
that implements full disk encryption on the driveComputing defines the Mobile Trusted Module, a
hardware, circumventing any performance concernssecurity chip (or some software running in a
that software solutions have. There is no good reasonhighly-trusted and secure mode performing the same
why the next drive you buy should not support thefunction) that adds the same features as the TPM
Opal specification.plus a few extras suitable to the music world. Now, the
2. Unified secure login to your favourite sitesmobile operator can have rock-solid DRM for their
The OpenID initiative has produced a method to logring-tones (yes, you may roll your eyes too at that
into many sites with a single password while keepingcomment!), but more importantly your mobile banking
that password managed in one central location. This iscan be as secure, if not more secure, than PC banking.
a great initiative, but for wider adoption, and forThe National Security Agency of the US is even
adoption by entities such as banks that have higherrumoured to be looking at this for who knows what...
security requirements, and for adoption by usersSo, there are five great reasons to get exciting about
themselves who have higher security requirements,Trusted Computing. In some of the cases above it
Wave Systems have taken this one step further bymay not seem like your friend, but Trusted Computing
protecting these passwords with a Trusted Platformis certainly not your enemy, unless of course you are
Module, so that the servers on the other end can bea hacker! The people working on these Trusted
assured who the user really is as the password isComputing standards are very talented guys and few
backed with the guaranteed identity from the TPM,if any of them, not even the Microsoft guys I know,
and the user can be assured that access to theare out to get you and lock you into their products.
services can only be made from the computer withIndeed, the TPM specification bends over backwards
the TPM installed.to maintain your privacy at the expense of
3. Network assurancefunctionality!
This feature is a great one for corporates, perhaps