English
Language : 

L12-TCPA-PALLADIUM Datasheet, PDF (11/12 Pages) List of Unclassifed Manufacturers – TCPA and Palladium
11
Nexus Policy
• Everything that runs today will run on Palladium systems
• The platform will run any nexus
• The user will be in charge of what nexuses he chooses to run
• The MS nexus will run any application
• The user will be in charge of the applications that he chooses to run
• The MS nexus will interoperate with any network service provider
• The MS nexus source code will be made available for review
“The security mode will be off by default. You can’t have it on by default. This is a hard lesson
for Microsoft. Users always click ‘yes, sure, go ahead format my hard drive — I don’t have time to
read this! I have work to do.’ ” Somehow you have to tell Microsoft what to run on Palladium.
The talk was interrupted by Q&A. See the Palladium slides (24-29) posted on the course handout
page for information about:
• Privacy of Machine Identity
• Pseudo-Identities
• Registering a Pseudo-Identity
• Summary
9 Questions & Answers
Q: Have you thought about user interface for designating right hand side application windows vs
left hand side applications?
A: You could store a secret (user’s favorite fruit plus number) in Palladium, and display that secret
every time Palladium window comes up. Alternately, you could use a hardware indicator.
Q: Can I run pirated Microsoft Word on this? - Randall Davis
A: Well yes, now, but it is possible to use Palladium to interfere in the future maybe, i.e. if part
of Word runs in the right hand (it never makes sense to run it all in the right hand because
it’s too big and takes too much work to migrate over). So it is possible to write applications
that do that. We [Palladium group] are not involved with the app guys, though. MS is a tribe
of 200 groups that dislike each other. Word sits on the left hand side now. Anything I send
out to word in the left hand is insecure. - Brian LaMacchia
Q: Would it be possible to design the crypto so that the user can always force a decryption – is
it technically possible (if not smart)? - Hal Abelson