ie8 fix
madison

Gutmann: "I'm going to ignore" questions about Vista FUD

By | August 16, 2007, 9:17am PDT

Summary: If you’re waiting for Peter Gutmann to reply to my questions or those of my ZDNet colleague George Ou about his confusing, contradictory, and inflammatory Windows Vista “research,” I’ve got some bad news. In a note on his website, Gutmann says he “doesn’t have the time” to back up his theories with actual facts. Anyone want to take bets on how many publications that unquestioningly picked up his original FUD will publish follow-up stories?

If you’re waiting for Peter Gutmann to reply to my questions or those of my ZDNet colleague George Ou about his confusing, contradictory, and inflammatory Windows Vista “research,” I’ve got some bad news. A note posted by the New Zealand encryption researcher sometime in the last 24 hours (it wasn’t there at 5:15AM PDT yesterday) says fuggedaboutit:

Unlike George, ZDNet isn’t paying me to do this stuff and I really have better things to do with my time so I’m going to pretty much ignore it, I just added this note in case people had seen one of his rants and were wondering what the story was.

The irony is rich, of course. Gutmann had the time to write more than 7,000 words on the subject last December, add another 3,000 words in January, many of them dripping with sarcasm. He had the time to add another 14,000 words in the intervening months. When Microsoft prepared a response, he had the time to compare them to Nazis and violent street criminals. The organizers of the Usenix Security Symposium invited Gutmann to speak at their event in Northern California Boston last week, and he had the time to prepare 132 PowerPoint slides; then he had the time to fly halfway around the world to give that talk. He’s had the time to update the notes at the top of his website at least three times this week alone.

But a couple of bloggers point out the ridiculous errors in his column and ask for some explanations, and he “has better things to do with his time”?

Maybe they do things differently in the Southern Hemisphere, but where I come from, that’s called “slinking away with your tail between your legs.”

I hope every publication that picked up this ludicrous story will run a follow-up noting the complete collapse of Gutmann’s claims.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ed Bott is an award-winning technology writer with more than two decades' experience writing for mainstream media outlets and online publications.

Disclosure

Ed Bott

Ed Bott is a freelance technical journalist and book author. All work that Ed does is on a contractual basis.

Since 1994, Ed has written more than 25 books about Microsoft Windows and Office. Along with various co-authors, Ed is completely responsible for the content of the books he writes. As a key part of his contractual relationship with publishers, he gives them permission to print and distribute the content he writes and to pay him a royalty based on the actual sales of those books. Ed's books written prior to fall 2011 have been distributed by Que Publishing (a division of Pearson Education) and by Microsoft Press. As of November 2011, Ed is a partner in the independent publishing company Fair Trade Digital Exchange, which exclusively publishes his books.

On occasion, Ed accepts consulting assignments. In recent years, he has worked as an expert witness in cases where his experience and knowledge of Microsoft and Microsoft Windows have been useful. In each such case, his compensation is on an hourly basis, and he is hired as a witness, not an advocate.

Ed does not own stock or have any other financial interest in Microsoft or any other software company. He owns 500 shares of stock in EMC Corporation, which was purchased before the company's acquisition of VMware. In addition, he owns 350 shares of stock in Intel Corporation, purchased more than two years ago. All stocks are held in retirement accounts for long-term growth.

Ed does not accept gifts from companies he covers. All hardware products he writes about are purchased with his own funds or are review units covered under formal loan agreements and are returned after the review is complete.

Biography

Ed Bott

Ed Bott is an award-winning technology writer with more than two decades' experience writing for mainstream media outlets and online publications. He's served as editor of the U.S. edition of PC Computing and managing editor of PC World; both publications had monthly paid circulation in excess of 1 million during his tenure. He is the author of more than 25 books on Microsoft Windows and Office, including the recently released Windows 7 Inside Out.

165
Comments

Join the conversation!

Just In

RE: Gutmann:
beijing2008 14th Sep
I LOVE THIS POST replica rolex watches
0 Votes
+ -
Where are the real scientists?
MisterGilles 16th Aug 2007
What we need from Gutmann is some real empirical evidence of what he claims. Actual experimentation with mesurable results. But I guess "getting his hands dirty" with CPUs, power supplies and all those strange contraptions we call computers is really below him now that he's been elevated into the world's intellectual elite. The great scientists of old must be rolling in their grave! Science is all about measurable facts and not some crazy theory. I could argue all night about how I think Steve Jobs is in fact the devil incarnate secretly plotting to take over the world one Iphone at a time... but that's just a theory wink
0 Votes
+ -
There is very little
frgough 28th Aug 2007
actual science these days. Most of it is Aristotlean philosophy: Make an observation, form an hypothesis, argue your position. The one who makes the most persuasive argument is correct.

The revolutionary part of the scientific method wasn't observe, hypothesize or conclude, it was experiment.
0 Votes
+ -
RE: Gutmann:
beijing2008 14th Sep
I LOVE THIS POST replica rolex watches
0 Votes
+ -
These claims sounded good
mtgarden 16th Aug 2007
before Vista released. Now, under the harsh light of reality, they fade like the morning dew.

Unbelievable. I agree with his general dislike of the DRM and anti-piracy tools in Vista, but let's be honest with the facts.
0 Votes
+ -
DRM must die !
MisterGilles 16th Aug 2007
enough said on that. But it's still no excuse for scientific laziness !
0 Votes
+ -
I dont understand...
mrlinux 16th Aug 2007
Is the document is a review of Microsoft's Spec (FROM Microsoft) and one of Ed's big items is from an article not written by Peter, but a reporter and from looking at the statement, it looks like the reporter condensed 2 or 3 sentences to one, and made it sound like something Peter said. If you read Peter's article he does not say this. And now he is leaving out some the story again, Peter was planning on posting his slides when he got back home, but ZDNet bloggers couldnt be patient and wait and George made the statement
"Peter Gutmann has posted a slam at the top of his ?research? paper that I didn?t wait for his slides. I find it funny that he has time to write a paragraph slamming me but he doesn?t have time to post the slides and he doesn?t have time to post any data to support his theories. So far he?s only asked others to provide data since he hasn?t touched Vista yet.]"

Well I dont know if that is a slam, it sounds like the truth,
maybe George his slides were not with him and were on his system at home(It's easy to download a document from the web modify it and upload it back) however if dont have the slides with you, it's tough to upload them. Ed I find you and Georges blogging on this subject extremely poor

And I dont blame Peter for not posting (I am disappointed) since you (ED and George) just fling FUD about everything he sez anyway.
0 Votes
+ -
All we want is proof that Gutman
mtgarden 16th Aug 2007
tested his hypothesis. Since others have tested them and since Gutmann has had six months to test them, Gutmann needs to make some public comments.

I'm not saying that Gutmann was completely wrong, but I would rather trust someone who tested the claims than someone who won't do so.

Furthermore, his approach to argumentation forces me to question his analysis. If he must resort to sarcasm, name-calling, and generalizations, then I take everything he says as suspect. And this isn't just with this particular instance; it's my approach to life. Even when I agree with the conclusions of the speaker, these types of argumentation make me cringe and re-evaluate what I thought correct.

So simply put: if Gutmann won't give evidence that backs up his claims, then he doesn't deserve any credit or support. End of story.
0 Votes
+ -
I have 2 issues....
mrlinux 16th Aug 2007
1) Peter was reviewing a spec that Microsoft released and it was done in December prior to GA of the code.
Reviewing a Software Specification release from a Vendor
requires testing.


2) Some of what you what evidence of stuff, of where he tested this, comes right out of the Microsoft Spec.
Example,
From George
"Gutmann not only failed to test any of his theories with real-world experiments, but he didn?t even bother to come up with a good postulation by doing the basic math on what 20 CPU clocks per byte means on a modern CPU."


The above statement is not one of Peters theories it's one of Microsoft's.
From the spec:
"The problem with regular AES is that it takes about 20 CPU clocks to encrypt each byte. This is OK for compressed or semi-compressed video, but for the multiple HD uncompressed case, it is too much even for a 2006 processor. A dual HD uncompressed stream with potential sub-picture information can be up to 250 MBytes/sec."



Note: I dont agree totally with Peter, but if you are going to report stuff, how about trying to do some basic research (Reading the DOCs), This is directed @ Ed and George.
0 Votes
+ -
Contributr
Vista was released in November
Ed Bott 16th Aug 2007
When this was first published, the RTM code had been out for nearly two months. Release candidates had been publicly available for four months or more. And since the commercial/retail release, Gutmann has written 14,000 more words.

This isn't about a spec, it's about a product, one that is widely available.
....
0 Votes
+ -
Contributr
It was widely available
Ed Bott 16th Aug 2007
The consumer versions of Vista (Home Basic, Home Preium, Ultimate) were released in November 2006. They just were not made available for retail sale.

Anyone with a TechNet or MSDN account could download it.

But that is irrelevant. You keep talking about the spec. Last time I looked, custoers actually buy the software, install it on a computer, and use it. The behavior of the software is what we're talking about.
At what stage would anyone with a home computer be dealing with 2 raw encrypted HD streams? Video editiing? I don't think so. This is all based on Gutmann's obviously garbage claim that even your home movies go through AES.

As this isn't true, your Premiere Elements HD Holiday videos will not suffer any performance issues as a result of the DRM.as it isn't switched on and therefore uses zero CPU cycles.
0 Votes
+ -
"This is all based on Gutmann's obviously garbage claim that even your home movies go through AES."
0 Votes
+ -
Really?
odubtaig 17th Aug 2007
So when he claims that even personal 'unprotected' HD video will be downscaled without HDCP compliant hardware (which means AES capability) what magical secondary mechanism that no-one else seems to know about is causing this effect? I mean, given that this only happens when AES is required for full resolution playback.
0 Votes
+ -
Then please apply that same logic
zkiwi 16th Aug 2007
To pretty much any of George's "theories." He is big on rant, big on "creative accounting" with regard to facts/data etc, and very very small about reality.
0 Votes
+ -
Glad you articulated and emphsized
xuniL_z 16th Aug 2007
Guttman's theories. Nice job!! I could care less how you feel about George, but to hear you describe Gutman in the same breath was a refreshing change from your usual stance against ms no matter how much it rips apart your credibility.
0 Votes
+ -
Anything to do with my views on his theory?
0 Votes
+ -
It was the way
xuniL_z 16th Aug 2007
you framed your reply. no question, would hold up in court.
0 Votes
+ -
Message has been deleted.
The_Nutty_Zealot Updated - 17th Aug 2007
  • Flagged
0 Votes
+ -
nuff said! While I do not always agree with Ed and George, the fact that they are calling on Gutmann to show some proof is far from spreading FUD. It's called scientific rigor or common sense.

PowerPoing Slides are not going to proove anything. Unless they show measured data that has been peer reviewed. Anything else from Gutmann is a simple theory and IS IN FACT FUD.
0 Votes
+ -
but making false claims, such as the ones that have been made are wrong. Such as the one George makes
"Gutmann postulated that the encryption required by Vista DRM means that it will drive CPU utilization ?full steam? and he cites the fact that AES takes about 20 CPU clocks to encrypt each byte. Gutmann not only failed to test any of his theories with real-world experiments, but he didn?t even bother to come up with a good postulation by doing the basic math on what 20 CPU clocks per byte means on a modern CPU. "

Well Peter didnt need to do testing since this was a quote from the Microsoft document that George didnt read.

http://www.microsoft.com/whdc/device/stream/output_protect.mspx
From Microsoft
"The problem with regular AES is that it takes about 20 CPU clocks to encrypt each byte. This is OK for compressed or semi-compressed video, but for the multiple HD uncompressed case, it is too much even for a 2006 processor. A dual HD uncompressed stream with potential sub-picture information can be up to 250 MBytes/sec."
0 Votes
+ -
The bit where you left out the following two paragraphs.

An encryption mechanism more like 4 or 5 CPU clocks per byte was required. Schemes such as Linear-Feedback Shift Register (LFSR) were considered, but did not provide the required security strength. The security bar for uncompressed premium video is not quite as high as for compressed premium video, but it is still very high.

In response to the 4 or 5 clocks-per-byte challenge, the concept of re-encoding the AES cipher blocks to allow mild re-use was born. A specific implementation of this concept was invented by two cryptographers at Intel, Ernie Brickell and Gary Graunke.


Later followed by:

The Intel Cascaded Cipher is the default preferred cipher to use as the High Bandwidth Cipher in PVP-UAB. It is a promising design, but it is not, however, the only possibility for the High Bandwidth Cipher.
0 Votes
+ -
You don't just make claims without having some evidence. He ranted about the evils of this OS without having ever even touched it. He is worse than the Mac/MS "fanboys" that everyone and his brother hates. At least most of them have some reliable data to back up their claims (usually). He just started talking, and didn't stop to think that you actually have to have some kind of empirical data.

All of this is Gutmann's fault for not bothering to back-up his claims in the first place. Now he's refusing to, basically admitting that he is full of crap. Who cares if he didn't have time to upload is PPt slides? It doesn't matter. He should have done that for his first review. That is what CREDIBLE scientists and journalists do - they report the truth as evidenced by the supporting data. They do not spout off information as if it were gospel without having any proof whatsoever.
0 Votes
+ -
Well lets look at Peter Statement's
mrlinux 16th Aug 2007
1) He read Microsoft's spec on Vista
http://www.microsoft.com/whdc/device/stream/output_protect.mspx
2) He released a response to this Doc, calling the longest sucide note in history.

3) Lots of the Info he sites in his response comes directly from the above Document, but yet no one questions it ????
They just take what he writes from the Microsoft Document as some of the reason he see this as a suicide from Microsoft and claims he doest provide any evidence or does any testing.

4) Well I have read all three doc's and Listened to Peter's
responses to the Doc and such directly from Peter during his interview.
Security Now Podcasts
http://grc.com/securitynow (search for DRM)
maybe Ed and George could take some time and listen to them.
Instead of taking reporters statement's of what he supposedly said and quoting like Peter Said it directly.

5) And for all those out there testing and claiming no issues,
you can not have tested since the content producers have not
released any content that requires the activation of the
AES 128bit encryption/decryption feature. This is the problem with testing Vista, The DRM features are activated on an HD-DVD Disc basis, it not an ALL DRM or no DRM. Again I refer you to Microsoft's spec.

Note: I do not agree 100% with Peter, but most of those are based on the fact I dont believe Microsoft will be stupid enough to implement what they have placed in their spec, but I could be wrong.
0 Votes
+ -
And he convinced the open source sheep to follow.
0 Votes
+ -
Nah
zkiwi 16th Aug 2007
For raving lunatic you have to a zdnet blogger or a poster like yourself. Who knows, too much exposure to zdnet might even endanger me!
0 Votes
+ -
You have nothing to worry about
xuniL_z 16th Aug 2007
You are already as raving and lunatic as is possible.


Where have you been hiding zkiwi? Don't say you've had things to do. (refer back to my original statement)
0 Votes
+ -
Still delusional then?
zkiwi 16th Aug 2007
That was rhetorical and the implied answer was that you are still delusional. And just to annoy you, yes I have had and do have things to do. Oh wait, you asked me not to mention that. Now you go back to minding your windows boxes and all that "good stuff."
0 Votes
+ -
whatever
xuniL_z 16th Aug 2007
this from someone that literally thought I would be affected somehow with the "shock and awe" of telling me what you do. Real or imagined, you need to gain some perspective. And a personality would be nice too.

I do hate to burst your little bubble, but you don't have the power to affect me, annoy me...whatever. nada. sorry.

0 Votes
+ -
0 Votes
+ -
CodeWarrior.
xuniL_z 16th Aug 2007
Hey, nice nic. You really had to have it didn't you.


And I can see why from your posts it's surely fitting.

You take someone else's code....then you kill it. nice..nice.
0 Votes
+ -
Your head is in the sand ...
ShadeTree 16th Aug 2007
... and your credibility is the equal of Peters. He said he would post the slides and didn't. He was returning from presenting them so he had them with him. You can spin it any way you want but what happened is obvious.
0 Votes
+ -
So...
zkiwi 16th Aug 2007
Would you agree that George's credibility is "in the sand" as well, considering his "I'll post the emails in a couple of days" promise?
0 Votes
+ -
Don't change the subject.
ShadeTree 17th Aug 2007
We are talking about Gutman's claims and his unwillingness to prove them. Your vendetta against George is something you and your shrink need to work out.
0 Votes
+ -
And yet...
zkiwi 17th Aug 2007
You'd prefer to trust George when he's not even seen the slides/presentation in question. That is really head in the sand stuff.
0 Votes
+ -
Misdirection is not working!!!
ShadeTree 17th Aug 2007
No where does Gutmman deny that he said what is being presented as his words. Not Once. Instead he is attacking the messenger. He goes on and on about George as do the rest of you but the last time I checked this is Ed's blog. Then there is the fact he offered to post the slides but has not. It seems that if he stands by his presentation there is no reasonable for not posting it and letting us all decide.
0 Votes
+ -
Well...
zkiwi 17th Aug 2007
Correct me if I am wrong, but weren't you one of the people who preferred to believe George over the "Maynor silliness" without one shred of proof from George? And here you are now not giving Gutmann the same "consideration."
0 Votes
+ -
Your still trying to ...
ShadeTree 17th Aug 2007
... change the subject. Try to stay focused on the conversation at hand.
0 Votes
+ -
It's all about equal opportunity
zkiwi 17th Aug 2007
Which you aren't prepared to give.
0 Votes
+ -
DRM is dead
voska 17th Aug 2007
At least dead for content delivery.
0 Votes
+ -
They're quick to spread their FUD. But when challenge with facts they either ignore the challenger (as is the case here) or start up their ad hominem "arguments".
0 Votes
+ -
Nice NBM FUD Tactic
Rick_K 16th Aug 2007
There Mr. windows fanboi. It's just like Jihad George and his slanderous claims about
Apple. Ed has little, if any credibility. I read his garbage for the humor value. These
two clowns are so deep in Microsoft's pocket, they can't see reality. What's your
excuse?
0 Votes
+ -
What a loser
laura.b 16th Aug 2007
If he actually thinks that people are just going to take what he says as gospel without a shred of proof, and considers that FUD as opposed to justified incredulity, then he's more than just an anti-MS liar, he's also an idiot, and apparently thinks that everyone else is as well. I didn't like the guy in the first place, he can't rationally argue anything without sarcasm and name calling, but not even bothering to respond to a simple questions "Where did your data come from?" which, frankly, should have been made known from the first word out of him, he is basically admitting that he made it all up and he can't be trusted.

Stay on him. Eventually he'll have to reply, and when he does, the whole world will know what a lying idiot he is. happy
0 Votes
+ -
Didn't you know that? Or do you believe George/Ed without reference to anything else?
he never had data and admited it, but the media sucked it up. Bruce Schneier jumped on board and started citing Gutmann then the media started citing Schneier and Gutmann. Something is terribly wrong here.
0 Votes
+ -
He certainly had Microsoft SPEC..
mrlinux 16th Aug 2007
Which what the subject of his article was about!!!!!!
of course you have not read it.
0 Votes
+ -
Not only that...
Wolfie2K3 17th Aug 2007
But didn't Gutmann say several times that he wanted other people to confirm his whacky theories of reality because he didn't have Vista handy to test it?
0 Votes
+ -
Yes, he asked other people to confirm his theory, but apparently he only wants other people?s data if it confirms his theory. If you want him to do the testing, he has stated that he wants someone to loan him a 27" HDMI HDCP capable display until the year 2012. Now he's apparently complaining can't get funding to conduct this research.
0 Votes
+ -
Excellent points but...
dfolk 16th Aug 2007
All good points about having good data and testing to support ones technical assertions. But....do we hold MS to such a standard? I think we do not. They have become, in too many cases, shameless propagandists, and we have simply become accustomed to their behavior. No one expects candor and accuracy from MS anymore because of their very long track record to the contrary.
Lets hold everyone to a decent standard. It is worthwhile to expose ALL who do not meet basic standards.
0 Votes
+ -
True yet...
MisterGilles 16th Aug 2007
Microsoft is a business and as such anything coming out of Redmont that sounds even remotely scientific should be taken with a grain of salt the size of texas.

That being said, we should have more independent scientists doing independant research on ALL operating systems without any kind of emotion involved (all too many emotional debate on linux vs windows vx OS-X)

I'm envisioning a world where a bunch of vulcan scientists lead by none other that mister Spock himself do the testing. Only then will I listen. Until that happens, I will continue to call on all the feces slinger out there who do not know the first thing about critical thinking and plain old hard science.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix