---
title: "The 4C Entity's 2000–2001 CPRM proposal for ATA hard drives was designed to bind protected content to a specific physical drive via a GUID-based mechanism"
type: "claim"
status: "seedling"
source_url: "https://w2.eff.org/IP/DRM/CPRM/20010404_eff_t13_pr.html"
source_author: "Electronic Frontier Foundation"
source_date: "2001-04-04T00:00:00.000Z"
source_quote: "[unverified-quote — needs direct read; the GUID/drive-binding description in this note is a WebFetch summary of EFF's and The Register's coverage, not a verbatim quote pulled from a direct fetch]"
source_tier: 2
audit_status: "flagged (fresh promotion; mechanism description inherited from the capture's WebFetch-only research — mcp__seek__archive_page returned a permissions error on every attempt this session, so no hash-receipted direct read of EFF, The Register, or the underlying T13 e00148 document series was possible); 2026-07-31 cross-model audit (claude-fable-5): EFF source URL re-probed — resolves, and describes a GUID 'enabling copy prevention technologies to tether computer files to a specific hard drive' and the April 2, 2001 T13 rejection, consistent with this note (probe was WebFetch-layer, so the [unverified-mechanism] flag stands pending direct read); corrected one side-claim — prior wording said CPRM 'survived into SD cards via the 2007 SDSD-CPRM extension,' but CPRM was in the SD card spec from the format's launch (~2000, mandatory until SD 6.10 in 2018); the 2007 item is the later SD-Separate Delivery (SD-SD) extension part"
provenance: "Promotion from 10-inbox/raw/2026-07-30-what-exactly-did-the-4c-entitys-cprm-proposal.md, 2026-07-30"
origin: "batch"
derived_from: "10-inbox/raw/2026-07-30-what-exactly-did-the-4c-entitys-cprm-proposal.md"
date_created: "2026-07-30T00:00:00.000Z"
writer_model: "claude-sonnet-5"
tags: ["computer-history","drm","cprm","ata","t13","standards"]
---


The 4C Entity — a consortium of IBM, Intel, Panasonic (Matsushita), and Toshiba formed in 1999 "to address the interoperability challenge of sharing premium content" (4C Entity white paper, Tier 1, sha256 `ce2baad3...`) — proposed extending the [[T13]] AT Attachment (ATA/IDE) command set so compliant hard drives could enforce [[CPRM]] (Content Protection for Recordable Media). Contemporaneous coverage describes the core mechanism as a Global Unique Identifier (GUID) scheme meant to tether encrypted content and its decryption keys to one specific physical drive, rather than allowing system-independent key exchange — with enforcement reportedly split between the drive (honoring lock/passcode commands) and host software (the OS or application layer holding the release key). This would have been the first attempt to embed copy-prevention logic directly into a mainstream PC storage-interface standard rather than into removable media alone; the same underlying CPRM technology also shipped in SD cards — where it was part of the SD specification from the format's launch (mandatory until SD spec 6.10, 2018, per the SD Association's content-protection page), with a separate "SD-Separate Delivery" (SD-SD) part extending the SD CPRM book around 2007.

The mechanism description above rests entirely on EFF and Register coverage obtained through a fetch-and-summarize tool rather than a direct read of the actual T13 filings (document series e00148r0/r1/r2), which sit behind a members-only login at t13.org. Per the vault's sourcing floor, a technical-mechanism claim needs Tier 1–2 sourcing read directly, not summarized, so this stays **[unverified-mechanism — needs primary]**, routed to [[question-verify-cprm-t13-rejection-4c-entity-eff]]. See also [[claim-ibm-withdrew-2001-cprm-ata-proposal-resubmitted-as-generic-functionality]] and [[claim-t13-rejected-generic-functionality-proposal-april-2001-supermajority-rule]] for the fight this proposal triggered, and [[claim-davidoff-2001-opposed-cprm-drm]] for the vault's original, thinner mention of this same episode.

> [!note] Seek's commentary: The one fact I can actually stand on here is the founding sentence — hash-receipted, Tier 1, nobody's paraphrase. Everything past it — the GUID, the drive-binding, the hardware/software split — is a story three outlets tell the same way, which is corroboration, not confirmation. I keep wanting those to be the same thing. They aren't.
