Felten Follower Examines Crippled Music Disks
D4C5CE writes "Following in the footsteps of his famous professor, in his paper "Evaluating New Copy-Prevention Techniques for Audio CDs" (yes, that's pure PS), which is one of many interesting contributions to the 2002 ACM Workshop on Digital Rights Management, Princeton student Alex Halderman takes apart (bit by bit, literally) the "tricks on tracks" employed by the music industry to frustrate fair use."
I think examining the strength/weaknesses of algorithms without regard to the surroundings is not a good idea. With Windows providing most of the drivers in signed form, and refusing to accept unsigned drivers, it could be difficult to apply the "breaking" methods defined, in the mainstream operating systems. Ofcourse, in other OS's this shouldnot be a problem.
"Do something man. Right now."
I hope he knows such trips to conferences may last longer than expected. Instead of bodyguards he should be guarded by lawyers.
Yours, Martin
For those that don't have a Postscript viewer and run Windows, check out RoPS - small, fast and effective.
Do they have wheelchairs or crutches?
Be you Admins? nay, we are but lusers!
Anyone care to repost that doc in another format ??? Our IT department are very very strict and I can't install jack on my NT box.... oh and my sun box can't see the 'net..... how much does that suck :C
Cheers
tom-george.comBecause geeks rate higher t
Is it just me, or does he have a picture of Natalie Portman in his photo collection?
Her name is Julie?
Copy-protection bashing and Natalie Portman... A hero to us all. I salute you!
they prefer the term "Music Discs with Disabilities"
Exactly. There is no way that an audio cd can be made copy-protected, and remain reasonably compatible with redbook CD players. It was never built in to the spec, and there is no way to shoe-horn it in to the spec now.
As the paper points out, these schemes rely on "bugs" and "mis-features" in reader firmware, and it suggests that CDDA copy prevention won't last since "[...]Hardware and Software adaption is an inevitable and natural extension of improved design and bug fixing".
The question is if the hardware manufacturers will begin competing for customers by providing the very best fireware in their drives, or if they will join hands with the RIAA and the snake-oil salesmen. So far I see no decisive move in either direction.
Some drives can 'clone' protections just fine or need only better software on the computer side, but on the other hand there's a whole class of typical hardware -- like the Toshiba in this case -- which has been b0rken for so long that I really think the manufacturer is playing nice with the copy-protection industry.
Maybe what we really need is drives with a more capable RAW reading interface, then all errors could be emulated and/or corrected as necessary on the side we control, the computer.
Belief is the currency of delusion.
Seems that some industries define standards to break them (for "additional features"). Interesting what happens to players if they follow the standard, i.e. they probably need to be a bit "non-standard" to play crippled CDs...
...as if the music industry's actions has nothing whatsoever to do with frustrating music pirates.
Let's be fair here. We all know that recent copy protection schemes do in fact (at the very least) interfere with fair use, but we can't forget/deliberately ignore the underlying goal of the music industry for the sake of sensationalism, however faulty their methods are.
"Ask not what your country can do for you." --John F. Kennedy
it doesn't have an icon on my windows xp system. Do I use notepad :(
On a related note (since I try to stomp out FUD where I find it), I'd have a hard time saying that the industry's intent is to destroy fair use. Where's the profit in that? I have little doubt that the problems that are occurring are because they're trying to -comply- with spec, not obliterate it -- namely, the problems some have noted with copy-protected compact discs are because the industry is trying to protect its content while remaining compatible with an obsolete standard. I have little doubt that when the next generation of media arrives, with effective digital rights management built in, that it will have the capability to deliver content and permit fair use while preventing the sort of rampant piracy that is driving small record chains out of business. I think that the free market will probably be the best way to determine how importantly fair use should factor in to these new designs.
Try not. Do or do not, there is no try.
-- Dr. Spock, stardate 2822-3.
I just had contact with an copy protected audio cd.
It was a present at a birthday party on which musik was played with a pc. We just wanted to insert the CD to the cdrom an listen to the music. The music wasn't playing and the cdplayer just hung. So we booted into Winblows to try it over there. Same result. The guy was only listening to the music with his computer. So i took the cd with me and ripped it in my CD-Burner. So now i have a spare copy of the disk just because it was copy protected. Doh.
Music industrie annoys me - haven't bought any CD's lately. This boycott is not very constructive
but i just don't have any idea how to "fair use" the music of the artist.
Whatever games they and you (and for all we know you are they) play to pretend otherwise, their goal is to squeeze more and more money out of those who legally purchase their works, thinking that as long as the market may be able to bear more, it is their duty to extract more by further restriction of rights, whatever that means to their customers.
This is also very obvious from your / their push to extend copyright perpetually, extracting more and more, not from the copyright violators, but from those who abide by the laws.
While you / they feel it is your right to push it to the edge to squeeze every last drop from the paying public who have suported you thus far, claiming you / they are just trying to make pirates pay their fair share. The fact kicking those who have been buying dozens or hundreds of new titles every a year does not make us more loyal, and will eventually lead to changes more fundamental than what you / they complain about today.
We know your industry hates discussion of fair use. If they ever showed any signs of actually caring about preserving the rights of the customer, they might have a legitimate sympathizer or two among the paying public. An approach that exhibited any evenhandedness, restoring some of what they have driven so hard to take away, would shock their opponents. There are any number of forms this could take technologically.
...because this only pisses off their existing customers. I've yet to see one CD protection that hasn't been bit-exact ripped by someone (which is all it takes).
If they can't play it in the devices they have will they
a) Call it a defective cd? Most likely.
b) When they find out it's defective by design, will they
1) Continue to buy defective CDs?
2) Get a normal CD(-R) from friends or mp3 from internet?
We get more and more DVD/CD/MP3/kitchen sink consumer players. Break compatibility with those, and the MPAA will have only themselves to thank when the customers abandon them (Who the hell pays $20-25/CD anyway, that's the usual full price here in Norway...)
Kjella
Live today, because you never know what tomorrow brings
This paper appears to have a lot of good pointers to software writers, including a "recipie" to make cdr-dao read the faulty discs on all hardware readers that support it.
Will this lead to a new release of cdr-dao "soon" that incorporates theese suggestsions? will the apperantly "dead" cdparanoia also be updated? (yes, it did work good on plextor, but for other cd-roms, can it be made to work?)
I also wonder, how can theese suggestions be incorporated in the average cd player? things like xmms would probably need updating to the cd player module to handle some of theese. I know it's ugly hacking to go around broken hardware, but thats what we do in all other places....
I didn't do this, now did I?
Whose dome are we freeing?
There is no scheme yet devised that will significantly hamper true music pirates. And by that term, I mean people who create and redistribute bootleg CDs for profit. Any of those folks will just take an audio CD player and capture the music via the SPDIF output.
The music industry wants to convince the world that anyone who records a CD to their hard disc is a "pirate." They want consumers to believe that making a backup copy in case of damage is piracy. They want people to believe that creating a "mix CD" of your favorite songs is piracy. They want the public to believe that the guy who copies a CD so he can have one in his car and one at home is a pirate. In short, they are waging a campaign to equate simple copying with piracy.
In their ideal world, if you wanted a copy of a CD for the car and one for the home, you would have to purchase two of them. If you wanted a "mix CD" with numerous hits, you would choose from their canned compilations. If you damaged the CD while moving it from player to player, you would have to purchase a new one (since you would not have a backup). This is not about piracy. It's about making you pay multiple times for the same music.
Now it's not just the DMCA we're up against; we also have to worry about the ADA. If you don't buy one of these copy-protected CDs you may be sued for discriminating against the handicapped.
Perhaps it is a sledgehammer to crack a nut but I would rather use GhostScript. Both variants (AFPL and GPL) are esentially and totally free, respectively which I prefer. For such an article, is a commercial (and overpriced)viewer really appropriate?
I have to wonder whether publishing the results of such endeavours violates the DMCA -- it sure seems like everything that involves data security does these days. I'm still happy he's published but I wonder whether the lawyer-boys in the RIAA are salivating right now... (insert hungry animal growling noise here).
The difference, I feel, is that the region system is something which average joes can understand and question; "So you're saying that for some artifical reason this player will reject DVDs I've bought over-seas?", while the reliance by CDDA copy-protection schemes on reader firmware (as opposed to being fully contained within the CDs themselves) isn't as apparent or easy to convey. Basically, people are mostly unaware that their choice of drive will and can change the degree to which they can use copy-protected discs on their computer.
I wish they'd used a Lite-On drive in the tests too. Plextor is mostly bought by people in-the-know, while Lite-on provides quality firmware (my experience) on a much wider level and could be used as a good recommendation based on quality, high availability and low price.
I'd also like to see future research which goes beyond the black-box approach and actually use a custom firmware to dump the disc.
I just hope that some manufacturer recognize the opportunity and either provides a good quality firmware with good failovers which just rips through these protections, or provides a firmware which can be switched into "dummy cd-player mode" in which it would behave exactly like a dumb cd-player would. This shouldn't take up too many bytes, and the interface could be anything from a simple "tripple-click eject button to change mode" to a nice looking GUI-app (which Plextor is very good with already, via their "PlexTools".
(I don't work for Plextor or Lite-On. I do own drives from both manufacturers though)
Belief is the currency of delusion.
Call me a karma-whoring idiot if you like, but I thought I'd stick up a copy of this in a format that's not quite so bitmapped. ph33r my l33t OCRing skillz, etc. :)
Click here for an HTML version.
Whose dome are we freeing?
Nobody's, domes should belong to themselves, that's why we're freeing them.
Looks like we can get ahead of the game here, by ensuring that we have our "Free Alex" flyers and placards printed out in advance.
Seriously, the amount of information in this paper is similar to that which got Dmitry Sklyarov detained under the Downloaded Music Criminalization Act (DMCA). It even gives information as to which programs and hardware are most effective at bypassing these copy-restriction technologies.
It's well worth a read to see how these technolgies only work due to buggy or fragile implementations of the standard.
Sean Ellis
Follow OfQuack's antics on Twitter.
Isn't this technical research mostly based on the assumption that the firmware programmers of Plextor did their job good (while others can't)? I think he should has done his technical analysis with more drives, like Teac or the latest Yamaha F1. Drives like this also read audio protections fine.
The industry likes to threaten lawsuits over technical discussions of their various techniques, but they will never actually let one of those lawsuits be taken to court because they know they'll be bitchslapped into the middle of next week by a pissed off judge. They'd far rather stick an academian with the cost of initially retaining a lawyer rather than risk having to pay his legal fees for blatantly abusing the legal system.
So they may file a lawsuit but it'll be retracted as soon as Halderman's lawer files his first brief.
I'm trying to teach myself to set people on fire with my mind... Is it hot in here?
imagine, buying a SONY minidisc player, that's advertised being easy to use and fast to transfer songs to from your cd's via your pc(and able to play mp3's), and that come's with software to do that.
you buy it at an all purpose entertainment electronics supermarket that sells cd's too, you pick up a record you like that's published by SONY thinking that at least that one should work easily (because you are not very tech savvy and would like the first transfer to go smooth as possible).
you get home after that, excited about your new purchase, software installs easily but the cd copy to player just won't work, completely clueless you call your geek friend who then comes over, and explains he could tell you how to do it but would have to kill you afterwards.
would the average consumer be a LITTLE confused and afterwards disappointed at this?
could the companies PLEASE at least make up their mind about the issues?(sure they might be different depts. of same corp. but still.. and sure this same issue might have been brought up before too.)
world was created 5 seconds before this post as it is.
The music industry considers fair use to be theft. See, for instance, the dialogue between Hilary Rosen and Orrin Hatch, where she told him that it should be illegal to copy a CD he bought for his car or for his wife.
Infuriate left and right
Since when did Red Hat release with a 4.2.18-3 kernel? I can't seem to find it in the official tree, so I might just have to reconsider my loyalties to SuSE.
[FUCK BETA]
the guy writes his paper in postscript, what do you expect?
I wonder what the world would be like if all these efforts were directed at actually getting information into the hands and minds of people, as opposed to hiding it from them? Simplistic, yes. Information is just information to me. There is plenty of it for free or very low cost, and the for pay can be quickly reverse engineered in the human mind in a pinch. Timely delivery or well crafted information is of value and has a limited term business model.. i.e. books, research, art, .. but for the most part, in an economic sense, people should probably focus on tangible goods and services (not to be confused with Greenspeak's new economy folly).
I hope for an age of reason and innovation, a fairly major paradigm shift. But it's a possibility as these MNCs continue to p*ss away their working capital trying to abate evolution.. it's good that some of these cathedrals will fall, because there are some great raw materials there that can be recycled and used to create things of better value.
Not to feed the trolls -- or, in this case, the Balrogs -- but...
There are far fewer than six degrees of separation between Tolkien's Magnum Opus and the Third Reich's own modern mythology. Himmler and the good Professor both drew from the same sources. Himmler, of course, took a very wrong turn Eastward through Hindu Mythology, but had both men sat at the same table at a dinner party, they would have had a lot to talk about...
Kudos to whoever modded this as Funny.
/. is breaking down... mentioning the RIAA, MPAA, DMCA and MS will no longer get you an instant +5.
In other news, the "instant karma" algorithm on
I continue to feel that attention should be paid to how these things interact with home audio CD recorders, and not just because I happen to own one.
Under the Audio Home Recording Act of 1992, blank media for home audio CD recorders includes a fee which is distributed to publishers and artists in exchange for the right to copy the CD. Home audio recorders are restricted from writing to ordinary blank CD-R media; the media must have the encoding that identifies them as a "Music CD-R" thus verifying that the fee has been paid, and they also incorporate a "serial copy control system" which makes it difficult for people to create huge numbers of copies by making copies for three friends who each make copies for three friends, etc.
Copy-protection schemes have to corrupt the data enough to prevent access by standard computer software. HOWEVER, they must not corrupt it so much that home audio CD recorders fail, or they are (probably) violating the AHRA.
In practice, Universal Music evaded answering any questions I asked them about this issue; however, when I sent them a copy of "The Fast and the Furious" which my home audio CD recorder refused to copy, they sent me a replacement which did! I believe their strategy is "avoid public discussion by taking care of any individuals who complain, on a case-by-case basis."
"How to Do Nothing," kids activities, back in print!
I think that they are pretty clear on this issue - they don't really care if you copy a competitor's cd's. Just don't copy theirs. Sounds pretty clear to me
-Thomas___ This sig is in boldface to emphasize its importance!
Isn't any discussion of any type of security measure realted to ANYTHING cause for an instant 10-year prison sentence without trial under the DMCA? ...Oh yeah, it's trollin' time...
I am alone, yet I also surf the universal backwash of undifferentiated Being, which is LOVE.
Why was this modded down? It's a valid way of bypassing copyprotection.
RIAA (or members thereof) will be unhappy that you didn't buy their crippled CDs.
Of course some companies (e.g. AOL Time Warner) are members of both - and one distributes leading mp3 software (Nullsoft Winamp/Shoutcast).
HTH, HAND.
sulli
RTFJ.
Very ironic that it is presented in double Adobe. You can't just view the damned thing, you have to download it, convert it, and open it again.
Am I the only one who hates adobe?
What's worse is the screen fonts are nearly unreadable. Does anybody have a less insane version (like, say, HTML)?
I'd like to see the paper but don't want to waste the ink printing it.
On the other hand, can this guy possibly know anything about computers if he presents his papers in this God-awful format?
-steve
mcgrew.info
(bending mah ears): "Huh...?"
... I've yet to see one CD protection that hasn't been bit-exact ripped by someone (which is all it takes) ...
You are mistaken. Many high schools kids wouldn't have a clue as to how to get around the protection, nor would they know anyone who could, directly or indirectly. They barely know how to dupe a CD with their CD-RW. After a few coasters they give up.
It's been like this for a long time, proection in general not coasters. Copy protection doesn't have to be perfect, it just has to stop enough to be cost effective.
Some people have misread the Slashdot headline as implying that I had some involvement in writing the CD copy protection paper, or doing the research, or thinking up the idea. I did not play any of those roles.
It's a great paper, and Alex Halderman deserves all of the credit for it.
Ed Felten
Conspiracy theory mode kicks in: Microsoft, Panasonic propose (another) CD standard
Microsoft HighMAT announcement
with this quote from the MS page:
While by definition you're storing digital media on a digital format, that combined with specially designed consumer devices hints that there is more than just data re-ordering on disc going on here. OK, it could just be a "special file format" for pointing to important data that should be pre-cached, but...
And finally the specifications:
Nothing of interest at the site yet that I could see. I wonder if you've got to sign an NDA just to see the licensing agreement and the fees for using the specification...
Lots of questions and not too many answers at the moment. Make of it what you will. (Unable to get a preview, so posting as is).
A physicist is an atom's way of thinking about atoms
It is widely regarded that the hobbits represented the simple virtues of the English working classes, who were drafted into service in a conflict about an outside world for which they had little regard, but for which they perceived the danger to their liberty and took up force of arms to fight.
Looks like Telepolis was faster than /. this time:
5 7/ 1.html
http://www.heise.de/tp/deutsch/inhalt/musik/134
I've always found that an annoying aspect of (La)TeX documents on the web...a lot of them look really crappy when converted to PDF...
They don't have to. With teTeX, if you generate the PDFs with pdftex or pdflatex (as appropriate), the vector fonts will be used. The problem arises when people use dvips with ps2pdf (or similar); by default, dvips uses bitmap fonts even when vector ones are available. However, this can be fixed by editing the script /usr/share/texmf/dvips/config/updmap (adjust path as needed) and changing the value of the parameter type1_default, then running that script as a sufficiently privileged user. (I'd love to know if there's a nicer way of doing that.) Also, older versions of ghostscript (ps2pdf is a wrapper for gs) would rasterize embedded fonts when generating PDF, but recent ones don't have that problem. Oh, and specifying a font like cmr13 rather than cmr10 scaled 1300 can cause bitmappedness.
HTH. HAND.
I know how to generate my own PDFs from LaTeX source files (IIRC I used dvipdf in the MikTeX distribution to typeset my senior thesis...pdflatex didn't handle my thesis template and/or graphics very well), but most LaTeXed documents are posted on the web in Postscript format which, as is well-documented in this thread, often does not convert very well to PDF. Your comment did remind me that Ghostscript does a pretty good job of converting Postscript to PDF, but it pales in comparison with the anti-aliased output when the author typesets the document directly to PDF using pdf(la)tex or converts DVI straight to PDF.
"It take 9 months to bear a child, no matter how many women you assign to the job."
Not to mention the strain of racism that ran through the LOTR mythology.
Look at the allies of Sauron and Saruman. Look at their skin colors, the oliphants, etc.
We need not even talk about the whole white/dark sybologies.