Slashdot Mirror


Researchers Want Right to Bypass Protected Spyware

Dotnaught writes "Computer security researchers Professor Edward Felten and Alex Halderman have asked the U.S. Copyright Office for an exemption (pdf) to the Digital Millennium Copyright Act (DMCA) so that they can circumvent copy protection technology used to protect spyware. The DMCA currently makes it illegal to bypass digital locks almost regardless of what they protect or the user's intent. As noted by the Electronic Frontier Foundation, the Copyright Office theoretically grants exemptions, but in reality discourages anyone from asking. What's significant about the application submitted by Felten and Halderman is that they knew about the dangers posed by Sony's XCP DRM software a month before the news became public. But they delayed publication for fear of prosecution. During that time, many more consumers fell victim to the spyware propagated by Sony."

35 of 266 comments (clear)

  1. A horrible idea... by ovit · · Score: 5, Insightful

    This strikes me as a horrible idea.

    I fear that by building these loopholes, we will actually be legitamizing the DMCA as a whole... And we will be losing 1 more datapoint in our arguments against this monstrosity...

    1. Re:A horrible idea... by Urusai · · Score: 5, Insightful

      We can defeat the DMCA by moving all research to a democratic country. Hopefully, they'll take me with them.

    2. Re:A horrible idea... by nine-times · · Score: 5, Insightful
      Well, IANAL, but the summary that, "The DMCA currently makes it illegal to bypass digital locks almost regardless of what they protect or the user's intent," seems to match what I understand about the DMCA. Now, if we can get enough loopholes in it that it becomes legal again to bypass digital locks and break encryption *for a good reason*, then I have no problem with the DMCA. I'm perfectly fine with people being legally forbidden from bypassing digital locks without any argument as to why they have a valid reason to do so.

      For example, if I encrypt my personal data on my hard drive, I think it should be generally illegal for you to break the encryption, just like it's generally illegal to break into my house. That's fair, right?

      The problem I have with the DMCA is the idea that it might allow someone to lock data that I believe I should have access to, and I have no legal recourse. For example, AFAIK, it's illegal to rip DVDs to your hard drive, even if you have no intention of violating copyrights. To my mind, that's like being forbidden from creating an alternate means of entry into my own house, rather than being forbidden from breaking into someone else's house.

      I guess what I'm saying is, if the US government wants to give stiffer penalties for copyright infringement if the act includes bypassing copy protection, that doesn't bother me. Insofar as the DMCA does that, I don't mind. It only starts bothering me if it's used to go after private individuals who bypass protection for the purpose of fair use.

    3. Re:A horrible idea... by Em+Adespoton · · Score: 4, Insightful
      It's been a while since I've read the DMCA, but I'd like to comment on some of your comments.

      For example, if I encrypt my personal data on my hard drive, I think it should be generally illegal for you to break the encryption, just like it's generally illegal to break into my house. That's fair, right?

      Yes, that's fair, and that's why it's illegal even without the DMCA. The trick is that most laws don't make methods illegal, they make actions illegal. Accessing your personal property without permission is illegal.

      The problem I have with the DMCA is the idea that it might allow someone to lock data that I believe I should have access to, and I have no legal recourse. For example, AFAIK, it's illegal to rip DVDs to your hard drive, even if you have no intention of violating copyrights. To my mind, that's like being forbidden from creating an alternate means of entry into my own house, rather than being forbidden from breaking into someone else's house.

      AFAIK, the DMCA says nothing about ripping DVDs; they can be easily imaged to a HDD. The trick is that you get into copyright trouble (DeCSS) when trying to convert them to a new format playable by software not originally designed to play the DVD. Also, the DMCA says nothing about region encoding. Your thoughts on the subject are still valid however.

      I guess what I'm saying is, if the US government wants to give stiffer penalties for copyright infringement if the act includes bypassing copy protection, that doesn't bother me. Insofar as the DMCA does that, I don't mind. It only starts bothering me if it's used to go after private individuals who bypass protection for the purpose of fair use.

      It bothers me -- methods should not create stiffer penalties; actions should. People get caught up in the "technology" used to commit pre-defined crimes, and forget that they are already crimes irrespective of how they were committed. We don't need an "Internet auction fraud" law, because we already have a perfectly usable fraud law that applies. If an old law no longer carries appropriate penalties for a crime, the old law needs to be revised.

      To sum up, everything illegal under the DMCA that should be illegal already was -- everything else is being overturned on a case-by-case basis, which is putting the onus on the innocent parties to prove they're innocent, instead of putting the onus on the prosecution to prove they're guilty. The DMCA is a "guilty until proven innocent" law.

  2. Corporations or the Government? by Beliskner · · Score: 3, Insightful

    I am grateful to live outside the United States when I see lawyers, judges and DMCA bureaucrats shackling reasonable fair use and fair experimentation research.

    --
    A caveman dreams of being us, the incalculable power and riches. We dream of being Q, then what?
  3. It's Really Sad That... by Nom+du+Keyboard · · Score: 5, Insightful
    It's really sad that someone has to ask for this exemption. It should have been there from the beginning. Furthermore, I should be able without fear of prosecution to investigate anything on my computer that affects its operation for the purposes of removing it safely and completely without fear of prosecution.

    Just another reason why politicians shouldn't be writing laws concerning subjects they know nothing about.

    --
    "It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
    1. Re:It's Really Sad That... by Nom+du+Keyboard · · Score: 5, Insightful
      it's not reasonable to assume that they would prosecute you unless you published the information you obtained (indeed, how would they know?).

      By your interpretation, every single user would have to be a Computer Scientist able to diagnose and repair their own complex operating software, since no one could share their discoveries.

      And since Viruses hide themselves, no anti-virus firm could market a product to remove them since that would be making use of illegal bypassing of the Virus's anti-circumvention provisions.

      You see where this leads. Without the ability to share information on threats, the ability to remove and protect against them is essentially nullified. The DMCA is a damn horrible awful thing for consumers.

      --
      "It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
    2. Re:It's Really Sad That... by ZachPruckowski · · Score: 5, Insightful

      Well, be careful not to overstate the problem. While the language of the DMCA makes it clear that it is illegal to even do this type of investigation with your own computer, it's not reasonable to assume that they would prosecute you unless you published the information you obtained (indeed, how would they know?)

      First of all, I don't like actions that are necessary for my safety to make me a "criminal", even in the theoretical (non-prosecutorial) sense.

      Secondly, it reflects badly on a gov't to have a law that is unenforceable.

    3. Re:It's Really Sad That... by gstoddart · · Score: 5, Insightful
      It's really sad that someone has to ask for this exemption. It should have been there from the beginning. Furthermore, I should be able without fear of prosecution to investigate anything on my computer that affects its operation for the purposes of removing it safely and completely without fear of prosecution.

      Exactly. The computer is the person's property. I don't understand how the owner doesn't retain full control over it.

      But, I'm confused. Isn't reverse-engineering broad enough to cover researchers dissecting it?

      If the day comes that anything with 'digital security' can't be looked at except by those who made it, we'll all be screwed. Hell, I should think you could go around putting a physical device on people's cars and houses that locks them -- and since it's got some digital components, it would be illegal for the owner to open them without running afoul of the DMCA.

      No room for extortion there --- "You're not allowed to remove our lock from your car due to the DMCA, but for $1000 we'll remove it" -- what if the lock was placed illegally? (Or the software was installed surrepticiously in the case of spyware.)

      This is completely irrational. If I go to a store and buy new windshield wipers, the merchant can't make it illegal for me to buy windshield wipers from someone else ever again.

      At some point, the consumer needs the ability to terminate a contract when they no longer wish to do business with someone. Making it illegal to dissect/remove spyware would be like enforced vendor lock-in in the real world. You signed up once, now you have to be signed up in perpetuity??
      --
      Lost at C:>. Found at C.
    4. Re:It's Really Sad That... by Shakrai · · Score: 4, Insightful

      Just another reason why politicians shouldn't be writing laws concerning subjects they know nothing about.

      Actually, you should have said "just another reason why politicians shouldn't be enacting laws that were written by lobbyists". It's a bit unfair to demand that Congresscritters will be experts in all subjects.

      But on a related topic -- why isn't there a CTO (Congressional Technology Office)? There's the Congressional Budget Office -- which is (allegedly) a non partisan office that exists to advise Congress on budgetary issues. They are the ones releasing the figures about Social Security that disagree wildly with what the White House would have us believe.

      So why shouldn't there be a CTO? It's unreasonable to expect that all Congresscritters can be knowledgeable techies. They should have a non partisan agency to advise them about these issues -- then perhaps stuff like this wouldn't be overlooked.

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
    5. Re:It's Really Sad That... by Loconut1389 · · Score: 3, Insightful

      someone needs to make a bunch of boots for cars that have some sort of encryption (rot13?) that would make it illegal to remove and then just start booting senators cars.

    6. Re:It's Really Sad That... by IAmTheDave · · Score: 3, Insightful
      You see where this leads. Without the ability to share information on threats, the ability to remove and protect against them is essentially nullified. The DMCA is a damn horrible awful thing for consumers.

      True - imagine a world where you couldn't share any information regarding any threat. See a person with dynamite strapped to them? Don't say anything, you could be sued for removing their coat to see the bomb. Car built with bad brakes? Don't say anything, you'll be prosecuted for removing the tire which protects the brakes.

      Sharing information is the very cornerstone of freedom, and using the DMCA to control information is quite evil.

      --
      Excuse my speling.
      Making The Bar Project
    7. Re:It's Really Sad That... by hanshotfirst · · Score: 2, Insightful

      So... you're saying there should only be laws about sucking up, pandering, money grubbing, and backstabbing?

      Can anyone say "Campaign Finance Reform"? They can't even write good legislation on the subjects mentioned.

      I thought the reason for choosing to be a representative republic (rather than a pure democracy) was that the common man wasn't educated enough to make critical decisions. Oh wait - that's the electoral college. The congress was supposed to represent the interests and concerns of the public who elected them.

      How did it get all backwards in 200 years??

      --
      Why, oh why, didn't I take the Blue Pill?
  4. Hindsight by theRhinoceros · · Score: 3, Insightful

    Part of me wishes Sony had not withdrawn their software voluntarily and had put up a legal fight, such that the courts could have struck down parts of the law as unconstitutional and or invalid. An appeal to the US Copyright office has less legal weight and force of precedence, IMO.

    1. Re:Hindsight by Miros · · Score: 3, Insightful

      Sure, but that wouldn't make any sense. Defending their actions would cost more money than they hoped to recover by thwarting piracy. By retracting the software, they enable themselves to do it again (but more carefully) without having to pay for the right to do so (expensive court case).

    2. Re:Hindsight by shotfeel · · Score: 2, Insightful

      A agree with the latter part of your statement, but the first part makes a big assumption -that DRM is about thwarting piracty. IMO its not. Its about controlling content after the sale. For proof I can offer only:

      Conjecture : The RIAA and MPAA know DRM schemes will be broken, thus don't rely on them to protect their revenue stream.

      Observation : The MPAA already has more control over your DVD player than you do. I've already run across a couple DVDs that won't even allow me to bypass the trailers at the beginning. Even pushing the "Stop" button only elicits an "Operation Not Permitted" message. Is that preventing piracy or exerting control?

      Just wait until the broadcast flag passes, TiVo has already given us a glimpse. Think you'll be able to save an entire season of a show on your PVR? Think your PVR will allow you to fast-forward through commercials? Isn't it wonderful what digital tech lets them do that they couldn't do with the old analog stuff because they were too late? Note how current laws like the DMCA are the only things that let them do it.

  5. Would they have dared? by despe666 · · Score: 5, Insightful

    It would have taken a lot of gall from Sony to sue anyone who would blow the whistle on their rootkit. Their public image has been damaged enough as it is with the rootkit scandal to damage it even more with a stupid lawsuit.

    1. Re:Would they have dared? by MightyMartian · · Score: 5, Insightful

      Look at Sony's first response when it was revealed what they were putting on people's computers. I'll wager Sony would have sued. Remember, these guys have no ethics whatsoever. They'd sell their own mother if they thought they could get away with. It seems, however, that the corporate whores in Congress won't be doing anything to assure that this stunt leads to jail time and substantial fines for those who thought up the stunt. That sort of treatment is only for little girls, old men and mothers who get accused of pirating. When a big corporation does it, that's okay, because Congressmen are getting whores, cash and vacations. Perhaps that's the solution. Taxpayers should build up bribe accounts so that when they need to protect themselves from ludicrous laws, they can hand it to the whore that represents them so that maybe he won't sell them down the river for a financial blow job.

      --
      The world's burning. Moped Jesus spotted on I50. Details at 11.
  6. It's like guns by Red+Flayer · · Score: 5, Insightful

    In the US, it is legal (with restrictions) to own a gun. It is not legal to go out and randomly pop a cap in someone's behind. The tool, or mechanism, is legal, but the act is not.

    Contrast that to the restrictions being argued against. The tool, circumvention of copy protection technology, is illegal. The act, distributing copies in violation of copyright, is also illegal.

    Why is circumventing copy protection illegal? Because the **AA want it to be.

    Say I want to rent a bike for the day. I license the use of the bike, and am provided with a bike lock. Is it illegal for me to pick that lock? Even if you go by the **AAs' ridiculous licensing theory, it still doesn't make sense to have circumventing copy protection be illegal.

    --
    "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
  7. Re:what tools! by CyberLord+Seven · · Score: 3, Insightful

    Your argument doesn't work against those wanting the excemption. Your argument actually applies to employees of the Sony corporation who knew that they were installing a rootkit on computers and what damage it could do. This is closer to the Nuremburg Trials situation wherein Nazi officers claimed that they were only following orders.
    At Nuremburg the court held that if you know something is wrong/evil you are obligated to not do it no matter what your superior officers tell you to do.

    --
    We have always been at war with Eurasia!
  8. Re:what tools! by Rosco+P.+Coltrane · · Score: 2, Insightful

    If you know that someone is doing something mean, nasty and evil.... you let someone know. Plain and simple.

    I assume you have plenty of money to fight frivolous lawsuits filed against you when you heroically denounce evil deeds, right? For the rest of us, when the law muzzles us, we tend to shut up because otherwise we'd go broke. Sad but that's how it is, and I suspect you'd probably do the same despite all your Slashdot bravado.

    --
    "A door is what a dog is perpetually on the wrong side of" - Ogden Nash
  9. Reverse Engineering / Removal by Renraku · · Score: 5, Insightful

    If a company ever tried to bring charges against me because I released a fix to their crippleware/malware/spyware/lameware to neuter it or remove it completely, I would be citing 'home defense' laws.

    They brought their property, on to yours, with the intent to cripple or hinder use of your equipment, without adequately informing you and without your express permission. In my world, this is the same as home invasion. Just the same as a fat man standing over your computer yelling at you or fucking with your machine's innards when you weren't looking.

    Its absolutely retarded that this is even LEGAL. The only reason they haven't been able to apply the DMCA to car innards is because they know that the person OWNS that piece of equipment, and putting in measures to defeat it would be taken apart in all of ten minutes. And spread the information. Eventually it would lead to bad press, as a useless piece of metal would be trying to keep you from having access TO YOUR OWN car. Same thing with computers and software..but people don't think they're as important as things meatside.

    --
    Job? I don't have time to get a job! Who will sit around and bitch about being broke and unemployed then?
  10. Re:what tools! Nope by Nom+du+Keyboard · · Score: 3, Insightful
    will do NOTHING. Sounds like the defence used in the Nurenburg trials.

    Nope. At Nurenberg they were on trial because they'd definitely done SOMETHING! They were not guilty of acts of ommission, like forgetting to tell you that they'd installed DRM software onto your computer BEFORE presenting you with an EULA and asking if you wanted to allow them to install software on your computer.

    --
    "It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
  11. Prohibition of curiosity by Anonymous Coward · · Score: 2, Insightful

    How can it be moral or ethical to prevent someone from examining how something they use and integrate into their computer? A person should have the right to know what they are buying, renting, or using when they pay for it. They should know exactly what a computer program is doing, especially when the computer is also used to buy items online and check health care stuff. I expect to know what I am buying whether it's a a hamburger (does it have something I am allergic to? Is it prepared safe ?), a paper plate, a car (do the brakes work as normal), or software (does it make my system vulnerable, can it affect other software?).

    And no, them saying it won't does suffice (unless I get a massive payment if it turns out they are wrong). Not even third party certification would work (although they would never agree to that anyway).

  12. Re:what tools! by diogenesx · · Score: 3, Insightful

    Perhaps they kept thier mouths shut not only out of fear, but to use the situation as an opportunity to do exactly what they are doing. By waiting until it was public they have legitimized their claims without fear of a lawsuit.

  13. Reasonable Action by massivefoot · · Score: 2, Insightful

    Does anyone know if similar laws to the DMCA exist is the UK? I'd be seriously worried if they do. I'm of the opinion that you have a right to bypass any technology used to protect spyware. It's a pretty deceitful form of software, it's effectively carrying out surviellence against you, you should be able to respond to it.

  14. My computer is my property. by mmell · · Score: 3, Insightful
    I rent an apartment. The landlord has a right to enter and inspect, but not to dictate how I will decorate and maintain my apartment (other than to say that I mustn't damage the property).

    So . . . why do software manufacturers (including malware manufacturers) have a right to dictate what I will do with my hardware. Certainly, if I start making bootlegged copies of software/data available I can see where I have abnegated the implicit agreement between myself and the software vendor (damaging the apartment), but so long as such transgressions remain securely within the bounds of my equipment they should have no right to complain (I furnished the apartment with the most hideous furniture in existence, but the apartment remains undamaged).

  15. Re:It's Really Sad That...Bad Because? by Nom+du+Keyboard · · Score: 2, Insightful
    Politicians don't know anything except politicking - if we followed this rule then we wouldn't have any useful laws.

    And this would be bad because...?

    --
    "It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
  16. Re:Pros And Cons by MightyMartian · · Score: 2, Insightful

    Look, the hackers don't give a damn about the DMCA. Heck, a good many live outside the US, so what does that even matter. By making circumvention illegal, the only people that are being harmed are consumers who don't find out when corporate villains like Sony start distributing this kind of crap until it's too late. But Congress is the core of this. By essentially ignoring anything other than the corporate sugar daddies, they have tacitly given them permission to be as immoral and unethical as they please.

    --
    The world's burning. Moped Jesus spotted on I50. Details at 11.
  17. Good. Freakin'. Luck. by Caspian · · Score: 3, Insightful

    Look. If American corporations and the American government actually wanted to work together to eradicate spyware (as opposed to working together to make lots of money), we wouldn't have spyware. We also wouldn't have spam, viruses, or any number of other nasty things. The fact of the matter is that almost all sorts of online nastiness can be used to benefit the already super-rich. Example: Spyware used to benefit Sony (or so they think), viruses used by companies to insert, well, spyware... spam used, of course, to advertise the products of big companies (directly, indirectly, or "The makers of Viagra paid a marketing firm, who paid another marketing firm, who paid a slightly sleazier marketing firm, who sold a list to an even sleazier one, who sold it in turn to an even sleazier one, who ended up spamming you about buying Viagra")...

    They. Don't. Give. A. Fuck. In fact, tacitly I think they like this sort of online plague, since they know damned well that only the 'little guys' (read: their competition and their user base) will ever get in trouble for breaking the DMCA, or spreading spyware, or releasing viruses, or spamming-- but they never will.

    It will be a cold day in Hell when Sony actually experiences any pain over this. N.b.: A pathetic boycott by 0.1% of 1% of nerds, who in turn make up 1% of the population, will not cause them pain. Also, a $100,000,000 *kof*slaponthewrist*kof* "fine" will not cause them pain either.

    The DMCA was conceived as a way of keeping the rich rich. Full stop. End sentence.

    And to those of you who think that the combined might of the Fortune 500 companies and the American government couldn't eradicate spyware, spam, etc. if they REALLY wanted to, think again. It's as simple as implementing new security standards and specs, testing them with the cooperation of the security community, setting a worldwide/nationwide rollout date, then requiring everyone's software to support them as of that date. Think "Attention (ebay|Yahoo|Google|MSN) Users: After JULY 23, 2007, you must have upgraded your Web browser to support the new HardenedHTTP specification. Browsers which support this include: Mozilla Firefox 2.0, Netscape 8.1, Opera 9.01, or Internet Explorer 8 Beta."

    Yeah, it'd cost billions. But these companies and the US government, put together, have TRILLIONS.

    They don't care, though. They'd rather bring their considerable resources to bear upon the tricky problem of making their CEOs and Board members a few more billion apiece. Consumers? Pfeh, they don't even have people to read their email for them. Who cares about them?

    --
    With spending like this, exactly what are "conservatives" conserving?
  18. Re:Hindsight - wrong way around by Nom+du+Keyboard · · Score: 2, Insightful
    Part of me wishes Sony had not withdrawn their software voluntarily and had put up a legal fight, such that the courts could have struck down parts of the law as unconstitutional and or invalid.

    Sony wouldn't have had a DMCA fight by continuing to ship the software. That's not illegal under the DMCA, nor are they being sued under its provisions.

    The researchers who determined how it worked, and how to workaround and/or remove it would have had to carry the burden of the fight if Sony charged them with violating the DMCA.

    Sony had to pull it because of: a) Immense bad PR; and b) Being sued for every instance still out there under Spyware/Computer Invasion laws. Sony's only hope for defense (a huge lie, btw, in light of what has been revealed since this story first broke) is, "We didn't know it was bad when we shipped it, and the moment we found out it was bad we recalled it and offered replacements."

    I hope this won't save them because they truly deserve to go all the way down over this, and should serve as a severe warning to every other remaining company that this is just plain Wrong!

    --
    "It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
  19. Slashdot is alone in this.. by jskline · · Score: 2, Insightful

    I generally do not see much of any coverage relating to the issues surrounding the DCMA and all the hoopla coming from it. Seems like all of the news about it is on Slashdot or the Register. Why are the big news outfits not publishing anything on this???

    My suspicions are that "keeping it quiet" is a tendancy being brought about by a select group of lawyers that work quite possibly in the entertainment industry, and are looking to covet their bank accounts and the future deposits thereof.

    I mean;.. we all know the silly thing is entirely political apeasement to a small group, and that somehow the thing got in and passed with very little fanfare. What is disturbing is that it takes all this to convince folks to take a look at the language of this thing, and research it against constitutional law. Odds are that you would find that it nullifies much of your rights without you ever even committing a crime!

    Yea, I know... "Black hellicopter" and all... but.. sure does make you wonder what the heck is going on!!

    Cheers.

    --
    All content in this message is copyright (c) 2008. All rights reserved. RIAA is prohibited here.
  20. Re:Why doesn't MS patch autorun? by Prophet+of+Nixon · · Score: 2, Insightful

    There should just be a general warning, "Do you wish to allow execution of software on this CD?" for all CDs that try to autorun... with games/programs/etc, the answer is probably yes, but seeing that on a music CD, or a DVD should set off some alarms in people. Maybe even have a list of known CDs somewhere, so that you can click a 'always do this action for this CD' box or something, sort of like what they do with file types.

  21. Re:what tools! by drdewm · · Score: 2, Insightful

    If the government told you to jump off a cliff or chop your own hand off would you? No of course not and even if they made a law saying that all left handers must chop off their left hands and become righties you still wouldn't. When the laws are ridiculous and the governement is out of control people need to stop obeying and change them out even if it's bloody and hard. The US govenment used to be like a block of cheese that had some mold (corruption) on the outside which you could avoid and still enjoy the center. Now the whole thing is moldy and the room smells like feet so something has got to be done, unless of course you enjoy the smell of toe cheese.

  22. The US IS less democratic by parodyca · · Score: 5, Insightful

    then it ever use to be.

    Who modded the parent as Flamebait? The US has moved far from it's democratic ideals. It may not be any China or North Korea, but it is a far sight less free and democratic then it ever use to be.

    To wit:
    1) DMCA
    2) Patriot Act
    3) Congressional gerrymandering.
    4) Copyright extentions and patent law broadening.
    5) Air travel ID requirements