A Legal Analysis of the Sony BMG Rootkit Debacle
YIAAL writes "Two lawyers from the Berkeley Center for Law and Technology look at the Sony BMG Rootkit debacle: 'The Article first addresses the market-based rationales that likely influenced Sony BMG's deployment of these DRM systems and reveals that even the most charitable interpretation of Sony BMG's internal strategizing demonstrates a failure to adequately value security and privacy. After taking stock of the then-existing technological environment that both encouraged and enabled the distribution of these protection measures, the Article examines law, the third vector of influence on Sony BMG's decision to release flawed protection measures into the wild, and argues that existing doctrine in the fields of contract, intellectual property, and consumer protection law fails to adequately counter the technological and market forces that allowed a self-interested actor to inflict these harms on the public.' Yes, under 'even the most charitable interpretation' it was a lousy idea. The article also suggests some changes to the DMCA to protect consumers from this sort of intrusive, and security-undermining, technique in the future."
Good old greed..
This shouldn't be about laws, its a moral issue.
Laws don't and should not be the only guiding factor in the actions of people or corporations. It is not the case that anything specifically prevented by law is allowed. A person or corporation should also be a good citizen, and there are things you just should not do, such as inflict root kits on other people's computers.
The question then is; how did somebody at Sony arrive at the conclusion that they should try to protect their IP right in this manner?
Waas this a comittee decision where moral judgement went out the window in a corporate meeting? Or are people at Sony severely lacking personal moral judgement?
I would like to know.
A quote from Lessig's Free Culture:
Legal norms are not just about judicial precedent.
Of course this would be a non-issue if Windows didn't automatically run software when you put a CD in the drive; this is just another reason why auto-run is an insanely bad idea.
Can we please get an Icon that has a foot and a handgun?
Support NYCountryLawyer RIAA vs People
...the market-based rationales that likely influenced Sony BMG's deployment of these DRM systems... ...demonstrates a failure to adequately value security and privacy.
... then-existing technological environment that both encouraged and enabled the distribution of these protection measures... ... flawed protection measures... ... contract, intellectual property, and consumer protection law... ...is whatever the hell Sony's legal department says it is. And we have many, many millions of dollars, euro, UK pounds, or yen to prove it. Without the cash, talk is trash.
... Yes, under 'even the most charitable interpretation' it was a lousy idea...
...
That's pretty simple. They thought that there was a vast network of 13-year-old superhackers that were going to destroy the company by sharing files of music recordings. Then some schmuck (names? anyone who knows?) in the firmware special projects department told some marketing manager that he knew how to keep 13-year-old superhackers from copying music from CDs by simply adding a little piece of code.
The only security and privacy that they care about is their own. These concepts don't exist for people who are not executives in the company. Especially customers.
"Since we own the music on the disk that is placed into a computer CD drive, we, by the simple and obvious extension of corporate logic, thereby own the computer and all of the data inside it." If you want to become a corporate executive, you need to start thinking like one.
If it keeps ordinary people from copying stupid pop songs from our CDs, then it is not flawed. If it destroys or corrupts the data on user's PC, we don't care. Serves them right as they are supposed to only be listening to CDs on a real Sony CD player. After all, we invented the CD so we can set the terms on its use.
Next year's rootkit software will work. And the first thing that it will do is send your name and address to our lawyer's office who will prepare a standardized form charging you with theft of intellectual property (which is some illiterate junkie thug under Sony corporate contract moaning 'baby, baby, baby' over and over). Our bot software will then serve this to anyone who puts a Sony music CD into any device with internet access (unless, of course, the device is a $999 Sony model DRM-XKE CD player with hi-def 2-inch LCD screen and wireless internet access). After all, we invented the CD so we can set the terms on its use.
suggests some changes to the DMCA
The only changes that our legal department will allow the US politicians to pass will be ones that increase the criminal penalties for possession of music. This will happen when Sony completes its corporate merger with Wackenhut and CCA and completes the vast network of corporate prisons being built in distant lands. These will be needed to hold the vast number of unemployed former American college students who not only illegally listened to music, but also fell behind on their student loan payments.
"The article also suggests some changes to the DMCA to protect consumers from this sort of intrusive, and security-undermining, technique in the future."
How about this, when an industry pushes legislative half assed measures and gets them passed in to law, they forfeit normal protections afforded every other group out there.
In this case DMCA law prohibits the consumer from doing all sorts of things, in an effort to protect a particular industry. Since Sony installed, without permission, software that effectively broke computers, they'd held to a HIGHER standard than any other organization.
In this case the law should have revoked the corporate charter surrendered all assets to the government. Since the Corporation is a "legal" entity, the same as a person, the government should treat it exactly like a person caught doing the same thing.
My $.02
Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
And now meet what I like to call handcuffs.
An easy solution to this problem, and it would only take a few instances, would be to seize all assets of the company in question and begin prosecution. If corporations are damn near treated like real humans, then let them see the other side of the coin. Make every failure in process hurt them where it matters, I guarantee we won't have this happen again. Or we end up with less corporations willing to "risk" product release in the US.
As it stands companies can seemingly get away with whatever they want to protect their business model.
My immediate thoughts upon reading it were quite the opposite actually: Having a journal article written about this might make these issues more difficult for congress to ignore or dismiss as sensationalism; if they actually take note, those who are not already in the pockets of the recording industry may find it more difficult to follow those who are.
Any piece of solid, credible research that demonstrates the reality of the situation is welcomed by me; eventually - if enough of these sorts of things are published - the weight of the evidence may become too overbearing for even the recording industry to buy off elected officials.
The rootkit was put on those CDs by Sony/BMG, which is a separate entity that is 50/50 owned by Sony and Bertelsmann (BMG stands for Bertelsmann Music Group). Furthermore, the people at the top, who make all of the important decisions are all from the BMG side. So, if either company is more to blame, it is Bertelsmann. Does this mean you should boycott Bertelsmann? It does seem a bit silly to boycott Random House (major book publisher and Bertelsmann subsidiary) over what happened to some music CDs, and yet that is what some are doing w.r.t. Sony Vaio, Sony cameras, etc. My suggestion would be to boycott the product that Sony/BMG puts out-their music CDs.
Islam certainly teaches a system of morality. Whether it is the one you want taught is another matter.
http://humanists.net/alisina/islamic_morality.htm
echo -e 'global _start\n _start:\n mov eax, 2\n int 80h\n jmp _start' > a.asm; nasm a.asm -f elf; ld a.o -o a;
Read my post again. The bit about "prism of religion". In fact Islam and the Evangelicals was exactly what I meant there. Sigh...
Baker's Law: Misery no longer loves company. Nowadays it insists on it
http://www.sigsegv.cx/
Not just because of the conclusions ("Part III examines potential market-based rationales that influenced Sony BMG's deployment of these DRM systems and reveals that even the most charitable interpretation of Sony BMG's internal strategizing demonstrates a failure to adequately value security and privacy.") but also because of the rant-free and very lucid and illuminating analysis of the factors involved.
To me, the best part was: "After taking stock of the then-existing technological environment that both encouraged and enabled the distribution of these protection measures in Part IV, we examine law, the third vector of influence on Sony BMG's decision to release flawed protection measures into the wild, in Part V. We argue that existing doctrine in the fields of contract, intellectual property, and consumer protection law fails to adequately counter the technological and market forces that allowed a self-interested actor to inflict such harms on the public.".
Those who have hopes for political action to amend the current crop of laws may be interested to read: "Finally in Part VI, we present two recommendations aimed at reducing the likelihood of companies deploying protection measures with known security vulnerabilities in the consumer marketplace. First, we suggest that Congress should alter the Digital Millennium Copyright Act (DMCA) by creating permanent exemptions from its anti-circumvention and anti trafficking provisions in order to enable security research and the dissemination of tools to remove harmful protection measures. Second, we offer promising ways to leverage insights from the field of human computer interaction security (HCI-Sec) to develop a stronger framework for user control over the security and privacy aspects of computers."
"Even today, one of the qualifications that many people look for in their elected leaders is previous military service."
"Even today, one of the qualifications that many people IN THE USA look for in their elected leaders is previous military service."
The US has a weird, hyper-patriotic society that a lot of Europeans find bizarre, brainwashing and militaristic.
And only giving the franchise to people who have previously served in the military? Screw you! What gives you the right to decide that? What gives those citizens the right to decide how everyone else gets to live? Nothing whatsoever.
Ugh... The movie... Puke...
It has nothing to do with the original message from the novel. The novel had a number of very powerful messages regarding social structure, moral, etc. These are all absent from the film. And in the novel the enemy was anything but low tech.
Baker's Law: Misery no longer loves company. Nowadays it insists on it
http://www.sigsegv.cx/
The way I see it, my computer is my property much like my house is also my property. They both have "doors" to the outside world, but that doesn't mean that anyone can just walk in and have a beer. I guess my favorite analogy is buying a new TV. What if you went out and bought a new TV that had a hidden camera in it, but you didn't know about the hidden camera, and it was broadcasting a signal to anyone who wanted to watch. Would you keep the TV? Would you litigate against the company that made the TV? The camera in the TV is much like the Rootkit in a CD/DVD/etc...They are both there "To make sure you aren't breaking any laws" but they are also massive invasions of privacy into a place that they entered without permission. It would be clear cut if it was a hardware camera, why is it different because it is a software camera?