Lala Invents Network DRM
An anonymous reader writes in with a CNet story about the record label-backed music company Lala, which claims to have invented "Network DRM." Lala has filed for a patent on moving DRM from a file wrapper, like Windows Media and FairPlay, to the server. Digital music veteran Michael Robertson has quotes from the patent application on his blog. (Here is the application.) Lala describes an invention that monitors every access, allows only authorized devices (so far there are none), blocks downloads, and can revoke content at the labels' request.
I cracked it yesterday. Next.
...you can record it. Case closed.
With a little luck, this DRM will end up on the entire network of a major corporation (we could only dream it's IBM or Microsoft!) and lock up their operations so BADLY that the entire corporate world will lash out with lawsuits. The resulting backlash could spell the end of DRM for good.
In other words, it's a patent on how to not distribute content.
This "network DRM" seems to be a combination of old news and new buzzwords.
The notion of conditional access to a server, or aspects of a server is decades old and utterly ubiquitous. If you have the credentials you can log in, access some file, do SMTP, whatever. This aspect of "network DRM" simply seems to be a renaming of password protected downloads.
The second part of this system, which they seem to want to gloss over; but is obviously there, is some sort of client side DRM. Again, utterly non-novel. They claim that it is all on the network, and you can't download and copy; but that makes no sense. If your computer is playing it to you, you obviously did download it, and it obviously resides somewhere in your system's memory.
This is pathetic. It's just a streaming service with client side DRM added on. Useless; but hardly novel.
This technology isn't exactly DRM, although it plays a roll similar to DRM. Essentially what they've done is put a access layer on a streaming server, which isn't really anything new. It's not exactly DRM as DRM is used to manage (cripple) what you're allowed to do with a file, where as this system is more like putting a tollbooth on a road. In theory once you've sucked the content down you could just rip it to a file much as the previous attempts at controlling streaming media were circumvented. Also, due to the streaming nature of this approach it's more or less doomed to failure as it won't work on anything that doesn't have a permanent internet connection (IE iPods, by far the dominate portable media player out there).
Curiosity was framed, Ignorance killed the cat.
You see, when I buy something, I like to own it. If I buy a car, I like to know that the car won't be taken away from me just because I lend it to a friend. If I cannot own something or there are stipulations, then I will not buy it. If there is no alternative than "piracy", I will obtain it. Simple as that. Why am I not buying Blu-Ray discs? I cannot be sure they will be playable for all time on my Linux computer. If I download a pirated mkv high def movie, I know that it will always be supported.
In conclusion, this won't stop illegal downloading. The only thing that can stop illegal downloading is treating your customers with respect and offering something of value, not the latest in a long line of DIVX/DRM garbage.
Then again, maybe the rest of the world isn't like me. Maybe most people in the world are stupid enough to pay for something they won't actually own.
...you can record it. Case closed.
Yeah, but this amazingly intrusive technology was planning for that:
(i) scanning storage files of the user's computer to identify any digital media content files stored therein,(ii) uploading a list of any identified digital media content files to the host computer system, and(iii) adding to the list any digital media content files that the user purchases from the purchasing component of the host computer system
You would think it would end at notifying the mothership that you are in possession of that file. Nope, from the details:
For each digital media file on the list, the Uploader finds the matching source file and transcodes the media into a format supported by the system components, if necessary.
Man, I can't wait to install that uploader only to find my entire MP3 collection has been transformed to .lala and no longer works unless I pay for it. Sounds a bit like my medical records.
My work here is dung.
I wish I were making this up - seriously. But's true - check out how nefarious these assholes are and how stupid people that they are still in business. For your dining and dancing pleasure, I submit, from TFA (emphasis mine):
The patent proves Lala is trying to develop a new type of DRM, according to Robertson. Instead of wrapping individual songs in DRM, Lala's plan calls for a network to act as a fortress that surrounds an entire music ecosystem. Lala CEO Geoff Ralston confirmed that Lala filed the patent but denied the company is trying to wrest control away from users.
"It's a patent around Web Songs," Ralston said.
Web Songs are one of the cornerstones of the company's latest business model. Lala, which has switched focus from two prior models, now offers three main features. In the first, MP3s unprotected by DRM can be purchased and download for rates comparable to iTunes. A second option offers users unlimited, ad-free streaming access to music they already own. The way this works is that users allow Lala to scan their hard drives and preserve a list of the songs the person owns. Lala's system will then stream its own copies of the songs to the user. This way users don't have to worry about losing their music to hard-drive meltdowns or misplaced music players.
Lala's last feature allows people to listen to streaming music--that they don't already own--for 10 cents per song. Lala calls these Web Songs. One of the ways Web Songs is different than MP3s is they can't be downloaded to a portable device.
"A Web Song by definition has a limited set of rights associated with it," Ralston said. "One right you don't have is the right to take it with you. It's not a portable song. Another right you don't have is to copy it. Everything has limited rights, even an MP3. You're not allowed to take an MP3, copy it, and sell it."
Here's another slice, for those who'd like to avoid RTFA (emphasis NOT mine):
"A network-based DRM system manages digital media assets stored in the network," states the document from Lala, which has been praised by music labels and has financial backing from Warner Music Group. "The system provides consumers with access to the digital media from any device connected to an electronic network such as the Internet, while enforcing the intended uses by the copyright owners."
"The Web restricted nature of the offering," Lala writes elsewhere in the filing, "means that the digital assets are at all times controlled by the system and thus result in minimal piracy."
Love the language - minimal piracy. Think about it.
Pathological kinda promises Path + Logical - but instead, you get stuck with pathetic.
Yeah, people are SO going to purchase content that can be revoked on a whim.
You mean like how no one uses the iTunes store or Steam?
The basic idea is that content is encrypted with a per-user public key, where the private key is held ("securely", for some definition of "securely") in display and playback devices that the user owns. When a private key is issued to a user, it is delivered in a secure (again, for some definition of "secure" key store, from which a limited number of copies can be imported to "authorized" (using some PKI mechanism) display and playback devices.
This has the benefit that content can (a) be copied for backup and archival purposes, (b) played on a "reasonable" number of devices a user owns, (c) played on other devices via temporary "secure" key export and import functions (so you can watch your movies at your friend's house, but not on your TV at the same time, unless on an "extra" TV -- within the limits of key copies), (d) lent to a small number of friends to access your library, and (e) allow anyone to make content for your display and playback devices (remember, the encryption key is public).
This is not rocket science, and to "someone practiced in the art" of PKI, strikes me as sufficiently obvious as to invalidate any patent claims.
It suffers from two problems:
First, the concept of someone having possession of a decryption key and not access to it are at odds. Like I said, "for some definition of 'secure'" Tamper-proof crypto chips are not cheap. Of course, the cost of extracting a key to allow access to one person's licensed media probably makes it sufficiently impractical: if media are watermarked as well as encrypted on a per-licencee basis, tracking back to who's key was used to crack some content would be easy, as well as an individual who licenses excessive amounts of content (to crack, and illegally redistribute in plain form, or encrypted with others' public keys).
Second, and more troubling, is that it does not allow for arguably fair uses: mashup videos, for example, because one can't extract some of the content, and how much could be extracted as a fair use would depend on the use. Some arguably legal fair uses could be prevented, and others abused by a group of indivuduals to reproduce the whole from the sum of arbitrarily small parts.
The issue of what happens when one loses a device holding private keys to one's media also deserves consideration. Of course, content providers could form a consortium that provide key escrow services so that lost keys could be recovered.
In Liberty, Rene
What'll you do when it gets quiet
and nothing's stored on your hard drive?
You've been renting not owning all those songs.
You know it's just a foolish buy.
Lala, I'm typing on my keys.
Lala, I need my MP3s.
Lala, darling please release my music files.
I tried to tell you not to do it,
that the server would go down.
Like a fool, you used their music tools,
Now you're left without your sounds.
Chorus
Let's store all of our own information,
you know it saves us from the pain.
Please don't say you've found a better way,
we've tried things in the same ol' vein.
Chorus
Help! Help! I'm being repressed!