Copyright act gags programmers

NEWS
Two well-known computer security experts pulled down their works from the Internet this week for fear of being prosecuted under 1998's Digital Millennium Copyright Act. Along with the threatened lawsuit of Princeton computer-science professor Edward Felten, and the arrest of Russian encryption expert Dmitry Sklyarov, the incidents are the latest to point at what is quickly becoming a touchy environment for security experts. "When they started to arrest people and threaten researchers, I decided the legal risk was not worth it," said Fred Cohen, a well-known security consultant and a professor of digital forensics, who took his evidence-gathering tool--dubbed Forensix--off his Web site earlier this week. Dug Song, a security expert at network-protection company Arbor Networks, pulled his own site down in protest as well. Now the only text on the site, "Censored by the Digital Millennium Copyright Act," links to a DMCA protest site, Anti-DMCA.org. And last month, fearing retribution, Dutch encryption expert Niels Ferguson refused to publish his discovery that Intel's encryption scheme for Firewire connections, known as the high-bandwidth digital content protection (HDCP) system, had a major flaw. "I travel to the US regularly, both for professional and for personal reasons," he said in an online statement. "I simply cannot afford to be sued or prosecuted in the US I would go bankrupt paying for my lawyers." Lawyers and proponents of the law argue that the response from the security community is at best a misinterpretation of the law and more likely protest veiled as legitimate fear. "Some of the opponents of the DMCA are trying to resurrect this issue to get another day in court," said Robert Holleyman, president and chief executive of the Business Software Alliance, the piracy-fighting organisation that represents the lion's share of software companies. "Security testing is definitely permitted under the DMCA." The DMCA, passed in 1998, prohibits the circumvention of copy protection and the distribution of devices that can be used to circumvent copyrights--even if their users don't do anything illegal once they've broken the security. Software makers, Hollywood and the music industry make up the core proponents of the law. The BSA says such laws are necessary to head off software piracy, which the group estimates cost software companies $11bn (about £8bn) in lost revenue last year. Yet, for many security researchers the question is whether stress-testing the security of software products and publicising vulnerabilities and how they were taken advantage of violates the DMCA. "There are provisions in the law for certain security research," said Mark Smith, a network-security engineer and spokesman for Anti-DMCA.org, "but you shouldn't have to hire a lawyer to make sure you are not breaking a law." That's a problem in an industry where a large number of security vulnerabilities are found by individuals and small groups of hackers--the people without the deep pockets to fend off a lawsuit or hire lawyers to review research prior to its release. That pretty much turns the question of publishing into a business decision, said consultant Cohen. "From a risk-management standpoint, I can't afford to deal with the issue," he said. "Some big businesses can afford to sell the product. I can't." But Marc Zwillinger, an intellectual-property attorney and partner at Washington, DC law firm Kirkland & Ellis, calls Cohen's move a political one. "I don't think that forensics software would (be considered illegal) under any reading of the DMCA," said the former Department of Justice attorney, who now files suit on behalf of copyright holders. He said Cohen's forensics tool is a program that is not primarily designed to circumvent the protections of copyrighted work, so his actions are unnecessary. And the Dutch researcher has little to worry about, at least from US authorities, Zwillinger said. "You cannot be arrested under the DMCA unless you are selling software for profit," he said. Yet the willingness of software makers and media companies to sue over any potential threat makes security researchers nervous. In 1999, the movie industry filed multiple lawsuits against the creators of a program to decrypt DVD disks. Originally, the program had been created to add DVD playback ability to the Linux operating system. This April, Princeton's Felten found himself on the sticky side of a threatened lawsuit when he planned to release research questioning the effectiveness of a purported Secure Digital Music Initiative. Following the filing of his own suit, the professor presented his paper at the USENIX Security Conference in August. But it was the arrest and criminal indictment of Russian encryption expert Dmitry Sklyarov at the Def Con hacking conference that really drove the point home. The incident also unnerved Russian programmers thinking of visiting the United States. "We would like to draw the attention of all the Russian software and programming specialists cooperating with US firms that, regardless of a final decision in the Sklyarov case, provisions of the 1998 Act may be used against them on the territory of the United States," the Russian Ministry of Foreign Affairs said in a statement issued last week. Already, some security researchers are going underground. Last week, when an encryption expert reportedly found a hole in Microsoft's e-Book format, he anonymously went to the news media rather than face arrest. According to Anti-DMCA.org's Smith, the DMCA could dramatically set back computer security. "We crash test cars to create stronger, safer vehicles," he said. "We need to crash test software to promote stronger, safer software. But with the DMCA, a company can do minimal research on security, and if someone does crack their software, they can sic the FBI on them." See the Net Crime News Section for the latest on hacking, fraud, online child safety, viruses and legal issues. See the Software News Section for full coverage. Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum. Let the editors know what you think in the Mailroom. And read other letters.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

32 minutes ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

3 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

3 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

4 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

5 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

6 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

6 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

6 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

7 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

7 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

8 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

8 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

8 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

11 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

12 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

12 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

13 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

14 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

16 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

24 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility

Latest in Application Development