Schneier: Steps to combat file-sharing are misguided

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

Q&A

Leading security expert Bruce Schneier was in London this week on a whirlwind lecture tour. ZDNet UK caught up with the ex-NSA man, who is now BT's chief security technology officer, at lectures in parliament and at University College London.

Schneier talked to ZDNet UK about his views on behavioural advertising, the efforts of various governments to tackle unlawful file-sharing, cyber-warfare and vendor lock-in.

Q: The UK government is currently trying to pass the Digital Economy Bill, which includes provisions to penalise unlawful file-sharing. Is this technically feasible?
A: The problem with a lot of these measures is that they only affect the average user. Professionals, hackers, clever people can get around them.

No, I don't think this is technically feasible. The ones they don't care about, the average user, are the ones they are going to stop, and the detection mechanisms are sloppy. There are so many examples of the industry getting it wrong.

If you look at the economics, file-sharing is good for music companies. They've got it wrong. Records were originally sold to promote live performances. When they realised people wanted to buy the records, they changed their business model. They are going to have to change it back. Or Steve Jobs will.

The bill does not require a court order to disconnect people from the internet. Is that reasonable?
I'm not a fan of vigilante justice, which in general is what these laws are. Similar laws are being developed in the US, in Germany, in France, in the UK, and the notion they are lacking is due process.

What is your view of copyright?
The costs of a movie are tens of millions of dollars, but then distribution costs nothing — a couple of pounds for a DVD, files are just about free.

That means the industry has to invent anti-capitalist cheats, like patents and copyright, that are effectively legally guaranteed monopolies in distributing the thing. These are all ways to try to recover fixed costs.

A lot of computing devices we buy have that strategy, combined with switching costs — the cost to switch from a product to a competitor. Sometimes those costs are high.

Are you thinking of any devices or software in particular?
The cost to switch from Internet Explorer to Firefox is high — you have to change your default browser, change bookmarks, and so on. I still use Opera, because switching costs are high.

You can get companies stuck in a product because switching costs are so high. They have a system with six years worth of data bound up in it. Throughout IT, companies try to keep up switching costs. With iTunes, you might have £500 worth of music, which you will lose if you switch.

It's the same with proprietary formats. Microsoft doesn't want other people using its formats, because that will keep the switching costs high. It makes the effort to use different document formats high.

How is the security industry changing?
IT is becoming part of the infrastructure — it's just there. IT is becoming a utility, something you just expect in a job, like a desk or a stapler.

A car comes with security features fitted in. You don't buy a car and they say to you, 'Oh, by the way, we really recommend you stop off at a third-party supplier and get some brakes'. I don't buy bottled water and expect it to kill me. Security will stop being a separate thing and become part of the thing.

There are numerous organisations using deep packet inspection at the moment, for reasons ranging from law enforcement to behavioural advertising. Do you think using deep packet inspection for behavioural advertising is necessary?
I don't like it, I think it's an invasion of privacy, but we live in a world where anything legal can be done. As long as they are allowed, companies will do it — because otherwise they would be crazy not to.

In the US, we have separate carriers and content. The carrier is not supposed to touch the content. In the US DPI is an extremely bad can of worms.

A lot of countries have come out in the past couple of years and said they are developing or have developed cyber-offensive capabilities, including the UK and the US. Is this necessary?
I think it's stupid not to do it, but a cyber first strike will never happen, because the collateral damage would be too great. Unintended consequences.

Do you think the internet itself, or internet provision for a particular country, could be brought down?
It's hard to say. The internet on the one hand is so resilient, and on the other hand so fragile. If you really wanted to take it down, you could. The DNS system is so fragile. My belief as to why it hasn't been done yet is because it would require a lot of specialist knowledge. There just aren't a lot of people who could hack the backbone.

There are only 14 critical nodes in the switching network, and we see outages caused by physical accidents like undersea cables being cut.

The weird thing is, we are talking about emerging properties. You don't know when a worm is released what the extent of the damage will be. There was a blackout in the north-east quadrant of the US when Blaster was released, that was probably caused by Blaster. We're dealing with emerging properties, in tightly coupled non-linear systems. The way to figure out what will happen is to try it.

Talkback

i read your article ,with a little bewilderment and yet a little glimmer of hope, for us the commomners, without whome their would be no internet or buiseness or anything,because we are the public/the customers/the people and before people who we elect go passing silly laws and disconnecting people, THEY THEY HAD BETTER WATCH OUT,NOW I KNOW THEIR PUMPING US FULL OF STUFFS TO QUELL US ?but it will were thin and their will be riots thats why governments are arming the police, because they know there just bordering on mass anarcy mark my words sez lezlow

lezlow 10 December, 2009 20:33
Reply

Yup I wasn't expecting that either, good read.

CA 10 December, 2009 21:17
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

1 hour ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

1 hour ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

18 hours ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

18 hours ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

20 hours ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

20 hours ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

21 hours ago by apexwm on Windows 8 start-up speed forces USB boot workaround
Gavin Goodman

You can now buy the Xi3 modular computer in the UK at http://www.ocdistribution.com . This can be bought with the Tand3m software, pricing and...

21 hours ago by Gavin Goodman on CES 2012: Xi3 microSERV3R
Phil at Cloud4

I agree: Mike Lynch can clearly build a business and manage strategy. I suspect the exit of Mike is more likely the end of a planned handover...

1 day ago by Phil at Cloud4 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Phil at Cloud4

This is unbeleivable government wastage with only one winner... Microsoft 1 - Tax payer Nil!

1 day ago by Phil at Cloud4 on 6 million wasted licences and £1,200 PCs: welcome to government IT
Mispam

So what do you do when you can't boot into windows? Why can't I just hold Shift while I power up instead of having to boot into windows and click a...

1 day ago by Mispam on Windows 8 start-up speed forces USB boot workaround
apexwm

I've also seen that Mac OS X for Intel machines is supposed to run in VirtualBox, which would also be a nice solution. I've never tried it though.

1 day ago by apexwm on xTreme Triple Booting: Linux, Mac & Windows
dave heasman

What I wonder is why when companies are caught bang to rights in not providing contracted services, people bend over to smear the customers? Surely...

1 day ago by dave heasman on Virgin throttles broadband for high-speed customers
pjc158

Strange statement from HP regarding Mike Lynch and not capable of scaling a company. Autonomy was a $7bn purchase which started as a small company...

1 day ago by pjc158 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
lojolondon

Or - possibly, they will destroy business by ensuring people do not invest where there is no return. Another socialist idea, well beyond it's...

1 day ago by lojolondon on Open Data Institute will act as biz incubator
J.A. Watson

Good stuff Jake, very interesting. Thanks. jw

1 day ago by J.A. Watson on xTreme Triple Booting: Linux, Mac & Windows
openhgs

"the cost of a second LCD screen is about the same as one day of an office worker's time, so this should soon be recouped in extra productivity."...

1 day ago by openhgs on Windows 8 could speed multi-monitor uptake
Thomas Gellhaus

I also installed the KDE version; I also will probably try out razorqt since I really haven't had a chance to before. I'm looking forward to the...

2 days ago by Thomas Gellhaus via Facebook on Mageia 2 Released
francisabigail

Acquiring when reinvention/cannibalization is too challenging for a large organization can be an excellent strategy- still, so many mergers stumble...

2 days ago by francisabigail on Ariba buy parks SAP on Oracle's cloud turf
apexwm

All of the feedback regarding using a touch monitor for a desktop PC is right on. Several months ago, we installed a "demo" multitouch all-in-one...

2 days ago by apexwm on Windows 8 could speed multi-monitor uptake