Free Technology Newsletters
» All 33 InfoWorld Newsletters
Technology & Business Daily
 
InfoWorld
 
   

How the Copyright Office Protected Sony's Rootkit

By Ed Foster, Section Columns
Posted on Fri Apr 14, 2006 at 12:43:17 AM PDT

When Congress passed the Digital Millennium Copyright Act in 1998, it threw one small bone to those who feared the new law imperiled fair use rights. It mandated the U.S. Copyright Office to conduct a rulemaking process every three years to study and correct any adverse effects the law might have. And since we all know that the DMCA has had little but adverse effects ever since, it certainly leads one to wonder when the Copyright Office is going to do something about it.


Prompting this train of thought is yesterday's publication by the Electronic Frontier Foundation of an updated version of its long-running DMCA "Unintended Consequences" documentation. EFF's paper is the best summary yet of the many ways the DMCA has been abused and misused since it was enacted. I'd forgotten some of them, such as Microsoft threatening Slashdot, and I'd never known about some others, like HP implementing regional coding in printer cartridges. So it makes for very interesting reading, although you might want to wait until you're in the mood to have your hackles raised.

EFF's paper also points out how the DMCA played a role that Congress did not intend, one would hope, in the Sony rootkit debacle. As Princeton University researchers Ed Felton and Alex Halderman told the Copyright Office for its 2006 DMCA rulemaking process, they were aware of the XCP software rootkit in Sony BMG CDs about a month before its existence was made public by Mark Russinovich. The Princeton researchers had "delayed publication in order to consult with counsel about legal concerns," they said. "This delay left millions of consumers at risk for weeks longer than necessary."

You can't blame Felten and Halderman for checking with the lawyers first, because they've been burned by the DMCA before. In 2000, Felton and other researchers were threatened with action under the DMCA when they responded to a public challenge to defeat a digital watermark technology by doing so. In 2003, Halderman was threatened with a DMCA lawsuit after he revealed how SunComm's DRM for music CDs could be defeated by holding down the shift key.

Although the DMCA and some grudging exceptions produced in the Copyright Office's 2000 and 2003 rulemaking do have some limited protections for security researchers, Felton and Halderman are asking the Copyright Office for a clear rule this time. "Unfortunately, the DMCA's anti-circumvention provision chills the efforts of security researchers," they wrote in filing for an exemption on the DMCA's provisions against circumvention of digital rights management schemes. "Because of the narrow scope of the DMCA's research exemption, the security researchers who are best situated to discover and disclose serious threats to personal computers face uncertain liability for their activities ... They must consult not only with their own attorneys but with the general counsel of their academic institutions as well. Unavoidably, the legal uncertainty surrounding their research leads to delays and lost opportunities."

But this isn't the first time the Copyright Office has been asked in its Congressionally mandated role to fix the DMCA in order to protect the researchers who are trying to protect us. "The exemption we asked for in 2003 was basically the same," says Fred von Lohmann, EFF senior attorney. "What the Copyright Office said last time was that they just don't think it's their place to change the exceptions Congress originally enacted in the law. But that's a cop-out. Obviously, Congress in 1998 could not have anticipated Sony using a rootkit, so I think it absolutely is the Copyright Office's responsibility to revisit these issues in the light of today's realities."

The Copyright Office has finished taking testimony for the 2006 DMCA rulemaking process, and any new rules it issues are expected by October. But don't be surprised if, even with the horrendous example of the Sony rootkit staring it in the face, the agency does nothing that really moderates the DMCA's most negative effects. Time and time again the Copyright Office has backed away from making any changes to the DMCA that might offend copyright holders. And the agency's bureaucrats always seem ready to show up on Capitol Hill to cheerlead for the latest Hollywood- and/or RIAA-inspired legislation that would more clearly eliminate all forms of fair use. One might even get the impression that the Copyright Office thinks it just works for copyright holders, rather than all American citizens.

But whatever changes, if any, the Copyright Office comes up with in October, they won't come close to fixing the DMCA. As EFF's "Unintended Consequences" litany makes clear, the problems don't begin or end with the Sony rootkit. If we really want the DMCA fixed, you and I will have to make sure it happens in November.

< IBM's Brand Takes on a Different Nuance | Expedia Exacerbates Excruciating Experience >


Display: Sort:
How the Copyright Office Protected Sony's Rootkit | 9 comments (9 topical) | Post A Comment
If the government won't protect us ...[ Reply to This ] (none / 0) (#1)
by Anonymous User on Fri Apr 14, 2006 at 11:14:06 AM PDT

... then I guess we'll just have to protect ourselves. AnyDVD is a good start (it will also protect you from CD schemes like the Sony RootKit).

[ Reply to This ]


You don't need to pay.[ Parent | Reply to This ] (none / 0) (#2)
by Anonymous User on Mon Apr 17, 2006 at 09:41:43 AM PDT

There is a free program named DVD43 that does the same thing. Don't be conned into paying for it. It really is free.

I will not explain how to get it, however.

And, of course, by 'the same thing', I'm merely talking about how it can remove region restrictions in countries where such restrictions are illegal, much like the program you mentioned. I know of no other purpose for either of these program.

Congress shall make no law abridging the freedom of speech...HA!

[ Parent | Reply to This ]



The only purpose of AnyDVD??[ Parent | Reply to This ] (none / 0) (#6)
by LasVegan on Thu Apr 27, 2006 at 10:34:46 AM PDT

I'm running it here--and I've never had a region-protected DVD to be an issue. It's got other nice things, though--such as removing many of the restrictions built into the DVD. Ever get annoyed at all the non-abortable junk at the start of many movies? While the chapter skip button often will fail (AnyDVD can enable it, it can't make sure it points to someplace rational) the fast forward will always work under AnyDVD.

[ Parent | Reply to This ]


You are missing the point[ Parent | Reply to This ] (none / 0) (#4)
by Anonymous User on Wed Apr 26, 2006 at 12:39:58 AM PDT

Protecting your self is probably illegal under the DMCA.

[ Parent | Reply to This ]


Justification defense[ Parent | Reply to This ] (none / 0) (#5)
by Anonymous User on Wed Apr 26, 2006 at 02:33:37 AM PDT

If courts will accept self-defense as a justification defense for homicide, surely they will accept self-defense as a justification defense for circumventing DRM? :)

[ Parent | Reply to This ]


Sony rootkit debacle[ Reply to This ] (none / 0) (#3)
by Anonymous User on Tue Apr 18, 2006 at 01:42:45 PM PDT

I am a student writing a paper for my networking class about unconventional security threats facing networks. This situation provides plenty for me to write about! It really is troubling to see that some of the most potent security threats originate from within business and government entities that we should be able to trust.

[ Reply to This ]


Well[ Reply to This ] (none / 0) (#7)
by RickJamez on Thu Apr 27, 2006 at 08:33:31 PM PDT

Back when this was making headlines at BoingBoing, people were outraged but not that suprised, wonder what the latest tail on this is.
cell phone wallpapers free
[ Reply to This ]


Grr[ Parent | Reply to This ] (none / 0) (#8)
by Anonymous User on Fri Apr 28, 2006 at 01:07:44 AM PDT

It has indeed gotten so bad that nobody is surprised anymore when a "reputable" company resorts to rootkits. MS has pushed for the right to hack into your computer if they suspect your Windows isn't Genuine. The only bright points in all this are that a) things like the Sony debacle keep grabbing attention to egregious anti-consumer practises, and b) all the research on "trusted computing" will at least have one worthy application -- as the singularity draws near, uploads and artificial intelligences will want to be able to protect themselves against being hacked, "uninstalled" (i.e. murdered), and so on, and being protected by TC like methods seems the best way to defend the rights of sentient software, once some exists.

[ Parent | Reply to This ]


Re;[ Parent | Reply to This ] (none / 0) (#9)
by Anonymous User on Sun Mar 09, 2008 at 08:02:07 AM PDT

Yale buy acomplia viagra alternative Google buy viagra Google UK buy cialis Yahoo! buy zoloft Stanford buy paxil online buy propecia Google Org Google USA

[ Parent | Reply to This ]


How the Copyright Office Protected Sony's Rootkit | 9 comments (9 topical) | Post A Comment
Display: Sort:
Recent Entries
Apple Leaves Hawaiian Investor in the Cold
2 comments

Riding the Autorenewal Express
8 comments

Comcast Gets Nominated for Worst ToS
3 comments

Taxing Software Experiences
12 comments

Terms of Ridicule
8 comments

Sneakwrapped Medical Forms
7 comments

More The Gripelog...

Submit a gripe
About the Author
Email Ed Foster

Help Ed and his readers build these projects:
The Gripewiki
The EULA Library

Login
Make a new account
Username:
Password:

Live Gripes
Has AOL Changed Their Ways?
4 comments

A Nestle SweeTarts Conspiracy
15 comments

AT&T Kills "Bad" Username
12 comments

DESPERATE! AOL HAS TAKEN OVER MY COMPUTER
28 comments

parkingticket.com SCAM on refunds
30 comments

Don't let Net Enforcers Ruin Your Day.
16 comments

More Live Gripes...

Sign up for my newsletter

To have my column automatically e-mailed to you, submit your email address in the form below. Of course, I will not turn your address over to any other party or send you any unrequested e-mail.

Infoworld Blogs

Recomended Sites
The AFFECT Coalition
Electronic Frontier Foundation
Electronic Privacy Information Center
Free Software Foundation
HearUsNow.org
Public Knowledge
StopBadware.org

Jeff Angus
Ben Edelman
Dan Gillmor
Bob Lewis
Brian Livingston
Freedom to Tinker
Lawmeme
PC World's Techlog
SunBeltSoftware Blog
Troubleshootsers.com

Rss Feeds
How this works
 Top News 
 Columnists 
 Tech Watch 
 Test Center Reviews 
 Applications 
 App Development 
 E-Business Solutions & Strategies 
 End-user Hardware 
 Networking 
 Operating Systems 
 Platforms 
 Security 
 Standards & Protocols 
 Storage 
 Telecommunications 
 Wireless 
 Web Services 

 

create account | faq | search