Because every country strives to be more like Syria. "MPAA told Congress that they wanted SOPA and knew it would work because it was the same tactic used by governments in "China, Iran, the UAE, Armenia, Ethiopia, Saudi Arabia, Yemen, Bahrain, Burma, Syria, Turkmenistan, Uzbekistan, and Vietnam."
US entertainment industry to Congress: make it legal for us to deploy rootkits
91–100 of 269 posts
Re: US entertainment industry to Congress: make it legal for us to deploy rootkits
#92Would it also then become illegal to program software that would defend against such software rooting your machine and erasing things that goes against its views of fairness? I'd like see them try to root my Gentoo box.
Just about every Linux kernel version has had some root privilege escalation bug. So long as they can get some executable software on your system (perhaps not easy!) it's reasonable any such bug could be exploited, and voila, they can install a rootkit!
Re: US entertainment industry to Congress: make it legal for us to deploy rootkits
#93I kind of hope this happens, just to increase the demand for real security. In the short term it would make things worse, but in the long run we'd end up with market pressure to give individuals control over their own resources (both protection from corporate control and from incompetent implementation).
Re: US entertainment industry to Congress: make it legal for us to deploy rootkits
#94This has little to do with the entertainment industry. This is dealing with intellectual property such as research and development. They are trying to protect U.S. companies from having their R&D stolen and used by foreign companies, calling for sanctions via the FTC and by amending the espionage act to go after those who steal trade secrets, for example. The whole paper is on protecting the innovations developed in…
Re: US entertainment industry to Congress: make it legal for us to deploy rootkits
#95Re: US entertainment industry to Congress: make it legal for us to deploy rootkits
#96Earlier quoted context omitted.
Rootkits are a thing. They're neither good nor bad. That value is supplied subjectively within different contexts, no? Would I want the RIAA/MPAA to install rootkits in media files that are distributed to customers? Absolutely not. Would I want the ability to install rootkits in engineering schematics and documentation that are never intended to be distributed outside of my organization and are only activated in case…
I would also want the ability to shoot anybody I dislike at will, but make it so no one else would have this ability. But fortunately for our civilization, it is not rules by what I like. That's why if you suspect somebody stole a car from you, you can not just make it blow up - you have to call the police. If you suspect somebody stole a software from you, should you be allowed to blow up their computer? In the same…
I certainly have the right to disable my car remotely if it is stolen. I also have the right to lock the doors and take pictures of the assailant who stole it and send them to the police.
Re: US entertainment industry to Congress: make it legal for us to deploy rootkits
#97This has little to do with the entertainment industry. This is dealing with intellectual property such as research and development. They are trying to protect U.S. companies from having their R&D stolen and used by foreign companies, calling for sanctions via the FTC and by amending the espionage act to go after those who steal trade secrets, for example. The whole paper is on protecting the innovations developed in…
The proposals that allow select private companies to deploy destructive software which would land other people in jail very quickly is that crazy. Notion that it is somehow OK to kidnap my property because somebody thinks I owe them some money is that crazy. We have courts and due process for that. We can see how they are abused by copyright trolls (see Prenda Law case, for example, but there are many more). I can't…
"Informed deliberations over whether corporations and individuals should be legally able to conduct threat-based deterrence operations against network intrusion, without doing undue harm to an attacker or to innocent third parties, ought to be undertaken."
"he Department of Homeland Security, the Department of Defense, and law enforcement agencies should have the legal authority to use threat-based deterrence systems that operate at network speed against unauthorized intrusions into national security and critical infrastructure networks."
Apart from the proposal that starts "In the future..." and ends "The Commission is not ready to endorse this recommendation", that's as crazy as it gets.
-------------
edit: after reading the boingboing article I see it's about 20 words and two out of context paragraphs.
The first paragraph specifically states that "such measures do not violate existing laws on the use of the Internet." It is simply recommending this as a measure to protect corporate IP, not as something that should be changed.
The second paragraph is immediately followed by noting that such actions are currently illegal, and then recommending deliberation on whether it should be made legal.
Re: US entertainment industry to Congress: make it legal for us to deploy rootkits
#98This has little to do with the entertainment industry. This is dealing with intellectual property such as research and development. They are trying to protect U.S. companies from having their R&D stolen and used by foreign companies, calling for sanctions via the FTC and by amending the espionage act to go after those who steal trade secrets, for example. The whole paper is on protecting the innovations developed in…
Does it say anywhere how deployment would be restricted? Even if it's the case, it's both dangerous (I could easily imagine this getting deployed by accident because a contractor set it wrong) and one hell of a slippery slope.
Re: US entertainment industry to Congress: make it legal for us to deploy rootkits
#991. The content they want.
2. Quality (i.e. resolution, bitrate, etc.)
3. Reliability (it actually plays)
4. Low annoyance (no ads, warnings, etc.)
5. Safety (guaranteed freedom from malware, etc.)
The movie and music industries haven't done a perfect job of delivering #1-4. Region coding means the content users want is frequently only available through pirate channels. Lower quality releases (DVD vs Bluray) are also often all that is available in some regions. Bluray is not reliable if users don't keep their hardware/software up to date. Nearly all DVD's and bluray discs on the market are utterly infested with annoying advertisements and warning screens.
#5 was the one thing that legally purchased media had an undeniable edge in over pirated media. If users lose trust in the safety of legally purchased media they will be driven to piracy in unprecedented numbers.
It is tempting to give RIAA and MPAA the rope to hang themselves with, sit back, and laugh. However, let's not forget that every piece of code they write and every root-kit they successfully deploy will soon be taken advantage of by black-hats, quite probably in ways that will cause damage to systems completely unrelated to media playback of any sort. The only way I can see to let the MPAA/RIAA proceed is to require them to post a significant bond (in the billions) to pay for damages their rootkits will cause. Managing how damages are going to be awarded is going to be a legal nightmare though, since this will not affect only U.S. systems and citizens. If the U.S. permits this, I sincerely hope other nations hold the U.S. government responsible for damages, so the U.S. had better make sure Hollywood is ready to foot the bill.
Re: US entertainment industry to Congress: make it legal for us to deploy rootkits
#100Earlier quoted context omitted.
Rootkits are a thing. They're neither good nor bad. That value is supplied subjectively within different contexts, no? Would I want the RIAA/MPAA to install rootkits in media files that are distributed to customers? Absolutely not. Would I want the ability to install rootkits in engineering schematics and documentation that are never intended to be distributed outside of my organization and are only activated in case…
A major problem with this is liability the first time this causes major damage to systems because the rootkit had a bug or because someone in your organization legally redistributed the data outside your organization, with approval, but without realizing the consequences. Especially as it is unlikely this would affect serious criminals: If tech like this becomes common, then nobody sane would open stolen files withou…