Live data from Hacker News

US entertainment industry to Congress: make it legal for us to deploy rootkits

boingboing.net

101–110 of 269 posts

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#101
If "they" are both the planters of the rootkit (taking over the computer) and the ones claiming to be wronged, looking for recompense, doesn't this create an unreconcilable conflict of interest as well as a worthless chain of custody for evidence of any wrongdoing? What would stop them from simply taking over computers, planting evidence and profitting (extorting) hugely?

I would think that once my computer spends any length of time not under my direct and exclusive control, I would no longer be solely liable for any actions that may have been taken with it. There would be huge doubt, no?

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#102
post #56
post #43

Earlier quoted context omitted.

To be fair: 1) Anonymous/Lulzsec aren't necessarily a best-of-the-best of the 'hacker world.' Do they want to raise the ire of even more skilled people? 2) Anonymous/Lulzsec are/were in it mostly for the publicity, and 'cheap thrills.' I'm sure that they could have done a lot more damage had they been focused on being as malicious as possible.

> mostly for the publicity, and 'cheap thrills. You mean... for the lulz?

I purposely expanded 'for the lulz' into something a bit more succinct.

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#103
post #82
post #44

This has little to do with the entertainment industry. This is dealing with intellectual property such as research and development. They are trying to protect U.S. companies from having their R&D stolen and used by foreign companies, calling for sanctions via the FTC and by amending the espionage act to go after those who steal trade secrets, for example. The whole paper is on protecting the innovations developed in…

The proposals that allow select private companies to deploy destructive software which would land other people in jail very quickly is that crazy. Notion that it is somehow OK to kidnap my property because somebody thinks I owe them some money is that crazy. We have courts and due process for that. We can see how they are abused by copyright trolls (see Prenda Law case, for example, but there are many more). I can't…

Maybe we have a different understanding of how this would work. My understanding is that the malware would not be deployed to remote computers. Rather, the malware would be embedded in files that were never meant to be distributed outside of your network. You are either in possession of those files or not, and whether someone believes that you have them or that you owe them money is not really relevant.

The issue of IP theft is not simply moral panic. There are national security implications, as we saw in the Chinese attacks on defense contractors.

(Not that I believe that embedded rootkits would have been helpful or anything)

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#104
There is no way this will ever pass, this is the most ridiculous sounding proposed legislation I have ever heard. You think SOPA is bad if something like this were to ever be passed theoretically of course, you can bet the world would be a sad, dark place to live in.

There are consequences to this kind of thing and many things to consider. I mean imagine if hackers somehow managed to find a security exploit in the malware the entertainment companies are forcefully installing on peoples computers? Ransomware one minute, botnet the next.

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#105
post #68
post #66

Earlier quoted context omitted.

What gives you the impression that Hollywood is behind it? The BoingBoing article completely misrepresents what is in the paper, so I would not be surprised if they got that part wrong, too. Have you read it? It proposes protecting American companies from foreign entities stealing our technology and using it to develop products. Here are the members of The Commission of the Theft of American Intellectual Property, th…

At this point, does it even matter? This lobby still has the backing of the entertainment industry, and it doesn't matter if it's stolen IP, trying to create an exemption for installing rootkits on remote machines is the entertainment industry's dream.

That is not what is being proposed by this paper at all.

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#106
post #11

I'm sick and tired of being in such a lazy-ass, apathetic society that possesses zero regard to freedom. Stallman may be a nut, but when you think long and hard about what he says, and think about SOPA, PIPA, and this lobby, in horror, your face twists in fear and you watch, helplessly, as your fellow citizens bend over backwards and let the government have their way. I don't even know what to do anymore. Nobody will…

We need more activists. And without them, we are fucked. You can change the system from within as well. While it is impractical to go out and run for President and hope to win, one of the things I hope the current crop of young adults will see is that they have the power to become the system and change it. First build a resume in public service (city council, county supervisor, state representative) then use your tra…

I didn't mind what you said until you brought in the horrible example of the tea party. Even ignoring its political message it was pretty much all astroturf, pumped up and hyped by established players. A few election cycles later it's pretty much gone.

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#107
post #96
post #84

Earlier quoted context omitted.

I would also want the ability to shoot anybody I dislike at will, but make it so no one else would have this ability. But fortunately for our civilization, it is not rules by what I like. That's why if you suspect somebody stole a car from you, you can not just make it blow up - you have to call the police. If you suspect somebody stole a software from you, should you be allowed to blow up their computer? In the same…

Based on your comment, I can see that you have not read the paper. The section with rootkits is about thwarting active, targeted cyber espionage. Organizations should have the right to protect files on their own networks by any reasonable means. They are not proposing a mechanism by which organizations would be allowed to distribute rootkits. I certainly have the right to disable my car remotely if it is stolen. I al…

I also have the right to lock the doors and take pictures of the assailant who stole it and send them to the police.

Wouldn't locking the doors effectively be kidnapping?

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#108
From the paper - "Recommend that Congress and the administration impose a tariff on all Chinese-origin imports, designed to raise 150% of all U.S. losses from Chinese IP theft in the previous year, as estimated by the secretary of commerce."

So... they want their people to pay for the crimes of others?

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#109
post #96

Earlier quoted context omitted.

Based on your comment, I can see that you have not read the paper. The section with rootkits is about thwarting active, targeted cyber espionage. Organizations should have the right to protect files on their own networks by any reasonable means. They are not proposing a mechanism by which organizations would be allowed to distribute rootkits. I certainly have the right to disable my car remotely if it is stolen. I al…

I also have the right to lock the doors and take pictures of the assailant who stole it and send them to the police. Wouldn't locking the doors effectively be kidnapping?

Is it kidnapping when doors lock in robbers during bank robberies? I believe that it would be covered under citizen's arrest common law and statutes. Generally, a private citizen has the right to make a warrantless arrest during or after the commission of a felony or during the commission of a misdemeanor.

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#110
post #99

What qualities do people look for when buying movies and music? 1. The content they want. 2. Quality (i.e. resolution, bitrate, etc.) 3. Reliability (it actually plays) 4. Low annoyance (no ads, warnings, etc.) 5. Safety (guaranteed freedom from malware, etc.) The movie and music industries haven't done a perfect job of delivering #1-4. Region coding means the content users want is frequently only available through p…

#5 Safety (guaranteed freedom from malware, etc.)... was the one thing that legally purchased media had an undeniable edge in over pirated media.

Disagreed. Sony rootkit was on the legally purchased media. DRM on streaming services can do all kind of stuff without users consent. DRM built into hardware with cameras can do even weirder stuff (just note the crazy DRM idea patented by Microsoft regarding detecting the people in the room). Since DRM is a black box, you never know what it can do. There is completely no reason to trust that it will respect your privacy and rights. Therefore DRMed media has no edge over pirated media at all.

Safety requires transparency (for the user), as well as trust in the used technology. DRM by its very definition is non trustworthy and non transparent, it's the antithesis of that. It's totally opaque precisely because it attempts to hide something from the user. Because ironically, DRM proponents don't trust the user! User is treated as potential criminal by default. How can users in situation when they aren't trusted, trust the DRM vendor in return? They can not, and they should not! Trust can be only mutual. I.e. DRM always implies something shady and risky. DRM proponents should be treated as potential criminals by default in return. And what do such criminals usually hide in their code? Malware.

Post reply on HN