Live data from Hacker News

US entertainment industry to Congress: make it legal for us to deploy rootkits

boingboing.net

151–160 of 269 posts

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#151
post #143
post #137

Earlier quoted context omitted.

Remember when you couldn't watch DVDs on Linux? And then someone wrote DeCSS, which provided decryption of DVD for Linux users. It'll be similar if this law passes. There's a binary blob for Windows and OSX. It's illegal to reverse engineer that blob. It's illegal to circumvent the need for that blob.

I guess we'll just have to use a VM then. They can "root" that all they want.

Of course, the blob would detect a virtual machine and refuse access to the content.

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#152
post #45

Earlier quoted context omitted.

For an industry as fucking inept as the MPAA and the rest of the copyright cartel, I'd be absolutely floored if they managed to break into a Linux machine.

They have the money to pay people who can though!

But not the competence to identify them

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#153
post #110
post #99

What qualities do people look for when buying movies and music? 1. The content they want. 2. Quality (i.e. resolution, bitrate, etc.) 3. Reliability (it actually plays) 4. Low annoyance (no ads, warnings, etc.) 5. Safety (guaranteed freedom from malware, etc.) The movie and music industries haven't done a perfect job of delivering #1-4. Region coding means the content users want is frequently only available through p…

#5 Safety (guaranteed freedom from malware, etc.)... was the one thing that legally purchased media had an undeniable edge in over pirated media. Disagreed. Sony rootkit was on the legally purchased media. DRM on streaming services can do all kind of stuff without users consent. DRM built into hardware with cameras can do even weirder stuff (just note the crazy DRM idea patented by Microsoft regarding detecting the p…

I think OP was talking about average-Joe's understanding of safety. The "if I buy original version, it won't have viruses on it that break my computer". This is true so far, DRMs or not, and people trust legal media. But the moment this trust gets broken, there will be little reason to go to shop instead of Pirate Bay.

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#154
post #92

Earlier quoted context omitted.

Just about every Linux kernel version has had some root privilege escalation bug. So long as they can get some executable software on your system (perhaps not easy!) it's reasonable any such bug could be exploited, and voila, they can install a rootkit!

Good luck for them breaking out of the VM their software would end up getting run in.

This is not as unlikely as you may think. All it takes is the right bug in a virtio driver, and they can go from vm-root to host-user, and assuming some level of competence they can go from host-user to host-root. Of course, you're welcome not to use any virtio devices, and you're welcome not to use hardware virtualisation support, but the performance of your guest will not be much to write home about.

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#155
post #99

What qualities do people look for when buying movies and music? 1. The content they want. 2. Quality (i.e. resolution, bitrate, etc.) 3. Reliability (it actually plays) 4. Low annoyance (no ads, warnings, etc.) 5. Safety (guaranteed freedom from malware, etc.) The movie and music industries haven't done a perfect job of delivering #1-4. Region coding means the content users want is frequently only available through p…

> However, let's not forget that every piece of code they write and every root-kit they successfully deploy will soon be taken advantage of by black-hats, quite probably in ways that will cause damage to systems completely unrelated to media playback of any sort.

It will be stupidly easy to execute; if the malware shuts down computer when it detects illegal download, the only thing an attacker needs to do is to trick the computer/user into downloading illegal content. And that's it. Though this simple trick doesn't let them steal data or take control of the computer, there are many uses an attacker can find for just killing the machine. Blackmailing, social engineering, or just disturbing some crucial business operations. I can even imagine 4chan folks trolling people like this for fun.

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#156
post #86

This is not going to go where they think it will go. Right now their enemies are just pirates wanting to watch Game Of Thrones for free. A business threat, certainly, but one they're generally handling well. But start infecting people's computers, and a portion of them are going to fight back. Then the entertainment industry has enemies actively trying to destroy their systems. A whole different level of conflict, an…

If I ever find a rootkit on my system stemming from a company that thinks they can do stuff like this, and it is legal, it is to a demonstration that the law is not worthy of any respect any more, and that it is time for war. And given the resource discrepancy, the only way of fighting back against companies like this would be to cause vastly disproportionate amounts of damage. I'm sure getting rootkits into their ne…

Sony's network has been a fertile testing ground for third-party rootkits for the past few years.

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#158

When I read those excerpts from this report, I assumed it was written by some extremist lobbying group that doesn't have any real power. Then I read this statement from Congressman Mike Rogers (Chair of CHPSCI, House Permanent Select Committee on Intelligence): “It is already clear to me that this report is going to make a very important contribution to the discussion about the grave danger that IP theft poses to our…

The cognitive dissonance involved in playing up the "Chinese economic espionage" threat while simultaneously supporting a move to legally make everyone's computers less secure is astounding.

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#159
post #143

Earlier quoted context omitted.

I guess we'll just have to use a VM then. They can "root" that all they want.

Of course, the blob would detect a virtual machine and refuse access to the content.

In a more modern version, VM just won't be able to support a hardware-assisted DRM conveniently preinstalled straight into your CPU or video card's firmware.

Hmm. This leads me to the idea. Why care for software rootkits when PCIe hardware may actively screw with the system? Considering MAFIAA already had success with enforcing HDCP on almost every modern video card out there...

Re: US entertainment industry to Congress: make it legal for us to deploy rootkits

#160
post #9

I tried to be rational and then I got to the second paragraph of their own brief: "The second and even more pernicious effect is that illegal theft of intellectual property is undermining both the means and the incentive for entrepreneurs to innovate, which will slow the development of new inventions and industries that can further expand the world economy and continue to raise the prosperity and quality of life for…

> "illegal theft of intellectual property" Say what? Such bizarre phrases make me seriously doubt the intelligence and education of the people who wrote this.

They are not stupid. This isn't a mistake. It's Dark Arts. They're trying (quite successfully) to attach the word "theft" to copyright infringement, so that people discuss it in terms of moral intuitions about stealing. 'cause if it is called "stealing" then it must be evil, right?
Post reply on HN