Showing posts with label DRM. Show all posts
Showing posts with label DRM. Show all posts

Friday, September 21, 2007

DRM: a Threat to Privacy

Via Michael Geist by way of BoingBoing we learn that The University of Ottawa's Canadian Internet Policy and Public Interest Clinic has released a report concluding that DRM pose a significant threat to privacy. From the executive summary:


• Fundamental privacy-based criticisms of DRM are well-founded: we observed
tracking of usage habits, surfing habits, and technical data.
• Privacy invasive behaviour emerged in surprising places. For example, we
observed e-book software profiling individuals. We unexpectedly encountered
DoubleClick – an online marketing firm – in a library digital audio book.
• Many organizations take the position that IP addresses do not constitute
“personal information” under PIPEDA [Personal Information Protection and
Electronic Documents Act] and therefore can be collected, used
and disclosed at will. This interpretation is contrary to Privacy Commissioner
findings. IP addresses are collected by a variety of DRM tools, including
tracking technologies such as cookies and pixel tags (also known as web
bugs, clear gifs, and web beacons).
• Companies using DRM to deliver content often do not adequately document
in their privacy policies the DRM-related collection, use and disclosure of
personal information. This is particularly so where the DRM originates with a
third party supplier.
• Companies using DRM often fail to comply with basic requirements of
PIPEDA.


This, sadly, should not be a surprise. Copyright organizations have shown themselves to be actively hostile to concerns about information security and data privacy (see, e.g., the discussion of concerns related to watermarking here, or Sony's now infamous fondness for installing rootkits). Indeed, the only time when copyright and information security are (supposedly) aligned is when copyright is trying to piggyback on security concerns to achieve its own ends (e.g., the destruction of P2P networks, as described here).

The happy news though, is that the study came out in the first place. It is possible that this examination of the impact of DRM on privacy could be a reflection of some sort of backlash against the copyright industry's current tactics - something that, if supported by legislation, could result in significant benefits for privacy and security of individual data.

Tuesday, August 21, 2007

Watermarking: Threat to Privacy?

Recently, a mini-firestorm has erupted over the possibility that the recording industry will add watermarks to music files (e.g., articles here, here, and here). The idea behind the watermarks is that they will allow copyright holders to see where files on peer to peer networks came from and file lawsuits accordingly. Whether such tracking would actually allow the RIAA to file suits without being embarassed (e.g., as described in this article, which eventually led to a charge of malicious prosecution) is an open question. However, what I would like to address is not whether the watermarks will help in prosecution of copyright infringers, but what they will do for individual privacy. In a wired.com article on the subject, Evan Hill, CTO of Activated Content, a company that provides watermarking solutions to Universal, Sony/BMG and other labels is quoted as calling watermarks which uniquely identify each file purchased by each user a "privacy nightmare." While there are certainly concerns about watermarking, I don't think those concerns are really that significant. The reason for this is that problems with watermarking are really only a symptom of a larger issue: users being forced to sacrifice their privacy in order to participate in the modern economy. I've blogged previously (see post here) about the threat posed to privacy by the routine enforcement of clickwrap licenses where service providers can basically dictate terms because users either don't or can't understand what they're agreeing to. Similarly, in the case of music distribution, service providers (i.e., record companies) can basically dictate terms to users, because people won't bother to read the licenses provided with the songs and, even if they did, they wouldn't have any choice about accepting them because the record labels have government enforced copyrights (assuming the consumers care about buying licensed copies of the songs, of course). In both cases though, the problem isn't the watermarks (or the clickwraps) it's the economy, and the legal system which allows those tools to be used in ways that strip users of their privacy.

Tuesday, June 26, 2007

What Can Information Security Learn From Digital Rights Management

Recently, Mircosoft decided not to remove virtualization restrictions from its Vista operating system. According to this article, the probable reason for Microsoft's decision is that Vista's virtualization features have the practical effect of incapacitating Vista's Digital Rights Management (DRM) features. Given that the fundamental purpose of DRM technology - controlling reproduction and use of information - is the same as the fundamental purpose of most information security policies, Microsoft's decision to simply restrict access to a desirable product feature could mean that some technologies, such as virtualization, are simply incompatible with information control. The lesson for businesses seeking to avoid security breaches? The threat from some technologies (e.g., portable mass storage devices) might be so great that they should be kept out of corporate networks all together. Otherwise, until an effective technical solution is found (and Microsoft apparently hasn't been able to develop one yet), some things are just an invitation for trouble.