Battle brews over reverse engineering
Computerworld - Recent court decisions limiting developers' rights to reverse-engineer software products have sparked an outcry by critics who say these actions could severely limit developers and users trying to interoperate or find flaws in commercial software.
U.S. judges have recently ruled that unauthorized re-engineering of the digital video disc playback system and a Web filtering program called CyberPatrol violated copyright and trade-secret laws.
Reverse engineering is also forbidden by many shrink-wrap license agreements. This restriction will likely be strengthened by the Uniform Computer Information Transactions Act (UCITA), which gives vendors powerful leverage in contract negotiations.
While some software vendors and content owners insist these decisions strengthen intellectual property protections, developers and system administrators argue they are losing the right to use products as they wish.
"Clearly, if we are not allowed to reverse-engineer the software that we didn't buy but are most graciously allowed to 'license' by agreeing to an arbitrary contract, then we have no control over what software is running on the computers we own," said Ian Goldberg, chief scientist at Zero-Knowledge Systems Inc. in Montreal. "Bugs, security holes or worse, explicit back doors, might be undetected, but only talked about within the bad guys' community. Publicly disclosing the information would be illegal."
Fair-use provisions in the copyright laws that permit reverse engineering have spurred the development of software that competes with proprietary applications such as Microsoft Word and Excel. For example, San Jose-based Phoenix Technologies Ltd.'s reverse engineering of IBM's BIOS in the mid-1980s became the basis for the entire PC clone industry.
During the annual Computers, Freedom and Privacy conference held last month in Toronto, Jessica Litman, Professor of Law at Wayne State University in Detroit, Mich., said controversial court decisions are rapidly eroding the "fair use" provisions that traditionally permitted unauthorized use of software for the purpose of reverse-engineering. The provision allows developers to disassemble and decompile a program and use what they learned to create and sell an interoperable or competing program as long as it doesn't infringe on the original code.
While Congress made exceptions in the 1998 Digital Millennium Copyright Act for interoperability development and security testing, these exceptions have been overridden in favor of anticircumvention provisions and trade secrecy laws.
But Pamela Samuelson, a professor at the School of Information Management and Systems at the University of California at Berkley, said the ruling is unprecedented because defendants in the DVD CCA case hadn't violated the shrink-wrap license. "If you have gotten information from somebody that the judge decides was a misappropriation of



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Live Webcast
North Pole to South Seas: Overcoming the Pitfalls of remote Performance - In today's always-on world, connectivity is a business requirement. You need the tools that allow you to operate as if you were on...
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Live Webcast
Banish Poor Application Performance: Eliminate Business Disruptions, Increase End User Productivity - End User Experience, 30-Min Webinar
Wed. Feb. 22nd ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...