Skip the navigation

Don't Shoot the Messenger

Gagging researchers who find security flaws will backfire.

By Ann Harrison
September 24, 2001 12:00 PM ET

Computerworld - Would you invest in a digital access control system whose biggest users are trying to suppress evidence that it can be hacked?

Licensees of a digital watermarking system created by Verance Corp. should be asking themselves that question. The San Diego-based company was sued in June by a group of researchers who contend that Verance's biggest users in the music industry are trying to prevent them from revealing flaws in the company's watermarking technology.

Verance's watermarking system uses cryptography to secure content from unauthorized copying. In 1999, it was adopted as the worldwide industry standard for copy control of DVD-Audio and digitally delivered music under the first phase of the recording industry's Secure Digital Music Initiative (SDMI). The system's initial licensees included five major record labels and a broad spectrum of recorded music and Internet-based music delivery companies.

In September, the Washington-based Recording Industry Association of America (RIAA) and the SDMI Foundation invited anyone to try to break the watermark scheme to test its strength. Scientists from Princeton University and Rice University obliged and wrote a paper describing their successful attempt to remove a Verance watermark from a digital music file.

The researchers also documented vulnerabilities in other watermarking technologies. When Princeton computer science professor Ed Felten and his research team announced that they planned to publish their paper, the music industry tried to silence them.

Matt Oppenheim, an officer of both the RIAA and SDMI, sent Felten a letter threatening legal action if he published the results. Oppenheim contended that disclosure of the research could directly lead to the illegal distribution of copyrighted material. He claimed that Felten and his team had violated the contest rules and were subject to prosecution under the Digital Millennium Copyright Act, which prohibits discussion of technology that might be used to bypass copy controls. Verance and the RIAA declined to comment for this story.

Mathematics and computer code aren't circumvention devices. But Felten and his researchers were concerned about possible prosecution and withdrew their paper. The San Francisco-based Electronic Frontier Foundation sued the RIAA, SDMI, Verance and the U.S. Department of Justice. The plaintiffs asked the court to rule that they have a First Amendment right to present their research. "Studying digital access technologies and publishing the research for our colleagues are both fundamental to the progress of science and academic freedom," said Felten. "The recording industry's interpretation of the copyright act would make scientific progress on this important topic illegal."

Users of the Verance watermarking system should ask themselves if it's wiseto invest in products from a company that suppresses peer review and full disclosure of flaws. They should take a close look at the value of digital rights-management systems that depend on litigation rather than strong cryptography to secure content. And they should figure out what they will say to their content providers and their shareholders if their watermarking scheme fails to prevent unauthorized copying of their intellectual property. ROI

Read more about ROI in Computerworld's ROI Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

ROI White Papers
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
All ROI White Papers
ROI Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All ROI Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs