Don't Shoot the Messenger
Gagging researchers who find security flaws will backfire.
Computerworld - Would you invest in a digital access control system whose biggest users are trying to suppress evidence that it can be hacked?
Licensees of a digital watermarking system created by Verance Corp. should be asking themselves that question. The San Diego-based company was sued in June by a group of researchers who contend that Verance's biggest users in the music industry are trying to prevent them from revealing flaws in the company's watermarking technology.
Verance's watermarking system uses cryptography to secure content from unauthorized copying. In 1999, it was adopted as the worldwide industry standard for copy control of DVD-Audio and digitally delivered music under the first phase of the recording industry's Secure Digital Music Initiative (SDMI). The system's initial licensees included five major record labels and a broad spectrum of recorded music and Internet-based music delivery companies.
In September, the Washington-based Recording Industry Association of America (RIAA) and the SDMI Foundation invited anyone to try to break the watermark scheme to test its strength. Scientists from Princeton University and Rice University obliged and wrote a paper describing their successful attempt to remove a Verance watermark from a digital music file.
The researchers also documented vulnerabilities in other watermarking technologies. When Princeton computer science professor Ed Felten and his research team announced that they planned to publish their paper, the music industry tried to silence them.
Matt Oppenheim, an officer of both the RIAA and SDMI, sent Felten a letter threatening legal action if he published the results. Oppenheim contended that disclosure of the research could directly lead to the illegal distribution of copyrighted material. He claimed that Felten and his team had violated the contest rules and were subject to prosecution under the Digital Millennium Copyright Act, which prohibits discussion of technology that might be used to bypass copy controls. Verance and the RIAA declined to comment for this story.
Mathematics and computer code aren't circumvention devices. But Felten and his researchers were concerned about possible prosecution and withdrew their paper. The San Francisco-based Electronic Frontier Foundation sued the RIAA, SDMI, Verance and the U.S. Department of Justice. The plaintiffs asked the court to rule that they have a First Amendment right to present their research. "Studying digital access technologies and publishing the research for our colleagues are both fundamental to the progress of science and academic freedom," said Felten. "The recording industry's interpretation of the copyright act would make scientific progress on this important topic illegal."
Users of the Verance watermarking system should ask themselves if it's wiseto invest in products from a company that suppresses peer review and full disclosure of flaws. They should take a close look at the value of digital rights-management systems that depend on litigation rather than strong cryptography to secure content. And they should figure out what they will say to their content providers and their shareholders if their watermarking scheme fails to prevent unauthorized copying of their intellectual property. ROI
Read more about ROI in Computerworld's ROI Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All ROI White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All ROI Webcasts