Showing posts with label non-owner locks. Show all posts
Showing posts with label non-owner locks. Show all posts

Thursday, December 14, 2017

We wouldn't even be having this conversation if it was cars rather than computers!

Section 92 of Canada's copyright act indicates:

Review of Act

92 Five years after the day on which this section comes into force and at the end of each subsequent period of five years, a committee of the Senate, of the House of Commons or of both Houses of Parliament is to be designated or established for the purpose of reviewing this Act.

1997, c. 24, s. 50; 2012, c. 20, s. 58.

On December 13'th the following was included in a motion by Bardish Chagger Leader of the Government in the House of Commons and Minister of Small Business and Tourism:

(c) the Standing Committee on Industry, Science and Technology be the committee designated for the purposes of section 92 of the Copyright Act; and

This indicates that in the new year that the INDU committee will be reviewing the Copyright Act.



I was actively involved in the process last round.  I joined the process in the summer of 2001 when I heard that Canada was contemplating adding "technological protection measures" to our Copyright Act.  Software authors already understood the harm from the anti-circumvention aspects of the USA's Digital Millennium Copyright Act (DMCA).

In an earlier article I discuss a layered model for road transportation, and that "technological protection measures" (TPMs) are actually a restriction on who is allowed to drive (IE: author software for), or choose drivers for, communications technology.

While I don't have a drivers license or drive a car, I have been driving computers since 1981.  The rights of computer owners to drive their own computers, or choose their own drivers if they don't have the skills themselves, should be understood as fundamental a right as driving automobiles already is to the rest of society.


I had to get involved in this policy discussion, even though it never made sense to me that we were even having the discussion.  I acknowledge that technology, whether transportation or communications technology, can be abused in breaking the law.  While this has always been true of vehicles, there has never been a serious policy discussion about disallowing vehicle owners the right to drive their own vehicles, or disallow them to choose their own drivers if they didn't have those skills.   The only reason we were having this conversation is because policy makers, similar to the general public, lack adequate literacy on communications technology which we all take for granted for transportation technology.


While the section 92 review was announced in the summer of 2001, it wasn't until October 2003 that submissions were due.  My first formal submission to that process is available through my website.  In the summer of 2001 I started a discussion forum called "canada-dmca-opponents" which grew into the Digital Copyright Canada website.


I spent considerable time from 2001 through the passage of Bill C-11 in 2012 active in that area of policy.  This included only accepting part-time jobs so that I could participate.  When I started my current job in 2011 I only accepted an 80% contract so that I could attend every Bill C-32 and Bill C-11 committee meeting.


While my focus was on the rights of technology owners, false claims were often made about my views on copyright.  It was frequently suggested that if I was opposed to TPMs, the only possible reason could be because I didn't believe authors should get paid.   As a software author myself this was a ludicrous suggestion, and yet even some of the most sympathetic journalists would falsely claim I was an "anti-copyright crusader".

This would never have happened if we were talking about cars rather than computers.  Someone claiming that the only reason someone wants to drive their own car is because they wish to break the law or are a criminal would be appropriately laughed out of the room.   Unfortunately when it comes to technological measures, few recognize just how ridiculous it is.


It took me years to realize just how low technology literacy is within policy circles.  Most of the conversations about TPMs come from the belief that it is something applied to copyrighted works, and that these measures allow decisions to be made (can copies be made, under what conditions, etc).  This is similar to believing that a paperback book is sentient, and can come alive and autonomously run away if the reader of the book tries to do something the book doesn't like.  I have come to refer to this as the "Harry Potter" understanding of TPMs.  While purely based on fiction, this is the most common misunderstanding of TPMs.

If we were talking about cars rather than computers, people with such a low literacy of the relevant subject matter would not be considered experts or be allowed to dominate the debate.


I wish the review of the Copyright act would be about Copyright law.

I've learned quite a bit by speaking with fellow creators and creator groups, and have knowledge of the wide variety of market changes each group is facing.  In nearly all cases there are legitimate changes in which intermediaries are involved in the relationships between creators and their audiences.  While there are many intermediaries crying fowl at these advancements, the vast majority of the changes I've observed are positive for creators and should be encouraged.  In many cases when there are infringements, these are infringements induced by the harmful business practices of specific intermediaries: they are infringements that could be handled with an "inducement" regime for contributory infringements, rather than the incorrect focus of the "enablement" policy that was added as part of C-11.


I am forced again to focus on TPMs this round of Copyright Act review.  While it may be true that some copyright holders use TPMs, it has no more place in Copyright law than a National Energy Program has simply because some copyright holders use electricity.

I look forward to a future when the Copyright Act only has Copyright related provisions in it, and we can finally have a proper conversation about modernizing copyright law that isn't tainted by being dominated by non-copyright related discussion.

Monday, April 4, 2016

Perspectives on computer security and encryption from Apple, the FBI and I : Apple

Apple's perspective on computer security and encryption

This is the third in a series that started with discussing the FBI and my own use of security and encryption technology.

Apple's most lucrative product line at the moment is their iOS based distributed content delivery platform. This includes the iPhone, iPad, Apple TV, iWatch, and related hardware.  While this hardware is distributed to customers, the platform is similar to the platform I manage for my employer where hardware is distributed geographically but control remains in our hands.   This is the platform which Apple has been marketing to the content industry for decades as a safe secure platform for them to distribute their multimedia where it is Apple and not the end users which control the technology.

These devices are intended to be connected to the network, and the ongoing work to secure them is similar to any other network connected device.  The network and exploits carried out on the network don't differentiate clients and servers as much as the layperson thinks, and any network connected device must be constantly updated to deny unauthorized control.  The question of authorized control doesn't differentiate between types of devices, and it is just as easy for Apple to remotely manage an iOS device as it is for me to remotely manage the computers I do.  The major difference is in the reliability of the network connection, with mobile devices having less stable network connections than servers.  People also don't tend to turn servers off when a specific user isn't using them, but remote management and control doesn't require constant network access.

Hardware assistance for Apple's security

Apple's iPhone 5C which was discussed in the FBI vs Apple lawsuit does not include Touch ID or a Security Enclave, so it is similar to the existing control which Canadiana has of our distributed computers. While Apple remains in control of the platform, they are not as secure from malicious apps or intruders with physical access to the computers as they would like.

Secure Enclave is Apples implementation of the SecureCore and TrustZone technologies from ARM I discussed in the previous article.  This will grant Apple greater control over the technology than they had before, including greater control over the scenario where the attacker has physical access to the hardware.

Some users may find this technology will eventually make what is commonly called jailbreaking much harder, if not impossible.  Apple could opt to use Secure Enclave to disallow the people who possess the hardware from having any ability to bypass any of Apple's control.  It is critical to understand that Apple's use of this technology is not to grant the technology user more control over the hardware or their data, but to transfer any remaining control that the user might have had to Apple.  People who possess this hardware often incorrectly think of themselves as owners, even though acquiring an iOS device has become legally more similar to renting than purchasing due to anti-circumvention legislation.

People who acquire this hardware are not alone in the confusion. When James B. Comey, Director of the FBI, offered testimony in front of the Judiciary Committee he said, "In recent months, however, we have on a new scale seen mainstream products and services designed in a way that gives users sole control over access to their data."  While some people have suggested he might have been talking about Apples adoption of SecureCore and TrustZone, he is incorrectly suggesting it was "users" of these devices who would have sole control over access to data rather than Apple having additional control over the device.  It is possible that he fully understands Apple's use of technology, and wants to offer free advertising to Apple knowing that Apple is specifically not offering the service he is suggesting they are.

This is the same concern I have with the services I provide:  If law enforcement and courts believe it is the entity that possesses the hardware that is in control rather than the entity controlling the software stack with full network access then they will continue to send court orders to the wrong entity.

Law enforcement need to understand the technology better.  In the case of an iOS device, it is Apple who is the responsible entity and should be served with the warrant.  A very different scenario would be someone who is running CyanogenMod where it is the individual user (in this case, legitimately called an owner) of the device that is in control and thus they should be served with the warrant.

Limits to Apple's control

In the specific case before the courts the technology user didn't destroy the device, and there has been nothing to suggest that the user even "jailbroke" the device to bypass any of Apple's control.  The FBI currently possesses the device and will obviously be granting network access and power to the device.  This means that all the potential limits to Apple's control do not apply in this case, and thus they have full access to do anything requested of them.

In this case it appears that the FBI jailbroke the device on their own, no longer having a technical requirement to require assistance from Apple.

The law

While I may believe that lawful access all too often grants excessive access to police without adequate oversight, the law is clearly in the government's favour in this instance with the iPhone.  If we were talking about information stored on Facebook or Twitter, where the physical location and who was in control of the computer in question wasn't confusing people, the debate would not be happening at all.  Clearly Facebook is in control of their network of computers whether or not the devices are stored in locations that Facebook owns, and Apple is similarly in control of their secured platform.

There is no back-door being discussed.  All that Apple was being asked is to use their keys to the front door and access the data.  They are the entity that holds those keys, not the user of the technology who under anti-circumvention laws are denied legal access to the keys.

While Apple has been misdirecting people and stalling, and there are "engineers" who have allegedly threatened to leave Apple if the government is lawfully granted access, the situation is no different than any other of hundreds of technology companies providing services to users on a platform that the vendor rather than the user controls.  If Apple executives or individual employees are destroying evidence they should be found in contempt of court, and handled severely.

If Apple's engineering staff is not sufficient (or no longer after vigilantes resign) to solve any technical problems, then the court should order all source code and technical specifications to be disclosed to a third party who can do the require work.   If Apple refuses to disclose this information, then I would suggest that revoking their corporate charter should be the minimum on the table.

The fact that the FBI jailbroke the device should not have ended the case, and Apple should still be pursued by the government.

Politics

Adi Shamir, an award-winning cryptographer who helped create the RSA encryption algorithm in 1977, suggested that Apple "wait for a better test case to fight where the case is not so clearly in favor of the FBI."

I'm not convinced that Apple had an interest in winning the case. Apple's greatest threat to the market share for their secure vendor controlled content delivery platform comes from technology users switching to devices which they can individually control. Apple has a history of dishonestly trying to misdirect responsibility for their centralized control. While for decades it has been the confused content industry that still has some who mistakenly believe that this vendor control benefits them, a far more powerful scapegoat would be law enforcement and national security agencies.

Apple has the FBI falsely suggesting that next generation iOS devices "gives users sole control over access to their data", providing Apple with marketing for a service they don't provide and driving users to technology which the FBI and other government agencies will have easier access to through the legal system than competing technology. Whenever Apple is requested to disclose information they can claim "the Government made me do it", even though it is Apple who denied users of their services any device control in the first place.

It seems unlikely to me that the FBI didn't already have technology to "jailbreak" the device at hand.  This isn't going to be the simpler third party services available to end users, as governments will have far more resources and techniques available to them to "jailbreak" devices.  I suspect that the case was pursued for political reasons to try to push this issue forward, and likely to prop up Apple's marketing claims that they are providing technology which protects the users rather than Apple's conflicting interests.

Apple also knows that their business model and lobbying in support of anti-circumvention legislation is controversial, and them being the ones to push this case forward would provide less community opposition to the FBI than if a less divisive company were bringing the case forward.  Their involvement complicates what could have been an easy to understand set of sound bites in support of protecting technology owners rights against unreasonable search and seizure into something extremely complex to discuss.  I have been delayed in participating in the discussion as it took me a while to decide how to explain my position, and I fully expect to still get confused "but Apple are the good guys" comments to this article.

Apple's ongoing attack on technology owners interests could cause considerable damage.  If it becomes considered normal to have the vendor rather than the user be in control of communications technologies it may eventually lead (likely with Apple's continuing political lobbying) to governments outlawing citizen controlled technology which competes with Apple's vendor controlled technology.  It could be used to strengthen backwards laws which outlaw alleged device "owners" from removing non-owner locks from their devices, with the justifications moving from odd unproven theories about protecting "copyright" to even further counter-productive arguments about law enforcement and national security.

Conclusion

My answer to the question of whether I was on Apple or the FBI's side is clearly neither, as I consider them to have perspectives dangerously close to each other.  Neither are interested in allowing the wide deployment of technology that "gives users sole control over access to their data", and while their positions appear to be in opposition they are actually greatly helping each other.

Those who recognize the critical importance of secure citizen controlled communications technology should be opposing both of these entities, not siding with one or the other in a battle where the public interest loses no matter which one of those entities wins.

Perspectives on computer security and encryption from Apple, the FBI and I : my use

My perspective on computer security and encryption

This is a second article in a series that started with discussing the FBI and will end with discussing Apple.

I have worked in this industry since the early 1990's, administering Internet network connected computers.  I have worked for companies that produced firewalls, as well as worked in government departments where implementing security policies were critical.  Encryption is a critical part of what I do for clients and/or employers, as without it we could not build the services we are able to offer.

Local vs Remote Control

One of the hardest concepts to grasp with modern technology, including with fairly technical people, is the need to separate the concepts of geography and control.  With simpler technology the person who possessed something was the one who controlled it, but with modern computing this is not the case.

A big part of my current job at Canadiana is to manage a network of computers.  While some of the computers are located in the building I normally work in, most are not.  We currently have computers in Ottawa, Montreal, Toronto and Edmonton, with plans to continue to expand across the country as we grow. I control all of these computers from wherever I am at the time, whether that is physically in our main Ottawa office or when I am working from remote (I am in Sudbury as I type this).

We use Virtual Private Networking (VPN) technology to connect these computers together, and a variety of other encryption technologies used for authentication and privacy.  In order to connect to any of these computers I must possess both the required cryptographic keys as well as passphrases required to unlock those keys.   This is required to ensure that it is only authorized individuals like myself that can gain administrative access to these computers, and we need to ensure that nobody can eavesdrop on this communication and learn anything that might allow them unauthorized access.  We often are working with multiple layers of cryptography: secured ssh command-line access through VPN encrypted connections to network interfaces which don't have publicly routable addresses.

It is modern computer security and cryptography which makes this critical feature possible.  It is what allows us to know that we are able to have exclusive control over these devices regardless of their location. Any weakening of computer security, either to benefit law enforcement or some third party special interests (device manufacturers, etc), opens the technology up to other unauthorized access and makes my clients at risk.  I am not alone, and much of the modern economy and politics of society is built upon the need to continuously improve computer security and encryption.

Hardware assistance for security

We plan to expand our services beyond what we currently offer in two important ways that will impact security policies.

Currently we host our servers in partner organizations that we trust, as well as a commercial service provider. As we expand we may want to physically locate computers on networks and in server rooms of organizations that we have less trust in.  We will want security features which will protect us even from people who have physical access to the computers, to ensure that the most they could do is disable a node and not be able to abuse keys/etc stored within that node to attack other nodes in our network.

As we move from hosting digitized images towards the data which the digital humanities community need, we will have reasons to offer these communities the ability to author apps which run on our servers with faster access to the data and only need to communicate the results of complex queries to remote computers. These apps will run on our computer, but we will want to ensure that nothing that these apps can do can impact the rest of our network.  While there is a wide variety of software based virtualization technologies, we may have reason to harness hardware assistance to implement security policies.

One example is ARM architecture manufacturers which offer SecurCore and TrustZone technologies.   This allows combinations of multiple physical CPUs as well as multiple sections within a CPU being separated, allowing one to secure the other.  This can be used in conjunction with UEFI secure boot, which if implemented correctly can ensure that only software digitally signed by the owner can run on the computer.

Using separate System on Chip (SoC) technologies, the firmware loaded into a secure SoC can be instructed to erase local keys if it detects tampering.  This way encrypted data on the system could not be accessed even if the computer itself was physically compromised.  Keys could be stored in that secure zone, meaning that even if disks were removed from the server the data on them would be inaccessible.

While some companies will be able to afford to manage the software stack on each CPU within each zone, many will simply hire this from other companies.  Ideal in these environments is if the hardware vendors and software authors of the different components consider each other hostile, providing the same types of checks-and-balances within a computer that we need in our public policy spaces.  In this way the operating system might detect hostile secure zone firmware in the same way that the secure zone firmware may detect a hostile operating system, with both working together to protect the computer owner from hostile applications.

For some of us we will only put our trust in transparent and accountable FLOSS.  Genode provides good documentation on their TrustZone implementation. Open Virtualization provides a great ARM TrustZone FAQ, which describes the relationship between TrustZone and the Trusted Platform Mobile (TPM).  These are both commercially supported projects which offer both FLOSS and non-FLOSS licensing options for software which is open and accountable.

The limits of physical access

Once a computer is fully secure, there are only a few things that someone with physical access can do that is not under the control of the entity with all the security keys.
  • They can disconnect the device from the network.  This doesn't grant the person with physical access control, but it does deny the remote owner the ability to issue new commands to the device.  The device can only act on instructions it already has on it, in the form of installed software.
  • They can disconnect the power to the device.  This also doesn't grant the person with physical access control, but denies the ability of the remote owner to execute any commands whether the software was already installed on the device or not.
  • They can destroy the device.  This also doesn't grant the person with physical access control, but denies the ability of anyone to ever control the device again.
This means that while it is possible for someone with physical access to disrupt the operations of the device, it doesn't grant them control over the device.

The Law

When I am controlling a distributed set of computers on behalf of my employer, I and my employer should not be considered above the law.  If evidence of a crime was stored on our computers, and we were served with a valid court order to present this information to law enforcement or the court, we would obviously do so.

I would not consider it a reasonable course of action to deliberately configure computers under our control to destroy evidence.  As much as we might claim we are protecting the "privacy" of our clients, I don't consider that to be a valid reason to ignore a court order.  I would consider this an example of vigilantism that would be contrary to the public interest.  When a government makes harmful demands this should be something that is fought in the courts and debated in parliaments, not something that individual citizens or corporations take on themselves.   While we might agree or disagree with any specific government in any individual case, it makes us all unsafe if we condone individuals or governments ignoring the rule of law.

When a law is wrong we work hard as citizens to fix the law, not ignore it.  While I agree there are many buggy laws deployed in every country, I consider this a reason to get politically engaged as any trustworthy citizen or corporation should.

Law enforcement and courts need to modernize their understanding of technology, most importantly the question of control in a networked computing environment.  They need to understand that the physical location of the computer is not the most important factor to determining who controls the computer, and thus who to serve warrants to.

If we deployed fully secure hardware with hardware assistance, and had security put in place to protect us against attacks by unauthorized persons with physical access (IE: wiped keys if unauthorized physical access detected), then law enforcement must be aware of this advancement.  If in the pursuit of evidence to convict a user of our services they served a warrant against the physical hosting company rather than us then they risk destroying the evidence they are trying to collect.     The warrant must be served against the entity that controls the computer, not the entity that physically houses the computer.

It must never be considered the fault of the computer owner that evidence was destroyed by law enforcement.  The current technology illiterate or technology neophyte politicians, judges and police officers are making all of us unsafe.  Technology literacy must become a requirement of those who will be trying to make or enforce laws impacting technology.


Keep reading: Apple's use of computer security and encryption

Perspectives on computer security and encryption from Apple, the FBI and I : FBI

Many people have weighed in on the Apple vs FBI case, including a speech by President Obama.  People in the technology industry have lined up in support of one or the other.

My views can't be expressed as a simple support of one position or the other.  As I believe there is a third option I am authoring this as a series of articles that discusses the issue from three perspectives:

* This article discusses FBI
* A second article discusses my use of security and encryption technology
* A third article discussing Apple

Lawful Access

I've written about the question of lawful access before, and the requirement for there to be strong oversight of police and security agencies in order for those agencies to not themselves be the risk to society that they are supposed to be reducing.  Law enforcement and security agencies must have strong court oversight, and the courts themselves must have strong citizen oversight through ensuring the number of closed court sessions are kept to an extreme minimum.

There is a conflict of interest when it comes to law enforcement and security agencies and protecting the public.  Often these agencies will confuse protecting citizens against death from protecting their lives.  They promote policies which make it easier for them to find and punish wrongdoers, but generally have no concern about the harmful consequences of those policies on the health, safety and security of citizens.

FBI Opposition to encryption

There is no better example of why there is a need for checks-and-balances than the extreme views expressed by James B. Comey, Director of the FBI.  He has for some time been suggesting that the world is "going dark" because an increasing amount of communications is encrypted.  He sees only the narrow potential downsides of this technology in that it might hide criminal activity from the FBI, and ignores the critically important features -- the very fact that the modern economy and much of modern society is built upon private communications requiring strong encryption.

If Mr Comey were a doctor, he would recommend amputating a patients head to solve a back pain problem. He would be correct in saying that after amputation the patient would no longer feel back pain, and would likely be confused why people would consider that a failure.

Fortunately in our society we don't leave extremists like him solely in charge.  Even the NSA, which does its own cracking of encryption and has been accused many times of trying to weaken or put back doors in encryption, had its director come out in favour of encryption due to the extreme views expressed by Mr Comey.  In fact, there is a rift within the US government about this issue, and it is quite a complex one that simply can't be expressed by saying individuals and agencies are picking sides between Apple or the FBI.

The FBI or any other government agency, here in North America or elsewhere, should never be given "back door" access to technology in general as that would enable them to bypass the required checks and balances which the courts and the public must be able to provide in a democratic society.  I have absolutely no respect for the position that suggests they should have no barriers to their investigations, as I do not believe democracy and the required separation of power between agencies can ever be claimed to be a barrier to protecting a democracy.


Keep reading:  My use of computer security and encryption

Wednesday, October 21, 2015

A (non)Copyright question in a Canadian federal election 2015 quiz.

On Monday many co-workers were circulating around a links to political quizzes.  I was asked what I thought about one that included a copyright related question, and if I was happy that Copyright was considered important enough to be part of one of these quizzes.

I would have been excited, except that what I found was one of those non-copyright related issues which people commonly lump in with copyright law -- including governments who add these non-copyright related issues to copyright acts.

The issue is so-called "digital locks", which when applied to content in the form of encrypted media are a competition law issues (Tied selling) and when applied to devices and software is a property law issue (IE: non-owners applying locks to things they don't own).

The wording of the question and the available answers were:

Should the government allow digital publishers to place locks on their content (MP3s, etc)?


I of course clicked "Add your own stance" and said "No, these locks should be considered illegal tied selling under competition law.  There has been no proof that these technologies benefit the interests of artists."


  • I obviously disagree with the unjustified "Yes"
  • Saying "No" over-simplifies the question and allows the presumption in the question that this is an issue that only or even primarily affects "digital publishers" and thus they should be the only ones involved in decision.  The impact to software authors and hardware owners is far greater than the impact to "digital publishers" - and in all cases the impact is negative (Beneficiary is hardware vendors).
  • Statutory monopoly laws are a massive government intervention in the market, so the pseudo-libertarian folks can't have it both ways.  Other than those with an orthodox ideologically blinded view on statutory monopolies, most recognize a need to have anti-trust/competition and other laws balance the statutory monopolies granted by government in copyright, patent and related laws.
  • I have yet to see evidence that encrypted media (digital locks, access controls applied to multimedia files) protect rather than threaten artist's revenues.  Most analysis that claims benefit are based on incorrect understandings of how the technologies actually work, and thus lead to incorrect conclusions about the impact.


The Bill C-11 FAQ contains quite a bit of information on digital locks and the real-world issues around them (Rather than the Harry Potter fictional understanding most non-technical people have of digital locks).

Sunday, October 11, 2015

Harper locking Canada into failed Clinton-era policy at root of software-based corruption

Most people have heard about the emissions scandal where Volkswagen was caught hiding the fact that they were deliberately breaking the law.  This specific issue is minor when compared to the inevitable fatalities which will result from vehicles that allow remote control, or medical devices where the person whose life is being maintained by the technology aren't allowed to independently audit what and whose instructions it is obeying.

Harper amended the rules for a caretaker government this election so that his minister can continue pushing forward controversial policy which would lock Canadian law to disallow the required transparency and accountability of the very rules which govern everything from transportation and communications to medical devices and in some cases elections.

While the "copyright" aspects of the Trans-Pacific Partnership are being covered elsewhere, there are non-copyright aspects embedded in the leaked Intellectual Property Rights Chapter that regulate the general transparency and accountability of software.

Unlike the 1996 WIPO treaties which tie what are now called "use controls" to copyright infringing activities, article QQ.G.10: {Technological Protection Measures} of the TPP mandates legal protection of access controls.  The TPP is based on the USA's DMCA which is based on the failed Lehman report from 1995 during the Clinton administration. While Bill C-11 also protects access controls, this is a critical mistake by the Harper government that a future government will need to fix.  Harper is aggressively pushing Canada into the TPP which will require that a future government get permission from TPP "partners" to finally fix these problems.

Access controls are controversial for a number of important reasons:


  • Access controls and other non-owner locks on software and hardware reduces the transparency and accountability of the rules that govern these devices.  Technology owners are disallowed from making their own independent software choices, as well as doing their own or having trusted third parties do software audits.
  • Access controls applied to multimedia content (more commonly known as "encrypted media" outside of policy circles) are used to tie access to culture to specific brands of access technology, pretty much always technology where the hardware and software has non-owner locks to disable auditability.  This type of tied selling is known to be harmful to the economy (is included in most anti-trust or competition policy), but also impacts cultural rights embedded in the UN Universal Declaration of Human Rights.
  • These policies allegedly relating to "copyright" are being applied to technology which intermediates most aspects of our modern lives.  While there have been expensive court cases to create narrow exceptions for uses of devices unrelated to copyright, most businesses (and even fewer individuals) don't have the financial resources to fight court battles to protect basic property and other rights.  The harmful impacts to the economy go well beyond copyright related industries, and the harmful impacts extend to issues surrounding health and safety, privacy, and national security.
  • There has been no credible evidence to the claim that these controls reduce copyright infringement, and considerable evidence to suggest they induce infringement
  • Creators of cultural works are as dependent as audience are (if not more) on having control of their own technology, and thus these non-owner locks on technology harm creators' rights

The cost to taxpayors alone of Harper doubling-down on this failed policy cannot be understated.  As one small example, the Canadian Forces are hiring people to hack into vechicle control systems (See: Cyber Security of Automotive Systems (W7701-166085/A)) to do basic auditing, but given the illegitimate claims of exclusive rights this taxpayer funded audit will not likely be widely published. The only reason why taxpayers have to foot this bill, rather than the costs being distributed across other interested and skilled device owners is because of this Harper policy.




It is sad that Harper even promotes his reckless behavior during the election, trying to pull the wool over voters eyes by claiming the TPP is "trade" policy rather than the harmonization of non-trade related policies --- often untested policies, or where the policies were proven failures in countries where they were tested.

Harper suggests people should vote for him and his nominated candidates because of their record on the economy and on security. This policy is one example among many where Harpers record indicates failure.

Monday, October 31, 2011

Are paywalls a Copyright issue?

We should answer the question of whether a paywall is a copyright issue, before we dive into the question of the importance of this question for the debate around the Paracopyright provisions in Bill C-11.

I am familiar with paywalls from the perspective of both a user and a provider of such services. I will offer two specific examples of paywalls to illustrate the issues.

I have been a paid subscriber to The Hill Times since 2005. This is an example of a service that offers some access to anonymous browsers on the Internet, but offers advanced services (full access to search through considerable archives, access to all new articles, etc) only to paid subscribers. You use a simple username and password to log in to prove you are a subscribe.

My current job is as a software author and system administrator for Canadiana.org. We offer anonymous access to some content, while other content is only available to paid subscribers. All the content is in the public domain, so copyright isn't relevant to our service. What is being paid for is access to this content as a method to fund the work we do in digitizing and organizing this information. We have individual and institutional subscribers, with individual users able to subscribe quickly making use of a simple PayPal payment system. While institutional subscribers are given access based on their internet address, individual subscribers use a simple username and password to indicate they are a subscriber.


These two services equally use of a paywall to differentiate between anonymous access and subscribers. While The Hill Time is offering access to copyrighted works, Canadian.org is not. From a legal standpoint these paywalls should be treated the same, with each being offered the same level of legal protection against people who might want to gain unauthorized access to our services.

There has been suggestions from some people that paywalls are inadequately legally protected in Canada. This is often being claimed by proponents of the Paracopyright ("digital locks") provisions in Bill C-11. I don't know for certain whether paywalls are offered adequate legal protection under existing Canadian federal or provincial laws, including whether existing criminal code is sufficient.

I will state that the Copyright act is exactly the wrong law to provide this legal protection. It would make very bad law if legal protection for a paywall was dependent on the specifics of what is offered behind the paywall rather than protecting all paywalls equally and fairly. While I agree with the suggestion that paywalls should be offered legal protection, it must be in the correct law.

While it is true that some copyright holders make use of paywalls in support of their businesses, it is also true that even more copyright holders use electricity in support of their businesses. Suggesting that legal protection for paywalls must be in C-11 makes about as much sense as suggesting that a national energy strategy must also be included in Bill C-11.

The question of whether paywalls are a copyright question came up in a twitter conversation where a proponent of Bill C-11 style Paracopyright was trying to be critical of Postmedia for considering paywalls. He was trying to suggest this conflicted with other articles on the Globe and Mail which were critical of the Paracopyright provisions of Bill C-11.

I hope it is obvious that there is no conflict with supporting, subscribing to or even providing paywall services and being strongly opposed to the Paracopyright provisions of Bill C-11. My primary motivation for my involvement in the copyright revision process is as an opponent to abuses of these provisions to infringe owners rights which Paracopyright provisions may enable.

Trying to conflate different issues like this is a common political tactic of those trying to promote these provisions. They take a non-controvercial technology like paywalls, claim that this is all that is meant by "technological measures" or "digital locks" in C-11, and then try to shove under the rug all the opposition to these highly controversial measures.


What most stakeholders are asking for is that any Paracopyright contained within Canadian copyright law should be tied strongly to otherwise copyright infringing acts. This is what the two 1996 WIPO treaties were calling for, given they are tied to "technological measures that are used by authors in connection with the exercise of " copyright related rights "that restrict acts, in respect of their works, which are not authorized by the authors concerned or permitted by law".

The further protection for "technological measures" added to copyright law strays from copyright infringing activities, the easier it is for providers of these technologies (the holders of the keys to these "digital locks") can abuse these provisions to circumvent laws including (but not limited to) contract, e-commerce, property, competition, trade as well as copyright.

One really has to wonder the motivation of those who want legal protection for "technological measures" added to copyright law to have little or no connection to otherwise copyright infringing activities. In some cases it is a lack of understanding of the underlying technology.

In some cases there may be ulterior motives. Some companies may want their circumvention of existing laws protected by beyond-WIPO Paracopyright provisions. There are some popular hardware brands in the game console, cell phone and other mobile computing space which have been outright hostile to the property rights of technology owners. Some of the representatives of these hardware manufacturers, including some representatives of the Entertainment Software Association of Canada, have made some of the most extreme claims.

Friday, October 7, 2011

Will you explain why DRM is bad?

I was asked on twitter to explain why DRM is bad.  Given I have spent more than a decade talking about this topic, you would think there is a simple twitter-length answer: but there isn't.


Whether you believe the acronym expands to Digital Rights Management, Digital Restrictions Management, or Dishonest Relationship Misinformation, it doesn't define a specific technology or technique.  The acronym is used to refer to non-controversial technologies such as databases describing content and eCommerce websites, to highly controversial things such as digital locks which lock out the owners of what is locked.


We can't entirely avoid using confusing terms, as people will immediately say "Aren't you talking about DRM" when you want to speak about specific harmful activities.  It is very useful to be clear whenever the time is available.


When some people are concerned about DRM they are concerned about the inability to loan electronic books, or to exercise their fair dealing rights.  While that is peripherally interesting to me, and I agree with some and disagree with other of these ideas, my main concern is impacts which are entirely outside of copyright.  I am happy to discuss (including in comments below, or on the Digital-copyright.ca site) copyright related topics, but for the purpose of this article I am going to talk about things which are unrelated to copyright.


The two techniques I have been fighting against are anti-interoperability locks on content, and non-owner locks on devices.


I believe it should be obvious why having a lock, digital or otherwise, which locks the owner out of what they own is wrong.  In our society most people have at least a minimum of respect for the concept of property rights, and believe that if locks exist it should be the owner that controls them.  Locks should certainly never be allowed to be abused to lock the owner out of what they own, and our laws should protect the owner against such scenarios.  I would be happy to discuss this more if people want, but I am honest in saying that I can't understand why people demonstrate such a lack of respect for or understanding why governments property rights in these discussions.


It shouldn't matter if what is locked is our homes, our cars, or our computers: we should never allow for digital exceptionalism where we ignore basic property rights if the property happens to be digital technology.


The anti-interoperability lock on content ties the ability to access the content to specific brands of devices.   This is harmful in a variety of ways, including being what I consider to be a textbook example of tied selling as described in section 77 of our competition act.   Governments have competition and anti-trust laws for a reason, and again we should not throw away this body of law simply because the tied selling includes something digital.


I don't believe that copyright holders should have the right to decide what brands of technology I use, or what features should exist in the technology that is created and sold.  That said, those who support this policy should recognize that in the vast majority of real-world scenarios it is not the copyright holder that controls the keys to these digital locks.  It is the vendor of the DRM system, a technology company, that controls the keys.  Any digital lock, analog or digital, protects the interests of the key-holder and not necessarily the owner.  I have observed many copyright holders switch their position from being in strong support of technological measures being added to copyright law to being strong opponents once they realized that they as copyright holders would not have the keys or any real-world control over these digital locks.


More important to me, these anti-interoperability locks tie people to non-owner locked devices, something I believe should be prohibited in law.  My primary issue in this debate is the protection of the tangible property rights of technology owners.  Even if it were copyright holders that held the keys to the digital locks on their content, and even if there was a shred of evidence that these locks reduced copyright infringement (most evidence suggests increases), I would still disagree that this justified the legalization of non-owner locks on our devices or anti-competitive behaviour that encouraged the use of non-owner locked devices.




While I believe that these two controversial locks should be prohibited in law,  Bill C-11 (and C-32 and C-61 before them) provide legal protection for them.   While these bills are called "An Act to amend the Copyright Act", the digital locks provisions are not related to the subject matter of copyright law.  In fact, these digital locks have been and will continue to be abused to circumvent the contours of existing laws including contract, e-commerce, property, competition, trade and even copyright.


We have a long way to go in this conversation.  In my mind anyone who respects contract, e-commerce, property, competition, trade, and/or copyright should be opposed to "technological measures" being added to the copyright act.  Legal protection for "technological measures" must be added to the correct law in order for them not to be abused to circumvent the law.


If a technical measure is protecting contracting terms, including a copyright license agreement, then the legal protection should be in provincial contract law.


If a technical measure is protecting electronic commerce, then the legal protection should be in provincial e-commerce law.


And so on...


Hope this helps, and sorry that there isn't a twitter-sized response to this question.  There is a lack of clarity in what the acronym means, which add to the confusion that most of the impacts of adding "technological measures" to copyright law have nothing to do with copyright.