From: Tudor Bosman <tudorb@pikka.net>
To: "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
Subject: Re: Linux 2.2.20pre10
Date: Mon, 22 Oct 2001 12:14:47 -0700 [thread overview]
Message-ID: <20011022121447.A5618@frood.pikka.net> (raw)
In-Reply-To: <86256AED.0065BD5D.00@smtpnotes.altec.com>
In-Reply-To: <86256AED.0065BD5D.00@smtpnotes.altec.com>
OK, let's get the disclaimer out of the way. This post is opinionated,
and IANAL. Now...
For reference, here is the full text of the DMCA subsection in question:
(1201(2)):
``(2) No person shall manufacture, import, offer to the public,
provide, or otherwise traffic in any technology, product, service,
device, component, or part thereof, that-
``(A) is primarily designed or produced for the purpose
of circumventing a technological measure that effectively con-
trols access to a work protected under this title;
``(B) has only limited commercially significant purpose or
use other than to circumvent a technological measure that
effectively controls access to a work protected under this title;
or
``(C) is marketed by that person or another acting in concert
with that person with that person's knowledge for use in cir-
cumventing a technological measure that effectively controls
access to a work protected under this title.
I would like to comment on this from two different angles.
1. The subsection mentions "any technology, product, service, device,
component, or part thereof". While this definition is vague, and we
hackers tend to like splitting hairs (see Dave Touretzky's DeCSS
gallery, http://www-2.cs.cmu.edu/~dst/DeCSS/Gallery/index.html), there
is a clear distinction between (constitutionally-protected) speech (in a
non-machine readable) form, and a software product. Other forms of
expression (source code, non-machine readable source code, source code
set to music, etc.) lie on the fine line between the two.
For example, exporting PGP on paper and OCR-ing it (because exporting it
in electronic form was illegal) was a legal absurdity. While this
hair-splitting might have amused a few lawyers and judges here and
there, I believe that a well-versed attorney could have torn that
defense to pieces, because we tried drawing demarcation lines instead of
concentrating on defeating the spirit of the law.
The above-mentioned paragraphs make no reference to "information" or a
"description" of such a circumvention device. A high-level description
(in plain English) of a security hole is not a "technology, product,
service, device, component, or part thereof"; and if it can be construed
as such, surely the realization of such description (the source code
itself) is much closer to the notion of a "product". Is this the end of
full disclosure and open source/free software? Should BUGTRAQ be banned
from US residents?
2. The arguments for/against publishing the description of the security
hole in the DMCA context are the same as the arguments for/against full
disclosure in the security field in general. IF the description were
published, then... (paraphrasing the three DMCA paragraphs I cited)
(A) it would NOT be primarily designed for circumventing a technological
measure that effectively controls access to a protected work- it would
be primarily designed for informing system administrators of their risks
and the importance of the patch, and informing developers of pitfalls to
avoid in writing new code;
(B) it would have a LARGE commercially significant purpose other than to
circumvent a technological measure that effectively controls access to a
protected work- the main purpose would be to urge system administrators
and developers to implement a higher degree of protection (at the very
least, apply the patch), and
(C) it would NOT be marketed by Alan Cox or another acting in concert
with him for use in circumventing a technological measure that
effectively controls access to a protected work- this is a no-brainer, I
don't think there are many people on this list who openly advocate
exploiting security holes for gaining unauthorized access.
In conclusion, I tried to make two points in the above rant:
1. A description of a security hole is constitutionally protected
speech, and as such cannot be construed as violating the sections of the
DMCA. If such description fits the definition of "technology, product,
service, device, component, or part thereof", then we're in big trouble,
because source code itself is much closer to the definition of a
"product" than a description of the source code.
2. A description of a security hole, or unpatched source code, or even
exploit code do not meet the criteria set forward by the DMCA for
illegal circumvention devices.
Best regards,
Tudor.
--
"They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety."
- Benjamin Franklin, Historical Review of Pennsylvania, 1759.
next prev parent reply other threads:[~2001-10-22 19:15 UTC|newest]
Thread overview: 184+ messages / expand[flat|nested] mbox.gz Atom feed top
2001-10-22 18:27 Wayne.Brown
2001-10-22 18:38 ` Nick LeRoy
2001-10-22 18:40 ` Alexander Viro
2001-10-22 19:23 ` Paul Fulghum
2001-10-22 19:14 ` Tudor Bosman [this message]
2001-10-22 19:42 ` Mike Fedyk
2001-10-22 19:55 ` Tom Sightler
2001-10-22 20:42 ` Alan Cox
2001-10-22 20:45 ` Dan Hollis
2001-10-22 21:12 ` Tom Sightler
2001-10-22 21:35 ` Dan Hollis
2001-10-22 22:49 ` David Weinehall
2001-10-22 23:29 ` Tom Sightler
2001-10-22 23:49 ` D. Stimits
2001-10-23 1:32 ` Tom Sightler
2001-10-23 0:37 ` Re[2]: " victor
2001-10-22 21:04 ` Tom Sightler
2001-10-22 20:28 ` Alan Cox
2001-10-24 19:00 ` Riley Williams
2001-10-22 23:19 ` Luigi Genoni
-- strict thread matches above, loose matches on Subject: below --
2001-10-26 20:26 Fabian Svara
2001-10-26 18:49 ` Rik van Riel
2001-10-23 12:31 Jesse Pollard
2001-10-23 3:45 Thomas Hood
2001-10-23 2:48 Patrick Chase
2001-10-22 23:40 Carsten Kuckuk
2001-10-22 23:06 ` D. Stimits
2001-10-22 23:35 Craig Dickson
2001-10-23 0:53 ` Luigi Genoni
2001-10-23 1:08 ` Craig Dickson
2001-10-22 23:30 Thomas Hood
2001-10-22 23:45 ` D. Stimits
2001-10-22 22:27 Wayne.Brown
2001-10-22 23:56 ` David Weinehall
2001-10-23 0:40 ` Chris Gomez
2001-10-23 16:21 ` Jonathan Amery
2001-10-22 22:20 Leif Sawyer
[not found] <fa.mf0j8bv.1e5o8jq@ifi.uio.no>
2001-10-22 22:15 ` Sam Varshavchik
2001-10-22 22:12 Wayne.Brown
2001-10-22 22:26 ` Kilobug
2001-10-22 21:07 Wayne.Brown
2001-10-22 20:57 Craig Dickson
2001-10-22 21:07 ` Rik van Riel
2001-10-22 21:21 ` Tom Sightler
2001-10-22 21:23 ` Craig Dickson
2001-10-22 21:32 ` Rik van Riel
2001-10-22 22:13 ` Craig Dickson
2001-10-22 22:22 ` Jan Niehusmann
2001-10-22 23:25 ` Jeff Golds
2001-10-22 23:27 ` Jeff Garzik
2001-10-23 16:27 ` Geert Uytterhoeven
2001-10-23 1:59 ` Aaron Lehmann
2001-10-23 4:36 ` CaT
2001-10-23 10:50 ` Rik van Riel
2001-10-23 17:36 ` Paul Jakma
2001-10-23 18:25 ` David S. Miller
2001-10-22 21:37 ` Bob Glamm
2001-10-22 22:02 ` D. Stimits
2001-10-22 22:17 ` Pedro Corte-Real
2001-10-22 23:02 ` D. Stimits
2001-10-22 21:27 ` ogd116
2001-10-22 21:37 ` Craig Dickson
2001-10-22 21:43 ` Rik van Riel
2001-10-22 21:58 ` Tony Hoyle
2001-10-22 22:04 ` Rik van Riel
2001-10-22 21:48 ` ognen
2001-10-22 20:27 PinkFreud
2001-10-22 20:30 ` Rik van Riel
2001-10-22 20:42 ` PinkFreud
2001-10-22 22:57 ` Mike Fedyk
2001-10-22 23:21 ` Jeff Garzik
2001-10-22 21:17 ` D. Stimits
2001-10-23 0:11 ` Luigi Genoni
2001-10-23 10:00 ` Marco Colombo
2001-10-22 20:22 Torrey Hoffman
2001-10-22 20:37 ` Tommy Reynolds
2001-10-22 19:58 Rogier Wolff
2001-10-22 20:28 ` Steve Brueggeman
2001-10-22 18:59 Wayne.Brown
2001-10-22 20:01 ` bill davidsen
2001-10-22 18:13 Per Jessen
2001-10-24 13:27 ` Horst von Brand
2001-10-22 17:51 Wayne.Brown
2001-10-22 18:06 ` Rik van Riel
2001-10-22 21:52 ` Kilobug
2001-10-23 6:29 ` Yoann Vandoorselaere
2001-10-22 18:41 ` Joel Jaeggli
2001-10-22 19:38 ` Adrian Bunk
2001-10-22 17:21 Wayne.Brown
2001-10-22 17:35 ` George Garvey
2001-10-22 17:46 ` Nick LeRoy
2001-10-22 17:57 ` Rob Turk
2001-10-22 19:45 ` D. Stimits
2001-10-22 20:17 ` Alan Cox
2001-10-22 17:51 ` Rob Turk
2001-10-22 15:11 Wayne.Brown
2001-10-22 15:42 ` Tom Sightler
2001-10-22 16:03 ` Rik van Riel
2001-10-22 10:21 Alan Cox
2001-10-22 10:37 ` bert hubert
2001-10-22 11:30 ` Alan Cox
2001-10-22 11:35 ` bert hubert
2001-10-22 11:55 ` Alan Cox
2001-10-22 12:06 ` Matthias Andree
2001-10-22 12:29 ` Alan Cox
2001-10-22 13:24 ` Luigi Genoni
2001-10-22 19:27 ` brian
2001-10-22 19:39 ` Rik van Riel
2001-10-22 20:04 ` Richard B. Johnson
2001-10-22 20:44 ` Alan Cox
2001-10-22 20:45 ` Richard B. Johnson
2001-10-23 5:56 ` Paul P Komkoff Jr
2001-10-27 16:18 ` Henning P. Schmiedehausen
2001-10-22 20:34 ` Alan Cox
2001-10-22 22:45 ` Steven Walter
2001-10-22 23:07 ` Mike Fedyk
2001-10-22 23:24 ` Steven Walter
2001-10-24 5:02 ` Paul G. Allen
2001-10-23 3:55 ` Nicholas Dronen
2001-10-22 23:39 ` Jonathan Lundell
2001-10-22 23:47 ` Steven Walter
2001-10-23 1:01 ` Jeff Golds
2001-10-23 1:35 ` Steven Walter
2001-10-22 23:58 ` Jonathan Lundell
2001-10-23 1:40 ` Steven Walter
2001-10-22 23:04 ` David Ford
2001-10-22 23:15 ` Alan Cox
2001-10-22 23:32 ` Mike Fedyk
2001-10-22 23:38 ` D. Stimits
2001-10-22 23:57 ` Sam Vilain
2001-10-22 12:08 ` bert hubert
2001-10-22 12:30 ` Alan Cox
2001-10-22 12:25 ` bert hubert
2001-10-22 12:37 ` Rik van Riel
2001-10-22 13:33 ` Horst von Brand
2001-10-22 18:21 ` Dan Hollis
2001-10-22 19:29 ` D. Stimits
2001-10-22 18:14 ` Dan Hollis
2001-10-22 19:24 ` D. Stimits
2001-10-22 13:07 ` Roger Gammans
2001-10-22 13:30 ` bert hubert
2001-10-22 16:11 ` David Lang
2001-10-22 14:11 ` Danny ter Haar
2001-10-22 16:20 ` bill davidsen
2001-10-22 16:34 ` Rik van Riel
2001-10-22 16:52 ` Nick LeRoy
2001-10-22 19:39 ` D. Stimits
2001-10-22 19:49 ` Doug McNaught
2001-10-22 20:51 ` D. Stimits
2001-10-22 23:07 ` Luigi Genoni
2001-10-22 23:30 ` D. Stimits
2001-10-23 0:41 ` Luigi Genoni
2001-10-23 0:42 ` Michael Rothwell
2001-10-22 19:56 ` Gregory Ade
2001-10-22 20:59 ` Jussi Laako
2001-10-22 21:56 ` Bill Davidsen
2001-10-22 22:10 ` Dan Hollis
2001-10-22 22:16 ` Tony Hoyle
2001-10-23 13:21 ` Nick LeRoy
2001-10-22 16:49 ` Alan Cox
2001-10-22 17:16 ` Greg Hennessy
2001-10-22 19:35 ` D. Stimits
2001-10-22 16:30 ` Andreas D. Landmark
2001-10-22 19:43 ` Gregory Ade
2001-10-22 20:14 ` Alan Cox
2001-10-22 21:30 ` Gerhard Mack
2001-10-24 8:18 ` Florian Weimer
2001-10-24 17:45 ` Riley Williams
2001-10-22 19:28 ` Gavin Baker
2001-10-22 10:40 ` Allan Sandfeld
2001-10-22 17:31 ` Dominik Kubla
2001-10-27 15:57 ` Henning P. Schmiedehausen
2001-10-22 10:41 ` Andreas Haumer
2001-10-22 10:52 ` Alan Cox
2001-10-24 22:41 ` Rik van Riel
2001-09-11 23:06 Alan Cox
2001-09-12 8:01 ` Roberto Nibali
2001-09-12 8:08 ` David Woodhouse
2001-09-12 8:36 ` Kai Germaschewski
2001-09-12 8:38 ` David Woodhouse
2001-09-12 8:21 ` Andreas Haumer
2001-09-17 6:08 ` Mike Fedyk
2001-09-17 12:24 ` Alan Cox
2001-10-22 15:04 ` Nicolas Turro
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20011022121447.A5618@frood.pikka.net \
--to=tudorb@pikka.net \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®