﻿<?xml version="1.0" encoding="utf-8"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><ttl>60</ttl><title>Digital Rights Management, IPR and copy control</title><link>http://drm-blog.locklizard.com</link><lastBuildDate>Thu, 11 Mar 2010 14:33:42 GMT</lastBuildDate><pubDate>Thu, 11 Mar 2010 14:33:42 GMT</pubDate><language>en</language><copyright /><itunes:subtitle> </itunes:subtitle><itunes:author /><itunes:summary /><description /><itunes:owner><itunes:name /><itunes:email>steve.mathews@locklizard.com</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:category text="Arts" /><item><title>The Internet is the right to copy</title><link>http://drm-blog.locklizard.com/2010/02/12/the-internet-is-the-right-to-copy.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;br&gt;One of the most unreasonable arguments that you see applied day in and day out on the Internet (and on roads before the introduction of speed cameras) is the 'right' to do something just because you can.&lt;br&gt;&lt;br&gt;It's an interesting argument because it is really an argument for the ultimate failure in ordered society - that I can do anything I can get away with - I have no morals, ethics, scruples or responsibilities.&lt;br&gt;&lt;br&gt;After all, it justifies any action at all, rape, murder, child pornography - you name it and it's OK.&lt;br&gt;&lt;br&gt;Hey, but wait a minute, you say.&amp;nbsp; That's all too heavy.&amp;nbsp; I didn’t mean all that nasty and illegal stuff.&amp;nbsp; Obviously that's all way too bad and has got to be wrong (well I sure hope that's what you're saying).&lt;br&gt;&lt;br&gt;So we are into drawing lines?&amp;nbsp; Some things are agreed to be bad and just because you can do them does not mean that you should, and if society (not just the cops) finds you doing them then there shall be punishment.&lt;br&gt;&lt;br&gt;Now obviously murder is not good.&amp;nbsp; But where is drug dealing?&amp;nbsp; Does it rank alongside liquor selling?&amp;nbsp; Is pornography OK but child pornography is not?&amp;nbsp; And how do you define them anyway?&amp;nbsp; Where do you rate selling dud cars (maybe that's a bit too topical right now).&lt;br&gt;&lt;br&gt;But let's cut to the chase.&amp;nbsp; Does the guy who writes music or the gal writing a play or the group playing a track deserve to get paid for their work?&lt;br&gt;&lt;br&gt;OK, you could argue that the group playing tracks can get paid for live performances, but I don't know as Elvis, The Beatles, or Madonna would be terrifically impressed by that.&amp;nbsp; Yes, live work is important to artistes because they get what you never can from a dead studio - an audience, the feel, the thrill of the audience.&amp;nbsp; So, what about the others.&amp;nbsp; Are they just supposed to produce and then give it away?&amp;nbsp; How long do you think authors would last if they had to give away their work and rely on a few crumbs from the hostel to keep them going? &amp;nbsp;&lt;br&gt;&lt;br&gt;True, some authors made it big on the conference circuit.&amp;nbsp; Now I don't mean Tony Blair or GW Bush or their like.&amp;nbsp; For one thing, authors they ain't.&amp;nbsp; But Charles Dickens did very well of it for the Brits, and Mark Twain for the Yanks, and you can certainly describe them as authors.&lt;br&gt;&lt;br&gt;But their real money did not come from lectures, but from printing.&amp;nbsp; Thomas Paine made his legendary contribution - The Rights of Man, for the American Civil War, as a paid for pamphlet!&amp;nbsp; If the Internet had existed then, do you suppose Twitter would have produced anything like in under a century?&amp;nbsp; Being well read is not the same thing as being well paid.&lt;br&gt;&lt;br&gt;In fact the laws of copyright were introduced in order to prevent the rich (the well paid) from gaining a monopoly over the production and delivery of information.&lt;br&gt;&lt;br&gt;So whilst the Internet may have given enormous freedoms - the freedom of expression - the access to open and alternative publicity, it has not created a new medium by and through which those creating information as their trading activity can make their livings. &amp;nbsp;&lt;br&gt;&lt;br&gt;And whilst this remains the case, however much the Internet may prevent censorship and may grant great voice to the weak and the oppressed - truly great capabilities of our time - it acts to deny information and knowledge creators their right to employment and to trade. &amp;nbsp;&lt;br&gt;&lt;br&gt;At the moment, outside of the communities paid for by advertising, people pay in order to make information available on the Internet.&amp;nbsp; Whether it's purchasing your own server or paying for a domain name, or paying to put up a web site, it's all paying to peddle your own knowledge.&amp;nbsp; But can you afford to give away the information that you need to sell to make a living?&amp;nbsp; Maybe the knowledge economy is already dead.&lt;br&gt;</description><category>Copy Control</category><comments>http://drm-blog.locklizard.com/2010/02/12/the-internet-is-the-right-to-copy.aspx#Comments</comments><guid isPermaLink="false">11cd912a-bf4d-4c82-ab14-670ec7d3bc23</guid><pubDate>Fri, 12 Feb 2010 22:03:00 GMT</pubDate></item><item><title>A crisis of identity</title><link>http://drm-blog.locklizard.com/2009/12/09/a-crisis-of-identity.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;br&gt;It is difficult to guess whether the national security and counter terrorism and contra paedophile brigades will, even when combined, push through a demand for electronic identity more than the anti-hacker and anti-spam and DRM must be personal brigades.&amp;nbsp; No, this is not one of those nice after dinner talking points, but a close analysis of the must have an identity brigades and their stances.&lt;br&gt;&lt;br&gt;In our own little backwater of the United Kingdom we have seen the government move through regulations that mean you cannot open a bank or savings account, or buy property or trade in shares, without producing photo-id.&amp;nbsp; Never mind who that disenfranchises.&amp;nbsp; You know it is for your own good because it could only ever be a problem if you had something to hide!&lt;br&gt;&lt;br&gt;That might not be so bad except they also intend to use it to enable them to dig into every aspect of every electronic transaction you ever carry out, and once cheques and cash have been removed that should just about cover it.&amp;nbsp; After all, no-one could ever steal your electronic identity - could they?&lt;br&gt;&lt;br&gt;But bigger battles are being fought in the US and the Far East.&lt;br&gt;&lt;br&gt;In the US there are some interesting conflicts (and I am not talking about Iraq/Afghanistan here), with the national security boys wanting to be able to monitor anything wherever, whenever and however they choose, the counter-terrorism (not quite the same slice) people wanting to make sure they can identify who everyone is at a physical level, and the contra paedophile groups wanting to be able to identify everyone who has ever gone near a porn site because they must be inherently evil.&amp;nbsp; Their ideas of identification vary significantly, because their end objectives of using the information also vary. &amp;nbsp;&lt;br&gt;&lt;br&gt;The US and the Far East also have some interests in common, perhaps because the Far East is now a major investor in the entertainments sector – films, music, computer games and hardware – the DRM brigade.&amp;nbsp; In some circumstances (downloading from file sharing or similar) they wish to be able to identify who is at both ends of the equation, but mainly they want to be able to enforce a series of use rules for electronic information, and they really really really do not want to know who is the user unless that is the only way to run the system because it causes lots of other problems.&lt;br&gt;&lt;br&gt;But the war is being fought by global commerce and industry.&amp;nbsp; They are sick to the back teeth with the cost and damage caused by spam, hacking, information theft, so-called social networking systems and other employee time-wasting activities that it seems impossible to prevent.&amp;nbsp; That is where real money is lost that makes the cries of all the other players unimportant.&lt;br&gt;&lt;br&gt;And the people that deserve a bit of help here are commerce and industry – globally.&amp;nbsp; Because there is no angle for gain by any one country over all the others.&amp;nbsp; After all, security mechanisms fail at the weakest link, don't they.&amp;nbsp; So we are either all in this together, or we have nothing at all.&lt;br&gt;&lt;br&gt;But since global commerce and industry do not have a voice, whilst all the other players do, we are going to continue seeing the lobby industries maintain their conflicting momentum whilst successfully draining time, energy and money from the people actually trying to do business.&amp;nbsp; Of course they will say that their agenda is valid and will solve everyone’s problems, but then they would, wouldn't they.&lt;br&gt;&lt;br&gt;Meantime I think we will stick to our guns.&amp;nbsp; Simple DRM systems that do not try to identify the actual individual who is licensed, but stop whoever they are from readily giving away what they have bought.&amp;nbsp; It may not solve the world's problems, but it solves a defined problem, which is a lot better than doing nothing. &amp;nbsp;&lt;br&gt;&lt;br&gt;Oh, and it avoids all the stuff about personal data, monitoring and so on, that gets some regulators really excited.</description><category>Digital Rights Management</category><category>Intellectual Property</category><comments>http://drm-blog.locklizard.com/2009/12/09/a-crisis-of-identity.aspx#Comments</comments><guid isPermaLink="false">2cbb2ecf-c179-4ca7-9ee1-2f844855e248</guid><pubDate>Wed, 09 Dec 2009 15:39:00 GMT</pubDate></item><item><title>Is DRM open to abuse?</title><link>http://drm-blog.locklizard.com/2009/08/19/is-drm-open-to-abuse.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&amp;nbsp;&lt;br&gt;Is DRM open to abuse?&lt;br&gt;&lt;br&gt;In a word, yes.&lt;br&gt;&lt;br&gt;Whilst we are not ashamed to be significant suppliers of DRM enforcing mechanisms and systems, we are convinced that the original reasons for creating copyright law, as demonstrated by the debates in the British parliament, were correct, and should be observed.&lt;br&gt;&lt;br&gt;Although the origins of copyright might be argued to go back to ancient China and the right to reproduce official forms, modern copyright was determined to make sure that authors (creators) of works would be able to enjoy the fruits of their labours, just as those who created physical goods.&amp;nbsp; Because if they did not, then the only authors would be those sponsored by government, industry and commerce, an unhappy trinity on which to place your reliance.&lt;br&gt;&lt;br&gt;And it was recognized that, in those days, getting full recompense for the writing of a book (other than popular novels) could take a very long time, and so copyright was granted even after the death of the author so that the family might draw benefit of the inheritance.&lt;br&gt;&lt;br&gt;There was strong debate to the effect that the legislators did not want ‘publishers’ to be able to buy copyrights, because that might give them the means to decide what was to be published and what was not, but market forces prevented the development of the idea that author rights should be inalienable.&lt;br&gt;&lt;br&gt;Now all of us can readily develop arguments to propose that in the Internet age distribution costs are marginal, and access to market is immediately global, and therefore perhaps copyright should last for no longer than the author (as it were).&amp;nbsp; But we cannot support arguments that say that an author should be behoven to hand-outs from those who feel like giving some money.&amp;nbsp; This reduces the author to the status of a street beggar, a corner musician or a pavement artist.&amp;nbsp; We believe that approach to be flawed (as no doubt would JK Rowling on the one hand and the estate of JRR Tolkein on the other).&lt;br&gt;&lt;br&gt;But that should not be taken to mean that we believe DRM should be used as a mechanism to forcibly manipulate markets.&lt;br&gt;&lt;br&gt;We live today in what Arthur C Clarke famously described to the US Congress (positing words originally from Marshall McLuhan) that the world is a global village.&amp;nbsp; But the dictum is that we are global.&amp;nbsp; And to be global is to be transparent in our dealings with our global customers.&lt;br&gt;&lt;br&gt;So we do not accept that there should be regional pricing models, or that Internet goods and services should be restricted by either price of delivery date.&amp;nbsp; We, as a business, operate transparently in all markets.&amp;nbsp; We offer what we have at the same price (on the day of quotation since we suffer from exposure to the [unnecessary] manipulation of the currency markets) to any and all countries in the world permitted to purchase encryption technology by regulation.&lt;br&gt;&lt;br&gt;When we release new product it is done globally, even though we have the tools to do otherwise.&amp;nbsp; Why don’t we charge different prices in different markets?&amp;nbsp; Simply because we believe that is a flawed and dangerous trade model.&amp;nbsp; It would be wrong for us to, through our pricing structures, compel different regions to compete at an economic (dis)advantage as determined by us.&amp;nbsp; The world is already the global village that Clarke foresaw, but it seems that some folks have thus far failed to, following Belshazzar, read the writing on the wall.&lt;br&gt;&lt;br&gt;So we believe that DRM controls are correct, and that it is essential to reward the rights of an author to get paid for the work that they have carried out.&amp;nbsp; But we do not believe that DRM controls should be used to manipulate the economic environment.</description><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2009/08/19/is-drm-open-to-abuse.aspx#Comments</comments><guid isPermaLink="false">908a0605-1bdc-44ad-a098-0eb77bea03e1</guid><pubDate>Wed, 19 Aug 2009 16:35:00 GMT</pubDate></item><item><title>Associated Press makes the DRM news (but not how you think)</title><link>http://drm-blog.locklizard.com/2009/08/10/drmnews.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&amp;nbsp;&lt;br&gt;I read in an article &lt;a href="http://arstechnica.com/tech-policy/news/2009/07/drm-for-news-inside-the-aps-plan-to-wrap-its-content.ars"&gt;arstechnica.com/tech-policy/news/2009/07/drm-for-news-inside-the-aps-plan-to-wrap-its-content.ars&lt;/a&gt; that Associated Press (AP) would like a bit more DRM control over information they publish on the web.&lt;br&gt;&lt;br&gt;Now you might be forgiven for thinking that applying security to information you want to publish for public use, and to be incorporated, either by reference or as text, in the work of others, would be a challenge.&amp;nbsp; And you’d be right!&lt;br&gt;&lt;br&gt;The reasons security is so difficult to introduce are:&lt;br&gt;&lt;br&gt;-&amp;nbsp;&amp;nbsp; &amp;nbsp;content suppliers put accessibility above everything else;&lt;br&gt;-&amp;nbsp;&amp;nbsp; &amp;nbsp;web product providers want to be first to get the latest and greatest out there and grab whatever market share for themselves – regardless of the sustainability (more frequently lack of) of the economic model they are pursuing;&lt;br&gt;-&amp;nbsp;&amp;nbsp; &amp;nbsp;information security requires people to do something for which they do not perceive they have any gain or any responsibility, so they don’t bother.&lt;br&gt;&lt;br&gt;So what is AP trying to do?&amp;nbsp; Introduce another HTML tag which contains the authors (or copyright owner’s) rights.&lt;br&gt;&lt;br&gt;Now that’s not likely to set the world on fire, and I agree with the other security people talked to about this, it doesn’t change current security at all. &amp;nbsp;&lt;br&gt;&lt;br&gt;But whilst the AP approach looks like fig leaf and mirrors (conceals and reveals all at the same time – a bit like the Windmill?) there actually is some value to it.&lt;br&gt;&lt;br&gt;It doesn’t stop copying or actual theft and manipulation.&amp;nbsp; To achieve that it would have to envelope content and have a content licensing system, and that would be heavy, complex (for them to implement) and could have profound implications on their direct customers using them as a news feed.&amp;nbsp; Bad news indeed.&lt;br&gt;&lt;br&gt;But it does achieve two things that will go a long way to solving problems caused by ‘deep linking’ where a web site links through content that is not its own, but makes it look like it is from them. &amp;nbsp;&lt;br&gt;&lt;br&gt;The first is that by adding tags that will pass through the browsers unharmed, anyone doing nothing more than linking will be caught by a simple tool such as a web crawler, which can automatically process the apparent content and locate unauthorized content re-distributors who can then be investigated manually, and prosecuted when it is in the commercial interest of AP so to do.&lt;br&gt;&lt;br&gt;The second is to establish a ‘standard’ (and they ought to be looking to join a European initiative on that front because this is not a competitive matter and because if you go for two standards the odds are you will lose both) by which authors rights can be represented, so that the encoding can get international recognition, and, perhaps, go on to become something that law can be used to dignify and recognize.&amp;nbsp; That would be valuable to the IT industry because it would set markers for how to start looking at the rules to apply to web content.&amp;nbsp; And you never know – DRM integration might just be starting.</description><category>Copy Control</category><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2009/08/10/drmnews.aspx#Comments</comments><guid isPermaLink="false">724398d7-60e5-4b79-8617-dcaca56731a9</guid><pubDate>Mon, 10 Aug 2009 20:11:00 GMT</pubDate></item><item><title>Arguments for and against DRM</title><link>http://drm-blog.locklizard.com/2009/04/03/arguments-for-and-against-drm.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;br&gt;The US Federal Trade Commission recently held a ‘town hall’ meeting in order to listen to the arguments being put for and against DRM.&lt;br&gt;&lt;br&gt;Naturally, the great and the good from all [California?] camps were represented and much was said about the music, film and computer games industries, and how DRM was evil and had failed and therefore should never ever be used, and, in fact, you should never try to protect any information (my own summary).&lt;br&gt;&lt;br&gt;Gamers and music players said, “DRM only harms lawful owners and does nothing to prevent dedicated hackers, so there is no purpose in having it.” &amp;nbsp;&lt;br&gt;&lt;br&gt;Well, I guess you might say that having speeding or DUI laws has no effect on criminals (actually, no amount of law has any effect on criminals if you think about it) so we should not have laws.&amp;nbsp; Maybe bank fraud is OK as well?&lt;br&gt;&lt;br&gt;The nub of the argument goes that if I try it and like it then I might think about buying it.&amp;nbsp; But I have a full copy already, so there’s not actually any real pressure on me to do anything!&amp;nbsp; This is about the same as having access to every book in the world for free and then trying to make a case for having to buy one of them.&lt;br&gt;&lt;br&gt;Freedom in artistic and literary expression comes from the ability to profit from it, not be condemned to starve for lack of income.&amp;nbsp; Great pamphleteers such as Thomas Paine didn’t give away their work – far from it.&amp;nbsp; He sold it.&amp;nbsp; He wrote the three top-selling literary works of the eighteenth century, which inspired the American Revolution, issued a historic battle cry for individual rights and challenged the corrupt power of government churches.&amp;nbsp; And the income helped him continue his work.&amp;nbsp; Perhaps the modern age would prefer he had never succeeded?&lt;br&gt;&lt;br&gt;Aha! cry the modern Internet copiers.&amp;nbsp; But talent is what sells, not scarcity.&lt;br&gt;&lt;br&gt;Well, if you are a music group and you get your real money out of gigs then &lt;br&gt;I can see where you are coming from.&amp;nbsp; But if you are a writer, then exactly what gigs do you present at?&amp;nbsp; And if you do electronic training courses precisely because you can’t be at all the gigs, then are you supposed to suffer because you have a different economic model?&lt;br&gt;&lt;br&gt;The only economic model you ever have to consider is how sales get made and invoices get paid.&amp;nbsp; So if a folk band find that giving away tracks is good PR for getting ‘bums on seats’ at gigs then that’s fine.&amp;nbsp; But don’t go claiming that it’s the only possible and valid economic model. &amp;nbsp;&lt;br&gt;&lt;br&gt;DRM is here to stay where the economic model dictates that scarcity is the most effective route to market.&amp;nbsp; Who would spend a lot of money for a financial analysis of a market if they can get it for nothing, or pay for a training course if they can get it for free.&amp;nbsp; The fact of the matter is that people don’t pay for what they get for free.&amp;nbsp; There is no economic model here. &amp;nbsp;&lt;br&gt;&lt;br&gt;Even the people who first brought in Copyright law said that they hated the idea of it, but if you denied the author economic benefit from the use of their intellect (as opposed to their hands) then there was no incentive to create works.&amp;nbsp; And if you left it to ‘market forces’ (the rich, companies, governments) then you would usher in the most deadly of futures for the creation and dissemination of knowledge.&lt;br&gt;&lt;br&gt;So forget the posturing of the music copying community.&amp;nbsp; They are busy re-inventing music concerts (gigs) as the way bands made their livings before records really got going.&amp;nbsp; Maybe they want to reinvent the public lecture tours when successful authors made a part of their living (now a circuit for retired politicians).&amp;nbsp; Check out your own economic model, and if you need scarcity to protect your intellectual capital, then you need DRM!</description><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2009/04/03/arguments-for-and-against-drm.aspx#Comments</comments><guid isPermaLink="false">314b6491-e773-4637-bf7b-dbeb71bfe843</guid><pubDate>Fri, 03 Apr 2009 13:49:00 GMT</pubDate></item><item><title>Anti-DRM fun and fallacy</title><link>http://drm-blog.locklizard.com/2008/12/11/antidrm-fun-and-fallacy.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;br&gt;Reading through many articles and blogs provides curious glimpses into the thinking processes of authors (or perhaps more accurately academic project writers?).&lt;br&gt;&lt;br&gt;A recent observation that interested me was a statement that, “I don’t see why I should have to pay to read a whole book.&amp;nbsp; All I want is a very small portion of the text, and I don’t see why I should have to pay for that.”&lt;br&gt;&lt;br&gt;Having just had dinner, I wondered how my butcher/supermarket would feel if I said that I didn’t want the whole cow, just the fillet of beef, and since that was such a small piece I didn’t see why I should pay to have it either. &amp;nbsp;&lt;br&gt;&lt;br&gt;OK, maybe that’s not such a good example.&lt;br&gt;&lt;br&gt;So let’s get to the point.&amp;nbsp; How would you know, without reading a significant portion of the book, which paragraph was the right one to quote from and why?&amp;nbsp; And why is it you think there should be a right to grab a key piece of the hard work of someone else for nothing in order to benefit yourself, for nothing?&lt;br&gt;&lt;br&gt;Let’s expand on this.&amp;nbsp; The only way you can possibly know the value of one paragraph as against another in an author’s work is to have read it.&amp;nbsp; Take the following abstraction from an article by Joseph Priestly:&lt;br&gt;&lt;br&gt;“It is no doubt time, and of course opportunity of examination and discussion, that gives stability to any principles. But this new theory has not only kept its ground, but has been constantly and uniformly advancing in reputation, more than ten years, which, as the attention of so many persons, the best judges of everything relating to the subject has been unremittingly given to it, is no inconsiderable period. Every year of the last twenty or thirty has been of more importance to science, and especially to chemistry, than any ten in the preceding century. So firmly established has this new theory been considered, that a new nomenclature, entirely founded upon it, has been invented, and is now almost in universal use; so that, whether adopt the new system or not, we are under the necessity of learning the new language, if we would understand some of the most valuable of modern publications.”&lt;br&gt;&lt;br&gt;Now this is jolly good stuff, and with very little effort you could use this paragraph to support almost any scientific claim that you might feel like making.&amp;nbsp; It might dampen the ardour to understand that Priestly was arguing about Phlogiston, in 1796.&amp;nbsp; To know whether he was for or against, you would have to read a great deal more of the text.&amp;nbsp; And that is the point our modern author pointedly ignores.&lt;br&gt;&lt;br&gt;The second point is to wonder why people think anything in a digital format is a ‘free lunch.’&amp;nbsp; Just because something is in digital form does not mean it is being given away – just try convincing Microsoft to give away Windows Vista and see where that gets you!&amp;nbsp; Sure modern authors and publishers are moving to using digital form for publishing.&amp;nbsp; But that does not equate to them giving everything away for free.&amp;nbsp; Publishers pay people to write, they pay to create market interest, awareness, they syndicate work with other publishers, and so on.&amp;nbsp; That all costs money, and, especially in this modern economic climate, people expect to be paid for what they do.&amp;nbsp; As any student of entropy will tell you, “There are no free lunches.”&lt;br&gt;&lt;br&gt;So maybe our scholars should think more carefully?&amp;nbsp; If you want to go out and do the work needed to be able to write the paragraph in your own name, that’s fine.&amp;nbsp; But don’t claim that in advance you know exactly which paragraph of a work is exactly correct for you.&amp;nbsp; That’s obviously not true unless you have already read the work, and one might wonder how that could be without having purchased it?&amp;nbsp; And please don’t claim that you shouldn’t have to pay for just choosing a very small part of the work.&amp;nbsp; Maybe pearls are free in WalMart this week, but likely not.</description><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2008/12/11/antidrm-fun-and-fallacy.aspx#Comments</comments><guid isPermaLink="false">deff3018-0f72-457c-91c1-fee8582672b1</guid><pubDate>Thu, 11 Dec 2008 22:53:00 GMT</pubDate></item><item><title>Cryptography isn’t DRM</title><link>http://drm-blog.locklizard.com/2008/10/21/cryptography-isnt-drm.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&amp;nbsp;&lt;br&gt;One of the commonest errors you see made in articles about information security is to equate the secrecy obtained by cryptography with the licensing control applied by DRM.&lt;br&gt;&lt;br&gt;You will see plenty of ‘experts’ state that you can use cryptography to ensure the security of your information, when what they actually mean is that a recipient can check that what they receive has not been altered or falsified, and that unauthorized people cannot have read it first.&lt;br&gt;&lt;br&gt;Now that isn’t DRM.&amp;nbsp; When you, as the authorized recipient of encrypted information decrypt it, you can do precisely what you like with it.&amp;nbsp; Copy it, send it to your friends (or even your enemies), alter it, anything you feel like.&lt;br&gt;&lt;br&gt;But DRM is about very much more.&lt;br&gt;&lt;br&gt;DRM has to deal with what you are allowed to do with information that you are authorized to receive.&amp;nbsp; Generally you are not allowed to pass information on to others.&amp;nbsp; (That is considered implicit in military systems, but is a physical or manual control, and you can’t apply that to electronic information.&amp;nbsp; What the military do is make sure it can’t leave the system it is stored on, which is not an option if you’re selling eBooks.)&lt;br&gt;&lt;br&gt;As importantly, you may not be able to make printed copies, or that might be allowed but a Copyright mark is prominently displayed when you do that.&amp;nbsp; You might only be able to use the electronic information for a limited number of times (pay per view) or for a limited time period (documents for evaluation or for bidding for contracts).&lt;br&gt;&lt;br&gt;Only DRM controls have the ability to ensure that the controls, or license terms that go along with the information actually get enforced.&lt;br&gt;&lt;br&gt;Of course DRM also makes use of encryption technology both to be sure that nothing can be used unless the recipient is authorized, but that’s only the start of the story.&lt;br&gt;&lt;br&gt;So next time someone tells you that all your security problems can be solved by encryption, just let them know better.</description><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2008/10/21/cryptography-isnt-drm.aspx#Comments</comments><guid isPermaLink="false">7af2d675-5796-444e-abcc-5f199c283aee</guid><pubDate>Tue, 21 Oct 2008 12:46:00 GMT</pubDate></item><item><title>It’s a funny old world</title><link>http://drm-blog.locklizard.com/2008/09/24/its-a-funny-old-world.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&amp;nbsp;&lt;br&gt;Although not the only person to use the quotation, Margaret Thatcher famously said those words to describe losing the election to be the leader of the Conservative Party and therefore the post of Prime Minister and First Lord of the Treasury.&lt;br&gt;&lt;br&gt;And when you look out at the IT security industry you risk having the same feeling that she did.&lt;br&gt;&lt;br&gt;Although not very surprising, people have gone out and solved problems that were easy, leaving the difficult ones to specialists whilst using marketing muscle to ‘persuade’ customers that their solutions fit the problems.&lt;br&gt;&lt;br&gt;A good case in point would be the global adoption of the secure connection technology SSL (Secure Sockets Layer).&amp;nbsp; Pedalled for many years as the certainty of a secure connection, it has been nothing of the kind.&amp;nbsp; Yes, it very securely connects together two locations that do not know each other.&amp;nbsp; And that’s the problem.&amp;nbsp; You only think you are connected to the bank, and they only think they are connected to you.&lt;br&gt;&lt;br&gt;It’s been a bit the same with DRM.&lt;br&gt;&lt;br&gt;At one level it has been stunningly bad.&amp;nbsp; The music and film copying brigades got it into their heads that just because in the cassette tape days you could tape anything off the radio or the record deck (mind you the quality was absolutely dreadful) and make copies (which were even worse – but you could do it!) then you had the divine right to copy anything. After all, let’s not worry about copyright.&lt;br&gt;&lt;br&gt;And at the other end of the equation, DRM system providers did themselves no favours either.&amp;nbsp; They tried to implement DRM that prevented people from making copies of their own works, or DRM that just enabled suppliers to charge different amounts for exactly the same product in different places around the world.&amp;nbsp; Finally, DRM providers made the serious mistake of trying to embed themselves into operating systems, and behaving like viruses or hackers.&lt;br&gt;&lt;br&gt;There has also been the dichotomy about use of DRM protected products – to print or not to print?&amp;nbsp; I have discussed this with several eBook publishers and they have mixed views.&amp;nbsp; At one level we all agree that the eBook has immense power and potential over the paper book – quick indexes; searching; linking both internal and external: all things a paper book simply can’t deliver.&amp;nbsp; At another level, people just don’t really read eBooks the same way they do paper. &amp;nbsp;&lt;br&gt;&lt;br&gt;When did you last take your laptop to the lavatory so you could read something in peace?&lt;br&gt;&lt;br&gt;And maybe that’s what’s lacking in the eBook development thinking?&amp;nbsp; An eBook version of a training course is not quite the same proposition as the eBook version of a fashion magazine.&amp;nbsp; And the eBook version of your broker’s guide to share trading is not the same as the latest best selling novel.&lt;br&gt;&lt;br&gt;There are similarities, certainly, but a good guide would be found by looking at the ‘intended use scenario.’&amp;nbsp;&amp;nbsp; Is the product intended primarily for social, domestic and leisure, or is it primarily for business?&lt;br&gt;&lt;br&gt;Current document DRM systems are focused on business applications use (which includes handling formal business documents that may be used both at work and at home – the home element does not dominate the primary point that the business use dominates the rights and rights management).&amp;nbsp; Business DRM is reasonably well scoped.&lt;br&gt;&lt;br&gt;But many suppliers are leaping onto the DRM bandwagon trying to apply it to scenarios where the use (and the formality of use) is very different.&lt;br&gt;&lt;br&gt;If you argued that when you buy a novel, when you have read it then you can give it, in its entirety (not a copy) to someone else that might be an acceptable use.&amp;nbsp; But a business training course was never provided for that purpose.&amp;nbsp; It was provided for a specific and limited use, often for a very restricted period of time.&amp;nbsp; And the same concepts do not apply.&lt;br&gt;&lt;br&gt;And some business documents are not being distributed for copying at all.&amp;nbsp; Some are business secrets, some are documents disclosed because they have to be, but only to identified individuals, and so on.&amp;nbsp; There is absolutely every reason for the distributor to want to be sure that the document is not copied, or forwarded to anyone, or maybe even printed. &amp;nbsp;&lt;br&gt;&lt;br&gt;But the DRM mechanisms are just the same.&amp;nbsp; The secret is in who you apply them to and how you apply them.&lt;br&gt;&lt;br&gt;Of course you will upset people by introducing DRM.&amp;nbsp; All the people who think they should be able to copy and distribute your information for starters!&amp;nbsp; And all the people who hate DRM just on principle (but please&amp;nbsp; see the first group again also).&lt;br&gt;&lt;br&gt;But maybe those are the very people you wanted to control in the first place?&lt;br&gt;&lt;br&gt;It’s a funny old world, isn’t it?</description><category>Copy Control</category><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2008/09/24/its-a-funny-old-world.aspx#Comments</comments><guid isPermaLink="false">ce0c16d9-2bec-4aef-805f-5b36dc0780e1</guid><pubDate>Wed, 24 Sep 2008 16:11:00 GMT</pubDate></item><item><title>DRM is a barrier to eBook adoption say students</title><link>http://drm-blog.locklizard.com/2008/09/02/drm-is-a-barrier-to-ebook-adoption-say-students.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;p&gt;&amp;nbsp;&lt;br&gt;Being interested in opinions on the rights, wrongs, virtues and demerits perceived by many communities, I found the following article &lt;a href="http://arstechnica.com/news.ars/post/20080828-study-students-need-open-source-e-textbooks.html"&gt;http://arstechnica.com/news.ars/post/20080828-study-students-need-open-source-e-textbooks.html&lt;/a&gt; to be of some interest.&lt;/p&gt;
&lt;p&gt;If you read the article, you start from an offered conclusion that student text books ought to be available under open source type Creative Commons licenses.&amp;nbsp; But as you dig further down, you find out that students are complaining about the cost of text books.&lt;/p&gt;
&lt;p&gt;The arguments seem to be:&lt;/p&gt;
&lt;p&gt;-&amp;nbsp;text books are too expensive anyway;&lt;br&gt;-&amp;nbsp;you can’t print out much at a go;&lt;br&gt;-&amp;nbsp;they have a short life;&lt;br&gt;-&amp;nbsp;they cost as much as the print editions.&lt;/p&gt;
&lt;p&gt;So the complaints seem to be much more like those being used on film and music companies than they are about DRM itself.&lt;/p&gt;
&lt;p&gt;Now I would have to agree that it seems very strange that it costs me the same to buy a book that I have for ever, or an electronic book which I only get to use for 6 months.&amp;nbsp; At the same time the electronic book supplier might be offering me something rather different with the electronic book – things I just can’t do with the paper edition.&amp;nbsp; Searching (it saves me having to read the whole thing although maybe I actually learn less?) and hyperlinking to other reference work, articles, forums and so on are things I just don’t get on paper, or images I can work with.&lt;/p&gt;
&lt;p&gt;Why should I get upset about not being able to print the ebook?&amp;nbsp; If I want a print edition then surely that is what I should have purchased to begin with.&amp;nbsp; If I want to print information then I should expect to pay a premium (normally called a royalty) for the right to make copies of the book.&amp;nbsp; That’s totally normal.&amp;nbsp; And just the same as in the software world.&amp;nbsp; It isn’t realistic to think I can buy some software for one machine and then put it on as many machines as I suddenly decide – hey man, that’s piracy.&lt;/p&gt;
&lt;p&gt;So I am not totally convinced by the student’s arguments.&amp;nbsp; Yes, we all moan about the price of things, from cars to condos and from tuna to text books.&amp;nbsp; And that’s normal, good and healthy.&amp;nbsp; And in the bargaining business you always start from an extreme position if you think you can get away with it, so, of course, a study that asks the students the right questions will get whatever result they feel like.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;I’m equally certain that if you asked the College Professors who specified the books for the term and the course (and maybe even wrote them?) they would not be wanting to give away their work, even though they were paid to gain their expertise.&amp;nbsp; And if you asked the publishers, they will have a view all of their own (but don’t ask me what it is because I haven’t asked them).&lt;/p&gt;
&lt;p&gt;So bottom line, it’s popular to attack DRM because, hey, it stops me from doing my own thing.&amp;nbsp; Everyone seems to think that buying something grants you the right to use what you bought anyhow you want.&amp;nbsp; Well, that isn’t the case with automobiles, guns, software, drugs, or a whole load of other things.&amp;nbsp; And so far there’s no proof ebooks are any different.&lt;/p&gt;
&lt;p&gt;As a closing thought, the other day I had to spend 350 bucks to buy a paper book that is a definitive reference on company valuation methods.&amp;nbsp; It is out of print, and there are only two companies who can supply it from stock.&amp;nbsp; There are no electronic versions, and it is not in the library.&amp;nbsp; Next?&amp;nbsp; I would have liked an ebook version with search and hyperlinks but it isn’t available.&amp;nbsp; And I bet if it was it would cost a damn site more than the paper edition – and I would have paid it!&lt;/p&gt;</description><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2008/09/02/drm-is-a-barrier-to-ebook-adoption-say-students.aspx#Comments</comments><guid isPermaLink="false">369fa7a4-63a1-44a7-9102-cf780a6517e1</guid><pubDate>Tue, 02 Sep 2008 21:57:00 GMT</pubDate></item><item><title>Is there such a thing as personal data anymore</title><link>http://drm-blog.locklizard.com/2008/08/26/is-there-such-a-thing-as-personal-data-anymore.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;P&gt;&amp;nbsp;&lt;BR&gt;The other day we see reported in the press (in this case SC Magazine &lt;A href="http://haymarket.puresendmail.com/hmiclick/4t6676cRbkg92yRmd0R8l9a2cRng1R4tbura/2/www.scmagazineuk.com/UK-Government-takes-rap-for-latest-data-blunder/article/115785/"&gt;http://haymarket.puresendmail.com/hmiclick/4t6676cRbkg92yRmd0R8l9a2cRng1R4tbura/2/www.scmagazineuk.com/UK-Government-takes-rap-for-latest-data-blunder/article/115785/&lt;/A&gt;) that yet again personal data held by the UK government has leaked its way out into the public domain.&lt;/P&gt;
&lt;P&gt;In the past we have managed to hit tax claimants, car drivers, and student doctors.&amp;nbsp; But just as we thought things were getting better they and their partners managed to hit a most unlikely and vulnerable sector of society – criminals.&lt;/P&gt;
&lt;P&gt;It might well be jingoism to say, “Well, why should they get protection – so who cares.”&amp;nbsp; But as we know, it turns out that there are wrong convictions, and not every prisoner is a paedophile, murderer, rapist or thief.&amp;nbsp; Some are just people who couldn’t pay the mortgage.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;And would we want people to be readily exposed to blackmail because of their pasts?&amp;nbsp;&amp;nbsp; Making it easier for other criminals to recruit them when they have served the punishment society exacted?&amp;nbsp; Probably not a good idea.&lt;/P&gt;
&lt;P&gt;What it also does is reinforce genuine and growing concern that information professionals and management simply do not have any grip on protecting the privacy of information.&amp;nbsp; They may (and the Press may say they may not) have some grasp about access controls.&amp;nbsp; But there seems to be no clue about how to stop the leaking and spreading of information that has been entrusted to them to manage.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;And the biggest collectors and processors of really high value and fairly accurate personal data are - governments, whether national or local.&lt;/P&gt;
&lt;P&gt;So the nightmare scenario is that governments give themselves the right to collect more and more personal information about people (not just their citizens), and consolidate it under the guise of (pick one or more for your own country as required) identity control, taxation, prevention of terrorism, then they are at the same time creating the opportunity for even bigger targets for hackers, and ever bigger losses of personal data.&lt;/P&gt;
&lt;P&gt;But whilst there seems to be no effective way, if news stories are correct, of persuading government officials and the companies working for them to raise standards and take personal responsibility for losses, then you can forget having personal data.&lt;/P&gt;</description><category>Identity Theft</category><comments>http://drm-blog.locklizard.com/2008/08/26/is-there-such-a-thing-as-personal-data-anymore.aspx#Comments</comments><guid isPermaLink="false">b905ef52-a340-44e9-a954-26fb4f75aed9</guid><pubDate>Tue, 26 Aug 2008 17:58:00 GMT</pubDate></item><item><title>Customers demand DRM controls – it’s true</title><link>http://drm-blog.locklizard.com/2008/08/19/customers-demand-drm-controls--its-true.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;P&gt;&amp;nbsp;&lt;BR&gt;Now even consultants would normally be hard pressed to find an argument that customers want DRM controls protecting information.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;If you believe the modern anti-DRM blog sites, DRM is akin to the works of the (please pick a suitable negative deity suited to your particular persuasion).&amp;nbsp; Imposing controls on honest citizens is an affront to their dignity (let’s just not worry about speed traps because we don’t believe you can be trusted to obey the law).&amp;nbsp; &lt;/P&gt;
&lt;P&gt;But, and this is serious, there are sectors of the community that want the protection of DRM controls.&lt;/P&gt;
&lt;P&gt;One important group is the individuals or organizations that are buying training courses so that they can train themselves or their people so they can carry out licensed services and demonstrate that they have proven capabilities and expertise.&amp;nbsp; They are investing serious money in the enhancement and development of their staff and their businesses.&amp;nbsp; The last thing they want to see is competitors being able to undercut them because they haven’t paid the proper fees.&amp;nbsp; That is unfair competition from the unethical and unscrupulous.&amp;nbsp; Why should the honest and law abiding suffer at the hands of the dishonest?&amp;nbsp; Or is that the purpose of hacking?&lt;/P&gt;
&lt;P&gt;Another group who demand DRM controls are those receiving confidential information.&amp;nbsp; Because when confidential information leaks out, the finger pointing starts, and absent DRM controls that can act to identify the actual source of a leak, then the selection of a scapegoat can commence.&amp;nbsp; So the presence of DRM controls helps protect the recipients of information, because it can help prove they were not the source of any leak or compromize.&amp;nbsp; And when it comes to keeping your reputation as well as your job, DRM can prove invaluable.&lt;/P&gt;
&lt;P&gt;And a third group who want DRM controls are those who need to receive information but the owner of the information wants some actual certainty the information will be looked after properly.&amp;nbsp; In this group are the people who have to send out personal data that has to be human accessible.&amp;nbsp; This is the fastest growing group, because US regulation is now getting much more stern about encrypting personal data in computers.&amp;nbsp; It is now specifying that there has to be some management and control, and is going for tougher penalties to incentivise compliance.&amp;nbsp; Naturally, people sending out DRM controlled information are better placed to easily prove they did a good job.&lt;/P&gt;
&lt;P&gt;So before you show me another web site about how bad DRM is and how it is that nothing should be DRM protected, just think for a moment about the fact that it is essential in some industries, and, that without it, your personal data can still be handed around without anyone being able to stop it.&lt;/P&gt;</description><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2008/08/19/customers-demand-drm-controls--its-true.aspx#Comments</comments><guid isPermaLink="false">67d86dc2-7291-428d-8de7-1e14720b0509</guid><pubDate>Tue, 19 Aug 2008 21:11:00 GMT</pubDate></item><item><title>When in doubt – shoot the messenger!</title><link>http://drm-blog.locklizard.com/2008/08/06/when-in-doubt--shoot-the-messenger.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;P&gt;&amp;nbsp;&lt;BR&gt;Sophocles, in his work Antigone, said, "No one loves the messenger who brings bad news."&lt;/P&gt;
&lt;P&gt;This week provided more than it’s share of light entertainment with blogs of disinformation.&amp;nbsp; Top of the list goes to the people who figure that Lizard Safeguard ought to work on every operating system known to man (or is that persons?).&amp;nbsp; It says clearly on the box, works with PC and Mac – and nothing else.&amp;nbsp; It’s rather like buying a book that’s published in English and then complaining because it isn’t in Danish (and likely never will be).&amp;nbsp; It doesn’t run on an IBM mainframe either, btw.&lt;/P&gt;
&lt;P&gt;And second error prize has to go to those who say it doesn’t work on the Mac.&amp;nbsp; It does.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;As a general rule, two out of three is pretty bad, but what about number 3?&lt;/P&gt;
&lt;P&gt;“The system is unusable because it insists on always connecting to the Internet before you can use anything.”&lt;/P&gt;
&lt;P&gt;It is true that you have to connect to the Internet the first time you open a document – it has to check that you are the bona fide purchaser, and it has to get the information needed to decrypt the document.&amp;nbsp; After that, it totally depends on what the owner of the document has chosen to enforce.&amp;nbsp; And nothing to do with LockLizard, because they can only enforce what the publisher defines as the rules.&amp;nbsp; You don’t go round blaming Microsoft because your system administrator decided the frequency you update your logon password – so why blame LockLizard about the way the system administrator has configured their controls?&lt;/P&gt;
&lt;P&gt;But, of course, the modern attitude is to use any possible reason to try and prevent people from implementing DRM controls, even though all the available evidence proves rampant piracy and theft of digitized information.&amp;nbsp; So use every possible opportunity, no matter how ridiculous, to claim rights that don’t exist.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;And don’t forget to blame the messenger!&amp;nbsp; The DRM provider creates a toolkit that the publisher implements in whatever way they see fit.&amp;nbsp; But of course the DRM provider is the evil guy because they are stupid enough to implement what the publisher said.&amp;nbsp; It’s Hobson’s choice - damned if you do and damned if you don’t.&amp;nbsp; If you are the DRM provider and you don’t enforce what your customer, the publisher, says, then they will soon be after you, and probably with good cause.&amp;nbsp; But it seems that if you implement what the publishers want, then the people getting the information want to blame you for doing a good job!&lt;/P&gt;
&lt;P&gt;Of course the attitudes are so different if what is being published is personal data – oh you should have taken the strongest possible means to protect it – what do you mean you didn’t check who was accessing the data.&amp;nbsp; And so on.&amp;nbsp; Just because it’s not your personal data, it doesn’t mean you have the right to do what you like with it – or does it?&lt;/P&gt;</description><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2008/08/06/when-in-doubt--shoot-the-messenger.aspx#Comments</comments><guid isPermaLink="false">ef7e7d1c-50b4-48f2-9118-dfffc1eac133</guid><pubDate>Wed, 06 Aug 2008 21:59:00 GMT</pubDate></item><item><title>Web 2.0 - What’s wrong with using what you know?</title><link>http://drm-blog.locklizard.com/2008/08/06/web-20--whats-wrong-with-using-what-you-know.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;P&gt;&amp;nbsp;&lt;BR&gt;It has been interesting reading the blogs, analysts and industrial pundits who have decided that Web 2.0 is the best thing since ….. well, maybe Web 1.x? and that every being on the planet should endorse its concepts – sharing information, whether personal or corporate in places whether public or private.&lt;/P&gt;
&lt;P&gt;Team playing, that’s the thing.&amp;nbsp; As long as we all work together the results will be bigger, better, quicker, cheaper, more FUN.&lt;BR&gt;&amp;nbsp;&lt;BR&gt;To try and avoid the risk of being a party pooper I put out a few inquiries (name the usual search engines) about Web 2.0 security.&amp;nbsp; After all, before I go revealing whatever it is that I decide I’m going to reveal, I’d rather like a few ideas about who might get their sticky little hands on whatever I am posting.&amp;nbsp; Well, Google muscled in with (around?) 160,000,000 entries, Yahoo hoisted 316,000,000 and MSN claimed 72,800,000.&amp;nbsp; I admit it.&amp;nbsp; I didn’t read them all, I just didn’t have the time.&lt;/P&gt;
&lt;P&gt;But the summaries on the first few pages, regardless of who I consulted, was just the same.&amp;nbsp; No security, and no plan for security.&lt;/P&gt;
&lt;P&gt;Now this is kind of worrying.&lt;/P&gt;
&lt;P&gt;We are all supposed to bring in whatever we want and then share it (knowingly or otherwise) with a group of people we may (or may actually not) know, and that’s good.&lt;/P&gt;
&lt;P&gt;Somehow I figure there’s going to be a ton of material that my CEO (wife, partner, children, friends and acquaintances – the list goes on) does not want me to give to other people.&amp;nbsp; Yes, I know a couple of those photos after the hot tub might be a bit insensitive, but, hell, it happened didn’t it?&amp;nbsp; And maybe I shouldn’t have published that extract about how we always get the best procurement price – but it is what we do, isn’t it?&lt;/P&gt;
&lt;P&gt;You see, that’s the problem.&amp;nbsp; We all coexist with and in many groups, all at the same time.&amp;nbsp; But those groups are not connected by common views, objectives, rules or members.&amp;nbsp; And it’s not clear if the members of each group even share common ideals.&amp;nbsp; All Americans support America, of course.&amp;nbsp; Except those who crash jets, or oppose foreign wars, or ….&amp;nbsp;&amp;nbsp; &lt;/P&gt;
&lt;P&gt;So even when you think you know who the players are you don’t know what they will do with the information you give them, or what information you may have given them access to without your even knowing.&lt;/P&gt;
&lt;P&gt;The problem is that Web 2.0 does not have DRM controls that help you decide the limits that can be put on the use of your information.&amp;nbsp; It’s certainly the information super highway – but it’s all about sharing and none of it’s about control.&amp;nbsp; Caveat orator – let the speaker beware – should be our watchword.&lt;/P&gt;
&lt;P&gt;But no doubt, like the IT fashions and fancies that have gone before, it will require a lot of fingers to be burned before any security, let alone DRM gets added.&amp;nbsp; So in the meantime, if you don’t want your information being shared about, get some DRM protecting what you have got, whilst you still have it.&lt;/P&gt;</description><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2008/08/06/web-20--whats-wrong-with-using-what-you-know.aspx#Comments</comments><guid isPermaLink="false">4215e0e2-40c5-4355-812b-defa70ec75d7</guid><pubDate>Wed, 06 Aug 2008 11:29:00 GMT</pubDate></item><item><title>Does the death of music DRM mean the death of DRM itself?</title><link>http://drm-blog.locklizard.com/2008/07/31/does-the-death-of-music-drm-mean-the-death-of-drm-itself.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;P&gt;&amp;nbsp;&lt;BR&gt;I am sure you will have read the article in efflux.com &lt;A href="http://www.efluxmedia.com/news_Yahoo_Music_Dead_Another_Reason_To_Never_Buy_DRM_Protected_Tracks_21005.html"&gt;http://www.efluxmedia.com/news_Yahoo_Music_Dead_Another_Reason_To_Never_Buy_DRM_Protected_Tracks_21005.html&lt;/A&gt; warning of the death of the Microsoft music DRM by August 31, and Google by September 30 (2008).&lt;/P&gt;
&lt;P&gt;Their conclusion?&amp;nbsp; “Digital rights management technologies are a failure commercially and technically. There are too many standards which are not interoperable, they restrict the customer's freedom to high degrees and they are an everyday nuisance to work with.”&lt;/P&gt;
&lt;P&gt;Well wash my mouth out with soap (no I don’t mean SOAP which is another load of XML).&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Let’s look at that rather broad conclusion.&lt;/P&gt;
&lt;P&gt;There are too many standards?&amp;nbsp; Excuse me?&amp;nbsp; I looked up DRM standards in ISO (International Standards Organization, the people who figure out what is the standard for electric cable so you don’t blow your hands off touching the stuff, the rails that trains run on so that they stay running on them, and serious computer standards – you know, stuff that matters), and drew a blank.&amp;nbsp; Now if someone had said manufacturer’s standards, I could buy into the argument.&lt;/P&gt;
&lt;P&gt;An everyday nuisance to work with?&amp;nbsp; Well, you might get paid to listen to music tracks.&amp;nbsp; Or maybe they just mean you can’t readily copy tracks and give them away?&amp;nbsp; (I bet you can buy a license to do that, but its costly.)&lt;/P&gt;
&lt;P&gt;But what most people have yet to understand is that the DRM industry is seriously new, and that there is precisely no desire by major players (tape, CD, DVD, PDF and so on) to provide interoperable standards, when we haven’t even agreed what standards are being looked for, and why, or how they should be implemented.&lt;/P&gt;
&lt;P&gt;The current market is in what the economists call the ‘prime mover’ phase.&amp;nbsp; Literally, that means that the first into the market can do what they like, set any standards they feel like, and charge any price that suits them!&amp;nbsp; The market has been there since the late 1990s.&amp;nbsp; Not quite recently?&amp;nbsp; And mainly because it has not suited any major player to see International Standards emerge, it has not changed.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Actually, rather than worry about the latest squabble about whose industrial standard should be dominant, we should be worrying about what sorts of DRM standards are going to emerge, and how to be able to influence them.&amp;nbsp; They are rather like taxation – you can never stop a government from taxing you.&amp;nbsp; That’s how they stay alive, by taking your money (and if the statistics are correct they get more money out of individuals than they get out of corporations, which ought to be rather worrying).&lt;/P&gt;
&lt;P&gt;Despite what the pundits say, DRM is not going to go away.&amp;nbsp; The people who create and sell intellectual property (IPR) have to make their livings from doing that.&amp;nbsp; They are not going to give away their livelihoods any more than you or the pirates are going to.&amp;nbsp; The people you really need to fear are those who do not need a day job to pay their way, or where the day job is so badly supervised that they can afford to waste their employer’s time whilst they pursue illegal interests.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;And just as the Internet has moved from being a free information source (1995-2002) it is now increasingly a paid information source and what was previously free is no longer available unless you pay for it.&amp;nbsp; If you examine information sources now they consist of sources that have been paid for as a matter of public interest (the Gutenberg series that have made much of the Classical repertoire (Shakespeare, Plato and many other Classical greats such as Chaucer) accessible to any and all.&amp;nbsp; We applaud these measures.&amp;nbsp; Even if modern schooling fails to inculcate any appreciation for works other than Homer Simpson, we agree that works out of copyright should be available to all – but MUST be assured as being the actual words, and not some Bowdlerism (Thomas Bowdler (July 11, 1754 – February 24, 1825) was an English physician who published an expurgated edition of William Shakespeare's work that he considered to be more appropriate for women and children than the original, and, according to some sources, actually made it more accessible!).&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Apparently political correctness is not a new disease?&lt;/P&gt;
&lt;P&gt;Seekers after truth deserve some measured verity.&amp;nbsp; But you can’t deliver that without DRM.&amp;nbsp; Because DRM is, as the Germans say, “A sword with no handles.”&amp;nbsp; It does not merely control what a recipient can do with the information they receive, it verifies that the information they have gained possession of is truly coming from the claimed source – the publisher.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;There is nothing negative in this for the publisher.&amp;nbsp; Actually, for the publisher it is a comfort.&amp;nbsp; Because otherwise how else can a publisher ‘prove’ what it is they actually published, given the modern world where information theft and the misuse of information are commonplace?&amp;nbsp; The fact of DRM tools provides an abiding proof that they truly are the source of specific information, and that can help publishers obtain prosecution of unreasonable and irresponsible pirates on the one hand, and avoid prosecution for things they never did publish, on the other.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;So think carefully before trying to consign DRM to the dustbin of history.&amp;nbsp; It may be following closely behind such must have’s as death and taxes.&lt;/P&gt;</description><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2008/07/31/does-the-death-of-music-drm-mean-the-death-of-drm-itself.aspx#Comments</comments><guid isPermaLink="false">d1175fd7-bb94-4d25-9fa7-3923a60ebea7</guid><pubDate>Thu, 31 Jul 2008 19:00:00 GMT</pubDate></item><item><title>Does organized piracy contribute to better markets?</title><link>http://drm-blog.locklizard.com/2008/07/28/does-organized-piracy-contribute-to-better-markets.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;P&gt;&amp;nbsp;&lt;BR&gt;I read, from the July pages of &lt;A href="http://www.starnewsonline.com/"&gt;www.StarNewsOnline.com&lt;/A&gt; that “The Pirate Bay, which is based in Sweden, presents a devilishly fearless challenge to American textbook publishers. It describes itself as an “anticopyright organization” and offers music, movies, television shows and software, as well as e-books like textbooks — not a single item of which, it boasts, has ever been removed at the request of a copyright owner.”&amp;nbsp; Hmm.&amp;nbsp; Sounds like Pirates?&lt;/P&gt;
&lt;P&gt;But how many economic analyses have you read that actually examined the effects of piracy on product markets?&amp;nbsp; Probably very few.&lt;/P&gt;
&lt;P&gt;Big hitters like the music, TV and film people complain about losses in their industries.&amp;nbsp; Designer label clothes and perfume producers complain.&amp;nbsp; Software manufacturers also complain.&lt;/P&gt;
&lt;P&gt;But if you make a careful analysis, piracy always occurs when there are serious market pricing inequalities that are not addressed by regulation.&amp;nbsp; Or to try to be a bit clearer, when you can buy a product in one country for x, and in another country for a half of x, there is a serious price inequality.&amp;nbsp; If no action is taken to correct a price inequality, this creates the vacuum that pirates, being, at heart, just as serious capitalists as any industrialist, will naturally seek to fill.&lt;/P&gt;
&lt;P&gt;This is not some vague modern theory.&amp;nbsp; Rather it is a statement that has stood the test of time.&amp;nbsp; When in the UK in the 1800s, it was decided by government to raise the tax on alcohol and tobacco to be significantly above that of France, somewhere only 14 miles away, pirates were handed a market second only to the government forcing you buy your postal service from them (and they did do that).&amp;nbsp; &lt;/P&gt;
&lt;P&gt;There are many more recent examples.&amp;nbsp; Designer jeans manufacturers and perfume manufacturers won global legal battles that enabled them to enforce per country pricing for their products, and to be able to prevent countries purchasing at lower prices from reselling to other, higher priced countries.&lt;/P&gt;
&lt;P&gt;The same has been true in the information world.&lt;/P&gt;
&lt;P&gt;I cannot understand how it is that the same information can possibly have a different value in a different country.&amp;nbsp; I agree, that, if translation into a different language from the source is necessary, then that might introduce a cost that has to be paid for, but I also assume that the seller will have thought about the effects of price on market before launching their wares, and will have worried about what price to set in order to make a viable return (please see economists for the math behind price/market/demand models, I don’t have the desire to write a book on it).&amp;nbsp; To give you a practical example, the other day I paid over $350 for a book that it was essential I could read right now, was out of print, and only one supplier could deliver a copy next day.&lt;/P&gt;
&lt;P&gt;The bottom line, as they say, is that any DRM controls built by man can be removed by man.&amp;nbsp; It all depends on cost/effort/desire.&amp;nbsp; Risk analysis.&amp;nbsp; DRM controls over things that can be seen or heard can be ‘removed’ using a camera and a microphone.&amp;nbsp; That cannot be prevented.&amp;nbsp; There will be loss of quality, and, if your product has high embedded functionality (ability to search on information, links to other objects, embedded information) there may be critical loss of functionality that renders a copy of little or no value in the market place.&amp;nbsp; You may also be using features such as dynamic watermarking, that significantly reduce the desire of legitimate users to allow pirates access to their materials because they may be personally identified as the source of piracy.&amp;nbsp; Hopefully, in your DRM system, you are using features such as encryption, that can prevent trivial ways of accessing and copying your work(s).&amp;nbsp; &lt;/P&gt;
&lt;P&gt;But do please always remember that to a greater or lesser extent, if the cost and effort are low enough, and the desire is high enough, then copies of the basic information can be made.&amp;nbsp; What can be stopped is stealing embedded functionality that the DRM controls also protect.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;The greatest effector you can face is desire.&amp;nbsp; If your market is students and your strategy is to charge premium price then you can expect a high ‘desire’ to break your controls.&amp;nbsp; If you choose a lower price because you can sell year on year the same product, then you lower desire.&lt;/P&gt;
&lt;P&gt;We sell our products at exactly the same price globally.&amp;nbsp; There are no exceptions.&amp;nbsp; There are no premiums.&amp;nbsp; There are no discounts.&amp;nbsp; At one level it’s a rough deal because poor economies have to pay ‘relatively’ more.&amp;nbsp; But there is a level playing field.&amp;nbsp; There is no market price fixing.&amp;nbsp; We do not demand a different price in Chile from Canada, or in the United States from the United Kingdom.&amp;nbsp; And maybe that’s part of the equation?&amp;nbsp; Part of the equation of persuading people it’s not worth the bother of pirating information is to set prices that are both globally consistent and do not overly increase the desire to find a way to bypass them.&lt;/P&gt;
&lt;P&gt;That’s not part of the choice of a DRM product supplier, although you might prefer to choose one that is realistic about what can be achieved and clear about being a DRM provider and nothing else.&lt;/P&gt;</description><category>Digital Rights Management</category><category>Intellectual Property</category><comments>http://drm-blog.locklizard.com/2008/07/28/does-organized-piracy-contribute-to-better-markets.aspx#Comments</comments><guid isPermaLink="false">1ad4152a-bff9-458b-9b74-13fd4c131eb7</guid><pubDate>Mon, 28 Jul 2008 23:09:00 GMT</pubDate></item><item><title>Getting too casual with information</title><link>http://drm-blog.locklizard.com/2008/07/15/getting-too-casual-with-information.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;P&gt;&amp;nbsp; &lt;BR&gt;As can be the case, we have been rather overtaken by recent events – in my case an office move – actually only about a mile as the (insert the feathered creature of your preference) flies.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Fortunately our office move really did happen over a weekend.&amp;nbsp; And whilst it had precisely zero impact on our customers – everything carried on running seamlessly – that was not entirely the case for us staff.&lt;/P&gt;
&lt;P&gt;Take me (please), for instance.&amp;nbsp; For reasons that are so obvious I am not going to explain them, my shaver cord happened to be on my desk when the removers came.&amp;nbsp; That is the last time I, or anyone else saw it.&amp;nbsp; So the emerging beard can be explained by the fact that I am too tight to buy a new Braun top of the range machine without a fight!&lt;/P&gt;
&lt;P&gt;And what has that got to do with information security?&lt;/P&gt;
&lt;P&gt;Well, during last week the UK government published a whole series of reports (on the same day, so you know they had saved up all the bad news for a moment when they hoped nobody was watching) on how major government departments like the Inland Revenue (HMRC in the UK and IRS in the US) and the Ministry of Defense had managed to lose millions of people’s personal data and that none of it was protected in any way, shape or form.&lt;/P&gt;
&lt;P&gt;The major thrust of the reports was that management did not consider that the personal data they held in trust was their responsibility to protect and therefore they did not see any need to spend any money at all on protecting it.&lt;/P&gt;
&lt;P&gt;A second, and perhaps even more dangerous revelation was that government collected information that it subsequently used for purposes that were not consistent with what it had been collected it for.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;It is, of course, now normal that neither government ministers nor civil service officials will be exposed as charlatans or hypocrites, and that nobody will have their careers ended because they clearly failed to live up to the standards (moral, ethical, documented or expected) that they pretended were in force.&amp;nbsp; Governments and their officials should not pretend surprise when the electorate ignore them – if nobody is accountable then who cares who gets elected?&lt;/P&gt;
&lt;P&gt;Well, with guidance like that from on high, what hope is there for the rest of us?&lt;/P&gt;
&lt;P&gt;Usually we look to governments and big industry to show the way in both corporate and civil behaviour.&amp;nbsp; After all, they make the law, and they enforce that law.&lt;/P&gt;
&lt;P&gt;But right now their governance is, to put it mildly, severely lacking.&amp;nbsp; If, to quote a very famous film, “Frankly, my dear, I don’t give a damn,” then why should we believe them when they talk about Copyright and similar protections?&amp;nbsp; It looks like a load of irrelevance, and anyone wanting information protection will have to go with what they can get.&amp;nbsp; There’s no point in waiting for the prognostications of the governments, or the divinations of standards bodies (international or industry led) because it is totally clear that the leaders are not interested.&lt;/P&gt;
&lt;P&gt;And that brings me back to the power cord.&amp;nbsp; Nobody at the removers is interested in my problem.&amp;nbsp; So I am going to have to sort it out for myself – and the beard itches!&lt;/P&gt;</description><category>Intellectual Property</category><comments>http://drm-blog.locklizard.com/2008/07/15/getting-too-casual-with-information.aspx#Comments</comments><guid isPermaLink="false">c632c43e-7fb2-442a-98db-3341d73ff79f</guid><pubDate>Tue, 15 Jul 2008 14:05:00 GMT</pubDate></item><item><title>The case for Digital Rights Management</title><link>http://drm-blog.locklizard.com/2008/04/01/casefordrm.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;P&gt;&lt;BR&gt;There are many good and valid reasons why people wish to be able to publish and transmit information electronically.&amp;nbsp; The rise of social web sites testifies to the willingness of people to make information available to selected individuals or groups.&lt;/P&gt;
&lt;P&gt;However, a willingness to share should not be interpreted as a wholesale license to all and sundry to freely make copies of electronic information and re-distribute it without even acknowledging the original ownership, or paying a Copyright fee.&lt;/P&gt;
&lt;P&gt;Much has been made, in the technology world, of the concepts of Open Source, CopyLeft, Limited Rights and so on, as arguments for the desirability of making all electronically held information freely available to all comers.&amp;nbsp; In the music receiving industry (as against the music publishing industry) there has been considerable pressure to make copying and redistribution a ‘right,’ merely because it is difficult to prevent.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Such arguments are intellectually barren.&amp;nbsp; They are like saying that because you own a gun you have a ‘right’ to shoot anything you like because it is difficult to stop you, or that because you can buy a car you can drive it anywhere you like and in any manner that you wish.&lt;/P&gt;
&lt;P&gt;Because people suffer physical harm as a result of such poor behaviours we pass laws to take action if behaviour is unacceptable.&amp;nbsp; Since Copyright is an economic right, we also have laws to protect Copyright owners from economic harm where behaviour is unacceptable.&lt;/P&gt;
&lt;P&gt;So we must reject the claim that merely because you can do something then you automatically have the right to do it.&amp;nbsp; (This was never true in Roman Law countries anyway.)&lt;/P&gt;
&lt;P&gt;Empirical evidence suggests that computer users cannot be trusted to use information provided electronically only and solely for lawful purposes.&amp;nbsp; Regrettably, it is essential to instil enlightened self-interest into the users of electronically provided information.&amp;nbsp; This is essential, simply because, “Computers are all about copying.” (Prof. JAL Sterling and S Mathews in a paper on protocols and interfaces).&amp;nbsp; Not only do computers facilitate copying, but they ensure that such copies are always perfect in every detail.&lt;/P&gt;
&lt;P&gt;This creates significant problems whose Intellectual Property(IP) (whether being offered for sale or being made available for some purpose as the result of a commercial agreement or a ruling of a competent Court, or some other reason) is being distributed electronically.&amp;nbsp; Agreements for the control of the use of IP are normally very precise, and set out to prevent unauthorized use.&amp;nbsp; Given the propensity of users to do things because they can, it is essential to provide a system of controls (Digital Rights Management or DRM) that actively ensure that the permitted uses must be observed, and cannot be trivially ignored.&lt;/P&gt;
&lt;P&gt;Similarly, those wishing to make their livings from selling their intellectual capacity (creating works by thinking) as opposed to their physical capacity (making objects) must have the ability to enforce their economic right.&amp;nbsp; To suggest that all the world (tout le monde) cannot make their livings from publishing and selling on the Internet would be a travesty of the so-called knowledge-based economies.&amp;nbsp; Whilst some may seek to demonstrate their intellectual capacities by ‘giving away’ the fruits of their labours as marketing in the hope of selling something else, not everyone has the luxury of such an indulgence.&amp;nbsp; One cannot see authors such as JK Rowling agreeing,&amp;nbsp; &lt;A href="http://entertainment.timesonline.co.uk/tol/arts_and_entertainment/books/article3621625.ece"&gt;http://entertainment.timesonline.co.uk/tol/arts_and_entertainment/books/article3621625.ece&lt;/A&gt; seems to be an indication of her view about copying!&lt;/P&gt;
&lt;P&gt;Academics (who, incidentally are paid to write, and often write as a matter of advertising, as do I) may claim that all intellectual capacity should be available for their study, comment, parody and so on.&amp;nbsp; I wonder how many electronic copies of Deathly Hallows were provided free gratis to the academic community for that purpose?&amp;nbsp; And without any limitation as to copying and being able to pass on?&lt;/P&gt;
&lt;P&gt;The fact of the matter is that there are cogent economic and political reasons why DRM technologies are required to protect documents in electronic form, and it is wrong to suggest that that there should be no mechanisms enforcing the control of authorized use made available and put in place.&amp;nbsp; Let those who wish to give away their work do so if they will, but allow those who sell their work to obtain fair and relevant recompense for their labours.&lt;/P&gt;</description><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2008/04/01/casefordrm.aspx#Comments</comments><guid isPermaLink="false">b7ff8dd2-ab05-46b9-9353-839bee08a046</guid><pubDate>Tue, 01 Apr 2008 16:31:00 GMT</pubDate></item><item><title>National ID law without debate – achieving the unacceptable by the unscrupulous?</title><link>http://drm-blog.locklizard.com/2008/02/06/idlaw.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;P&gt;Those familiar with reading our columns know that we are not normally exercised by minor debates.&amp;nbsp; But we are amazed by the report (which we rely upon as being true) by ZDNet at &lt;A href="http://news.zdnet.com/2100-9588_22-6228910.html?tag=nl.e550"&gt;http://news.zdnet.com/2100-9588_22-6228910.html?tag=nl.e550&lt;/A&gt; (correct at the time of publication) that the United States has mandated Federal identity controls on the back of a Bill ostensibly to do with "Emergency Supplemental Appropriations Act for Defense, the Global War on Terror, and Tsunami Relief, 2005."&lt;/P&gt;
&lt;P&gt;Well, OK, we do have the text in there about the ‘Global War on Terror’ so I guess that this might be a fine argument.&lt;/P&gt;
&lt;P&gt;But come on – get real – if you read the text it’s all about making the driver’s license the authorized Federally approved identity document!&lt;/P&gt;
&lt;P&gt;Now I realize that in the USA if you do not have a driver’s license then you are probably some kind of low life that does not exist, so therefore you are of no significance, and obviously not a terrorist, and therefore we do not need to worry about you.&amp;nbsp; After all, a terrorist could not possibly drive a car without a license just to deliver a bomb, could they?&lt;/P&gt;
&lt;P&gt;Hey, but that’s only a social analysis that says that the downtrodden underclasses are not likely to be terrorists, so we don’t need to worry about them.&lt;/P&gt;
&lt;P&gt;Let’s try thinking out of the box for a moment.&amp;nbsp; Why would you want this legislation when the people you are trying to catch are running outside of the system in the first place?&amp;nbsp; After all, history teaches us that criminals are generally outside the system because being inside the system is a highly negative advantage!&lt;/P&gt;
&lt;P&gt;Think for a moment about the costs that are going to be involved in granting the Secretary of Homeland Security this (wild?) desire to collect, at the expense of the States, and therefore at the direct expense of the Citizen, without there being any demonstrable benefit from this to that citizen (unless you count the collection of information about law-abiding people, because no self-respecting terrorist of any kind would be caught by such a an obvious trap) provable personal identifiers to standards that have not been promulgated and security controls that have not yet been identified.&lt;/P&gt;
&lt;P&gt;Yes, this bill will be the mother of all pork barrels to industries who strut their stuff about all manner of personal identification methods (despite the simple fact that there are no recognized international standards in this field, so anyone can claim anything they like – snake oil?) and the bill completely fails to say anything of any substance about standards, compliance, certification, accreditation and so on.&lt;/P&gt;
&lt;P&gt;So we screw the US car driver for shedloads of money – is that a problem?&lt;/P&gt;
&lt;P&gt;Well, if the punter is willing to pay, then I guess not.&amp;nbsp; After all, that’s what a capitalist economy is all about.&amp;nbsp; Capitalism is about what industry can screw out of consumers and governments can screw out of both (not maybe what Carl Marx actually wrote, but close enough).&lt;/P&gt;
&lt;P&gt;So this may actually come down to cost.&amp;nbsp; If the cost of implementing legislation that has not had public debate, is of questionable public benefit, has a cost that may not be appropriate to the actual benefit achieved (Since 9/11 precisely what has happened?&amp;nbsp; Well at the current rate of experience, nothing.) then why are we bothering?&amp;nbsp; Surely governments are being held to account for spending taxpayer money wisely and effectively.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;But, of course, if this is really a bill to hand the Secretary a future blank check for getting funding, even if that office has so far failed to do anything tangible for the protection of the public, then it is completely understandable.&lt;/P&gt;
&lt;P&gt;But then, you have to accept that by insisting on the registration of the law abiding (at an unknown, but certainly high cost to them personally) you can catch terrorists, who are, by definition, not law-abiding, and therefore outside of the system, then this is something you should go for.&amp;nbsp; But please suspend the use of logic, finance, governance or anything similar.&lt;/P&gt;
&lt;P&gt;On the other hand, if you feel like funding another Star Wars program personally, then step in line and vote.&lt;/P&gt;</description><category>Identity Theft</category><comments>http://drm-blog.locklizard.com/2008/02/06/idlaw.aspx#Comments</comments><guid isPermaLink="false">a343093f-143c-4767-97b4-60755dc79f95</guid><pubDate>Wed, 06 Feb 2008 23:48:00 GMT</pubDate></item><item><title>DRM is dead – Long live DRM!</title><link>http://drm-blog.locklizard.com/2008/01/14/drm-is-dead--long-live-drm.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;P&gt;If you believed everything you heard from the music and film industries, you could get very confused very easily.&amp;nbsp; And you could all be fooled into thinking that they are the only industries that exist when it comes to needing DRM (it’s a bit like saying that governments are the only organizations that need privacy!).&amp;nbsp; So Amazon and Sony now say DRM is dead?&amp;nbsp; Or is this nothing more than the usual marketing hype after a disaster?&lt;/P&gt;
&lt;P&gt;Actually, music and film have had long, chequered and cyclical love/hate relationship with DRM, mainly because they were the first people to get seriously exposed to piracy, and to feel pain where it truly hurts – in the bank account.&amp;nbsp; They got there in the 1960’s, long before the PC, or the iPod were more than the work of science fiction writers like Arthur C Clarke.&amp;nbsp; The fact that it would take almost 50 years before book publishers and organizations woke up and smelt the coffee is just history.&lt;/P&gt;
&lt;P&gt;Their first outing was the cassette tape.&amp;nbsp; Up to then, copying a record was practically impossible, and although reel-to-reel recorders were around they were too expensive and difficult to use for normal mortals.&amp;nbsp; But anyone could use a cassette, and everyone did.&amp;nbsp; They tried suing people who sold cassette decks that would copy from one to another, but they failed, and thus started the hunt for the Holy Grail of the industry – a way of stopping people from copying music (and later film) so that they could charge premium rates for their wares.&lt;/P&gt;
&lt;P&gt;Alas, it was not to be.&amp;nbsp; They lost the cassette wars, and later the VHS wars.&amp;nbsp; They won the DAT war (Digital Audio Tape) – remember it?&amp;nbsp; maybe not, when the hardware manufacturers lost a fortune because no consumer would buy into it because the copying controls were so aggressive you couldn’t necessarily copy your own personal recordings.&amp;nbsp; CD controls proved to be a lost cause, and DVD region pricing was outflanked by hardware manufacturers who were determined not to lose out on their own market opportunity this time around.&amp;nbsp; I remember a big meeting in LA when the music industry said they were going to implement secure MP3!&amp;nbsp; Laugh like a drain?&amp;nbsp; Well, I must confess I was close to being thrown out of the meeting.&amp;nbsp; Lately it seems that Sony decided on a rootkit approach to preventing copying that also opened up a serious hacking opportunity.&lt;/P&gt;
&lt;P&gt;So maybe you should see the current position to be nothing more than posturing by an industry that wants to be the content deliverer to the mass consumer market, and has only one objective in mind – its own profitability.&lt;/P&gt;
&lt;P&gt;That’s not to say that there’s anything bad about profit.&amp;nbsp; All of us are in business (in a particular sense), and if we don’t show a profit, one way or another, then things are very bad indeed (see Charles Dickens on Wilkins Micawber).&amp;nbsp; &lt;/P&gt;
&lt;P&gt;And what most people (and organizations, for that matter) trade on is their intellectual property.&amp;nbsp; In the ‘knowledge economy’ that is what we are selling.&amp;nbsp; So we have to safeguard that IP or anyone and everyone (I used to say the World and His Wife, but apparently that is no longer Politically Correct, and saying it would render me liable to being excommunicated by the deity or politician of your choice) can rip (RIP – Requiescat In Pace or ‘you will rest in peace’) you off and make your personal trade value slightly lower than that of a Eunuch’s scrotum.&amp;nbsp; (Apparently that is still Politically Correct!)&lt;/P&gt;
&lt;P&gt;What one has to think about very carefully, is what value DRM controls provide to you (either as an individual or as a business) in order to say if they matter, and when it is that they matter.&lt;/P&gt;
&lt;P&gt;The music/film industries are under the cosh because you can either copy their stuff, or you can’t.&amp;nbsp; If you can buy a legal version, and then copy it by recording the sound or filming the picture on a seriously high quality screen then you are in business.&amp;nbsp; And they are not.&lt;/P&gt;
&lt;P&gt;But that is a problem for those industries.&amp;nbsp; You can buy cracked codes for satellite TV systems with little or no effort or risk.&amp;nbsp; Try eBay – if it’s too cheap can it be real?&amp;nbsp; &lt;/P&gt;
&lt;P&gt;But, for the document handling industries, things are only just beginning to warm up.&amp;nbsp; Computing is all about copying.&amp;nbsp; When you read this you are looking at a copy of what I wrote, in fact I am doing that when I watch the characters come up on screen in front of me.&amp;nbsp; And that’s the major hazard for the PC and the Internet.&amp;nbsp; Everything has been set up to promote copying.&amp;nbsp; And the software does not give a ‘tuppeny damn’ whether the information is to be public, be controlled, or kept totally secret.&amp;nbsp; Which is bad news if you are in the business of selling, or simply providing, information (your knowledge, expertise, capability, private advice to clients, tax return computations, price lists, sales manuals, repair manuals ….. the list seems endless).&amp;nbsp; &lt;/P&gt;
&lt;P&gt;So enter DRM.&amp;nbsp; DRM is the only approach available that lets you specify not only who can see your proprietary information, but what use they can make of it.&amp;nbsp; The film and music industries were interested in preventing copying, but you will likely need to be able to stop people using information after a particular date, or make sure they can only see it for a couple of times, or print it once, or any number of other things.&amp;nbsp; Encryption does none of these things, it just prevents the un-anointed from being able to access information, not limit how and when they might use it.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;So whilst the music and film businesses figure they need to flex their market in order to maximize their own profits, they are operating in a different environment.&amp;nbsp; Commerce, industry, publishers, authors and ordinary mortals need DRM technology to protect their personal and commercial interests.&amp;nbsp; They have nothing else.&amp;nbsp; They are exposed to commercial or personal ruin by the uninhibited ability of the PC and the Internet to copy and re-distribute their information without any control at all.&lt;/P&gt;
&lt;P&gt;So whilst the record industries declare DRM is dead, we say, “Long live DRM.”&lt;/P&gt;</description><category>Digital Rights Management</category><comments>http://drm-blog.locklizard.com/2008/01/14/drm-is-dead--long-live-drm.aspx#Comments</comments><guid isPermaLink="false">6e6941d0-44d9-440a-9e91-c51b063002a8</guid><pubDate>Tue, 15 Jan 2008 00:42:00 GMT</pubDate></item><item><title>A brand new Whitehall farce?</title><link>http://drm-blog.locklizard.com/2007/12/03/dataprotectionact.aspx?ref=rss</link><dc:creator>Steve Mathews</dc:creator><description>&lt;DIV&gt;Without question, the doyen of the Whitehall farce from 1944 to 1969 was Baron Bryan Rix (made a life peer for his tireless work for the mentally handicapped).&amp;nbsp; But he had the wisdom to appear at the Whitehall theatre, and deliberately set out to entertain and delight his customers.&lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;The twists and turns of another Whitehall farce, in this case starring Her Majesty’s Revenue and Customs (HMRC) and the National Audit Office(NAO), in what is about to become the long running Child Benefit Data Farce, can now be seen onstage at the BBC (and any number of other entertainment purveyors).&lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;Sadly, these jokers appear to lack all the skills of the Baron Rix.&amp;nbsp; They do not entertain and delight their audience either.&amp;nbsp; It did not appear to concern them that there are laws (the Data Protection Directive 95/46/EC, and the Data Protection Act 1998) that have to be considered before processing data.&amp;nbsp; &lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;If we are to believe &lt;A href="http://news.bbc.co.uk/1/hi/uk_politics/7108532.stm"&gt;http://news.bbc.co.uk/1/hi/uk_politics/7108532.stm&lt;/A&gt; then the only concerns shown by all concerned were to save a few pounds (30 to buy some decent encryption software) and to skimp on proper delivery controls (it seems that HMRC don’t know what courier they used, or even if the courier ever got the missing CDs) – and, just for fun, it seems that at least 6 CDs have vanished and not just the two they first mentioned.&amp;nbsp; &lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;Ah, now it sounds much more like the traditional farce.&amp;nbsp; In the Rix farces, every time one of the main characters walks onstage some new disaster that was hidden from us is now revealed.&amp;nbsp; And any additional characters are unwillingly dragged into a doom not of their own making.&amp;nbsp; It seems that the NAO thought it was OK to regularly send all the data to their own auditors because NAO didn’t have the computer power needed to do their own audit work (?) and that was OK because the auditors were a ‘long standing strategic partner.’&amp;nbsp; To be scrupulous, the NAO did ask HMRC to remove unnecessary data, but HMRC refused, and so it’s all ‘their’ fault that the disks had unnecessary data.&amp;nbsp; &lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;The HMRC web site makes the following statement about their exemptions from the Data Protection Act: “&lt;BR&gt;•&amp;nbsp;Section 29 ‘crime and taxation’ &lt;BR&gt;•&amp;nbsp;Section 35 ‘disclosures required by law or in connection with legal proceedings’. &lt;BR&gt;The application of exemptions is quite complex and if you require further information or assistance you should seek further guidance.”&amp;nbsp; &lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;Well, now that’s quite clear, since we are entitled, as a matter of fact, to understand that what is listed publicly are truly the most important exemptions, and that all others are minor and trivial because if they were not then they should have been made just as clear.&amp;nbsp; This is the same argument as is used in contract law, that if something is so important that you have to rely upon it in a Court of Law, then you must have made it utterly clear in the agreement, not hidden it away deep in some small print. &lt;BR&gt;&lt;BR&gt;But back to the plot.&lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;So the NAO figure they are not responsible for their own actions of distributing disks that contained data that were not necessary for a specified business purpose, because it was not their data.&amp;nbsp; It was the HMRC data.&amp;nbsp; They gave us data we didn’t ask for so there was nothing wrong in us giving it to other people.&amp;nbsp;&amp;nbsp; Maybe there is going to be a glorious moment when Basil Fawlty walks on stage and tells us, “We were only obeying orders.”&amp;nbsp; Or maybe that’s in Act 2.&amp;nbsp; Thank goodness I booked triple drinks for the interval.&lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;Now OK, maybe you think I am being a bit harsh.&amp;nbsp; But if you ever ask government for information about anything, the very first question is, “Who needs to know?”&amp;nbsp; That is the bedrock of handling classified information.&amp;nbsp; So why is it that UK government departments seem to have such a casual indifference when handling the personal (and, given what we know about threats such as identity theft) sensitive data of some 25 million people (not quite half the country in round terms).&amp;nbsp; Well, in the true sense of farce, if there were not some things that are completely impossible to explain, or completely defy any form of logic, then farce would not work.&lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;I guess if you didn’t have a classical education you might miss the subtle difference between farce and tragedy.&amp;nbsp; Ask any Greek.&amp;nbsp; The difference is the number of dead at the end of the play.&amp;nbsp; But if governments run true to form there will be no shortage of sacrificial goats.&amp;nbsp; &lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;The really sad part of the whole play (remember, Shakespeare said, “All the world’s a stage, And all the men and women merely Players.”) is that the people actually at risk are, on the one hand, the people claiming child benefit, and on the other hand the taxpayer (because they are the real lender of last resort to any and every government).&amp;nbsp; When the Northern Rock hit a hard place the British taxpayer picked up the bill.&amp;nbsp; So much for the moral risk.&lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;Now maybe (or most likely) the people inside governments are too overcome with their own self-importance to notice that they are also taxpayers, or maybe they have inflation proof pensions, so they really don’t care about the implications of what they do, because they, uniquely, are where no amount of incompetence can harm them.&amp;nbsp; In any event, you should be saying that only those who can be personally harmed by their decisions should be allowed to make decisions.&amp;nbsp; &lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;So maybe that’s what the farce is.&amp;nbsp; That really big organizations behave as if they are either outside or above the law, and have deep enough pockets that all they have to fear is press exposure, because nothing else can really harm them.&amp;nbsp; And the tragedy is that public confidence continues to fall as electors see that governments serve themselves and not their electorates.&amp;nbsp; Perhaps the Greeks were right after all?&lt;/DIV&gt;</description><category>Intellectual Property</category><comments>http://drm-blog.locklizard.com/2007/12/03/dataprotectionact.aspx#Comments</comments><guid isPermaLink="false">8f5afdbb-e536-4909-ac3e-f13d3d49f61b</guid><pubDate>Mon, 03 Dec 2007 22:26:00 GMT</pubDate></item></channel></rss>