|
Search
CRA TumbleLog
Archives
April 2007
March 2007 February 2007 January 2007 December 2006 November 2006 October 2006 September 2006 August 2006 July 2006 June 2006 May 2006 April 2006 March 2006 February 2006 January 2006 December 2005 November 2005 October 2005 September 2005 August 2005 July 2005 June 2005 May 2005 April 2005 March 2005 February 2005 January 2005 December 2004 November 2004 October 2004 September 2004 August 2004 July 2004 June 2004 May 2004 April 2004 March 2004 February 2004 January 2004
Archives by Category
American Competitiveness Initiative (45)
CRA (38) Computing Community Consortium (CCC) (6) Diversity in Computing (9) Events (8) FY06 Appropriations (13) FY07 Appropriations (32) FY08 Appropriations (8) Funding (135) Misc. (42) People (67) Policy (179) R&D in the Press (56) Research (45) Security (20)
Recent Entries
NY Times on Women's Interest in Computing
Time on GENI Innovation Briefing Event NSF Reauthorization Eugene Spafford Honored with ACM President's Award Innovation Bill Moves Forward CRA's Hiring Innovation Funding Featured in House Budget Resolution Announcing the Computing Research Policy TumbleLog Innovation Press Conference and Hearing
CRA Links
Computing Research News
CRA-Bulletin Computing Data and Resources CRA in the News Computing Research in the FY05 Budget
What We're Reading
Computational Complexity
CNSR Online Danger Room Defense Tech Freedom to Tinker InsideHPC Lessig Blog Nothing is as simple... Reed's Ruminations Schneier on Security Techdirt UMBC eBiquity Blog USACM Tech Policy Blog
Advocacy Materials
IT R&D One-pager (pdf)
DARPA and University Research One-pager (pdf) Cyber Security R&D One-pager (pdf) Current and Requested IT R&D Funding Charts (pdf)
Recent Testimony
|
December 02, 2005DMCA Slowed Disclosure of Sony/BMG SpywareCRA has often argued that the Digital Millennium Copyright Act (DMCA) -- enacted in 1998 to combat digital piracy -- is disruptive to the process of research. When computer security researchers feel compelled by the potential liability created by DMCA to consult with an army of attorneys before moving forward with previously legitimate research, there's a cost -- a cost, we'd argue, that affects national and individual security, the pace of innovation, and IP management. In the case of the Sony/BMG spyware debacle, it appears that chilling effect cost unwitting consumers of Sony's CDs at least a month of additional exposure to the major security vulnerability introduced by "copy protection" on the Sony discs. Ed Felten and Alex Halderman detail this effect in their submission to the Copyright Office requesting exemptions from the anti-circumvention provisions of the DMCA as part of the office's triennial review of the legislation. As Felten notes on Freedom To Tinker, he and Halderman were aware of the vulnerabilities created by the Sony CD a month before the first public disclosure, but delayed publication of their findings until they could consult with university counsel about liability posed by DMCA. From the submission: Researchers like Professor Edward Felten and Alex Halderman waste valuable research time consulting attorneys due to concerns about liability under the DMCA. They must consult not only with their own attorneys but with the general counsel of their academic institutions as well. Unavoidably, the legal uncertainty surrounding their research leads to delays and lost opportunities. In the case of the CDs at issue, Halderman and Felten were aware of problems with the XCP software almost a month before the news became public, but they delayed publication in order to consult with counsel about legal concerns. This delay left millions of consumers at risk for weeks longer than necessary.Felten and Halderman are asking the Copyright Office for an exemption to the DMCA that would allow circumvention of compact disk copy protection technologies that have certain spyware-ish features or create security holes. You can read the whole submission here (pdf). Unfortunately, the Copyright Office was pretty miserly about granting exemptions during the last two reviews, so it's not clear how even Felten and Halderman's compelling request will fare. But we'll keep track of the process here and post the details. Posted by PeterHarsha at December 2, 2005 12:28 PM Posted to Security |