Showing posts with label copy protection. Show all posts
Showing posts with label copy protection. Show all posts

Friday, November 6, 2009

Moto perpetuo

It occurs to me that unbreakable copy protection is the perpetual motion of our day.

Back at the beginnings of the industrial revolution, when inventions like the steam engine and electrical generator were making new and mysterious things possible and were not widely understood, people were constantly coming up with perpetual motion schemes. And why not? If you can generate more power than hundreds of strong men and horses can produce just by burning coal, and transmit that power miles and miles away with simple metal wires, is it so implausible that some arrangement of magnets and overbalanced wheels could generate endless power from nothing?

Eventually, in the early 1800s, after commercial steam power had been around for about a century, the principle of conservation of energy came to be widely accepted and by the the middle of the century the familiar laws of thermodynamics were established, including the crucial first two:
  1. You can't win (conservation of energy).
  2. You can't break even (entropy increases in a closed system).
These two principles explain why perpetual motion schemes don't work. That hasn't stopped people from coming up with them, but it has stopped knowledgeable engineers and scientists from wasting time on them. It hasn't completely stopped investors from investing in them, but the long and sorry track record of such schemes probably has been a deterrent.

Why do people still bother, then? Because if it were possible, large-scale perpetual motion would do away with energy shortages forever. It woudn't necessarily make any money, infinite supply implying zero price, and an energy surplus would have drawbacks of its own, but we could probably deal with those problems when they came up. The point is that people try to prove that perpetual motion is possible because they really, really want it to be.

Anyone in the business of selling information would really, really like to be able to control the propagation of that information. You do the math.

I don't know of any specific principle of information theory that explains why this will never work, but there's a growing body of empirical evidence to that effect. Intuitively, copying bits costs much less than the price sellers would like to charge, so the protection has to come in the conversion of those bits into usable form. That runs you right in to the analog reconversion problem, of which "camming" (sneaking cameras into movie theaters) is a crude but effective example.

Clearly none of this is currently stopping people from trying to come up with copy protection schemes, or people from paying for them. The track record probably isn't quite long or sorry enough yet. I suspect it eventually will be.

Fortunately, selling bits and making them impossible to copy are two different things.

Wednesday, November 4, 2009

60 Minutes and the MPAA: Part V - Relevance

OK, so the L.E.K. study says that people who buy pirated DVDs say they would have collectively spent billions of dollars on legitimate fare if the pirated DVDs hadn't been available. Let's assume these people are telling the truth and are accurately estimating how much they would have spent. So we're done, right? That's how much money the studios are losing.

Actually there's another level of estimation involved. The $6.1 billion quoted was the amount the studios were said to be losing and itself is a portion of the larger total that the motion picture industry as a whole was said to be losing. But let's take that, too, at face value. Now we're done, right?

Well ... remember when I was discussing BitTorrent in Part I and mentioned the importance of carefully considering what problem you're trying to solve? The principle is just as vital here.

The MPAA, like the music industry before it, and the software industry before it, seems to be trying to solve the problem of keeping people from copying bits. Being no more able to do this than their predecessors, and with Moore's law catching up with them just like it did with everyone else, they -- again like everyone before them -- claim damages by comparing the real world with what they might have had if they could stop people from copying bits.

Fair enough, but they can't. No one can, and a false antecedent implies anything you want it to. Rather than trying to keep people from copying bits, would it not be better to frame the problem as how to make money from making movies?

The traditional way of doing that, selling tickets at theaters, is still bringing in revenue, on what I'd call a slight upward trend and what the site I got the figures from says is "not any substantial increase". That's not great news for an industry constantly trying to grow, particularly once you adjust for inflation, but neither are they falling off a cliff. Evidently "Let me take you to the movies" can sometimes have more appeal than "Let's go back to my grungy apartment and watch a DVD."

Leaving aside the TV networks, cable movie channels and pay-per-view (which is not necessarily a valid approach) the complaint, and certainly the thrust of the L.E.K. study, is that DVD sales are not doing as well as expected. They were supposed keep chugging along like video before them, but they appear to be levelling off or even falling. At the same time people are selling lots of pirated videos, so the difference is attributed to piracy. QED.

But correlation does not imply cause. Certainly one interpretation of those facts is that piracy is hurting DVD sales, but another one, which I personally find more plausible, is that since bits are getting easier to copy and watching digital movies no longer requires a DVD, DVDs just aren't that valuable any more and the original sales projections that they would be were just wrong. Another symptom of the same technological changes is that making shoddy DVDs is easy enough that you can still make money off of them by charging closer to what they're worth, but neither of these symptoms is the cause of the other.

I don't recall when I last bought a DVD and I can assure you it's not because of piracy. Why pay $20 or even $12 for a DVD to take home and unwrap when I can order up a movie on demand for $4 or (if it's not particularly popular) watch it over Netflix as part of my $10/month subscription? How many DVDs do I watch more than three or four times? The commentary tracks seemed cool at first, but I don't really have time for those, either. Manifestly, I'd rather blog about DVDs than buy them.

I would, however, gladly pay more than $10/month for some sort of "premium" Netflix subscription that would open up more selection. I suspect I'm not alone. There's certainly money to be made legitimately by selling high-quality video online that won't get you sued or arrested. It's not a foregone conclusion that there's enough money to be made to keep the movie studios going in the style to which they (and we) have become accustomed, but I'm quite sure that money is not to be found in trying to prevent bit-copying.

Saturday, May 9, 2009

Yet more silliness -- with chicken!

This one has been all over the news (here's a bit from Reuters, for example). I didn't participate directly, but I know people who tried.

It seems that KFC and Oprah Winfrey teamed up to promote an offer of free grilled chicken (maybe it should now be "KGC"?). All you had to do was download a coupon, print it out and take it to your local KFC. Except for the small matter of scale, it's a classic loss-leader to get people into the stores and get them to try a new product, one arguably healthier than the usual eleven-secret-herbs-and-spices formulation. I'm guessing the healthy part was Oprah's angle on it.

The results were not particularly hard to predict. My favorite tidbit was KFC spokesperson Laurie Schalow explaining that "there was no riot" and that "some KFC stores may have run out of some products, such as mashed potatoes and gravy or cole slaw, 'but they are substituting as best they can.'" I can only wonder what you get when you ask your tablemate to please pass the mashed potato substitute, but I give the lady full credit for even showing up to work that day.

Meanwhile, on the "how to use the internet to get $3 worth of free chicken" end of things, my correspondents' simple quest to print out a few coupons before heading out for lunch turned into a full-on mini geekfest involving much hilarity as the online offer evolved from a simple "Here's a PDF, print it out" to a twitching beast clearly thrown together in a hurried attempt to slow the tide.

I don't know the exact details, so don't quote me on any of this, but it seems that somewhere along the line KFC tried to put a unique serial number on the coupons. That can work reasonably well if the infrastructure is there (see the very first post on this blog for an example), but not so well if in all the confusion the individual stores are not clear on whether to enforce the one-serial-number-per-customer restriction and zillions of people have already printed out or otherwise copied the original non-unique coupon.

This doesn't seem to have stopped the webmasters from trying to control the printing of coupons to keep people from churning them out by the dozen for themselves. This trick never really works and it seems particularly pointless given that the offer was for a limited time, the stores were already giving away chicken as fast as they could, the whole point of the exercise was to get people in the store, not to make it hard for them, and that making the web site annoying risked costing well more in bad PR than just giving away chicken would cost in chicken, but again, I give the crew full credit just for showing up to work on this one.

At some point I recall hearing that the site was trying to get you to install a .exe on your Windows box and if you were running in a virtual machine (not a bad idea if you're installing some random .exe), refusing to print. There was also something about being asked to upgrade to a Mac, but I may have this garbled.

Monday, January 12, 2009

More muddling over music

We may finally be figuring out how to pay for music in the digital age.

Actually, the likely answer has been clear for a while now. The news is that the major players seem to be warming to it: Buyers pay per song. Some of them cheat. Many of them don't. Musicians may sell directly, or they may go through a label.

Probably the strongest evidence is iTunes dropping DRM, or rather, the labels agreeing to drop DRM. The flip side of the deal is that iTunes will no longer charge a flat $0.99 per song. New songs by popular artists will cost more. Older pop songs will cost less. Other genres will follow their own traditions and customs.

It's an interesting question which of several factors have had how much influence in making all this happen. In no particular order:
  • Labels may be getting comfortable with the idea that while there's going to be "leakage", enough people will be willing to pay for them to keep the wheels turning. It probably helps that the marginal cost of selling songs online is near zero, but probably not as much as one might think. Pressing CDs is pretty cheap, too. I forget how cheap, but it's a small portion of the retail price. Some of the additional costs -- storefront costs for a brick-and-mortar music shop, for example -- go away online, but many of them, particularly marketing costs, don't. Someone has to pay for all those award shows and after-parties.
  • Labels may be getting scared by sales of physical media going through the floor. One might be tempted to gloat over yet another example of physical copy-protection yielding to the Mighty Web, except that CDs don't really offer any copy protection either.
  • Apple seems to have figured out that a flat pricing scheme looks completely screwy to labels, who have been selling music for a lot longer than it has. Charge the same price for the Billboard #1 as for a Johann Kropfgans lute concerto? You're kidding, right? Labels understand that different groups are willing to pay diffrent prices for different music. Before any classical music fans out there pummel me, let me hasten to add that the Kropfgans recording I found costs a bit more than the current #1, Lady Gaga. If classical listeners weren't willing to pay more, there'd be no market.
Further, people will pay different amounts for the exact same music depending on whether they buy it while it's hot and all the cool kids are listening to it, or whether it's sitting in the virtual remainder bin with Herb Alpert (Before any Herb Alpert fans out there pummel me, let me hasten to admit that I own at least one Tijuana Brass album. Now the cool kids can pummel me instead.) It's called "walking down the demand curve," a concept I vividly and bitterly remember learning as an economics guinea pig in college when the Trader Joe's money I'd been counting on failed to materialise.

All of this leads me to inaugurate a new tag (which I'll backfill at some point, as I've been beating this drum for a while now): not-so-disruptive technology. After a bumpy start, and a few false starts, we seem to be converging on a model that looks a lot like the old one.

Did online music Change Everything? No. It's changed some things, but so did the 45, the LP, the boombox, the walkman, the CD, the MP3 player and its cousins, heck, even 8-track. Did iTunes Change Everything? No. In the end the studios have lived to fight another day.

Probably.

Postscript: Some have argued that albums are going to fade away as the iTunes generation picks and chooses the songs it likes, but this may just as well be a pendulum swinging. One could argue whether albums are an artifact of the LP and CD, or whether people will continue to like their songs in that form, but the Billboard hot 100 has been going since 1958, when 45rpm singles were the only real game in town.

Post postscript: There's a whole other interesting discussion to be had over whether file sharing Changed Everything. It should be no surprise that I don't think it did. The more interesting question is how much of that has to do with the labels breathing legal fire about it, and how much of it has to do with the economics of the free-rider problem.

Wednesday, November 26, 2008

CD Player. Comes with music.

This is take two of the post I was trying to write when I ended up writing about BodyNet instead.

Technically, there's not a lot of difference between a cell phone and a streaming audio player. Throw in some flash memory and downloaded tunes are no problem either. Add a screen and you can say the same thing for video. But how do you get the content to the phone? Two models spring to mind:
  1. A big happy open web-driven marketplace. Surf wherever you want. Find something you like? Download it to your phone just like you'd download it to your PC. Pay whoever you need to when you download (or pay for a subscription). This is pretty similar to the CD/DVD market. Sounds nice, but as far as I know you can't do it. It's a lot easier to do DRM on a captive device like a cell phone, and cell phone makers are pretty aggressive about making sure you don't tamper with their devices.
  2. A collaboration between the content owners (i.e., studios and record labels, not to be confused with singers, songwriters, screenwriters, actors etc.) and the service providers. Subscribe to a service and you can also download or stream content from whatever content owners the provider has partnered with. This is pretty similar to the cable TV model. It ensures that everybody gets a cut (as always, we can argue over who gets what cut) and a number of partnerships have formed.
There's another model that doesn't come to mind because when you try to map it back to "old media" terms, it doesn't really fit. Yet there are at least two examples going, one of them recent:
  1. The cell phone makers sell the content. As the title suggests, this seems like selling a CD player and then selling the CDs to go with it. You see this in niches (e.g., Disney makes an MP3 player and sells plug-in cards with songs from their artists), and I wouldn't be surprised if some early phonograph maker tried it, but it doesn't seem like a great idea. Selling electronic widgets and selling bits are just two different things. Nonetheless, it certainly worked for Apple and the iPod/iPhone, and now Nokia is trying the same approach with Comes With Music (TM). It's not quite the same model as iPhone -- for a subscription fee, you can download all you want and keep it forever -- but it does share the feature of putting the phone maker in the content business.
So maybe they know something I don't. Wouldn't be the first time.

Wednesday, August 27, 2008

You saw the website. Now read the book!

Someone sent me a link the other day to a definition on Urban Dictionary. While enjoying that, I noticed a link for their latest book. It's not surprising that a major site should have an associated book or two. What's surprising is that it's not surprising.

I've argued before that text as a medium is not going to die out any time soon and that the web is a major factor in that. But it's a bit more puzzling why print doesn't die out. Books from web sites are a particular curiosity, and one for an online reference even more so. Think about it: The online version is searchable, hyperlinked and up to date. The print version is none of the three.

A dictionary is meant to be searched, is generally more fun and useful to browse by chasing cross-references, and had best be up to date (it'll often be new words you'll want to know the meaning of, at least when it comes to slang). Why bother with print? I can see why a publisher would bother: they know how to get paid for print. But why bother to buy a book?

Copy protection isn't an issue for a free online dictionary. It's got to be the form factor. It's still hard to take the online version with you wherever you go. Sure, you can carry a laptop with you, and there are hot spots and cell modems, but a book is generally smaller and more reliable. And it's not that hard to search, particularly if the entries are alphabetized.

Kindle was supposed to change all that, but as far as I can tell the infrastructure and selection aren't quite there yet to make Kindle take off.

Tuesday, May 13, 2008

More on Blu-Ray

Kris made a couple of good points in a comment on "Two things I didn't know about Blu-Ray".

First, if the content is songs recorded in the '60s, it doesn't matter how many bits your medium can hold. Those old analog tapes are still going to sound the same, and if you're a fan you probably already have them anyway.

Now in Neil's case, that's not what he's selling. He's selling new material (to us, not him) in a snazzy presentation that will allow you to do things like ponder lyrics and photographs while listening to the digitally scrubbed tape hiss on Mr. Soul or whatever. That's not enough for me personally to take the plunge, but for some folks it will be.

The second and more fundamental point is that, assuming the DRM stuff works, a blu-ray disc, even a "live" one, is a closed medium. You can only play it on a blu-ray player, not on your car stereo or your portable music player, or even on the upstairs TV unless you get another player. That's a feature to whoever's making the players, but a bug to the rest of us.

In the original post I was a bit too vague in calling that a "wrinkle". The other wrinkle, that modifications can be tied to a particular player, is also hard to see as a feature.

If you can't make your own copy, you're also stuck if you should lose or damage the original. The manufacturers know this and have developed a special scratch-resistant coating for the new disks, but however you coat it, having one copy is no match for being able to make backups. We've seen this movie a couple of times already, enough to have a pretty good idea how it ends.

Tuesday, March 25, 2008

We want the world and we want it reasonably soon

One of the nice features of digital TV is that you can decide when to watch a given program. This isn't a new feature, but digital delivery makes it a lot easier. Anyone remember VCR Plus?

In fact, you can time-shift in two different ways with a typical digital cable setup (at least, I think mine is fairly typical):
  • Record a program and watch it at your leisure
  • Get it on demand
In either case, you watch the show when you want. The difference is when the bits arrive. In the first case, they arrive when the broadcaster decides to send them. In the second case, they arrive when you ask for them.

What determines which way the bits get to you?
  • Storage space: Your DVR will only hold so much. If you try to record everything you might possibly be interested in, you're liable to run out of space. This factor is rapidly changing.
  • Broadcast bandwidth: There's only so much spectrum available. With infinite bandwidth, a provider could broadcast every piece of video/film ever made at 1,000,000x speed on an infinite loop and everyone could grab what they wanted as it came by [See this post for some implications of that].
  • Copy protection: A provider might prefer that you not store a copy of the bits. Instead, it would prefer to send encrypted bits to a box that decodes them, without offering a ready way to store the results. This factor is also subject to change as the whole copy protection issue shakes out.
  • Time sensitivity. A live event has to go out live. Even pre-recorded material can have more impact if everyone gets it at the same time -- the water-cooler effect.
The broadcast-and-record model doesn't require a data network. Traditional TV/Radio broadcasting, whether from towers or satellites, works just fine. VHF and UHF together comprise around 3GHz of bandwidth, readily available without building out a "last mile". At the moment, that's still quite a bit of bandwidth. Even if the broadcast is via a data network, there's no requirement that said network be connected to or behave like the internet.

The downside is that (for the most part) you don't get to choose when the bits are sent. But how much of a downside is that? It's not a problem for live content -- quite the opposite. It's not a problem for not-so-live content either, as long as you can still choose when you watch.

Again, the connection between receiving and watching has been loosening over time as storage gets cheaper and easier. Maybe this is just me, but if my favorite show comes in while I'm asleep and I can watch it whenever I want the next day, I've got no problem. On the other hand, if it's something that everyone just absolutely has to watch at a given time, that's essentially live content.

The upshot is this: Given ample cheap storage, it would appear worthwhile to broadcast anything new that lots of people want to see, regardless of whether they want to see right at that moment.

I haven't paid a lot of attention to satellite TV lately, having had cable for the past few years, but I could imagine someone shipping out a set-top box pre-loaded with a huge video library and space for plenty more. Only new content gets broadcast.

Live content comes in as it happens. Pre-recorded content comes in whenever the bandwidth is available. Everything gets stored on the box, using double-secret heavy encryption mojo. You can have whatever you want, and reasonably soon. The result would be pretty much indistinguishable from a cable set-up.

You would even have on-demand viewing. This difference is that instead of demanding the bits, you're demanding authorization to decrypt the bits (for a while, at least). You might well obtain the decryption key via the web, in which case the web handles the transaction, but the heavy lifting of moving large hunks of video around can happen elsewhere if that makes sense.

Such a scheme would also have all of the usual data-protection problems, notably including analog conversion, but that comes with the territory. Whether it's less secure than an existing on-demand service depends on just how good the double-secret heavy encryption mojo is. I can see content providers being nervous about putting the keys to the kingdom directly in the hands of millions of subscribers, however well protected the data may be. But on the other hand, isn't the whole point of mass media to get the bits to as many people as possible?

Friday, February 15, 2008

Facebook and copy protection

A slightly different take on the previous post:

Facebook's terms of service bring out an interesting gray area in copy protection. The gist of the contract appears to be that you own whatever you put up, but you don't own anything else. In particular, you don't own your friends list. Facebook does. I haven't checked, but I assume this is the norm on such sites, not just a Facebook thing.

But what does that ownership mean? Facebook obviously doesn't mind you telling people "I know so-and-so on Facebook." That's good for business. They shouldn't mind if you happen to have an email address book that has the exact same contents as your friends list. That's none of their business, and it would clearly fit into the "personal, non-commercial use" exception.

On the other hand, they definitely mind if you, say, write a script to crawl your friends list and whatever can be reached from there and make a copy of it. There are very specific "no bots" clauses aimed at just that.

The presumption is that if you're using a bot, as opposed to personally browsing, cutting and pasting, you must have some commercial reason for it. It will be interesting to see how well that holds up.

Another thought: For most of history, copy protection has relied on it just being too slow to copy things yourself. Technology has disrupted that, starting with the photocopier and the tape recorder, spurring the development of cryptographic copy protection.

"No bot" clauses are a sort of throwback. The content is unprotected, beyond requiring a password to get into the system, but if you access too much of it too fast, the hammer falls.

Wednesday, January 2, 2008

Economic copy protection

Suppose I've created something really cool, say a screensaver that's so entrancing that when you see it on my screen, you've got to have it. I agree to give you, and only you, the binary for it, for a hefty sum. Bear with me -- it's a thought experiment.

You've got the binary. I've made no effort to copy protect it. You can copy it as much as you want and give it away to all your friends if you want. Will you?

My guess is no. If you've paid a bunch to have my screensaver on your screen and your screen only, why would you give it away? Will I copy it and give it to someone else? Not if I want to do business with you again.

In effect, the work is copy-protected, but by economic, not technical means.

Now suppose you grow tired of my creation. You could just give it away then, but why not try to get something out of it? Say, sell it to your six friends that have been drooling over it, with each paying 20% of the original price you paid me. They get the cool screensaver at a heavily discounted price (to make up for their not having had it hot off the press), and you get a cool 20% profit. Plus the use of the cool screensaver in the meantime.

But If I'd known you were going to do that, I would have been better off just selling to you six friends to begin with, and maybe to you as well if you could tolerate not being the only one with the new work.

With more customers I can charge less per customer, but by charging less I will also pick up more customers who don't see any need to refrain from copying the work and giving it away. If you pay, say, $4 for something and get as much enjoyment out of it as you would from a fancy cup of coffee, your investment at that point is zero. So why not give it away (absent any technical or legal barrier)?

Monday, December 10, 2007

Why is there still print?

The Newsweek article on Kindle quotes Jeff Bezos as saying "Books are the last bastion of analog." I take his point, but it seems an odd statement. Text, after all, is arguably the first real digital medium. What he means by "digital", of course, is "available to computers". Unlike music and video, which are now routinely released in computer-readable form, books are still released in a form you can't just download. Bezos aims to change this with the Kindle.

The interesting question is, why does print resist digitization so well? I've suggested that publishers like it because it provides copy protection, but why does it? The answer has to be economic, not technical. Technically, it's trivial to digitize a book. Just scan it in. Don't bother to try to convert the image back to text. If all that people want to do with the result is read it, the image should work fine.

There's an interesting subplot here. Optical character recognition (OCR) seems to do fairly well these days on well-printed books, judging by Google books and Amazon's own "Search inside the book" feature. On the other hand, the fully general problem of reading anything a person can make out still appears to be hard, which is why sites use distorted text CAPTCHAs to try to stop bots. This seems like the equivalent of anX-prize for freelance OCR hackers, and indeed the inevitable arms race appears to be well under way. Finally, bringing us full circle, one source of these CAPTCHAs is printed text that failed to scan correctly.

In any case, the difficulty doesn't seem to be digitizing text in a readable form. The problem is, what do you do with it once you've got it? It's technically trivial to scan a book, but it still takes some time and effort to flip through all the pages, at least without expensive specialized equipment. So if I've done this, I'd like to see some compensation -- assuming I don't mind violating copyright laws.

Can I put it on the web and sell it? Well, um, I've just brought it into digital form, thereby making it hugely easier to copy. In other words, I've just put myself in the position of the publisher whose print-based copy protection I've just broken. If copy-protection is out, there's always advertising. Except that's maybe not such a good idea given that I've just broken the law.

This same argument would seem to act as a counterbalance to all sorts of unauthorized copying, but obviously it doesn't apply as effectively to audio and video. This is probably because copying CDs and DVDs is much, much easier than scanning books, and also because books are simply a different medium. I'd expect that PhDs have already been earned on just such matters.

Kindle and print

While looking for something else, I ran across the November 26 issue of Newsweek. The cover story was on Amazon's new Kindle e-book. Conveniently enough, the article is available online.

Overall I found the article pretty evenhanded, balancing the "print is inherently inefficient" side with the "books are inherently special" side. As usual, I think both sides have valid points. A few thoughts:
  • Yes, print is inherently inefficient. That doesn't mean it will die anytime soon. People still sent hand-delivered messages long after the telephone became widespread. Steam trains ran long after the diesel came along. Western Union only recently shut down its telegraph service.
  • On the other hand, it's hard to imagine print not giving way to bits over time and eventually reaching niche status. My completely unfounded guess is that it will end up more like blacksmithing than buggy whips.
  • Amazon is right to recognize that it's not enough just to have an electronic device that more or less looks like a book. The Kindle is not just a device but a service. Along with searchability and the potential for hyperlinks, Amazon hopes the killer app will be the "buy and read it right now" feature. Push a button (and pay Amazon a fee generally less than you'd pay for print) and the Kindle will download whatever book you like. Whether this is enough to pull people in remains to be seen, but it at least seems plausible.
  • The Kindle relies on copy protection, presumably using some Trusted Computing-like facility. I've argued that it's not unreasonable to expect a special-purpose device to give up programmability in an attempt to lock down copy protection. Again, it will be interesting to see how well this works.
  • Conversely, print has a nice, well-understood copy protection model. Copying a book means physically copying pages. In theory this is quite breakable. In practice it works well (so far). Publishers naturally like this. It would be interesting to try to quantify how much this convenience to publishers is extending the lifetime of the book, as opposed to the "nice to curl up with and read" aspect.

Saturday, November 10, 2007

Trusted computing: What could be better?

The fundamental tension behind trusted computing is over programmability. Someone sending out protected content wants to be sure that it can only be accessed on a restricted set of particular devices. This is a lot easier of the devices in question are not highly programmable. In the case of a portable music player or set-top box, the keys involved can be kept in special tamper-resistant hardware and otherwise protected from exposure or modification.

If your playback device is a general-purpose computer, the game becomes a lot harder. I could send you a player application with a key branded into it, but there are any number of ways to get such a player to yield up its secrets, or yield up the unprotected content without having to uncover the secrets themselves.

The trusted computing model tries to combat this by restricting access to the information on a given computer and tightly controlling all modification to such an otherwise-programmable device. In other words, the vendor asserts control over programmability. It is this idea, not the idea that the creator of content should have control over the content, that fundamentally conflicts with the ideas (and ideals) of personal computing in general and free software in particular.

The TC model, depending on tight control of all possible modifications, is inherently fragile. Compare it to the models used in modern cryptography (on which it heavily relies). In modern cryptography, one makes extremely pessimistic assumptions about what will happen in practice.

For example, in designing a cipher, one typically assumes an adaptive chosen-plaintext attack. This means that the attacker can repeatedly choose a message to be encrypted, look at the resulting ciphertext, choose another message to be encrypted and so on. This did not come about by accident. There are various ways a real-world attacker can perform such an attack on a real-world cipher.

Cipher design, and robust engineering in general, assumes that anything that can go wrong will. This generaly means minimizing the number of dependencies and moving parts. The RSA cipher, for example, consists of raising a number representing the message to a known power and taking the remainder against a large number, called the modulus. The modulus (along with a second exponent used to decrypt the message) is derived from two large, randomly-chosen prime numbers by a simple recipe.

That's it. That's one of the most secure ciphers known. But even with that simple recipe there are known subtleties in choosing a good key and in preparing messages for encryption in order to avoid various attacks.

Trusted computing relies on five key technologies, which interact in various ways to provide the full model. You need hardware support in several places to even have a chance at making it all work. There are legitimate questions about how all this will affect basic system functions like backup. It's quite clear that any TC system will be actively attacked by hackers in both senses (I shouldn't get started on this, but I still like to think of "hacker" as meaning someone who does clever things with technology for the sake of learning and having fun; the more popular meaning is someone who tries to break into systems).

It doesn't seem like a good bet.

Trying to prevent or control modifications to a general-purpose computer is swimming upstream. The main driver here is to protect content like music and video. That requires a tamper-resistant decoder (and faith that this is a worthwhile exercise, despite analog reconversion). From this point of view, TC tries to enable general-purpose computers to become decoders by first making them tamper-resistant.

The alternative is not to try to make general-purpose computers into decoders. If my computer has an encrypted-bits-to-sound-and-video decoder attached to it, then I can reprogram my computer all I want, and I can make as many copies of protected content as I want. When I want to play a song or video, I send it to my decoder, which has all the attributes TC wants: it's tamper-resistant, non-programmable and has a private key embedded in it as tightly as modern technology will allow.

I can use my favorite software to index the content that I've bought the rights to, to sequence it, to dispatch it to the various decoders I own and so forth. I can use my favorite non-media software without having to worry about what measures my OS vendor is taking to control my use of the content I bought the rights to.

This is not to far from how current content-delivery systems like cable and satellite boxes work, as I understand it. Given that, it's not clear to me how much farther we need to go down the TC road.

Thursday, November 8, 2007

How do writers get paid without copy protection?

Hal comments (thanks!) that music and video can't be protected, and as a result only interactive content, particularly games, will be commercially viable. Music and video will be produced mainly as an adjunct to games and given away free. I was going to get into this anyway, so that seems like a great jumping-off point.

First, I completely agree that music and video can't be protected by purely technical means, and that interactive media have a much better shot. Copy protection fundamentally requires a tight connection to an object or event in the physical world, and interactivity provides such a connection. Frankly, though, I'm reluctant to claim categorically that anything can be effectively copy-protected, even when it looks like there's an airtight case. Where there's a will there's very often a way.

Nonetheless, the model of paying a fee to be able to participate in an interactive experience with others looks viable. It certainly seems to be working so far. I can also see single-user cases working, particularly if the game play has a random element to it. This also seems to be working so far.

On the other hand, I'm not convinced that it's necessary to protect content strongly in order for content creators to make a living. Text, for example, is impossible to protect. No one really tries, that I'm aware of. The exception would be environments where secrecy is at a premium, in which case protection is generally a combination of encryption to prevent casual access and stiff penalties for giving away the keys or unencrypted content.

And yet writers can still make (a little) money. How?

First, the traditional print model is still alive. I've heard newspaper publishers express concerns, given that classified ads have serious alternatives online (often including the newspaper's own online ads), but daily papers are still around, as are independent weeklies, supermarket tabloids and mass-market magazines, coffee-table books, specialized trade rags, pulp fiction and pretty much everything else.

Not only has print not disappeared, I'm not sure I can even think of a particular commercial genre or format that's disappeared. You'd think by now something would have. Small-circulation newsletters tend to be emailed or on web pages these days, and office memos have (thankfully) more or less bitten the dust, but those are non-commercial.

Print has (at least) three ways of making money. At least one of them carries over quite well to the online world:
  • The book as a physical artifact. Coffee-table books look great. You just can't get that on your screen. If nothing else, the resolution and contrast are way higher than for anything you can get on a screen. Other books use special paper and fancy bindings to look gorgeous. Children's books are particularly inventive in using pop-ups, textured materials and so forth. These are niche markets, though. What's interesting is that nothing electronic yet seems to have killed off even the humble paperback.
  • Subscriptions. You pay me a regular supply of money, I give you a regular supply of content. This seems to work well for cable TV and satellite radio. In the case of music radio, you can get all the content elsewhere, but what you don't get is the particular selections and, of course, the charming DJ's. Talk radio is more of a live performance and in many cases interactive. As such, it's one prototype for (probably) copy-protectable interactive content. Not all radio or TV is paid for by subscription, though, and pure subscription models are fairly rare in print (investment newsletters come to mind). The alternative, of course is
  • Advertising. Not even Mad magazine survives purely on subscriptions any more. Plenty of "free" publications survive on advertising alone. Online, without the cost of printing presses, paper and delivery, no one needs to charge a subscription fee. Why bother, given that it's trivial to copy the content? So instead, you get a variety of ads in exchange for the convenience of being able to get a document hot off your search engine. There are various technical ways of stripping out ads, but the dirty secret is this: ads are actually useful, at least sometimes. The symbiosis between "real" content and ads has been around for a long time and very much alive and kicking now. Just ask Larry and Sergey.
This by no means exhausts the possibilities for making money without strong copy protection. I've singled out text here because it's been unprotected for longer -- at least as long as we've been calling the web the web -- while other media are still a bit more difficult to copy. For now.

Of the three approaches above, physical print is all about literal copy protection, while subscription depends at least to some degree on protection through interactivity (even a print magazine has to stay fresh by responding to its readers). Advertising stands out in that it not only doesn't require copy protection, but actively encourages free copying (as long as the ads stay attached). The more copying, the more people see the ads.

Tuesday, November 6, 2007

Analog reconversion and copy quality

All copy-protection schemes have at least one prominent hole. At some point, they have to deliver you something. A music player has to play music, a document viewer has to show you a document, and so forth.

There's nothing at all stopping you from recording the sound that comes out of the headphones, or taking a picture of a document on a screen (and in the Trusted Computing nightmare scenario of the disappearing order, that might be a very good idea).

Of course, the usual objection is that you've lost information in the process. You've lost sound quality in the case of music. In the case of a document, you're just seeing text on the screen, not the underlying markup or structure.

Well yes, but ... if all you can do with a piece of music is play it on your headphones, and you record the analog signal going to the headphones (or even coming out of the headphones), then you have copied all the information needed to listen to the music with the quality those headphones give. Which is all you had in the first place.

Similarly, if you capture the images on the screen as you view a document, then you can go back and re-read the document any time you want. With optical character recognition, you could even reconstruct the text with fair accuracy. The process in general is called analog reconversion.

If all you are granted is the ability to view images or listen to sound, then you have already lost information. Recording the analog signal results in further loss, but as playback and recording equipment gets better and better, the loss becomes less and less perceptible. The ultimate limit here is human bandwidth, not computer bandwidth.

At the moment, recapturing the full glory of an HD DVD is beyond most people's capability. There are just too many bits going up on the screen and compressing would take too long. But grabbing enough to re-sell as a cheap pirated copy is clearly within many people's capability, and Moore's law will come into play sooner or later.

Attempts to plug this "analog hole" tend to be draconian, e.g., restricting the use of digital recording devices, and don't tend to get very far. Not that that will keep people from trying.

Hypertext is an interesting counterexample. I could record my viewing of a web site, and probably even analyze the results and reconstruct the links I've followed. What I can't do, however, is know what's behind the links I didn't follow, or even where they point.

Monday, November 5, 2007

Degrees of access control

Following on to the previous post, I wanted to explore just what kinds of control one currently has over one's data and could potentially have. Here are some possibilities:
  • None. If I post an anonymous comment somewhere, anyone can read it, copy it, quote it or whatever they want. If I've been careful, it can't be traced back to me, so conversely I (generally) have no claim to it.
  • Open access, but traceable origin. This blog is strongly tied to my online identity, which in turn is more-or-less strongly tied to my real identity. If I were to write something libelous, I would have to answer to it, but on the other hand if someone were to try to pass something here off as their own, I would have a believable claim to authorship. Note that an anonymous message can still be traceable, if it's digitally signed but the identity behind the signature is kept secret.
  • Access by software key. Now things get interesting. If I send you an encrypted message, only you have access to it. But once you decrypt it for your own access, there is nothing technically preventing you from doing whatever you want with it. For example, you could charge people to look over your shoulder and read it off your screen, without giving them permanent access to it. As always, copy protection works by tying information to a physical object. This leads to ...
  • Access via dedicated hardware. This is access by key, but the key is strongly tied to a physical device, which presents the data only in analog form. One successful example of this is the set-top box. If "trusted" hardware devices are widespread, this actually gives quite a bit of flexibility -- to whoever holds the keys. One could grant permission to a group of devices (say, all of my family's music players), or transfer permission between devices.
The point of that last point is that DRM is not binary. There is quite a bit of potential for flexibility in control. The contentious issue is not control per se, but whose control.

Sunday, November 4, 2007

Stallman on Trusted Computing and DRM

I previously mentioned Paul Vixie's speech to the Commonwealth Club about (among other things) one's continued free access to one's own data. Of course, he's not the only one so concerned. Along with other prominent people, Richard Stallman has been beating this drum for some time now, for example in Can you trust your computer?.

This essay takes aim at trusted computing, which Stallman calls "treacherous computing" and which I'll refer to here as "TC". It's the same initiative that Vixie mentions, though not by name. Given the history involved it's no surprise Stallman should take the position he does, but when not one but several of the major pioneers of the net as we know it are sounding a caution, it's a good idea to think particularly carefully about what they're saying.

Reading Stallman's piece, I feel a bit of dissonance that I'm not completely sure how to resolve. My particular viewpoint coming in includes these basic tenets:
  • Information is hard to constrain. I don't believe there's some undefinable essence in information itself that causes it to thwart restrictions, but as a practical matter, anything that appears on the net unencrypted has the potential to spread very far very fast (whether anyone will pay attention is a different matter, one of human bandwidth).
  • Technology is largely neutral. As the lady said, any tool is a weapon if you hold it right. The converse also holds. Apparent controversies about technology often turn out to be controversies about law, society and ethics.
  • It's hard, and often counterproductive, to fight market forces; market forces, like technology, are largely neutral.
So whence the dissonance? On the one hand, I'm very sympathetic to the idea that trying to use technology to stop people from using technology inappropriately is risky at best and open to abuse at worst. Technology doesn't know when it's being used inappropriately. I also share the more general skepticism toward promises to do something for me for my own good.

On the other hand, I don't find the arguments Stallman advances against initiatives like TC particularly satisfying either. Thence the dissonance.

Let's back up a bit and look at what TC is. There are two basic components:
  • Content -- whether music, email, code or whatever -- is strongly encrypted.
  • The keys needed for decryption are tightly tied to particular physical pieces of hardware (using a combination of hardware support, further encryption and digital signatures).
For example, suppose I buy the right to listen to a song someone has recorded. In the TC world, this means that my song player will get a key enabling it to play the song, possibly along with further instructions such as "only play this song N times" or "don't play this song after such-and-such date". Since the ability to play that encrypted song rests solely with my player, I can copy the song file and share it all I want, but the experience of hearing it is still tied to that physical player (or others that have been authorized).

Personally, I don't have a problem with this scenario per se. I'm fine with pay-per-view movies on TV, for example. I don't feel I have some basic right to store and copy any collection of bits that happens to enter my house. The movie I watch on PPV isn't mine. I didn't write it, direct it, produce it or act in it. My cable provider is selling me the opportunity to watch that movie at home during a given time period. That seems fair.

Whether you approve of the particular way my $4 gets distributed among the cable operator, the studio, the creative people involved, their agents, the catering truck on the set and so forth is a separate, non-technical issue.

I believe this is one source of dissonance. To check this, I went back and re-read the GNU Manifesto. If you haven't read it in a while (or ever), please do so and take a moment to appreciate how much it got right over twenty years ago and to consider how much of today's landscape was shaped by it. I'm writing this using Firefox running on Ubuntu, for example. If you work for, say, Red Hat, in a real sense you owe your job in part to this document.

[FSF's position on copyrights is more sophisticated than what I describe next. I had originally tried to fix the text up, but later realized that it's more bloggish just to let the text stand as written (or as close as I could un-fix it) and continue the conversation, as for example here. -- DH 18 Nov 2007]
One of the bases of GNU is that software copyrights are not only not useful, but inherently harmful. One reason given is that a piece of software is fundamentally different from a book, play, musical composition or what-have-you. Another is that network technology has changed the economics of copying.

It's an easy extrapolation from this second point to the notion that copyrights are not only inapplicable to software but to anything else as well. For centuries, copyrights could be enforced (logically enough) by limiting the means of copying. That avenue is open to serious challenge now, and TC as applied to DRM is clearly an attempt to put the genie back into the bottle.

I'm skeptical of genie-bottling exercises in general, but I'm not ready to give up on the idea of copyrights as a legal and economic construct. Much of the backlash against TC, however, seems to be based on the idea that copyrights in general are harmful -- at least when used in particular ways. Stallman says as much in a footnote, and others have mentioned it more prominently:

A previous statement by the palladium developers stated the basic premise that whoever developed or collected information should have total control of how you use it. This would represent a revolutionary overturn of past ideas of ethics and of the legal system, and create an unprecedented system of control.
But the whole point of existing copyrights is that the creator of a work retains control over what happens to it. A common magazine contract is for "first serial rights", meaning that the buyer (a magazine) has the right to print the article once, but that the author retains the right to publish it again, for example in an anthology. When I buy that magazine, I in turn have the right to read it, but not to copy it or quote it outside the fairly well-delimited area of "fair use". Otherwise I am breaking the law and subject to stiff penalties.

This is fairly complete control over the physical realization of an author's ideas, and this is the current law, not a revolutionary break from it. So what's different in the digital world? My guess is that in the physical world, copyright is quite tightly controlled when it comes to large publishers -- a magazine publishing plagiarized work will be subject to major lawsuits and a seriously damaged reputation -- but pretty lax once you enter the home.

Who hasn't made a mix tape/CD? No one cares, even though an anthology is a "derived work", at least as far as I understand US law. TC has the potential to seriously disrupt this. It is not the idea of authors retaining control that is new and unsettling. It is the high degree of automated, fine control. TC can impose restrictions like "you can only listen to this song at these precise times on this particular player, and the player can report any attempt to get around this" as opposed to "if you try to make and sell a lot of copies of this song, you'll be in big trouble if we catch you." At the very least, this will require a lot of further hashing out in the courts and the markets.

There is a lot more to be said here. I haven't even touched on the very legitimate concerns about civil liberties and Orwellian nightmares. Again, I don't believe the problems are quite as new as they might seem nor the world quite as unprepared, but these too bear careful scrutiny. More to follow, I hope.

Thursday, October 11, 2007

Pumping data through the Hetch Hetchy Aqueduct

Paul Vixie made a very interesting speech to the Commonwealth Club in San Francisco last year. As it was aimed at a general audience, he started out with some familiar points. I'll repeat them here [with a couple of comments] because they lead up to the more interesting conclusions:
  • Cash flow is more important than cash. The word for the day is monetize: to extract cash flow from.
  • One's ability to monetize things in the physical world is governed by regulations, including anti-trust regulations, balancing the good of society against the good of the individual.
  • Owning a physical CD or book or such is ownership in the dictionary sense.
  • This is regulated by copyright law, a fair system which has made a lot of money for content creators while supplying a lot of content to people who might not have had it otherwise.
  • This doesn't work in the virtual world, where perfect copying is cheap.
  • In the case of music, this is mostly a concern to the major labels and their artists. Smaller artists give away music digitally to promote concerts and sell T-shirts [see also Radiohead's latest release]
  • Big music, after trying to stop digital copying [actually, those lawsuits are still shaking out] has decided to try to make money off of digital music.
  • They do this by letting you listen to what you want but controlling the means of playing it. A typical software player reports your downloading, maybe shows pop-ups, and ties you to one of the commercial OS's -- and its upgrades. Again, the word is "monetize".
  • (For his part, Vixie just buys CDs and plays them on his Linux laptop. And respects copyrights.)
So far so good. But then he goes on:
  • This model of monetizing content applies to all content on computers, even content you produce yourself for your own use, that is, your email, text documents, etc. How does that work? It works because ...
  • Viruses, worms etc. are a major problem for computer users these days, a problem that many companies are trying to solve, that is, monetize.
  • Consumers just want their computers to work, but there's not actually any money to be had in solving that problem. A computer that Just Works is like a razor blade that never gets dull.
  • One part of the solution is to rent virus protection. In a fuller solution, OSs would ideally only run trusted applications registered with the OS vendor -- for a fee, of course. This is already how game boxes work.
  • Carry this over to the application world, and you end up renting the ability to access your own content, which is now stored in encrypted and/or proprietary form.
  • Fortunately, this is very difficult to pull off on current platforms. It would really require a whole new kind of hardware/software platform. Best to start small. Say, with music ...
And finally, Vixie draws a contrast between San Francisco's decision in the early twentieth century to build, operate and therefore control its own water supply, and its decision in the early twenty-first century not to build and operate its own wireless internet infrastructure, instead putting it out to bid.

In light of the points above, this may not be such a good idea. That doesn't mean that software vendors, record labels and so forth are evil, just that they're for-profit entities and must be expected to act as such.

Friday, September 28, 2007

This iPhone will self-destruct in five seconds

Two questions come to mind about Apple's recent iPhone update which, as Apple had warned, makes hacked iPhones inoperable:

Who's better off for this? Owners of hacked phones now have $500 paperweights. Granted, they were warned and I would think were in violation of some license or service agreement. There are reports that some owners of non-hacked phones have lost contact data and possibly the use of their phones. Apple comes off looking like The Man instead of The Rest of Us, thereby calling down the wrath of hackers everywhere, but what were they going to do? The one group clearly to gain is makers of whizzy phones that aren't locked to a single carrier and/or don't self-destruct if you try to unlock them.

Just how does the self-destruct feature work? Apple asserts that the hacked phones are now "permanently inoperable". Did the update fry some hard-to-replace chip? If not, just what claim is Apple making? Clearly the self-destruct update will have left affected phones unable to receive further updates the usual way. But is it impossible even in principle to re-load the OS, for example by copying the image from a working phone? I would expect it to be difficult -- dongle-based copy protection is a lot easier to pull off for something highly integrated like a phone -- but could not even Apple do it back at the factory? [My understanding is that they just re-flashed the firmware and that Apple could fix such a phone at the factory (but has no reason to). In some cases, such a phone might also be fixable without help from Apple.]

Wednesday, September 26, 2007

A use case for provenances

It's the not-too-distant future. I'm walking down the street, vaguely aware that there are all manner of webcams around me. As it happens, I'm touring my city with a friend from out of town. "Oooh!" my friend says, "Let's take your picture in front of that statue!"

I say OK and we do. What makes that picture different from the dozens or hundreds of thousands that various webcams took as we strolled?

When my friend took my picture, the camera got in touch with my personal datastore, using the appropriate PK mojo and one of my friend's keys. My personal datastore stored the picture for me and sent it (or a pointer to it) to my friend's datastore, bundled together with "On this date, <my friend> took this picture with permission from <me>" all signed with one of my keys. The random webcam pictures lack that permission.

Again, that doesn't mean that no one can take my picture and look at it. That's just a fact of going out in public, even today (though ubiquitous webcams do change the picture, so to speak). What it does mean is that if they share such a picture, my permission will be conspicuously absent. Publishing? Swim at your own risk. Publishing content without permission will probably be grounds for a civil suit, at least.

Of course, there's the issue of The Man getting access to those pictures, since The Man don't care about permission. But that's a separate issue.

As before, the point here is that while using encryption to try to prevent unauthorized copying has, at the least, a few hurdles to overcome, it may well be better to de-emphasize that and use signatures instead to leave a paper trail of authorized copying.

If you can copy music all you want, but commercial players won't play music without proof of purchase (or proof of permission, for non-commercial works), then yes, you can always get a bootleg player, but it ought to be much easier to control those than the music itself. Or, if you prefer, players can just report whether there's permmission and let the listener's conscience be their guide.

In the case of pictures, where you can't control whether someone takes your picture, you can at least say convincingly whether they had your permission to do so. In this scenario, your browser (or whatever does what browsers now do) will be able to tell you the provenance (or lack of provenance) of a particular piece of content.

It won't cure all ills, but it seems useful.