5 ms·
Would it also then become illegal to program software that would defend against such software rooting your machine and erasing things that goes against its view
by maeon3 13y ago
Would it also then become illegal to program software that would defend against such software rooting your machine and erasing things that goes against its views of fairness?
I'd like see them try to root my Gentoo box.
- shmerl 13y agoIt would automatically be illegal to break this spyware (i.e. to defend against it) the moment the spyware itself becomes legal. Since breaking DRM is forbidden by DMCA. DMCA/1201 should be really repealed, as well as any such new idiocy pushed by the DRM lobby.
- kintamanimatt 13y agoJust about every Linux kernel version has had some root privilege escalation bug. So long as they can get some executable software on your system (perhaps not easy!) it's reasonable any such bug could be exploited, and voila, they can install a rootkit!
- eru 13y agoBut they don't have all the same bug.
- kintamanimatt 13y agoOf course not. But it's easy to maintain a list of public bugs for different kernel versions and also a list of 0day bugs that may have been found, and then exploit the appropriate privilege escalation bug depending on the kernel version.
- beedogs 13y agoFor an industry as fucking inept as the MPAA and the rest of the copyright cartel, I'd be absolutely floored if they managed to break into a Linux machine.
- kintamanimatt 13y agoThey have the money to pay people who can though!
- tacticus 13y agoBut not the competence to identify them
- vidarh 13y agoGood luck for them breaking out of the VM their software would end up getting run in.
- regularfry 13y agoThis is not as unlikely as you may think. All it takes is the right bug in a virtio driver, and they can go from vm-root to host-user, and assuming some level of competence they can go from host-user to host-root. Of course, you're welcome not to use any virtio devices, and you're welcome not to use hardware virtualisation support, but the performance of your guest will not be much to write home about.
- vidarh 13y agoOf course it is possible that they find holes, but I consider the odds that they will find holes like that early enough that countermeasures won't already be deployed in a situation where people have come to expect destructive actions from their software on a regular basis to be quite unlikely. Also OS level virtualization is not the only protection worth using in a scenario like this. Sandboxing at the syscall level (restricting allowed syscalls and arguments substantially) is also highly useful, and if we start seeing a threat from apps that people are expected to intentionally install knowing that they pose a risk, we will see a lot more aggressive security work.
- regularfry 13y ago> Of course it is possible that they find holes, but I consider the odds that they will find holes like that early enough that countermeasures won't already be deployed in a situation where people have come to expect destructive actions from their software on a regular basis to be quite unlikely. That's incredibly optimistic.
- vidarh 13y agoHow so? People will be expecting their software to contain rootkits, and so there will be tons of people immediately analyzing any new releases. Given that already when I last bothered with pirated software in the early 90's, serious warez traders were mostly only interested in software weeks before its scheduled release (it was not uncommon for unfinished versions of games to leak), which involved not just getting hold of the releases through leaks or hacking, but breaking any protection, and this would make up the first serious challenge for the warez scene in many years, and this will draw not just the warez scene, but security researchers, as well as a lot of "regular" developers like me who are fed up with these kinds of attempts, they are facing pretty much an army that will be dissecting every release. Sure, some will slip through for some users, but every single instance will result in new counter-measures, many of which you can expect will cover as-yet undiscovered flaws in addition to just fixing specific issues. E.g. a logical protection against attempts at attacking faulty filesystem permissions settings is to blanket ban access to the filesystem and whitelist specific files, specific directories, and sanity check all access to them. For every loss, we will win more robust application sandboxing capabilities, and more people will be motivated to consistently make use of them.
- DanBC 13y agoRemember when you couldn't watch DVDs on Linux? And then someone wrote DeCSS, which provided decryption of DVD for Linux users. It'll be similar if this law passes. There's a binary blob for Windows and OSX. It's illegal to reverse engineer that blob. It's illegal to circumvent the need for that blob.
- troels 13y agoI guess we'll just have to use a VM then. They can "root" that all they want.
- solarexplorer 13y agoOf course, the blob would detect a virtual machine and refuse access to the content.
- drdaeman 13y agoIn a more modern version, VM just won't be able to support a hardware-assisted DRM conveniently preinstalled straight into your CPU or video card's firmware. Hmm. This leads me to the idea. Why care for software rootkits when PCIe hardware may actively screw with the system? Considering MAFIAA already had success with enforcing HDCP on almost every modern video card out there...
- vxNsr 13y agoI actually just read a book set in 2040 England where this basically happened, they'd created a system where if you tried to remove the hardware the CPU would be dissolved. The book was called "Pirate [something]" I can't remember the exact name but it had pirate in it...
- hfsktr 13y agoThe best I could do after a lot of searching (lots of books with pirate in the title): http://www.amazon.com/Pirate-Cinema-Cory-Doctorow/dp/0765329085 http://www.amazon.com/Pirate-Cinema-Cory-Doctorow/dp/0765329... Your description sounds good. This book doesn't sound that good but it is future England, has to do with computers has pirate in the title.
- deleted 13y ago[deleted]