5 ms·
So, no one ever dares to ask this, but I'm going to because I never see mention of it crop up in these sorts of discussions. Where do you draw the line between
by downer94 13y ago
So, no one ever dares to ask this, but I'm going to because I never see mention of it crop up in these sorts of discussions.
Where do you draw the line between an individual's assertion of privacy over confidential information, and contrast it with the premise of intellectual property and the use of encryption to achieve goals traditionally perceived as less noble, such as DRM?
Where does the distinction emerge, that my social security number and HIV status deserve protection, but an episode of Game of Thrones does not?
I'm not asking this question because I don't understand the distinction. I'm asking this question because it's not often discussed.
If information wants to be free, then what is our objective measure, to define the reason why we might choose to confine some, all or none of our information, especially when employing encryption?
- genwin 13y agoThe 4th Amendment implies that conversations about anything including the bits to Game of Thrones should be free from snooping, if only when those conversations are encrypted. Law enforcement can get a warrant when they have sufficient evidence of illegal activity.
- downer94 13y agoYeah, Phil Zimmerman's article mostly addresses intercepting vulnerable transmissions over a wire or through the air waves. Not so much about breaking encryption, and attacking a static target. I think Phil Zimmerman's assumption (at least, withing the context of this article) is that if you're attacking an sample of encrypted information, that act alone comes with the implicit understanding that you're probably acting against the interests of the person who locked the information away in the first place. Whether that person or group of people are worthy of the attack is its own judgement call.
- grahamburger 13y agoDRM and encryption aren't the same thing. I don't think anyone would complain that Game of Thrones is stored in an encrypted format on it's servers, or transmitted using encryption to broadcasting stations. Conversely, I doubt you would want your social security number or HIV status stored under DRM - you might lose access to that information in the future.
- downer94 13y agoI know that DRM isn't explicitly defined as encryption, but encryption is usually the apparatus that achieves the goal of DRM. In most modern situations DRM schemes involve carefully implemented encryption. But ultimately, the content is being defended with encryption. If there's a dossier in an office somewhere, because I visited a doctor, I would want the clerks charged with handling that dossier to exert control over it. If they're saving it to disk on a server in a basement IT closet, I'd want it encrypted. Meanwhile, if I was an employee at a production company, producing a television episode, I'd probably be expected to exert the same degree of control over the fragments of unfinished content, as they trickle in from the soundstage and are finished up in post production, but then, they undergo a different type of encryption, when locked up in DRM for release to paying subscribers. The question is more an ethical one, not a technical one. If we have encryption as a tool we might use, when is its use respectable, and when is its defeat admirable, and why? Why is it cool when we crack DVDCSS, but awful when the NSA breaks into Google and bypasses their SSL firewall? Are we just hypocrites who want to have their cake and eat it too, or is there an appreciable measure of difference between the two?
- swombat 13y agoEncryption is a tool, like a knife. The use of it is what makes an action useful or not: to cut a steak, or to stab an innocent person.
- eps 13y agoApples to oranges. Game of Thrones series are inherently meant for distribution, while my emails and your HIV report are not.
- downer94 13y agoBoth are intended for controlled distribution. I expect my doctor and the testing center to control the dissemination of my protected healthcare information. The production company and the TV station expect its viewers to contol the dissemination of their artistic works. Is one expectation less reasonable than the other?
- gibybo 13y agoI draw the line between things that are intended to be private, and things that are intended to be publicly available. If HBO intended to only share Game of Thrones with their friends and not the public, then it's their right to encrypt it and only make it available to those people. If their intention is to share it with me because I paid for it, it's a little bit ridiculous to give me access to the decryption key (perhaps embedded in a blu-ray player I own) and then tell me how and when I'm allowed to use it under penalty of law.
- acrucker 13y agoThe real question here is not one of information freedom, but one of trust. If I were to send you a GPG-encrypted email, it's a relationship of mutual trust: I know that you have full access to the information, and can do with it what you want. However, the ISP/NSA/GCHQ/KGB do not have access, because they are naturally not trusted. DRM is different: if I distribute content to you using DRM, I am saying that I do not trust you to have the unencrypted content. Furthermore, DRM implies control over the hardware and software used to play content.
- r0s 13y agoPersonally I feel trading a single copy of any IP with a friend or individual should be covered under fair use. Broadcasting, or reselling should be covered by legal protections against.
- lelandbatey 13y agoThat seems so right, but it gets fuzzy so fast as to be impractical. Does that mean you can only give one copy to one person? If not, then can you give one copy to as many people as you like? If that's true, what's wrong with using bittorrent to do all of that quickly and more easily?
- r0s 13y agoNothing, in my opinion. Making protected IP easily and publicly available rails pretty hard against the copyright legal framework, it's almost incompatible. I'd rather see a more nuanced legal approach. Ideally, a more balanced and fair system would probably lead to a greater respect for the law overall. Off the top of my head: Running a few torrents is, and should be, ignorable. Running a huge amount of them should be a small fine, like a traffic ticket. Any kind of commercial operation or reseller should be shut down. I'm actually fine with public trackers being outlawed, as long as search engines aren't neutered. If someone finds a tracker, and passes some kind of vetting process to gain access, it's clearly not publicly accessible so shouldn't be subject to legal investigation without a warrant. Just my arm-chair policy on a lazy saturday :)
- 6d0debc071 13y agoIf HBO want to encrypt stuff on a system they own, or transmit it encrypted, that's their business. However, a computer system should always serve the owner. And the only way you can do effective DRM; leaving it viewable to me but only under your conditions; is through subverting my computer from my control - otherwise I'll just be able to read the key. DRM constitutes an attack on the loyal functioning of someone else's machine, in a way that the owner of that machine is not meant to counteract. Which is distinct from just having an encrypted file, which represents no such compromise to the loyalty expected of the computer it happens to be on at any particular time, (indeed encryption sort of assumes that it'll end up on an unfriendly machine in some form or another, else there'd be no point.)
- downer94 13y agoI agree. In that scenario, I feel absolutely no need for restraint in attacking someone else's encrypted information. Namely, when that someone else is an uninvited eavesdropper. I refuse to tolerate the idea of placing a high-powered machine in my living room, if that machine won't tell me what it's doing or who it's talking to. In that moment I feel completely justified in my attempts to break encryption, read the information collected about me, and reverse engineer or destroy the device. This is an aspect that OP's article doesn't cover: Consumer products bundled with mandated encryption that operates against the interest of the end user, with designs to eavesdrop on the user simply to capture their ambient behavior as a rule, and disinform the user of the information collected about them, whether it be accelerometer information, GPS information, or channel changing habits. This is the inverse of Phil Zimmerman's goal. Pervasive, continuous observation and telemetry, especially that which occurs without the consent or awareness of the observed.