The Internet's premier standards-setting body is concerned that its participants could be subject to criminal or civil lawsuits under the U.S. Digital Millennium Copyright Act as they develop security protocols that can be used to protect copyrighted materials on the `Net.
Although the risk is slim, the Internet Engineering Task Force (IETF) will discuss the issue at an open mike session being held in Salt Lake City Thursday night.
The IETF's leadership became aware of the DMCA threat a few weeks ago, and they have contacted their attorneys as well as experts at the Electronic Frontier Foundation (EFF) for advice. At issue is whether ongoing research in digital rights management or development of encryption protocols puts the organization at risk.
"Our lawyers have cautioned us not to disregard the threat, but the likelihood of the IETF being challenged under DMCA is very small," says Scott Bradner, the IETF's external liaison and a director of the IETF's transport area.
Bradner adds that the public image of a copyright holder that sued the IETF for trying to improve Internet security would be badly damaged.
"There's a theoretical liability, but I don't believe there's an actual liability," Bradner adds.
Passed in 1998, the much-maligned DMCA was a comprehensive reform of U.S. copyright law designed to take into account advances in digital communications. DMCA has provisions that allow the U.S. government to file criminal charges against individuals who circumvent copyright protection systems for commercial gain. DMCA also allows private lawsuits against individuals who investigate the circumvention of copyright protection systems.
The IETF's digital rights management research - conducted by the group's companion Internet Research Task Force - is not investigating copyright protection systems. But "in the design of building good systems, we learn from breaking systems," admits Thomas Hardjono, co-chair of the digital rights management research group and a principal scientist with VeriSign Inc.
The research group is surveying work in digital rights management that is being done in R&D labs, other standards bodies and in industry groups to investigate the impact of these technologies on the IP network architecture. Launched six months ago, the research group has met twice.
At this point, the IETF has no plans to shut down or scale back the digital rights management research effort. However, the IETF leadership is discussing changing the name of the group to lower its profile.
John Klensin, chair of the IETF's Internet Architecture Board, which oversees the digital rights management research, says it's important for the IETF to do a threat analysis but it should continue with its work.
"It's important to be very aware of these issuesÂ…and then to proceed because the alternative is paralysis," Klensin told the digital rights management research group at its meeting Tuesday.
Another option is for the IETF to require companies that pitch their security technologies as potential standards to sign a disclaimer waiving their rights to DMCA claims, much as they already sign a disclaimer on intellectual property claims.
"The DMCA could run the risk of really hurting the standards process by making people afraid to test and publish their research,'' says Cindy Cohn, legal director at the EFF. DMCA disclaimers "would restore confidence that the technologies that are being rolled out as standards have been thoroughly tested and vetted."
Two recent, high-profile DMCA cases have caused anxiety among IETF participants and other network researchers:
-- In July, the FBI arrested Dmitry Sklyarov, a Russian computer science student, for an alleged violation of DMCA. Sklyarov delivered a speech in a Las Vegas hotel pointing out security holes in Adobe Systems Inc.'s eBooks software.
-- In November, Princeton University Professor Ed Felten challenged the DMCA on free speech grounds in federal district court, but the court dismissed the case. Felten and a team of researchers from Princeton University, Rice University and Xerox Corp. discovered security vulnerabilities in the digital watermark technology under development to protect music sold on the `Net. Two recording industry groups - the Recording Industry Association of America and the Secure Digital Music Initiative Foundation - threatened to file suit against Felten and his team if they published their research at a conference. After intense media scrutiny, the two groups allowed Felten to publish his work.
Some members of the IETF community fear that because of these cases, the DMCA will have a chilling effect on security-related research.
"Among academics and scientists in the security area, the level of concern is very high," Cohn says, pointing out that some security workshops will be held overseas next year because of DMCA. "Many foreign scientists will not publish their work because they don't want to get arrested."
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Best Practice in Building an Integrated Information Management Strategy
Achieving the impossible: Unlimited application scalability
Wireless LANs: Is my enterprise at risk?
Email Archiving 101—Customer Case Study
Security Inside Out
Strategies for Eliminating .PST Files
Solve Exchange Mailbox Storage Issues Once and for All
Data grids and service-oriented architecture
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Vignette Announces 2008 Excellence Awards 2008-11-21 10:50:00+11
PGP and Ponemon Institute Unveil Inaugural Australian Data Breach Study 2008 2008-11-20 17:34:00+11
Symantec Cloud Services Transform Data Centre Operations Through Proactive Management 2008-11-20 12:06:00+11
Verizon Business Offers Tips to Building a Successful Unified Communications and Collaboration Plan 2008-11-20 12:04:00+11
AARNet Brings 4K Digital Cinema to Australia: First 4K HD Video Signal delivered into Australia by AARNet 2008-11-20 12:02:00+11
Email Archiving Implementation: Five Costly Mistakes to Avoid
Email Archiving is essential for managing email data, but is potentially expensive to implement. Read on to discover the five key areas where email archiving costs can be contained, including data capture methods and default configuration methods.









