Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

DRM is broken as a theoretical construct.

MD5 is broken, but the concept of cryptographic hashes is solid. There's no theoretical problem with the idea of a function where f(a) != f(b) implies a != b to an extremely high probability. The only trick is coming up with real-world systems which approach the theoretical ideal.

DRM, on the other hand, is a theoretical impossibility. It aims to show content without allowing it to be copied, which is a concept that makes no sense. In practice it can work to an extent, but this is only done by coming up with real-world systems which run in the opposite direction from the theoretical ideal.

I'm not at all convinced that business owners couldn't care less. They keep raising the bar, both technologically and legally. Breaking DRM, even for purposes that would otherwise be legitimate, has been illegal in the US for over a decade now. And this is ultimately the crux of the problem, and what causes people to frustratedly declare that DRM is a broken concept. It is a crime to express certain mathematical concepts, and the only reason that's the case is because businesses make up for the lack of theoretical rigor in DRM by bringing in the power of the law.

Imagine if the cryptographic community's response to the break of MD5 was to lobby for a law that made it illegal to generate hash collisions or create or distribute code that could do that, because theory prohibited anything substantially better than MD5 from being produced. MD5 is still a useful hash through the present day and well into the future, but in that hypothetical and counter-factual situation, I think it would be reasonable to call the concept of cryptographic hashing broken.



We're talking past each other. I'm stipulating that DRM is "broken theoretically" and arguing that it doesn't matter.

I'm also pointing out that MD5, though "broken" is actually cryptographically viable in some constructions --- in other words, there are cryptographic applications of MD5 that have no known viable attacks, even though MD5 is itself a weak hash. It's a tangent, but I thought a telling one: even though the nerdy vantage point is "MD5 is broken, avoid at all costs!", the reality is that it still works in some settings. Just like DRM.

Finally, if you want to reason through the legalities of DRM laws, start thinking in terms of contract law instead of technology. The reason content owners would like it to be unlawful to break DRM is that they shouldn't need to incur an arms race merely to enforce otherwise binding contracts. The fact is that it is entirely lawful to make access to an entertainment title conditioned on acceptance of a contract not to distribute the title. Violating that contract is unlawful. DRM exists in order to make it harder to violate binding contracts. In fact, the laws regarding DRM even anticipate the hardships DRM creates for normal users, and creates exceptions for breaking DRM in cases of interoperability and security research.

It is no case a "crime" to express mathematical concepts, except under exceedingly silly definitions of the term "mathematical concept" (any piece of content can of course be described mathematically; that doesn't make it lawful for me to steal and publish your credit card number).


The illegality of distributing a title without permission has nothing to do with contract law. It's a basic principle of copyright. No contract needs to be in place, explicit or implicit, to prevent that.

DRM does not solely exist to make it harder to violate that law. DRM also exists to prevent use of the buyer's own rights. DRM prevents fair use as well as infringement, and I'm pretty sure the media companies consider this to be a feature, not a bug.

When I say "mathematical concepts", I'm talking about algorithms, not content. I think that e.g. the core of DeCSS qualifies as a mathematical concept, and it's illegal to express it under current US law, although that law is widely ignored.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: