Re: exploit in linux kernel

"Joerg W Mittag" <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization jwm-WARE
Message-ID <[email protected]>
Adam Trilling wrote:
> On Sat, 26 Oct 2002, Bob Kimmel wrote:
>> I must be missing something here.  Details for the exploit
>> are not available, because of the US-DMCA, when source code
>> for the entire kernel is freely available?
> Sounds like a troll to me.  The DMCA only applies to the companies
> who purchased it (ie, the media industry), in cases where you find a
> security hole in a content-protection system.
>
> If the DMCA applied to security flaws in UNIX-based operating
> systems, a number of my friends would be in jail right now, rather
> than being paid large sums of money by companies and universities.

I am neither a lawyer nor a native English speaker so I had quite some
difficulties understanding the legalese in the DMCA. However, I think
this passage is what the hassle is all about:

| No person shall manufacture, import, offer to the public, provide,
| or otherwise traffic in any technology, product, service, device,
| component, or part thereof, that is primarily designed or produced
| for the purpose of circumventing a technological measure that
| effectively controls access to a work protected under this title.

AFAIK the Linux user management is considered to be such an "access
control" and demonstrating a security flaw in the kernel would then
qualify as "offering to the public" a "circumvention device or
technology".

At least, this passage *could* be interpreted like that, and that's
the way Alan Cox and some other hackers interpret it (see also the
thread about Alan's changelog entry for Linux 2.2.20pre11 on LKML).
Whether that's correct or not, I can't say, that's up to the lawyers.

Greets from Europe, where at the moment we don't have such laws (which
unfortunately is very likely to change in the near future).

jwm

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.