RE: Managing licenses in Gnutella

"Philippe Verdy" <[email protected]>
Newsgroups gmane.network.gnutella.devel
Organization Ordinateur Personnel
Message-ID <[email protected]>
De la part de Arne Babenhauserheide
> Philippe Verdy posted about manageing licenses in another thread, and I
> criticised him harshly, because he proposed trying to solve a problem
> (license management) with a worse problem (DRM).
> 
> That said, I think that managing licenses is a good thing. It just must
> not be
> done with DRM.

When I used the term "DRM" it was not referring to the current system,
because it is definitely not implemented the right way, and fails even at
its definition. DRM means "Digital Rights Management", but those digital
rights are all but manageable, and the rights they are supposed to protect
are not even trustable.

In fact, with those deployed systems, they are easily abused, first by the
vendors of those licences, which are sending us unverifiable licences (and
they even abuse the licences, by producing their own ones, without being
able to prove that they do have the right to do that; in other words, we are
paying licences to them without even getting sure they were not
counterfeighted).

So yes, those deployed commercial DRM systems are a farce: billions of users
are abused by a set of vendors that all have their own management but did
not even created any mesh of trust relationship, and that did not even
provide any backup solution for the "rights" we get.

That's why I spoke about creating a distributed mesh of trustable and
verifiable licences, and about creating a portable portafolio of user
licences. But the vendors are refusing to create this, simply because they
are even abusing the system, and do not even pay to authors the rights they
are supposed to sell us legally. There's absolutely nothing that proves that
what they sell is not illegal, and they are actually selling lots of
counterfeighted licences, paying pennies/cents for the huge amount of
dollars/euros/pounds we give them with our credit cards.

And yes, giving them full control on our computer is a severe problem when
what they are selling is not even secure and verifiable (see the various
issues with Sony rootkits, that not only were spying us and stealing private
data without consent, but also compromised the security of our systems,
exposing them to remote attacks). What they created is even blocking normal
fair competition between providers: once you start with one vendor, all will
be done by it to block us from accessing to licences sold by another vendor
(so you'll be denied all accesses to iTunes-like DRM licences if you get
MS-like DRM licences, and there are now many non-interoperable licences sold
everywhere by major distributors, that have created their own
non-interoperable systems, for example the system used by Virgin, which do
not work with the one from Universal, or from Sony... these just are
examples!)

By principle, those major vendors/distributors have even lobbied the
politicians (with huge campaigns based on lots of lies, that I would really
like to demonstrate that this was true corruption) to force them to adop
laws that will forbid anyone to check if what they are doing is lawful (so
reverse engineering was criminalized). Not only consumers are limited
because they don't even get their basic rights (right to backup, right to
resell their legally acquired products), but they are spied illegally and
forced to trust them even though they are not the legitimate right owners.

So in fact, those current DRM systems are not only abusing final users, but
they are also abusing right owners. You're right when you say it is a farce.
But true DRM systems, that may be trustable can be built; this is not a
technological limitation. If we speak about trustable licences, the first
thing that we need is trust. Trust can't work reliably when there's no way
to choose who we trust, and no way for uses to build their own trust network
(such personal trust network is what we all build in real life), in a way
that allows us accepting someone or removing someone at anytime from our
trust network, and check at anytime what others are thinking about those we
chose to trust in our network.

The only system proposed today is to sign a single and exclusive,
non-transferable and non-repudiatable trust relationship with vendors that
don't legitimately own the rights they are selling, by giving them all
control on our system, including the permanent possibility to cancel
themselves every other trust-relationship we have made with others. When
they delete our rights without our consent (or block them), there's
absolutely no way to recover our rights in the case they made a bad
decision. There's no appeal, and not even a way for us to justify our
pre-existing rights that we have lost.

They created a system into which they can even drop without notice even the
rights they have sold us at some time. So the medias stop working without
notice, and we are forced to buy them again from them or from an unlawful
vendor that has killed the licences sold by another one.

Yes the system stinks. What we need is not medias signed with DRM, but a way
for users to demonstrate that they have the licences associated with the
medias we have. There's absolutely nothing that justifies the need to link
the licences (which are immaterial by nature, given that they are contracts
between parties) to unrelated things (notably medias whose rights are not
legitimately owned by the final user or the distributor, or the hardware we
use to play them).

In the normal market system, we don't build trust relationships by putting
their controls fully in the hands of a single party. If we need trust, we
need an independant and neutral third-party. The distributors are not
neutral third-parties between us and the authors. What they sell prove
nothing, given that they can destroy themselves the "proofs" that they
should keep forever, as long as the rights we get are supposed to be valid.

And in a reliable trust-making system, all parties need a way to negociate
and choose their third-party. The current DRM promoters have repeatedly
refused to adopt existing technologies that allow trust mesh to be created
in a neutral way. Such systems do exist today, these are PKI infrastructures
(including free ones like GNU GPG), where many independent certification
authorities are acting as trustable third-parties to testify that no one
abused its rights or obligations.

So yes "DRM" currently is a farce because it does not make what it is
described to do (and named for). There's NO management in DRM, and NOTHING
to prove that rights exist, and NOTHING to prove that we can effectively get
our rights, given that only ONE non-neutral party can do whatever it wants,
including stealing our rights at anytimes, spying us, and
blocking/cancelling the rights we get from other parties. Those systems are
based on uncontrolled single central all-powered servers, and customers are
just slaves.

A true DRM system really needs something else. To make it trustable, the
only topology that can allow making the necessary per-user trust relation
networks is not centralized and asymmetric client-server models, but a P2P
system where all parties are equally powered.

It will still not avoid some to abuse the system, because this is also
happening in true life. But in true life, we have independent third-parties,
including legal courts and appeal systems. The DRM promoters on the opposite
have the full power to destroy all proofs that they collected about a past
trust-making relationship. It is really unfair, and even illegal.

For this reason, P2P networks must not be made illegal. It would be a severe
coup d'Etat on elementary democratic rights that we and our ancestors battle
for very hard. In fact, P2P topologies is the most elementary construction
brick we use in normal life to protect us and interact with each other,
without becoming dependant of a single party. If we have the right to
choose, it's because we can create many independent meshes of relations. All
the trust we give to anyone is based on equal exchanges and the possibility
to enter and exit from any relationship and nobody can force us to enter
their game; in other words, everyone we meet is forced to negociate with us.
That's not what the current DRM systems propose, which is completely
antidemocratic.

Basically, a reliable DRM system would necessarily need to become a true P2P
system whose topology is a mesh network, like in real life, not a
centralized system which uses unfair competition where independant vendors
can kill the licences sold by another one without being able to prove
anything about the rights they sell, and without even being able to prove to
legitimate authors that they don't abuse them!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.