Re: [OS:N:] DRM and Open Source
"Les Bell" <[email protected]>
| Newsgroups | gmane.org.open-source-now |
|---|---|
| Message-ID | <[email protected]> |
James Michael DuPont <[email protected]> wrote: >> > I don't see how DRM - in and of itself - can make open source > unusable. because it is impossible to make an "open source" program that cannot be modified to LIE about its own state. << In that case, the DRM algorithms violate Kerchoff's Second Principle, stated in "La Cryptographie Militaire" (1883), which states that the security of the cipher must not depend on the secrecy of the algorithm. This is considered very basic to current cryptographic algorithms such as RSA, 3DES, Blowfish and Rijndael, all of which are published and extensively discussed, and for which there are open-source implementations. In other words, you can know the algorithm backwards, but you're still going to need the key to decrypt the ciphertext. While simple approaches, such as distributing content along with a matching one-time session key, are so obviously weak it's not funny (just give your friends the key along with the content), I'm not so sure more sophisticated approaches can't be achieved using open source. We can certainly provide *security* as good or better than proprietary programs, via OpenSSH, OpenSSL, FreeS/WAN, etc. I'm sure the open-source community could do something similar which allows content creators to distribute their work and achieve an equitable situation in which content is available at a fair price and creators can earn a living. Best, --- Les Bell, RHCE, CISSP [http://www.lesbell.com.au] _______________________________________________ Subscription and Archive: https://www.redhat.com/mailman/listinfo/open-source-now-list/ - For K12OS technical help join K12OSN: <https://www.redhat.com/mailman/listinfo/k12osn>