TMCnet Feature Free eNews Subscription
May 28, 2013

Ransomware, Malware and Hack-Backs: Potential Solutions to Online Piracy?

By Tara Seals, TMCnet Contributor

Should content companies and intellectual property rights holders be given the power to “hack back” at suspected Internet pirates? The Commission on the Theft of American Intellectual Property is saying maybe.

While accusations towards China regarding business espionage make up the bulk of the 84-page report on IP theft, buried in the document is the suggestion that entities like the MPAA or RIAA should be authorized to freely use malware, viruses and other cyber-baddies to punish people believed to be copying content illegally. One top concept? Locking up computers until the offending parties confess and pay a fine in a state-sanctioned ransomware scheme.

The commission—a private coalition of former U.S. government officials and ex-military—explained how this legalized hijacking would occur. “Software can be written that will allow only authorized users to open files containing valuable information,” the report noted. “If an unauthorized person accesses the information, a range of actions might then occur. For example, the file could be rendered inaccessible and the unauthorized user’s computer could be locked down, with instructions on how to contact law enforcement to get the password needed to unlock the account. Such measures do not violate existing laws on the use of the Internet, yet they serve to blunt attacks and stabilize a cyber incident to provide both time and evidence for law enforcement to become involved.”

But why stop there? The commission also noted that companies could be even more proactive, and go probing for pirated material. “While not currently permitted under U.S. law, there are increasing calls for creating a more permissive environment for active network defense that allows companies not only to stabilize a situation but to take further steps, including actively retrieving stolen information, altering it within the intruder’s networks, or even destroying the information within an unauthorized network."

But it’s not just about sniffing out ill-gotten movies and removing them. In addition to the ransomware and spyware concepts, other ideas floated by the commission include using computers’ built-in Web cams to surreptitiously photograph or videotape suspected pirates, presumably in a shame-centric punishment scheme, or worse: implanting malware or actively disabling a computer network entirely.

"These attacks would raise the cost to IP thieves of their actions, potentially deterring them from undertaking these activities in the first place," the commission said.

Needless to say, such a move would have a hard time passing Congressional scrutiny thanks to privacy concerns alone. But the potential for one-sided digital bullying on the part of rights-holders is clearly an elephant in the room. This is something that even the report tacitly admitted.

"The Commission is not ready to endorse this recommendation because of the larger questions of collateral damage caused by computer attacks, the dangers of misuse of legal hacking authorities, and the potential for nondestructive countermeasures such as beaconing, tagging, and self-destructing that are currently in development to stymie hackers without the potential for destructive collateral damage," it said.

Something, however, has to give. Piracy is a real issue, as is online privacy. Is there a solution that meets both sets of issues? Not yet. "[C]urrent law and law-enforcement procedures simply have not kept pace with the technology of hacking and the speed of the Internet," the commission said. "Almost all the advantages are on the side of the hacker; the current situation is not sustainable."




Edited by Alisen Downey
» More TMCnet Feature Articles
Get stories like this delivered straight to your inbox. [Free eNews Subscription]
SHARE THIS ARTICLE

LATEST TMCNET ARTICLES

» More TMCnet Feature Articles