Showing posts with label byteshield. Show all posts
Showing posts with label byteshield. Show all posts

Wednesday, September 24, 2008

Furthering the DRM Debate

I received a very timely response to my previous post from Christian Olsson this time around, so I'll address his points again in a new post. Again, Olsson in italics:

You’re right, there does not seem to be much academic research and perhaps that’s why companies have resorted to what you describe as ‘commercial research.’ The Goizueta Business School, Emory University, Atlanta GA academic research report “An Empirical Examination of Global Software Piracy: Implications for Pricing and Public Policy” doesn’t focus on software protection but it does investigate the effects of piracy and has some conclusions that you might find interesting.
The paper referenced is interesting indeed. The paper does seem to make the assumption that downloading digital content is the equivalent of lost sales, which I've made clear I think that there isn't a causal relationship between the two. There's no data to support the assumption that those who pirated the software would have purchased it if a pirate version were not available at all. I think it is folly to assume lost sales because of the download of a virtual product. I'd admit that there are still support costs involved, but that's not what the paper is addressing.

I haven't kept up to date on my math since college, so I apologize if I have interpreted the data incorrectly in any way. The paper sets up two stages with choices of either pirating or purchasing software in order to calculate the probability that an individual would pirate or purchase software. The results are interesting.
Remember that higher δ implies that a majority of the piracy costs are suffered in the first stage, i.e., more likely that people don’t pirate at all and a lower δ implies that a majority of the piracy costs are suffered in the second stage, i.e., consumers are more likely to be deterred from holding on to a pirated copy.
I'f I'm reading the paper correctly, then it seems that δ is low for all the years analyzed, which would mean that most of the piracy costs are suffered in the second stage.

The authors conclude:
Our findings show that lower piracy is not merely a result of consumers not pirating at all, rather it is a result of pirates turning buyers in the second stage. The latter is possibly due to the fact that post-updating, those who turn buyers perceive a greater value for the product than those who remain pirates (an indication of piracy’s sampling effect) and/or consumers are stopped by the deterrence costs in the second stage and hence end up buyers. Our results suggest that there is ample evidence of both.
This seems to state part of the argument that I think a lot of proponents of less restrictive copyright law make -- that digital file-sharing creates new buyers who would not otherwise have been buyers. The paper focuses on the effect of piracy deterrence as a motivator for second stage buyers; however, in the text, the paper states that there is also "ample evidence" that individuals become buyers because they "perceive a greater value for the product." In my mind, that means that exposure to new content has caused some individuals to want to support the artists/inventors who created that content. These second stage "pirates" could very well be individuals who lend out copies to friends and family, a practice which many content producers dislike and view as piracy, despite the fact that (at least in the US) this practice is protected by the First-Sale Doctrine. I'd say that this paper isn't conclusive about the effects of piracy, but offers some interesting insights. The bottom of the paper states that research is still in progress, so we'll have to wait to see the final results.
Russell Carroll's post, that you quote, also explains that Reflexive uses an in-house developed DRM that they have repeatedly improved and continue to use.

[...]

From our point of view the Reflexive example shows that DRM has increased revenue, though not as much as they would like. You are making our point that DRM has decreased piracy and increased sales. If Reflexive used ByteShield’s much stronger SUM protection they’d see more sales with very little impact on honest users. [emphasis in original]

I revisited the Carroll posts again, paying close attention to the details. Olsson pointed out that one of the commenters of the original post mentioned that DRM had increased sales by more than 80%. But as other commenters mentioned, an 80% increase on 8% sales isn't a whole lot. The piracy rate of the games that Carroll analyzed was at a staggering 92% to begin with. As Carroll wrote himself:
The 1000:1 ratio is really, I think, the key takeaway of the article. Several people have grasped that and started applying it to different numbers in the industry, and the results are very disappointing.
I agree with Carroll that the ratio is what is really important here. Again, I don't mean to dissuade efforts to prevent piracy; however, I have to wonder what the cost/benefit ratio is when such few sales are the result of implementing increasingly difficult to crack DRM. Even the section of that article that Olsson quotes from Carroll doesn't seem to make the case that further DRM has increased sales significantly:
Clearly, if we could always have a big gain from a fix that maintains itself, it is worth spending the time to fight piracy. However, since that isn't always the case, it can sometimes (often?) be pretty discouraging to try and stop piracy.
In my view, Carroll states that if there is a big gain, fighting piracy would be worth the cost. But as his research demonstrated, that's a big "if," and Carroll seems to believe that a big gain isn't always (or even often -- his own words) the case.

Olsson's other points don't require that I go into great detail. I think that Olsson's points really demonstrate that ByteShield is committed to implementing a DRM scheme that has a lesser impact on the user while also attempting to respect long held consumer rights. Olsson acknowledges the problem with the industry's current approach to "license" software rather than sell it, and I think that is promising. Court rulings have already come down against the practice -- i.e., just calling the product a "license" doesn't make it one.

One thing that I still have an issue with is online activation and persistent verification. I think Stardock's approach provides a good compromise in this case. Instead of requiring online activation, Stardock's games require online registration in order to stay "always up-to-date" and to receive any other free, additional content for purchased games. Users only need to have registered a valid CD-key, which isn't an inconvenience at all. Being online isn't a prerequisite for playing the games, and Stardock is able to have the same kind of protection for its games that online activation provides. It's the carrot approach -- want free updates and additional content? You have to buy the game. At the same time, no additional limitations are forced onto users.

Furthermore, as Olsson has stated, the developer/publisher still has ultimate control over the level of DRM implemented through SUM, and I think that offering tools like online activation and persistent verification leave room for violation of rights. I will say that I no longer think that consecutive offline runs appear to be a problem, since Olsson clarified that this mechanism does not limit the number of installations, only the number of installations running simultaneously.

Monday, September 22, 2008

What Cultural Values Do We Want to Protect?

Christian Olsson of ByteShield was kind enough to respond to my analysis of the company's white paper on DRM and PC piracy. I'll take each answer one at a time (Olsson's points in italics):

DRM can reduce some types of illegal copying. If it is extremely easy to circumvent the protection, many amateurs will do it. If the protection is more challenging, some people will not be able to get around the DRM and some of these will actually purchase the game/software, rather than find it on a torrent site. While virtually all DRM solutions have been cracked, the piracy problem might have been yet larger if all games/software had been distributed unprotected.
I'm not entirely convinced. I do accept that certain forms of copy-protection are more difficult to circumvent than others; however, I don't think that necessarily translates into fewer people cracking the protection. I've seen how hackers crack copy-protection while also synthesizing the steps necessary so that any user could repeat the steps with little technical knowledge. Even if we accept that more "amateurish" users will be unable to circumvent the copy-protection, I still find it unlikely that those users would then go out and purchase the software. And this brings me to the next point of Olsson's:
The real question is how much of piracy would turn into sales. Given piracy rates for certain games and software, the proportion does not need to be large before the impact is significant. For example, a UK study has shown that for every purchased copy of games, 10 pirated copies are used. AutoDesk has publicly stated similar numbers for AutoCAD. If only 1 of every 10 illegal copies turn into sales, revenues would double.

We have seen references to a European consumer research study, which claimed that 30% of piracy would turn into revenue. We find that number hard to believe, but if it is anywhere near true, the revenue potential is quite high.
I'm not familiar with the UK study referenced (or the European consumer research study, for that matter), but I would be interested in reading the paper. Still, I wonder if these studies are market research or academic -- it would be quite interesting if the latter and not the former. I've not seen any academic research that asks the question at hand, only commercial research, which is usually of questionable validity.

If the conversion ratio really is 1:10, then perhaps Christian is on to something. But as I wrote before, Russell Caroll, director of marketing for Reflexive Entertainment, found the ratio to be much larger:
As we believe that we are decreasing the number of pirates downloading the game with our DRM fixes, combining the increased sales number together with the decreased downloads, we find 1 additional sale for every 1,000 less pirated downloads. Put another way, for every 1,000 pirated copies we eliminated, we created 1 additional sale.

Though many of the pirates may be simply shifting to another source of games for their illegal activities, the number is nonetheless striking and poignant. The sales to download ratio found on Reflexive implies that a pirated copy is more similar to the loss of a download (a poorly converting one!) than the loss of a sale.

Though that doesn’t make a 92% piracy rate of one of our banner products any less distressing, knowing that eliminating 50,000 pirated copies might only produce 50 additional legal copies does help put things in perspective. [emphasis mine]
Reflexive found that ratio to be 1:1000, not 1:10. But I also think that Olsson is framing the question wrong. It's not how many pirated copies are used for each purchased copy, because that doesn't tell us whether or not those who pirated the games would have bought them at all. The proper way to look at this is the way that Carroll investigated the piracy of Reflexive's games -- how many sales did additional (i.e., more difficult to crack) DRM generate? The number appears to be quite small.

My own experience with people who regularly downloaded games without purchasing them paints a different picture than the one that Olsson assumes. If these individuals were unable to crack the copy-protection, they would usually just move on to another game, not purchase the game that they could not crack. The only data that I've seen on this is from Reflexive, and their conclusion supports my anecdotal evidence.
Your discussion is right on – the real issue is how easy or difficult is it to copy? A hardcover book is a lot of work to copy, a loose leaf article much easier and an electronic article requires almost no effort to copy. Thus, digital content is much easier to copy. The task of good DRM is to make it more work to copy, so that anybody desiring the content will purchase it.
This answers Wardell's question, "Is the goal of IP protection to increase our revenue or is it to prevent people who aren't going to buy games from playing them?" And that answer is to "make it more work to copy," i.e., "prevent people who aren't going to buy games from playing them." I don't think that the case has been made that making DRM more difficult to crack will result in increased sales. If the Reflexive experiment says anything, it's that we shouldn't assume preventing piracy results in new sales.

But to the point I was making -- my consumption of digital content does not deprive another of the same consumption. Because digital content is so easily produced and distributed, we can have an unlimited number of virtual copies. Physical content, by contrast, has limitations -- only one person can use a book at any time, and there is no easy way to make a copy for another person. Therefore, because of the limitations of physical content, my consumption of the book does prevent another from the same consumption. If I take a book from the library, no one else can take out that book. If I download a copy of the book from the internet, the book is still available for everyone else. This is a key distinction that copyright law does not address. The nature of digital content is different from physical content, and thus, should be regulated differently.
The key word is ‘tools’. Everything can be broken ‘manually’ and/or by brute force. The key inventions in ByteShield aim to make it necessary to solve a large number of ‘puzzles’, one at a time. Yes, it can be cracked, but the work effort required is very large.
Here, Olsson essentially concedes my point. Whoever cracks the copy-protection will likely make it easy for others to do so as well, otherwise the hacker's effort won't be of use to most anyone else. For example, a crack isn't a detailed description about how to modify an .exe file, it is the modified .exe file. I don't mean to dissuade ByteShield's efforts, but at a fundamental level, it's all the same.
ByteShield’s answer is both – prevention will increase revenue, control of free, full-feature trials encourages purchases.
I've already discussed how why I don't think DRM will increase revenue, so I won't go over it again. However, I do think that full-feature trials could encourage purchases.
ByteShield believes protection is valuable if approached our way i.e. extremely large effort to crack, no or minor impact on honest users and no impact on PC game and software developers.
The last part of that sentence is key. I think that ByteShield understands the concerns of honest gamers, and so far their SUM protection scheme does appear to have a lesser impact on users than other schemes such as SecuROM and StarForce.
ByteShield will in such cases assist the Publisher in changing the ByteShield SUM protection from limited usage to free and unlimited usage.
This is also very good to hear. Value has said the same thing about Steam, which is one reason that I think a lot of people are willing to put up with Value's DRM. EA, on the other hand, has made no such promises and has a history of ending online support for past games. I think that is part of the reason so many people are upset with the way that EA handles copy-protection.
Online connectivity is becoming ubiquitous because of the benefits it affords users – always on, always up-to-date, always connected, etc, etc and ByteShield is simply taking advantage of that situation to enable copyright protection along with multiple user benefits such as ‘unlimited activations’ – yes an occasional internet connection is needed but this is a necessary component of balancing the rights of both copyright holders and honest users without all the other limitations of DRM systems.
I understand that ByteShield is taking advantage of the "always connected" aspect of some people's computers; however, this is still a limitation that did not exist before. I can take a book anywhere. I can read it in the car, on a train, or in my living room. If online activations and persistent re-activations are enforced, I will be unable to be so flexible with my digital content as I am with my physical content. This is what has been called a technological quick-fix, and as it is currently stated, conflicts with the values that we commonly associate with our cultural content.

Not to mention that not all users will have an "always connected" broadband internet connection, or even an internet connection at all. I don't have to phone Random House every time I open a book, so why should I have to phone EA every time I want to play a game?
About a year ago, a unit of the Department of Defense invested 2 months in trying to crack ByteShield and, as far as we can tell, they did not succeed (the results are classified).
I guess I'll have to take ByteShield's word for it. That does seem promising, though.
This is crucial to our product and why we view ByteShield as considerably more end user friendly than other solutions. End users can install the game/software on an unlimited number of computers and keep on adding installations, as hardware changes or system crashes etc. occur. The real item to control is not the number of installations; it is how many of these installations can be used, at the same time. Thus, with ByteShield, the permission to run moves from one PC to another, seamlessly. The publisher can decide, per activation code:

a) How many users will be allowed
b) How many active installations each user will be allowed
c) How quickly the permission to run moves from one user to another and from one computer to another
Ah, ok. This makes more sense to me now. ByteShield checks for multiple installations of the same software activating at the same time. While ByteShield allows for more permissive use of software, the decision appears to be up to the publisher/developer, ultimately. Would EA choose to be so permissive? Doubtful, considering that users can only have one account per copy of Spore, which was virtually unheard of beforehand. Think of it as getting only one save file with Doom.

Again, we're allowing technology to dictate our values instead of using law. I don't predict good things when we allow publishers/developers to have this kind of control, especially when the potential exists to circumvent long established user rights and expectations.

The most important point I want to get across is that digital content is different from physical content. Copyright law does not address these differences. DRM and other copy-protection schemes violate users' long held consumer rights more than they prevent piracy.

Ultimately, we need to decide what values we want to protect. Do we want to be able to use our cultural content as we see fit? Do we want to protect our seemingly natural inclination to share, modify, sample, and create further derivative works from existing works? Do we still believe that the works of artists/inventors are a public service, and that as an incentive to create such works the public grants said artists/inventors with a monopoly on production and distribution for a limited time?

Friday, September 5, 2008

Copyright Law in the Virtual World

Christian Olsson of ByteShield, Inc. took the time to write an interesting comment on my last post about PC gaming, copy-protection, and piracy. I wanted to respond through another post because I think his comment raises some interesting questions. I'll start first with ByteShield's whitepaper, Is Anti-Piracy/DRM the Cure or the Disease for PC Games?, that Christian mentioned in his comment.

In the introduction of the white paper, it acknowledges that DRM schemes have failed and are rapidly cracked; however, at the same time the white paper acknowledges that piracy would be worse than it is today if no such measures were taken. I can't seem to understand how these two realities can coexist. If DRM has failed, then how has DRM made piracy less of a problem? I don't follow the logic being used here. Again, I see this acknowledgment that DRM has lessened piracy somewhat to be a vapid "conventional wisdom" of the gaming industry, much like peer-to-peer file-sharing is seen as a decrease in sales in the music industry.

The white paper also makes passing mention of digital technology "decimat[ing]" the music industry, as well as mentioning the "threat" to DVD sales. I've written about the music industry before, and there is conflicting evidence about the loss of CD sales due to digital file-sharing. I'm more convinced by the studies that have shown that CD sale losses have lessened as a result of file-sharing, and remember that CD sales were already declining before applications like Napster hit the scene. I'm not familiar with DVD sales, but I'm not convinced that file-sharing is causing a decrease in sales, either.

I'll reference this post again, because I make a point towards the end of the post that I think needs repeating. All too often it is assumed that piracy of digital content equals lost sales. I'm not convinced of this at all because those making this assumption have never provided any evidence to support what is underlying this assumption -- that those who have pirated the content would have purchased the content if there were no means to obtain it otherwise. The music industry makes this assumption all the time -- that a downloaded song is less revenue in their pockets. But they have no reason to think that the individual who downloaded the song would have purchased it in the first place.

There's another piece to this that I think needs to be mentioned as well. Digital content is different from physical content in a number of ways, and the most important is also the most obvious -- digital content is virtual. Why is this important? The virtual nature of digital content means that my consumption of this content does not in any way deprive another of consumption and enjoyment of this content. Perfect copies can be infinitely created at almost no cost. Digital content will never be a scarce commodity, and here lies the problem.

Our entire copyright system is based upon the assumptions and limitations of physical content. Physical content is limited in quantity, deteriorates over time, and the analog nature of physical content means that any copies of the content will be of lesser quality than the original. All of these things make the original more valuable than any copies, which is different from digital content. All the digital copies will be exactly the same, making them the same value. Content producers are trying to force digital content into the limitations of physical content. Copyright works by creating artificial scarcity -- it grants authors/inventors the exclusive right to produce and distribute copies for a set amount of time. DRM schemes are attempts to create that artificial scarcity; however, the nature of computers and software means that copies have to be made in order to run the program. Digital content exists within a realm of infinite copies. Furthermore, making copies of digital content is easier than ever. Just as the printing press lowered the barriers to entry in the book publishing world, computers and software have lowered the barriers to entry in the digital content world.

DRM schemes will always be hacked, bypassed, and subverted. As I argued in the older post, this is because of the nature of encryption. DRM is encryption, but in order to make that encrypted content useful content producers have to provide a means for the consumer to decrypt and read the content. DRM fails because DRM will always give hackers all the tools to crack their code. Without providing those tools, the content is useless and unreadable to consumers who have obtained the content legally.

To bring this all together, I think Brad Wardell sums up everything concisely:

The question our industry needs to ask itself is pretty straight forward: Is the goal of IP protection to increase our revenue or is it to prevent people who aren't going to buy games from playing them?
The white paper does make some good points. There's discussion about the lost trust between gamers and developers, and I think that is a key point. Gamers don't want to feel like criminals, nor do gamers want to be punished with draconian DRM for legally purchasing a game. ByteShield recognizes that, and I applaud them for it. ByteShield also appears to recognize that copy-protection will be hacked at some point in the game's life cycle, but the company doesn't think that DRM is ultimately futile.

The protection scheme in the white paper appears to use some features of the current DRM schemes like StarForce and SecuROM. The key to ByteShield's SUM (Software Usage Management) seems to be a connection to a remote server to run the various security checks. That in-and-of-itself us a huge potential problem for DRM. What happens when ByteShield turns off its servers? Or moves over to a new system, much like what the MLB did for its downloadable game service? What happens when ByteShield goes out of business? There's no guarantee that any of the content protected by SUM will be anything but useless to the consumer.

Also included in the protection scheme are limited number of activations and repeated verification. Gamers screamed to high hell when BioWare announced they were going to use repeated verification for Mass Effect, and the same protest was heard when EA revealed that Spore would do the same thing. Ultimately, that part of the copy-protection scheme was dropped. I don't think that ByteShield is going to have much success with that.

ByteShield is very confident that their copy-protection will be virtually unhackable to all but the most determined programming sadists. I'll be curious to see how their system holds up.

The white paper also goes through a number of common complaints against DRM and discusses ByteShield's response to those complaints. The company claims that SUM will not install hidden drivers or files, and will install transparently. In this spirit of transparency, games loaded with SUM will be clearly marked on the box for consumers. They also claim that they will retain the ability to remove the DRM at any point in the game's life cycle, that the DRM files will not run unless the game is running (gee... where have we heard that one before?), that SUM will not edit the user's registry, that SUM will not require the CD/DVD to be in the drive, that SUM will be uninstalled with the game, and the SUM will not refuse a game launch because of programs like drive emulators. If true, this is all well and good.

There are a couple of things mentioned that trouble me -- number one being the required internet connection to activate the game. Not everyone uses the internet at home, or even has access to broadband. Some gamers have a separate "gaming" PC, which is never connected to the internet. Patches and updates can usually be downloaded from another computer and then transferred to the computer without an internet connection. If repeated verification is used, then I think there is too much of a burden placed on users. What should someone, who has legally purchased a game, do if they lose their internet connection and SUM decides that a verification is in order? Moreover, people should not be required to have an internet connection for a game like Mass Effect, which is entirely single-player.

Another thing that is troubling, and maybe I'm just not entirely clear about it, is the limited user/installation distinction. ByteShield claims that the number of users will be limited, not the number of installations. I'm not sure I understand how ByteShield will go about differentiating the two. Other DRM schemes track the number of installations as if they were users. In any event, I see the potential that a legitimate user could be denied re-installing a game at some point. I need further explanation about how this actually works.

ByteShield is also offering a lot of options to developers -- the ability to offer full feature trial versions is good for the industry. Many gamers complain that demos do not accurately represent what the game is, and therefore, they become less likely to make a purchase. One thing that I think would be beneficial is the full disclosure of all the options a developer has chosen. Since it seems that each developer can customize the copy-protection using ByteShield's system, it would continue that spirit of transparency to be open and up front about what gamers can expect to be able to do with each protected game.

In the end, I feel that ByteShield will be different enough from StarForce and SecuROM to actually respect some consumer rights; however, I think the same potentials for exploitation exist within the SUM system. In addition, I think that these kinds of protection schemes are still missing the point -- digital content is too different from physical content to be treated as the same in copyright law. We need more than just a re-appropriation of existing laws to digital content; we need to recognize that digital content and its copyright needs to be handled differently than physical content, lest we stifle creativity and innovation by overprotecting content.

[UPDATE]: Further reading here (Talkjack's 16 point PC Gamers' DRM Charter, referenced in the white paper), and here (discussion of StarForce DRM by Talkjack).