Showing posts with label copyright. Show all posts
Showing posts with label copyright. Show all posts

Tuesday, March 31, 2009

DRM and EULAs for PC Games

Great read over at Ars Technica about the Entertainment Consumers Association pushing for the requirement of full disclosure of DRM on PC game boxes, as well as the standardization of EULA agreements. Hal Halpin of the ECA told Ars Technica:

We suggested a few things to the FTC, one of which was we'd like to see DRM disclosed. So when people go to the store and buy the packaged good, the PC game, they'll see something on the front of the box saying there is DRM inside, and to what degree it will be invasive.

The second thing that we recommended was that EULAs get standardized, so again, rather than have 30 or 40 types of agreements, there would be one standard one for all different types of computer games. People go into the store, buy the game, open it, and they can no longer return it... by standardizing the EULA, consumers will have the confidence to know what it is they're agreeing to before they buy the product.

That didn't go over so well. There was a room of attorneys that kind of gasped when we suggested standardization. One panelist commented that the EULA really were there as consumer information, and that was the one and only time that the FTC jumped in and said "wait a second, this has nothing to do with consumer information, this is purely IP protection." I pointed out that when we ran the IEMA (Interactive Entertainment Merchants Association) we were able to get the size of the boxes standardized, and to get the PC CD-ROM logo on the box. These were not herculean undertakings, and they didn't require legislation. So if we can do those things, then certainly we can do these.
This can only be good for consumers, and I'm particularly pleased to see the ECA raising the conflicts that digital distribution channels like Steam have with the concept of ownership.

Monday, March 2, 2009

Amazon Caves to Copyright Fear Mongers

Last week Author's Guild president Roy Blount Jr. wrote a column for the New York Times arguing that Amazon's Kindle 2 is in violation of copyright law because of the unit's text-to-speech functionality. Blount argued that such functionality was a derivative work -- I won't get into why that is incorrect, since BoingBoing has a nice refutation of Blount's argument.

Today, I read an Associated Press article which reports that Amazon has caved to the Author's Guild:

Amazon.com Inc. changed course Friday and said it would allow copyright holders to decide whether they will permit their works to be read aloud using the second-generation Kindle electronic reader's new text-to-speech feature.
The worst part, though, is this:
The Web retailer also said the text-to-speech feature is legal — and wouldn't require Amazon to pay out additional royalties — because a book read aloud doesn't constitute a copy, a derivative work or a performance.
If the feature is legal, why cave to the Author's Guild? Allowing the author of a work to disable the functionality of Amazon's Kindle isn't good for users of the product. That would be like VCR manufacturers giving television broadcasters the ability to disable home recording for any particular program. Amazon's move here doesn't make any sense. Giving in to the unreasonable demands of overly-restrictive copyright proponents will only give credence to their arguments. Amazon should take a stand; the fact that Amazon's position is clearly of the right side of the law should have made this an easy decision.

I hope this blows up in the face of the Author's Guild and that e-books which allow the text-to-speech feature sell far beyond those that don't.

Thursday, January 15, 2009

Breaking Conventional Wisdom On Sharing, Remixing, and Reusing Content

Nine Inch Nails' CC-licensed mp3 album, Ghosts I-IV, is also the best selling mp3 album on Amazon. A perfect summary is already available, here.

In other words, despite the fact that NIN's CC license meant that the digital album could be freely shared, remixed and reused, it was still the #1 selling album on Amazon.

RIAA, put that in your pipe and smoke it.

Wednesday, December 3, 2008

Constitutionality of RIAA Lawsuits Being Challenged

Joel Tennenbaum is currently being sued by the RIAA for having 7 songs in a shared folder when he was 17 years old. Tennenbaum is now in his 3rd year of graduate school. The RIAA is asking for damages amounting to more than $1,000,000.

Charlie Nesson is representing Tennenbaum and challenging the constitutionality of such lawsuits in the hope of stopping any similar lawsuits in the future. If successful, individuals who have shared music in a personal, noncommercial fashion could no longer be targets in the RIAA's sights.

Nesson and Tennenbaum were interviewed by David Weinberger, Harvard law professor, yesterday. Nesson lays out the grounds on which the lawsuits are being challenged. He makes the comparison between file-sharers today and radio broadcasters in the '50s; both individuals engaged in a similar activity -- sharing music for free. The difference, Nesson points out, is that the broadcasters were given payola, while file-sharers are sued ridiculous amounts of money. He also states that the RIAA's tactics are constitutional because they are a private company using the federal court system to enforce civil lawsuits through coercion, threats, and fear, amounting to extortion tactics.

Both Nesson and Tennenbaum recognize and articulate the concept that the music industry has decided to fight against file-sharing and digital technology in order to continue using their old business model rather than embrace these new technological and cultural changes by adopting a new business model.

I'll be watching their case to see how it develops.

Friday, November 14, 2008

DRM-Free v. DRM-Stricken

World of Goo, a puzzle game, has a 90% piracy rate -- a rough estimate by the developer 2D Boy. What's interesting to note is that the developers reference the Russell Carroll study that I've written about before to show that the piracy rates between DRM-free and DRM-stricken games aren't any different:

this is in line with a previous estimate by russell carroll (director of marketing at reflexive) for the game ricochet infinity. russell estimated a 92% piracy rate and i found his analysis quite interesting (check it out here if you’re curious). one thing that really jumped out at me was his estimate that preventing 1000 piracy attempts results in only a single additional sale. this supports our intuitive assessment that people who pirate our game aren’t people who would have purchased it had they not been able to get it without paying.

in our case, we might have even converted more than 1 in a 1000 pirates into legit purchases. either way, ricochet shipped with DRM, world of goo shipped without it, and there seems to be no difference in the outcomes. we can’t draw any conclusions based on two data points, but i’m hoping that others will release information about piracy rates so that everyone could see if DRM is the waste of time and money that we think it is. [emphasis/grammar in original]
I think the more important sentence in the quoted text is this: "people who pirate our game aren’t people who would have purchased it had they not been able to get it without paying."

Game developers and publishers should keep this in mind because it means that file-sharing isn't the same thing as lost sales, which is the opposite of what most developers and publishers assume to be the truth.

Friday, November 7, 2008

An Obama Administration and Copyright

Before the election, a former college professor of mine mentioned that Joe Biden was a big RIAA supporter. I did a little digging, and Biden's record on copyright is pretty distressing.

Today, though, I read this post over at Scienceblogs, which states that Barack Obama has placed coverage of election night under the Creative Commons Attribution Non-Commercial Share-Alike license. Good news, indeed!

If this is any indication of how Obama views copyright, I hope that Obama will follow his own leanings on copyright law and not those of Biden.

Wednesday, October 22, 2008

25 Arguments for the Elimination of Copy-Protection

A pretty good summary of why digital copy-protection and DRM are bad ideas.

Wednesday, October 1, 2008

EA Admits File-Sharing Does Not Equal Lost Sales

Gamasutra has the story. Mariam Sughayer of EA's corporate communications department states:

Stepping aside from the whole issue of DRM, people need to recognize that every BitTorrent download doesn’t represent a successful copy of a game, let alone a lost sale. [emphasis mine]
Dan Hewitt, the Entertainment Software Association's senior director of communications agreed:
It’s important to remember that it’s not a one-for-one equation. Our calculation isn’t such that we say that every game that’s been stolen [he means downloaded] is a sale loss." [emphasis mine]
This comes on the heels of TorrentFreak's analysis claiming that Spore has been downloaded from bittorrent file-sharing networks more than half a million times. Last week, EA reported that Spore had sold 1 million copies. Now, EA is trying to downplay the record number of Spore downloads.

I have to ask: EA, if a downloaded copy of Spore doesn't necessarily equate to a lost sale, what is the point of your DRM? Are your DRM schemes simply to stop people who wouldn't have bought your games from playing them? That's the only conclusion I can draw, since we can see that your inclusion of SecuROM did not stop people from pirating the game.

Tuesday, September 30, 2008

Penny Arcade's DRM Discussion

I wrote before about part one of Penny Arcade's "The Origin of the CD-Key" series, and I agree with much of what was said in that post. Crecente's post did a good job highlighting what essentially most DRM proponents are ignoring -- that DRM is a flawed form of encryption. All DRM schemes give away all the tools needed to crack them -- for it is necessary to do so if content providers want the content to be useful to legitimate customers. Buyers have to be able to decode the DRM in order to use the content. In doing so, any knowledgeable party will be able to eventually crack any form of DRM imaginable.

Part two was posted last week, and it amounts to a "so what?" argument. Author Chris Remo acknowledges that DRM doesn't work, but also argues that it's no big deal. For example, he argues that it doesn't matter if publishers stop supporting games that require online activation because users can simply find the hacker's crack to play the game. Except, Mr. Remo, it does matter. For one, the described practice is against the law, according to the DMCA. Even if an individual owns the content, the DMCA makes it illegal to bypass digital copy-protection. Secondly, legitimate users should not have to resort to illegal practices to get their content to work. Finally, Remo's suggestion does not address DRM's encroachment on the First-Sale Doctrine. Many of the new DRM schemes effectively kill the second-hand market by requiring activations to be tied to an account and limiting the number of installations.

Part three, posted yesterday, brings the discussion back to a level of reasonableness. Author Daniel James makes several salient points about the nature of digital content and the ultimate effects of DRM. James hints at the concept that copying is a integral part of software, and because of that, is it ultimately futile to try to limit copying. James also hints at the important concept of software being "open." He argues for all software being shareware, and then letting the market reward the best software. This is only a step away from open source software, which would arguably create a boon in innovation by giving more users access to the innards of software. By allowing anyone to improve upon the software, we end up with a better product in the end. Finally, James hits on the concept that DRM really only hurts legitimate customers. The trend towards increasingly draconian DRM is only driving away potential buyers, while doing nothing to stop rampant file-sharing.

Overall, Penny Arcade's "The Origin of the CD-Key" is a good back and forth discussion of DRM and computer software, and I recommend everyone to read all three parts.

Wednesday, September 24, 2008

DRM is PC Gaming's Ouroboros

I've been discussing DRM a lot lately, and I ran across this article on Penny Arcade by guest writer Brian Crecente of Kotaku. I think that Crecente makes a lot of relevant points, especially in this passage:

As long as there are creative works people will want to buy them, protect them and, yes, even steal them. Even this modern use of the word piracy dates back to the 1700s when Daniel Defoe agonized over hand-written, pirated copies of his poems sold on the streets. He called those erstwhile literary thieves "pirates" and "paragraph-men."

Imagine, though, an unsuspecting bibliophile returning home with their copy of The True-Born Englishman only to discover that once they’ve read it, the pages turn to ash. Or maybe they can read it and let a couple of friends borrow it, but that’s it. No more reads, thank you very much. What if they find that there is someone lurking outside their library window, watching them, making sure no one else catches a glance of page 32? Or, god forbid, they try to go and sell the book back?

No, copy protection in the 18th Century was a much simpler thing. There was no technology to obfuscate what a publisher was doing. No ghosts in the machine. No machines. But today, as the ways a game or creation can be stolen increases, so do the little lies, the hidden spies created by those creators.
I think it would be beneficial if we, as a society, had a discourse about what "intellectual property" actually means. What does it mean to "own ideas"? My previous post, "Who Owns Ideas" has a discussion about the role of ideas and expressions in a democracy, and I encourage everyone to listen to the radio program.

Furthering the DRM Debate

I received a very timely response to my previous post from Christian Olsson this time around, so I'll address his points again in a new post. Again, Olsson in italics:

You’re right, there does not seem to be much academic research and perhaps that’s why companies have resorted to what you describe as ‘commercial research.’ The Goizueta Business School, Emory University, Atlanta GA academic research report “An Empirical Examination of Global Software Piracy: Implications for Pricing and Public Policy” doesn’t focus on software protection but it does investigate the effects of piracy and has some conclusions that you might find interesting.
The paper referenced is interesting indeed. The paper does seem to make the assumption that downloading digital content is the equivalent of lost sales, which I've made clear I think that there isn't a causal relationship between the two. There's no data to support the assumption that those who pirated the software would have purchased it if a pirate version were not available at all. I think it is folly to assume lost sales because of the download of a virtual product. I'd admit that there are still support costs involved, but that's not what the paper is addressing.

I haven't kept up to date on my math since college, so I apologize if I have interpreted the data incorrectly in any way. The paper sets up two stages with choices of either pirating or purchasing software in order to calculate the probability that an individual would pirate or purchase software. The results are interesting.
Remember that higher δ implies that a majority of the piracy costs are suffered in the first stage, i.e., more likely that people don’t pirate at all and a lower δ implies that a majority of the piracy costs are suffered in the second stage, i.e., consumers are more likely to be deterred from holding on to a pirated copy.
I'f I'm reading the paper correctly, then it seems that δ is low for all the years analyzed, which would mean that most of the piracy costs are suffered in the second stage.

The authors conclude:
Our findings show that lower piracy is not merely a result of consumers not pirating at all, rather it is a result of pirates turning buyers in the second stage. The latter is possibly due to the fact that post-updating, those who turn buyers perceive a greater value for the product than those who remain pirates (an indication of piracy’s sampling effect) and/or consumers are stopped by the deterrence costs in the second stage and hence end up buyers. Our results suggest that there is ample evidence of both.
This seems to state part of the argument that I think a lot of proponents of less restrictive copyright law make -- that digital file-sharing creates new buyers who would not otherwise have been buyers. The paper focuses on the effect of piracy deterrence as a motivator for second stage buyers; however, in the text, the paper states that there is also "ample evidence" that individuals become buyers because they "perceive a greater value for the product." In my mind, that means that exposure to new content has caused some individuals to want to support the artists/inventors who created that content. These second stage "pirates" could very well be individuals who lend out copies to friends and family, a practice which many content producers dislike and view as piracy, despite the fact that (at least in the US) this practice is protected by the First-Sale Doctrine. I'd say that this paper isn't conclusive about the effects of piracy, but offers some interesting insights. The bottom of the paper states that research is still in progress, so we'll have to wait to see the final results.
Russell Carroll's post, that you quote, also explains that Reflexive uses an in-house developed DRM that they have repeatedly improved and continue to use.

[...]

From our point of view the Reflexive example shows that DRM has increased revenue, though not as much as they would like. You are making our point that DRM has decreased piracy and increased sales. If Reflexive used ByteShield’s much stronger SUM protection they’d see more sales with very little impact on honest users. [emphasis in original]

I revisited the Carroll posts again, paying close attention to the details. Olsson pointed out that one of the commenters of the original post mentioned that DRM had increased sales by more than 80%. But as other commenters mentioned, an 80% increase on 8% sales isn't a whole lot. The piracy rate of the games that Carroll analyzed was at a staggering 92% to begin with. As Carroll wrote himself:
The 1000:1 ratio is really, I think, the key takeaway of the article. Several people have grasped that and started applying it to different numbers in the industry, and the results are very disappointing.
I agree with Carroll that the ratio is what is really important here. Again, I don't mean to dissuade efforts to prevent piracy; however, I have to wonder what the cost/benefit ratio is when such few sales are the result of implementing increasingly difficult to crack DRM. Even the section of that article that Olsson quotes from Carroll doesn't seem to make the case that further DRM has increased sales significantly:
Clearly, if we could always have a big gain from a fix that maintains itself, it is worth spending the time to fight piracy. However, since that isn't always the case, it can sometimes (often?) be pretty discouraging to try and stop piracy.
In my view, Carroll states that if there is a big gain, fighting piracy would be worth the cost. But as his research demonstrated, that's a big "if," and Carroll seems to believe that a big gain isn't always (or even often -- his own words) the case.

Olsson's other points don't require that I go into great detail. I think that Olsson's points really demonstrate that ByteShield is committed to implementing a DRM scheme that has a lesser impact on the user while also attempting to respect long held consumer rights. Olsson acknowledges the problem with the industry's current approach to "license" software rather than sell it, and I think that is promising. Court rulings have already come down against the practice -- i.e., just calling the product a "license" doesn't make it one.

One thing that I still have an issue with is online activation and persistent verification. I think Stardock's approach provides a good compromise in this case. Instead of requiring online activation, Stardock's games require online registration in order to stay "always up-to-date" and to receive any other free, additional content for purchased games. Users only need to have registered a valid CD-key, which isn't an inconvenience at all. Being online isn't a prerequisite for playing the games, and Stardock is able to have the same kind of protection for its games that online activation provides. It's the carrot approach -- want free updates and additional content? You have to buy the game. At the same time, no additional limitations are forced onto users.

Furthermore, as Olsson has stated, the developer/publisher still has ultimate control over the level of DRM implemented through SUM, and I think that offering tools like online activation and persistent verification leave room for violation of rights. I will say that I no longer think that consecutive offline runs appear to be a problem, since Olsson clarified that this mechanism does not limit the number of installations, only the number of installations running simultaneously.

Monday, September 22, 2008

What Cultural Values Do We Want to Protect?

Christian Olsson of ByteShield was kind enough to respond to my analysis of the company's white paper on DRM and PC piracy. I'll take each answer one at a time (Olsson's points in italics):

DRM can reduce some types of illegal copying. If it is extremely easy to circumvent the protection, many amateurs will do it. If the protection is more challenging, some people will not be able to get around the DRM and some of these will actually purchase the game/software, rather than find it on a torrent site. While virtually all DRM solutions have been cracked, the piracy problem might have been yet larger if all games/software had been distributed unprotected.
I'm not entirely convinced. I do accept that certain forms of copy-protection are more difficult to circumvent than others; however, I don't think that necessarily translates into fewer people cracking the protection. I've seen how hackers crack copy-protection while also synthesizing the steps necessary so that any user could repeat the steps with little technical knowledge. Even if we accept that more "amateurish" users will be unable to circumvent the copy-protection, I still find it unlikely that those users would then go out and purchase the software. And this brings me to the next point of Olsson's:
The real question is how much of piracy would turn into sales. Given piracy rates for certain games and software, the proportion does not need to be large before the impact is significant. For example, a UK study has shown that for every purchased copy of games, 10 pirated copies are used. AutoDesk has publicly stated similar numbers for AutoCAD. If only 1 of every 10 illegal copies turn into sales, revenues would double.

We have seen references to a European consumer research study, which claimed that 30% of piracy would turn into revenue. We find that number hard to believe, but if it is anywhere near true, the revenue potential is quite high.
I'm not familiar with the UK study referenced (or the European consumer research study, for that matter), but I would be interested in reading the paper. Still, I wonder if these studies are market research or academic -- it would be quite interesting if the latter and not the former. I've not seen any academic research that asks the question at hand, only commercial research, which is usually of questionable validity.

If the conversion ratio really is 1:10, then perhaps Christian is on to something. But as I wrote before, Russell Caroll, director of marketing for Reflexive Entertainment, found the ratio to be much larger:
As we believe that we are decreasing the number of pirates downloading the game with our DRM fixes, combining the increased sales number together with the decreased downloads, we find 1 additional sale for every 1,000 less pirated downloads. Put another way, for every 1,000 pirated copies we eliminated, we created 1 additional sale.

Though many of the pirates may be simply shifting to another source of games for their illegal activities, the number is nonetheless striking and poignant. The sales to download ratio found on Reflexive implies that a pirated copy is more similar to the loss of a download (a poorly converting one!) than the loss of a sale.

Though that doesn’t make a 92% piracy rate of one of our banner products any less distressing, knowing that eliminating 50,000 pirated copies might only produce 50 additional legal copies does help put things in perspective. [emphasis mine]
Reflexive found that ratio to be 1:1000, not 1:10. But I also think that Olsson is framing the question wrong. It's not how many pirated copies are used for each purchased copy, because that doesn't tell us whether or not those who pirated the games would have bought them at all. The proper way to look at this is the way that Carroll investigated the piracy of Reflexive's games -- how many sales did additional (i.e., more difficult to crack) DRM generate? The number appears to be quite small.

My own experience with people who regularly downloaded games without purchasing them paints a different picture than the one that Olsson assumes. If these individuals were unable to crack the copy-protection, they would usually just move on to another game, not purchase the game that they could not crack. The only data that I've seen on this is from Reflexive, and their conclusion supports my anecdotal evidence.
Your discussion is right on – the real issue is how easy or difficult is it to copy? A hardcover book is a lot of work to copy, a loose leaf article much easier and an electronic article requires almost no effort to copy. Thus, digital content is much easier to copy. The task of good DRM is to make it more work to copy, so that anybody desiring the content will purchase it.
This answers Wardell's question, "Is the goal of IP protection to increase our revenue or is it to prevent people who aren't going to buy games from playing them?" And that answer is to "make it more work to copy," i.e., "prevent people who aren't going to buy games from playing them." I don't think that the case has been made that making DRM more difficult to crack will result in increased sales. If the Reflexive experiment says anything, it's that we shouldn't assume preventing piracy results in new sales.

But to the point I was making -- my consumption of digital content does not deprive another of the same consumption. Because digital content is so easily produced and distributed, we can have an unlimited number of virtual copies. Physical content, by contrast, has limitations -- only one person can use a book at any time, and there is no easy way to make a copy for another person. Therefore, because of the limitations of physical content, my consumption of the book does prevent another from the same consumption. If I take a book from the library, no one else can take out that book. If I download a copy of the book from the internet, the book is still available for everyone else. This is a key distinction that copyright law does not address. The nature of digital content is different from physical content, and thus, should be regulated differently.
The key word is ‘tools’. Everything can be broken ‘manually’ and/or by brute force. The key inventions in ByteShield aim to make it necessary to solve a large number of ‘puzzles’, one at a time. Yes, it can be cracked, but the work effort required is very large.
Here, Olsson essentially concedes my point. Whoever cracks the copy-protection will likely make it easy for others to do so as well, otherwise the hacker's effort won't be of use to most anyone else. For example, a crack isn't a detailed description about how to modify an .exe file, it is the modified .exe file. I don't mean to dissuade ByteShield's efforts, but at a fundamental level, it's all the same.
ByteShield’s answer is both – prevention will increase revenue, control of free, full-feature trials encourages purchases.
I've already discussed how why I don't think DRM will increase revenue, so I won't go over it again. However, I do think that full-feature trials could encourage purchases.
ByteShield believes protection is valuable if approached our way i.e. extremely large effort to crack, no or minor impact on honest users and no impact on PC game and software developers.
The last part of that sentence is key. I think that ByteShield understands the concerns of honest gamers, and so far their SUM protection scheme does appear to have a lesser impact on users than other schemes such as SecuROM and StarForce.
ByteShield will in such cases assist the Publisher in changing the ByteShield SUM protection from limited usage to free and unlimited usage.
This is also very good to hear. Value has said the same thing about Steam, which is one reason that I think a lot of people are willing to put up with Value's DRM. EA, on the other hand, has made no such promises and has a history of ending online support for past games. I think that is part of the reason so many people are upset with the way that EA handles copy-protection.
Online connectivity is becoming ubiquitous because of the benefits it affords users – always on, always up-to-date, always connected, etc, etc and ByteShield is simply taking advantage of that situation to enable copyright protection along with multiple user benefits such as ‘unlimited activations’ – yes an occasional internet connection is needed but this is a necessary component of balancing the rights of both copyright holders and honest users without all the other limitations of DRM systems.
I understand that ByteShield is taking advantage of the "always connected" aspect of some people's computers; however, this is still a limitation that did not exist before. I can take a book anywhere. I can read it in the car, on a train, or in my living room. If online activations and persistent re-activations are enforced, I will be unable to be so flexible with my digital content as I am with my physical content. This is what has been called a technological quick-fix, and as it is currently stated, conflicts with the values that we commonly associate with our cultural content.

Not to mention that not all users will have an "always connected" broadband internet connection, or even an internet connection at all. I don't have to phone Random House every time I open a book, so why should I have to phone EA every time I want to play a game?
About a year ago, a unit of the Department of Defense invested 2 months in trying to crack ByteShield and, as far as we can tell, they did not succeed (the results are classified).
I guess I'll have to take ByteShield's word for it. That does seem promising, though.
This is crucial to our product and why we view ByteShield as considerably more end user friendly than other solutions. End users can install the game/software on an unlimited number of computers and keep on adding installations, as hardware changes or system crashes etc. occur. The real item to control is not the number of installations; it is how many of these installations can be used, at the same time. Thus, with ByteShield, the permission to run moves from one PC to another, seamlessly. The publisher can decide, per activation code:

a) How many users will be allowed
b) How many active installations each user will be allowed
c) How quickly the permission to run moves from one user to another and from one computer to another
Ah, ok. This makes more sense to me now. ByteShield checks for multiple installations of the same software activating at the same time. While ByteShield allows for more permissive use of software, the decision appears to be up to the publisher/developer, ultimately. Would EA choose to be so permissive? Doubtful, considering that users can only have one account per copy of Spore, which was virtually unheard of beforehand. Think of it as getting only one save file with Doom.

Again, we're allowing technology to dictate our values instead of using law. I don't predict good things when we allow publishers/developers to have this kind of control, especially when the potential exists to circumvent long established user rights and expectations.

The most important point I want to get across is that digital content is different from physical content. Copyright law does not address these differences. DRM and other copy-protection schemes violate users' long held consumer rights more than they prevent piracy.

Ultimately, we need to decide what values we want to protect. Do we want to be able to use our cultural content as we see fit? Do we want to protect our seemingly natural inclination to share, modify, sample, and create further derivative works from existing works? Do we still believe that the works of artists/inventors are a public service, and that as an incentive to create such works the public grants said artists/inventors with a monopoly on production and distribution for a limited time?

Monday, September 15, 2008

Who Owns Ideas?

This radio broadcast is a very interesting and informative discussion of ideas, expression, and copyright. Commentary from Graham Henderson, Eric Flint, James Boyle, Siva Vaidhyanathan, Cory Doctorow, Jane Ginsburg, Michael Geist, and Steven Page.


Recommended.

Piracy of Spore Extraordinarily High

According to Forbes magazine, Spore has been shared via bittorrent clients at an increasingly faster rate than other triple-A titles have been in the past:

As of Thursday [9/11/2008] afternoon, "Spore" had been illegally downloaded on file-sharing networks using BitTorrent peer-to-peer transfer 171,402 times since Sept. 1, according to Big Champagne, a peer-to-peer research firm. That's hardly a record: a popular game often hits those kinds of six-figure piracy numbers, says Big Champagne Chief Executive Eric Garland.

But not usually so quickly. In just the 24-hour period between Wednesday and Thursday, illegal downloaders snagged more than 35,000 copies, and, as of Thursday evening, that rate of downloads was still accelerating. "The numbers are extraordinary," Garland says. "This is a very high level of torrent activity even for an immensely popular game title."
TorrentFreak reported last Saturday that Spore had been downloaded more than 500,000 times, and at this current rate the game is likely to earn the title "Most Pirated Game Ever" within a matter of weeks.

EA can't be this stupid. They have to know that their use of SecuROM DRM schemes are not going to stop people from pirating the game. In fact, the Forbes article reveals that Spore was pirated a full three days before it was launched on September 4th, 2008.

But this may not be about piracy at all -- it may be about ending the second-hand market through technological means.

Wednesday, September 10, 2008

"Casual Piracy"

So, I've been keeping up with the Spore DRM fiasco, and I've noticed a number of comments from individuals who identify something they call "casual piracy." In a nutshell, these people believe that lending your legally purchased content to friends or family constitutes copyright infringement. I'm fucking speechless.

This bears repeating -- remember the First-Sale Doctrine. It's a hard fought-for right that grants consumers the ability to do whatever they wish with their copyrighted materials after the first sale. Consumers can give away, lend, or sell their copyrighted materials to whomever they wish without compensating the copyright holder so long as no further copies of the materials are made. This means that, and I can't stress this enough, lending your PC games to friends and/or family for non-commercial use is not copyright infringement.

Hold onto your rights, people!

Tuesday, September 9, 2008

Spore's DRM Backfires

This is very interesting. I wrote before that I decided against buying Spore because of the SecuROM DRM scheme being implemented, and it looks like I wasn't alone in that decision. As of 9:04 AM this morning, there are 1,272 one star reviews on Amazon for Spore.

Reviewer Brian Fox wrote:

DRM is a show stopper. I doubt this game will work for me after a few years given my habit of new hardware purchases and system snapshots. Like others have said, this game is for rent not sale.
Reviewer Fox News Sucks wrote:
The DRM for the game utilizes securom which is essentially a virus that installs itself without warning when you install the game. There is no way to completely remove it without reformatting and it is constantly running in the background if not removed. Sucking up computer resources.

It also is overpriced. This is actually a RENTAL, not a bought game because it only lets you install 3 times. If you install over 3 times then you must call EA customer support and beg them to let you play the game you bought. Did I mention the call is not free? If you live outside the U.S. it will be a very expensive call.
Reviewer N. Bolten wrote:
I was looking to buy the ultra-nerdy $80 package at release... no more now that I've learned of the crippling DRM. A message to EA: if you give your customers what they pay for, they're *not* going to pirate (they've already proven they will buy the game). Games are cracked *before* release, so that is not something you can avoid. Stop screwing your customers under the guise of protecting your copyrights and you'll get my cash. Until then I'll be happy playing games released by people who don't punish me like I've done something wrong for forking over $50-$80.
Further reading -- this blog post by a commenter at the Quarter to Three forums puts the issue into perspective nicely. Author peterb makes a point worth repeating; it's essentially what Brad Wardell of Stardock has been saying all along.
The damnable thing about Spore’s DRM is that it gives up some of the platform’s few advantages for…what, exactly? Is protecting yourself against pirates who are not and will never be customers really worth infuriating your paying customers and squandering your company’s goodwill?
Let's see if EA takes notice of this consumer insurrection against the DRM used for Spore.

[UPDATE]: In the span of one hour's time, another 42 one star reviews have been added to Spore's Amazon page, bringing the total 1,314 one star reviews.

[UPDATE 2]: It's nearly the end of the day here, so I checked in at Amazon one more time to see where the review count is. As of 4:19 PM, there are a total of 1,551 one star reviews. Looks like this little protest is getting some mainstream news coverage.

[UPDATE 3]: Another full day later -- as of 4:36 PM, there are 1,928 one star reviews. Doesn't look like this is coming to an end anytime soon.

[UPDATE 4]: Amazon deletes all reviews on their Spore page. Looks like it happened sometime today, 9/12/2008.

[UPDATE 5]: Looks like sometime over the weekend, Amazon put the Spore reviews back up. There are now 2,133 one star reviews, as of 9/15/2008 at 9:42 AM.

Friday, September 5, 2008

Copyright Law in the Virtual World

Christian Olsson of ByteShield, Inc. took the time to write an interesting comment on my last post about PC gaming, copy-protection, and piracy. I wanted to respond through another post because I think his comment raises some interesting questions. I'll start first with ByteShield's whitepaper, Is Anti-Piracy/DRM the Cure or the Disease for PC Games?, that Christian mentioned in his comment.

In the introduction of the white paper, it acknowledges that DRM schemes have failed and are rapidly cracked; however, at the same time the white paper acknowledges that piracy would be worse than it is today if no such measures were taken. I can't seem to understand how these two realities can coexist. If DRM has failed, then how has DRM made piracy less of a problem? I don't follow the logic being used here. Again, I see this acknowledgment that DRM has lessened piracy somewhat to be a vapid "conventional wisdom" of the gaming industry, much like peer-to-peer file-sharing is seen as a decrease in sales in the music industry.

The white paper also makes passing mention of digital technology "decimat[ing]" the music industry, as well as mentioning the "threat" to DVD sales. I've written about the music industry before, and there is conflicting evidence about the loss of CD sales due to digital file-sharing. I'm more convinced by the studies that have shown that CD sale losses have lessened as a result of file-sharing, and remember that CD sales were already declining before applications like Napster hit the scene. I'm not familiar with DVD sales, but I'm not convinced that file-sharing is causing a decrease in sales, either.

I'll reference this post again, because I make a point towards the end of the post that I think needs repeating. All too often it is assumed that piracy of digital content equals lost sales. I'm not convinced of this at all because those making this assumption have never provided any evidence to support what is underlying this assumption -- that those who have pirated the content would have purchased the content if there were no means to obtain it otherwise. The music industry makes this assumption all the time -- that a downloaded song is less revenue in their pockets. But they have no reason to think that the individual who downloaded the song would have purchased it in the first place.

There's another piece to this that I think needs to be mentioned as well. Digital content is different from physical content in a number of ways, and the most important is also the most obvious -- digital content is virtual. Why is this important? The virtual nature of digital content means that my consumption of this content does not in any way deprive another of consumption and enjoyment of this content. Perfect copies can be infinitely created at almost no cost. Digital content will never be a scarce commodity, and here lies the problem.

Our entire copyright system is based upon the assumptions and limitations of physical content. Physical content is limited in quantity, deteriorates over time, and the analog nature of physical content means that any copies of the content will be of lesser quality than the original. All of these things make the original more valuable than any copies, which is different from digital content. All the digital copies will be exactly the same, making them the same value. Content producers are trying to force digital content into the limitations of physical content. Copyright works by creating artificial scarcity -- it grants authors/inventors the exclusive right to produce and distribute copies for a set amount of time. DRM schemes are attempts to create that artificial scarcity; however, the nature of computers and software means that copies have to be made in order to run the program. Digital content exists within a realm of infinite copies. Furthermore, making copies of digital content is easier than ever. Just as the printing press lowered the barriers to entry in the book publishing world, computers and software have lowered the barriers to entry in the digital content world.

DRM schemes will always be hacked, bypassed, and subverted. As I argued in the older post, this is because of the nature of encryption. DRM is encryption, but in order to make that encrypted content useful content producers have to provide a means for the consumer to decrypt and read the content. DRM fails because DRM will always give hackers all the tools to crack their code. Without providing those tools, the content is useless and unreadable to consumers who have obtained the content legally.

To bring this all together, I think Brad Wardell sums up everything concisely:

The question our industry needs to ask itself is pretty straight forward: Is the goal of IP protection to increase our revenue or is it to prevent people who aren't going to buy games from playing them?
The white paper does make some good points. There's discussion about the lost trust between gamers and developers, and I think that is a key point. Gamers don't want to feel like criminals, nor do gamers want to be punished with draconian DRM for legally purchasing a game. ByteShield recognizes that, and I applaud them for it. ByteShield also appears to recognize that copy-protection will be hacked at some point in the game's life cycle, but the company doesn't think that DRM is ultimately futile.

The protection scheme in the white paper appears to use some features of the current DRM schemes like StarForce and SecuROM. The key to ByteShield's SUM (Software Usage Management) seems to be a connection to a remote server to run the various security checks. That in-and-of-itself us a huge potential problem for DRM. What happens when ByteShield turns off its servers? Or moves over to a new system, much like what the MLB did for its downloadable game service? What happens when ByteShield goes out of business? There's no guarantee that any of the content protected by SUM will be anything but useless to the consumer.

Also included in the protection scheme are limited number of activations and repeated verification. Gamers screamed to high hell when BioWare announced they were going to use repeated verification for Mass Effect, and the same protest was heard when EA revealed that Spore would do the same thing. Ultimately, that part of the copy-protection scheme was dropped. I don't think that ByteShield is going to have much success with that.

ByteShield is very confident that their copy-protection will be virtually unhackable to all but the most determined programming sadists. I'll be curious to see how their system holds up.

The white paper also goes through a number of common complaints against DRM and discusses ByteShield's response to those complaints. The company claims that SUM will not install hidden drivers or files, and will install transparently. In this spirit of transparency, games loaded with SUM will be clearly marked on the box for consumers. They also claim that they will retain the ability to remove the DRM at any point in the game's life cycle, that the DRM files will not run unless the game is running (gee... where have we heard that one before?), that SUM will not edit the user's registry, that SUM will not require the CD/DVD to be in the drive, that SUM will be uninstalled with the game, and the SUM will not refuse a game launch because of programs like drive emulators. If true, this is all well and good.

There are a couple of things mentioned that trouble me -- number one being the required internet connection to activate the game. Not everyone uses the internet at home, or even has access to broadband. Some gamers have a separate "gaming" PC, which is never connected to the internet. Patches and updates can usually be downloaded from another computer and then transferred to the computer without an internet connection. If repeated verification is used, then I think there is too much of a burden placed on users. What should someone, who has legally purchased a game, do if they lose their internet connection and SUM decides that a verification is in order? Moreover, people should not be required to have an internet connection for a game like Mass Effect, which is entirely single-player.

Another thing that is troubling, and maybe I'm just not entirely clear about it, is the limited user/installation distinction. ByteShield claims that the number of users will be limited, not the number of installations. I'm not sure I understand how ByteShield will go about differentiating the two. Other DRM schemes track the number of installations as if they were users. In any event, I see the potential that a legitimate user could be denied re-installing a game at some point. I need further explanation about how this actually works.

ByteShield is also offering a lot of options to developers -- the ability to offer full feature trial versions is good for the industry. Many gamers complain that demos do not accurately represent what the game is, and therefore, they become less likely to make a purchase. One thing that I think would be beneficial is the full disclosure of all the options a developer has chosen. Since it seems that each developer can customize the copy-protection using ByteShield's system, it would continue that spirit of transparency to be open and up front about what gamers can expect to be able to do with each protected game.

In the end, I feel that ByteShield will be different enough from StarForce and SecuROM to actually respect some consumer rights; however, I think the same potentials for exploitation exist within the SUM system. In addition, I think that these kinds of protection schemes are still missing the point -- digital content is too different from physical content to be treated as the same in copyright law. We need more than just a re-appropriation of existing laws to digital content; we need to recognize that digital content and its copyright needs to be handled differently than physical content, lest we stifle creativity and innovation by overprotecting content.

[UPDATE]: Further reading here (Talkjack's 16 point PC Gamers' DRM Charter, referenced in the white paper), and here (discussion of StarForce DRM by Talkjack).

Tuesday, September 2, 2008

Gamers' Bill of Rights

Last Friday, Stardock, video game publisher and developer, announced a Gamers' Bill of Rights. Here's the full list:

  1. Gamers shall have the right to return games that don’t work with their computers for a full refund.
  2. Gamers shall have the right to demand that games be released in a finished state.
  3. Gamers shall have the right to expect meaningful updates after a game’s release.
  4. Gamers shall have the right to demand that download managers and updaters not force themselves to run or be forced to load in order to play a game.
  5. Gamers shall have the right to expect that the minimum requirements for a game will mean that the game will play adequately on that computer.
  6. Gamers shall have the right to expect that games won’t install hidden drivers or other potentially harmful software without their consent.
  7. Gamers shall have the right to re-download the latest versions of the games they own at any time.
  8. Gamers shall have the right to not be treated as potential criminals by developers or publishers.
  9. Gamers shall have the right to demand that a single-player game not force them to be connected to the Internet every time they wish to play.
  10. Gamers shall have the right that games which are installed to the hard drive shall not require a CD/DVD to remain in the drive to play.
I fully support this idea, and do so further because of Stardock's intention to set up an "independent organization" that would regulate publishers and developers who agree to the terms of the Gamers' Bill of Rights.

I want to not only highlight Stardock's efforts, but to take this a step further. Many of these Rights are specifically worded to relate to video games; however, applied broadly, those same Rights are already held by consumers. The only difference here, and the only way I can see that gamers have been relinquished of these Rights, is that video games are, and always have been, a digital medium.

Games come packaged with EULAs (End User License Agreements), which in some form or another attempt to proclaim that the buyer is not actually purchasing a "copy" of the software, but rather a "license" to use the software. On top of these EULAs, games are coming packaged with increasingly draconian DRM (Digital Rights Management) copy-protection such as SecuROM.

The latest versions of SecuROM can be found in games such as BioShock, Mass Effect, and the hotly anticipated Spore. In all cases, the DRM limits the number of installations arbitrarily and requires an internet connection to activate the game. Mass Effect and Spore both attempted to require that the games be reactivated every 10 days, but reconsidered that requirement when massive amounts of vocal protest were directed at the developers. Instead, the games will only require reactivation when new game content or patches are installed.

Both the EULAs and DRM schemes like SecuROM are attempts to circumvent fair use rights of consumers. Rights such as the Doctrine of First Sale, which grant the buyer the right to resell purchased content without the need to compensate the copyright holder. I see Rights 4, 6, and 9 of the Gamers' Bill of Rights as combating this assault on consumers' rights to used content. Download managers, hidden registry keys, and online activation are all tools that can be used to make your legally purchased copy of a game useless to another person. Limiting the number of installations is another method to make a legally purchased copy of a game useless.

I also see Rights 1 - 3, 5, and 7 of the Gamers' Bill of Rights as affirming consumers' right not to be swindled. People expect a working product when they pay for something with their hard earned cash, and it shouldn't be any different with video games. Through digital distribution systems, like Valve's Steam, refunds are not available at all, even if the software distributed doesn't work. Brick and mortar retailers, like GameStop, won't refund defective games either, only replace them, and only within 30 days. If one copy of a PC game won't run on your computer, chances are that the game isn't compatible with your system specs and any further copies won't work either. Without a refund, the buyer is left with a very expensive coaster.

Right 10 of the Gamers' Bill of Rights I see as a right to convenience. If anything is clear, convenience will win out every time. And if the pirate community if offering a more convenient experience than those offered through legal channels, people are going to be less likely to purchase games legally. Right 8 plays directly into this sentiment -- treating customers like criminals with hefty DRM is another form of inconvenience. The more seamless the install process, the more likely people are going to purchase the game.

What I would like to see is game developers, and other software developers for that matter, to state these rights in more explicitly legal terms. In the end, we're really talking about copyright and how those laws should apply to digital content. If software developers set a precedent of respecting long held user rights, I think they can help stop the perception that DRM copy-protection schemes effectively combat privacy. On the contrary, these copy-protections are always eventually hacked, bypassed, or subverted, while their only accomplishment is to violate users' legitimate rights.

Final Thoughts

Over the last week, I read all about Spore's planned use of SecuROM copy-protection. I read many posts and forums about DRM, copy-protection, and piracy. Stardock's reveal of a Gamers' Bill of Rights gave me the perfect way to frame my frustrations at an increasingly hostile game publishing industry.

I have been looking forward to Spore for quite some time now; I had even purchased the Spore Creature Creator to whet my appetite for the game's release on the 7th. After reading about SecuROM's inclusion in Spore, I won't be purchasing the game anymore. EA, Maxis; you have lost this sale, permanently.

I've had my own trouble with SecuROM before, with BioShock, and I don't intend to relive the experience. In my readings last week, I found this website, SecuROM Must Be Destroyed! This article lays out several of the top complaints why a DRM scheme like SecuROM should be resisted by consumers. What will gamers do when authentication servers go offline, such as what happened with MLB's download service and MSN's music store? Limiting the number of installations can quickly descend into a nightmare due to the nature of PCs -- frequent hardware swaps, OS re-installations, and other PC upgrades. At the rate that computer technology advances, consumers shouldn't have their games become useless after a few years because of new OS installations and hardware upgrades. But this is exactly the kind of system that SecuROM is creating.

For a peak into the minds of publishers who embrace these DRM schemes, take a look at this article from The Escapist Magainze, as well as their imagining of an EA Gamers' Bill of Rights. I'll end with this Penny Arcade comic:

Tuesday, August 26, 2008

Legal Victory for Fair Use

Reports the EFF (Electronic Frontier Foundation):

A judge's ruling today is a major victory for free speech and fair use on the Internet, and will help protect everyone who creates content for the Web. In Lenz v. Universal (aka the "dancing baby" case), Judge Jeremy Fogel held that content owners must consider fair use before sending takedown notices under the Digital Millennium Copyright Act ("DMCA").

Universal Music Corporation ("Universal") had sent a takedown notice targeting a 29-second home movie of a toddler dancing in a kitchen to a Prince song, "Let's Go Crazy," which is heard playing in the background. Because her use of the song was obviously a fair use and, therefore, non-infringing, Lenz sued Universal for misrepresentation under the DMCA. Universal moved to dismiss the case, claiming, among other things, that it had no obligation to consider whether Lenz's use was fair before sending its notice. The judge firmly rejected Universal's theory.

Tuesday, August 19, 2008

Aw Fuck...

Muxtape is down. The website's blog says that no artists or labels complained. I hope that Muxtape can come out of this unscathed.

I really feel that the RIAA is overreaching here. This broadening copyright enforcement nonsense is quickly becoming ridiculous. As I have said before, how is Muxtape really that much different from radio? To make another analogy, isn't a website like Muxtape just the piano roll of our times?

Muxtape is merely a digital version of cassette mixtapes. Muxtape has taken pains to ensure that songs cannot be downloaded, that songs are accompanied with a link to Amazon's mp3 page, and that tapes have a variety of song selections (no tracks from the same artist/release on the same tape).

The fact that it is digital shouldn't make any difference, but the fact that it does means that the RIAA is still living in analog fantasy land.

[UPDATE]: The RIAA has released a statement regarding Muxtape:

For the past several months, we have communicated our legal concerns with the site and repeatedly tried to work with them to have illegal content taken down. Muxtape was hosting copies of copyrighted sound recordings without authorization from the copyright owners. Making these recordings available for streaming playback also requires authorization from the copyright owners. Muxtape has not obtained authorization from our member companies to host or stream copies of their sound recordings.
[UPDATE 2]: Ars Technica reports that Muxtape's future is likely grim:
Actually, it looks like Muxtape may indeed be closed indefinitely. The RIAA says it has been in communication with the site over the past several months over the getting the "illegal content" taken down. In order to get the RIAA's official blessing, Muxtape would likely have to sign a licensing agreement and begin paying royalties à la last.fm and Pandora. An agreement would dissipate the legal gray cloud hanging over Muxtape, but the royalty burden may well prove onerous, as industry stalwarts like Pandora are considering closing up shop due to the high royalty rates demanded by rightsholders.
Damn.