Perimeter
1/18/2012
05:45 PM
Robert Graham
Robert Graham
Commentary
50%
50%

A Firsthand Piracy Experience

Limited government support of intellectual property helps, but not the strong protections in SOPA/PIPA

Much has been written about SOPA/PIPA today, but I thought I’d give a personal perspective.

Thirteen years ago, I created the “BlackICE” products: “BlackICE Guard” was the first network IPS and “BlackICE Defender” was (one of) the first personal firewalls. My ability to sell these products depended on the government’s protection of intellectual property. I experienced exactly the problems targeted by those laws.

For example, foreign sites would crack the license key and sell pirated copies of the personal firewall, whose users would then come to us for software updates and support. This is the reason for Microsoft’s “Geniune Advantage” program targeting "victims of software piracy." It doesn’t target the casual user who pirates his own copy of Windows and puts it on multiple machines. Instead, it’s copying the foreign resellers of pirated CDs selling them on the streets of Shanghai.

However, while piracy was a problem, it was also an opportunity for BlackICE. Our target market was corporations, not home users.

Corporations might pirate software in order to try it out, but eventually they have to pay for it. In one memorable incident, the CSO of a Fortune 500 company admitted to pirating a few copies of our personal firewall to test it out in his lab -- as he signed the check for 10,000 legitimate copies for the company. Indeed, most security professionals in our industry who got their start in the late 1990s pirated my software at one point or another.

So why not simply make a free trial version available, or a shareware version? Mostly, it was perception. When you give something away for free, customers expect it to be free. It’s hard convincing customers to pay for something if you are already giving it away on the Internet. Conversely, when your software becomes the most pirated software on the Internet (as BlackICE was for a time), it creates a perception of value.

The moral of this story is that, yes, we need limited government support of intellectual property. Without such support, we could never have sold any product and never would have developed it. But on the other hand, we neither needed nor wanted the strong protections in the SOPA/PIPA bills. We didn't want these laws then, and since so much cybersecurity content is created by collaboration, such laws will be damaging to our future.

Robert Graham is CEO of Errata Security.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Mya
50%
50%
Mya,
User Rank: Apprentice
1/19/2012 | 5:34:17 AM
re: A Firsthand Piracy Experience
Sharing about your experience in the industry and your opinion about the government for intellectual property was interesting
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8802
Published: 2015-01-23
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

CVE-2014-9623
Published: 2015-01-23
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quote and cause a denial of service (disk consumption) by deleting an image in the saving state.

CVE-2014-9638
Published: 2015-01-23
oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.

CVE-2014-9639
Published: 2015-01-23
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

CVE-2014-9640
Published: 2015-01-23
oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.