Re: [Full-disclosure] Re: Case ID 51560370 - Notice of ClaimedInfringement

Valdis.Kletnieks_at_vt.edu
Date: 04/08/05

  • Next message: lor.tharholm_at_hushmail.com: "Re: [Full-disclosure] I need uh Qwik-Fix please sho 'nuff!"
    To: Jason <security@brvenik.com>
    Date: Fri, 08 Apr 2005 14:53:31 -0400
    
    
    
    

    On Fri, 08 Apr 2005 13:45:51 EDT, Jason said:

    > I get the point just fine. Injecting files C and D results in a
    > situation that cannot be resolved without downloading both files.
    >
    > Song A = mp3 format file with valid license to BSA
    > Song B = mp3 format file without valid license to BSA
    > Song C = zip of Song A plus pad to generate MD5
    > Song D = zip of Song B plus pad to generate same MD5
    >
    > It is now impossible to distinguish between C and D without downloading
    > both. The content inside is still fully usable and valid but a violation
    > cannot be confirmed without yourself violating the law.

    On the other hand, note the following:

    1) The copyright nazi's aren't going to be looking for C *or* D, because they're
    only looking for files that have the same hash as A. They'd have to actually
    download C and D and *listen* to it, and identify it (quick - how do you tell
    the difference between the audio content of the original Beatles "Come Together"
    and the Aerosmith cover of the same song?)

    2) It's of course simple to create an arms race where the copyright nazis need to
    expend more effort because they can't just go after the MD5 sum. However, it cuts
    both ways - if you see 15 copies of a file available with the same MD5 sum, you can
    have *some* trust it's not corrupted. If you see 15 copies with 15 different hashes,
    which one do you trust?

    3) If you change the size, date, and MD5 hash and rename it to "Frozzle-bar.doc",
    you're not likely to get a note from Metallica's representative about the
    pirated copy of their album. But it's probably not going to be accessed very
    much unless you re-rename it to Frozzle-bar-really-metallica-master-of-puppets.doc.
    Of course, at that point, you *may* get a note from their representative.. :)

    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


    • application/pgp-signature attachment: stored

  • Next message: lor.tharholm_at_hushmail.com: "Re: [Full-disclosure] I need uh Qwik-Fix please sho 'nuff!"

    Relevant Pages

    • Re: MD5SSUM-check minimal Ubuntu CD image.
      ... So based on the MD5 sum, it looks like you got the same ISO I did. ... This is the MD5SUM-code I found after downloading this image: ... Neither of these two pages has listed the MD5SUM code for 'mini.iso'. ...
      (Ubuntu)
    • Re: Trojan/backdoor in fragroute 1.2 source distribution
      ... Although downloading it now seems safe, I think folks should know this. ... MD5 sum of fragroute-1.2.tar.gz, ... guaranteed signatures. ... This might be a good discussion for another forum, ...
      (Bugtraq)
    • Re: Setup MD5 Checksum for FTP downloads on Win2000 Server OS
      ... This is what many of them use for windows to check MD5 Sum ... > Now I am looking for a way so that the people downloading these files can also verify the checksum for these downloads - please advice a way. ... > SafeNet India, New Delhi, India ...
      (Focus-Microsoft)
    • Re: Do we trust Red Hat servers ?
      ... > (eg some signature authority). ... in fact come from Redhat Inc. ... of downloading ISOs from one of the mirrors (the md5s are correct, ... GPG/PGP do not use the same trust mechanism as SSL certs, ...
      (comp.os.linux.security)
    • Re: mxtoolbox.com
      ... If you are receiving external e-mail just fine, then I would not trust the ... You might try downloading and running the Exchange Best Practices Analyzer ...
      (microsoft.public.exchange.admin)