Breaking the Zyzzyva encryption
medium.com
medium.com
I'm not entirely sure about OS X, but at least on Linux, system-assisted dynamic linking (i.e. not mmap(PROT_EXEC)) requires that all required symbols are exposed so that relocation can be done in the original executable; in other words, the OS needs to know where the functions in the library are so that it can tell the program how to call them.
Of course, you could obfuscate the function names, but then tracebacks wouldn't work properly and at that point you'd be better off just statically linking the whole program.
Debug symbols are completely different; if you have those, you can simply do "frame variables" which shows the args with names.
> Yesss. Time to get out the x86 assembly hats.
You don't even really need to do that. Since you know the function signature, you can assume (since it is in a separate library) that the function uses the standard System V AMD64 ABI where "the first six integer or pointer arguments are passed in registers RDI, RSI, RDX, RCX, R8, and R9" [0], meaning that the pKey pointer is probably in RDX. I know that the author said that it was in RAX, but since that is caller-saved, there must have been some copying or processing done to it inside the function.
[0] https://en.wikipedia.org/wiki/X86_calling_conventions#System...
"Dictionaries enjoy copyright protection for two main reasons: Their creators make judgments about what words to include, and entries feature definitions and other original material. (Just last week, a federal court in Massachusetts ruled against[2] a plaintiff who wanted to copy and repurpose the bulk of Merriam-Webster’s Collegiate, including definitions, for his own dictionary.) But in 1991, in Feist Publications Inc. v. Rural Telephone Service Co.[3], the Supreme Court decided that a phone company wasn’t entitled to a copyright on its white pages. That’s because the list of names and numbers lacked an important requirement: originality."
[1] http://www.slate.com/articles/life/gaming/2014/09/major_scra...
[2] http://www.scribd.com/doc/241384392/Richards-v-Webster
[3] http://scholar.google.com/scholar_case?case=1195336269698056...
09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0
Perhaps if they want more people to know they can file a takedown request.
Said another way, even as a very pro-copyright judge, I would have a hard time saying the author did not have a First Amendment right to publish his research. Now if he wrote a program to make it easy to crack these databases and sold it for $5 each, that would be a different matter.
Additionally, to the degree that hasbro/whoever the heck claims a copyright on the work of other people, they are themselves violating various parts of the DMCA dealing with rights management info, etc.
Hasbro/whoever should know that it is not possible to effect a transfer of copyright without an explicit signed agreement. Thus, if all these people contributed, and then they slapped a copyright on it, they own exactly nothing.
(There is such a thing as a compilation copyright, but it it is a very minimalistic copyright, and assumes they actually did anything creative or original to the compiled list)
If someone was to press this point against the scrabble players, they would A. likely lose as the list will be considered non-copyrightable subject matter B. If the list was somehow found copyrightable, and this story is accurate, they would be opening themselves up to copyright infringement lawsuits from the scrabble players who contributed to the wordlist.
So they kinda lose either way.
An explanation how copyright works in this case would be great.
This is really stupid. I mean I get copyright but I think copyright should only apply to "the 'creative' aspect[s]" if the author wants that.
The reason this is not considered copyrightable is that there must be some evidence of creative effort. Owning an infinite number of monkeys and typewriters does not entitle you to copyright everything they generate.
I think its preposterous that someone is able to trademark a word list. I bet its not even complete.
You could instead store only the hashes of the words, using a sha256 or something similar.
An even more interesting experiment would be to copyright the resulting key and the ciphertext, and put in the TOS for getting either one that you will not sue the publisher for any copyright violations.
That is, if I were so inclined :-)
Why not?
> Treating Colour as a function is almost the same as attaching tags to the bits - the difference is that when the Colour is a function of the bits, we don't have to worry about the tags being detached; on the other hand, when the Colour is a function of the bits, we can never have more than one possible Colour for a given sequence of bits. Monolith depends on exploiting this problem: it assumes that one file can only ever have one Colour, asserts that the Colour of its output file is the "you may copy this" Colour because of the (correct) claim that fixing any other single unchangeable Colour would raise legal problems, and then follows the logic to a claim that it can produce what would otherwise be an illegal copy of the copyrighted input, without breaking copyright law. One Colour per file was never one of the lawyers' rules of Colour; it's merely a consequence of "Colour is a function", and Colour being a function is just something we computer people decided to believe because functions make sense to our training and Colour doesn't. Colour is not actually a function at all.
By only publishing the steps, he gets the benefit of the publicity of breaking the encryption. Then anonymous people can easily break it themselves and spread the actual list, free from worry of being sued.