// COMPLETE THREAD

Re: Verilog encryption broken

3 expanded posts ยท every known parent and child

NODE 5a1ac7d8Re: Verilog encryption broken
> A recent anonymous posting in the comp.lang.verilog newsgroup on Usenet
> has generated a raging controversey and threatens to shake up the
> electronic design automation (EDA) community.  The posting was a program
> that broke the encryption scheme used to protect the proprietary
> libraries that are part of Cadence Design Systems high-end IC design
> tool Verilog-XL.  Verilog is a sophisticated CAD tool that allows
...

This does bring up an interesting ethical question.

What should one do when one discovers that a vendor is marketing
an encryption scheme for the protection or to limit the use of
specific information, which is easy to break.

Obviously, one is neither doing the vendor nor the customers of that
vendor a favour by posting a detailed account of the weakness of
the system.

One the other hand, if one justs sits on the information, it is clear 
that other people will be able to deduce the weakness in the system 
and actually use it to steal information; and why not, I suppose 
anyone who puts trust in "smoke and mirrors security" probably 
deserves exactly what they get. 

The world abounds with weak encryption algorithms which are being 
used to protect information of consderable value. The case with 
Verilog, and their use of an easily "crackable" scheme is far from 
unique. 

Still I don't have an answer. Say one discovers that a vendor is 
protecting its customers' information using a simple "crackable" 
linear encryption function. Is that information something to reveal, 
something to keep secret or what? If one were to approach the
vendor in question with that kind of information, I can imagine
all sorts of legal entanglements that might arise. 

There are other instances which are similar. Information on the
(in)security of various operating systems comes to mind.

Comments?

-- 
Mark Henderson      markh@wimsey.bc.ca (personal account)
RIPEM key available by key server/finger/E-mail
  MD5OfPublicKey: F1F5F0C3984CBEAF3889ADAFA2437433
NODE 61a107d7Re: Verilog encryption broken
In article <m0ohWe6-0001EbC@vanbc.wimsey.com>,
Mark C. Henderson <markh@wimsey.com> wrote:
: What should one do when one discovers that a vendor is marketing
: an encryption scheme for the protection or to limit the use of
: specific information, which is easy to break.

Whatever you want to do. Contrary to what I suppose is a popular
opinion, this is not an ethical question *unless* you have some
sort of contractual obligation that makes it so or unless your
personal, *private* ethics says something on the subject.

People who rely on trade secrets are making a bet. The bet is as
follows: first, that all people who have access to the trade
secret will respect the agreements, both by not disclosing their
trade secret and by protecting it from disclosure; and, second,
that if someone does violate one of those agreements, he has deep
enough pockets that suing him will make up for the loss. When the
trade secret is exposed, *it is gone*. *Forever*. That's the law.
Those who once had a trade secret cannot legally demand of
(uninvolved) others that they help them protect it.

I would guess that it is *Verilog* whose ass is in the fire. If
you or I were to use that script to extract information from their
libraries, *unless* we had an agreement with Verilog not to, it
would be perfectly legal to do so. And it would be perfectly
legal to broadcast that information. However, Verilog, by not
adequately protecting the information in the libraries, may well
be liable for the disclosure. What it looks like from this
distance is that Verilog is running scared, trying to frighten
would be extractors into not spreading the information they would
get so that the amount of damage Verilog will have to take will be
limited.

Verilog, their customers, and library providers, made a bet. They
lost. No one (who is uninvolved) has *any* obligation to help
them minimize the loss from losing their bet. I have no doubt
that Verilog would like to have the discussion turn away from the
simple business aspects toward a touchie-feelie mass-debation
about ethics but to do so would simply be evading the real issues.
NODE 2a823170Re: Verilog encryption broken
Uh, anyone save that particular article?  <grin>
-- 
Ed Carp, N7EKG			erc@apple.com			510/659-9560
                            anon-0001@khijol.uucp
If you want magic, let go of your armor.  Magic is so much stronger than
steel!        -- Richard Bach, "The Bridge Across Forever"