On TV.com: 2009's Most PIRATED TV Show
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: Jan 11, 2005 3:57:00 PM

A researcher who published exploit codes that could take advantage of bugs in an antivirus application could be imprisoned for violation of copyright laws.

In 2001, French researcher Guillaume Tena found a number of vulnerabilities in the Viguard antivirus software published by Tegam International, which is based in Paris. Tena, who at the time was known by his pseudonym Guillermito, published his research online in March 2002.

However, Tena's actions were not viewed kindly by Tegam, which initiated legal action against the researcher. That action resulted in a case being brought to trial in Paris. The trial kicked off on Jan. 4. The prosecution claims that Tena violated article 335.2 of the intellectual property code and is asking for a four-month jail term and a fine of about $7,900 (6,000 euros) . Additionally, Tegam is proceeding with a civil case against Tena and asking for about $1.2 million in damages.

According to Tena's Web site, his research "showed how the program worked, demonstrated a few security flaws and carried out some tests with real viruses. Unlike the advertising claimed, this software didn't detect and stop '100 percent of viruses.'"

Tena, who is currently a researcher for Harvard University in Massachusetts, said that Tegam responded in a "weird way" by first branding him a terrorist and then filing a formal complaint in Paris. During the resulting tribunal, Tena said the judge decided that because the published exploits included some re-engineered source code from Viguard’s software, he had violated French copyright laws.

According to French security site K-OTik, Tena had technically broken copyright laws because his exploits were "not for personal use, but were communicated to a third party".

However, K-OTik, which regularly publishes exploit codes, claims that the ruling could create a precedent so that vulnerabilities in software, however critical, could not be declared publicly without prior agreement from the software publisher.

K-OTik’s editors say the ruling is "unimaginable and unacceptable in any other field of scientific research".

On Tena's Web site, he claims that if independent researchers are not allowed to freely publish their findings about security software then consumers will be only have "marketing press releases" to assess the quality of the software. "Unfortunately, it seems that we are heading this way in France and maybe in Europe," Tena said.

"To use an analogy, it's a little bit as if Ford was selling cars with defective brakes. If I realized that there was a problem, opened the hood and took a few pictures to prove it, and published everything on my Web site, then Ford could file a complaint against me," added Tena.

Philip Argy, senior partner of the intellectual property and technology group at Australian law firm Mallesons Stephen Jaques, said that if a similar case was put to trial in Australia, the prosecution would be unlikely to get a conviction because of our "fair comment provisions."

"We have strong copyright protection as well as strong anti-hacking laws, but from what I can glean from the translations, all that Guillermito did was to publish the details of the parts of the code which contained serious bugs that made the software erroneously treat as a virus some legitimate software," Argy said.

The final ruling is set for March 8.

Munir Kotadia of ZDNet Australia reported from Sydney.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 37 Talkback(s)
Eula, Schmula; Any HONEST Judge Would Void Them as Extortion!
You buy the rights to install and run software (according to most EULAs, that is ALL you get, and not even the CD is legally "yours"). To be able to run the software you are COMPELLED to agree to the ... (Read the rest)
Posted by: lodaver Posted on: 01/13/05 You are currently: a Guest | | Terms of Use
OMG  Arrg | 01/11/05
Nopefully Tegam 's shares have just plummeted...  Jomo_z | 01/11/05
OMG  Inventor_z | 01/12/05
LUDICROUS  Jeff Spicoli | 01/11/05
The inevitable car analogy  rapson | 01/11/05
What is the difference between this guy and a whistle blower?  Squawkbox | 01/11/05
Whistleblower?  rapson | 01/11/05
There was a time  Squawkbox | 01/11/05
they can be accurate if...  linuxoverwindows | 01/13/05
so essentially...  linuxoverwindows | 01/13/05
Perhaps a countersuit  Letophoro | 01/11/05
Counter Suit  Inventor_z | 01/12/05
Refreshing twist  ShadeTree | 01/11/05
But it's copyright law.  Letophoro | 01/11/05
Copyright law  ShadeTree | 01/11/05
Copyright law  Letophoro | 01/11/05
Too simplistic?  ShadeTree | 01/11/05
True  Letophoro | 01/11/05
French Law  Inventor_z | 01/12/05
It is also refreshing..  Jeff Spicoli | 01/11/05
No one said...  ShadeTree | 01/11/05
YOU "said"..  Jeff Spicoli | 01/11/05
You read to much into the post  ShadeTree | 01/11/05
Caught you, my young grasshoppa!  Jeff Spicoli | 01/11/05
Key is "researcher"  Roger Ramjet | 01/11/05
Yeah, but you know this is meant to intimidate people into silence  Jeff Spicoli | 01/11/05
Yea, this is bad  Been_Done_Before | 01/11/05
Define Researcher  Nigel Johnstone | 01/11/05
This is completly stupid!  Mectron | 01/11/05
Its about time,  low-life | 01/11/05
Judging  bpierre@... | 01/12/05
if the judge in france finds him guilty, he can appeal to EU Court  hipparchus2000 | 01/11/05
Share it on Emule next time instead of the press.  GreatInca | 01/12/05
ULA  Inventor_z | 01/12/05
Eula, Schmula; Any HONEST Judge Would Void Them as Extortion!  lodaver | 01/13/05
French Corp. Lawyers: Show Me the Money!!!  tbbrickster_z | 01/12/05
proving again that the french are retarded  linuxoverwindows | 01/13/05

What do you think?

advertisement
Click Here
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here