Malware Suggests Search Plays a Major Role in Piracy

Image by stefanocar75

Copyright holders have long insisted that search results play a substantial role in driving users toward pirate sites.  Google and piracy advocates have generally countered that search does not drive much traffic to illegal sites because the people who consistently use infringing sites know what they’re doing and will go directly to the content they’re seeking.  This is a reasonable assumption to make about the population of committed infringers out there, but one fact that refutes this premise is the extraordinary volume of malware (a 1-in-3 chance) on infringing sites.  Because malware isn’t there to catch the experienced visitor—it’s there to catch the unsuspecting individuals who may not even realize they’re using illegal sites when they first visit.

For those who don’t know how it works, it goes like this:  A user is interested in watching Moonlight.  If he types “Moonlight” into Google Search, the second-tier results will be links that read “Watch Moonlight Online for Free,” all of which are directed to infringing sites.  If the user actually types “Watch Moonlight” into the search field, then the first-tier results will be infringing links. And quite often, Google will automatically suggest words that prompt the user toward an infringing site. For instance, if the user logically adds the word “movie” (because moonlight is a word and not just a title), then Google will complete the thought with “online,” which then yields top results with links to “watch moonlight movie online” via an infringing site.

Google and the piracy apologists are almost certainly correct that many avid visitors to infringing sites are fairly sophisticated users; they have VPNs, ad-blockers, security software, etc. to avoid detection and malware.  But if these were the only kind of visitors landing on these sites, then the underground market in malware-based trade would not be nearly so robust as it is.

As described in this 2015 post about a report called Digital Bait, commissioned by Digital Citizens Alliance and conducted by RiskIQ, a sophisticated “crimeware economy” exists on the Darknet, where criminals buy and sell goods and services used exclusively for preying on users. To use a blunt example, if a teenage girl visits an infringing site, she has up to a 30% chance of contracting malware. That malware may be a Remote Access Trojan (RAT), which gives fairly unsophisticated hackers control of her computer, including her webcam.  Then, her IP address may be sold in this black market to people who want to spy on teenage girls in their bedrooms. In many cases, a user doesn’t even have to consume the infringing content in order to infect a device. The promise of “free content” may be draw the user into a dead-end malware trap.

If all traffic to pirate sites truly comprised only the knowledgeable users, then the criminals would not have a financial incentive to deploy so much malware on sites that infringe, or promise to infringe, copyrighted content.  The very existence of prevalent malware is an indication that a substantial number of users who have no idea what they’re doing are visiting these sites, which logically leads to the conclusion that search must play a significant role in driving users toward these sites and into the hands of criminals.

Notice that, in this context, we don’t even need to address the subject of copyright infringement, let alone get bogged down in all the tedious rhetoric about free speech.  If Google’s top search results are indeed putting users in harm’s way, this is a consumer protection issue for the Fair Trade Administration and/or State Attorneys General.  And, in fact, Digital Citizens Alliance, after releasing its 2016 report Enabling Malware, began presenting its findings to the AGs.

Yes, it is likely true that once a user—even a fairly unsophisticated teenager—is aware of sites where free content is available, he will probably revisit those sites directly without going through a search engine. But even this kind of anecdotal assumption does not mean the role of search is insignificant, not least because the illegal nature of pirate sites means that they have a tendency to disappear and reappear as authorities in various regions shut them down.  A 2013 study indicated that 19% of the traffic to infringing sites could be directly attributable to search, and if that number were wrong by half, it would still represent billions of visits per year.

Consumers have a right to know the nature of their vulnerabilities when using any product or service, and they have a right to demand that U.S. companies take every reasonable step to mitigate exposure to risk.  To date, Google has refused to take even the obvious step of demoting known infringing sites in their search results, let alone to alter the way in which auto-complete may drive consumers toward these sites.

Google does now feature the legal channels for consuming media, including their own services like YouTube and Google Play, which is a good step but not likely sufficient to protect consumers as hackers become more sophisticated and more ambitious.  In fact, one likely consequence of advertisers becoming more effective at keeping their brands off pirate sites is that the criminals will depend more on the “crimeware economy” to make money through infringing content as a means to deliver malware.

Google is getting a lot of pushback lately—from the EU’s anti-trust decision, from the advertisers, and from the Canadian Supreme Court this week in the Equustek case. (More on that shortly.)  I would not be surprised if the State AGs and other consumer-protection agencies begin to take a more active interest in the relationship between search, piracy, and malware.

Cyberattack Effect in China Reveals Flaw in Piracy Logic

This month, computers around the world fell victim to what experts have called the largest cyberattack on record. Known by its name “WannaCry,” the ransomware* assault went global sending cyber-defense teams into hyperdrive trying to protect systems as vital as hospitals, banks, and telecommunications in Europe, Asia, and the U.S.  One notable consequence of the attack, as reported in The New York Times on May 15th, was that Chinese businesses, public institutions, and universities were especially stymied in responding to the threat for one simple reason:  software piracy.

Paul Mazour, writing for The Times, cites a 2015 study revealing that 70% of the software installed in Chinese computers is not licensed, noting later in the article that use of unlicensed software and other media is so embedded in the culture that many citizens don’t even know it’s illegal.  Clearly, when major institutions, including large corporations and one of three state-run telecom companies are implicated, we get the idea.

The “WannaCry” attack targeted older Windows operating systems, and because the Chinese make such widespread use of unlicensed versions of Windows, the unsupported software lacked the updates and patches that would have at least helped mitigate the effects of the assault. And because so many computers were unprotected, this facilitated a much wider and faster spread of the virus. Granted, there are broader aspects of this story, including China’s supposed desire to build a domestic alternative to Microsoft. But taken in isolation, this incident strikes me as a cautionary tale, albeit a stodgy and maternal one.

Imagine if everyone did it. 

Yeah, it’s an ancient, parental finger-wag; but it is also a basic concept that copyright advocates have been trying to explain to the pirating public for years.

In the same way that China’s high volume of piracy left so many users extra vulnerable in this security context, there is likewise a tipping point at which a certain volume of piracy in any market will end, or dramatically curtail, new production of the works being pirated.  Based on one very typical comment I read this week, though, it seems that people are still confused about the contrasts between a black market and a legal one.

The Verge published a story about the arrest and current status of alleged Kickass Torrents founder Artem Vaulin, and I won’t comment on that still-developing case at this time. But the reason I mention it is that the comments section, not surprisingly, shifts from the report itself to the broader subject of piracy and everything that’s wrong with Hollywood, and the usual litany of complaints.  This observation from one anonymous poster caught my attention, not because I want to pick on him/her, but because it is exemplary of familiar themes:

“As much as Netflix, Spotify, iTunes/AM etc. are combating piracy and being fairly succsessful [sic] at it I can’t help but feel it’s a sub-par experience. The constant exclusivity deals, every corporation with hit TV show pushing their streaming service, and the most ridiculous of all, geo-blocking, in their effort to get more out of consumer they end up being a great advert for piracy …”

So, here’s a simple truth in response to that:  no legal market will ever compete with a black market. Doing business legally, even making older libraries of works available, has costs considerably higher than running a piracy site.  If the piracy advocates are waiting for the day when every creative work ever produced is available worldwide for a single, low-price subscription before they’re willing to stop pirating, they might as well at least stop banging on about the subject. Because it ain’t gonna happen.

Maybe this fact alone seems like justification for many to pirate, but those who think this way need to remember that a black market doesn’t produce a damn thing. Pirates trade in illegally-obtained works that other investors, large and small, have spent trillions to produce.  Because legal consumption of works in many markets is greater than illegal consumption, the margin of difference is sufficient enough to mask much of the damage when viewed from a broad perspective. But that doesn’t mean damage doesn’t occur. It’s like a basic principle of ecology; nothing looks wrong for a while until suddenly everything is wrong all at once.

Smaller, independent creators tend to feel the effects of piracy more acutely than big, corporate producers who have the scale and depth to treat piracy (to an extent) as a cost of doing business; but this does not mean the effects are nil. The Chinese scramble to protect systems running unsupported software reveals that there is always a tipping point when self-interest becomes self-destructive.  If enough consumers opt for a black market because, as the cited commenter says, the legal market is “a sup-par experience,” the truly lousy experience will come when production of new works grinds to a halt.

Yes, there is competition among producers. That’s what happens when people invest millions of dollars hoping to make something the market will like.  This competition necessitates exclusive deals, windowing, marketing, and even the dreaded geo-blocking.  This last item may seem incomprehensible to many consumers, but it is actually a manifestation of the way in which many independent film productions are financed.

In fact, eighty film directors in Europe (i.e. not Hollywood executives) just signed a petition urging the EU not to adopt a digital single market approach because this would adversely disrupt the way in which their films get made. The petition, published this week ahead of a forum to be held at the Cannes Film Festival next Monday, contains the following statement:

“More than ever, the territoriality of copyright needs to be maintained: this principle ensures high level support for artistic creation in Europe, helping the most fragile filmmakers and European co-productions. Enshrining this principle underwrites the exclusivity of rights and the financing of works.”  [Emphasis added]

It’s all well and good to sit at a computer, know exactly nothing about how products like motion pictures are financed and produced, and pontificate on the theme that “Hollywood should learn from the pirates, and until they do, I’ll keep pirating.” But this is untenable logic, not only in Hollywood, but especially for the thousands of works that are produced far from Hollywood. And the only reason these delusions persist is that—for now anyway—the legal market remains larger than the illegal market.  But there is always a tipping point, even if nobody can tell you exactly where it is.


*Ransomware locks up files on a computer and demands that the user pay the hacker(s) to restore access.

DCA’s New Report on Enabling Malware

Enabling Malware

Andrew Orlowski reports at The Register that last week Google quietly suspended its legal action to “muzzle” an investigation by Mississippi Attorney General Hood into whether or not the search giant was abiding by the terms of its 2012, non-prosecutorial settlement with the government over illegal online sales of prescription drugs.  Any explanation of Google’s change in strategy or the future of that investigation are subjects for another day.  But the fact that AG Hood was ultimately not stymied—either by litigation or by a brazen attempt in the State House of Representatives to legislatively tie his hands—is probably good news for American consumers because State Attorneys General “often act as the de facto consumer protection arm in their respective states,” notes a new report published yesterday by Digital Citizens Alliance.

Following up on its December report, which presented a look into the scope of the malware hazard for consumers who visit content-theft sites, DCA and RiskIQ have again collaborated to begin looking at the hosting services that either inadvertently or knowingly support illegal sites, which then endanger consumers.  The hosting services in this regard are particularly relevant because they are not shadowy operators based in hard-to-reach geographies but are legal corporations with offices in the United States.  As such, the news that Google will now look to “cooperate with AG Hood” rather than remain on the offensive comes at a good moment for consumers.  This is because DCA notes that state AGs will be the first authorities who may choose to investigate US-operating hosting services to determine their role in fostering the dissemination of malware.

The December report called Digital Bait revealed the likelihood (about 30% in some cases) that users of content theft sites would infect their devices with malware, and the report also identified the various types of malware being deployed in order to steal information and/or assets from consumers.  Digital Bait also presented a glimpse into the dark web-based economy where criminals engage in transactions like selling the IP addresses of a girl’s computer or even a cybercriminal paying content-theft site owners to deliberately host malware on their sites.  The report contains some eye-opening statistics like the one from the DOJ, which states that 16.2 million American consumers have been victims of identity theft, incurring financial losses of more than $24.7 billion.

The report released yesterday, Enabling Malware, looks at two hosting companies, each of which responded very differently when DCA contacted them with their findings.  The first was CloudFlare, which is “known for its willingness to support, or at least overlook, illicit activities,” the report states.  CloudFlare is a hosting service that is specifically designed to mask the identity of site owners and of the true hosting site of any content, whether the content is legal or not.  The site’s blog reads, “Signing up for CloudFlare is like taking your number out of the phone book, and putting in CloudFlare’s number under your name.”

This type of service can be (and is) used by journalists or bloggers operating in locations with authoritarian governments or other hazards to free speech and reportage.  But it is also a natural hosting choice for content-theft site owners, thus earning the service the nickname “CrimeFlare” among cyber-security experts. DCA contacted CloudFlare with regard to its hosting sites like Putlocker and Animex, both of which were identified in the Digital Bait report as delivering malware to users.  CloudFlare did not respond until a day or two before the release of this new report and wrote the following:

“CloudFlare’s service protects and accelerates websites and applications. Because CloudFlare is not a host, we cannot control or remove customer content from the Internet. CloudFlare leaves the removal of online content to law enforcement agencies and complies with any legal requests made by the authorities. If we believe that one of our customers’ websites is distributing malware, CloudFlare will post an interstitial page that warns site visitors and asks them if they would like to proceed despite the warning. This practice follows established industry norms.”

In other words, CloudFlare is not going to do anything unless authorities make them.

The other hosting service DCA and RiskIQ looked at was HawkHost, whose support includes watchfreemoviesonline.top, which was found to have a 32% malware exposure rate in the research conducted for the Digital Bait report. When DCA contacted HawkHost, the company’s response was very different from CloudFlare’s, stating that the sites identified by DCA would be taken down because they “clearly violate our TOS/AUP,” according to CTO Cody Robertson. Additionally, executives at HawkHost have agreed to meet with DCA to discuss findings linking malware with content theft sites and to look for ways to better protect consumers.  DCA commends HawkHost, stating that they find the company’s response “an encouraging sign.”

DCA and RiskIQ will continue to study the link between content-theft sites and malware, as well as the legal hosting services that operate in the United States, which may be supporting malware-infested sites. These findings will be presented to State Attorneys General, who then have the authority to investigate the extent to which a particular hosting service may or may not be willfully turning a blind eye to illegal enterprise that is directly harming American consumers.  So, as mentioned, beyond any implications regarding the Google investigation itself, last week’s affirmation of AG Hood’s authority in that case is likely a good sign for protecting consumers in general from the chronic I-Didn’t-Know-Defense too-often employed by various OSPs.