<div dir="ltr">John's points about arms-race or cat&mouse are exactly correct.<div>It is a commitment to a continuous effort, not a one time solution.</div><div>Which leads to a constant re-assessment of what is the value of what you're protecting.</div><div>As much as it pissed off everyone involved, sometimes it was easier to pay damages or replace equipment at our cost.</div><div><br></div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Thu, Sep 10, 2026 at 10:19 AM John via Synth-diy <<a href="mailto:synth-diy@synth-diy.org">synth-diy@synth-diy.org</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On Thu, 10 Sep 2026 18:19:42 +0200<br>
cheater cheater via Synth-diy <<a href="mailto:synth-diy@synth-diy.org" target="_blank">synth-diy@synth-diy.org</a>> wrote:<br>
<br>
> One thing that I'm curious about is things like updating encryption,<br>
> in order to be able to repudiate compromised keys, eg from<br>
> manufacturers who have decided to start leaking them to companies who<br>
> shouldn't have them.<br>
<br>
Yes, it's yet another complicating factor; between the steady advance<br>
of cryptographic research and human-factors issues like trusted parties<br>
breaking trust (how many CAs have been coopted by malicious actors over<br>
the last ~30 years?) it's a practical inevitability that DRM breaks (or<br>
is broken) over time...<br>
<br>
...which means that maintaining control via DRM is a ceaseless struggle<br>
against this process, a Looney Tunes arms-race where the participants<br>
are continually one-upping each other until you find you're lugging a<br>
cannon around just to keep up with the demands of the bit.<br>
<br>
Take HTTPS or SMTP encryption, f'rexample. I could browse Web forums<br>
and send e-mail from an Amiga with a 40 MHz 68030 no problem, but once<br>
forum hosts and mail providers began requiring encryption the poor CPU<br>
just wasn't up to the task. And that was with SSL 1.0; these days, even<br>
a 900 MHz laptop from 2008 struggles to negotiate a connection to the<br>
GMail servers. The machine still works, and the underlying technology<br>
hasn't changed, but the burden of keeping up with security is too much.<br>
<br>
Of course, you might say that's worth it for a secure connection, and<br>
maybe it is; some of those websites are ones I punch my credit-card<br>
details into, after all. But who needs that in a modular synthesizer!?<br>
Who wants an instrument that may end up bricked in a few years because<br>
its am-I-in-the-club-guys protocol is obsolete and the manufacturer<br>
can't/won't update it!?<br>
________________________________________________________<br>
This is the Synth-diy mailing list<br>
Submit email to: <a href="mailto:Synth-diy@synth-diy.org" target="_blank">Synth-diy@synth-diy.org</a><br>
View archive at: <a href="https://synth-diy.org/pipermail/synth-diy/" rel="noreferrer" target="_blank">https://synth-diy.org/pipermail/synth-diy/</a><br>
Check your settings at: <a href="https://synth-diy.org/mailman/listinfo/synth-diy" rel="noreferrer" target="_blank">https://synth-diy.org/mailman/listinfo/synth-diy</a><br>
Selling or trading? Use <a href="mailto:marketplace@synth-diy.org" target="_blank">marketplace@synth-diy.org</a><br>
</blockquote></div>