DMCA Security Research Exemption and Election Security

Tori Noble

Voting Village @ DEF CON 33 · Day 1 · Voting Village

Overview

This talk, delivered by Tori Noble, a Staff Attorney at the Electronic Frontier Foundation (EFF), delves into the critical legal landscape surrounding security research, with a particular focus on its intersection with election security. The session provides an in-depth analysis of Section 1201 of the Digital Millennium Copyright Act (DMCA), a federal law notorious among security researchers for its broad prohibitions against circumventing technological protection measures. Noble elucidates how the DMCA, originally conceived to combat online piracy, inadvertently stifles legitimate security investigations into vulnerabilities in copyrighted software, including those embedded within voting machines.

Watch on YouTube

Visual summary for DMCA Security Research Exemption and Election Security by Tori Noble
Visual summary for DMCA Security Research Exemption and Election Security by Tori Noble

Key moments

  1. 0:00 Introduction to DMCA exemption and Voting Village history
  2. 2:30 DMCA exemption's fragility and EFF's advocacy for researchers
  3. 4:00 Tori Noble (EFF) introduction and talk agenda
  4. 5:50 Understanding DMCA Section 1201: Anti-circumvention provision
  5. 7:45 DMCA's unintended impact on voting machine security research
  6. 8:20 Detailing the two core prohibitions of DMCA Section 1201

DMCA Security Research Exemption and Election Security

Speakers: Tori Noble, Staff Attorney, Electronic Frontier Foundation

Conference: Voting Village

YouTube: https://www.youtube.com/watch?v=XVJd08ehNs4

Overview

This talk, delivered by Tori Noble, a Staff Attorney at the Electronic Frontier Foundation (EFF), delves into the critical legal landscape surrounding security research, with a particular focus on its intersection with election security. The session provides an in-depth analysis of Section 1201 of the Digital Millennium Copyright Act (DMCA), a federal law notorious among security researchers for its broad prohibitions against circumventing technological protection measures. Noble elucidates how the DMCA, originally conceived to combat online piracy, inadvertently stifles legitimate security investigations into vulnerabilities in copyrighted software, including those embedded within voting machines.

The core of Noble's presentation centers on the evolution and nuances of the DMCA’s security research exemptions. These exemptions are indispensable, as they provide a crucial legal shield for researchers who engage in reverse engineering and other vulnerability discovery activities that would otherwise be deemed illegal under the DMCA. For the Voting Village at Def Con, where researchers are actively encouraged to scrutinize election equipment, understanding these exemptions is not merely academic; it is the fundamental legal underpinning that allows such vital work to proceed without fear of severe civil or criminal penalties.

The talk underscores the ongoing fragility and complexity of these exemptions, highlighting why continuous advocacy and careful adherence to their specific requirements are paramount. It serves as a vital guide for anyone involved in security research, particularly those examining election systems, where vendors have historically been litigious. By demystifying the DMCA and its carve-outs, Noble empowers the security community to navigate this challenging legal terrain and continue their essential contributions to a more secure digital infrastructure, especially in the context of democratic processes.

Background

▶ Watch: Introduction to DMCA exemption and Voting Village history (0:00)

The Digital Millennium Copyright Act (DMCA), enacted in the late 1990s, was primarily a response to burgeoning concerns about online piracy. Its intent was to protect copyrighted works in the digital age by making it illegal to circumvent technological protection measures (TPMs), often referred to as Digital Rights Management (DRM), designed to control access to copyrighted content. This legislative framework, while aiming to safeguard intellectual property, inadvertently created significant legal hurdles for legitimate security research. Activities like reverse engineering, which are standard practice for identifying and remediating software vulnerabilities, often involve bypassing these TPMs, thereby falling afoul of the DMCA's broad prohibitions.

Specifically, Section 1201 of the DMCA contains two key prohibitions. The first, anti-circumvention (17 USC Section 1201(a)(1)(A)), makes it illegal to bypass a technological measure that effectively controls access to a copyrighted work. This means that if a system employs any form of digital protection—be it encryption, a password gate, or even a simple authentication handshake—and a researcher bypasses it without authorization, they could be in violation. The second prohibition, anti-trafficking (17 USC Section 1201(a)(2)), is even broader, making it illegal to manufacture, offer, or otherwise traffic in any technology primarily designed or produced for the purpose of circumventing a TPM. This provision can severely restrict the development and distribution of security tools, even those intended for defensive purposes.

TPMs are broadly defined and include a range of digital protections such as DRM on DVDs or streaming platforms, encryption, captchas, authentication mechanisms, and code signing. Crucially, a TPM does not need to be robust or difficult to bypass; even easily circumvented measures can trigger DMCA liability. Conversely, simply using an unauthorized username and password to access a system, without bypassing the underlying authentication mechanism itself, is generally not considered circumvention under the DMCA. The law also only applies to measures protecting copyrightable works, meaning purely factual information, if unorganized and uncurated, might not be covered, though determining copyrightability is a complex legal question.

A critical aspect of the DMCA's Section 1201 is the absence of a fair use defense. Unlike traditional copyright infringement claims, where uses for commentary, criticism, news reporting, or research can be defended as fair use, this defense does not apply to DMCA 1201 violations. This omission dramatically increases the risk for security researchers, as their work—even when transformational and beneficial for public safety, such as identifying vulnerabilities in voting machines—cannot automatically claim fair use protection. This legal vacuum necessitated the creation of specific exemptions to allow essential security research to proceed.

The penalties for violating DMCA Section 1201 are substantial. Civil liability can include injunctive relief, actual damages plus profits, or statutory damages ranging from $200 to $2,500 per act of circumvention or per product/service designed for circumvention. Repeated violations within a three-year period can incur triple damages. Criminal liability is also possible for willful violations undertaken for commercial purposes or private financial gain, with first offenses potentially leading to fines of up to $500,000 and/or five years in prison, and subsequent offenses doubling these penalties. These severe consequences underscore the chilling effect the DMCA has historically had on security research, making the need for robust exemptions critically important.

The Voting Village at Def Con, established in 2017, serves as a prime example of the practical impact of these exemptions. The Village was conceived after the initial DMCA security research exemption was granted, enabling researchers to legally access and analyze voting equipment for vulnerabilities. Without this exemption, the activities routinely conducted at the Voting Village—reverse engineering, vulnerability testing, and public disclosure of findings—would expose participants to significant legal risk, effectively preventing such crucial work from being carried out.

Key Findings

▶ Watch: Tori Noble (EFF) introduction and talk agenda (4:00)

Tori Noble's talk highlights that the impact of DMCA Section 1201 on security research has been significantly mitigated by the evolution of specific exemptions, which have undergone considerable expansion over time. Prior to 2015, security researchers were largely confined to very narrow permanent exemptions embedded within the DMCA statute itself. These early exemptions were highly restrictive, often requiring explicit authorization from device owners—a near-impossible condition when investigating vulnerabilities that manufacturers might prefer remain undiscovered. This severely chilled legitimate security research, as companies could easily thwart investigations by simply withholding permission.

The pivotal development came with the adoption of the first temporary research exemption in 2015 by the Library of Congress, following a formal rulemaking process. This exemption, which must be renewed every three years, marked a significant shift by beginning to carve out space for good faith security research. While initially helpful, it still contained limitations, notably the "other laws limitation," which meant the exemption would not apply if the research also violated other statutes, such as the Computer Fraud and Abuse Act (CFAA). This ambiguity was exploited by companies, like the voting machine vendor ES&S (formerly Election Systems & Software), which threatened researchers by leveraging the CFAA's broad and often litigated scope.

A major breakthrough occurred in 2021 when the "other laws limitation" was removed from the temporary exemption. This revision dramatically increased the utility of the exemption by clarifying that potential CFAA violations would no longer automatically invalidate the DMCA exemption. As a result, researchers could undertake investigations without the DMCA threat, even if other legal risks (like CFAA liability) still existed independently. The exemption has been renewed multiple times since 2015, and on three of those four occasions, it has been significantly broadened, indicating a positive momentum towards supporting security research. The current iteration, the 2024 security research exemption (37 CFR Section 201.40(b)(18)), specifically highlights the critical need for security research on voting machines, a testament to the persistent advocacy of election security researchers.

Despite these advancements, crucial challenges and ambiguities persist. The temporary exemption, while broad, does not apply to anti-trafficking violations. This means that while a researcher might be protected for circumventing a TPM for research purposes, developing or distributing a tool designed for that circumvention remains largely unprotected, except under the much narrower permanent exemptions. Furthermore, the temporary exemption itself is subject to renewal every three years, making its continued existence dependent on administrative decisions and potentially vulnerable to shifting political landscapes.

Two key ambiguities within the 2024 exemption language continue to pose risks: the meaning of "lawfully acquired device" and "good faith security research." Voting machine companies have exploited the "lawfully acquired device" clause by including resale bans in their vendor contracts. If a device is acquired from a third party that violated such a contract, its "lawfully acquired" status becomes questionable, potentially undermining the exemption's applicability. Similarly, "good faith security research" requires the access to be solely for testing, investigation, and/or correcting a security flaw, conducted in an environment designed to avoid public harm, and with information used primarily to promote security. The "solely" requirement and the definition of "harm to the public" introduce interpretative ambiguities that litigious vendors can exploit. The lack of judicial interpretation of this specific exemption means that the outer boundaries of these terms remain untested in court, leaving researchers in a legal gray area.

Technical Deep Dive

▶ Watch: Understanding DMCA Section 1201: Anti-circumvention provision (5:50)

The DMCA's Section 1201 establishes a complex legal framework that directly impacts security research. At its core are two distinct prohibitions that researchers must navigate: anti-circumvention and anti-trafficking.

The anti-circumvention provision (17 USC Section 1201(a)(1)(A)) prohibits the act of bypassing a technological measure that effectively controls access to a copyrighted work. This means that if a software, firmware, or digital content is protected by any technical barrier, and a researcher attempts to get around that barrier, they risk violating this part of the DMCA. For a measure to be covered, it must "effectively control" access to a copyrighted work. This implies that measures merely restricting location or non-copyrightable factual data might not apply, though the copyrightability of technical code and data is often a point of contention. Circumvention itself is broadly defined as removing, deactivating, impairing, bypassing, or working around such a measure without the copyright owner's permission, such as decrypting an encrypted work.

The anti-trafficking provision (17 USC Section 1201(a)(2)) goes further, making it illegal to manufacture, offer to the public, provide, or otherwise traffic in any technology, product, service, device, or component that (1) is primarily designed or produced for the purpose of circumventing a TPM, (2) has only limited commercially significant purposes or uses other than circumvention, or (3) is marketed for use in circumvention. This provision is particularly problematic for security researchers because it targets the tools and methods of circumvention, not just the act itself. This means developing and sharing proof-of-concept exploits or vulnerability research tools could potentially fall under this prohibition, even if the underlying circumvention act is covered by an exemption. Crucially, the broad temporary exemptions for security research generally do not provide protection against anti-trafficking claims, leaving a significant gap in legal protection for tool developers.

Effective Technical Measures (TPMs) are the digital locks that the DMCA protects. Examples include:

  • Digital Rights Management (DRM) found on media like DVDs, CDs, and streaming platforms.
  • Encryption schemes used to protect data or software.
  • CAPTCHAs and other bot-prevention mechanisms.
  • Authentication protocols and handshakes.
  • Code signing and integrity checks.
  • Any other technical barriers that direct or control access to a copyrighted work.

It is important to note that a TPM does not need to be sophisticated or difficult to bypass. Even simple, easily circumvented protections can qualify, meaning researchers don't need to perform "hacking" in the traditional sense to violate the DMCA.

A significant challenge for researchers is the DMCA's explicit exclusion of a fair use defense for Section 1201 violations. Unlike traditional copyright law, where using copyrighted material for purposes like criticism, commentary, or research can be legally permissible under fair use, this defense is unavailable for circumvention acts. This means that even if a researcher's actions are clearly beneficial for public good, such as identifying critical vulnerabilities in election systems, they cannot rely on fair use to defend against a DMCA 1201 claim.

To address these issues, various exemptions have been established:

Permanent Exemptions: These are written directly into the DMCA statute itself but are generally narrow.

  1. Security Testing Exemption (17 USC 1201(j)): This covers "good faith security testing" conducted solely for testing, investigating, or correcting a security flaw or vulnerability. However, it requires the authorization of the owner of the computer, system, or network. This authorization requirement has historically rendered it largely ineffective for independent security research on vendor-controlled systems. Furthermore, it explicitly states that the conduct cannot violate copyright or the Computer Fraud and Abuse Act (CFAA), an anti-hacking statute known for its broad and often ambiguous scope. This exemption does apply to anti-trafficking violations, making it a rare source of protection for tool development, but its stringent authorization requirement severely limits its practical use.
  2. Encryption Research Exemption (17 USC 1201(g)): This covers activities necessary to identify and analyze flaws in encryption technologies applied to copyrighted works. The research must advance knowledge in the field or assist in developing encryption products, and the device must be "lawfully obtained." This exemption is more flexible regarding authorization, requiring only a good faith effort to obtain authorization, not actual permission. However, it comes with several specific factors that courts would consider, such as reasonable dissemination of findings, the researcher's qualifications, and timely notice to the copyright owner. Its ambiguity and lack of judicial precedent make it a less reliable shield.

Temporary Research Exemption (37 CFR Section 201.40(b)(18)): This is the most impactful exemption for independent security researchers, particularly those in election security. It is adopted by the Library of Congress every three years through a rulemaking process and is subject to revision.

  • Scope: It covers the circumvention of TPMs to access computer programs on a lawfully acquired device for "good faith security research."
  • Authorization: Crucially, it does not require authorization from the device owner, a significant improvement over the permanent security testing exemption.
  • CFAA: The 2021 update removed the "other laws limitation," meaning that a potential CFAA violation will not defeat the DMCA exemption itself, though CFAA liability may still exist independently.
  • Anti-Trafficking: A major limitation is that this exemption does not apply to anti-trafficking violations. Researchers are protected for doing the research, but not necessarily for distributing the tools that enable it.
  • Ambiguities: Despite its breadth, ambiguities remain. "Lawfully acquired device" is a point of contention, especially when voting machine vendors include resale bans in their contracts, potentially rendering a device acquired from a third party as "unlawfully acquired." "Good faith security research" requires the access to be solely for testing/correcting flaws, conducted in an environment designed to "avoid any harm to the public," and with information used primarily to promote security or safety. The "solely" motivation and "harm minimization" requirements introduce subjective elements that can be legally challenged.

Understanding these technical and legal distinctions is crucial for security researchers to effectively navigate the DMCA landscape and ensure their vital work remains within legal bounds.

Demo / Proof of Concept

▶ Watch: DMCA's unintended impact on voting machine security research (7:45)

This talk focused on the intricate legal framework surrounding security research under the DMCA, rather than demonstrating a specific technical exploit or proof of concept. Tori Noble's presentation was an informational session designed to educate researchers on their legal rights and responsibilities when engaging in activities like reverse engineering and vulnerability discovery.

However, the very existence and success of the Voting Village at Def Con, where this talk was delivered, serves as a powerful, real-world "proof of concept" for the effectiveness of the DMCA security research exemption. The Voting Village allows researchers to physically interact with and analyze voting machines, exposing critical vulnerabilities that might otherwise remain hidden. This hands-on research, which directly involves circumventing TPMs on these devices, would be legally precarious without the protections afforded by the temporary security research exemption. The ability for participants to engage in this vital work year after year demonstrates the practical impact and necessity of these legal carve-outs, making the Voting Village itself a testament to the exemption's enabling power.

Defensive Implications

▶ Watch: Detailing the two core prohibitions of DMCA Section 1201 (8:20)

The detailed explanation of the DMCA security research exemptions offers crucial guidance for security defenders, particularly those operating in sensitive areas like election security. The "defensive implications" in this context largely pertain to how researchers can legally defend their actions and mitigate personal liability while performing essential vulnerability discovery.

First and foremost, researchers must thoroughly understand the scope and limitations of the temporary security research exemption (37 CFR Section 201.40(b)(18)). While this exemption removes the requirement for authorization from device owners and largely insulates researchers from DMCA claims even if their actions hypothetically violate the CFAA, it is not a bulletproof shield. Researchers should be acutely aware that the exemption does not apply to anti-trafficking violations. This means that developing, distributing, or marketing tools specifically designed for circumvention remains a significant legal risk, potentially exposing researchers to the full penalties of the DMCA. If the goal is to release a tool that aids circumvention, careful legal counsel should be sought to explore the narrow permanent exemptions (like the security testing exemption for anti-trafficking) or alternative distribution strategies.

A critical ambiguity for election security researchers lies in the "lawfully acquired device" requirement. Voting machine companies have historically used contractual clauses, such as resale bans in their vendor agreements, to try and undermine this aspect of the exemption. Researchers acquiring devices from third parties must investigate the provenance of the equipment to ascertain if its acquisition could be challenged as unlawful, potentially rendering the exemption inapplicable. Whenever possible, obtaining written authorization from the device owner, even if not strictly required by the temporary exemption, can significantly bolster a researcher's legal standing against claims of unlawful acquisition.

Furthermore, the condition of "good faith security research" demands careful adherence. Research must be conducted solely for the purpose of testing, investigating, or correcting a security flaw. This implies a clear and documented intent from the outset of the research project. Additionally, the research environment must be "designed to avoid any harm to the public." This points towards responsible disclosure practices, such as working in sandboxed environments, minimizing the risk of a vulnerability being exploited before a patch is available, and avoiding the release of personally identifiable information that could cause harm. While not explicitly defined, adhering to industry-standard responsible disclosure policies (e.g., notifying vendors and allowing a reasonable time for remediation before public disclosure) aligns with the spirit of harm minimization.

Defenders in the broader security community also have a role to play. The temporary exemption is precisely that—temporary—and requires renewal every three years. The fact that election security researchers' public comments have historically influenced the broadening of this exemption underscores the importance of continued advocacy. The security community should support organizations like the EFF and actively participate in future rulemaking processes to ensure the exemption is maintained and further strengthened.

Finally, while the temporary exemption offers DMCA protection, researchers must remain cognizant of other potential legal liabilities. The CFAA still exists as a federal anti-hacking statute, and while a CFAA violation no longer negates the DMCA exemption, it can still lead to separate civil or criminal charges. Similarly, state laws (e.g., computer trespass statutes) and common law claims (e.g., trespass to chattels) could be implicated. Therefore, a comprehensive understanding of the legal landscape beyond the DMCA is essential for any security researcher.

Key Takeaways

  • DMCA Section 1201's Broad Scope: The Digital Millennium Copyright Act (DMCA) Section 1201 broadly prohibits both the circumvention of technological protection measures (TPMs) and the trafficking of circumvention tools, regardless of the researcher's intent or the public benefit of their work.
  • Crucial Role of Temporary Exemption: The temporary security research exemption, renewed every three years by the Library of Congress, is vital for enabling legitimate security research, especially in election security. It allows circumvention without requiring authorization from device owners and, since 2021, does not automatically fail if the research hypothetically violates the Computer Fraud and Abuse Act (CFAA) for DMCA purposes.
  • Anti-Trafficking Gap: A significant limitation is that the temporary exemption does not apply to anti-trafficking violations, leaving researchers vulnerable if they develop or distribute tools designed for circumvention. Only very narrow permanent exemptions offer some protection for tool development.
  • Ambiguities and Vendor Exploitation: Key ambiguities remain in the exemption's language, particularly regarding "lawfully acquired device" and "good faith security research." Voting machine vendors have exploited these ambiguities, for instance, by including resale bans in contracts to challenge the "lawful acquisition" of devices by researchers.
  • Ongoing Fragility and Advocacy: The temporary nature of the exemption means it is not guaranteed to remain in law and requires active renewal every three years. Continued advocacy from the security community, as demonstrated by past successes in broadening its scope, is essential to maintain and strengthen these protections.
  • Other Legal Risks Remain: While the temporary exemption mitigates DMCA liability, researchers must still be aware of potential risks under other laws, including the CFAA, Electronic Communications Privacy Act (ECPA), state laws, and common law claims. Responsible disclosure practices and harm minimization remain critical.

About the Speaker(s)

Tori Noble is a Staff Attorney at the Electronic Frontier Foundation (EFF), a leading non-profit organization dedicated to defending civil liberties in the digital world. The EFF's mission includes protecting the rights of security researchers and developers to ensure products are more secure, often challenging laws like the DMCA that impede such essential work. In her role, Tori Noble specializes in outlining complex legal provisions like the DMCA's security research exemptions and addressing individual concerns regarding their application. Her expertise is crucial in guiding the security community through the intricate legal landscape of digital rights and intellectual property.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Noble is a credible EFF attorney delivering a necessary legal orientation for the Voting Village audience — the DMCA exemption landscape, anti-trafficking gaps, and vendor exploitation of 'lawfully acquired' ambiguity are all material that practitioners genuinely need to understand. The talk is competent and well-structured, but it's fundamentally a legal explainer that lives comfortably in the realm of 'things a well-written EFF blog post or whitepaper could cover just as effectively.'

Heather Calloway (CISO) — SOLID

Noble delivers a technically accurate and practically necessary legal briefing for election security researchers operating under the DMCA. It does what it sets out to do — but it stops well short of engaging the institutional and governance dimensions that make this problem consequential beyond the individual researcher.

→ Top-rated talks at Voting Village @ DEF CON 33

All talks from Voting Village @ DEF CON 33