From Property to Permission
https://sangtd.net/from-property-to-permission/The Constitution of the United States, Article I, Section 8, Clause 8, grants Congress the power “to promote the Progress of Science and useful Arts, by securing for limited Times to Authors and Inventors the exclusive Right to their respective Writings and Discoveries.” The phrase “limited Times” was not an afterthought. It was the central bargain. The government grants a temporary monopoly — fourteen years, renewable once for a total of twenty-eight — and in exchange, the work enters the public domain for everyone to build upon. The monopoly is not a natural right. It is a calculated incentive: give creators enough exclusivity to profit from their work, then return the work to the common pool. The system was designed to expand the public domain, not to protect private property forever.
The 1790 Copyright Act made this explicit. Fewer than five percent of works were ever renewed after the initial term because renewal required an active application. The public domain was the default. Protection was the exception, and it required paperwork.
Over the following two centuries, that balance has been inverted. The copyright term climbed from twenty-eight years to fifty-six, then to life plus fifty, then to life plus seventy. The renewal requirement was abolished — now every work is protected for the full term automatically, whether or not it has any commercial value. The Copyright Term Extension Act of 1998, known as the Mickey Mouse Protection Act, added twenty years to every existing and future copyright in the United States. The lobbying was led by Disney, whose earliest cartoons were about to enter the public domain. The law was written by the industry it regulated. “Limited Times” had been reinterpreted as “as long as we can pay for.”
The justification for each extension was always the same: creators need more time to profit. But the real beneficiaries are not individual creators. They are corporate copyright holders — studios, publishers, record labels — that own vast portfolios of works created by employees decades ago. A corporation does not need an incentive to create. It needs to maximize the return on its inventory. Term extension protects inventory, not creativity. This distinction between creator and corporation is the thread that runs through every subsequent expansion of copyright law. The laws are written by lobbyists for the recording industry, the motion picture association, and publishing conglomerates. The independent musician, the documentary filmmaker, the small press author — these are the people whose work is supposedly being protected, and they are not the ones funding the lobbying.
The DMCA of 1998 made the damage structural by shifting the balance from “you can use it unless the law says otherwise” to “you cannot use it unless the copyright holder explicitly permits it.” Its anti-circumvention provisions, Section 1201, made it illegal to bypass any technological protection measure, even for purposes that would otherwise be legal under fair use. A teacher who clips a scene from a DVD for classroom use is breaking the law. A researcher who studies a DRM system for security vulnerabilities is breaking the law. A consumer who plays a legally purchased Blu-ray on an open-source operating system is breaking the law. Fair use, the safety valve that allows limited copying for criticism, education, and commentary, is theoretically preserved — but the practical ability to exercise it is eliminated when circumvention is criminalized. The law does not need to ban fair use directly. It simply makes the tools for exercising fair use illegal to use.
The takedown provisions of Section 512 reinforced this shift by creating a system where platforms remove content first and ask questions never. A copyright holder can takedown a video that clearly falls under fair use, and the platform complies immediately because the law rewards speed over accuracy. The mechanism is biased toward censorship by default, and studies have shown it is routinely abused against competitors, critics, and users who have done nothing wrong. The European Union’s Article 17 extends this logic to upload filters — platforms must now prevent copyrighted content from appearing at all, even though content recognition systems cannot distinguish between a song used in a news report and the same song in a pirated upload. The over-blocking is industrial in scale, and the burden of proof falls on the uploader.
The consequence of all this is measurable. The public domain has effectively stopped growing for works created after 1928. A book from 1930, a film from 1940 — still locked. Every adaptation, every remix, every critical edition that cannot be made is a tax on future creativity, paid to protect corporate inventory.
Alongside the legal transformation, a commercial one was unfolding. A record store in 1995. You walk in, pick a CD off the shelf, hand over fifteen dollars, and walk out with a plastic case containing a disc. That disc is yours. You can play it a thousand times, lend it to a friend, resell it, burn a copy for your car, or leave it to your children. The store has no further claim on it. The label cannot reach into your home and take it back. You own a thing. A streaming service in 2024. You click “Buy,” pay fifteen dollars, and receive a license — permission to access a file on a server that belongs to someone else, through an application that checks an authorization server every time you open it. The file can be revoked. The license can be terminated. The platform can shut down. The shelf life depends entirely on corporate decisions. You are paying for the privilege of remaining a tenant.
This transition from owning objects to renting access happened not despite piracy, but because of it. Physical media was always vulnerable to copying — a cassette tape could be duplicated with two decks and a patch cable, a CD with any computer sold after 1995, a game cartridge with hardware costing fifty dollars. Every format had its copy protection, and every protection was broken within months. The industry spent billions on these systems, and they all failed because the customer has physical possession of the content. If you hold the bits, you can copy the bits.
The industry drew a conclusion from this, and it was not “make the legal product better than the pirate product.” It was “eliminate the physical medium entirely.” If the customer never possesses a physical object, there is nothing to rip or burn. If the content never leaves a server, copying becomes structurally impossible. This logic is sound in theory. In practice, it produced a world where paying customers have fewer rights than pirates. Netflix has removed over fifty titles in a single year, including original productions. Sony has removed purchased content from PlayStation libraries. HBO Max removed nearly two hundred episodes of a publicly funded show, then removed the entire section. These are not isolated incidents but structural features of a system where a “purchase” is a lease, and the lease terms can be rewritten at any time. The pirate faces none of these problems — no license server dependency, no geo-restriction, no platform shutdown risk. The pirate can play offline, transfer files to any device, organize them in any folder, use any software. The pirate has more ownership than the person who paid. The industry solved piracy by making the legitimate product worthless, and then charged the same price for it.
The law was rewritten to give corporations perpetual control. The business model was redesigned to eliminate customer ownership. But neither of these would be effective without a way to enforce the new rules on every device that touches copyrighted content. This enforcement layer is Digital Rights Management, and it is the most expensive failure in the history of content protection.
Every piece of copyrighted content delivered through a digital channel is encrypted before leaving the server and decrypted on the user’s device. The encryption serves no technical purpose — video files do not need to be encrypted for a screen to display them. It exists to control what the user does with the content after receiving it. The device is trusted to decrypt and render, but it must also enforce rules about copying, recording, and transferring. Google’s Widevine protects video on Android and Chrome. Microsoft’s PlayReady protects video on Windows and Xbox. Apple’s FairPlay protects content on iOS and Apple TV. HDCP encrypts the signal travelling over HDMI. Steam’s CEG protects PC games. Spotify and Apple Music encrypt their audio streams. Every system uses different cryptography, but every one shares the same fundamental architecture: the content is decrypted on the client, and the decryption key exists somewhere in the client’s memory at runtime.
This architectural fact makes every DRM system breakable by the same approach: extract the key, decrypt the content, distribute it without protection. Widevine Level 3 is trivially breakable — the key sits in user-space memory, dumpable with standard tools. Widevine Level 1, running in a hardware-backed trusted execution environment, is harder but has been broken repeatedly through side-channel attacks and firmware exploits. The AACS master key for Blu-ray was published online years ago. HDCP master keys have been leaked. Every Steam DRM format has been cracked within days of major releases. The pattern is not that a system is eventually broken — it is that every system is broken before it matters, and the industry responds by releasing a new version that costs more and gets broken slightly later.
The spending asymmetry is staggering. A content provider invests millions integrating a DRM system and maintaining its license infrastructure. The pirate spends a few hours with a screen capture tool or a few days reverse-engineering a key. The cost ratio is a million to one, and the attacker always wins, because the fundamental constraint is physical: content must be rendered into photons and sound waves for a human to perceive it, and anything that can be rendered can be captured. No DRM can prevent a camera pointed at a screen. Its highest achievement is making piracy slightly less convenient.
The people who bear the cost are legitimate users. HDCP forces monitors to refuse a signal when the handshake fails. Region locks prevent a disc bought abroad from playing on a domestic player. Widevine’s security tiers refuse playback on devices that miss a single checkbox on a spec sheet. These are not vulnerabilities — they are features, and they affect only paying customers. Pirates never see them.
The DMCA’s Section 1201 is what makes this system work. Without the law, DRM is just encryption that a user can bypass on their own device. With the law, bypassing that encryption is a federal crime, even if the purpose is perfectly legal under fair use. The technical protection is a decoy. The law does the real work. DRM is not a security system. It is a legal enforcement mechanism disguised as a technical one, designed not to protect content from pirates but to maintain the legal grounds for prosecuting anyone who uses their purchased content on terms the copyright holder did not approve.
The legal transformation, the commercial transformation, and the technical transformation are not separate phenomena. They are the same process unfolding in different domains. The law expands copyright terms and criminalizes fair use. The industry eliminates physical ownership and replaces it with revocable licenses. The technology encrypts every file and locks every device. Each step makes the customer more dependent and the corporation more powerful. Each step is justified as necessary to stop piracy. And each step fails at that goal.
The pirate operates outside all of these systems. The law does not reach them because they do not distribute through legal channels. The licensing model does not affect them because they have an actual file, not a revocable permission. The DRM does not constrain them because their copy was decrypted before it reached them. The pirate enjoys the full set of rights that physical ownership once provided: possession, transferability, offline use, permanent access. The paying customer enjoys none of these.
The copyright industry spent thirty years building this apparatus. It spent billions on lobbying, on lawyers, on DRM vendors, on platform integrations. It defeated Napster, shut down Grokster, imprisoned Kim Dotcom, and pressured ISPs into disconnecting alleged pirates. It won every legal battle, every political fight, every technical skirmish. And at the end of these three decades of victory, the pirate has a better product than the paying customer.
The system was never designed to stop piracy. It was designed to make piracy the only way to own what you buy.