Let the Pirates Patch? An Economic Analysis of Software Security Patch Restrictions
نویسندگان
چکیده
W study the question of whether a software vendor should allow users of unlicensed (pirated) copies of a software product to apply security patches. We present a joint model of network software security and software piracy and contrast two policies that a software vendor can enforce: (i) restriction of security patches only to legitimate users or (ii) provision of access to security patches to all users whether their copies are licensed or not. We find that when the software security risk is high and the piracy enforcement level is low, or when tendency for piracy in the consumer population is high, it is optimal for the vendor to restrict unlicensed users from applying security patches. When piracy tendency in the consumer population is low, applying software security patch restrictions is optimal for the vendor only when the piracy enforcement level is high. If patching costs are sufficiently low, however, an unrestricted patch release policy maximizes vendor profits. We also show that the vendor can use security patch restrictions as a substitute to investment in software security, and this effect can significantly reduce welfare. Furthermore, in certain cases, increased piracy enforcement levels can actually hurt vendor profits. We also show that governments can increase social surplus and intellectual property protection simultaneously by increasing piracy enforcement and utilizing the strategic interaction of piracy patch restrictions and network security. Finally, we demonstrate that, although unrestricted patching can maximize welfare when the piracy enforcement level is low, contrary to what one might expect, when the piracy enforcement level is high, restricting security patches only to licensed users can be socially optimal.
منابع مشابه
Let the Pirates Patch? An Economic Analysis of Network Software Security Patch Restrictions
Piracy has long been an important concern for the software industry. The relative ease of reproducing and distributing software, as with any digital good, combined with the high value that many software products command makes software a prime target for piracy and unlicensed use. Today, an estimated every third copy of Microsoft’s widely used Windows operating system is unlicensed (Fried 2005),...
متن کاملThe Countervailing Incentive of Restricted Patch Distribution: Economic and Policy Implications
Traditionally, the government has been the sole entity to enforce anti-piracy measures. Of late, software vendors are attempting to thwart piracy of their products by limiting the patch to only legal users. By doing so, the vendor can vertically differentiate the legal copy from the pirated copy since pirates suffer more from hacker activity. Such an action by the vendor has interesting implica...
متن کاملSystematic review and meta-analysis of diagnostic value of epicutaneous patch testing in patients with oral lichenoid lesions
BACKGROUND AND AIM: We sought to carry out a systematic review and meta-analysis of the diagnostic value of epicutaneous patch testing in patients with oral lichenoid lesions (OLLs). METHODS: Bibliographic searches were conducted in electronic databases such as PubMed, the Cochrane library, EBSCO, Scopus, Web of knowledge and Google scholar from January 1990 to December 2011. Search terms re...
متن کاملDetermination of Resonance Frequency of Dominant and Higher Order Modes in Thin and Thick Circular Microstrip Patch Antennas with Superstrate by MWM (RESEARCH NOTE)
An accurate model named as the Modified Wolff Model (MWM) is presented as an efficient CAD tool for determination of resonant frequency of the dominant and higher order modes under the multi-layer condition in thin and thick circular microstrip patch antennas. The effects of dielectric cover on the resonant frequency obtained from MWM have been compared against the result of theoretical method ...
متن کاملEconomic and Policy Implications of Restricted Patch Distribution
In this paper, we study how restricting the availability of patches to legal users impacts vendor’s profits, market share, software maintenance decisions, and welfare outcomes. Prior work on this topic assumes that hacker’s effort is independent of the vendor’s decision to release the patch freely or not. Clearly, if the patch is not available to everyone, the hacker finds it easier to exploit ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Information Systems Research
دوره 19 شماره
صفحات -
تاریخ انتشار 2008