News & Noteworthy

ADE in the Library eBook Data Lifecycle

Reader: “Hey, I heard there is some sort of problem with those ebooks I checked out from the library?” Librarian: “There are technical problems, potential legal problems, and philosophical problems – but not with the book itself nor your choice to read it.” [Update 2014.10.14@12.04pm: more info on security in the library data lifecycle added at the bottom of this post] As mentioned, there are (at least) three sides to the problem. Nate Hoffelder* discovered the technical problem with the way the current version (4) of Adobe Digital Editions (ADE) manages the ebook experience, which was confirmed by security researcher Benjamin Daniel Mussler, and later reviewed by Eric Hellman. The technical problem, that arguably private data is sent in plain text from a reader’s device to a central data-store, seems pretty obvious once it was discovered. The potential legal problem stems from laws in every state which protect reader privacy which set expectations for data security,…