Live data from Hacker News

US Court of Appeals: An IP address isn't enough to identify a pirate

techspot.com

11–20 of 68 posts

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#11

The court holds that the plaintiff must demonstrate reasonable evidence the defendant was the person using the computer. In this particular case, the defendant ran what amounts to lodging, was deposed, and it was immediately figured out it wasn't him. The complicating factor is that because his lodging was medical in nature, he was not able to hand over guest information. I mention this context because it's unlikely…

> I mention this context because it's unlikely you would be able to get out of being sued by saying "Well maybe it was my roommate LOL"

Well, the question is whether I'm responsible for the use of my computer network. If someone hacks into it and starts using it without me noticing, am I responsible?

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#12
post #8
post #4

It surprises me in a way that "big internet" (AT&T, Verizon, Comcast etc) and associated large enterprise interests have not been more staunch proponents of IPv6, at least for fixed consumer connections. It would be trivial in that circumstance to blow away any kind of NAT and the pseudo-anonymity/plausible deniabililty it provides and make client devices performing illegitimate activity directly identifiable. I wond…

> It would be trivial in that circumstance to blow away any kind of NAT Why do you think so? NAT can be used for IPv6 is exactly the same way it's used for IPv4.

AFAIK no home router you can buy does NAT66, so in practice it's not used.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#13

Earlier quoted context omitted.

The facts of the actual case make it much easier to understand the problem, but how is that situation actually different? There are still multiple people it could have been, no evidence is presented to distinguish between them at all and it's an obvious injustice to punish one person when it was another who did it.

How do you know it wasn't a nearby neighbour piggybacking on your wifi?

because wifi is reasonably secure by default these days?

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#14
post #4

It surprises me in a way that "big internet" (AT&T, Verizon, Comcast etc) and associated large enterprise interests have not been more staunch proponents of IPv6, at least for fixed consumer connections. It would be trivial in that circumstance to blow away any kind of NAT and the pseudo-anonymity/plausible deniabililty it provides and make client devices performing illegitimate activity directly identifiable. I wond…

Big ISPs don't want to become copyright enforcers; it costs them a lot of money already and enabling IPv6 would cost them even more. (ISPs that could cheaply deploy IPv6 have already done it, so the ones that haven't generally can't afford to.) They're greedy but they're not proactively evil.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#15

The court holds that the plaintiff must demonstrate reasonable evidence the defendant was the person using the computer. In this particular case, the defendant ran what amounts to lodging, was deposed, and it was immediately figured out it wasn't him. The complicating factor is that because his lodging was medical in nature, he was not able to hand over guest information. I mention this context because it's unlikely…

> I mention this context because it's unlikely you would be able to get out of being sued by saying "Well maybe it was my roommate LOL" Well, the question is whether I'm responsible for the use of my computer network. If someone hacks into it and starts using it without me noticing, am I responsible?

No, unlike something like a firearm which you are legally required to secure and can suffer potentially criminal and/or civil liability if someone steals it and uses it to commit a crime, there is no such legal requirement to secure your network against outsider misuse.

IANAL that’s just my personal understanding / belief.

The key point would be the use would have to be unsanctioned and you were totally unaware. Once you give someone your WiFi password, it’s less clear if you have any liability. I’m not sure of any case where the actual user was known but the person who provided the network connection was blamed.

Network access is fairly universal. The particular method used to access the Internet is practically irrelevant. The actor and the act are what is important, not how the packets are routed.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#16

Earlier quoted context omitted.

The facts of the actual case make it much easier to understand the problem, but how is that situation actually different? There are still multiple people it could have been, no evidence is presented to distinguish between them at all and it's an obvious injustice to punish one person when it was another who did it.

How do you know it wasn't a nearby neighbour piggybacking on your wifi?

You don't, that's the point; claiming "the criminals had mail sent to 1342 Grass Lane, therefore the owner of 1342 Grass Lane is the criminal" is patently ridiculous, and it's good that the court realizes that the same applies (if anything, even more so) to IP addresses.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#17
post #4

It surprises me in a way that "big internet" (AT&T, Verizon, Comcast etc) and associated large enterprise interests have not been more staunch proponents of IPv6, at least for fixed consumer connections. It would be trivial in that circumstance to blow away any kind of NAT and the pseudo-anonymity/plausible deniabililty it provides and make client devices performing illegitimate activity directly identifiable. I wond…

I would expect the home router to provide some level of device obfuscation in this case, specifically to help protect user privacy. I don’t its a fight that can be outright “won” but certainly you don’t just hand over unique device identifiers if at all possible.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#19
post #15

Earlier quoted context omitted.

> I mention this context because it's unlikely you would be able to get out of being sued by saying "Well maybe it was my roommate LOL" Well, the question is whether I'm responsible for the use of my computer network. If someone hacks into it and starts using it without me noticing, am I responsible?

No, unlike something like a firearm which you are legally required to secure and can suffer potentially criminal and/or civil liability if someone steals it and uses it to commit a crime, there is no such legal requirement to secure your network against outsider misuse. IANAL that’s just my personal understanding / belief. The key point would be the use would have to be unsanctioned and you were totally unaware. Once…

I believe the legal term you’re looking for is “strict liability”.

Many states don’t actually have laws about securing firearms directly but have a concept of strict liability about what happens if they are stolen, or stolen and not reported.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#20
post #3

>>> Judge rules that copyright trolls need more than just an IP address if they want to go after copyright infringement. An IP is not enough proof to tie a person to a crime. I didn't see anything in the story to suggest that the plaintiff was acting as a "troll" in the sense that I understand from reading about patent trolls. In this case, the plaintiff, while found to be in the wrong, was in fact the creator of the…

I would argue that in the case of file-sharing that it's Trolling when the plaintiff is going after an individual who, when removed from the system of distribution, would have no real effect on the rate or availability of the copyrighted work. Someone just downloading a copy would always fit this definition, and while BitTorrent always involves some amount of "distribution" by the legal definition, they don't represent a distributor in a meaningful way.

Going after this individual does not protect the the monetization of the copyrighted work. The individual's actions only represent the loss of motorization for the single copy they might have purchased. The only possible argument for this protecting monetization of the copyrighted work would be some kind of "chilling effect" on others sharing, but given the prevalence of file sharing after decades of such legal cases, this seems like a extremely weak argument.

Given that, then only reasonable conclusion is that the they are attempting to make money using the law itself, rather then using it to protect the monetization of the copyrighted work.

Post reply on HN