Live data from Hacker News

US Court of Appeals: An IP address isn't enough to identify a pirate

techspot.com

21–30 of 68 posts

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#21
post #15

Earlier quoted context omitted.

No, unlike something like a firearm which you are legally required to secure and can suffer potentially criminal and/or civil liability if someone steals it and uses it to commit a crime, there is no such legal requirement to secure your network against outsider misuse. IANAL that’s just my personal understanding / belief. The key point would be the use would have to be unsanctioned and you were totally unaware. Once…

I believe the legal term you’re looking for is “strict liability”. Many states don’t actually have laws about securing firearms directly but have a concept of strict liability about what happens if they are stolen, or stolen and not reported.

Thanks, this is super helpful terminology to know.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#22
post #15

Earlier quoted context omitted.

> I mention this context because it's unlikely you would be able to get out of being sued by saying "Well maybe it was my roommate LOL" Well, the question is whether I'm responsible for the use of my computer network. If someone hacks into it and starts using it without me noticing, am I responsible?

No, unlike something like a firearm which you are legally required to secure and can suffer potentially criminal and/or civil liability if someone steals it and uses it to commit a crime, there is no such legal requirement to secure your network against outsider misuse. IANAL that’s just my personal understanding / belief. The key point would be the use would have to be unsanctioned and you were totally unaware. Once…

> you are legally required to secure and can suffer potentially criminal and/or civil liability if someone steals it and uses it to commit a crime

Where does this happen?

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#23

Earlier quoted context omitted.

How do you know it wasn't a nearby neighbour piggybacking on your wifi?

because wifi is reasonably secure by default these days?

That notion is conradicted by numerous articles about WPA2 cracks.

https://hn.algolia.com/?query=wpa&sort=byDate&prefix&page=0&...

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#24

The court holds that the plaintiff must demonstrate reasonable evidence the defendant was the person using the computer. In this particular case, the defendant ran what amounts to lodging, was deposed, and it was immediately figured out it wasn't him. The complicating factor is that because his lodging was medical in nature, he was not able to hand over guest information. I mention this context because it's unlikely…

[deleted]

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#25

The court holds that the plaintiff must demonstrate reasonable evidence the defendant was the person using the computer. In this particular case, the defendant ran what amounts to lodging, was deposed, and it was immediately figured out it wasn't him. The complicating factor is that because his lodging was medical in nature, he was not able to hand over guest information. I mention this context because it's unlikely…

> I mention this context because it's unlikely you would be able to get out of being sued by saying "Well maybe it was my roommate LOL" Well, the question is whether I'm responsible for the use of my computer network. If someone hacks into it and starts using it without me noticing, am I responsible?

Suppose you lived alone, and this scenario unfolded. The plaintiff would reasonably argue that because you lived alone, you were the infringer. Would a court believe this to be reasonable? The ruling doesn't say. Now, if you then, using your own money, hired a computer forensics tech who discovered evidence you had been hacked, and also surrendered your computer and router in discovery and it was confirmed the router showed signs of unauthorized access and the computer didn't have file sharing programs or the file in question, I think it's fairly clear this court would let you off the hook. On the other hand, if your forensics tech found no evidence of tampering and did find filesharing software on your computer, I think you'd have a much harder time asserting that your alibi causes their allegation to fall apart.

The court is saying "Look, you can't just saying the IP address is the person, you need to offer a reasonable claim that it is". It is not saying IP addresses are useless or that your identity must be proven beyond a reasonable doubt.

Neither my first post nor this post were meant to be normative -- I'm not from the US, the country I am from makes passive filesharing (i.e. uploading while torrenting) more or less legal, and I would be very happy if legal rulings stopped piracy fishing expeditions. I just wanted to describe the substance of the ruling in a more substantial way than the headline did.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#27

The court holds that the plaintiff must demonstrate reasonable evidence the defendant was the person using the computer. In this particular case, the defendant ran what amounts to lodging, was deposed, and it was immediately figured out it wasn't him. The complicating factor is that because his lodging was medical in nature, he was not able to hand over guest information. I mention this context because it's unlikely…

>>I mention this context because it's unlikely you would be able to get out of being sued by saying "Well maybe it was my roommate LOL"

Why not? It's illegal to download a movie and they have to prove what person did it. Roommate, father, sister...neighbor.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#28

Earlier quoted context omitted.

> I mention this context because it's unlikely you would be able to get out of being sued by saying "Well maybe it was my roommate LOL" Well, the question is whether I'm responsible for the use of my computer network. If someone hacks into it and starts using it without me noticing, am I responsible?

Suppose you lived alone, and this scenario unfolded. The plaintiff would reasonably argue that because you lived alone, you were the infringer. Would a court believe this to be reasonable? The ruling doesn't say. Now, if you then, using your own money, hired a computer forensics tech who discovered evidence you had been hacked, and also surrendered your computer and router in discovery and it was confirmed the router…

> Suppose you lived alone

The best way I can interpret this is that your post was being deliberately misleading, because you implied that roommates won't invalidate IP authentication, but you actually meant that lying about having roommates won't invalidate IP identification.

Am I missing a more reasonable interpretation?

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#29

The court holds that the plaintiff must demonstrate reasonable evidence the defendant was the person using the computer. In this particular case, the defendant ran what amounts to lodging, was deposed, and it was immediately figured out it wasn't him. The complicating factor is that because his lodging was medical in nature, he was not able to hand over guest information. I mention this context because it's unlikely…

>>I mention this context because it's unlikely you would be able to get out of being sued by saying "Well maybe it was my roommate LOL" Why not? It's illegal to download a movie and they have to prove what person did it. Roommate, father, sister...neighbor.

This is a civil suit, not a criminal case.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#30
post #14
post #4

It surprises me in a way that "big internet" (AT&T, Verizon, Comcast etc) and associated large enterprise interests have not been more staunch proponents of IPv6, at least for fixed consumer connections. It would be trivial in that circumstance to blow away any kind of NAT and the pseudo-anonymity/plausible deniabililty it provides and make client devices performing illegitimate activity directly identifiable. I wond…

Big ISPs don't want to become copyright enforcers; it costs them a lot of money already and enabling IPv6 would cost them even more. (ISPs that could cheaply deploy IPv6 have already done it, so the ones that haven't generally can't afford to.) They're greedy but they're not proactively evil.

I don't agree. Keep in mind who owns the big ISPs and what corporate empires they're apart of. Several of the biggest ISPs (especially the cable ones) are part of giant media conglomerates - their corporate parents are also the parents of some of the biggest copyright owners out there.

Ex: https://en.wikipedia.org/wiki/List_of_assets_owned_by_NBCUni... (Comcast)

https://en.wikipedia.org/wiki/AT%26T#Corporate_structure (AT&T)

Post reply on HN