Live data from Hacker News

US Court of Appeals: An IP address isn't enough to identify a pirate

techspot.com

51–60 of 68 posts

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#51

Earlier quoted context omitted.

> I mention this context because it's unlikely you would be able to get out of being sued by saying "Well maybe it was my roommate LOL" Well, the question is whether I'm responsible for the use of my computer network. If someone hacks into it and starts using it without me noticing, am I responsible?

France managed to create a law for that specific reason. France decided that any owner of a connection is responsible for it. So if you invite friends over and they start to torrent movies or else, you will be responsible.

How does this work for public locations like libraries or Starbucks? I remember when I went to France many places had free wifi (sometimes with password but it's not like it's hard to ask for it).

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#52

Earlier quoted context omitted.

France managed to create a law for that specific reason. France decided that any owner of a connection is responsible for it. So if you invite friends over and they start to torrent movies or else, you will be responsible.

How does this work for public locations like libraries or Starbucks? I remember when I went to France many places had free wifi (sometimes with password but it's not like it's hard to ask for it).

It is up to the company to "secure" their connection to prevent this type of thing (block some ports that are used to torrent, block websites, ...). We, technical people, know that is such an imperfect law that can be circumvented in so many ways and yet it exists today.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#53

Earlier quoted context omitted.

France managed to create a law for that specific reason. France decided that any owner of a connection is responsible for it. So if you invite friends over and they start to torrent movies or else, you will be responsible.

This seems strange. If someone uses my car for a malicious act, or uses my house's electrical connection to damage the grid, or something like that, I'm clearly not liable.

> If someone uses my car for a malicious act [...] I'm clearly not liable.

It is not that simple if you left your car unlocked. Leaving an unlocked car around with the key in the ignition is clearly a public danger.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#54

Earlier quoted context omitted.

This seems strange. If someone uses my car for a malicious act, or uses my house's electrical connection to damage the grid, or something like that, I'm clearly not liable.

> If someone uses my car for a malicious act [...] I'm clearly not liable. It is not that simple if you left your car unlocked. Leaving an unlocked car around with the key in the ignition is clearly a public danger.

If you put a law like this, why even have a justice system? Either you are guilty of piracy or you are guilty of not securing enough your computer.

Having a case where you are guilty whatever you say makes no sense, especially for something where the damages to society are very abstract and not proven, like piracy.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#55

Earlier quoted context omitted.

> If someone uses my car for a malicious act [...] I'm clearly not liable. It is not that simple if you left your car unlocked. Leaving an unlocked car around with the key in the ignition is clearly a public danger.

If you put a law like this, why even have a justice system? Either you are guilty of piracy or you are guilty of not securing enough your computer. Having a case where you are guilty whatever you say makes no sense, especially for something where the damages to society are very abstract and not proven, like piracy.

It's possible to actually nor have your computer used in piracy, and the justice system would still be about proving whether it was. Also, even if there was liability for negligence in security contributing to piracy, it might be lesser than for willful piracy itself.

The law suggested may be bad, but it doesn't remove the role of the justice system in determine the existence and degree of liability.

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#56
post #4

It surprises me in a way that "big internet" (AT&T, Verizon, Comcast etc) and associated large enterprise interests have not been more staunch proponents of IPv6, at least for fixed consumer connections. It would be trivial in that circumstance to blow away any kind of NAT and the pseudo-anonymity/plausible deniabililty it provides and make client devices performing illegitimate activity directly identifiable. I wond…

How exactly would this work? It's my understanding the IP addresses have to be allocated in a somewhat uniform manner to make routing feasible so it looks like it would require you to give a block of IPv6 addresses to the customer's router for it to allocate to the attached PCs, phones and what not, which seems like it would take us back to chewing through the address space pretty quick and also not necessarily achieve the desired effect unless the router keeps logs of the assignments it makes.

But if every device has a fixed or randomized identifier then surely the identifier contains absolutely no routing information whatsoever (the machine might have an address starting ffff:ffff:... but might be behind routers eeee:eeee:... or dddd:dddd:... in completely different parts of the world).

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#57

Earlier quoted context omitted.

How does this work for public locations like libraries or Starbucks? I remember when I went to France many places had free wifi (sometimes with password but it's not like it's hard to ask for it).

It is up to the company to "secure" their connection to prevent this type of thing (block some ports that are used to torrent, block websites, ...). We, technical people, know that is such an imperfect law that can be circumvented in so many ways and yet it exists today.

> block some ports that are used to torrent

So basically all of them? Because I can tell my torrent client to use whatever port I want

Re: US Court of Appeals: An IP address isn't enough to identify a pirate

#58

Some IP addresses are more personal than others. What I mean is that yes, on it's own an IP address does not pinpoint persons, but devices. So it remains upon the complainer in the case of a copyright infringement case to present a further reasoning 'above the speculative level' that the by the IP identified device at the time of the infringement was under the control of the alleged infringer. In this case they faile…

It usually points to a router, of which there can be hundreds of devices connected to it on your home network. Securing your wifi is one thing (which doesn't even absolutely prove that it was one of your home devices that did the torrenting, thanks to things like the KRACK attacks), but to then say "well you should secure your internal network such that torrenting cannot happen" is absolutely ridiculous. Torrent programs can work off any port, so that filters out port blocks. Is grandma going to install layer 7 traffic inspection so the grandkids can't doing illegal stuff on that newfangled interwebs? They'll switch to https then...

My point is that anyone with the technical know-how and very rudimentary internet access can bypass almost any restriction you try to put on it. What if the pirate is a minor and won't listen to their parents and keeps on torrenting? Do you permanently take their internet access away? How does that then stifle them for school homework or their social interaction? How can we expect each and every citizen to deploy NSA grade traffic monitoring on their router? The whole thing is ridiculous and the courts are still vehemently out of touch

Post reply on HN