Live data from Hacker News

Mozilla hit with takedown request for anti-paywall addons

github.com

271–280 of 405 posts

Re: Mozilla hit with takedown request for anti-paywall addons

#271

Earlier quoted context omitted.

> To be fair, Linux and friends aren't much better in that regard. Linux gets there a different way. The standard way to install applications is from the package manager and essentially all of the applications in there are trustworthy (because they're all open source and if they did anything seriously user-hostile, someone would fork it and that version would be the one in the package manager). Meanwhile the package…

Package managers are exactly the centralized "app store" model, and there have been plenty of periods where users have had to add third party repositories to get basic functionality (DeCSS, video codecs, ZFS, etc). The difference is that Linux repositories are less noteworthy to attack, have a more distributed culture not ruled by capitulating lawyers, and can actually jurisdiction shop. The ultimate problem is a lac…

> Package managers are exactly the centralized "app store" model, and there have been plenty of periods where users have had to add third party repositories to get basic functionality (DeCSS, video codecs, ZFS, etc).

And they still work precisely because the user can do that.

> For decades we've been continually looking for better ways of isolating local apps, while also rejecting centralized control.

The main issue is that there is so little real benefit in it. It's possible to isolate e.g. LibreOffice so that it can't access anything it shouldn't, but in general the authors can be trusted not to be doing anything nefarious to begin with, so what you're really doing is limiting the damage in the event of compromise. In which case you're still pretty screwed, because it inherently needs access to your documents, so the focus has not surprisingly been on preventing compromise rather than mitigating after the fact.

> We keep looking, while centralization keeps ratcheting.

The motivations behind the rise in centralization are authoritarian and pecuniary rather than any legitimate security concern. Trying to prevent it by finding alternative ways to improve security is like trying to repeal the DMCA anti-circumvention rules by finding alternative ways to reduce piracy. They'll never be satisfied because their motivations aren't the stated ones.

Re: Mozilla hit with takedown request for anti-paywall addons

#272

Earlier quoted context omitted.

The protocol is the transaction demarcation point - anything else is sophistry. Let's try out an analogous argument with physical goods: Customer goes to Home Depot, buys a bunch of $5 aviators. Sells them on Amazon for $50. The distributor sues the customer-reseller for violating their contract to not commercially resell, which undermines their expensive offerings. Customer points out they never entered into any suc…

I don't find that analogy analogous. Alice goes to Home Depot. Aviators cost $50, but they're on sale for $5 if your name is Bob. Alice tells the cashier that her name is Bob and shows an (obviously) fake ID. The cashier isn't paid enough to care, so Alice gets the glasses for $5. I agree with you that anything Alice does after this point is her own business. I could accept an argument that Home Depot should've paid…

> Which the publishers do. They don't send the article unless they think you're Googlebot.

I've never had trouble viewing an article in incognito mode, or sometimes even hitting stopping a load before javascript runs, so I've been under the impression that it's mainly javascript trickery. My argument here was with that assumption, so perhaps it's moot.

> Alice tells the cashier that her name is Bob and shows an (obviously) fake ID. The cashier isn't paid enough to care

I'd say that the proper example is that the cashier doesn't check ID and isn't even expected to by corporate. Companies aren't even strictly against this type of soft-fraud word-of-mouth trick, as it just further helps their price discrimination and customer mindshare. Whether you get one free birthday desert per year or five, you're still buying meals.

The elephant in the room is that Google could easily setup a system whereby Googlebot got secure access to the articles. I think they haven't done this because of an idea that the same pages should be served to users. So who is defrauding whom?

Philosophically I'd assert that the Internet philosophy is directly opposed to the very concept of fraud - "identity" does not scale, especially across jurisdictions. We've finally got a way to formalize and mechanically execute contracts purely between private parties, so why cling to a heavyweight idea of post-facto enforcement based on nebulous ambient natural-language rules, especially as an overarching foundation? When you put a quarter into a "claw game" and it drops your prize before the chute you don't sue for "fraud" - you just stop putting quarters in.

Re: Mozilla hit with takedown request for anti-paywall addons

#273

The publishers want it both ways. They need to publish their full article content for search crawlers to read but don’t want humans to see it. The idea that this is a form of DRM protected by the DMCA is laughable in my opinion, but IANAL.

Could publishers index their own content and expose that through a common querying API that anybody could plug into ?

So Google could still deliver ranking and publishers put their content behind their walls.

Re: Mozilla hit with takedown request for anti-paywall addons

#274

This breaks the social contract of the web. If you publish on the web (over HTTP) using HTML (with or without css+js) then you respect the concept of a User-Agent that renders the content on behalf of the user. If you wish to get around this then create another file format and protocol and application/plugin to do so — one that enforces the DRM for the owner. Don’t take agency away from User-Agent.

[deleted]

Re: Mozilla hit with takedown request for anti-paywall addons

#275

Earlier quoted context omitted.

Package managers are exactly the centralized "app store" model, and there have been plenty of periods where users have had to add third party repositories to get basic functionality (DeCSS, video codecs, ZFS, etc). The difference is that Linux repositories are less noteworthy to attack, have a more distributed culture not ruled by capitulating lawyers, and can actually jurisdiction shop. The ultimate problem is a lac…

> Package managers are exactly the centralized "app store" model, and there have been plenty of periods where users have had to add third party repositories to get basic functionality (DeCSS, video codecs, ZFS, etc). And they still work precisely because the user can do that. > For decades we've been continually looking for better ways of isolating local apps, while also rejecting centralized control. The main issue…

> in general the authors can be trusted not to be doing anything nefarious to begin with

It's a dream. Kept alive by a very diligent community, but let's not kid ourselves that it's a very strong assumption.

> In which case you're still pretty screwed, because it inherently needs access to your documents

Access to the specific document you presently want to edit (say through an OS-provided file select dialog or equivalent cli) is much different than unfettered access to all of your files.

> The motivations behind the rise in centralization are authoritarian and pecuniary rather than any legitimate security concern

People do choose say Apple products precisely because of the curated Disneyland App store. Centralizers certainly have their selfish motives, but people are driven into their arms looking for safety. Browsers are used for software distribution precisely because they're a sandbox - there's much less fear of the unknown than running a random exe.

Re: Mozilla hit with takedown request for anti-paywall addons

#276

Earlier quoted context omitted.

[dead]

> Journalism has never been one of the foundation of democratic societies. So I'm assuming the news of what the people you voted for get to you via... diffusion? > . The united states and democracy itself existed far before journalist. You should sue your school for the permanent damage they did. Both in terms of grammar as well as history. In any case: if journalism is so useless, why are you jumping through hoops t…

> So I'm assuming the news of what the people you voted for get to you via... diffusion?

Maybe.

> You should sue your school for the permanent damage they did. Both in terms of grammar as well as history.

Okay. You might want to read about US history yourself. Take a gander at yellow journalism also and the history of news and news companies.

> In any case: if journalism is so useless, why are you jumping through hoops to read it?

I'm not.

Re: Mozilla hit with takedown request for anti-paywall addons

#277

Earlier quoted context omitted.

I don't find that analogy analogous. Alice goes to Home Depot. Aviators cost $50, but they're on sale for $5 if your name is Bob. Alice tells the cashier that her name is Bob and shows an (obviously) fake ID. The cashier isn't paid enough to care, so Alice gets the glasses for $5. I agree with you that anything Alice does after this point is her own business. I could accept an argument that Home Depot should've paid…

> Which the publishers do. They don't send the article unless they think you're Googlebot. I've never had trouble viewing an article in incognito mode, or sometimes even hitting stopping a load before javascript runs, so I've been under the impression that it's mainly javascript trickery. My argument here was with that assumption, so perhaps it's moot. > Alice tells the cashier that her name is Bob and shows an (obvi…

> I've never had trouble viewing an article in incognito mode, or sometimes even hitting stopping a load before javascript runs, so I've been under the impression that it's mainly javascript trickery. My argument here was with that assumption, so perhaps it's moot.

Typically publishers will use a combination of cookies and javascript to attempt to enforce a soft limit of X articles per month for normal users. Publishers also use UA sniffing to give unrestricted access to Googlebot and other crawlers.

Circumventing the former by blocking cookies or javascript definitely should be legal, because the client should be control of their local computer. Spoofing requests to take advantage of the latter (which is what this specific extension is doing) isn't okay IMO.

> The elephant in the room is that Google could easily setup a system whereby Googlebot got secure access to the articles. I think they haven't done this because of an idea that the same pages should be served to users. So who is defrauding whom?

Something other users have suggested[1] in response to this article. Maybe that will happen in the future, but I think it's a whataboutism with regards to this specific incident.

Google explicitly supports paywalled content[2], so I don't think it's fair to say that publishers are defrauding Google.

[1] https://news.ycombinator.com/item?id=18582893

[2] https://news.ycombinator.com/item?id=18584014

Re: Mozilla hit with takedown request for anti-paywall addons

#278

Earlier quoted context omitted.

> Just because something is on the internet doesn't give you the holly right of getting it for free. Why not?

The same reason why I can't just get your lawnmower even if it's visible, in your backyard.

A better comparison is dropping my lawnmower off in your backyard, teasing you with access, and then complaining when you touch it.

You cannot reasonably expect to protect or restrict content with a flawed understanding of the medium in which that content is conveyed.

If you don’t want me access it don’t put it on the web.

Re: Mozilla hit with takedown request for anti-paywall addons

#279
post #148

Earlier quoted context omitted.

I'd just move on. To be honest sites with those types of paywalls should not be indexed. The loophole you are taking advantage of here is a bait and switch by these sites. They want the search traffic but don't want public access. Most of us have already adapted, however, and avoid these sites or pay for them. Your plugin title blatantly describes that you're avoiding paying for something they are charging for so eve…

How is that bait and switch? Their content, their rules. Its like saying some people get Nike shoes for free in exchange for a review. And when I ask for it, or even take it, they have a problem with it. I think with physical goods we have an innate understanding of what constitutes as theft. Just because the distribution cost is zero doesn't make digital costs free-for-all.

It is a strained metaphor. What I was trying to say is that clicking on a search result and getting a paywall instead of the content alluded to on the search page is not expected behavior to the end user.

Re: Mozilla hit with takedown request for anti-paywall addons

#280
post #4

Earlier quoted context omitted.

Huh? This is a plugin that was removed from the plugin directories.

Yeah, just like you would remove a website from a websites "directory" or better just not display a website that breaks the law or better block it at ISP level! Welcome great firewall! Who said this is censorship?

You can install this plugin without repercussion. Let's not be dramatic.
Post reply on HN