Live data from Hacker News

YouTube-dl has received a DMCA takedown from RIAA

github.com

381–390 of 1001 posts

Re: YouTube-dl has received a DMCA takedown from RIAA

#381
post #322

Earlier quoted context omitted.

It's kind of amazing that computing in general, and the internet in particular, is as open and free as it is (contrast with the closed end-to-end "appliance" model of gaming consoles, or to some extent iOS). Cory Doctorow has been ringing alarm bells for over a decade about both technical and legal efforts to end general purpose computation itself, or at least to make it more the exception than the norm: https://www.…

> end general purpose computation itself, or at least to make it more the exception than the norm I'd argue, cautiously, that general computation is already an exception. That's why I prefer Linux to Windows. On Linux I can issue a command from a general command interface (the CLI) to just play a video. If I only want audio, it's an option away. I can script things together. Most of my tools are interoperable. That's…

One thing that might be coming up is CPUs reducing the user capability to fully control the system (regardless of whether you run Linux or Windows).

One such example is Intel ME. In the future, if the compute paradigm shifts towards something cloud-like, we might all be "stuck" inside an isolated Intel SGX container (or vice versa).

Re: YouTube-dl has received a DMCA takedown from RIAA

#382
post #139

While its good to get a backup of the source code, youtube-dl is one of those projects that quickly becomes useless as Google mixes stuff around within YouTube, which they like to do. Without an active developer base, the project will quickly become less and less effective, which is one of the big concerns IMO about this lawsuit.

What if collaboration on opensource projects (i.e. hosting, issues and their comments) was decentralized instead of relying on a central entity like Github? That would keep the developer base active and make DMCA takedowns ineffective.

Git-on-the-Blockchain?

Re: YouTube-dl has received a DMCA takedown from RIAA

#383

Curious if anyone with legal expertise knows if this has legs? They say: > The clear purpose of this source code is to (i) circumvent the technological protection measures used by authorized streaming services such as YouTube, and (ii) reproduce and distribute music videos and sound recordings owned by our member companies without authorization for such use. But the "circumventing" is still accessing a stream the use…

Also, does the fact that YouTube doesn't supply a download feature constitute a "technical protection measure"? From the RIAA's point of view, it works to their benefit that a download link doesn't exist, and it may be something they like, but that doesn't mean that's why. It could just as easily be that a download feature doesn't exist because YouTube wants you to keep returning to their site if you want to rewatch…

You are able to download YouTube videos on your phone, if you subscribe to YouTube premium. I haven’t made any deep investigation of this but I kinda assume the videos are protected by DRM.

Re: YouTube-dl has received a DMCA takedown from RIAA

#384
post #293

Earlier quoted context omitted.

Do you have some sort of RMS-style setup? If so, I'm curious about your reasons for that and why mainstream browsers aren't an option for you

Not OP, but I personally use youtube-dl to retrieve videos on a remote server accessed via ssh, which then get downloaded slowly over a low bandwidth link for offline viewing at a later time. They may or may not get reencoded using the ffmpeg integration before retrieving as well. YouTube's web interface is basically useless for me on a slow link, not to mention it's incredibly obnoxious with all its recommendations…

> YouTube's web interface is basically useless for me on a slow link

I've never used youtube-dl. How do you find the videos to download?

Re: YouTube-dl has received a DMCA takedown from RIAA

#385
post #4

Note that RIAA is making this takedown because the software CAN be used to download copyrighted music and videos, and it uses examples in the ~~README~~(unit tests, see correction[1]) as an example of that: > We also note that the source code prominently includes as sample uses of the source code the downloading of copies of our members’ copyrighted sound recordings and music videos, as noted in Exhibit A hereto. For…

IANAL, but regardless, according to RIAA, youtube-dl is circumventing the "DRM" built into YouTube, and therefore they're violating anti-circumvention parts of the DMCA. Therefore a DMCA claim can suffice to take it down. Perhaps if youtube-dl used different examples (i.e. videos not protected by anti-circumvention) perhaps they could have avoided this.

> according to RIAA, youtube-dl is circumventing the "DRM"

I didn't find any mention of "DRM" or "Digital rights management" on the page. Can you be more specific?

Re: YouTube-dl has received a DMCA takedown from RIAA

#386
The actual content of the legal argument being made by the RIAA in this and associated documents is lying by omission at best, and arguably is straight up perjury.

The only _concrete_ circumvention they level at youtube-dl is that it "circumvents YouTube’s rolling cipher". I looked into this more, and before I go into how totally bulshit it is that they've apparently conned judges into believing this, you should read their full accusation (or just read the full DMCA letter from the RIAA):

    For further context, please see the attached court decision from the Hamburg
    Regional Court that describes the technological measure at issue (known as
    YouTube’s “rolling cipher”), and the court’s determination that the technology
    employed by YouTube is an effective technical measure within the meaning of EU

    1 See https://github.com/ytdl-org/youtube-dl/blob/master/README.md#readme.

    and German law, which is materially identical to Title 17 U.S.C. §1201 of the
    United States Code. The court further determined that the service at issue in
    that case unlawfully circumvented YouTube’s rolling cipher technical
    protection measure.2 The youtube-dl source code functions in a manner
    essentially identical to the service at issue in the Hamburg Regional Court
    decision. As there, the youtube-dl source code available on Github (which is
    the subject of this notice) circumvents YouTube’s rolling cipher to gain
    unauthorized access to copyrighted audio files, in violation of YouTube’s
    express terms of service,3 and in plain violation of Section 1201 of the
    Digital Millennium Copyright Act, 17 U.S.C. §1201.
So that's what the RIAA is saying that youtube-dl is doing. However, they're referencing a document that I _presume_ was attached to their original email, the document from the Hamburg Regional Court, but we don't have that email, as Github didn't publish that document for us to see.

So I went looking, and it turns out that the RIAA has used this exact same excuse to go after some other people, their documents are available, and we can see more of what they wrote. I'm referencing this[1] document which I found through this[0] blog post about a 2016 case where the RIAA went after an online service called TYMP3. Here are the links, and here's what the RIAA said:

[0] - https://www.techdirt.com/articles/20160927/17062135646/can-s...

[1] - https://assets.documentcloud.org/documents/3114545/YTMP3-Com...

    
    39. Plaintiffs are informed and believe, and on that basis allege as follows:
    YouTube has adopted and implemented technological measures to control access to
    content maintained on its site and to prevent or inhibit downloading, copying,
    or illicit distribution of that content.  YouTube maintains two separate URLs
    for any given video file: one URL, which is visible to the user, is for the
    webpage where the video playback occurs, and one URL, which is not visible to
    the user, is for the video file itself.  The second URL is generated using a
    complex (and periodically changing) algorithm - known as a “rolling cipher” -
    that is intended to inhibit direct access to the underlying YouTube video
    files, thereby preventing or inhibiting the downloading, copying, or
    distribution of the video files.

    
    Among other things, Plaintiffs are informed and believe, and on that basis
    allege, that YTMP3 employs a means to circumvent the YouTube rolling cipher
    technology described above, and other technological means that YouTube employs
    to protect content on its site.
So, let's go see what the Youtube-dl source code actually is doing. The tl;dr version is that youtube does some slight rearranging of the characters in the URL of the remote resource, but they also supply you with the JS code to un-arrange that code into the actual working "signature" which you can use to request the video from youtube. So youtube-dl downloads the rearranged URL, and the JS that youtube provides, and uses a Python implementation of the JS interpreter to run YOUTUBE'S OWN JS THAT YOUTUBE SENT US IN CLEARTEXT TO FIGURE OUT HOW TO DOWNLOAD THE VIDEO. See the source code (hosted on gitlab for now, hopefully that stays up):

https://gitlab.com/HacktorIT/youtube-dl/-/blob/master/youtub...

So to summarize, youtube creates two URLs: one that's a public video URL, and one that's the URL to the actual video content. The URL to the video content changes on a rolling basis, and is slightly rearranged. All that's true. However, what the RIAA is avoiding saying, and which completely changes the context of this discussion is:

YOUTUBE SENDS YOU BOTH URLS IN CLEARTEXT, AND INCLUDES THE CODE FOR HOW TO DOWNLOAD THE VIDEO, SO YOU AND YOUR WEB BROWSER CAN DOWNLOAD THE VIDEOS WITHOUT USING ANY ENCRYPTION/DECODING.

So when a judge asks "how is it that you're getting around this 'rolling cipher' to access the video?" all you have to say is "Youtube told me where to download the video, so I followed Youtube's instructions and downloaded it from the URL that Youtube gave me."

Frankly, I'm amazed that any judge, or any lawyer, would ever lay out or believe such bare faced lies as is being spouted by the RIAA in this document.

FUCK THE RIAA

Re: YouTube-dl has received a DMCA takedown from RIAA

#387
post #37

Earlier quoted context omitted.

I was thinking the same thing: The next step following this line of thinking would be trying to ban all torrent clients, because they CAN be used to download copyrighted material. This is crazy.

Why stop with torrent clients? They should ban all browsers, because they CAN be used to download copyrighted materials!

We need to ban oxygen. It CAN be used to download copyrighted materials!

Re: YouTube-dl has received a DMCA takedown from RIAA

#389

It is a bit of a tough question. How would I feel about someone borrowing a book from a library and then photocopying it to keep a local copy? If the intent was to re-distribute then I would not feel comfortable allowing it. However, if the proposed remedy was to ban personal ownership of photocopiers I would not even consider that a valid approach. But would I expect I could keep my own photocopied version instead o…

While photocopying books for distribution is against the law, I disagree that it should be against the law. If 3 people all borrow the same book sequentially then it's fine. If one person borrow it, photocopies it twice to share with two others, then they've broken the law. And yet nobody in either case has made more or less money. I am in favor of copyright law that prevents profiting from another person's work, but…

I mean it's not the best setup, but what else do you suggest? This was meant for protecting income of authors while not being too inconvenient for most users. Netflix primary model is this and it is working great for them and users. Many people do share the account but it does add some inconvenience that only some maximum number of people can watch at the same time, making people get subscription.
Post reply on HN