Live data from Hacker News

RIAA’s YouTube-dl takedown ticks off developers and GitHub’s CEO

torrentfreak.com

31–40 of 292 posts

Re: RIAA’s YouTube-dl takedown ticks off developers and GitHub’s CEO

#31

> GitHub’s CEO suggested that YouTube-DL won’t be reinstated in its original form. But, the software may be able to return without the rolling cipher circumvention code and the examples of how to download copyrighted material. Which is frustrating. Isn't the information needed to do this provided by youtube themselves? This isn't some private key that wasn't supposed to be public; it's literally given out every time…

When Handbrake first came around, it installed DeCSS since it was meant to convert DVD media. Because of that, I was not allowed to use it at corp job. At some point Handbrake changed to not include DeCSS, but if you had VLC installed it would use the library provided by the VLC install. This met our lawyer's approval and allowed us to use Handbrake vX.X and higher only.

Just an anecdotal story about how software that offends lawyers can become acceptable by making certain changes. I hope the suggested changes to YT-dl will allow it to pass lawyer's smell test.

Re: RIAA’s YouTube-dl takedown ticks off developers and GitHub’s CEO

#32
post #2

Really good to see Nat Friedman working towards resolving this issue.

I disagree. This looks more like pandering than anything else. Friedman has nothing to lose by making public statements of support, but a lot of reputation to gain if people buy into it. Instead of taking it down in the first place, Friedman should have told the RIAA to shove it, deliberately opening Github up to liability with the intent to defend this in courts and create precedent should the RIAA file suit. Even l…

Furthermore, if you view the IRC logs in question, he is only willing to reinstate the project if they remove the code the RIAA alleges violates Section 1201.

Re: RIAA’s YouTube-dl takedown ticks off developers and GitHub’s CEO

#33
To me the most interesting (and new to me) part is §Cease and Desist Notices:

> Following our initial coverage, we learned that the pressure against YouTube-DL had already started weeks earlier in Germany. Law firm Rasch, which works with several major music industry players, sent out cease and desist orders in the hope of taking YouTube-DL offline.

> Hosting service Uberspace was one of the recipients. The company hosts the official YouTube-DL site and still does so today. Instead of taking the website down, Uberspace replied to the notice through its own lawyer, who said that the hosting company hasn’t don’t anything wrong. [emphasis added]

> When the cease and desist notice was filed, yt-dl.org wasn’t even hosting the tool, as all download links pointed to GitHub, the company informs us.

[But the site does host the tool now, and Uberspace still doesn’t appear to have taken it down]

> “The software itself wasn’t hosted on our systems anyway so [but IIUC it is now], to be honest, I felt it to be quite ridiculous to involve us in this issue anyway – a lawyer specializing in IT laws should know better,” Jonas from Uberspace says.

Re: RIAA’s YouTube-dl takedown ticks off developers and GitHub’s CEO

#34

Asking developers to remove code is ridiculous. It reads more like "Bad cop/good cop" routine rather than genuine help.

It's not like any of us are going to be able to change the DMCA overnight and people rely on this tool for all kinds of purposes. Do we wait for somebody to magically fix the DMCA or do we make minor fixes to youtube-dl to make it less susceptible to bullshit DMCA notices like this? I assume most people just want the original repo to go back up and for normal development to continue before functionality breaks because of changing websites.

Re: RIAA’s YouTube-dl takedown ticks off developers and GitHub’s CEO

#35

Earlier quoted context omitted.

Sorry I thought it was canon. I remember seeing something suggesting it _years_ back. Truecrypt is unmaintained now, isn't it?

Truecrypt was mysteriously shutdown out of nowhere. Rumours abound that it was because of a national security letter or some other governmental interference. TC was never proven to be fundamentally insecure, but the original developers abandoned the project with the incident and the project was forked by others as VeraCrypt, which is now the recommended solution for local encryption (on Windows at least). audit: http…

Thank you. This was the correction I was looking for.

Re: RIAA’s YouTube-dl takedown ticks off developers and GitHub’s CEO

#36
post #12
post #2

Really good to see Nat Friedman working towards resolving this issue.

Asking the project authors to remove features that are covered by fair use isn't exactly what the authors want. It's better than no action, but not by much.

I'm wondering whether any legal team or similar have donated some time to figure out whether this is actually fair use or to set a precedent, because looking from the outside in, it clearly looks like an implementation meant to circumvent some form of intentionally-obfuscated protected handshake or access control.

From a strictly code based POV, it is intended to download protected objects with tests to ensure that protections are circumvented and the correct material can be retrieved. At the same time, removal of this code probably disables downloading of the majority of YouTube, and on top of that if there is no official collaboration on it, it'll be outdated within days.

Re: RIAA’s YouTube-dl takedown ticks off developers and GitHub’s CEO

#37
post #9

Always host software outside of US or *eyes jurisdictions. Think Truecrypt.

What happened to Truecrypt? Isn't that the one with the fundamental flaw that means everything it encrypted is trivial to unlock today? EDIT: this is a genuine question, I thought it had been unmaintained for ages and vulnerabilities had been found. My memory betrays me?

The (real) reasons for it shutting down were never given.

However, at the time it was theorized that in the event the maintainers had found a fundamental flaw, disclosing that flaw by issuing a patch would immediately jeopardize all preexisting truecrypt containers by revealing a method for breaking them. That would be untenable, and so the only alternative would be to shut down the entire project and recommend no further use of the software - as was done.

A subsequent audit did not identify any such security flaw, so the prevailing theory is now that the maintainers were forced to stop work by a governmental agency. It's considered safe and now known as veracrypt.

However, the question I have is whether a single crowdsourced security audit would be capable of finding a flaw that it took the developers themselves years (decades?) to identify.

Re: RIAA’s YouTube-dl takedown ticks off developers and GitHub’s CEO

#38
post #6

> GitHub’s CEO suggested that YouTube-DL won’t be reinstated in its original form. But, the software may be able to return without the rolling cipher circumvention code and the examples of how to download copyrighted material. Which is frustrating. Isn't the information needed to do this provided by youtube themselves? This isn't some private key that wasn't supposed to be public; it's literally given out every time…

I also find it laughable to claim that a session token is a "rolling cipher". If the claim is to be taken at face value, it would ban any form of scraping, as most sites invariably use some sort of session token.

So just “remove” it. Out with “rolling cipher circumvention” in with session token handling.

Re: RIAA’s YouTube-dl takedown ticks off developers and GitHub’s CEO

#39
> One of the most creative responses we’ve seen was posted to Twitter by @GalacticFurball who encoded YouTube-DL into images that can be easily shared, encouraging others to share these as well.

Reminds me Free Speech Flag story: https://en.wikipedia.org/wiki/Free_Speech_Flag

All this highlights what an unconstitutional monstrosity DMCA 1201 is. You reap what you sow RIAA. Hopefully this will trigger the push to repeal this trash altogether.

Re: RIAA’s YouTube-dl takedown ticks off developers and GitHub’s CEO

#40
post #17
post #10

Earlier quoted context omitted.

You can download mp4 files directly from Youtube. I've found a way to download videos right from the domain googlevideo.com . No 3rd party tools, any requested clarity. I thought I'll make a post to explain this easy method, then realized Google would take down that method within a week, so I'm keeping quiet.

>> You can download mp4 files directly from Youtube. You really can't. >> I've found a way to download videos right from the domain googlevideo.com I assure you, you really didn't.

Just curious... why should anyone trust your assurances?
Post reply on HN