Live data from Hacker News

Ask HN: Take down my reverse-engineered Snapchat lib because they asked?

news.ycombinator.com

71–80 of 137 posts

Re: Ask HN: Take down my reverse-engineered Snapchat lib because they asked?

#71
post #54

I've just forked it on Github, as have 25 others (as I write this). As with file formats, the notion that network protocols & APIs should ever be granted any type of protection and that no-one other than the creators should be able to write software that conforms to these protocols is ridiculous. Snapchat, in my view, have every right to restrict who uses their service and in what manner - via standard mechanisms lik…

"But preventing third-party implementations of protocols or APIs is so 90s." I think the impending 3Taps (padmapper.com) v/s Craigslist case[1] will shed more light on this. padmapper were using Craigslist data that is 'freely available' and Craigslist didn't like it. [1] http://www.dmlp.org/threats/craigslist-v-3taps

I don't think that's relevant at all. A "protocol or API" as the GP mentions exists independently of the entity which created it. PadMapper, on the other hand, is actively accessing Craigslist against their service's TOS.

Re: Ask HN: Take down my reverse-engineered Snapchat lib because they asked?

#73
post #19

Earlier quoted context omitted.

It may be dumb, but it's not laugh-out-loud crazy. In fact, it's specifically one of the things that the DMCA does. Here's a whole ton of information about the law: http://chillingeffects.org/reverse/faq.cgi And here's an article from the EFF with a few citations of cases where DMCA article 1201 has been used: https://www.eff.org/es/wp/unintended-consequences-under-dmca

> In fact, it's specifically one of the things that the DMCA does. Well, the specific thing the DMCA does is to stop circumvention of an "effective technological protection measure". The crazy thing here is that there is no such measure: no use of encryption or scrambling -- or even passwords! -- that I can see, just simply using a network service's exposed command set. That makes it different to most (if not all) of…

A private (that is, not published) API Key sure sounds like a protection measure to me.

Re: Ask HN: Take down my reverse-engineered Snapchat lib because they asked?

#74

I hate to play devil's advocate here (especially since I already have a post here) but I had a thought. For Snapchat some of the biggest selling points are the self destruct abilities of the media sent. So an unauthorized client puts a stake trough the heart of that claim (and the company). I see why they may be worried, but I think that they should have communicated their concerns more clearly and pleading, and not…

Exactly. "Self destructing" messages are an illusion. Publicizing this fact may be bad for Snapchat's business, but it's good for their users who have a false sense of security.

When I heard of snapchat I spent two seconds figuring out that turning off your data connection after receiving the photo allows you take as many screenshots/view the picture as many times as you want (I have no idea if this still works).

Re: Ask HN: Take down my reverse-engineered Snapchat lib because they asked?

#75
post #37

Morally, I would take it down. It is all well and good to write these sorts of things as a demo, but distribution is something where I would defer to the actual owner of the API in question. After all, how many of us would want someone creating an unauthorized library to a private API that we don't wish to have public?

As was ruled in the recent Oracle vs. Google case, APIs are not subject to copyright protection: https://www.eff.org/deeplinks/2012/05/no-copyrights-apis-jud...

You're responding to a moral argument with a legal argument.

Snapchat developed the service and the API. They don't want alternative implementations of the API to access their service. Morally, publishing such an alternative implementation is questionable. At best, it is discourteous in the extreme.

If someone asks you not to copy the product of their creative work, what moral justification do you have for doing so?

Re: Ask HN: Take down my reverse-engineered Snapchat lib because they asked?

#76

Earlier quoted context omitted.

I'm writing to ask... we consider.... Assuming the posted letter is complete, a lawyer can't really do anything at this point. The letter (or is it actually an email?) doesn't invoke any requirements one is bound by law to obey. One might even say that it's careful not to do so, so I suspect that even though the "Director of Operations" signed it, it was originally written by a lawyer. This would actually be a useful…

> Assuming the posted letter is complete, a lawyer can't really do anything at this point. A lawyer can analyze the facts of what you have done, and provide you with advice as to whether it is likely to be found to be an anti-circumvention device under the cited section of the DMCA and, if so, what the likely consequences of that are and what steps you can take to mitigate any exposure you might have in that regard (…

...there will be less, not more, that a lawyer can do for you.

At this point in time, OP can take down the repo (but not the 115-and-counting forks thereof), or modify it (someone suggested removing keys issued by Snapchat), or not. How will this set of options change if Snapchat file suit? Of course one must respond to a suit, but couldn't one's response be "ok we've complied with all requests"?

If you're telling me that the suit could allege OP owes Snapchat money for his/her misdeeds, that's true, but it's always true, even after one complies with the sort of namby-pamby "C&D" we see here.

Re: Ask HN: Take down my reverse-engineered Snapchat lib because they asked?

#77
It very much depends where you are and what you can afford in legal fees.

When you signed up you will have agreed not to do this sort of thing in the terms and conditions - whether that is legally enforceable or not could be expensive to prove either way. Though the worst they can do you for here is breach of contract.

With regard to "copyright circumvention": un-rot13 has been classed as an encryption circumvention device before now, so don't bank on the law having any common sense here.

My advice:

1. If it is just a weekend project it isn't worth the hassle, drop it as requested.

2. If you really care about it, lawyer up and prepare to fight.

In either case post to HN and as many other places as you can that are relevant to make sure their status as litigious wankers is recorded as far and wide as possible ;-)

Re: Ask HN: Take down my reverse-engineered Snapchat lib because they asked?

#78

Earlier quoted context omitted.

As was ruled in the recent Oracle vs. Google case, APIs are not subject to copyright protection: https://www.eff.org/deeplinks/2012/05/no-copyrights-apis-jud...

You're responding to a moral argument with a legal argument. Snapchat developed the service and the API. They don't want alternative implementations of the API to access their service. Morally, publishing such an alternative implementation is questionable. At best, it is discourteous in the extreme. If someone asks you not to copy the product of their creative work, what moral justification do you have for doing so?

I see this case as being different to copying someone's work. I do admit it's a bit morally questionable, in the sense that it's something that Snapchat doesn't want people doing. However, my view of the relationship between Internet services and client software which accesses those services is such that alternative implementations of both should be considered legitimate.

You have raised a very good point though, and it's certainly made me revisit my take on this. I've personally been the victim of others taking copies of my app and selling it under different names (which I obviously do have a problem with). However I've also seen other people implement similar features and a similar UI to my own app, and I don't have a problem with that - we only got to where we are today because of the spread of ideas through these means (see: Xerox PARC and all the companies that have used their work).

In this particular case there was no IP violation. It was simply an alternative implementation of a network protocol - and in fact it was just a library, not an application in and of itself. The only thing I think the author did wrong was to include the API keys.

Re: Ask HN: Take down my reverse-engineered Snapchat lib because they asked?

#79
post #73

Earlier quoted context omitted.

> In fact, it's specifically one of the things that the DMCA does. Well, the specific thing the DMCA does is to stop circumvention of an "effective technological protection measure". The crazy thing here is that there is no such measure: no use of encryption or scrambling -- or even passwords! -- that I can see, just simply using a network service's exposed command set. That makes it different to most (if not all) of…

A private (that is, not published) API Key sure sounds like a protection measure to me.

So they can revoke the key.
Post reply on HN