Live data from Hacker News

Why you should not pirate Google’s geo APIs

petewarden.com

91–100 of 117 posts

Re: Why you should not pirate Google’s geo APIs

#91
post #67

Earlier quoted context omitted.

I would offer that any potential or actual user of the API is an apt judge of whether the API has been offered "in a reasonable manner." As it currently stands, one has the option of 2,500 requests per day for free or a minimum of $10,000 [1] and a limit of 100,000 requests per day. Is it unreasonable to wish for at least one option between the two current choices of $0 and >=$10,000? The parent isn't being self-enti…

So why was it outside the ToC to take the five snapshots for the Crime Doesn't Climb gif?

I do not know if the Crime Doesn't Climb usage was against the ToS.

They could have possibly made all their requests within the rate limit imposed by Google. I'm unsure, however, if their usage of the data was allowed: "The Elevation API may only be used in conjunction with displaying results on a Google map; using elevation data without displaying a map for which elevation data was requested is prohibited." [1]

That said, I certainly think it's reasonable to want Google to allow paid access to their API at a rate between their current free offering and their prohibitively expensive offering for personal and small business usage.

[1] https://developers.google.com/maps/documentation/elevation/#...

Re: Why you should not pirate Google’s geo APIs

#92
post #42

Earlier quoted context omitted.

Personally, I think it's silly to think that you may be bound to the terms of an agreement just because you clicked a button that says "Agree", without any of the fundamental attributes of a contract being present, and without even interacting with a representative of the other party in any way.

I've noticed typically I agree with your views, but on this case we diverge. I think it's reasonable to assume that when the service cannot be accessed before the accessor clicks "agree", and the accessor clicks "agree", that constitutes a valid contractual agreement. It's no more silly than mailing in a credit card application and being bound by those terms. The fundamental attributes are present. There is a contrac…

I'm not a lawyer, so take the following with much salt. Furthermore, I'm arguing more from an "ideal legal world" viewpoint rather than the current American legal environment.

A contract must consist of:

1. A "meeting of the minds." This means both sides come to a common understanding of what's in the contract. Basically, it means there's an offer by one side and acceptance by the other without changes.

2. Intention to be legally bound. Basically, this means that the context of a contract matters. It seems to boil down to commercial agreements generally being enforceable while others (e.g. promising money to family) are not.

3. Consideration. This is some sort of exchange of value. In short, a contract cannot be one-way. This is why you sometimes see e.g. things being sold for $1 rather than being just plain given away for free.

The way I see it, there are serious problems for click-through agreements for both 1 and 3. 2 is not a big deal, as despite the name, it doesn't appear to actually apply to the case where you click Agree without the intention to follow the contract.

One problem with #1 is that essentially nobody ever reads these things. In general, "I didn't read the contract I signed" is not an excuse, of course. However, I think this does (or should) change when everybody doesn't read it, because it means that the other party knows, or should know with reasonable certainty, that you're unaware of the contents. Normally you presume that each party is aware of the contents of the contract, but you can't do that with click-through agreements since it's widely-known that they go unread. A contract which I don't read and which you are well aware I didn't read should not be enforceable. For high-value, important contracts like buying a house, a person familiar with the contract will go over each page with you and have you initial it to affirm that you read it, precisely to avoid this problem. The combination of widespread failure to read the contracts and a complete lack of effort to ensure that you, personally read the one in question means that, IMO, there is no meeting of the minds.

Another problem with #1 is that there is either no opportunity to propose changes, or the other side never notices or reviews them. With a normal contract, I can cross out clauses, add or change wording, etc., at which point the other party can accept or reject my changes, or propose further changes. Where this really runs into trouble, I think, is when you edit the contract locally before clicking Agree. This is generally trivial using a DOM inspector for any click-through agreement found on the web. Imagine I take the ToS in question here and alter it to read, "In exchange for mikeash's use of the Google API, Google promises to pay mikeash the sum of ten million dollars." Then I click Agree. Should Google be bound by this agreement? I imagine you immediately and strongly say "No!" But why should I be bound by the original while they are not bound by the alteration? In a normal contractual setting, they have the opportunity to say yes or no to my proposed changes. They will, of course, say no. In this setting, they don't say no! They simply grant me access to their service after I "Agree" to the altered contract. Does this not imply acceptance on their part? If not, what's the difference between their situation and mine?

Finally, #3 seems to completely destroy the concept of any click-through agreement that isn't part of some sort of payment process. Terms of service presented as part of a checkout process would seem to be fine in this respect, but when presented as part of a free web site, it doesn't seem to work. They give you access in exchange for... nothing. Similarly, click-through software licenses seem to fail here because they show up after the money has been exchanged. I pay for a copy of software which I obtain, and only later am I presented with the EULA. Since the money and product already changed hands, there's no further consideration, and so the EULA should not have force.

That's my thinking. I welcome dissenting opinions.

Re: Why you should not pirate Google’s geo APIs

#93
post #40

Earlier quoted context omitted.

You're not at all obligated to abide by an open source license that just happened to be bundled in with a bunch of files you downloaded. The thing is, without that license, you're bound by copyright. That means you're not allowed to redistribute those files, or anything derived from them, at all without permission from the copyright holder, with the exception of uses allowed by fair use. For source code and similar t…

I think the point you make is an excellent one. However, we've seen court decisions that essentially equate ToS violations with wire fraud, no? I wonder where the line gets drawn...

My point is simply that the two are not at all equivalent. An open-source license grants additional rights to the person receiving the license, while terms of service restrict the person receiving it. As such, there is no inconsistency whatsoever with saying that one should not be automagically bound by such things just because they clicked through them or they happened to be sitting on a web site that you use. It doesn't matter at all if you violate the terms of an open source license. All that means is that you don't enjoy the additional rights granted to you by that license. You can still enjoy all of the rights granted to you by normal copyright, which means that you can use your copy and make additional copies in ways covered by fair use. If you go beyond that, you're violating copyright, and that is the fundamental problem, not violating the license. Violating the license is only a problem when you want to use some of it (e.g. the permission to distribute derived works) but not other parts of it (e.g. the requirement to distribute source code).

Violating a license isn't illegal, only violating copyright is. I don't think there's an equivalent for terms of service for a freely-available service.

Re: Why you should not pirate Google’s geo APIs

#94
post #4

Everyone should try OpenStreetMap based APIs, e.g. MapQuest Open.

I tried one part of the API recently - I'm building an app that's partially intended to give local cycling directions. Now I'm between a rock and a hard place. One the one hand some parts of the MapQuest Open API are extremely bad, on the other hand Google has an all-or-nothing license for their geo data, and their native iOS maps component sucks. MapQuest's cycling directions in Manhattan is worse than having no dir…

Yeah, I was doing some tinkering with OSM and found a lot of that kind of additional data (bike trails and such) to be missing. Obviously I should just roll up my sleeves and contribute to OSM, but it still means that I wouldn't build an app or do large research that depends on those kinds of details with OSM as the back-end, knowing how much stuff is missing.

And yes, more municipalities need to start releasing open data.

Re: Why you should not pirate Google’s geo APIs

#95

Earlier quoted context omitted.

If you agreed to a ToS by clicking yes, and the ToS allows them to install malware that's a failure on your part to read it. If your child clicks it, you probably have recourse in civil court because a 4-year-old is not able to execute contracts. Most ToS's include a clause that they can change it at any time; you might not be legally bound by the new one, check that with a lawyer. It seems like you are angered that…

No, I just say that the fact that someone clicked accept button on some website is not a proof that I accepted anything. If things worked like that you would not be required to go to the bank to sign a contract and take a loan, one mouse click on bank website would be enough. I could as well write whatever ToS on my homepage with "accept" and "not accept" link with whatever terms, and then wait for Google bot to "acc…

Well I think the burden of proof is going to be on you if you are found willfully using the service afterwards. Otherwise you're probably right.

Re: Why you should not pirate Google’s geo APIs

#96
post #90

Earlier quoted context omitted.

Building your own elevation API is absolutely trivial; I don't know why anyone would even want to pirate Google's API for large-scale usage. Firstly, the data is freely available. It's NASA's SRTM [1], downloadable from a zillion mirror sites. Then just take some code to calculate a lat/long offset and find the right position in the right tile. Bob Osola has some easily portable PHP for this if you need it [2]. Free…

interesting. I think of these data are freely available, then there ought to be more people using it and making competing versions so that google will not have a monopoly on provision of such data apis.

Don't wait for "other people;" if you think it should be done, I'd encourage you to do it yourself!

Re: Why you should not pirate Google’s geo APIs

#97
post #66

Earlier quoted context omitted.

In the specific example of the elevation data set, the data for the United States looks like it's public domain (USGS DEMs). The rest of the world may be more difficult to get high resolution but there is STRM which is reasonable ok for a lot of uses.

About three years ago I got in contact with some very nice people at NASA and/or the USGS (I don't recall which agency ended up being the end-point) for what, at the time, was some of the best data available from the joint ASTER missions they ran with Japan. The process was essentially to fill out a form and send them a new, unopened hard drive. What I got back a few weeks later was about 125GB of high resolution Geo…

I’ve worked with NASA and USGS a fair deal both for fun and professionally, and this is typical.

They are extremely competent and sincerely want you to have good data. They are also hampered by the bureaucratic limits of any large organization. So it’s like working with a large, well-run business that’s hired a lot of the best people in its field and is working on good problems, yet is large enough that it can’t move to meet the exact needs of any one customer.

But on top of that there are political concerns. They have an institutional fear that a congressperson in a budget debate is going to stand up and say something like “And apparently we’re paying the Geological Survey $N million a year to run a web server for something called geotiffs that tell you how tall hills are!” That’s my impression from reading between the lines, anyway; no government employee I know has been indiscreet enough to deliberately hint at such a fear.

For example, the best interface to SRTM isn’t from the agencies that made it, it’s a single-page project from Derek Watkins at the NYT: http://dwtkns.com/srtm/

Working with NASA in particular feels like working with an industry leader that has a mysterious policy against advertising, or even going out of its way to help you find resources. (Individuals do, but not the organization, at least not anywhere near in proportion to the number and value of its resources.)

NOAA too: they have some amazing satellite imagery that’s public domain, but they simply do not have the budget to do anything but the most halfassed job of hosting, publicizing, and documenting it, because from a funding perspective that’s frivolous. They barely archive their images, because no one with budget control gets why a weather agency should save its input data. Look up “VIIRS granule” – that’s technically open data, but yikes.

The resources are there, and if you make the effort to figure it out, the people who manage them are pretty much all a delight to work with. But you have to deal with the damage created by a political culture that too often treats our civilian space and geospatial agencies as afterthoughts rather than as highly multiplied public goods.

Re: Why you should not pirate Google’s geo APIs

#98
post #58

Earlier quoted context omitted.

I would have some sympathy with this if you made it easy for single people to pay you to be able to use your data in a manner outside of the ToS of the free APIs. However, for the Elevation API there are two choices: * free and heavily restricted * business api, which looks extremely sketchy † and is blocked to most people The gaming world has learned this with Steam and friends already. People will pirate the hell o…

I don't understand this feeling of self-entitlement - who are we to judge whether or not an API has been offered "in a reasonable manner?" I'm guessing it's very resource-consuming to collect, process, and maintain the data necessary for geolocation APIs (especially given the upstream providers). It'd be one thing for Google to be deceptive about it, offer a free service, and try to upsell you every point along the w…

There are many problems with the ownership of data, entitlement, etc.

I've argued with the founder of delicious endlessly about the API limits they imposed which ultimately meant that nothing interesting could be done on the outside with delicious. Nothing interesting ever happened on the inside and ultimately it got sold to Yahoo! and destroyed. I guess the founder got some cash, but the data that was contributed by the end users was destroyed.

Nobody asked them for permission to sell to a psychotic company, have the site destroyed, etc.

Towards the end spammers found that they could (within the API terms) get endless amounts of legitimate 'cover traffic' to cover their links.

Re: Why you should not pirate Google’s geo APIs

#99
post #58

Earlier quoted context omitted.

I don't understand this feeling of self-entitlement - who are we to judge whether or not an API has been offered "in a reasonable manner?" I'm guessing it's very resource-consuming to collect, process, and maintain the data necessary for geolocation APIs (especially given the upstream providers). It'd be one thing for Google to be deceptive about it, offer a free service, and try to upsell you every point along the w…

I would offer that any potential or actual user of the API is an apt judge of whether the API has been offered "in a reasonable manner." As it currently stands, one has the option of 2,500 requests per day for free or a minimum of $10,000 [1] and a limit of 100,000 requests per day. Is it unreasonable to wish for at least one option between the two current choices of $0 and >=$10,000? The parent isn't being self-enti…

I actually talked to Google yesterday. Minimum tier is 100k per day at $17.5k per year. Very fair price (If you think that is expensive, then you clearly do not work in commercial GIS, where licensing of software and data is insanely expensive). At the same time, they force you to use the data on a Google Map component (yes, even for the paid accounts), and while their api is acceptable, their js map control is severely lacking in features compared to something like leaflet, openlayers, or esri's js component. This may have very well been simply an arbitrary decision, but it has the effect of snuffing out any small companies or start ups that want to use their apis to build new, innovative applications. Considering the big few companies in this space bought up just about all the data companies that originally compiled the underlying data, this seems completely anti-competitive to me. I am not saying they should give it away for free, but there should definitely be some smaller paid plans with more open terms of use, considering that Google and the couple other competitors basically just purchased a cartel together over the last decade.

Re: Why you should not pirate Google’s geo APIs

#100
post #58

Earlier quoted context omitted.

I don't understand this feeling of self-entitlement - who are we to judge whether or not an API has been offered "in a reasonable manner?" I'm guessing it's very resource-consuming to collect, process, and maintain the data necessary for geolocation APIs (especially given the upstream providers). It'd be one thing for Google to be deceptive about it, offer a free service, and try to upsell you every point along the w…

Building your own elevation API is absolutely trivial; I don't know why anyone would even want to pirate Google's API for large-scale usage. Firstly, the data is freely available. It's NASA's SRTM [1], downloadable from a zillion mirror sites. Then just take some code to calculate a lat/long offset and find the right position in the right tile. Bob Osola has some easily portable PHP for this if you need it [2]. Free…

Building a robust elevation api is definitely not trivial for the average dev using the google api. If someone thought the only way to get elevations was through google then they definitely will not know how to find and compile the data, then write the TIN (triangulated irregular network) algos necessary to appropriately estimate the elevation of an arbitrary point. No, it is not that hard, since tools like Grass can do a lot of the TINing stuff for you, but just running Grass, much less scripting it, is not trivial for someone unfamiliar with GIS. Making this stuff stable and performant on a server (as opposed to a one off calculation on a dataset) is also not trivial in the least.
Post reply on HN