Live data from Hacker News

Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

techcrunch.com

51–60 of 125 posts

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#51
post #37

Earlier quoted context omitted.

Google is in the unusual situation of receiving a lot of blatantly invalid DMCA takedowns. Like, a movie studio (or a company under contract to them) will do a Google search for something broad, like "download game of thrones", and issue a mass takedown for every single link that shows up, often without even looking at the links . So a lot of perfectly legal content (e.g, a news article that says "Game Of Thrones is…

The ridiculous thing is that there are no consequences for the groups sending out those invalid DMCA requests. Every other week I read about how someone uses DMCA to censor a YouTube video or article that's critical of them, but apart from the loss of face with the public they don't see any of the legal or financial penalties that are supposed to result from invalid DMCAs.

A takedown notice is sent under penalty of perjury (which makes it different than a C&D notice). The issue is that it's up to the party that receives the takedown to petition the court for the perjury cause, and that's almost never worth it.

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#52

Brief summary: Thejesh has accused Indian Airtel and Flash Networks Layer8 of something that may be a crime (depending on the particulars of Indian law) and is definitely a scandal. Specifically, the accusation is that Flash Networks Layer8 wrote a piece of malicious software and that Airtel injected it into customers' network connections. Thejesh republished the injected script on GitHub. Flash Networks sent a nasty…

Just because code/webpages are delivered to you over the web doesn't mean you can take them and republish them somewhere else.

Is illegal code (i.e. malware) protected by the copyright to begin with? If it is, then all antiviruses blatantly violate copyright. But something tells me they don't need to ask any permission from malware authors.

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#54
post #6

Earlier quoted context omitted.

Not required exactly, but if they refuse to take down the content, then they can be sued for copyright infringement themselves. The DMCA removes their liability and makes the fight between the uploader and the copyright holder. But if they step outside of the "safe harbor" they become potential targets.

IANAL, but can't github still be sued in India where the DMCA doesn't apply? GitHub is doing business in India as well, so wouldn't they be subject to the jurisdiction of an indian court?

They may be able to, depending on Indian Court's jurisprudence on personal jurisdiction, but unless they have assets in India, the Indian judgement would have to be brought to the United States for enforcement. The U.S. has laws and procedures outlining what sorts of foreign judgements will and will not be honored and enforced by U.S. Courts. For example, a U.S. Court will not enforce a libel judgement from a UK court, because of the SPEECH Act. See more: http://en.wikipedia.org/wiki/Enforcement_of_foreign_judgment....

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#55

Brief summary: Thejesh has accused Indian Airtel and Flash Networks Layer8 of something that may be a crime (depending on the particulars of Indian law) and is definitely a scandal. Specifically, the accusation is that Flash Networks Layer8 wrote a piece of malicious software and that Airtel injected it into customers' network connections. Thejesh republished the injected script on GitHub. Flash Networks sent a nasty…

If anyone finds themselves in a similar situation, please email me the snippets and explain the story. I'll mirror them for you. scott@arciszewski.me Fuck censorship.

Your site is down.

Error 526 Ray ID: 1f474c500f7a0ef1 • 2015-06-10 18:56:46 UTC Invalid SSL certificate

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#56

Doesn't using HTTPS prevent such an injection?

I would hope so, unless there is some monkey business with the SSL Certs like the "superfish". A lot of pages aren't https yet though.

Superfish was because the laptop manufacturer bundled adware which added its own root certificate that was broken, they aren't able to add root certificates in this case.

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#58
post #55

Earlier quoted context omitted.

If anyone finds themselves in a similar situation, please email me the snippets and explain the story. I'll mirror them for you. scott@arciszewski.me Fuck censorship.

Your site is down. Error 526 Ray ID: 1f474c500f7a0ef1 • 2015-06-10 18:56:46 UTC Invalid SSL certificate

Oh? It's up from here. Maybe it's a CF issue?

Regardless, I have other domains/sites for mirroring content. ;)

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#59
post #46

Earlier quoted context omitted.

Just because fingerprints were found at the scene of the burglary doesn't mean you take them and republish them somewhere else.

Doesn't that fall under vigilantism? Publishing fingerprints might get you in trouble. In most countries you are forbidden to take photos in a private setting without permission, and in some even in public. wvenable's comment is on point. Just as public websites aren't public domain, publishing information delivered on request might not be legal.

It may not be legal, but I'm not sure it is wrong either (the web stuff and not the burglary)

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#60
post #6

Earlier quoted context omitted.

Not required exactly, but if they refuse to take down the content, then they can be sued for copyright infringement themselves. The DMCA removes their liability and makes the fight between the uploader and the copyright holder. But if they step outside of the "safe harbor" they become potential targets.

IANAL, but can't github still be sued in India where the DMCA doesn't apply? GitHub is doing business in India as well, so wouldn't they be subject to the jurisdiction of an indian court?

Didn't India ban Github a while back?

http://thenextweb.com/in/2014/12/31/vimeo-github-30-sites-bl...

Post reply on HN