Live data from Hacker News

Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

techcrunch.com

71–80 of 125 posts

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#71
post #52

Earlier quoted context omitted.

Just because code/webpages are delivered to you over the web doesn't mean you can take them and republish them somewhere else.

Is illegal code (i.e. malware) protected by the copyright to begin with? If it is, then all antiviruses blatantly violate copyright. But something tells me they don't need to ask any permission from malware authors.

why not?

i can probably patent a full auto gun, even if it's illegal for me to have one

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#72
post #52

Earlier quoted context omitted.

Is illegal code (i.e. malware) protected by the copyright to begin with? If it is, then all antiviruses blatantly violate copyright. But something tells me they don't need to ask any permission from malware authors.

I assume there is some fair use cover AV providers could argue ("purpose and character of use" sounds like their bag) but I'd be surprised if many authors want to come out of the woodwork to fight that fight with them in the first place. As we can see in this case, it's a big deal that the author is seeking copyright takedown.

It should teach them a lesson. Being exposed as malware authors (with intent to sell it to be used for malicious purposes) will not serve them well.

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#73
post #52

Earlier quoted context omitted.

Is illegal code (i.e. malware) protected by the copyright to begin with? If it is, then all antiviruses blatantly violate copyright. But something tells me they don't need to ask any permission from malware authors.

It seems like illegal works should be protected by copyright[1] But that begs the question, as ad injectors are probably not illegal. [1] http://www.cardozo.yu.edu/sites/default/files/Eldar%20Haber,...

I'm not sure they are not illegal. At least they shouldn't be any less illegal than many other types of malware. But I'm not familiar what laws that falls under.

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#74
post #13

Earlier quoted context omitted.

Yep. Part of DMCA safe harbor is that you have to pull it down for a couple weeks, regardless of frivolity.

Google rejects many DMCA requests, does that mean they aren't covered under safe harbor?

safe harbor means: if you do that, even if you are guilty, you are exempt.

if you are innocent, you don't need safe harbor because well, you're innocent!

but just like every criminal case in the usa where law representation is far from fair and free, its often better to accept the guilty while being innocent just to avoid the legal costs.

that's why dmca stinks. it forces your hand even more to just assume guilty for the low cost of censoring someone else in favor of someone that can pay a legal battle.

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#76
post #62

Earlier quoted context omitted.

Publishing research on malware should be perfectly legit.

Publishing a book report is very different than publishing the book itself.

If that book is malware itself? It should be OK, because it's security research and exposure of that malware. It should be covered by fair use.

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#77
post #55

Earlier quoted context omitted.

If anyone finds themselves in a similar situation, please email me the snippets and explain the story. I'll mirror them for you. scott@arciszewski.me Fuck censorship.

Your site is down. Error 526 Ray ID: 1f474c500f7a0ef1 • 2015-06-10 18:56:46 UTC Invalid SSL certificate

The link in his profile works (https://scott.arciszewski.me/)

even though I see the same error when going directly to https://arciszewski.me/ does not.

My guess is that arciszewski.me is not on the certificate because it is not meant to host web content, only the subdomains do.

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#78
post #47

Earlier quoted context omitted.

Just because fingerprints were found at the scene of the burglary doesn't mean you take them and republish them somewhere else.

Fingerprints are not copyrighted, code is. You might claim fair use if you published it as part of an article, but probably not on GitHub which is intended for using and editing code.

But fingerprints are personal data and at least in the EU the handling of personal data is very strictly regulated. It's not the same thing at all, but still the analogy works I think.

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#79
post #47

Earlier quoted context omitted.

Fingerprints are not copyrighted, code is. You might claim fair use if you published it as part of an article, but probably not on GitHub which is intended for using and editing code.

But fingerprints are personal data and at least in the EU the handling of personal data is very strictly regulated. It's not the same thing at all, but still the analogy works I think.

Personal data and copyright are completely different things. The analogy doesn't work at all.

For example, even if you are worried about personal data, you can still publish a fingerprint if you don't identify the individual.

Re: Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors

#80

Earlier quoted context omitted.

Because the story takes place in India, and since TechCrunch is an American publication, people would otherwise assume the story was taking place in the US.

That and the DMCA does not apply in India, they are just abusing the system.

Github is in the US, where India does not have jurisdiction. DMCA laws DO apply.
Post reply on HN