Live data from Hacker News

A Better DMCA Process

github.com

21–30 of 35 posts

Re: A Better DMCA Process

#21

Earlier quoted context omitted.

Here's the actual relevant text from the bill [1]: > upon notification of claimed infringement as described in subsection (c)(3), responds expeditiously to remove, or disable access to, the material that is claimed to be infringing or to be the subject of infringing activity Immediately contacting the repository owner, and asking them to remove the content themselves within a short window of time, sounds like an expe…

"Immediately contacting the repository owner, and asking them to remove the content themselves within a short window of time, sounds like an expeditious response to my non-lawyer ears. Except, uh, you cut out the object of this sentence, which is the service provider, not the user. That is, github, not the user, is supposed to be the person responding expeditiously to remove . Contacting someone is neither "removing"…

But as long as Github still removes the content in a reasonable time period if the user hasn't, aren't they still in compliance?

Re: A Better DMCA Process

#22

Earlier quoted context omitted.

Here's the actual relevant text from the bill [1]: > upon notification of claimed infringement as described in subsection (c)(3), responds expeditiously to remove, or disable access to, the material that is claimed to be infringing or to be the subject of infringing activity Immediately contacting the repository owner, and asking them to remove the content themselves within a short window of time, sounds like an expe…

"Immediately contacting the repository owner, and asking them to remove the content themselves within a short window of time, sounds like an expeditious response to my non-lawyer ears. Except, uh, you cut out the object of this sentence, which is the service provider, not the user. That is, github, not the user, is supposed to be the person responding expeditiously to remove . Contacting someone is neither "removing"…

[deleted]

Re: A Better DMCA Process

#23

Earlier quoted context omitted.

Here's the actual relevant text from the bill [1]: > upon notification of claimed infringement as described in subsection (c)(3), responds expeditiously to remove, or disable access to, the material that is claimed to be infringing or to be the subject of infringing activity Immediately contacting the repository owner, and asking them to remove the content themselves within a short window of time, sounds like an expe…

"Immediately contacting the repository owner, and asking them to remove the content themselves within a short window of time, sounds like an expeditious response to my non-lawyer ears. Except, uh, you cut out the object of this sentence, which is the service provider, not the user. That is, github, not the user, is supposed to be the person responding expeditiously to remove . Contacting someone is neither "removing"…

If the user doesn't do it themselves within that short window, then GitHub has to. Every web hosting company I've worked with in the last 10 years has forwarded DMCA notices on to customers. They only disable a server if you don't handle the removal yourself. I don't think GitHub is trying anything new here.

Re: A Better DMCA Process

#24

Interesting that this follows on the heels of the Popcorn Time DMCA takedown: https://github.com/github/dmca/blob/master/2014-07-11-MPAA.m... EDIT: Also here: https://news.ycombinator.com/item?id=8450145

Just a note concerning this. Popcorn allows users to easily find and watch torrents, which could be illegal copies. Why does the software that enables that fall under a DMCA request? Shouldn't any web browser or search engine also fall under the same rules because they allow me to browse and watch mp4 movies?

Re: A Better DMCA Process

#25
I can't help but think of the Snapchat breach. Surely the world understands that once something is on the internet, it's there forever, right? Complying with the DMCA is security theater at best, and at worst, stifling to innovation.

I mean, we have many laws centered around the difference between intentionally and unintentionally inflicting harm on others. So for example if you break someone’s rib performing CPR, you’re protected as a good samaritan. Or if you veer off the road and run someone over because you were texting, you can still be tried for manslaughter because you shouldn’t have been typing on your cell phone in the first place. I think we can all agree that it’s good we have these types of laws and don’t just focus on premeditated crime.

But the DMCA tries to be a moral compass when it’s not mathematically possible to do so. It’s a bit like setting up a booth on the Grand Canyon that charges money to take pictures. Sure, they can bust bootleggers that set up black market booths without a license. They can even bust scalpers selling photos. But in the end, the Grand Canyon is still there.

Whether someone gets irate about piracy/copying trade secrets or not, in the end, perhaps as a society we should ask if it makes any sense to spend tax dollars trying to stop something that can’t be stopped once the cat’s out of the bag.

Actually, I think GitHub is in a unique position to not comply with the DMCA. It has nothing to do with the size of GitHub, because no matter how large a private entity is, it is always subject to the laws of its government. It has more to do with the fact that every developer in the world has either heard of GitHub or uses it every day.

In other words, we are the people that form what can be thought of as the technology arm of society, so by extension the technology arm of government. That gives us a seat at the table in matters of technology, the same way that teachers unions are able to influence education or the American Medical Association can influence public health. If we decide that the DMCA is not a good use of taxpayer money and should no longer be enforced (in fact can’t be enforced), then it’s not up to a court to decide that, since they will side with the law every time (as they should). The law itself is what must be adjusted or repealed, by the people who have the means to do so by virtue of the role they play in society. We have the leverage to repeal it because without our support, there is no expertise to enforce it in the first place.

If GitHub complies with the DMCA and we use GitHub, then we are quietly endorsing the DMCA.

Re: A Better DMCA Process

#26

Earlier quoted context omitted.

Thanks to 17 USC § 512 (c), service providers are not liable for hosting copies of copyright infringing material so long as they don't have actual knowledge of that infringement. Since a fork can differ from its parent, notice that the parent may be infringing is not actual knowledge that the forks are as well. That means Github has, in theory, no legal liability for those copies. It can just point to federal law. ht…

"is not actual knowledge that the forks are as well" You assert this as if this is how a judge would see it (or as if it is well tested). That seems highly unlikely to me. It seems to be very easy to make the legal argument that because github knows which forks are copies and which aren't, they have actual knowledge of the ones that are still copies.

In order for GitHub to be presumed to know that the forks are also infringing, the takedown notice would have to specify what in the repo is infringing so that GitHub could compare the contents of the forks against the instance that the takedown notice is filed against. If the notice doesn't specify any particular files in the repo, then GitHub can't be expected to remove any fork that has any deletions in its history since the branch. The ease with which the accuser can check the forks for infringement also shifts the burden away from GitHub.

Re: A Better DMCA Process

#27

I can't help but think of the Snapchat breach. Surely the world understands that once something is on the internet, it's there forever, right? Complying with the DMCA is security theater at best, and at worst, stifling to innovation. I mean, we have many laws centered around the difference between intentionally and unintentionally inflicting harm on others. So for example if you break someone’s rib performing CPR, yo…

> If GitHub complies with the DMCA and we use GitHub, then we are quietly endorsing the DMCA.

I happily endorse § 512 of the DMCA. Not only is the safe harbor provision a well-balanced law for all parties involved, but it's the only thing that makes startups that host UCG legally viable. Without the DMCA, Github could not exist. They'd be personally liable for every copy of every file they distribute without a copyright holder's permission.

This particular piece of the DMCA doesn't have to eliminate all piracy online to be effective. Take the case of a feature film release -- a $XXXMM investment by the copyright holders into their product -- that could be seriously harmed to the tune of tens of millions of dollars by someone leaking a copy online a few days before ticket sales begin. The DMCA notices can disable the most visible (and most damaging) copies, expeditiously enough to save the film's box office sales. Mitigating much of the harm is better than nothing.

> perhaps as a society we should ask if it makes any sense to spend tax dollars

This part I don't get. The alternative to the above is an emergency court hearing for every instance of infringement, hoping to attain an emergency injunction, then get it to an ISP before too much damage is done. The safe harbor provision doesn't (directly) cost tax payers anything. It saves us billions. Every day, hundreds or thousands of instances of copyright infringement are handled by an e-mail instead of a taxpayer-funded court hearing.

It sounds to me like you're making an argument against copyright, not the DMCA. DMCA § 512 (the notice/counternotice safe harbor system) is about mitigating the legal liability created by the copyright act on service providers. In its entirety, the DMCA was the US's implementation of the WIPO Copyright and Performances and Phonograms Treaties. It is not what created copyright protection itself.

Re: A Better DMCA Process

#28

Earlier quoted context omitted.

"Immediately contacting the repository owner, and asking them to remove the content themselves within a short window of time, sounds like an expeditious response to my non-lawyer ears. Except, uh, you cut out the object of this sentence, which is the service provider, not the user. That is, github, not the user, is supposed to be the person responding expeditiously to remove . Contacting someone is neither "removing"…

But as long as Github still removes the content in a reasonable time period if the user hasn't, aren't they still in compliance?

reasonable is not the right word. If they do so "expeditiously", then yes. But that is not the same as a "reasonable" amount of time.

Re: A Better DMCA Process

#29

Earlier quoted context omitted.

"Immediately contacting the repository owner, and asking them to remove the content themselves within a short window of time, sounds like an expeditious response to my non-lawyer ears. Except, uh, you cut out the object of this sentence, which is the service provider, not the user. That is, github, not the user, is supposed to be the person responding expeditiously to remove . Contacting someone is neither "removing"…

If the user doesn't do it themselves within that short window, then GitHub has to. Every web hosting company I've worked with in the last 10 years has forwarded DMCA notices on to customers. They only disable a server if you don't handle the removal yourself. I don't think GitHub is trying anything new here.

"If the user doesn't do it themselves within that short window, then GitHub has to."

It sounded like you were claiming otherwise, saying that asking the user is acting expeditiously "enough", and that they can then "not remove" or slow down removal.

If you aren't claiming that, then we have no argument :)

Re: A Better DMCA Process

#30

Earlier quoted context omitted.

But once they get a takedown notice they have actual knowledge that the material is infringing. If there is a fork that they know about, they do have actual knowledge. They have been doing it in the past, and if they now try to make sure they don't know about forks, that is willful blindness and they will still be found to be infringing. 512(c)(1)(a)(ii) has the so called "red flag" requirement. "n the absence of suc…

from what i understood they have knowledge of the fork, but they don't have knowledge if the fork also contains copyrighted material -- so, if i fork x and i remove all the supposedly copyright stuff, my fork should be ok.

Under the red flag requirement, they got to at least check or think about how identical the fork is.

Yea, if you fork Linux and your fork just happens to use a stolen logo. Obviously there is no reason to think Linux is infringing.

But if you are forking popcorn time, that is unreasonable to assume that the fork is going to be non-infringing.

A general assumption that forks are okay is not a reasonable assumption. They'll have to look at this on a case by case basis.

This is even easier when the infringing content is a file or code. There is no excuse for not removing the infringing file from all github projects. And it is easy to check the forks for containing the alleged infringing code.

The safe harbor is not there to protect people acting in bad faith.

Post reply on HN