Live data from Hacker News

YouTube-dl's repository has been restored

github.blog

471–480 of 686 posts

Re: YouTube-dl's repository has been restored

#471

Earlier quoted context omitted.

Creating or providing a tool and using a tool are not the same action. Likewise, since there are legal fair use scenarios of copyrighted materials (short clips, criticism, satire, academic, etc) so even using the tool isn't inherently against the law and the person creating or providing the tools can't know and legally doesn't need to know the end user's intentions. Copyright lawyers working for the highest profile a…

Drug paraphernalia is still a crime in most places. Not sure what the equal to "spice grinder" here is.

Drug paraphernalia has a specific use (or at least, let's assume that for the sake of argument), but youtube-dl is more like a crowbar that has legal and illegal uses.

If I have a crowbar I can legally use it all day long for construction purposes. As soon as I'm caught breaking into a house with a crowbar, it's classified as burglar's tools. At no point is the hardware store or crowbar manufacturer liable for a burglary for selling me a crowbar.

Re: YouTube-dl's repository has been restored

#472

gitlab.com has their DMCA processing workflow online (as they do most of their policies and workflow documents, which is awesome and few if any other companies are as transparent). https://about.gitlab.com/handbook/engineering/security/opera... My reading of it is that under that gitlab workflow youtube-dl would still be down. Unless/until "there was a valid counter-notice and no response has been received from the p…

The normal safe harbor protections and takedown procedure specified by law does not apply to claims under section 1201 like this one was. This also means no safe harbor protections against being sued for redistributing section 1201 infringing works either. There is instead an "innocent violation" clause that offers extremely limited defense that could apply to sites like GitHub or gitlab, but which would become void…

Interesting, thanks this clears some things up and gives me avenues for more research to understand what's up.

Sounds like claims under 1201 (circumventing technology) are actually really dangerous for the host, there is no safe harbor? At least not after you've received any notification at all?

All the more surprising that a host would be willing to disagree with a claimant and say "nah, we don't think you'd win in court." they are definitely risking their own liability, not just the customers.

As you say, Microsoft can afford to do this cause Microsoft has deep pockets and the ability to counter-strike. All the more reason we should actually be grateful to the for USING that power to defend in this case, right? (And ironically, that suggests that you will get the most protection hosted by a company that has the resources to stand up, which not all do. I am not a fan of that outcome either).

DMCA is still awful regardless of host of course.

Re: YouTube-dl's repository has been restored

#473

Earlier quoted context omitted.

> Whenever you watch a video you are downloading it. Why is this comment downvoted? It's highlighting one of the most common misunderstandings that laypersons have regarding video download/streaming. Most people think that you can "view" content on the internet without downloading it. In this context, a tool which purports to "download" content, you know... sounds like it's nefariously doing something that the "viewi…

This may be completely true in a technical sense, but that's not how the law works (see https://ansuz.sooke.bc.ca/entry/23 ). And while the same bits pass through your connection, this equivalence already breaks down right away: There is clearly a difference between persisting a media file to disk vs having it ephemeral in browser memory.

> There is clearly a difference between persisting a media file to disk vs having it ephemeral in browser memory.

yes, at some point actual human intentions must come into play. you can't defend stuff like CP by saying "it's just some EM pulses, what's the big deal?". or "no I'm not invading your privacy with my IR camera, you are broadcasting in the IR spectrum!".

in this case the implementation does blur the line a little bit. what if the browser's memory gets swapped out to a page file on a (spinning) hard drive? even if the cache gets "deleted" after closing the tab, it might be quite a while before the sectors containing that protected sequence of bits get overwritten. is this infringement?

Re: YouTube-dl's repository has been restored

#475
post #402

Earlier quoted context omitted.

I even sidestepped the obvious of loading widevine.so, running it, symbolic execution, etc. It's mostly a thought experiment to show how everything is stupid in the end. I'm afraid in a few months/years, we'll see the hardware security level to become mandatory for Netflix, etc. And then YouTube.

In the old days, someone who wanted to send you this kind of content would build and sell hardware for you to receive and play it (like a DVD player). Online streaming services have, in part, scaled so quickly because they run on the general-purpose computers that people already own. So they don't need to bear that hardware cost. These general purpose computers have been fertile soil to grow and nurture the seeds tha…

[deleted]

Re: YouTube-dl's repository has been restored

#476
post #184

It seems like EFF fought for youtube-dl and GitHub used their letter as legal firepower to bring the repo back online. If GitHub were fighting for the developer they would have funded the attorney, right? Though from their blog post it does look like they are taking steps to fund defense in the future as well as other steps to improve the situation. Reading EFFs claim is pretty interesting, they state that saving a c…

Actually it seems more like the EFF had nothing to do with it at all and the unit test patch is the reason it was restored - just like Github says in the blog entry.

Re: YouTube-dl's repository has been restored

#477

Earlier quoted context omitted.

The EFF might deserve it more though

Couldn't agree more: https://supporters.eff.org/donate/

not sure if you noticed, but the parent comment was joking about your typo -- you said EEF, not EFF :)

Re: YouTube-dl's repository has been restored

#478

Rather interesting that GitHub decided to restore access 1 day after receiving the EFF's counter notice, instead of waiting 10 days. As a brief legal recap, in 1998 the DMCA added §512 [1] to US copyright law, which established a mechanism for shielding 'service providers' from liability for content posted by users (known as 'safe harbor'), but only as long as they follow formal procedures (known as 'DMCA takedown')…

> Perhaps a symbolic gesture to restore access a couple weeks before they would have been legally required to restore access anyway, but nonetheless interesting to see their willingness to set aside §512 safe harbor protections in the future if their reading of facts suggest a takedown claim doesn't have merit.

Do the DMCA legal requirements differentiate between good faith and tortuous takedowns? Meaning, is that 10-14 day range set in stone even if Github believes that the request was flagrantly over reaching or do they lose safe harbor protections right off the bat? Has this issue been litigated enough that there would be clear precedent?

Re: YouTube-dl's repository has been restored

#479
post #184

It seems like EFF fought for youtube-dl and GitHub used their letter as legal firepower to bring the repo back online. If GitHub were fighting for the developer they would have funded the attorney, right? Though from their blog post it does look like they are taking steps to fund defense in the future as well as other steps to improve the situation. Reading EFFs claim is pretty interesting, they state that saving a c…

AFAIU the argument is more that youtube-dl is effectively a web browser and doesn’t do anything that a web browser doesn’t do. Further, it does not include any “secret” key for DRM circumvention like might be bundled with e.g. Chrome in the case of Widevine, where browser vendors agree to protect the secret key.

That's a DMCA argument (I'm not hacking).

But it doesn't really work: If you protect your house with no lock, not even a door, but just a little rope with a sign on: "Do not jump over or duck under this ribbon, or cut it!", that's, for the DMCA, enough - so you get into fun games where you claim that, say, a long random unique key that is right there in the HTML youtube.com serves which links to the video is a 'security measure' and that 'I shall read the URLs in this tag and download what I find there instead of showing it on the screen' is 'circumventing this'.

How far can you stretch the meaning of 'circumventing access-control measures' before, in court, you lose your argument? I don't think anybody quite knows yet, but surely github doesn't want to be on the hook for it without microsoft's legal team and management signing off on the risk.

Furthermore, separate from DMCA's hacking provisions, there is simply the concept of who is responsible for any copyright infringement caused by stuff github hosts. As per 17 USC §512 (the so-called 'safe harbor provision'), the idea of claiming 'hey I just host this stuff, I'm not responsible for this, why dont you take it up with whomever uploaded this' is codified: You can do that, but it does mean that you _MUST_ take down the content in response to a takedown notice, and if you don't, then you are now liable any infringement that content makes.

The idea is that the owner of the data files a counterclaim notice, at which point the hoster (github) is free to re-host everything without opening itself up to liability, but only if, as per 17 USC §512, they do so 'no less than 10 days and no more than 14', and github did it in 1 day, so whoopsie there I guess.

At that point it does turn into a fight between claimer and counterclaimer: The idea behind those 10 days is that the supposed real content owner can then go file in court against the counterclaimer; merely filing a lawsuit is enough: Show that to the hoster (github), and they can no longer re-enable the content without then being liable for infringement by doing so.

You can't file a counterclaim until your content is removed.

Yeah, that means an utter bozo can take your content down for at least 10 days and there is nothing you can do about this. The DMCA is not particularly well designed in this manner (it doesn't protect against trolly crud well, and getting a barratry verdict in the US is borderline impossible). But that's how it works.

In github's shoes, the fact that youtube-dl doesn't infringe is relevant only insofar that they are willing to ride that notion allllll the way to the gavel in the ensuing court case, because they will be defendants if they ignore the takedown request. Presumably they weren't going to just do that without at least a close look by microsoft's legal team, and a signoff from the big wigs for the likely millions this will cost, given that US law in these matters is... well, have you ever seen one of those shows where 2 people are on a beam and trying to knock the other one off with a giant q-tip? US law is like that, except the ends of the q-tips are moneybags.

Re: YouTube-dl's repository has been restored

#480

I think it is important to note that GitHub's parent company[1] Microsoft is a member of the RIAA[0], the group who initially filed this DMCA. The cynic in me says this was deliberately pre-planned to garnet free press. That type of behavior would certainly be in-line for the company responsible for the Halloween Documents[2][3]. Even if we give GitHub, and by extension Microsoft the benefit of the doubt here, this i…

I agree. Any globo-corp is going to do funny shit for PR. They operate on an entirely different level that most people don't really understand. This is really just a war game for them... and now they understand how much they can provoke their own users.
Post reply on HN