Live data from Hacker News

YouTube-dl's repository has been restored

github.blog

591–600 of 686 posts

Re: YouTube-dl's repository has been restored

#591

Earlier quoted context omitted.

The 'copyright violations' section of the RIAA letter (regarding the unit tests) was clearly a standard §512 notice alleging copyright infringement. Even if §512 wasn't explicitly mentioned, it's still a legally effective notification of claimed infringement. > The rules in section 512 do not apply. Assuming you're referring only to the §1201 'anticircumvention' portion of the claim (the main focus of the GitHub post…

> Assuming you're referring only to the §1201 'anticircumvention' portion of the claim (the main focus of the GitHub post), whether this portion is _also_ subject to §512 rules is a little more ambiguous. §1201 defines a trafficking violation separate from copyright infringement itself, but some court rulings have established a requirement that §1201 violations establish a 'nexus' to copyright infringement in order t…

> I don't think that even if the first is true, the second is true: even the courts that hold the "nexus" position don't, AFAIK, hold that Sec. 1201 liability requires that the trafficker be already liable for contributory infringement, only that there be a connection of the trafficked circumvention measure to infringement.

Good point and important distinction- not to say that courts holding the 'nexus' position have already established Section 512 protections for Section 1201 violations, just that I could imagine a legal argument extending the position along these lines. If Section 512 protects services from liability for user-provided software that contributes to copyright infringement, it should also protect services from liability for user-provided software designed for the circumvention of technological measures protecting copyright infringement.

At the very least in the absence of further clarity, it makes sense that GitHub seems to apply section 512 law consistently across Section 1201 claims in addition to copyright infringement claims, not only to simplify their legal procedures but also to leave such a theoretical defense available to them in case they ever need it.

Re: YouTube-dl's repository has been restored

#592

Earlier quoted context omitted.

Youtube wasn't behind the DMCA takedown, though. Do they even care about youtube-dl?

Google quickly kills any iOS/Android app that offers offline playback functionality for YouTube, so I can't imagine they love youtube-dl. They probably only haven't made a stink because it might attract more attention to a tool primarily only known about in techhead circles.

And given how unlikely people are in the wider non-technical audience to god-forbid, run a command line program, I guess they really just don't care.

They do take easily accessible apps that use youtube-dl under the hood pretty seriously. I guess it depends on how much of an effort it is for them vs how much of their bottom line ytdl is cutting into.

Re: YouTube-dl's repository has been restored

#593
post #567
post #372

Earlier quoted context omitted.

> This sig / cipher being public means it is not a copyright protection mechanism. I can see this as ending up with Youtube being forced to require sign-ins. Massive expense for Google. Then Youtube-dl adds one parameter for the password, and we're back to square one.

I am not that afraid that google would require sign-ins for everything. Even google with its massive market dominance should be pretty scared of given such a clear opening for a competitor, and being accessible without a login is a huge feature in order to get market share quickly compared to a competitor that does not.

Not to mention, all that ad revenue.

People will literally just give up and straight up do something else if content is behind a auth-wall.

Re: YouTube-dl's repository has been restored

#594

Earlier quoted context omitted.

Youtube wasn't behind the DMCA takedown, though. Do they even care about youtube-dl?

> Do they [YouTube/Google] even care about youtube-dl? A downloaded video doesn't generate ad revenue.

Downloaded videos often get remixed into other videos that generate ad revenue. Commentary, reaction videos and compilations are substantial parts of youtube.

Re: YouTube-dl's repository has been restored

#595

Earlier quoted context omitted.

AFAIU the argument is more that youtube-dl is effectively a web browser and doesn’t do anything that a web browser doesn’t do. Further, it does not include any “secret” key for DRM circumvention like might be bundled with e.g. Chrome in the case of Widevine, where browser vendors agree to protect the secret key.

Right, but the law makes no mention of secret keys, it just says you can't go around anything that controls access to a copyright work; and you can't provide tools to do so. The actual legal definition of tools covers both actual technical purpose as well as marketed purpose. Rebranding, say, OBS as "Recorder for YouTube" and talking about how you can use it to get around YouTube's downloading protections by screenca…

There are exceptions. Access for the disabled is one of them and youtube-dl can very much be the basis for an accessibility tool.

Re: YouTube-dl's repository has been restored

#596

Earlier quoted context omitted.

I personally agree, but there are some interesting counter-examples. For example, if someone discloses the credentials to an account but says nobody is authorized to use those credentials, I think it violates the CFAA to use those credentials. Even more-so if they only tell you their username, but the password can be inferred without direct disclosure (e.g., if the username is "thepasswordishunter2").

CFAA covers unauthorized access to computer systems - the only case I know of where CFAA was used to prosecute something akin to a DMCA 1201 claim was Sony suing Geohot for putting a tweezer to the RAM on his PS3. It's a novel legal strategy (in case you don't think DMCA 1201 is broad enough), but it was never entirely litigated in court as Geohot settled the case. I still don't think it would have passed muster in c…

It's been a while since I've read about it, and I'm not a lawyer, but my recollection is that geohot said he deliberately kept his PS3 offline once it was compromised, and Sony's counterargument was (in effect, via some truly mind-bending equivocation) that geohot compromised the PS3 (the abstract computer for which authorization presumably proceeds from Sony) as opposed to his PS3 (the specific computer for which authorization presumably proceeds from geohot). Since the PS3 interacts with PSN, geohot had thereby gained unauthorized access to a computer used in interstate and foreign commerce.

It's one of those arguments for which I have a hard time deciding whether it's fiendishly clever, gratuitously obfuscated, or jaw-droppingly stupid.

Re: YouTube-dl's repository has been restored

#597
post #402

Earlier quoted context omitted.

I even sidestepped the obvious of loading widevine.so, running it, symbolic execution, etc. It's mostly a thought experiment to show how everything is stupid in the end. I'm afraid in a few months/years, we'll see the hardware security level to become mandatory for Netflix, etc. And then YouTube.

In the old days, someone who wanted to send you this kind of content would build and sell hardware for you to receive and play it (like a DVD player). Online streaming services have, in part, scaled so quickly because they run on the general-purpose computers that people already own. So they don't need to bear that hardware cost. These general purpose computers have been fertile soil to grow and nurture the seeds tha…

It's still going to be hardware everyone already owns, just with specific features. It's not a separate purchase of a dvd player, you're buying a phone that has the licensing chip built in

Re: YouTube-dl's repository has been restored

#598
post #328

Earlier quoted context omitted.

Pretty sure Google is ensuring employees to give money to EFF.

They should use the power of Chrome to discourage the use of DRM on the web instead.

Given that Google is the author of the main browser-based content decryption module in use (Widevine), and Google also has a bunch of content provider partnerships to maintain, and they run YouTube, which in some ways relies on content owners not getting pissed off and suing it out of existence (content owners are the reason YT has ContentID, not because of any legal requirement)... I don't think it's in Google's best financial interest to fight against DRM. So they won't do that.

Re: YouTube-dl's repository has been restored

#599
post #589
post #584

Earlier quoted context omitted.

This law article is utterly hilarious and self-contradictory. No-one should be able to circumvent "a technological measure that effectively controls access", by definition. If someone does circumvent a measure intended to control access, this proves that the measure was not, in fact, effective, thereby rendering the entire article inconsequential.

The lock at your door is also assumed to effectively control who can open it, but as we know keys can be dupplicated. However, it is not possible to copy it without access to your original key and the necessary effort. This is sufficient for the legislator. It would be different if you hung your key on the outside of the door a priori, like Youtube does.

It's possible to duplicate your key from the lock.

You need access to the key hole, a blank, and a file. The lock leaves scratches on the blank until it's been file down to the right spot

Re: YouTube-dl's repository has been restored

#600
post #587

Earlier quoted context omitted.

That commit details the replacement of the music videos with a generic test video, exactly what I said. I'm unsure how it is supposed to show it is not the case.

Incorrect. There's a single green line that has an alteration to replace a music video ID "UxxajLWwzqY" in a test case that actually only makes use of ID "BaW_jenozKc" ("Use the first video ID in the URL"). The removed "Test generic use_cipher_signature video (#897)" case did make use of ID UxxajLWwzqY.

I see what you mean, but the extractor file still features how to deal with videos containing the cipher, all that was removed was the tests. Testing the generic cipher video may have been ruled unnecessary as it's universal.
Post reply on HN