This is no different than any user writing a Tampermonkey script to modify any website they want to modify. Even further, this is no different than a user opening the Dev Tools console and modifying things there.
This is no different than any user writing a Tampermonkey script to modify any website they want to modify. Even further, this is no different than a user opening the Dev Tools console and modifying things there.
Will you cover his legal costs for choosing this decision? Right matters less than resources if it's expensive to even be right. You can state your case here on HN without repercussion, not so when being sued (it costs to even state your case reasonably due to hazards of self-defense and it costs dearly if you lose).
And if I choose to run my own code in my browser why not?? Who's computer is it, after all?
In your moralistic mind or in the courts? Because idealists are not immune to laws they don't like any more than the rest of us. This arm chair idealism is getting ridiculous.
In the 90s the music industry tried to claim that the buffering data while playing music was making a copy of their data for which they should be paid or which they did not authorize. A few technically ignorant judges initially sided with this argument but it was eventually laughed away.
Your calling this "armchair idealism" makes me think you might be suffering from a legal system Stockholm syndrome.
>Please respond to this message to acknowledge that you have received it. If you can resolve the matters specified above in the next seven days, that would be excellent. If you anticipate that it will take longer, please let us know. I’ve cc’d our Legal alias so that in the event that I am unable to respond, one of our product counsels will be able to provide any necessary assistance.
tl;dr: respond and desist or they will escalate to the next step. Legal action is heavily implied, and it's outright foolish for you to read that and somehow think there's no threat to sue, whether implicit or not
Maybe it's foolish, maybe it's not, but this email cost Slack the salary of the person for the time it took him/her to write it. At least make them also pay for an hour or two of legal fees to have this taken down.
As a slightly bad analogy imagine a disclaimer that customers of a fairground ride might experience back pain. If it was found that all previous customers had suffered back pain then the disclaimer would not be enforceable and the ride owners could be sued for negligence.
And tbh, Axel Springer isn't the most surprising entity to sue for this, the entire publication house is a bunch of asshats, who have been cited for being the most deplorable journalists and in one case someone argued that one should be as mean and rude as legally possible to employees of Axel Springer.
They have also succesfully sued the producer of an Anti-Anti-Adblocker since their Anti-Adblocker was considered DRM by the court (IIRC).
There are a bunch of folks doing this already for ad blockers.
It does work on Firefox for Android, if you enable Request Desktop Site. It's not optimized for small screens, though.
It does work with Firefox on Android (not Firefox Focus), if you check 'desktop mode'. Weird that you should have to fake the user-agent string to access it.
I find it hard to believe they would redirect you to a pirate site. Are you sure it was a pirate site and not just a third party site hosting apks
It seems anyone who tries gets such a backlash and end up losing more than what they gain, plus they expose themselves to have false positives (e.g. one image didn't load due connection issues but slack falsely assumed it was an extension blocking it)
We use slack and I still have to use 4+ other forms of communication at work daily (jira, confluence, outlook, github). Sometimes we use video chat services and conference calls as well. There are days where very little happens via slack, and I'm becoming increasingly convinced that anything beyond pinging for simple things (hey look at this jira ticket, have you done this?) is wasted effort.
Blocking ads is not quite the same thing as modifying a product - but I don’t see any obvious reason why an EULA which forbids ad-blocking wouldn’t be enforceable. Though it would be deeply unpopular.
https://www.reddit.com/r/IAmA/comments/2r3uok/we_developed_a...
https://www.quora.com/Is-AdBlock-legal-If-not-specifically-w...
Their product are the bits they ship to you and the code they run on their servers.
You're modifying a part of their product.
Since you can't modify their product, you also obviously shouldn't be able to use any web browser to view slack because those browsers take those bytes they ship you and interpret them in the context of the browser windowing system (its userChrome.css for example)... that's also clearly modifying the experience they delivered to you.
You also shouldn't be able to use a computer monitor that has color settings different from the web designers working at slack. If you accidentally have a monitor with slightly less blue than theirs, well, you just modified the slack UI to be a little less blue. Obviously a ToS violation and you shouldn't use them at all.
God forbid if you zoom in on the page to modify their product's resolution/size.
Jerk.
Explain.
I was going to comment something similar, but in trying to come up with details and examples to explain my point, I realized I couldn't, I so I decided they aren't really different with respect to modifying a product. What makes them different is how the product was modified, but that presupposes modifying the product and that's not really the way the question has been posed.
Blocking ads is removing the revenue mechanism, and is akin to patching out account verification for a desktop product (assuming the webapp/webpage has some AUP stating that the ads are required to be viewed as part of the service).
Modifying a program takes many forms, from removing authentication mechanisms to fixing bugs or adding enhancements, so while the legal system may or may not acknowledge those differences, it's at best an overly broad description of the case in question.
But then the next logical step is to argue that he’s inducing a breach of contract by his users, which seems to be the case.
Inducing a breach of contract is a tort [1]. It does not apply in all cases where someone is induced to break a contract but in this case where the extension author has knowledge of the Slack terms of service and the extension targets Slack only, it almost certainly does apply. This argument was used in the case of Blizzard vs Bossland [2].
[1] http://www.oxfordscholarship.com/view/10.1093/acprof:oso/978...
[2] https://www.bristows.com/news-and-publications/articles/bris...
There's far more of a financial incentive there.
Adblockers inject code into sites. So do password keepers. If sites could sue adblockers because it breaks their terms of service, don't you think they would?
You are not bound by the slack terms of service except in the scope of your slack account or an API connection of some type.
Someone else can use my software all day long to break their terms of service, but that doesn't make me liable. I didn't agree to anything.
People need to realize that terms of service are a civil contract. It's not "illegal" to break them. Especially if you didn't agree to the terms.
Being "right", sometimes, is not worth the fight.
Maybe the agreement isn't binding depending on his local jurisdiction, but it's unclear how he could use Slack without agreeing (or at least clicking "agree") to the terms.
It does not matter, he does not want to fight this.
That's only in the US as far as I know, everywhere else you can't be bound by an agreement without signing anything.
Regardless of where you are, the majority of the agreements you enter into are not only not signed, they are not even explicit (but rather implied).
Case in point: practically everytime you buy something and pay with cash, you have entered into a purchase agreement without having signed anything.
> And not using the product makes you not bound to the terms of use, unlike laws which you have to obey at all times.
Of course not. But in this specific case, it is safe to assume that he is using the product, or more specifically: he used Slack to develop BetterSlack.
So thats not true.
changing the name is not an issue... however, if I have to take it down, that's moot.
You mean you do not ignore cease and desist orders by principal? Why? There should be at least some criteria by which you judge which ones you can ignore and which you can't? What if they told you to cease and desist programming forever on any project because they state in their terms that once you mess with their UI with JavaScript you are not allowed to program anymore? Ridiculous right? So would you listen? Probably not.
So lets see what they are 'forbidding' you: They don't want you to write code that makes browsers do other things to their site... How is that any of their business?
What if a new browser comes along that renders all of their fonts differently so that they become unreadable, is that any of their business or is it the business of the people who use that browser? I'd say the latter.
I agree that a disclaimer and a change of name should be enough. I'd suggest 'SlackingOff' as a name.
You are free to write any extension that does anything to any website as long as you aren't hurting users' human rights and as long as you aren't hacking them if you ask me. Users can decide whether they want to use your extension perfectly fine on their own.
Also note that you are free to not write any extension as well. It is your life of course :)
None of them involve talking with a lawyer in a different country over something that's really not that important in my life.
On principle, I want to side with all these other commenters. Fact of the matter is that time is precious. Glad you're doing what you feel is important to you.
When you delete a public repository, one of the existing public forks is chosen to be the new parent repository. All other repositories are forked off of this new parent and subsequent pull requests go to this new parent."
https://help.github.com/articles/what-happens-to-forks-when-...
https://en.wikipedia.org/wiki/Craigslist_Inc._v._3Taps_Inc.
It seems unlikely to apply to a Chrome extension:
Craigslist Inc. v. 3Taps Inc., 942 F.Supp.2d 962 (N.D. Cal. 2013) was a Northern District of California Court case in which the court held that sending a cease-and-desist letter and enacting an IP address block is sufficient notice of online trespassing, which a plaintiff can use to claim a violation of the Computer Fraud and Abuse Act.
If you are in a different country than US I wouldn't worry at all. I would just avoid using the name "Slack".
But you're not the person being asked - the courts in g3rv4's jurisdiction and in Slack's are the ones who would be asked, if it came to it. Have you read the relevant law (including case law) about copyright and "cybercrime" in these jurisdictions and concluded that, in fact, Slack does not have the power to restrict this? Have you read the Slack user agreement and concluded that the provisions in that user agreement are unenforceable?
Is this your first week on the Internet? Of course he hasn't read any of those things! We're all arm chair lawyers here with our own personal, grumpy views about what shape society should be.
(I'm agreeing with you.)
I wanted to give you a moral boost, in case you were looking for a reason to take a stand. But if you don't want to, that's entirely valid.
It injects code into the dom model of the users browser.
But it doesn't inject code into their site, right? The HTTP request is made to the server all the same, nothing modified via the browser, it's all code additive/correction in the extension?
Don't be surprised about legal writing. He/She as a legal person is responsible for writing in a very clear and explicit way since any misunderstanding might cost the reader or themselves in the future. It just shows their accountability. You don't want a misunderstanding cost you trouble.
I have colleagues working in the legal department. They understand you, but they still have to make sure there is no misunderstanding there.
They are serving enterprise companies, Anything goes wrong can destroy their business. It makes sense for them not to risk anything.
Companies are paying them for the security. Otherwise, there are cheaper alternatives to Slack with somewhat similar features.
Slack could allow custom clients. But I'm pretty sure all major customers will require their employees not to use un-official clients for security reasons.
Ok, then he/she can be called out since we are on the front page of HN and there is a lot of noise and harm done. I honestly can’t see a single reason why slack legal department, probably worth millions per year, in a company worth several billions, can write such things just to kill a free chrome extension built by a single person for non profit reasons. I never used slack but from now on I will actively advice against using it. When you arrive at the point that you can’t even modify your browser to see whatever you like I think that we are almost at the brink of total destruction/anarchy/“choose your not so preferred destination”. Disclosure for slack layers: I never used your product, so I never agreed to your TOS and I would never use it hopefully. I am not associated in any way with any of your competitors. I sadly have to admit that sometimes I play with JSFiddle in my browser just for fun. If you want to sue me please go on, there is not much difference compared to what you are suing g3rv4 for.
And I don't. I mean, charitably this could be attributed to some non-tech person noticing the extension and sending/asking legal to send a C&D because they didn't like it. That's the only thing I can think of, because the alternative is plain malice. This is a client-side modification, the main part of their letter is just absurd, and the justification is nonsense.
If those enterprise customers are worried, they're free to lock down browser extensions on their employees' systems if they want. If they're worried about this, they should be just as worried about extensions acting on webmail, internal sites, etc.
are they going after all of them? if that's the case, I'd understand.
> Slack could allow custom clients. But I'm pretty sure all major customers will require their employees not to use un-official clients for security reasons.
Is security really a client side thing? Obviously I understand stuff like key logging and such in a malicious client, but how would somebody using a custom client affect another user's security with an official client? I mean if it would, wouldn't that be a horrible situation anyway from security point of view?
In that case, there would be no "contractual privity" between Slack and the dev, and Slack would have to go after him for inducing breach of contract or some such thing.
https://penguindreams.org/blog/discoverying-friend-list-chan...
I think the real lesson is "don't take legal advice from internet forums of non-lawyers", or at least take it with a grain of salt. Not all analogies are equally good and only a qualified lawyer is gonna know which analogies will fly in court.
[1] Here's a fun analogy in a tort law case cited at https://cyber.harvard.edu/bridge/Analogy/analogy3.htm:
In Adams v. New Jersey Steamboat Co., a steamboat passenger sued the owner after the theft of valuables from the rented cabin; neither passenger nor owner had been negligent. The passenger claimed the owner nonetheless was strictly responsible, regardless of any failure or compliance with care, in light of prior case ruling that innkeepers were strictly liable for the theft of boarders' valuables. The owner argued against strict liability and pointed to precedents rejecting liability claims by passengers on open-berth sleeping trains. For purposes of liability for theft from a passenger, should the steamboat owner be viewed as more like the innkeeper or more like the train owner? The court reasoned that "A steamer carrying passengers upon the water, and furnishing them with rooms and entertainment, is, for all practical purposes, a floating inn, and hence the duties which the proprietors owe to the passengers in their charge ought to be the same." The court noted that both innkeepers and steamboat operators are entrusted with high levels of confidence in the face of temptations by many to endanger guests. Given this parallel relationship to guests, innkeepers and steamboat operators should bear the same kinds of duties to guests.
I can't even count the number of them I have received. They look scary but basically will not be followed up with. You might as well just respond with "fuck off"