US Court of Appeals: An IP address isn't enough to identify a pirate
techspot.com
techspot.com
In this particular case, the defendant ran what amounts to lodging, was deposed, and it was immediately figured out it wasn't him. The complicating factor is that because his lodging was medical in nature, he was not able to hand over guest information.
I mention this context because it's unlikely you would be able to get out of being sued by saying "Well maybe it was my roommate LOL"
https://hn.algolia.com/?query=wpa&sort=byDate&prefix&page=0&...
Well, the question is whether I'm responsible for the use of my computer network. If someone hacks into it and starts using it without me noticing, am I responsible?
IANAL that’s just my personal understanding / belief.
The key point would be the use would have to be unsanctioned and you were totally unaware. Once you give someone your WiFi password, it’s less clear if you have any liability. I’m not sure of any case where the actual user was known but the person who provided the network connection was blamed.
Network access is fairly universal. The particular method used to access the Internet is practically irrelevant. The actor and the act are what is important, not how the packets are routed.
Many states don’t actually have laws about securing firearms directly but have a concept of strict liability about what happens if they are stolen, or stolen and not reported.
Where does this happen?
An example, this is from Verizon[1]
2. Use of your Service and Account and Compliance with Applicable Authority. You are responsible for all use of your Service and account, whether by you or someone using your account with or without your permission, including all secondary or sub-accounts associated with your primary account, and to pay for all activity associated with your account. You agree to comply with all applicable laws, regulations and rules regarding your use of the Service and to only use the Service within the United States (unless otherwise permitted by this Agreement).
3. Restrictions on Use. The Service is a consumer grade service and is not designed for or intended to be used for any commercial purpose. Except as otherwise set forth in this Agreement, you may not resell, re-provision or rent the Service, (either for a fee or without charge) or allow third parties to use the Service via wired, wireless or other means. For example, you may not provide Internet access to third parties through a wired or wireless connection or use the Service to facilitate public Internet access (such as through a Wi-Fi hotspot), use it for high volume purposes, or engage in similar activities that constitute such use (commercial or non-commercial). If you subscribe to a Broadband Service, you may connect multiple computers/devices within a single home to your modem and/or router to access the Service through a single Verizon-issued IP address, and if available through the Service, you may permit guests to access the Internet through your Service’s Wi-Fi capabilities. You also may not exceed the bandwidth usage limitations that Verizon may establish from time to time for the Service, or use the Service to host any type of server. Violation of this Section may result in bandwidth restrictions on your Service or suspension or termination of your Service.
[1]https://www.verizon.com/about/terms-conditions/verizon-onlin...
The court is saying "Look, you can't just saying the IP address is the person, you need to offer a reasonable claim that it is". It is not saying IP addresses are useless or that your identity must be proven beyond a reasonable doubt.
Neither my first post nor this post were meant to be normative -- I'm not from the US, the country I am from makes passive filesharing (i.e. uploading while torrenting) more or less legal, and I would be very happy if legal rulings stopped piracy fishing expeditions. I just wanted to describe the substance of the ruling in a more substantial way than the headline did.
The best way I can interpret this is that your post was being deliberately misleading, because you implied that roommates won't invalidate IP authentication, but you actually meant that lying about having roommates won't invalidate IP identification.
Am I missing a more reasonable interpretation?
I think so. I think in more than one way.
GP, if I read correctly, tries to limit the expectations we can have based on this ruling since the circumstances where unusual. (Read GPs post again for more details.)
English is not my first language but GP seemed very clear and easy to read.
It is not that simple if you left your car unlocked. Leaving an unlocked car around with the key in the ignition is clearly a public danger.
Having a case where you are guilty whatever you say makes no sense, especially for something where the damages to society are very abstract and not proven, like piracy.
The law suggested may be bad, but it doesn't remove the role of the justice system in determine the existence and degree of liability.
I had a quick google and I found mentions that you will get fines for this. I did not find an example of something bad happening with an unlocked car.
Depends on the act. In the state of Georgia, at least, if a passenger in the car you're driving throws litter out the window, you're responsible (not that this particular law is ever enforced).
So basically all of them? Because I can tell my torrent client to use whatever port I want
Have a look here[1] of the potential actions that can be taken against you and your potential response to those.
In the end it will be a matter of how far you and the other party are willing to push this.
This will be different of course if it can be demonstrated that you intentionally ran the open-wifi to bamboozle or encourage illegal use. (because you advertized for or boasted about it in an online forum for instance).
Why not? It's illegal to download a movie and they have to prove what person did it. Roommate, father, sister...neighbor.
Multiple users will cut that percentage up pretty quickly.
To clarify, the plaintiff does have to prove it was the defendant that wronged them, but instead the standard of proof being "beyond a reasonable doubt" it's something like on "the balance of probabilities."
Most subscription contracts have a clause to that effect.
It would be trivial in that circumstance to blow away any kind of NAT and the pseudo-anonymity/plausible deniabililty it provides and make client devices performing illegitimate activity directly identifiable.
I wonder if such a ruling might be different in that context. It's a perturbing thought.
Identifying the device and identifying the person using it are two entirely different things. Multiple people use the same device all the time.
Why do you think so? NAT can be used for IPv6 is exactly the same way it's used for IPv4.
> ... the ability of security services to track you on IPv4 versus IPv6 is pretty much about the same.
Ex: https://en.wikipedia.org/wiki/List_of_assets_owned_by_NBCUni... (Comcast)
https://en.wikipedia.org/wiki/AT%26T#Corporate_structure (AT&T)
I really don't think it matters too much for client devices anyways, we've found plenty of workarounds by now where it matters. Maybe the best case is NAT-optional.
But if every device has a fixed or randomized identifier then surely the identifier contains absolutely no routing information whatsoever (the machine might have an address starting ffff:ffff:... but might be behind routers eeee:eeee:... or dddd:dddd:... in completely different parts of the world).
In this case they failed. That doesn't mean it will always fail.
If you're mobile ISP uses IPv6 for everything and assigned your mobile a static IPv6 address, then it will be harder to argue it wasn't you.
If you're Home router is provided and managed by your ISP, and it is configured to use DHCP Static Leases, then the local IP of your mobile phone (a fairly personal device) is close (not equal) to being equally as effective as a personal identifier as it's MAC.
If on the other hand you connected to an Open-Wifi set up by an amateur 4 NAT's down that does not keep logs, and you randomize your MAC every time you connect to a new network, it might be more difficult for tying an IP to your device without reasonable doubt.
In that last case if the pursuer wanted the open-wifi operator's operation could be made more difficult by DMCA complaints and leverage through the ISP's terms of service.
My point is that anyone with the technical know-how and very rudimentary internet access can bypass almost any restriction you try to put on it. What if the pirate is a minor and won't listen to their parents and keeps on torrenting? Do you permanently take their internet access away? How does that then stifle them for school homework or their social interaction? How can we expect each and every citizen to deploy NSA grade traffic monitoring on their router? The whole thing is ridiculous and the courts are still vehemently out of touch
I didn't see anything in the story to suggest that the plaintiff was acting as a "troll" in the sense that I understand from reading about patent trolls. In this case, the plaintiff, while found to be in the wrong, was in fact the creator of the content and probably intended to commercialize it.
Going after this individual does not protect the the monetization of the copyrighted work. The individual's actions only represent the loss of motorization for the single copy they might have purchased. The only possible argument for this protecting monetization of the copyrighted work would be some kind of "chilling effect" on others sharing, but given the prevalence of file sharing after decades of such legal cases, this seems like a extremely weak argument.
Given that, then only reasonable conclusion is that the they are attempting to make money using the law itself, rather then using it to protect the monetization of the copyrighted work.
At the end of the day you will be tried by a judge or a jury. If your only defense is some kind of grand, implausible chain of maybes and what-ifs, they will rule against you. If you have a perfectly reasonable explanation, then they won't.
An IP is just evidence.
I'm not disagreeing, but I hope this will not re-open doors of trying to leverage this into getting IP addresses out of being privacy linked data in a privacy regulation context.