The creators of those various libraries should have a valid legal case against Facebook here, if they want to exercise it. I doubt any users are being harmed by this but it’s a violation of the software creator’s rights.
The creators of those various libraries should have a valid legal case against Facebook here, if they want to exercise it. I doubt any users are being harmed by this but it’s a violation of the software creator’s rights.
--------------------
> copying and uploading the libraries is actually illegal (copyright violation)
That isn't what is happening here - the headline is misleading.
Further into the tweet (FFS, it is a tweet and people aren't reading it all before reacting!) it clearly says "It periodically uploads metadata of system libraries to the server".
Basically that means they are sending and storing what versions of what things you have, not the code or other data in the libraries themselves. I'm pretty sure there is no reasonably copyright on the name and version number of a library in this context.
If it is being done for fingerprinting purposes then there might be an unreasonable tracking claim by the users, but not the library copyright holders.
The less worrying explanation is that it is being used for problem analysis: if a new version crashes a lot but only on devices with a specific version of a specific library, that makes tracking down the bug and implementing a workaround or fix much quicker. Of course this is facebook so if it is for the issue analysis (which it almost certainly is) but can also be used for fingerprinting as well, you can bet your bottom dollar that it will be used for fingerprinting as well.
"Facebook can upload the entire files of all system libraries to their server through their Android apps"
and
"I found they have already collected metadata of 2233 system libraries from my phone, in which 1162 system libraries are pending to be uploaded"
So they've already uploaded the metadata and are in process of uploading the whole files.
At first glance, the amount of damage being done is close to nil — even if they reverse engineer received files to steal trade secrets therein (lol), it is hard to pinpoint specific amount of harm, dealt to the copyright owners.
But actually... why are Facebook people doing that? If I were to wager a guess, Facebook needs those files to create exact copies of user systems to debug. In other words, they are trying to save up on buying real devices for their test lab! Using "pirated" copies of libraries to spin up testing VMs is most likely cheaper than owning lots of real smartphones with all available firmware versions. And also illegal.
I wonder if they gauged possibility of being sued for this along with possible legal expenses and found that it is still cheaper than buying those devices themselves.
Is it through?
If I'm uploading a library to virustotal to check if it's a known piece of malware, am I breaking the law if it was clean?
Note that there is an exception for such a copy when it’s necessary to run the program, I believe this exemption was added because otherwise running an executable on a personal computer would have been a copyright violation.
https://www.copyright.gov/title17/92chap1.html
> a) Making of Additional Copy or Adaptation by Owner of Copy.— Notwithstanding the provisions of section 106, it is not an infringement for the owner of a copy of a computer program to make or authorize the making of another copy or adaptation of that computer program provided:
> (1) that such a new copy or adaptation is created as an essential step in the utilization of the computer program in conjunction with a machine and that it is used in no other manner, or
> (2) that such new copy or adaptation is for archival purposes only and that all archival copies are destroyed in the event that continued possession of the computer program should cease to be rightful.
There are additional excemptions, including copying which is required in the normal use of software, and possibly other information, on electronic systems. Whether copying to a malware-scanning service may or may not be included in that, though it would seem a fair argument that it should be (transformative, doesn't impact market, does affect the whole work, purpose is constructive and not otherwise served, context is specific to the nature of the work).
Absent a rather dubious user agreement allowing Facebook to copy all the data off your phone, Facebook does not have that fair use right. Nor is it likely even remotely ethical to be doing this without explicitly notifying the user. So, illegal and unethical, but I guess unless some PR firm is paying the news media to be outraged about it, they're not likely to care.
Perhaps, but sadly, I don't actually foresee vendors wanting to exercise that right. From a business perspective, why bother?
Maybe in jurisdictions like the US, where the copyright lobby has been very effective in getting aggressive anti-piracy legislation with huge penalties enacted, the statutory damages alone could be astronomical? Since Facebook could still afford to pay them, it might also offer to settle for a very worthwhile sum without even the risk of going to court.
I'm generally not a fan of hugely disproportionate penalties for copyright infringement, but this isn't some normal person falling victim to opportunist lawyers engaging in a form of barratry, this is a huge company with its own legal team who should know better than to wilfully infringe copyright.
They could potentially have ... friends ... who would have an interest in seeing a case brought, though.
(And since Bollea, barratry seems acceptable.)