Instagram took down private unofficial APIs via DMCA
github.com
github.com
The core allegation is:
> Mgp25’s Instagram-API repository (and its forks) offers a tool expressly designed to circumvent the Company’s effective access controls and protection measures by avoiding, bypassing, removing, deactivating, or impairing the Company’s technological measures without the authority of the copyright owners or the Company. Mgp25’s Instagram-API is designed to emulate the official Instagram mobile app when communicating with Instagram’s servers, which allows users of mgp25’s Instagram-API to send and receive data (including receiving legitimate, copyrighted posts by Instagram’s users) through Instagram’s private API. Mgp25’s Instagram-API also permits other types of access to, and collection of, Instagram’s users’ copyrighted works in manners that exceed the scope of access and functionality that would be permitted by a user with a legitimate, authorized Instagram account.
It's been a long time since I read it, but my understanding of the DMCA is that you need to claim an actual copyright violation on the thing being taken down. This sounds like a claim of contributory copyright infringement, which a) I don't remember being covered by DMCA, and b) there's a reasonable claim here for substantial non-infringing use, so I'm not sure contributory copyright infringement really applies.
(I am not a lawyer, but I spend an unreasonable amount of my time staring at Section 1201 issues; if anyone needs legal advice they should contact a lawyer: nothing I say should possibly be construed as legal advice.)
The author admitted to this in the readme of the repo.
Sounds 100% like the API was designed to try and bypass access control mechanisms...
Not sure if that falls under the legal definition or not.
Sure, but your parent's point is that this doesn't appear to be grounds for a takedown. Takedowns are for infringing content, which this isn't.
> [DCMA] criminalizes production and dissemination of technology, devices, or services intended to circumvent measures that control access to copyrighted works (commonly known as digital rights management or DRM). It also criminalizes the act of circumventing an access control, whether or not there is actual infringement of copyright itself.
While I initially thought (like many others on here) that DCMA was to keep you from spreading copyright content or passing it off as your own, the true purpose of DCMA is actually to criminalize the act of circumventing DRM. Access control on a social network I guess is considered a type of DRM for the content within the network (which, lest we not forget, is wholly owned by Instagram as soon as you post it). It specifically states that circumventing access control is a violation, regardless of whether any copyright was actually infringed upon.
So from my keyboard lawyer perspective, it seems like Instagram is actually within their rights here.
[Source](https://en.wikipedia.org/wiki/Digital_Millennium_Copyright_A...)
The claim you're arguing against isn't that the DMCA doesn't cover this. The claim is that the DMCA takedown process doesn't apply to all infringements of the DMCA, only those of copyright wrt safe harbor.
https://github.com/github/dmca/blob/master/2016/2016-03-16-M...
Effective access controls? I think, when someone produces a tool that can access the API despite not having valid keys, you forfeit the right to call the access controls "effective".
Guess that day is here.
Seriously though, we've been waiting years for an Instagram DM API. Anyone know why they haven't yet released one?
Because it would immediately be leveraged for spam?
Shoot me an email.
How could this possibly be a violation of copyright, if it's just a client that accesses their API? Their API is not truly "private," just undocumented. If you distribute a free app that calls a remote API over users' networks, you can't make the case that it's private, because it's clearly accessible from every network/connection/device. Something exposed to the public cannot simultaneously be private.
At least, maybe the author's lawyer could argue the above in court.
Among many things I hate about the DMCA, it's that hosts have basically no option other than to respond to takedown requests by actually taking down the content in question, for fear of litigation. It just rubs me the wrong way.
Edit: people are assuming too much about my intent of this question and downvoting, I was just curious, moreover a good answer to this will make the case stronger against Instagram/Fb.
That's the entire point. A DMCA takedown request is supposed to lead to the content being taken down. The person who uploaded it can send a counternotice, which will lead to the content being put back up if no lawsuit is filed.
What would you change about the system? Should rights owners have no recourse short of litigation to get their content taken down?
3 strikes and you are out. Take down 3 obviously (probably decided by a judge) non-infringing things and you lose the ability to send takedowns.
3 strikes, can't send notices for a week. 3 more strikes, a month. 3 more strikes, a year
Once it reaches this point, the service provider would likely stop accepting the notices anyway. See e.g. the recent lawsuit by Youtube against Brady, who sent a bunch of bogus notices. Once they realized that, they stopped accepting the notices.
There's hardly a critical mass of takedowns by people who've been found 3 times by a judge to have sent fraudulent takedowns.
Because those rarely go in front of a judge. Torrentfreak [0] gets many takedown notices where for example their reporting on a leak gets targeted with a DMCA request. If those companies had to fear someone challenging these (in this example an easy win) and making them lose their ability to send them out at all, that would change a lot.
[0]: https://torrentfreak.com/all-dmca-notices-filed-against-torr...
> In previous years we’ve received erroneous complaints from the likes of Amazon, Electronic Arts, Disney, Entertainment One, Vertigo Films, Magnolia Pictures, NBCUniversal, Paramount, and even BBC Worldwide. This year we can add more.
> According to Google’s Transparency Report, in 2019 Google received a further 11 DMCA takedown notices targeting our domain, sent on behalf of Columbia Pictures, Sony Pictures, and sundry others. All of them were completely bogus.
Why hasn't torrentfreak sued? Presumably because it's not an easy win and doesn't produce real benefits for them. I'm struggling to see how any of that would change under your proposal.
For what it's worth, judges have occasionally issued injunctions preventing people from filing claims, under the DMCA and otherwise. See e.g.
https://www.courtlistener.com/docket/16599762/home-it-inc-v-... ("ORDERED that the Defendant Wupin Wen, no later than eighteen (18) hours after service of this Order on her via email to trademark@cn-ip.cn, trynow@cn-ip.cn, and bzkjuk@126.com: a. Notify Amazon that the trademark owner’s allegations of infringement against HOMEIT are withdrawn and that Amazon should re-list the involved products to its website as soon as possible; and b. Refrain from filing or otherwise communicating any allegations of infringement by HOMEIT to any third party, at minimum, for the duration of the instant litigation relative to Saganizer branded products." docket 21
https://www.courtlistener.com/docket/4160397/design-furnishi... (older case from 2010), "Defendant is therefore enjoined from notifying eBay that defendant has copyrights in the wicker patio furniture offered for sale by plaintiff and that plaintiff’s sales violate those copyrights. " docket 29
https://www.courtlistener.com/docket/16630192/california-bea... "THEREFORE, DU AND ALL PERSONS IN ACTIVE CONCERT OR PARTICIPATION WITH DU, ARE TEMPORARILY RESTRAINED from taking down, based on any alleged copyright infringement, from Facebook and Instagram, or any other service provider’s website, CBC’s online content or product line. Du is temporarily not permitted to file any further takedown notices with Facebook, Instagram, or any other service provider’s website as to CBC’s online content or product line. Any current and operative takedown notices in effect that were filed by Du as to CBC are restrained, and are to be disregarded by the online service provider. Accordingly, and specifically, Facebook (Report #2576187715997707) and Instagram (Report #1407615876061304) are directed to disregard Du’s takedown notice and to reinstate CBC’s online content during the period of this Order. " docket 22
See https://blog.ericgoldman.org/archives/2019/05/court-rejects-... for a court finding otherwise on a similar case.
If you're running a business, there's different expectations.
a) I’m not sure they can even sue currently, isn’t the only thing illegal misrepresenting that you have the right you claim? b) Even if they could, as you say, no real benefit c) The change would mean that just the threat of getting sued for malicious DMCA notices would make the companies sending them better at actually having a case. Currently, there is no risk at all shooting with cluster bombs when sending notices. Barely any risk using DMCA to prevent speech. That is what my proposal would take away.
c) To do that, you'd need to make suing easier. I don't see how your proposal does that.
https://en.wikipedia.org/wiki/Amaretto_Ranch_Breedables,_LLC....
Seems like virtual worlds dealing with the DMCA is complicated, and even if you restore it due to a counter notice process seems like things can break due it... Then I know I was reading before some companies just delete things instead of disabling the content, so they can't even restore it.
Maybe you have an object that includes a item bought from the marketplace and linked it(for people not familiar with SL, sorta like gluing or grouping multiple 3D objects together to become one larger 3D object) to your item, wonder if they just remove the entire object even if 1 part was covered by the DMCA? and then modifying objects, etc probably changes the signature used to detect it... And I know people have used DMCA to troll and mess with competitors businesses. and not sure if the DMCA even allows you to verify people are who they say they are when submitting them, someone could use TOR and say they are the content owner even if they aren't from my understanding... I think they should require a Photo ID and picture of themselves to process a DMCA, but It's probably illegal to ask? You need a Photo ID to do almost anything else though.
I know the though the DMCA was made back in the early days of the internet where people ran their own servers before massive sites with user generated content, seems like it needs reformed.
If you are required to do something by law, you can't just ignore (bad cases of) it, and call it case closed.
DMCA doesn't require them to take it down. It just removes their safe harbor from liability if they don't. If YouTube is confident that a notice is BS, they can just ignore it.
There's an takedown API/dashboard access to which is given to large content producers ( networks, large studios, transmitters, broadcasters, rights holders ). It is them who triggers the takedown action and selects the "reason" which triggers an automated action by the platform. Most of the "content had been taken down by mistake" comes not from internal system but rather from other parties having access to the takedown API.
See also https://www.eff.org/deeplinks/2015/11/youtube-backs-its-user...
This is a major hole in the current law.
USC 512 (f)
EDIT: see for example https://news.ycombinator.com/item?id=22211087
This is a problem with unequal access to the legal system, not with the law.
>Also, from what I hear, many implementations of DMCA do not give the individual enough information to take action against false claims.
It's pretty simple to get the actual information in a lawsuit. Subpoena the service provider for the complete notice sent.
In most cases a lawsuit isn't needed. If you receive a false complaint and file a counternotice, the content gets restored 10-14 days later if there's no lawsuit filed.
Yes indeed, this is exactly what is happening: they get off the hook, and they can keep filing false claims as much as they want because taking action against them is too hard. Hence, toothless. No consequence for sending false claims, the only people who suffer are those who get their stuff unjustly taken down for two weeks.
It'd be a little more equal if, upon receiving a counternotice, all the original claimant's claims would be instantly put on hold for 10-14 days (and then dropped) unless they file a suit.
If you're not willing to do that, and the claimant is willing to swear to infringement, why should we give you the benefit of the doubt simply because someone else said the claimant was wrong in an unrelated case?
I never said that.
The reason why you should give people the benefit of the doubt is because otherwise the system is horrendously unfair and unbalanced in that 1) those who file false claims have nothing to lose (because the likelihood that they get dragged into court is virtually nil, and in most cases even dragging them to court would most likely lose you more time=money than you can hope to claim in damages) 2) those who have their content unjustly taken down keep losing over and over again.
If it's word against word, then yes both sides' word should have equal weight and consequence. Currently, that is not the case.
I'm not sure what you mean here. In that scenario, a DMCA notice was sent and a counternotice was sent. The content gets put back up after 14 days. This seems acceptable to me, and doesn't favor one side disproportionately. Either side can choose to go to court, but if they choose not to, the content is put back up after a delay.
I agree that there's a problem with people filing false claims. But I don't see how a law could improve that.
The legal system didn't magically become the way it is recently or suddenly. When the law was created, the legislators knew that there would be unequal access to the law. They did it anyway.
>In most cases a lawsuit isn't needed. If you receive a false complaint and file a counternotice, the content gets restored 10-14 days later if there's no lawsuit filed.
And your content is taken down for 14 days with no reasonable recourse for you.
This is a very small harm comparatively, in my view an acceptable loss in order to establish the overall framework. The alternative is not having any way to remove content short of a lawsuit, which would lead to significantly more lawsuits that's more expensive for everyone, and hurt smaller content owners that can't afford a lawsuit.
Regardless of what the law is, people prepared to spend money on lawsuits will do better. But the direct impact of the law is moving most disputes outside of the legal system, which has the effect of making it more equal, not less. It's weird to blame the law for the few parts that do require lawsuits, when the alternative is many more suits.
This "rule" was also approved and jammed through by the same lobbyists that protect DMCA abusers. It's all smoke and mirrors to trick people into thinking "oh no it's covered see here's the fine print they would never do that"
https://www.courtlistener.com/?q=%22512(f)%22+dmca&type=r&or...
Yes
Maybe, if you’re lucky. More often it will be ignored.
See #8: https://help.github.com/en/github/site-policy/dmca-takedown-...
Instagram is asserting that this software is such a tool.
"The complaint claims that the tool 'Instagram-API' allows unauthorized access to Instagram users' posts, which the company says are copyrighted works to which it grants protected access."
More info here: https://torrentfreak.com/instagram-uses-dmca-complaint-to-pr...
The only difference is in the tool intent, but all of them can be used for exactly the same purpose, some of them more easily than the others.
Back in the 80s, Sony made a video player that ran Betamax tapes. You might remember the HDVD vs BluRay wars of a decade ago when both formats were battling for dominance to become the new standard for playing HD movies on disc. Well, before that was the VHS vs Betamax wars. During these battles, Sony was trying to make Betamax the new standard for home movies. They wanted to distinguish themselves from VHS in some way and they ended up distinguishing themselves with an amazing and unheard of feature (for the time), you could not only watch movies with Betamax tapes, but you could RECORD movies to watch later. You could record anything on TV, in order to watch it later. This is 20+ years before DVRs, 30 years before streaming services. It was a crazy idea.
But Universal Studios didn't like the idea that someone could record a show on TV and watch it later, or watch it however many times they wanted. Someone could theoretically even sell that Betamax tape to someone else. So Universal Studios sued Sony over this invention. Universal Studios claimed it violated copyright. Sony claimed it was protected under the "fair use" clause for copyright.
The lawsuit ended up tipping in Sony's favor, but only barely. One of the most popular kids shows at the time was "Mr. Roger's Neighborhood". The supreme court heard from Mr. Roger's himself who testified that he was ok with people recording his show because it allowed them to be with their family and not controlled by the schedules dictated by the television studios. He said he was against the studios controlling people's schedule. The supreme court ultimately mentioned that this testimony is what tipped the case into Sony's favor.
But it didn't just tip in Sony's favor. This landmark case is what opened the door for all recording media in the future. The Betamax eventually died, but the VHS later made the same features available. Radios and boomboxes in the 90s had a recording feature added. DVRs came about in the early 2000's to record TV to harddrives. Then computers had screenshotting, and web browsers likely got "save image as" because of the precedent set by this landmark case.
Where the DCMA differs is that it protects tools built with direct intent to circumvent a specific copyrighted content. So the linked tool for example is a script built specifically to circumvent Instragram's access control. It doesn't circumvent anyone else's access control, and its primary purpose for existing was to gain access into Instagram. So I think Instagram can make a reasonable case to go after this tool.
However, going after a general tool like screenshotting would go nowhere, because it is considered a general good. It provides value that far surpasses the damage Instagram can claim from it.
Again, we can probably thank Mr. Rogers. Without him, recording might not be something we could take for granted today.
Sources:
- https://en.wikipedia.org/wiki/Sony_Corp._of_America_v._Unive....
- https://www.theatlantic.com/technology/archive/2012/01/the-c...
> Why did I make this API?
> After legal measures, Facebook, WhatsApp and Instagram blocked my accounts. In order to use Instagram on my phone I needed a new phone, as they banned my UDID, so that is basically why I made this API.
Here's a script I made to backup all your repos, throw it into a cron and run once a month or something, where 20 is the largest number of pages you have, adjust accordingly. I actually wrote this up when a fork I had disappeared.
#!/bin/bash
USERNAME='segmond'
for i in `seq 1 20`;
do
curl --fail -s https://api.github.com/users/$USERNAME/repos?page=$i | jq '.[] | .clone_url' | xargs -t -n1 git clone
sleep 1
donehttps://help.github.com/en/github/collaborating-with-issues-...
I don't think that's true, I've personally recovered deleted repositories by finding its forks.
edit: Ah never mind it seems things work differently in the case of DMCA takedowns
The latter isn't "github fork" even if it is a "git fork" and won't be affected by most[1] automated takedowns.
1> where most is defined as somewhere between 0 and 100%
This is an honest question, and not a rhetorical one.
[1] https://github.com/NantipatSoftEn/Instagram-API
[2] https://gitlab.com/alihesari/Instagram-API
[3] https://github.com/DarriusAlexander/speaklight/tree/1b4167c3...
https://web.archive.org/web/20191207221404/https://github.co...
Is the only difference between using this library and using Instagram's mobile app the fact that the library is not the "right" web browser?
Isn't the library simply a different web client accessing a publicly available API? And requests from the library are properly authenticated / authorized by Instagram's servers through normal means (the library isn't bypassing some mechanism, it's just not the official app)?
If it's true that it's just a different API client, then there may be some TOS violation, but isn't DMCA an overreach? Is there any validity to the claim?
The fact that they're willing to just throw tons of money at lawyers to be wrong and infringe on everyone else's rights is exactly the reason we should make them take us to court on principle.
My understanding is that Google bought YouTube mostly to avoid an underfunded YouTube in legal trouble having a bad precedent set.
If Facebook thought they could win against Google or Apple, they would have sent DMCA letters to Google and Apple for making web browsers and phone emulators with "developer tools" built in. But they know they'd lose, so they went after some random person on the Internet with no money.
The reason for that is simple: DMCA takedowns in large companies are handled by someone who at best is a year out of law school who processes hundreds of them per day. 99.99% of those go unchallenged because no one knows about the process. As soon as the counter-notice is served this person/entity indicates that they aren't the 99.99%, at which point someone actually starts looking at their play book. It will be another round of notice/counter notice game before someone that bills $400/h looks at the merit of a company's assertion. In the larger companies the cooler hands tend to prevail in non-obvious cases.
So people should be cheering this no? I mean facebook are protecting their users from nefarious developers seeking to get access to people's data.
The only crit is that it took so damn long to find it. (since 2016!) https://web.archive.org/web/20160603201221/https://github.co...
I know thats not whats annoyed most people. But if facebook really are serious about privacy, then they took too damn long
It's almost as if they're making the same error as OP who identified the library as "an API" rather than a client of an insecure API implemented by Instagram. Presumably they know better.
What if it turns out they detected this code was run by other people and responsible for 50% of the unauthorized access? Just because it doesn’t entirely solve the problem, does not mean they shouldn’t pursue all partial tactics.
That mention in the readme from 2016 mentions a UUID banned from Whatsapp, so I'm not sure if that's what the author meant or just something copied from another readme. Either way, if Instagram was banning UUIDs it would be as trivial as getting another phone to bypass it, or to log in via a web browser.