The document claims that youtube-dl is illegal for being able to download video and audio from YouTube but not for hosting copyrighted material in the repo or binary distributions. The RIAA is claiming youtube-dl is "circumventing DRM".
So if that is true, then youtube-dl is not illegal and this DMCA is easily reverted.
RIAA is just trying to use their deep pockets against a nobody and Microsoft is basically saying "We side with you" knowing damn well their lawyers know this code is not illegal.
They are both obviously user agents used for accessing video content hosted on a public remote server using standard web protocols.
Then tell me how uBlock Origin is somehow Ok if YouTube-dl is not.
Anyone who read the justification in the original complaint would see how these are different, but it doesn't matter; the RIAA is not pursuing them so until they or someone else does it's irrelevant.
One comes from the publisher and is intended to play back the content in an approved way.
The other is a reimplementation of the first, intended to circumvent the restrictions imposed by the first. That's illegal, per the DMCA. It's black-letter law in the US and elsewhere.
In this case we have video which is streaming on the open web, which trivially provides for the user agent to download / cache a copy. The question is not a matter of whether that copy is being redistributed, but that the user agent can watch it in an ad-free space whenever they want. You could probably accomplish the same thing, or nearly so, with a browser plugin.
Which is why I make the comparison to uBlock. uBlock is similarly "playing back the content in an unapproved way" and perhaps you could say it is also a circumvention device.
The whole concept of "user agent" is that software on the user's machine -- that they control -- is rendering remote content in a form and fashion chosen by the user. The HTML provided by a remote server is not a legal contract for how that content must be displayed. It is a semantic description of the content, which the user agent can do with whatever it pleases for display to the user.
As long as no redistribution is occurring, the whole basis of the world-wide web is that a user agent can do whatever it wants to the content, including save a copy on the local machine.
So to me the most interesting question is exactly how youtube-dl becomes/became distinct from a user agent.
No-one out there thinks there's any problem watching them on Youtube, where royalties can be traced and paid.
You can use youtube-dl to download videos, but the intended use here is clearly for watching them. Just because syringe needles are tested on (and advertised for) human skin and are also tested with poisonous chemicals, that doesn't mean you should attack syringe needle manufacturers for making murder weapons.
For starters, intent is factored into the law. There's several different classifications of murder depending on intent. Likewise someone carrying a kitchen knife home, still packaged, from the shops is unlikely to be reprimanded compared to someone carrying a more decorative knife around. They're both knives but one instance clearly carries a different intent to another.
The problem with youtube-dl is that having tests which work against copyrighted content and having the README describe usages against copyrighted content, it's much harder to argue that the intent of this is purely for copyleft content. Your point about this being an access tool (which actually makes no difference in terms of circumventing DRM anyway -- which was the claim for the take down) also doesn't fly because this tool creates a file on your local disk so it's hard to argue that the intent is for that file to be temporary.
I'm not saying I agree with the take down notice (I don't) but something a great many techies on here miss is that not every argument can be won with science.
What gets lost or missed is the underlying intent of the protocols and tools being used to share content. An http server serves files independent of the client/user-agent–that's how the web works. If a work is published this way then that's the expectation. If YouTube and the RIAA want it to work another way, then use a different protocol/medium and put the content behind a login and limit access.
I'm not saying people should be free then to republish/share copyrighted works. Just that we are free to use tools to retrieve files that have been served openly via the web.
It's not as clear as let's say access to a public park on private land. But the idea would carry weight that youtube may control the manner in which their publicaly accessable website may be accessed.
Let's say you can access via the YouTube app which does not require an account, and now you reverse engineer that app to bypass the app all together. It's a bit like cutting a hole in the fence around the playground.
I'm not a fan of what happened it's just clear to me why it happened.
There's an expectation from the publishing/serving side of the equation that the content is being served to a proprietary app or a web browser that works a particular way. With the browser being one of Chrome, Firefox, etc., along with Google's YouTube apps.
On the user side, especially those who understand how the content is served, that the browser is not the only abstraction allowed. Google themselves run bots to scour the internet employing all sorts of tricks to access and index content. There's a fundamental way in which the http protocol works and its content served that is client agnostic. Everyone, Google Search most of all, have benefitted from this.
Making tools other than browsers illegal will fundamentally break the internet in my opinion.
They don't use HTTP. HTTP is used to bootstrap the player, not to feed the content. The content itself is served over another protocol such as RTMP and that protocol is a streaming protocol (it sends chunked data) and it wasn't intended for downloading files and writing them to disk as a singular binary blob. Obviously it can be used that way but it's fair to say services like youtube-dl are using the protocol in ways it wasn't originally intended to be used rather than content owners serving content on a protocol that was always designed for distributing files.
It's a bit like recording something on VCR from an RF signal; there's nothing technically stopping you from doing that as recording a TV show is technically equivalent to watching it. But equally you can't blame TV networks for using RF to air their broadcasts knowing that risk is there.
The problem is any delivery system you can dream up for enabling consumers to view a recording will have some unintended method for copying said content. Even if it is as low tech as someone physically sat in a cinema with a handheld camcorder (how many movies have been leaked online that way?!)
This is why I keep coming back to the point that you can't use science to argue a legal issue; they ultimately serve different purposes. Science can prove something can be possible, the law is there to argue if something should be allowed to happen (putting aside for one moment the variety of differing opinions about morality et al). So if you have an issue with the youtube-dl take down then you need to treat it as a legal problem rather than a misunderstanding of a technical solution.
Not true at all, most YouTube videos are offered as plain webm files.
Also, keep in mind that recording TV's is legal.
It's been a while since I've written a video streaming scraper but it used to be quite common for a file to be served over HTTP but that file was a small "shortcut" type file to an RTMP stream. So a webm file wasn't the content itself but instead a pointer to where to stream the content from.
I'd imagine the same would still be true for YouTube since, like most other video streaming services, YouTube can adaptively switch bitrate depending on the bandwidth available to the end user. That seamless switching can't be done with a HTTP GET of a singular video file but it can happen effectively with a chunked streaming protocol.
> Also, keep in mind that recording TV's is legal.
Yes but with caveats, depending on the country.
Though it is worth noting the only reason America and UK law is so relaxed regarding VCR usage is because corporations making video recorders were taken to court by film studios and won their case. So once again it comes down to presenting a legal argument rather than a technical one.
HLS is not about downloading a file, it's about downloading chunked data. It wasn't intended (though it can't be prevented) that the chunks would be used to recreate a video in full, unlike with a stream of bytes from a HTTP GET which are very much intended to be recreated in full at the receivers end.
HLS really only uses HTTP transport as headers to circumvent many firewalls (and in fact you can do this with RTMP too, eg RTMPT) but aside from that it's a completely different beast to GET.
Is this even a science argument though? The law and its enforcement may occasionally use science to illustrate specific cases (the implementation) but it's more the documentation of a giant, waterfall-based architecture project. Why are we suprised when we see specific cases that seem like failures despite agreeing with the fundamental premise?
I use YouTube-dl as much as the next guy for lawful reasons but these HN comments saying it's not for YouTube and it's not for downloading is silly. It's literally in the name.
Please remember that to reverse this YouTube-dl needs to go through a court. Courts are not code that can be tricked by clever wording. If anything you'll be trying to describe what it is to some old grandma who hasn't got a clue what GitHub is never mind convincing them this software isn't for downloading YouTube videos.
By all means everyone go on with coming up with clever interpretations of the law but you're just farting into the wind
P.s downvoting my comments doesn't change the way the law works either, but if it helps you feel good have at it :)
Regardless of the name, the tool supports over a thousand different sites, not just YouTube, and is routinely used for streaming rather than downloading, with no permanent copy saved. If you run "mpv https://youtu.be/WhWc3b3KhnY" to simply play the Blender Open Movie "Spring" it relies on youtube-dl behind the scenes to stream the video. (Though of course the difference between streaming and downloading is a trivial one; getting the content to the end user's device is the hard part.)
YouTube itself is the entity responsible for duplicating and distributing the content, and they have a license to do so, ergo there is no copyright violation here. The most any user of youtube-dl might be liable for, assuming they don't save a permanent copy or further redistribute the data, would be a violation of YouTube's TOS. Which is no concern of the RIAA. To call youtube-dl a "circumvention tool" is laughable; obfuscation of a video's URL is not DRM.
Do you have a source on this? I can't find anything about this through a quick Google search, but I'd love for this to be true.
This, at the core, means it is very hard to argue that some library written to circumvent DRM is "illegal tech" and have it taken down in this manner, because the DRM could be inappropriate and it is not the copyright owner who has to decide that.
The ECJ was asked by a Milan court for a preliminary, so they gave instructions how the Milan court should handle the matter and how the law is to be interpreted. The base case was about a mod-chip sold by pc-box, who argued as a defendant, that circumventing nintendos DRM for the purpose of playing homebrews was ok and nintendo preventing that is inappropriate.
In the general case this was a huge win, because "circumventing DRM is illegal" is only true with a big IF, not as a blanket statement. And from that follows that usage of alternative clients is well within the consumers rights, but again i am not a lawyer.
However note that the Milan court then ruled in its case 12508/2015 that this particular mod chip is illegal. Nintendo gave a lot of evidence about the advantages of their DRM in terms of cost, ease of use, security etc, comparing it to inferior implementations of their choice that would fail to protect the copyright holders interests, as well as evidence of usage of the mod chip for piracy. On the other side pc-box defaulted, filing no evidence showing that their users are a vibrant community of homebrew gamers and techheads that circumvent DRM for purposes well within their rights, like running self written software on the hardware. The Milan court also argues that defendant has a burden of proof to show that a more proportionate drm method was possible, which i strongly disagree with, and which seems to follow nintendos argument that their solution is appropriate even if more restrictive then strictly necessary. Note that Milan does not speak for the EU.
https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:... article 6(1):
> 1. The authorisation of the rightholder shall not be required where reproduction of the code and translation of its form within the meaning of points (a) and (b) of Article 4(1) are indispensable to obtain the information necessary to achieve the interoperability of an independently created computer program with other programs, provided that the following conditions are met:
(a) you're allowed to use YouTube, (b) YouTube is undocumented, (c) this only applies to relevant parts of the code.
> 2. The provisions of paragraph 1 shall not permit the information obtained through its application:
to be (a) used for other stuff, (b) distributed, (c) used for cloning or copyright infringement.
> 3. In accordance with the provisions of the Berne Convention for the protection of Literary and Artistic Works, the provisions of this Article may not be interpreted in such a way as to allow its application to be used in a manner which unreasonably prejudices the rightholder's legitimate interests or conflicts with a normal exploitation of the computer program.
Creating youtube-dl isn't infringing on anyone's copyright, and the rightsholder here is Google, so it's allowed. There's wiggle room for arguing – it's not as cut and dry as most Big Bold Legal Statements I make, so iamnotalawyerandthisisnotlegaladvice – but I'm fairly sure this is sound.
In the UK, you have unequivocal rights to do this. https://www.legislation.gov.uk/ukpga/1988/48/section/50B, based on this directive, says:
> (3) In particular, the conditions in subsection (2) are not met if the lawful user—
> (a)has readily available to him the information necessary to achieve the permitted objective;
> (b)does not confine the decompiling to such acts as are necessary to achieve the permitted objective;
> (c)supplies the information obtained by the decompiling to any person to whom it is not necessary to supply it in order to achieve the permitted objective; or
> (d)uses the information to create a program which is substantially similar in its expression to the program decompiled or to do any act restricted by copyright.
The wording in (d), here, is clearer than the EU directive – unless youtube-dl's existence can somehow be shown to be a copyright violation (specifically, if its creation was an act restricted by copyright), it's permitted. Not sure whether this would help in an EU court, but if other countries' implementations have taken the obvious interpretation of the directive, then the other language versions of the directive are probably clear on the matter.
What you’re describing is a circumvention device. The DMCA explicitly outlaws these. 17 U.S. Code § 1201
Or are we talking a sweetheart deal only available to specific parnters ?coughvevocough
No it's not, in Switzerland for example it's legal to use tools to remove stuff like DRM, if you DONT redistribute the decrypted stuff.
What a German Court says is often not relevant outside germany.
In short, what a german court says will absolutely influence what a US court says in the context of an international copyright treaty.
Not will but can. That's a difference...and i dont watch a 1h20min YT video about Copyright...when decrypting has nothing todo with copyright.
Watch it, don't watch it, it doesn't matter to anyone here, but please lower that horse back down to earth, it's a little high.
As if your talking about yourself, maybe your a bit young but we had the exact same problem in the past (decrypting DVD's) those are Disc who stored Movies on it. And a Swiss Court decided that it's legal to use dvcss (not sure about the name).
And you tell me to watch a YT from a US Lawyer.
So yeah, tone it down a bit.
Speak for yourself please.
And download a Youtube Video is legal.
Storing your DVD's in another format and rip your CD's
EDIT: BTW in the take-down notice you can read that the tool promotes or is/can be used to download Justin Timberlake (and that would be illegal if you redistribute it) so it's not that the code to decrypt is illegal (you know "hackertools" are illegal in germany too) but the potential intention of the tool.
The DMCA as written is a little more nuanced, but on whole the laws serve the same purpose.
Not the tool is meant here but the User, and you know it.
It's legal to record radio, and record/download Youtube videos, if you don't redistribute it (outside Family and Friends
[1] https://github.com/github/dmca/blob/master/2020/10/2020-10-2...
https://joindiaspora.com/posts/808cf690f8e801381778002590d8e...
The DMCA makes circumventing "effective" protection measures illegal. "Effective" is a term defined in law and basically means any hoop you have to jump through to get to copyrighted material, no matter how flawed or trivially bypassed. The restrictions in place to allow YouTube videos to be only downloaded through YouTube count.
Youtube-dl is absolutely illegal software.
Not in Italy
What US law says is often irrelevant outside of the US of A
[1] https://www.wipo.int/edocs/lexdocs/laws/en/it/it211en.pdf
[2] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A...
You should know that "absolutely" means anytime, everywhere, which is obviously wrong.
You should also know that in Italy for something to be claimed illegal the court has to emit a verdict.
If nobody challenge the status of youtube-dl obtaining a guilty verdict, it is perfectly legal.
Last but not least, that law was created during fascmism, so there's also that.
But in any case "fair use"(as you americans call it) is always permitted in Italy, you don't need a license, you are liable only if the entity detaining the copyright obtains a restricting order from a judge.
So in Italy I can download any video I want from YouTube and I am permitted to watch them, It's not against the law.
What's against the law is the re-distribution of the content.
Moreover, you probably misread the law or skipped that passage, in Italy internet publishing (such as file downloading) itś a different right and it's called "exclusive right of communication to the public of the work"
> it also includes the making available to the public of a work in such a way that members of the public may access it from a place and at a time individually chosen by them
Sorry.
All the responses "not illegal in COUNTRY X"; how is this relevant? Is the RIAA using a law from <UTOPIA_COUNTRY> on a company based in <FANTASY_LAND>?
You can absolutely host this repo with a country & business that doesn't recognize or cooperate with US laws. Your choice is somewhat limited.
The infringement described in their notice is hypothetical, not an actual instance of infringement, which is one of the required things in a DMCA notice.
GitHub can indeed leave the repo up, as this notice is insufficient to trigger the part of the DMCA that forces them to remove it.
More info from Parker Higgins in a tweet thread:
It is risky though, as the company opens itself up to a lot of liability if its wrong.
Anyone daring to put up a fight with Wikipedia risks being flattened by outrage.
In all honesty, we need a GH alternative hosted outside the US, in any place where absurd laws like DMCA don't exist.
Even though other sites like GitLab exist that GitHub remains a near-monopoly default doesn't bode well for attempting to migrate to a completely decentralized system as default. There are decentralized extensions of git (like git-ssb).
Addenda: Git is also not well suited for a lot of decentralization due to how branches are modeled. Patch-theory based systems like darcs and pijul would need more adoption before code repositories could be decentralized.
If I have for example my own Gitlab server I have the ability to clone a project from GitHub and maintain my fork on my server. However, to contribute back, I will still need to bring my changes back to GitHub first.
What a federated implementation of such a "git hosting/collaboration platform" would allow me to do would be to fork a project from another instance to my self-hosted instance. It would benefit every open-source project that would be willing to host their own instance. I could then easily contribute back into the main project without needing an account on their instance.
It would also make it much harder to take down a project with a DMCA like this because forks of it would exist across instances, meaning claims would have to be sent to each maintainer of these instances. In this case, they were simply able to list all of the forks on GitHub and because GitHub is one website, all of them were taken down, seemingly without any further inspection wether the claim covers these forks as well.
I realise that this is difficult to implement but I think mastodon is a great example of how such federation can work in practice.
What if you could make a federated/decentralized git that doesn't care whether the git repo is made available by github or my-fancy-federated-git-host?
It is like wanting to keep Twitter in the loop when migrating to federated alternatives like the Fediverse. Twitter (or Github) wont federate in good faith and will actively attempt to capture as much users as possible.
> What if you could make a federated/decentralized git that doesn't care whether the git repo is made available by github or my-fancy-federated-git-host?
Git is distributed already; remotes work like that.
Github is simply hosting the repos.
Git is decentralized already. That's the key difference between Twitter and Github and why I made GAnarchy the way I did. and also why I make a point of hosting a GAnarchy instance on github pages and encouraging others to do the same. (self-hosted is better of course, but.)
Gmail has an enormous market share (about 40%) but I don't think that's related to the nature of SMTP, more about their incredibly competitive free tier and the decidedly not federated groupware for their business offering.
If gmail decided to ban a number of accounts due to something like a DMCA claim, I would be unaffected by that.
The same is not true on GitHub which is one Website. Every fork of this project on GitHub was affected by this claim...
They did let one-in-20 or so emails through, but everything else got to gmail recipients’ Spam folder. I wasn’t able to troubleshoot this with Google tools, and there’s no one to talk to at google.
(Worst thing, you get no feedback - except realizing a month later that someone didn’t get an email you sent)
I gave up and replaced small ISP with fastmail.
My bottom line is that, no you can’t really run your own SMTP server anymore unless google, Microsoft and fastmail let you, by virtue of hoisting 90% of your recipients.
I have many domains that I use to send and receive mails, and I have personally never had these issues.
Now if I did have a gmail account, I suppose I would have to check the spam folder regularly. But I don't have that problem with my server, it affects their users more so than me.
in a federated world, while github may still host all the code, you could potentially submit prs with and have metadata about a repository, such as issues, spread across multiple different providers. Instead of needing a github account to contribute, you just need an account that github could federate with.
This would mean that if Github did start doing something you didn't like, you would be able to change code host without losing the metadata.
Potentially, anyway.
Federation doesn't prevent centralisation if the service is good enough; it just makes it less painful to decentralise if better competition exists. It also diversifies ownership of data, which is in general a good thing for consumers - and a bad thing for big tech companies that wish to make money off of analytics, which is why we will never see current social media platforms allow federation with other social networks, even if would be better for the world and consumers.
No, at most-- they lose a safe harbour if the notice was well formed and properly delivered, and they don't follow the procedure.
But the vast majority of notices are not well formed or properly delivered.
And loss of the safe harbour isn't particularly important if the complaint is bogus to begin with.
Sure, it does mean a slightly increased risk of legal costs-- though anyone can sue github at any time regardless-- but ultimately those sorts of risks are business decisions that have to be weighed against other business costs and benefits.
Github has historically been pretty unusual in its degree of following the DMCA takedown requirements, a lot of other places are a LOT more willing to ignore apparently spurious DMCA complaints than Github has been. I had hoped that this would change with the Microsoft acquisition, because maybe before their position was just that they couldn't afford any legal fights... but it doesn't seem to have been.
The 17 USC (2)(c)(1)(C) safe-harbour protections apply only to hosting of infringing works, and neither youtube-dl nor its test suites infringe on any RIAA or member copyrights as averred in RIAA's notice.
https://www.law.cornell.edu/uscode/text/17/512
The RIAA's letter does not claim infringement within the text of youtube-dl source or test suites, though it tries hard to appear so, but rather anti-circumvention of a "copyright protection mechanism", under §1201. That is also part of the DMCA, but falls outside the safe-harbour.
At best, youtube-dl's test suite may be infringing works when run, in which case infringement would accrue to the operator, presumably a tester or Github's CI/CD process. Even that argument is specious.
Given output is discarded, no permanent copy is retained, and the action is for research and development, and numerous Fair Use affirmative defence claims exist under §107, notably (1) and (4), test suite execution falls outside exclusive rights. Any one fair-use test is sufficient, or none at all. Test suite execution could be argued non-infinging under numerous theories, including reverse engineering, research, interoperability, all under §1201, or under general limitations on exclusive rights in §112, §117, or elsewhere.
This is where ... things get interesting....
- The "copyright protection scheme" in question, if it even is one, was written by and is provided by Google/Youtube, not the RIAA.
- It is not even clear to me the RIAA has standing to sue under §1203: "Any person injured by a violation of section 1201 or 1202 may bring a civil action in an appropriate United States district court for such violation." RIAA are not injured due to utilisation of a non-member's mechanism.
- Does not pass the 17 USC 1201 (a)(2)(B) test: "has only limited commercially significant purpose or use other than to circumvent a technological measure that effectively controls access to a work protected under this title".
- Yes, Microsoft / Github may have liability under 17 USC 1201 (a)(2), "offer to the public, provide, or otherwise traffic" the code, subject to the same test above. However there is no safe-harbour provision for such violations.
- Microsoft (owner of Github) is listed on the RIAA's members page. Neither Google LLC, its Youtube subsidiary, nor parent Alphabet Inc. are. The RIAA are threatening a member for a §1201 violation against a nonmember. That's ... weird. https://www.riaa.com/about-riaa/riaa-members/
- There's an exception in §1201(f)(2) "a person may develop and employ technological means to circumvent a technological measure, or to circumvent protection afforded by a technological measure, in order to enable the identification and analysis under paragraph (1), or for the purpose of enabling interoperability of an independently created computer program with other programs".
- Youtube-dl is executing code as a World Wide Web user agent, provided by Google/YouTube, and meant to be accessed and run by user agents in order to access YouTube content. That is, youtube-dl's operation is entirely within YouTube's technical design and intent.
- Any potential copyright infringement which might occur through use of youtube-dl is at the volition of users, not the software's authors, actions would properly be directed at such users for individual acts of infringement, and much of this is subject to the same and other defences listed above.
The remaining question is whether or not this claim should be contested. I argue that it should, on numerous grounds;
1. Though the claim is made under US law, similar anti-circ provisions exist in international law, which is highly standardised in large part thanks to the RIAA, MPAA (video), SIIA (software), WIPO, and other copyright monopoly cartels' special-interest deep-pockets lobbying. Offshore legal safe havens are limited and vulnerable. Defence within DMCA /anti-circ / WIPO / Berne regions is unfortunately necessary. Simply hosting the repository outside US jurisdiction is not sufficient, though a valid immediate response.
2. Such claims are specious at best, carry heavy chilling efects, may be entirely fraudulent, and should carry considerable risk. A countersuit agaist RIAA may help make this cartel, or others, think twice about repeating such attempts, as well as establish precedent agaist future such attemps.
3. The future of software, to which Microsoft claims to have harnessed its own wagon, is open, collaborative, Free Software. As such, the software and information services industry's interests diverge from those of regressive copyright maximalists.
TL;DR: This is not a 17 USC 512 infringement/safe-harbour, RIAA's standing is highly questionable, it is threatening a member for an averred nonmember's §1201 injury, any actual works duplication is not performed by youtube-dl's developers directly, nor is the work itself or its test suite an infringement of RIAA / members copyrights, and numerous defences exist for routine use or incidental transmission or copies made by others. Further, youtube-dl, digital and information liberties groups, Microsoft, and Google/Youtube should fight the RIAA's claim.
> Microsoft (owner of Github) is listed on the RIAA's members page. Neither Google LLC, its Youtube subsidiary, nor parent Alphabet Inc. are. The RIAA are threatening a member for a §1201 violation against a nonmember. That's ... weird. https://www.riaa.com/about-riaa/riaa-members/
I'm guessing that's a typo, and this was actually meant to say the following?
> Youtube-dl is executing code as a World Wide Web user agent, accessing a service provided by Google/YouTube [...]
I'll try to clarify that elsewhere:
> Youtube-dl is executing code provided by Google/YouTube, for Wold Wide Web user agents, as a World Wide Web user agent, and meant to be accessed _and run_ by user agents in order to access YouTube content. That is, youtube-dl's operation is entirely within YouTube's technical design and intent.
https://joindiaspora.com/posts/808cf690f8e801381778002590d8e...