RIAA’s YouTube-dl takedown ticks off developers and GitHub’s CEO
torrentfreak.com
torrentfreak.com
Did it though? Sure, the Streisand effect caused more distribution of youtube-dl, but that's never really been an issue. Open source software as widely used as youtube-dl is mirrored in a hundred different places.
The issue here is what does future development of youtube-dl look like? It sounds like the rolling cipher stuff is going to have to go if development is to remain on Github, and that's a win for RIAA.
This isn't all that different from the fact that sites which prominently support free speech attract all the extremists, because that's the only place they have.
It's easy for an individual site to break youtube-dl, and it happens often. Awareness/distribution don't matter if:
A) there is no central repository for updating the project//distributing updates B) threat of legal action deters maintainers from the project
Source: I added a custom YouTube player to my app several years ago, and, actually, besides my own reverse engineering, youdube-dl sources were quite helpful with figuring it all out. It didn't play those "protected" videos though.
https://gitlab.com/ytdl-org/youtube-dl/-/blob/master/youtube...
When I think of what it's like being an engineer (regardless of field), I think of the distance between "isn't the solution as simple as...?" and what the project actually looks like after a year in production after encountering the full domain of things that can go wrong.
Though youtube-dl also simply does more than what you're assuming. And ctrl-f for "drm".
Thus, for most videos, there is no need to circumvent any technological measure, e.g., a so-called "rolling cipher" for the video signature. Section 1201, specifically referenced in RIAA's letter, requires that the circumvention software be "primarily" designed for circumvention. It's arguable youtube-dl is not primarily designed for downloading the minority of YT videos that use the rolling cipher, or whatever "protection" Google may choose to offer the minority of YT accounts that want to use YT as a distribution channel for commercial content, e.g., VEVO.
With the rolling cipher, Google tries to ensure all HTTP requests sent by the user are made via its own Javascript player. However this still does not stop anyone using a popular browser with Developer Tools or the equivalent (such as Microsoft's own Edge browser) from obtaining the download URL and using any TCP client the user chooses to perform the download. Nor does it stop any user from observing the download URL via other means, e.g., users observing the TCP traffic entering their personal networks.
Through the use of the rolling cipher, YT does not restrict access to the the download URL. It simply changes the URL periodically. The rolling cipher is thus not an effective access control. For example, when Google promises YT account holders Google can prevent users in a certain geographic region from accessing a video, does Google use a rolling cipher in the Javascript player as the access control.
This issue is silly to me because the YT videos I am interested almost never use the rolling cipher. I cannot be the only one. If the user is someone who wants to consume commercial content from VEVO and the like via YT, surely she is also content to do so using Google's Javascript player and submitting herself to ads and tracking that web browsers enable.
IMO, there is more to YT than what the RIAA's members contribute.
The point of the rolling cipher is that you can't access the video without running their JS. youtube-dl did exactly that, just as any user agent would.
Not sure about that. The RIAA approach over the last few years doesn't seem very well researched or well thought out. They seem to more go after "targets of opportunity" + add in coercion wherever possible.
That's just my impression anyway.
Now, if they had designed a system where the key could only be operated once/for a given timeframe from a specific left hand glove, then the intent would be clear (IOW DRM container like widevine or fairplay). But the intent of making it from cumbersome to impossible for right handed, broken armed, or disabled people, or just missed the bus and being late, to use the key would be very clear also.
What’s clear to me from this overall SNAFU is that they’re after the eyeballs. The content only matters as an eyeball attractor.
I’m wondering if in the EU youtube-dl could fall under protection for interoperability.
You can see the Mona Lisa but you cannot take a photo of the Mona Lisa without previous consent of the Louvre.
You can, they just ask you to responsibly not use a flash.
https://c8.alamy.com/comp/F0948J/tourists-photographing-mona...
This specific painting is public domain, you could copy it to your heart’s content.
> I think a better analogy is: Handing someone a key to unlock a door to watch an artwork and then taking the (a copy of, a photo of) artwork with you.
I kinda get your point, but it’s completely non obvious that the key from YouTube has any sort of such value: it’s just a string of chars, it could just as well be some homegrown encoding, tracking system, or error check+. A ticket has clear information about its validity in space and time. I’d argue that the alleged protection is so lousy as such that it could very well be dismissed as being one, whereas a ticket+museum or video+drm you cannot get the content out of the container, at least not easily so, and it’s very obvious that it’s there to prevent that, with enforcement of metadata on the key (e.g cert/key with time, device or account id, pubkey signature, ...)
I seem to recall a legal provision (might be DMCA even) that says if the protection scheme comes to be trivially bypassed then the circumvention clause doesn’t hold water, in essence codifying protection obsolescence and making e.g DeCSS ultimately legal, but I can’t find the reference to that.
+ I’d argue it’s actually more akin to the second one.
I still think it's debatable whether youtube-dl constitutes circumvention of effective controls or not. This is the relevant definition:
> a technological measure “effectively controls access to a work” if the measure, in the ordinary course of its operation, requires the application of information, or a process or a treatment, with the authority of the copyright owner, to gain access to the work.
I'm not intimately familiar, but is youtube-dl cracking the rolling cipher, or using the keys that YouTube provides? I believe there is a very valid argument that using youtube-dl is not evidence of circumvention of effective access control systems. There are a plethora of other reasons one might want to use it. One perfectly legitimate example is if you want to watch a video in 1080p without constant buffering, but you aren't on a network connection that can support that. You're basically using your hard drive as a much, much larger buffer. You can often even play the videos with the same browser that opened YouTube, so it really does become effectively cached content (albeit a cache external to your browser).
I think they would also have to demonstrate that downloading one of those videos is a copyright violation. You could argue that as long as the video is available, it should be valid for you to cache those videos. If I'm going on a plane, or I know my internet is going to be out, is it really a DMCA violation for me to download those videos and time shift my viewing to when my internet is out?
> Through the use of the rolling cipher, YT does not restrict access to the the download URL. It simply changes the URL periodically. The rolling cipher is thus not an effective access control. For example, when Google promises YT account holders Google can prevent users in a certain geographic region from accessing a video, does Google use a rolling cipher in the Javascript player as the access control.
I disagree with this part. As much as I don't like it, I can't find any way that the rolling cipher is not "effective access control". I linked the definition above, but to the layman (and these laws were written by laymen, so you do have to bear in mind their intent) periodically changing the download URL is an effective access control because they can't bookmark it and go back to it later. We can argue that using the Developer Tools is "in the normal course of operation", but I think you're extremely unlikely to get a judge to agree that opening the Developer Tools is "in the normal course of operation". It's normal to us, but it is not normal for the US as a whole.
In short, I think anything that you can't bookmark a download for probably counts as "effectively controls access". I'm sure other industries feel the same way; oil execs say what they're doing is slightly different than what the law stipulates, doctors says what they did doesn't exactly match up with what malpractice law requires, etc. The only person who's opinion matters is the judge, and they probably aren't an expert.
As an overall summary, I think we're more likely to succeed by poking holes in the RIAA's case. Youtube-DL is under no legal obligation to prove anything; the RIAA as the plaintiff is responsible for proving all of the facts they assert. As long as we try to combat that with our own assertions, they can simply try to poke holes in those. It seems much more difficult to prove that youtube-dl's usage is legitimate than it is to poke holes in one of the assumptions underlying the RIAA's lawsuit. If this is legitimate use, youtube-dl wins. If this is not circumvention, but an alternate access mechanism, youtube-dl wins. If you can prove that rolling ciphers are not an effective control measure, youtube-dl wins. I think the most likely of those options is demonstrating that youtube-dl is fair use (I wonder if there are any accessibility reasons to use youtube-dl; that would hamstring the RIAA, as they'd be caught between the ADA and the DMCA. They either have a valid DMCA complaint but YouTube is liable under DMCA, or they don't have a valid complaint because youtube-dl is required to meet ADA specifications). I don't even have to think very hard to come up with a few non-infringing reasons why someone would use youtube-dl. The RIAA then has to prove that youtube-dl is "primarily designed ... for the purpose of circumventing a technological measure", rather than for the variety of non-infringing reasons one might use youtube-dl.
2017: https://tyrrrz.me/blog/reverse-engineering-youtube
2015: https://github.com/bitnol/CipherAPI
2014: https://gist.github.com/kl/9070523
2014: https://api.w3hills.com/ytcipher
Regarding the "bookmark" comment, there is no way to "bookmark" any YT download URL because all YT download URLs (not just ones that have a changing signature) include timestamps; as is typical of download URLs on video sites, they have an expiration. Generating URLs that expire is not done as a means of copyright-related "access control"; the purpose has to do with caching.
RIAA depends on it being debateble. Debatable means you get to spend hundreds of thousands of dollars arguing over it in court. Sine the RIAA’s members business model depends on it, they are willing to spend whatever it takes. No one else is.
In a free market it is important that when you are displeased with a supplier that you truthfully tell that supplier why you are displeased (ideally very vocally) and are actively considering alternatives. It is one of the few early-warning signals that might change their behaviour.
But ideally, just stop giving them money immediately and tell them, but mention that you are willing to change your mind if they change their behaviour. And if they vascillate too often between what is right and what is profitable, inform the entire system even if it is a great personal expense. As long as it benefits the system, you will come out okay in the end.
May I introduce you to GitTorrent?
Also relevant if you go the p2p route:
Rather than getting mad at companies for complying with the law of the country they operate in, why not support organizations like EFF that are actively working to change the DMCA?
> Following our initial coverage, we learned that the pressure against YouTube-DL had already started weeks earlier in Germany. Law firm Rasch, which works with several major music industry players, sent out cease and desist orders in the hope of taking YouTube-DL offline.
> Hosting service Uberspace was one of the recipients. The company hosts the official YouTube-DL site and still does so today. Instead of taking the website down, Uberspace replied to the notice through its own lawyer, who said that the hosting company hasn’t don’t anything wrong. [emphasis added]
> When the cease and desist notice was filed, yt-dl.org wasn’t even hosting the tool, as all download links pointed to GitHub, the company informs us.
[But the site does host the tool now, and Uberspace still doesn’t appear to have taken it down]
> “The software itself wasn’t hosted on our systems anyway so [but IIUC it is now], to be honest, I felt it to be quite ridiculous to involve us in this issue anyway – a lawyer specializing in IT laws should know better,” Jonas from Uberspace says.
However German laws are essentially: "Once you are notified of copyright infringing/illegal content, you have to remove it, lest you lose your protection as a service provider and become responsible for the content."
A DMCA takedown notice would be such a notification.
On the upside you don't need to do anything if you don't have reason to believe the content is illegal in any way (unlike with DMCAs where you pretty much always have to remove first).
On the downside it's a bit easier to get into trouble as a provider if you chose to let something stay online.
The DMCA works the same way. If you refuse to remove content and it turns out to be legal, then you as a service provider can't be held liable. You only get in trouble if you ignore a valid notice and there is infringement.
Neither is relevant here, though, as it wasn't a DMCA notice but a claim of anti-circumvention.
Youtube-dl itself isn't copyright infringement though. It's a tool that could theoretically be used for copyright infringement.
I don't think it'd be ironic, but it's also not true. It's obviously not a free speech issue, and Germany has laws regarding copyright and circumvention of constraints. I doubt a large company would have taken the same route, uberspace is just generally pretty cool and user friendly.
For instance, it's against the law to insult a government official like a cop (Beamtenbeleidigung). This could mean saying something like "damn cops" in earshot of the police - it doesn't take much.
You could argue that courts aren't as accessible in the US as they should be without deep pockets (rightfully so), but fundamentally free speech _is_ much better protected in the US.
In Austria and Germany insulting a government official is handled by the same law as insulting a normal citizen is (except for that also the superior can file charges for subordinates).
Speaking of Austria, blasphemy laws still apply there and were upheld by an EU court when challenged two years ago [1].
[1] https://humanism.org.uk/2018/10/29/european-court-of-human-r...
This is a bit personal, but my brothers and I grew up in Germany with a father who was verbally and emotionally abusive. However, he didn’t break any laws regarding offensive speech at least.
Ironically legislating against offensive speech protects people from superficial harm of “offense”, causes a chilling effect by curtailing “offensive” speech (what can you say about a corrupt cop in Germany or France without breaking the law?), and does little to prevent actually emotionally abusive speech.
Obviously my views are biased by my own experience, but I think the US is two _centuries_ ahead of the curve here while Europe still struggles with the ghosts of former monarchs.
[0] https://nos.nl/artikel/2038180-fuck-de-koning-roeper-niet-la...
But that's plainly a curtailment of speech. A rose by any other name, etc., etc. Perhaps the restriction is just in your view, but it is what it is.
Are you saying that it's ok/good for people with less money to have worse access to courts than people with more money? If so, why?
https://archive.org/details/SchmhkritikAnRecepTayyipErdoanzd...
Here's a transcript: https://translate.google.com/translate?sl=auto&tl=en&u=https...
Imagine doing such a poem about Trump in the US. I believe the author would be punished much more harshly than this guy, who even managed to keep his job...
it's hard to imagine any legal action taken against someone who wrote an insulting poem about trump though. people say stuff like "I hope he dies" on social media every day.
"His dick stinks badly like kebab, even a pig's fart smells nicer. He is the man who beats girls while wearing rubber masks. Most of all he likes to fuck goats and oppress minorities."
But like Wikipedia says, Böhmerman retained his job. In my opinion, that's the difference. A higher level of tolerance for speech that most people disagree with.
https://www.dw.com/en/germany-revokes-lese-majeste-law/a-390...
Famously, games in the Wolfenstein series are pretty heavily censored in Germany:
https://kotaku.com/wolfenstein-2-has-a-strange-workaround-fo...
The problem is that the project may not survive this.
Major distributions for example will no longer carry the project and likely refuse to touch it even with a ten-foot pole (think media codecs situation). It will be relegated to 3rd party repos. They will lose users, they will lose contributors. And how long until YT's (and/or the other supported websites) HTML changes more rapidly until the remaining manpower can't keep up?
I would no longer expect FDroid now to keep doing this if they risk a DCMA letter that takes out their entire repo.
And I would assume a shitton of users use yt-dl code through another GUI application, rather than directly through an EasyInstall/virtualenv/whatever. And will most py repos still dare to host/link this code if the risk is a DMCA letter to their ISP?
I really doubt the "it's just the test cases" justification btw, since test cases would likely be fair use. The deencryption stuff is the problem, and NewPipe does it too.
Distribution/integration is the easy part. The hard part is to anonymise and secure core developers, and to allow contributions to continue flowing in a safe manner.
A tarball of _ancient_ DeCSS code has some value because you can use it to "decss" _all_ content made _before_ a certain date (e.g. most physical DVDs). So it makes sense to preserve the tarball in any method possible.
A tarball of an _ancient_ youtube-dl version is absolutely useless because the youtube HTML will have changed a million times in the meanwhile. You will not be able to use it for anything, neither for old nor for new content. Publishing/preserving youtube-dl tarballs is an absolute waste of effort.
The RIAA here is targeting existing project developers, and possibly also users. Trying to scare them away. Not trying to censorship old tarballs of the code which will quickly become useless.
i.e. replace YT with $YOUR_FAVORITE_VIDEO_HOSTING_WEBSITE in the message above.
Or a misunderstanding of the word "anything". (-:
Whereas it is a reach, ironically, for you to assume that all WWW sites are like YouTube, especially given the discussion of "extractors" that I pointed to, and even are moving targets.
As I said before, this premise, that you have assumed like AshamedCaptain, is highly erroneous. I suspect that neither of you have actually looked to see what WWW sites out of the hundreds that youtube-dl works with actually do have changing HTML, and how many of the "extractors" are still happily working years after they were written. (Sadly, the open issues list on GitHub, which would have helped to determine this, is gone, GitHub being a single point of failure.)
This is just entirely erroneous assumption and hyperbole, that everything is like YouTube, that things will change "a million times", and that magically all of those hundreds of WWW sites will stop working and "you will not be able to use it for anything".
"You will not be able to use it for anything because YouTube and every other video sharing website supported by youtube-dl will have changed a million times.
Acknowledge the point and move on.
But it's not a tarball of an ancient version of youtube-dl. It's a tarball of a version of youtube-dl from like two days ago. So then it gets posted to some other host or some distributed thing and development continues over there, only with twice as much support because of all the media coverage.
The codebase was not the useful thing about this project: it was the constant upkeep and whack-a-mole-ing of the various site changes over the 1000+ supported sites.
This event may spark renewed interest and help, but my money is on "slow death" as support for sites and videos decays.
I started downloading from youtube because of this. I haven't come across RIAA protected content but who knows what the future holds
I have never been able to get youtube-dl to work with (both ubuntu / mint) distro packages. The packages always fall out of date due to youtube changing things, and you need to download it directly from the youtube-dl website regardless.
I don’t think pip is even installed by default under most distributions, and Iirc some actively discourage its use. It’s also Supply chain insecure when compared to trusted repos.
But congratulations on catching the technicality!
You had to install the Github version anyway if you wanted to have a recent version that would work with YT.
And even then, where are users going to search the most recent version? You will definitely not preserve the same number of users if you switch from yt-dl being "one apt-get away/one FDroid install away/one pip install away" to "one bittorrent search/wget from shady .ru website". And let's not talk about how will people contribute. The project could be as good as dead.
I kind of hope they adopt flatpak or appimage based disto for it, giving it a more standard distribution mechanism and promoting one of those platforms.
Either way, this sort of advertisement is hard to beat. I'd expect the project to come out of this with more manpower, not less.
I thought all they need to do is to issue a counter-notice. Popcorn did this and got their code reinstated on github: https://news.ycombinator.com/item?id=24885079
In the worst case, they need to adjust their tests. This is what the issuer of the complaint brought up. Their tests of the code downloaded a couple of seconds of what the RIAA thought is copyrighted material. If I'm not mistaken, this is what they are basing their case on.
If youtube-dl removes those explicit urls from their test cases, I don't think they have a case. You could argue fair use, but remember it's only a test case in that program. The authors could just as easily reprogram the test cases to accept any url a user wants to test.
Anyways, consult lawyers, perhaps change the test code and issue a counter notice and move on.
If it's not a dmca takedown and those rules don't apply then I would assume github would need to explain why they filed it as such. (It's probably the RIAAs "fault", but "we" have only direct contact with github so we need to go through them)
[0] https://github.com/github/dmca/blob/master/2020/10/2020-10-2...
Bandwidth and distribution are no longer the limitations on independent hosting they once were. Independent discovery methods (e.g., DDG video search), are improving. Noncommercial orientation makes youtube-dl and similar mechanisms a net positive --- simplify the web-based delivery, increase viewer flexibility, provide greater tolerance for network or system variability.
My own interest in YouTube has very little to do with commercial mass media, and far less to do with ad-seeking chum-spewing bottom-feeders.
More options are more options, surprisingly enough.
I hate to burst your bubble but that's not even close to be a realistic possibility. Wish it was but it's just not.
That way only the fork get periodically DMCA'd, which will be way easier to recover from : just create another fork with the tests
Do the digital equivalent of the way rich people use holding companies and shell companies. Put all the high risk stuff into the smallest independent repo possible and abandon it at the first sign of trouble. Use an MIT license so anyone can fork it and continue development if you have to abandon it.
It probably wouldn't even take a ton of money to set up a matching corporate structure so you could control everything. Put all the risk into a subsidiary that doesn't make any money (or makes very little). Drag out DMCA complaints until they sue you and then bankrupt the asset-less company. Rinse and repeat.
If you want to get super ballsy, sell the plugins that infringe, but siphon all the money out of the subsidiary with trademark licensing. That way you can license the same trademark to the next company to maintain the brand. Bonus points if you put the holding company in a tax haven.
IANAL. That's probably a really bad idea. Don't do it.
The source code for ForgeFed[6][7] might be also of interest for improvement.
[1] https://github.com/go-gitea/gitea/issues/1612
[2] https://github.com/go-gitea/gitea/issues/9045
[3] https://gitlab.com/gitlab-org/gitlab/-/issues/6468
[4] https://gitlab.com/gitlab-org/gitlab/-/issues/33665
[5] https://opencollective.com/gitea
I do like Tom Scott's comprehensive video on the subject https://www.youtube.com/watch?v=1Jwo5qc78QU
We petitioned for an exemption to allow museums and libraries to reboot old MMOs in closed rooms with no network connections. That's because we couldn't get anything more from the Copyright office. Still, the RIAA's lawyer was there to lie and not understand a god damn thing we said, and accuse us of making tools that could be used to pirate any MMO.
I begged for them to tell me where to find such tools, as it would make life so much easier. Their lawyers were complete imbeciles who seemed never to have touched a computer, yet here they were telling a group of game programmers what they could and could not do with their programs.
Fucking horrible people, all of them.
The RIAA generally doesn't have any involvement in video games, other than where its members license music to games (i.e., GTA), and they generally wouldn't have any grounds for being part of the proceedings you've described if their involvement was just the music licensing.
I can see the ESA being a huge dick in these proceedings, because it's their job to do that, but the RIAA literally wouldn't care as long as somebody paid the music licensing fee (for that low volume of users the licensing fee would generally be less than $100 annually, all inclusive).
I've been on the other side of an RIAA negotiation, and they were very easy to work with. We theoretically owed them millions of dollars for several years of unlicensed music streaming, and they waived the statutory penalties they were legally entitled to in exchange for us agreeing to pay a few hundred dollars of royalties a year to stream their members' music. All told, we paid less than $2500/year for streaming licenses for all of the Big 3 labels and a dozen or more smaller labels.
Appears the same lawyer was representing ESA/RIAA/MPAA.
I briefly started reading some of them a while back and they're, uh, frustrating to read.
218 Congresspeople
60 Senators
1 President
5 Supreme Court (in)justices.
A conservative estimate is that getting the DMCA reformed would cost at least a billion dollars in bribes ('campaign contributions'). No one who has that much money spare has enough of an interest in public-interest copyright reform to be willing to spend that much money.
As a practical matter, it's much more feasible to cultivate hosting infrastructure outside of the United States than to consider DMCA reform.
As they're written into international treaties every functional Western democracy has them.
Pretty much the only exemption is Israel.
You can look up how much the RIAA and MPAA spent on campaign contributions. It wasn't a billion dollars.
And "campaign contributions" are only one path to victory. You could also go the route of getting Wikipedia et al to do what they did for SOPA.
Sure you can download this and download music videos, but there's legal cases such as downloading a political campaign ad, and using small parts of it to fact check them them under fair use. Our local news station in fact did something like that. Also there is a rep not far from here, where she was doing vlog style videos for her campaign and the guy running against her downloaded her videos and put them in his own ad.
Using it to backup your own content or public domain content is another use case too. However if it's your own account I believe YouTube let's you download a mp4 of it from the creators studio but been a while since I've played with it since the redesign.
In a few years it'll be normal for new developers to view a software project and a GitHub project as the same thing because the entire process from creating the project to publishing it (on Azure most likely) will happen via GitHub.
Saying that no one is dependent on GitHub is like saying a mechanic isn't dependent on their tools. Moving away from GitHub is like a mechanic walking out of the garage with a single crescent wrench (the git repo). Then you find out no one else sells any of the tools you know how to use and that the only option is to rent them from someone else (Atlassian or GitLab).
Random "good thing" addition: If CI and other features create more of a github lock-in, maybe they could implement cross-git features (like pull requests from gitlab) without that being a disruptive feature that reduces their monopoly situation.
Which is frustrating. Isn't the information needed to do this provided by youtube themselves? This isn't some private key that wasn't supposed to be public; it's literally given out every time you view a video using it.
Also, the "examples" were tests that used a given algorithm, as there may be different methods used on different videos.
But in case they do something that stupid, there will be forks. I will probably even make one fork myself with removed code reinstated.
EDIT: what the downvotes are for? Do you really want youtube-dl to appease Microsoft, RIAA or something?
...which many entities would love to do. If it were illegal to extract data any way but through an official API, with a TOS and fees and everything, that would make a bunch of dying business models so much more viable.
> A federal appeals court last week issued a “hugely important” decision with potentially major implications for data journalists when it held that using computer programs to collect publicly available information from the internet — or “scraping” — likely does not violate the Computer Fraud and Abuse Act, the main federal computer crime statute.
Links are in the quoted text.
I thought I'll make a post to explain this easy method, then realized Google would take down that method within a week, so I'm keeping quiet.
You really can't.
>> I've found a way to download videos right from the domain googlevideo.com
I assure you, you really didn't.
Here's a really simple site that can do it: https://en.savefrom.net/1-youtube-video-downloader-4/ There are tens of others.
I'm not gaining anything from your assurance. I've found the best way - A first party method. No shady downloaders, extensions. I'm going to keep using it.
Just remove the range parameter in the URL.
https://freedom.press/news/riaa-github-youtube-dl-journalist...
Just an anecdotal story about how software that offends lawyers can become acceptable by making certain changes. I hope the suggested changes to YT-dl will allow it to pass lawyer's smell test.
Years ago I noticed all the Recent records on Chilling Effects (now Lumen) were originated from German. I dug a little deeper and found out one of the firms were generating thousands of records per day and some of the claims were simply mistakes because they used simple string matching algorithms to automatically report massive amount of google search results.
After some email exchanges, their CEO admitted to me that they only generate 5% wrongful claims and somehow he's proud of it...
Think Truecrypt.
EDIT: this is a genuine question, I thought it had been unmaintained for ages and vulnerabilities had been found. My memory betrays me?
Has this been substantiated?
audit: http://istruecryptauditedyet.com/
final audit summary: https://blog.cryptographyengineering.com/2015/04/02/truecryp...
Or do you have a competing tool? Let me guess. Someone will ask for an alternative and another will suggest..
This doesn't mean it has a "fundamental flaw that means everything it encrypted is trivial to unlock today."
There has been no evidence to suggest that is true. An NCC Group audit found no significant flaws: https://opencryptoaudit.org/reports/TrueCrypt_Phase_II_NCC_O...
If you are unsure of a fact, you can always do some quick research using your web browser before posting incorrect information in a way that may be misunderstood.
However, at the time it was theorized that in the event the maintainers had found a fundamental flaw, disclosing that flaw by issuing a patch would immediately jeopardize all preexisting truecrypt containers by revealing a method for breaking them. That would be untenable, and so the only alternative would be to shut down the entire project and recommend no further use of the software - as was done.
A subsequent audit did not identify any such security flaw, so the prevailing theory is now that the maintainers were forced to stop work by a governmental agency. It's considered safe and now known as veracrypt.
However, the question I have is whether a single crowdsourced security audit would be capable of finding a flaw that it took the developers themselves years (decades?) to identify.
> Using TrueCrypt is not secure as it may contain unfixed security issues.
Not Secure As. Whether this holds any weight, only the maintainers would know.
More info: https://grahamcluley.com/truecrypt-hidden-message/
https://en.wikipedia.org/wiki/Paul_Le_Roux
> In 2019, Evan Ratliff—who wrote a series of articles about Le Roux for The Atavist Magazine—published The Mastermind, a 446-page account of Le Roux's ventures.
https://www.penguinrandomhouse.com/books/549566/the-mastermi...
If record labels want to stop users from downloading their content, that's more than fine. It's a giant attack vector for such a small net benefit.
To support legal use-cases such as archival?
That is the case pretty much anywhere.
Is there? Just because someone claims (without court determining it) that some content is illegal doesn't make it so. So there would have to be some language in the law that the intermediary incurs liability due to mere allegations.
Not only that, the argument here is supposed to be that youtube-dl is "primarily designed or produced for the purpose of circumventing a technological measure" etc.
If you can remove <1% of the code and somehow cause it to not be that anymore and yet still be something which is useful for the majority of what people do with it, doesn't that just mean it was never that to begin with?
What this whole episode should do is make it more common place to use tools like git-bug and mirror repos. Maybe someone will even write a tool to do so easily. But what I see happening is people just wanting the status quo to stay.
Until we learn to decentralize our code and write the tools to do so, this will keep happening. Maybe in 10 years we'll have learned our lesson, but it seems we're just doomed to repeat our mistakes.
It's mostly because I remember filesystems from my university time and trying to implement one in a file myself. Continuously adding data is fine, but when you remove data either you leave a "hole" in the file and have to keep track of the "empty" blocks, or you shift everything to fill the hole. Off-by-one errors corrupt files.
Those are all resolved problems for filesystems, but additionally, I learned the hard way (performance) that SQLite wasn't good as a production db. The situation here is different of course (db access isn't very frequent), but I can't quite shake it.
Maybe I'll dig into the internals to understand what kind of optimisations they made. The wiki and bug-tracking are definitely a plus though.
> RIAA Efforts Backfire
Basically every story written about RIAA since the Clinton administration :-)
Its long been known that the way to defeat piracy is to offer a better service. Its what Steam did, its what Netflix did.
Ironically, the fragmentation of those ecosystems is bringing it back. Piracy is the ultimate invisible hand on the entertainment distribution industry.
For example, Justin Beiber, Lorde, Billie Eilish, Lil Nas X, were all discovered independently due to their own efforts and had decent success on their own. (Farther back in time, the Beatles and most classic rock bands similarly got signed to labels after demonstrating success.)
But they're all signed to major labels now, because touring is expensive, and the scale of exposure you get with a label is very different from what you get on your own, and the income correspondingly increases as well.
In many (but not all) cases, the artists usually also get lump-sum advances against new albums or singles which removes the financial risks for creating new music.
Piracy was never about discovery. It was simply about people being too cheap to pay for other people's work. Sometimes, as with Adobe and Microsoft, they were okay with it because that just locked in their market dominance and created more future customers. But for fad-driven and taste-driven industries, privacy has a notable impact on creator's earnings.
Do you have any data that doesn't make the ridiculous and false assertion that 1 download = 1 lost sale, with which to back that claim?
Because from what I've read, piracy has the opposite effect.
But it's well-documented that piracy negatively affects music, film, and game studio income. See, e.g., https://www.ipi.org/ipi_issues/detail/the-true-cost-of-sound...
Piracy may the opposite effect for software but it definitely has a negative effect on entertainment related IP.
High school events where I grew up were basically an iMac with the student body officers' MP3 collections and a PA system. All the pirated MP3s people were playing at those various official and unofficial gatherings of my youth led to me buying CDs once I had money of my own.
Has a non-industry-affiliated research group produced causal data (not just declining sales figures) showing that noncommercial entertainment piracy is a net harm?
IPI is an associate member of the State Policy Network (SPN), a network of right-wing "think tanks" and other non profits spanning 49 states, D.C., and Puerto Rico.[2]
The conservative Capital Research Center ranked IPI as amongst the most conservative groups in the US, scoring it as an "eight" on a scale of one to eight.[3] IPI has received funding from corporations like Exxon Mobil and organizations like the Kochs' Claude R. Lambe Foundation, Scaife Foundations, the Bradley Foundation and others....
https://www.sourcewatch.org/index.php?title=Institute_for_Po...
https://www.engadget.com/2017-09-22-eu-suppressed-study-pira...
https://gizmodo.com/the-eu-suppressed-a-300-page-study-that-...
From what I can tell, most of the studies establishing a clear economic cost to piracy tend to rely on numbers originating from the music industry without clear attribution to data, or by naïve analyses estimating that 1 download = X lost sales, without considering effects like budgetary limits (I'll spend at most $X on entertainment this year) or conversions to profitable sales.
Additionally, there's a lot fewer studies on piracy post-revenue nadir. It seems as if the rise of streaming has caused the industry to stop panicking so much about piracy, and there's some evidence that streaming has converted consumers to paying customers.
All-in-all, I would say that it's not so much that piracy hurt the industry as piracy filled the existence of a market segment that the industry refused to fill. Piracy only hurt the industry in the same way digital cameras hurt Kodak: the existing business model was unsustainable, but they refused to pivot to take advantage of the clear coming shift in the business model.
The traditional business model of a record label is almost entirely obsolete, and they need new revenue streams. That said, the people who run these businesses are antithetical to innovation and creativity in business and that's why industry groups like the RIAA exist in the first place.
How would streaming become the only game in town? Piracy and any other online mischief are being stamped out the hard way, by taking control of our technology from us. Approved operating system, approved drivers, approved software, approved browser, approved websites, no piracy, no privacy, no deviance.
Not sure that they interpret the Streisand Effect in the conventional way. If anything, temporary increase in usage of targeted tools helps them make the case that they're being harmed by said tools' existence.
Ironically, by using youtube-dl en masse to "stick it to the RIAA" they may have inadvertently dug its grave instead.
Reminds me of What color are your bits: https://ansuz.sooke.bc.ca/entry/23.
Nobody at the RIAA cares you are angry about their moves, in fact they are likely glad that you are, and not the actual responsible parties.
In this case, I would not be surprised if Google was ultimately driving the push to get rid of youtube-dl using the RIAA as a proxy, both for PR purposes and because the RIAA has a semi-plausible claim to legal standing.
Youtube has ramped up its consumer abuse policies lately, such as the begging screen that demands unauthenticated users log in and requires four clicks to dismiss, and it would not be even remotely surprising if Google is also working to get rid of tools that allow people to watch YouTube videos without being subjected to advertising abuse.
Yesterday, I moved about 250 repos away to a gitea instance. Transition required a bit of tinkering (a few scripts) but went smoothly.
The good sides are:
- very fast, a lot faster than github for pushing/pulling but also the web UI is a lot faster
- I'm in total control, I can change the look of the UI, create as many orgs as I want to organize my repos…
Now the cons:
- No social network effect, I don't know how contributions to my projects will evolve
- Subject to DDoS and the like, I need to keep my instance accessible because I moved my FOSS projects on it
Maybe more, it's been one day only.
I am not suggesting all project should move out of github, it is a very good tool, but I think it wouldn't be bad to rely less on it.
From a strictly code based POV, it is intended to download protected objects with tests to ensure that protections are circumvented and the correct material can be retrieved. At the same time, removal of this code probably disables downloading of the majority of YouTube, and on top of that if there is no official collaboration on it, it'll be outdated within days.
Youtube stores cache files to a user's computer, obfuscated so they can't be easily copied or accessed, most likely as part of the terms of their license. That is legally sufficient to constitute a copyright protection scheme.
Instead of taking it down in the first place, Friedman should have told the RIAA to shove it, deliberately opening Github up to liability with the intent to defend this in courts and create precedent should the RIAA file suit. Even losing - and losing a few million in legal fees and damages in the process - and losing is far from certain - would create precedent that would create a lot more certainty of what goes and does not go with the current law, and give activists and lobbyists concrete jurisprudence to point to when approaching law makers and Library of Congress for changes.
Now that would have been real support. A somewhat risky move indeed, but also a necessary move if Friedman really thinks youtube-dl is an important piece of technology (with important policy implications).
Instead, he essentially left the developers, which lack the deep pockets of Github/Microsoft, to fight on their own, going even so far to suggest to budge to the RIAA's claims that youtube-dl contains a "circumvention" technology without challenge and remove the offending bits.
But at least he publicly stated he is "annoyed" by the RIAA. Talk is cheap. This is like showing up and telling David that "well, tough shit, Goliath is annoying but a lot bigger than you and will win, so you better capitulate, and I can help with that!".
(Yes, Microsoft being a RIAA member complicates things; Microsoft should in my humble opinion leave the RIAA; being a member of RIAA isn't compatible with their "we're the good guys now" image they are trying to foster regardless of the youtube-dl fiasco)
Friedman would certainly be removed by Microsoft if he jeopardized GitHub's legal protections by defying the mandated process, to say nothing of the potential of creating personal legal liability, both criminal and civil.
youtube-dl remains freely available off-GitHub (not to mention on the local disk of anyone who ran `git clone`). I just used it 10 minutes ago. There is no public good served by defying the law here, and there is no reason to put the whole kit and kaboodle on the line over it.
tl;dr, ignoring the DMCA process isn't just a "somewhat risky move". If we're going to break out the pitchforks, let's at least point them in the right direction: write your Congresscritters and tell them you want to see copyright law reform.
Correct, that's why I said they should deliberately open themselves to liability, and the fight this in court.
Moreover, technically they already have, anyway. The anti-circumvention law (17 § 1201) does not even offer safe harbor protections; these are meant for copyright infringement only (17 § 512).
>Friedman would certainly be removed by Microsoft if he jeopardized GitHub's legal protections by defying the mandated process, to say nothing of the potential of creating personal legal liability, both criminal and civil.
Certainly? There is a risk of that happening, sure. But that is counter to the risk that MS faces from backlash within tech over a decision to fire him for taking on the RIAA.
But yeah, I know, Github and Microsoft standing up here is wishful thinking. One may dream :D
>youtube-dl remains freely available off-GitHub (not to mention on the local disk of anyone who ran `git clone`). I just used it 10 minutes ago. There is no public good served by defying the law here, and there is no reason to put the whole kit and kaboodle on the line over it.
It is less accessible. And the RIAA will not stop coming for them. Getting them thrown out of search results by sending the same legal bullshitery to google, bing, duckduckgo etc. Going after the hosters of the website (like they apparently already tried)
Moreover, they "lost" a large chunk of the community they had on github, incl issues and discussions etc (maybe Friedman at least has the stones to let them have their data?). People will also now think twice before getting involved in the project.
>tl;dr, ignoring the DMCA process isn't just a "somewhat risky move".
That's exactly what it is. The RIAA would have to respond by suing them (or stopping their campaign). Github isn't automatically liable, they just lost protection from liability, but can still win in courts.
https://joindiaspora.com/posts/808cf690f8e801381778002590d8e...
At the bottom of the image; after being asked what needs to be done, he says: "Just the rolling cipher circumvention code and the examples of how to get the copyrighted material" (emphasis mine).
He's essentially echoing the main talking point that YTDL isn't a scraping tool that acts as a User-Agent (which is legal), but an illegal tool that "circumvents technological measures" because it "decrypts" and runs some JS code just like any browser would.
It's what we call being "yeah, yeah yeah'd" -- I don't expect much from GitHubHQ at this point other than trying to save face and maintain their position as the "developers friend".
Reminds me Free Speech Flag story: https://en.wikipedia.org/wiki/Free_Speech_Flag
All this highlights what an unconstitutional monstrosity DMCA 1201 is. You reap what you sow RIAA. Hopefully this will trigger the push to repeal this trash altogether.
Sure in this instance GitHub CEO is helping. However GitHub could kick you or the repo out any second.
We ought to build a more resilient internet.
It OBVIOUSLY reasonable to have three private corporations owning the majority of modern musical output... and they even have a little club where they discuss pricing! How quaint...
The outrageous thing is why the fuck we as a society defend these corporations, when they have a literal monopoly on what they’re selling, and the monopoly is guaranteed by the government of every western country
Media offers money, exposure, glamour and/or star power, spectacle, distraction, attention, and manipulation, all of interest to politicians.
Much of recent copyright law, and the DMCA specifically, was largely driven by Democrats.
Then never include a test case with music videos. I was using it to download public domain videos, if certain video producers want specific drm then that's fine.
The far bigger part of the job would be rewriting all 800 custom extractors, then perpetually maintaining them against constant, silent, often adversarial breaking changes in each one.
Using Rust instead of Python would cut the very fat long tail of contributions that makes most of this viable, and would doom this project more than most.
My point was someone needs to basically rebuild the tool as a completely seperate repo. Breaking DRM is a really bad idea
That's a funny way to spell "a moral imperative."