It may not be surprising or even "evil", but at best it is excessively cautious for a company who profess to serve the open source community and want/need the goodwill thereof. Clearly this is the corporate owner (Microsoft) behind Github showing its hand.
Time to move to other platforms.
You should check out the history of the DCMA repo.
Yes, which means it's straight up a crime to use or distribute youtube-dl, and GitHub does not want to be criminally liable.
GitLab and similar sites will follow suit -- or face federal charges.
There is nothing in the law that talks about the effectiveness of the anti-circumvention tech, so even if the tech is trivial to bypass, if that bypass is done via "unintended usage" (according to the rights holder, not you) then they can claim you are doing something illegal.
It's a shitty law.
YouTube obfuscates the URL of the video stream for videos which have been identified as containing copyrighted material and are licensed for streaming only through the YouTube Web player or app. The copyright owner has made the material available under a license which permits ONLY that.
Youtube-dl contains code to decrypt the URL of the video stream in order to download and save the copyrighted material, in violation of the license.
Now let's look at some definitions from the DMCA:
(A) to “circumvent protection afforded by a technological measure” means avoiding, bypassing, removing, deactivating, or otherwise impairing a technological measure; and (B) a technological measure “effectively protects a right of a copyright owner under this title” if the measure, in the ordinary course of its operation, prevents, restricts, or otherwise limits the exercise of a right of a copyright owner under this title.
We have to ask ourselves two questions. First, is the URL obfuscation scheme a "technological measure" that “effectively protects a right of a copyright owner under this title”? Yes, it is. In the normal course of its operation, it prevents the user from accessing the work except to stream it through YouTube's Web player or its app. The bar set by the law for "effective" protection is very low. If your "DRM" is a simple XOR cipher whose key is "hello world", then it "effectively protects a right of the copyright owner under this title", provided that it does its job of restricting access to anyone who doesn't know the key.
Secondly, does youtube-dl circumvent protection afforded by the technological measure? Yes, it does. The technological measure enforces certain policies by means of its decryption algorithm; youtube-dl reimplements the algorithm, but does not enforce the policies, allowing people to get around restrictions demanded by rightsholders like the RIAA and implemented by Google. Does youtube-dl have limited use other than to circumvent protections afforded by the technical measure? Yes, it does. If the URLs were not obfuscated, a simple HTTP client might suffice to download the video data. The primary use of youtube-dl is to get around the measures Google had put in place to restrict access to YouTube content (the same for other video sites).
Therefore... youtube-dl is a circumvention device prohibited under the DMCA, and is therefore ILLEGAL. Distributing it is a felony under federal law, punishable by up to five years in prison.
Go ahead. Ask any copyright lawyer. I'm sure they'll tell you the same.
YouTube-dl has a lot of use cases, among which are the downloading of potentially copyrighted works, in a way which seems similar in my mind to the way a VCR has a lot of use cases including, possibly, the recording of TV shows in violation of a license.
Why are VCRs permissible to distribute but not this software?
1) Because the Supreme Court -- in a narrow 5-4 decision -- ruled them so in the "Betamax case" after the MPAA tried -- and up to that point succeeded -- to have them banned as tools of copyright infringement. The MPAA was sore about this for decades afterward, maintaining that the SCOTUS was simply wrong as a matter of law. My girlfriend's stepfather was a high-powered attorney for the MPAA, and he banned the use of VCRs in the house because to use them to record off the TV was, in his view, unquestionably copyright infringement, SCOTUS ruling or no SCOTUS ruling. And he was one of the foremost experts in the country on this area of the law.
2) The Court, in its Betamax decision, said that "[T]he sale of copying equipment, like the sale of other articles of commerce, does not constitute contributory infringement if the product is widely used for legitimate, unobjectionable purposes. Indeed, it need merely be capable of substantial noninfringing uses." However, the DMCA explicitly closes that loophole. Any tool or device whose primary purpose is to circumvent copyright protection is illegal to use or distribute -- save for certain carve-out exceptions including security research, interoperability research, and law enforcement use -- irrespective of whether it has "substantial noninfringing uses" as would, for example, a tool to strip out Denuvo protection from your legitimately purchased copy of Doom Eternal so you can play the game without Denuvo pegging your CPU. The fact that DRM is an irritant that owners of legitimate copies may wish to be removed is immaterial; providing the means to remove it is still a crime.
In a nutshell: When Betamax and VHS VCRs came out, tv shows generally aired once, did not repeat, and were not available for purchase on an individual basis. Recording the show to watch later (aka, "time shifting") was the only means some people had to watch an episode.
And importantly: because the episode was not otherwise available (i.e., it wasn't sold or rebroadcast) there was no financial harm to the content owner for copies being made.
DVRs like Tivo relied on this logic as well. And it worked, until the studios caught on and began making film and TV content available for purchase on an individual basis, and offering the content for transitory consumption (aka streaming). By doing so, they eliminated the "time-shifting" rationale of the Betamax case (by offering downloadable copies, albeit at a higher fee, they've also addressed the "connectivity shifting" rationale techies keep bringing up). And indeed, that is why Tivo and other companies stopped selling standalone DVRs in the U.S. and Europe a few years ago. (All of the DVRs you can find today in the U.S. are offered by cable companies or the subscription service providers (Hulu, Youtube TV, etc.) pursuant to streaming and time-shifted viewing licenses they have with the studios.)
Thus, even if the Betamax case was still binding precedent (it hasn't been since the DMCA), it wouldn't apply today.
You can't host something publicly, available via common, general purpose technology and then claim protection when someone uses this general purpose technology to obtain it.
The RIAA would have more of a case if they hosted this on their own site and made it accessible only through their own special purpose tooling. It would still be stupid, but then they could at least claim a RIAA Player(tm) is required to access the content.
I'm not saying this is wrong, but how do you know?
That is, do you claim to have a grounded understanding of the law? (Perhaps as a lawyer, or a layperson who's studied this in some depth.) Or are you simply saying that in your opinion the law should consider youtube-dl's decryption acceptable by this reasoning? Or something else?
(I'm not even asking for citations here, if it's the first thing.)
I'm also interested, though: can you imagine a phrasing or argument that would invalidate the sentence you quoted? How would the restriction be framed? Would it mention a list of concrete programs which you can to access the website? Can RIAA for instance, in your opinion, mandate that a website can only be accessed through Chrome?
But the sorts of things I could imagine going wrong with your argument might be...
* Yes, browsers are in violation of the thing bitwize quoted, but it doesn't apply to them for reasons written elsewhere.
* Yes, browsers are actually in violation of DMCA. People probably noticed this when the law was being written, but no one listened to them. If anyone tried to enforce DMCA against browsers, DMCA would get overturned, so no one's going to try. (I think this is unlikely - if there was an argument that browsers violate DMCA, I think I'd probably have heard of it. Probably. But including for completeness.)
* Browsers need Javascript engines for many many reasons. Youtube-dl (afaik) needs a javascript engine specifically to get around this obfuscation. That could be relevant somehow. (Similar reasoning might say that locksmiths are allowed to own lockpicks and no one else is. I believe the law has roundly rejected that. But that doesn't mean the law would reject this, too.)
Again, not claiming any of these actually apply. Just, this sort of thing is why I'm hesitant to make inferences that seem otherwise sensible.
To answer very shortly: to my knowledge, there are no such exemptions for browsers specifically. Point 2 would actually work against DMCA, as you observed. I think point 3 is defeated by the fact that there are websites which require JS support to initiate video reproduction but which do not use it as an obfuscation technique.
Instead, RIAA is counting on this matter not to reach the courts and everyone submitting to their will out of fear, which ever so slightly modifies public opinion on the matter and pushes the Overton window.
From my experience, in cases like this the law turns out to be somewhat arbitrary and devolves into "whatever the judge(s) of the highest order think". It is extremely important not to get self-defeatist at this point and argue aggressively for the outcome you want to see play out.
Of course, I am not sure how this would in fact play out in court, but I think no one is. If anyone is aware of a concrete fact which makes my reasoning outright invalid, I invite them to cite it.
No, they're not. The Javascript was designed to run in the browsers as authorized user agents so that a user can view the video.
You can't host something publicly, available via common, general purpose technology and then claim protection when someone uses this general purpose technology to obtain it.
Yes, you can. Literally, the entire point of copyright and IP law is to incentive creators to make their creations public by protecting them when they do so.
What are "browsers"?
> Yes, you can. Literally, the entire point of copyright and IP law is to incentive creators to make their creations public by protecting them when they do so.
Sure, but that has little to do with the topic at hand since copyright is not being challenged. Clearly it is the RIAA's intent for the content they publish publicly to be available publicly.
However, a tool which selectively evaluates the JavaScript to decrypt the content URL without implementing the rightsholder's policies would count as disabling or evading effective protection under the DMCA, and thus be illegal. Browsers are not such tools; however, distributing software (say, a GreaseMonkey script) or instructions on how to make a browser evaluate the decryption JavaScript and download the video without implementing the policies would also be illegal.
Why is this so hard to understand? The law is very clear: when a protective measure is set up, be it in JavaScript, Visual Basic, or anything else, anything that gets around that measure is a crime to distribute.
No service provider is going to fight a specific case of DMCA for a third-party.
How far do you think I'll get if I tried to file a bogus DMCA request for a Microsoft repo?
It happens that they own Github, but s/Microsoft/Oracle/ and you'll probably get the same result.
The automated systems will take down the repo for a bit, then the owner of the repo will kick your ass in court.
It just happens that youtube-dl doesn't have a large corporate owner, and the RIAA _is_ a large corporate entity, and so this is how it happens.
Your anger is misdirected here....
That seems unlikely, considering that would be a massive DDoS vector.
With most companies, Hanlon's razor would probably apply ("never attribute to malice that which is adequately explained by stupidity"). But in this case it is rather dubious (if not shocking) how GitHub's legal department appears to have completely failed to do their basic job.
As a company, GitHub at least has a legal duty to know the law, or be held accountable for the consequences of their actions when they monumentally fuck things up (while doing serious harm in the process).
Either way .. with Microsoft's track record in mind, GitHub's silence on legitimate questions regarding the validity of the RIAA's actions, and now this warning of inflicting harm to people if those dare to not play along with the companies dubious legal decisions .. all in all, I'd say that GitHub has long lost any benefit of a doubt by now.
With every day passing, this appears to be shifting more towards plausible (if not likely) malice. On top of that, this isn't a light matter either. Most likely a serious anti-trust violation and might even constitute a criminal enterprise. Not that I expect US authorities to do anything about it, considering its own dubious and dismal track record, for at least several decades.
0: https://joindiaspora.com/posts/808cf690f8e801381778002590d8e...
From a formatting perspective, format is generally irrelevant to notices like this because the law does not state a particular format must be used. Thus, any format which conveys the necessary information is generally acceptable.
And while formatting is somewhat irrelevant from a legal standpoint it is still one of the tools Github uses to ensure that their take-down requests contain all the required information. Acting upon a request that doesn't conform to the format is risky.