RIAA Takedowns Backfire as Pirated MP3s Now Surface on GitHub
torrentfreak.com
torrentfreak.com
RIAA couldn't care less. As far as I understand, they practically are just a team of lawyers whose job is to attack whoever they can reach, take whatever they can down and collect money when possible. They hardly even care about the actual recording business, let alone about how do people feel about them.
Copyright cartels live by bullying. It is not important how much of the takedowns are actually effective, as long as they get to dominate the news with their lawsuits. Because only that will already deter al lot of people. Just drag everything on forever and have an occasional success that you can trump on every news channel. That is enough to spread fear. And that works also in other countries, like The Netherlands, because they will have some representative organization there (Brein, in this case) that is happy to take on the role of the bully for a small amount of cash.
Thing about software is it doesn't need a lot of people. Just a handful.
oink.cd was viral.
PopcornTime is viral.
The Pirate Bay was/is viral.
RIAA doesn't care. Their main business is extortion racket. And it's extremely lucrative.
And it's extortion on all sides. They extort money from DMCA and copyright lawsuits. They extort money from artists. They extort money from music services.
The RIAA and other copyright holder representatives have automated submitting a DMCA takedown request process ages ago, and now submit thousands a day to e.g. youtube. Youtube in turn has automated taking down content that receives said requests and probably a big part of the appeal process as well. Is Github that far already?
Microsoft bought Github for 7.5 billion dollars. Github is a website wrapping a git-server; you know Microsoft could have built their own for a lot less money. The didn't buy the technology, they bought a network, its data and a brand. They are trying to improve their reputation with the open source community. It's really hard to measure such a thing, but this RIAA take down reduced developer trust. If Microsoft chose to fight a legal battle, win or lose they would win on their branding front. They would signal that they are defending open source.
Then again... who remembers Digg?
I don't think so... instead what I expect would most probably happen is that they automate it even more, which will suck even more. We got enough damage already from Youtube doing it...
The question rather is: how much will developers continue to respect Microsoft?
It’s easy to stand at a distance and mock those who do something we disagree with, but when you’re actually in that situation, your tune is going to change very quickly. A bad example, but if you’re getting mugged, sure, you could fight back, but your life is on the line.
I would also be curious to see you cite a case that says that refusing a takedown notice in one case costs anyone the Section 512 safe harbor in all other cases where they continue to execute takedown notices, since that would be oppressive and ridiculous.
I do. It was pretty good, then they destroyed it, de facto paving the way for Reddit's success.
I am aware of two open source ones: RedReader and Slide (both Android).
Over time, Facebook groups and Twitter have become the de facto discussion hubs for communities that I've been a part of for years. Those platforms make it hard to not reveal your true identity online, and you have to give Facebook and Twitter your phone number just to register. Facebook will even ask users to verify their identities with their driver's licenses. At least for me, this causes a chilling effect on my online participation in these communities.
For example, I won't talk about politics in my neighborhood's Facebook group because I don't want to be harassed. I recently witnessed a single mother get harassed because she respectfully disagreed with someone's politics in the group. People started posting pictures of her kids, putting them into crude memes, and the mayor went through public records to find her full name and address.
https://en.m.wikipedia.org/wiki/AACS_encryption_key_controve...
All GitHub got was a take down request (which they were required to act on), not proof of anything being illegal (which requires a court case to prove)
A potential employer.
"Oh, you committed code to a repo I consider dubious though nothing proven... hmmm not sure I'll hire you".
"Oh, you shop at a store run by a non-white person.... hmmm not sure I'll hire you".
"Oh, you follow a religion, but I'm atheist... hmmm not sure I'll hire you".
... the list goes on.
Two of those are protected classes... the third one isn't.
Implying criminality because you're participating on something "of dubious legality" defined nebulously ("guilt by association") wouldn't play well.
A company could also freely and legally discriminate based on whether or not you prefer whole-wheat bread. That's not a protected class. It doesn't matter that whole-wheat bread is legal.
If, as an employer, I decide that because you chose a specific project (or political party, or brand of motor bike, etc. anything whose association has potential 'dubious legal status') that you're part of a criminal organization (and hence a criminal, or any other description that might be undesirable/harmful) because of that and don't hire you, that may put me at risk.
Obviously there would be a legal bar to meet from that, not the least of which would be proving that it was intentional to defame the person, and resulted in actual damages to that person (i.e. proper standing - would not getting the job be enough?)
IDK IANAL, but I sure AF wouldn't want to be the trailblazer for finding out (like IBM is right now).
> "Oh, you committed code to a repo I consider dubious though nothing proven... hmmm not sure I'll hire you". > "Oh, you shop at a store run by a non-white person.... hmmm not sure I'll hire you". > "Oh, you follow a religion, but I'm atheist... hmmm not sure I'll hire you".
There are zero laws on the books to stop a company from firing you for committing code to an open source project.
Unless you can find me a law that actually says "Companies can't terminate employment or otherwise discriminate based on a code repo commit".
There ARE actual laws that say "You can't discriminate based on Race/Religion/Sex/ethnicity/etc".
Whether or not YTDL is illegal (I doubt it is) is irrelevant to this thread. Just like a company firing you because of a post on facebook or twitter is generally allowed (local laws and state statutes may grant more protections).
Please... prove me wrong and provide laws - local or otherwise - and possible a case where someone successfully sued for wrongful discrimination based on code they wrote.
Projects like YouTube-dl are usually born out of passion, and the best kind of projects.
Plus when you use an anonymous name and get a popular project out of it, you still get recognition. Even if it's not publicly in your name. You'll still feel good about contributing to the world.
But the extra steps are not completely trivial to do right if strong anonymity has to be ensured.
But now I have a copy of the source, and have been thinking about how I might contribute and/or repackage it as a “browser” (with the option to run it in “headless mode”, of course).
(apologies for rewording the Striesand Effect but it is very real).
Also there are tons of options GNU Savannah, Gogs,Gitea , Git Bucket ...
What is hard is managing the identity/ authentication process of large numbers of developers.
Even harder is actually covering your costs, i.e. running a going concern.
... no wait, that was my Youtube channel.
I am going to leave Github, since the tech giants + Mozilla should not be trusted.
Or maybe I'm just being naïve.
It doesn't seem to read as bad as what you make it sounds but it could end up exactly that bad. As dotdi said, I hope that companies like Mozilla joined to (try to) influence these decisions.
[1] https://edima-eu.org/wp-content/uploads/2020/10/ORF-Series_-...
In a moment of greatness, which we have very few, EU officials specifically disallowed "forward policing".
Perhaps I do have a fundamental misunderstanding and the ambition is indeed to restrict general monitoring (sic) and these attempts are meant to sway some more zealous voices. But a lot of these companies here have shown interest in getting more data rather than less.
Without further comment this seems to be an attempt to fortify their positions as "leading internet companies" as they describe themselves and furthermore...
> limited liability when they take proactive action to ensure that illegal content [...]
... can basically allow propaganda. You just need to conjure a threat of incoming "illegal" content.
It's not as though a fork couldn't have added those.
And despite adding those the user share of Firefox continues to decline.
It has done much for the net though, it should not be forgotten.
What a silly headline.
If you want to actually something that will matter then make sure that github doesn't become a single point of failure for FLOSS software in the future. Or get your GH account banned by posting Lady Gaga tracks in your repos, you do you.
"EFF believes that the circumvention restrictions in DMCA section 1201, which prevent people from bypassing technological restrictions, are too broad.
DMCA 1201 is incredibly broad, apparently allowing rightsholders to legally harass any ‘trafficker’ in code that lets users re-take control of their devices from DRM locks,” EFF wrote recently."
This creates an unaccountable enforcement party who can harass "targets" on behalf of another unaccountable party. The way it is written, reddit would have to take down a selectively unpopular subreddit for providing technology that facilitates the trafficking of copyrighted images. Whose copyright? Who cares? One could inject a bunch of copyrighted material into sites and then use a DMCA notice against their upstream provider to shut them off - a pattern I would predict is likely to materialize in coming months. Write sideloaded apps for a community because an app store uses their policy against you? "Circumvention!" The opportunities for abuse are endless.
While teleological arguments are always a bit iffy, the final objective is to ensure that there can be no information or service on the internet that is outside not only U.S. subpoena, but that there can be no communities or networks of personal relationships that are not governed by legacy institutions. It is under the auspices of people being "accountable," for their thoughts and beliefs, and yet without precision about to whom one is being held to account by.
To every establishment growth is the greatest threat of all, and the DMCA s1201 is effectively designed to suppress it. The good news is these blunt attacks are a forcing function for developing decentralized technologies, and every one of these creates a cohort of new hackers.
RIAA made a habit of attacking things seen as reasonable and harmless and has earned a reputation for being unreasonable and harmful. Musicians deserve better. Ultimately, they are the bosses here. Perhaps someday they'll start acting like it.
Some do. I seem to recall Nirvana being outspoken of their corporate attack dogs the RIAA back in the Napster days when the RIAA was with a straight face claiming damages that totaled more money than was in circulation, globally.
When they are done with open piracy they will move to other stuff.
Did you whistle a copyrighted tune in the elevator? You owe us money now.
(If you think I'm joking, look at Japan who jails musicians for 10+ years for playing covers at parties without paying royalties)
A party large enough is effectively a broadcast/performance.
It's not as cut and dried and greed-filled as all that.
For large acts and musical pieces that have moved into the larger cultural milieu, sure—there's a discussion to be had about the place of the work in that society. (And then maybe the society as a whole should compensate the artist they've so benefited from more directly)
Those licensing and copyright laws were designed to protect journeyman musicians from having their life's work robbed by large publishers and broadcasters and it still serves that purpose.
Imagine proprietary software from your work was lifted and incorporated by a potential client. I'm certain in most cases that would be grounds for litigation in most peoples' minds. (Or, for example Robert Kearns' case)
10 years, not a second more! For all IP .. no exceptions.
People have a lingering hatred on for the RIAA, and maybe rightfully so, from the Napster trials and so on from the early 2000's and I think they let it blind them to the history of music and creators' rights in North America.
The assumption that musicians are all a bunch of greedy sods making it filthy rich, undeservingly, is pretty awful. The reality is they get robbed often.
(And people get all hot under the collar when it comes to licensing of performances and broadcasts because they want to rant about the RIAA, but that's not really their wheelhouse—that's more the domain of organizations like SOCAN, ASCAP, BMI, etc, and they do a lot for artists).
But who am I kidding. It's 2020. Everywhere I look, people want their music, films, and journalism for free while they proceed to whip the creators for whatever faults they find with the creation or research...
I used to buy lots of music and video. I deliberately stopped buying anything in that line way back in the early 2000s. Roughly at the same time as my Sony boycott.
You helped make an album? Great - here's your flat fee, royalties go to the artist and the artist only. The problem would fix itself overnight.
Unless you literally want Microsoft to start committing insurrection against the US government. I'd rather lose youtube-dl than live in a world where tech companies are corporate sovereigns.
> While GitHub’s CEO Nat Friedman was annoyed by RIAA takedown efforts, he stressed that the platform legally had to comply, which it did. More recently, the company even said that users who continue to republish the code risk being banned.
Mates, just put the youtube-dl code up on IPFS[1] or SourceHut[2], which is a platform much more sympathetic to and defensive for the open source cause. No need to put it back up on GitHub and risk banishment there. There are lots of options here. The RIAA can't sensor open source software. At least, I'd like to see them try.
I wanted also to say that I don't necessarily agree with jacking videos off of youtube. But who knows? What if you have the permission of the youtuber? What if the youtuber is just posting stuff that's in the public domain anyway? What if you're downloading the whole video so that you can get clips of the video you intend to put in your own video in an attempt to criticize the video, thus invoking fair use? The RIAA does not and should not have the power to take down open source software just because it could be used for nefarious purposes. There are also plenty of innocent uses out there.
If the original creator endorses a fork, is he making himself liable? - not sure what happens if you repost after a takedown notice.
And the involvement of the law, and the publicity will lead overall to self-censoring, as most devs won't want to deal with this...
Doesn't seem to me to making things worse for the RIAA
Github is more interesting because of eg issue tracking, but there are other ways to do that.
youtube-dl has made new releases after the takedown, so development appears to be continuing.
This has nothing to do with youtube-dl; it's just someone annoyed about it doing something completely pointless.
Systems which rely on Github in production, such as Rust's "cargo", now need to be using multiple sources and checking hashes.
I think that pirating streams actually helps to sell music. At least, in my limited sample pool, that has been the case.
I used to stream an Internet radio station that played Industrial (dating myself -no one else will), and would often grab songs from it.
A lot of times, the only reason that I grabbed it, was so that I could find out more about it. The quality of the audio grab wasn't really what I wanted as a "keeper."
These pretty obscure groups made a lot of sales (to me) because they had their stuff out there.
So you say that users pirate the music and then buy the same music they illegally downloaded?
But this pipeline you establish - of people "pirating" music and then purchasing that same music later on - was a very common one, and remains so to this day.
Before digital audio was a thing, people would routinely record songs onto tape while listening to the radio. They would then play this music in other contexts, to which they had no license, effectively making these individuals "pirates." Any "pirate" who recorded a Todd Rundgren song in 1972 from the radio, and then purchased his full double-LP "Something/Anything" at Sears the next week, was definitely a win for the artist, the record label, and the industry as a whole.
On top of this, also don't forget that even to this day, consumers commonly purchase the same music when it gets released on a newer audio distribution format (vinyl -> 8-track -> cassette -> CD -> iTunes -> Spotify/Apple Music). "Piracy" now does commonly mean a "purchase" later.
Yes? That is really not as far fetched as you make it sound. I have no problem paying a creator for something that I enjoy. But I do want to know that its worth the money. In older times we would use the radio to help make that decision. Nowadays there is so much more available than what is played radio, but I still want to make an informed decision. Youtube works well for that too.
Since this site has a technical audience, please explain to me how streamed music is played at all, if it is not downloaded?
What I am getting at is - where is the line drawn? Supposedly I am fine to download when streaming but I am not allowed to retain that downloaded file. Once the stream is in my cache, I can rewind and play it a thousand times without downloading it again, but if I close my browser or power off the PC, suddenly I seem to be legally required to download it again - all of this on a PC that I have paid for, and on a network connection that I also pay for data on.
This all seems like a lot of control for a third party to demand over the internal workings of a PC and network connection that I pay the bills for.
Legally, would I be able to run a virtual machine with a browser inside, take a snapshot of the state just after caching a stream, and save that to return to later? Why or why not?
I haven't used iTunes in quite a while, but it's worth noting that Bandcamp is still waiving its revenue share the first Friday of the month. Of course that only makes sense given the variety options which also support the platform itself, like their vinyl program.
run
1. run `node dmca.js` to get a Justin Timberlake - Tunnel Vision (Official Music Video) (Explicit).mp3 file
2. `node youtube.dl.js` to get a youtube-dl-master.zip file
;-)
It would be nice if for once platforms stood up legally for their users when they believe its unjust.
no i did not. i am demonstrating that most people on this site haven't the slightest clue what they are talking about.
it costs money and time to fight something and companies have something called a risk management department that decides whether it is worth the risk to fight or comply.
github knows that getting into a heated legal battle is going to cost alot, especially going up against the deep pockets of the RIAA. not saying that github and microsoft don't have deep pockets, but that this _will_ become an expensive battle to fight and defending a grey area open source project isn't worth the time nor the money.
Genuine question: why? The police won't get involved in a civil matter, only a criminal one. So what happens if you just ignore the other side's lawyers?
IAN[even_close_to_being]AL but I'm fairly sure this would result in a default judgment. At least it does in civil cases between citizens (in the US) and corporations- when a company files with the court clerk, a complaint ("you've been served" kind of thing) is issued to the defendant and they typically have 21 days to respond by filing their own motion with the clerk. If they ignore this or never actually receive this, a hearing is scheduled where a court date is decided, which the court will attempt to communicate to the defendant if they didn't show up to the hearing. The court date will come and go, and if the defendant is still ignoring the situation, the judge assumes there's no contest and will issue a default judgment against the defendant. In the case of corporations vs citizens, this is when damages/fines are accessed and wage garnishment notices get issued. Garnishments (and the corporate equivalent of fines) are no joke- corporate accountants take them extremely seriously because of the penalties for failing to carry them out: if they don't, the company's assets can get seized, accounts can get raided (depending on the type of case [medical and taxes are two large categories] and the plaintiff), and fines get levied and even increase. I imagine it's the same way with default judgments against corporations, but again, I'm no lawyer- just a guy musing about corporate civil suits based on citizen civil suits.
need i say more?
No, wait - the executives that sent the lobbyists. The fault lies with the corporations that have built and hijacked 'the music industry'.
Yes, I have a pretty easy time blaming a lot of social ills on greed.
The recourse is filing a declaratory judgement to establish the legality of the code.
Which is expensive relative to the resources of some individuals doing this as a hobby, so some kind of legal defense fund may be in order.
Of course, the other option is to put enough pressure on Github/Microsoft to get them to be the ones to defend it, since it's not that expensive relative to the resources of a trillion dollar corporation, and they could quite plausibly have more to gain in positive PR with developers (or in avoiding continued negative PR) than they pay to the lawyers they probably already have on staff.
We shouldn't forgive companies who do the wrong thing on issues like this, because the cost of people not forgiving them is a major incentive for them not to do the wrong thing.
[1] https://www.eff.org/deeplinks/2020/11/github-youtube-dl-take...
They might decide not to counter-notice, because there's a big trap in the DMCA counter-notice: as far as I know, for a DMCA counter-notice to be valid, the one doing the counter-notice must agree to be bound to the jurisdiction of an USA court. If the youtube-dl author is not from the USA (I think he's from the EU), that would expose him to legal risk.
(As a non-USA person, to me this is the most evil part of the DMCA take-down system: even a defective DMCA notice leads to a dilemma, either you keep the content offline, or you risk being sued in a foreign jurisdiction you have no control over. This is also why I believe one should always prefer to host in one's own country, so that any dispute can be resolved by the local courts.)
The biggest thing a counter-notice could do (if it's even possible) is reveal one's identity and only if Microsoft/Github tries to verify it, which would be bad, because it could be used for harassment. But the author is obviously Russian, not sure if he lives in Russia, but if he does, they definitely won't be able to get him in Russia, only harass him.
To keep their business they should defend from both sides.
1. https://www.infoworld.com/article/2676459/microsoft-sues-lin...
If issues, wiki and code review were integrated in git proper it would be trivial to change host on a dime. Unfortunately it doesn't work that way (yet?).
Basically I am glad that git does source control well. And I prefer that there is a marketplace of issue trackers, patch management and CI software layered on top. Until we have a clear excellent solution I don't think there is a need to bind them together.
Let there be choice!
I suppose the ideal would be if git somehow provided a low level API that could be used to build these types of solution and then everybody would be free to build their own solution on top of it.
Much easier said than done, of course.
I don't see your argument here. Any decentralized solution wouldn't really help here if it wasn't used. And if it was used any decentralized solution would have helped even if it wasn't built into git.
Is the argument that if we bundled it together people would be more likely to use it?
Basically my point is that I consider issues to be an integral part of a repository's history, and it's a weakness of VCSs not to integrate it. A lot of the time I find Github comments on a feature/issue to be vastly more interesting and important than the resulting commit message.
It would also constrain the various competing solutions to all conform to the git standard.
That's already more-or-less the case. Gitlab refuses to add Hg support because they pretty much hardcoded their platform around Git and don't want to abstract that away. Github doesn't support Hg. And in August, Bitbucket permanently disabled their Hg support too.
Personally, I want to see Git die. But you're talking about pantomime portability here.
Maybe with good tooling that would be workable with git as it is.
> You could, but that would get messy quick since it would
> add a new commits to be merged/rebased every time somebody
> wants to comment.
How about a branch "bugtracker". A smart UI could keep this branch checked out internally.You know what, I'm going to flesh this out. If anybody has something insightful, please comment here. I'll write the first rough UI in Python CLI app, but the real value I'm looking to create is in the file formats so that other UIs can be created.
I'll do issues first, then PRs, but all input is welcome.
My gmail username is the same as my HN username if anybody would prefer to contact me in email.
Note that this is very rough, it only has about two hours of work in it.