Update to our privacy policy and apology
github.com
github.com
When people started forking Audacity over the privacy policy change I was surprised (in the "is this what it take for people to fork?" sense), but I sure hope those forks stick around and improve because I don't trust Audacity to not do stupid things again.
1: https://lwn.net/Articles/862073/, HN: https://news.ycombinator.com/item?id=27926611
E: A couple of edits to space stuff out and add links.
Indeed, despite the massive amount of fearmongering I saw about it on Twitter, that appears to be what happened:
> The most unclear and damaging part of the original document stated that we collect personal information “…necessary for law enforcement, litigation and authorities' requests (if any)”. This was interpreted to mean that we intended to collect and store unspecified additional information on top of the basic system information mentioned elsewhere in the privacy policy. This is not true, as could be seen through inspection of the source code and network analysis of the release binaries. However, we agree that the wording used in the old privacy policy made it sound like it might be true. We have now changed the wording to remove this source of confusion. To be clear, any organisation, if ordered by the court, is required to cooperate with an investigation, and doing otherwise is considered to be an obstruction of justice. These are not the rules we create, these are the requirements we must follow. However, we would only be able to provide the specific information mentioned in the privacy policy (outlined below) and nothing more.
On the other hand, I 100% agree with everything else you've said about Muse: they appear to be deeply untrustworthy and have a deservedly bad reputation for some of the stuff they've done. Likewise, I hope a community fork takes off and succeeds. Sometimes an issue like this is the straw that breaks the camel's back. Similarly, resentment stewed among contributors toward OpenOffice before it was forked, and that turned out to be a massive success.
You cannot polish a turd.
Like I said, though, maybe I am being uncharitable. Am I missing something?
I think so. It optionally phones home to see if there are version updates. It optionally phones home after a crash. They have to publish legalese to comply with GDPR because those phones to home store audacity version number, operating system and operating system version number, and country of origin (based on up). It allows them to know when it’s safe to drop support for certain operating system versions.
https://www.swlaw.com/blog/data-security/2015/03/12/why-you-....
But I know Audacity has a sizable European userbase, too.
Also, it's an optional feature. You can just turn it off if it's not a benefit to you.
I swear it seems like there’s a whole generation that doesn’t understand that how to build software that isn’t always phoning home and requires a subscription fee.
An audio editor has an incomparably smaller network attack surface - perhaps even none, if it's sandboxed and makes no use of the network at all.
[0] some plugin host apps do "sandbox" the plugins by running them in a separate process, but this is absolutely nothing like the sandboxing done by browsers. The separate processes run with all the priviledges of the host app process.
Seriously. Don’t do that.
Perhaps that's the current state of things, but like you mentioned with web browsers, it's a thing that can be done if you're willing to sink enough effort into it. Browsers had to go through this process at some point too. There's nothing that prevents plugins from running in a sandbox where the only I/O is waveform in, waveform out.
I've done that in the past, more times than I care to remember, and never have I thought 'Blimey! That's a great use of my time! Let's do it again!'.
I appreciate the fact they've spent some time actually thinking about this and working on revising their policy and making a thought out statement.
What everyone wants is the phone home code removed.
If they just did that a git commit comment would suffice.
Is that tax haven?
>"For the purposes of this Notice, WSM Group with registered office at Moskovsky pr-t,40-1301, Kaliningrad, Russia, 236004 (“Audacity“, “us“, “we“, or “our“) acts as the data controller for the Personal Data that is collected via the App and through the App."
The new version replaced that line with this:
>"For the purposes of this Notice, MuseCY SM Ltd., a Cyprus company with an address at Spyrou Kyprianou, 84, 4004, Limassol, Cyprus (“Audacity Team“, “us“, “we“, or “our“) acts as the data controller for the personal information that is collected via the App and through the use of the App, as further outlined in section 2 (“personal information”)."
source: archive.is mirrors
https://archive.is/https://www.audacityteam.org/about/deskto...
This is great. Does anyone have any idea on how the actual mechanics of data transmission and storage can play on the legal side of things to enable use by under 13?
> The best example is the catchall phrase ‘personal information’, a non-specific term that understandably raises concerns for regular readers.
Personal information is actually a pretty accurate designation with sufficiently clear boundaries in GDPR context and the concerns it may raise are perfectly valid. It can't be downplayed to "just legalese". E.g only because IP address are personal information you had to separate your collection and retention policies very clearly, and could be help accountable on that.
> The most unclear and damaging part of the original document stated that we collect personal information “…necessary for law enforcement, litigation and authorities' requests (if any)”.
> In addition, the steps we have taken to anonymise all stored data means that it would be of extremely limited use to anyone.
Be that as it may, those records are required for your GDPR compliance too, an information that is pretty useful about how honestly this policy will be executed.
> It is verifiably untrue that we hid the exact data being collected. As noted by journalists who investigated the issue, Audacity is free and open source software, and an inspection of its source code shows that the data it shares is extremely limited.
That is only true for the client code. To my knowledge the server side code is not public, as such it is completely unverifiable outside an audit context that whether you merely collected the IP address or also retained it for example.
I am not an active user anymore, but I hope people make repeated data takeout requests just for that redundant bit of evidence in case they are found to be in non-compliance.
Let's say there's still 30 bits of an ipv4 address left after they "truncated it before hashing". How long would it take to brute force the entire truncated address space? An hour?
Muse Group's head of strategy told someone to take down their (allegedly copyright-violating) repository or else supposedly be at risk of being deported to China and then punished for their alleged political speech against the Chinese government.
https://twitter.com/marcan42/status/1417085393762099200
The irony is that the original MuseScore data being mirrored in the repository is itself full of copyright violations.
The options here are believing someone when they say "I would report this but it might cause far more harm to the person than I feel comfortable being responsible for" but going into more detail than strictly required, or believing that it's all a thinly veiled threat to get them to act.
I'm more inclined to believe it's both, that the person making the statement doesn't want to be responsible for something like that, and is also spelling it out so the person in question is aware of what's possibly on the line, because "there will come a time when hesitation is no longer possible" is not necessarily a threat, it's a statement of fact for anyone that wants to retain a copyright, as if you don't defend it you end up losing it.
There may be more to it that puts it in a different light, and I'll also definitely admit that I might have a bit of bias just from seeing that it came from twitter. My default assumption about anyone getting outraged about anything on twitter is that they've likely jumped to conclusions and gotten one or more salient facts wrong, and that generally has served me well. Twitter, as a medium, seems to work best in expressing extreme emotions and not delivering all the useful facts, so incentivizes such things.
Edit: Correction, in fact it's trademark that you can lose if you don't defend it, not copyright, and has happened to "aspirin, escalator, butterscotch, zipper, yo-yo, thermos, and heroin" according to one source I found. I'm not sure exactly how this affects my point materially though, as I don't think that's necessarily a requirement for wanting to enforce the law on something that you think it causing you harm.
Here's the relevant part of the GitHub issue comment, before he edited it to remove most of it: https://pbs.twimg.com/media/E6p_DcrUcAMWFtB?format=jpg&name=...
To steelman it, let's assume for the sake of argument that he genuinely believes it is copyright infringement, and that it actually is copyright infringement; and criminal copyright infringement, to boot.
He claims that they're refraining from filing a lawsuit because they don't want him to be deported and handed over to the CCP - that they are being "empathetic", and that this "is not at all a threat, but an informed assessment of your own personal legal risk".
Now let's assume their case is a lot shakier than that. Maybe he believes it's strong, maybe he doesn't, but let's say it's not a clear-cut case. That completely changes the implied framing: it's more like "take this down... or you might die". It's potentially a way of strongarming someone into compliance while bypassing the legal system, perhaps because that may have a higher chance of success than filing a lawsuit.
I don't think he actually wants him to be killed, but the tactics here still come across as very shady and intimidating. If you believe you need to file a lawsuit, then just file the lawsuit. Let the defendant handle it as they choose based on if they think they're in the right and their perceived chances of winning and chances of being charged or convicted with a crime. The author is probably already aware that a criminal conviction could result in deportation. (And, more importantly, there's basically zero chance of criminal liability here.) If you want to be "empathetic", provide a settlement offer where you'll drop the suit if he takes everything down. If he refuses the offer, then it's in the court's hands.
I also find the line "what I have described in this post is not at all a threat" interesting, perhaps not unlike "this isn't racist, but", or "this is perfectly legal". This can potentially be a kind of psychological defense mechanism that kicks in when, deep down, you know you're basically threatening someone to at least some extent but need to convince yourself and others that you're not. The lady doth protest too much, etc.
Lines like "I do not mention which country [he lives in] out of courtesy or any other details such as the basis of residency out of respect for personal privacy" also seems interesting. This could easily be interpreted as "FYI, I know all of these details about you, but I'll mercifully protect your privacy, and then we'll sort all this out, right?" It feels like piling more and more things on to project a show of power and force.
I certainly can't claim these are his conscious or subconscious intentions with high confidence - else I'd be spouting Freudian-esque pseudoscience - but I think they're plausible.
Additionally, even if one assumes he has a decent chance of being found civilly liable, I think the implication that he might be criminally charged is extremely spurious and makes it seem much more like an intimidation attempt. (I wrote more here: https://news.ycombinator.com/item?id=27928028) Again, it seems like piling more things on to instill fear and project power. The threat of criminal charges seems so absurd that it seems like it's necessarily either a malicious threat or unfathomable incompetence / lack of care for facts. He could've easily researched the law or consulted others beforehand; this wasn't a spur-of-the-moment comment he wrote.
I agree that intimidation or extortion is probably not 100% of the intent. But, at the moment, I'm sticking to my assessment that it likely essentially is partly a "it would be a shame if something happened to it"-type strongarming / "out-of-band settlement attempt". Or at least that it very, very much comes across that way and can easily be read that way.
It's ambiguous and maybe he really doesn't have any bad intentions whatsoever, but I think it's quite possible it is an attempt to pressure him because they don't want to incur the costs of a lawsuit and the risk of losing, and isn't just out of claimed empathy. And it could possibly be half and half, and possibly a mix of conscious and subconscious behavior.
>There may be more to it that puts it in a different light, and I'll also definitely admit that I might have a bit of bias just from seeing that it came from twitter. My default assumption about anyone getting outraged about anything on twitter is that they've likely jumped to conclusions and gotten one or more salient facts wrong, and that generally has served me well. Twitter, as a medium, seems to work best in expressing extreme emotions and not delivering all the useful facts, so incentivizes such things.
For what it's worth, I didn't find out about it from Twitter and don't know if that's the original source. I first found it from an HN thread. (The Twitter thread does seem to predate the oldest HN thread on it, though.) If my first exposure to it was from a Twitter thread, my opinion probably would've been colored in a similarly skeptical way, as I (and probably most HN readers?) fully share your view of Twitter. Framing and first impressions can have powerful effects.
--------------------
Additionally, this is in the context of the other Muse Group developer previously adding this at the end of the initial takedown request emailed to the author:
>Otherwise, I will have to transfer information about you to lawyers who will cooperate with github.com and Chinese government to physically find you and stop the illegal use of licensed content.
The combination of these two messages from two employees, plus the supposedly leaked Chief Product Officer quote saying "His actions are total copyright infringement. So I suppose none of us should worry about his feelings." afterwards, makes intimidation seem like the most likely hypothesis, IMO.
If I see someone take something of mine, and they refuse to give it back, I might feel okay in saying "if you don't return that, I'm going to have to call the police. Getting the police involved in this is definitely not going to go well for you. Is this thing you'e taken really worth that? Please just give it back and let's go our separate ways."
Am I using intimidation to sway that person in this theoretical situation? Yes. Do I feel justified in using that intimidation? Yes.
Really, what I think this comes down to is whether Audacity thinks they have been harmed and are in the right legally and/or morally in trying to get the other party to stop that harm. In that circumstance, I think telling someone what their actions might result in if you follow through with what you considered a perfectly acceptable and legal action (defending yourself) is not nearly the same as threatening some action that is purely for your personal gain even if the other party has done nothing wrong.
Importantly, I also think that statement should be made based on what Audacity believes, not necessarily the specific law or outcome of a legal case were it to be brought.
I think the above explains how the following situations are viewed differently by people, even if the statements are essentially the same (threatening some bad outcome for the other if you take some action so they capitulate in some way):
"It's in your best interest to make sure that emergency exit is working for all our safety. If I have to report you, I doubt the fines and problems are worth not fixing it now. The only reason I haven't reported you is so you can handle it yourself and avoid that." Acceptable. The target is not following the rules and everyone else is taking some small harm (risk) from it.
"You should really buy this 'insurance' I'm offering you. It would be a shame if you hadn't and someone does something bad to your business. I bet that might even happen within a week." Unacceptable. The target caused no harm, and needs to take some action to prevent harm having done nothing to cause the situation.
> So I suppose none of us should worry about his feelings." afterwards, makes intimidation seem like the most likely hypothesis, IMO.
I agree it's intimidation. The question is whether it's justified. It's hard to justify exposing someone to that amount of risk. It may be justifiable to threaten someone with that level of risk to try to get them to stop some harm them are doing to you, but it does seem a bit over the top to the point that it's very distasteful. There is the concept of a proportionate response, and I think this is probably disproportionate, which is what people are really upset about, and incorrectly attributing it to the intimidation in general. We wouldn't be talking about this is they simply said "stop or we'll bring legal action, with all the negatives that entails" but that's also intimidation, just proportionate and seen as normal and/or justified to most.
And I'm pretty sure there is a group of MuseGroup fans/trolls that are going around downvoting content negative about MuseGroup.
Actual quote, including full-on "it would be a shame if something happened to him" villain line:
>Upon further investigation, it became clear that [author] is a Chinese national, but not resident in China. As a guest in his current country, his residency status is predicated on a number of conditions, one of which is not violating the law.
>If found in violation of laws, residency may be revoked and he may be deported to his home country.
>This becomes even further complicated given another repo of his - Fuck 学习强国, which is highly critical of the Chinese government. Were he deported to China, who knows how he may be received.
For those who don't wish to, in summary:
The problem is that they can't DMCA the downloader repo (as it doesn't contain any copyrighted content), but the downloader violates their service's TOS and specifically costs them licensing fees, as the rights holders extract payment for each download.
Their only recourse, in this instance, is to sue... But if they sue, they risk outsized impact on the life of the github author, something that it appears they have no desire to do.
But what do they do, stuck between the rock of "this guy is costing us money and effecting our business" and the hard place of "if we sue this guy he may end up a political prisoner in China"?
So they say that awful sounding line. The guy is an bumbling idiot when it comes to optics, clearly, with no understanding of how what he was saying was going to be read, but I don't think he's as villainous as the quote makes him out to be.
Essentially, I argue that - perhaps counter-intuitively - the actually empathetic and good faith thing to do would've been to just file the lawsuit rather than post what he posted, despite the claim that they're doing all this out of empathy.
Maybe I'll change my stance on it in the future, but those are my current feelings on it. At the very least, it's indeed one of the worst and least self-aware ways anyone could handle this situation.
You're entitled to your opinion and so do they. I don't really see how there's basis for bad faith accusations. Their stance and actions seems reasonable and consistent, even if other people would have acted differently.
Criminal copyright infringement is a thing, but I strongly doubt it would apply here:
>There are four essential elements to a charge of criminal copyright infringement. In order to sustain a conviction under section 506(a), the government must demonstrate: (1) that a valid copyright; (2) was infringed by the defendant; (3) willfully; and (4) for purposes of commercial advantage or private financial gain.
Even if one assumes for the sake of argument that (1), (2), and even (3) are actually met, (4) clearly doesn't apply. And based on all of the author's statements, I think it's unlikely (3) would be met, either.
The only thing that matters is that the relevant parties believe it would possibly result in a criminal copyright case, or form some other grounds for deportation.
And again if they did believe that (and the Ars article mentions that they at least seem earnest) they're still idiots, but they're not moustache twirling cartoon bad guys, either.
I get the activism aspect and I agree that copyright laws are outdated, but how entitled do you need to be to expect preferential treatment because of your political beliefs? If you're in a foreign country and hasn't settled yet, just create a fake persona and disassociate from controversial activities.
World problems are here to stay, they'll still be around for you to solve once you get a citizenship.
[Latest updates to the story below]
A supposedly leaked statement from their "Chief Product Officer", possibly suggesting the death threat is officially approved:
>We put a lot of effort to neutralize his code, and spent a lot of $ and time for this. His actions are total copyright infringement. So I suppose none of us should worry about his feelings.
Response from the threatened author:
>If the statement is real, does it mean my project costs them a lot of money and effort, so it's ok to send a kind of death-threat to me?
The author posted a call for help here: https://github.com/Xmader/musescore-downloader/issues/130#is...
>Rather than money, more importantly, I need good lawyers for copyright, immigration status / status of political refugee
I find this orders of magnitude more outrageous and infuriating than the telemetry brouhaha. Based on the actual facts, that scandal seemed a bit overblown despite their poor handling of it. This, on the other hand, is truly fucked up.
To me, the situation reads more like: Muse Group have held back on litigating over copyright infringement (whether that is a valid claim or not) because they are aware of the alleged infringer's precarious political situation, however they've turned a blind eye for too long and are now in a difficult position where they either lose money where they are paying for licences for content that this developer has allegedly stolen, or they litigate to protect their interest and risk having the guy deported.
It seems like they're just trying to be frank and level with the guy.
Maybe it's just that text isn't the best way to get this message across, or the CPO's communication style doesn't work for some folks.
But I don't think it's like an "offer you can't refuse" mobster tactic as some would like to claim.
In my opinion, even if you earnestly try to read it as charitably as possible and give full benefit of the doubt, it's still not good.