Cloudflare doesn’t have to cut off copyright-infringing websites, judge rules
arstechnica.com
arstechnica.com
Either because it is expensive or court obviously won't agree about every flawed claim they created. That isn't really a problem only in America.
Some people in Taiwan also tries to pass similar law, end up get backfired when someone noticed it and stop the law creating process everytime. (And they still didn't give up )
> Cloudflare's security services do impact the ability of third parties to identify a website's hosting provider and the IP address of the server on which it resides. If Cloudflare's provision of these services made it more difficult for a third party to report incidents of infringement to the web host as part of an effort to get the underlying content taken down, perhaps it could be liable for contributory infringement. But here, the parties agree that Cloudflare informs complainants of the identity of the host in response to receiving a copyright complaint, in addition to forwarding the complaint along to the host provider.
Did banks sue the Ford dealer for selling big V8 getaway cars to bank robbers? Or the city for operating the roads that they used to get away? Or the toll collector for letting the bank robbers cross a bridge after they paid the toll?
No, because any of those things would have been ridiculous.
At some point we as a society are going to have to get off this intellectual property high horse.
Maybe we should stop trying to protect things that are easy to copy like website designs and wedding dresses. The enormous effort to try and protect these things damages society more than the benefit that even a successful outcome might have for a rights holder.
If I may briefly stand on my soapbox: I'm starting to think analogies never help prove a point. No matter how relevant or true they might be, someone will pull some comparison out of the analogy and use that to detract from the main point being compared and expect that comparison to be a valid rebuttal, often to great popular success. Anybody else notice this?
Fight bad analogies with bad analogies. Show off how useless a tool they are.
It's very frustrating when they make a counterpoint to the analogy that doesn't actually correspond back to the original point.
HN is particularly bad for chains of increasingly surreal analogies, each of which the poster seems to think is a silver bullet. the analogies are some of the least useful content on the site, next to sarcasm.
> to great popular success
This is an HN audience issue, not an analogy one.
The userbase here tends to be technical, tends towards (or is at least dominated by) particular political positions, and seems to be much more literally-minded than other online communities.
Is the landlord at 1308 Halifax liable when his tenants sell someone a counterfeit Ford?
This is not a comparable analogy, CF isn't selling each website you visit.
They are providing Privacy and Security via 100% automated tools.
Perhaps take it up with the registrar, or file a lawsuit against CF and the Reg and get a court ordered TakeDown. There are avenues of resolution for such disputes, if one is passionate enough to exercise them.
Right, but the website is being used to scam customers and steal their information. So, that's not even the same thing. It's like Cloudflare protecting people that send out spam phishing emails that look like PayPal, etc. It's not just because the site was copied outright, though that's bad enough. It's about tricking customers entirely. It's literally fraud.
Cloudflare is not Batman.
(Edit to add: yes, I'm aware law enforcement is often useless when it comes to cybercrime. But that's what we need to fix, rather than encouraging private companies to act as vigilantes.)
Your analogy amounts to a person having a private road, for which a random person comes buy proclaiming "hey there is meth lab up your road" from this you then jump to the conclusion that the person that owns the road now legally "knows" about the meth lab, thus if a methlab is found they are complicit.
I would find this to be very lacking from a legal standpoint that some random person yelling an accusation at you constitutes "informing" someone of a fact to whit they would then become legally liable.
No proof, evidence, or other actionable noticed has been given, so the owner can simply ignore you accusation and move along with their day, in fact legally that would be the best course because if they then investigated they could become complicit, but at the moment of accusation they are not
Uh, no I am not. It is illegal to landlock someone, this is a pretty common thing in rural areas.
Let’s say I purchase all of the property between person X and the highway. Well, he has to have access to it so I have to give him a right of way. But that doesn’t make me the police. He’s responsible for what he does, not me.
Or, if you think this is a grand idea, I think landlords should be responsible for crimes committed by tenants. If you make that a co-condition of these ridiculous IP laws they’d all be dead and gone in a week…
Most web services do have strict restrictions on conduct. This is a far cry from vigilantism.
It’s messed up for Cloudfare to wash their hands of any responsibility here.
In the case of a crime being committed in a hotel room, the criminal is the nuisance. The hotel operator gladly participates with law enforcement to remove the nuisance. In the case of something as ridiculous as these plaintiff wedding dress makers claiming "intellectual property" over a white dress, the plaintiff is the nuisance, not the people they are accusing.
There are numerous accounts of illegal activity at hotels, hostels, government sanctioned housing, college rental properties, and any privately owned, leased property, but no one, ever has been held accountable for illegal behavior (like domestic violence, illicit drugs, underage drinking, etc), so why should a SaaS?
Meanwhile, it isn't even "in the public's best interest" for the hotel to act as law enforcement as the most they can do is evict the person from their one hotel, not actually stop them from doing whatever "illegal behavior" is taking place. (At this point, apologists for monopolies probably start arguing that this is why we are all better off if everyone is forced to use one or two providers, so that everyone can be forced to fall in line with whatever the new corporate vigilante justice rules are... sigh.) Law enforcement is empowered, trained, and equipped to actually do something, not the hotel staff.
And cloudflare isn't even doing that. They just shrugged and decided they would continue to collect profit off the criminal behavior and act as a brick wall for OP in this case. They don't have to be the law enforcement here, but they should be obligated to report this activity to law enforcement and let law enforcement do their jobs. OP will probably have to get a lawyer and spend a lot of money and time to force cloudflares hand to turn in the phisher, all while their business is being hurt directly, and that's just not right at all.
edit: spelling
If CF start to do that, then this is where it starts to look a lot like the legal process, so why reinvent something that already exists?
One counter point that regularly comes up is that people have become cynical of the system and feel that it doesn't respond to their need fast enough or even in an easy and accessible manner. This is partly true. Laws and regulations still haven't caught up to the various things online platforms are trying at a fast pace. (And that's by design in mature democracies - politicians are supposed to observe the effect of something on a society before deciding the best way to legislate on it). And thus people are being forced to turn to the corporates instead to address their need.
I mean, who wouldn't prefer to just yell at Twitter or Facebook to take down a post compared to the convulated process of the judiciary to do it legally?
Thankfully, the governments around the world are finally starting to debate laws and regulations on Privacy, Right to Repair, etc. are starting to legislate on it.
It seems obvious that something phishy is going on, but that's for law enforcement to figure out. They can then instruct Cloudflare to take down the infringing site. It's not up to a random individual to tell Cloudflare to take down random sites, and it's not up to Cloudflare to decide on questions of law.
It's "innocent until proven guilty in a court of law", not "innocent until accused by a random dude on the internet".
If someone calls my office and tells me that one of our customers is doing something illegal, I will not, under any circumstance, forward that information to law enforcement. Why would I? All I have is an unproven accusation by someone I know absolutely nothing about! What, exactly, is stopping the person making the accusation from calling the police himself, instead of me? Why is he contacting me - is that because contacting the police would get him into legal hot water? If so, would it be wise for me to act as his unpaid proxy in this? No, of course not!
Again, we still don't even know if the person making the accusation is in fact the injured party, or guilty of the very fraud he is accusing the other website of! Why are you trusting him at all? You don't know either party, you don't know the websites, so what are you basing your preference on?
Besides, if a domain owner can switch to Fastly, Akami, Cloudfront or any other CDN, are we really solving this problem in the right place, or are we just giving Cloudflare extra responsibilities and powers that they shouldn't have?
5 years ago I might have agreed that Cloudflare should intervene a lot more. Now I don't.
Can you expand on this a little more. What were your thoughts 5 years ago, what changed your mind?
The most immediate reason for that is of course that you grant them that right when you sign the customer agreement, the default one even containing:
> Additionally, we may at our sole discretion terminate your user account or suspend or terminate your access to the Service at any time, with or without notice for any reason or no reason at all.
> especially in light of the downsides of them having that responsibility/power being as large as they are.
No clue what you're referring to. They almost certainly already do this, they may just be doing it badly.
You just made that up and also failed to define what you deem "malicious content" at first place. What ethics framework are you even talking about?
I dont understand how US got to to this point, having tech companies making morale judgement and law enforcement on pretty much every issue.
This is not being snark, troll or whatever you what to call it. I am genuinely curious. How? Why? Did we arrived here.
At one point you thought this is some thing that are amplified by social media, and they are a small minority. You ignore Social Media. Then you see this even on HN, or some other specific / niche forum. And someday you meet people in real life who actually believe in it. That company should do the right thing. And these people are suppose to be smart, from an educational or pay grade scale.
Because the institutions that should have handled these responsibilities got broken down intentionally due to "starve the beast" libertarian ideology. Congress is gridlocked and plagued with cronyism, corruption and obstructionism for decades, and the fact that FPTP leads to extreme polarization doesn't help either.
Regarding law enforcement, the problem is similar - the fact that police unions are so powerful that they can threaten democratically decided reform projects (e.g. https://www.newyorker.com/magazine/2020/08/03/how-police-uni...) is maddening in itself.
The end result is a weird form of anarchism - trial by public, one may call it IMO... in the absence of government regulation - no matter if due to incompetence, old age of those in decision-making power or bribery - individual actors simply do whatever they want (aka makes the most profit for them), unless the pressure of the public in form of protest campaigns reins them in a bit.
Oh thank you. That makes lots of sense.
Historically, the position of liberal/libertarian free market advocates has been that protecting and enforcing property rights is a core responsibility of the state - one of very few core responsibilities.
You can probably find some fringe opinions that would question even this limited role of government, but I think you're going to find it very difficult to demonstrate that this is a significant political force.
Underfunding or general ineffectiveness of the judiciary and law enforcement can be a consequence of many political and organsiational failures. You can find it in many countries around the world that could never be called remotely libertarian.
Libertarian ideology famously pro-cronyism, corruption and obstructionism?
:)
If a stated principle conflicts with common behaviour, then you focus on the behaviour. People/organisations aren't incorrupt just because they claim to be.
American conservative politics is absolutely ridden with corruption, obstructionism, and cronyism.
Again, just because someone claims that they are incorruptible and only looking out for your best interests, it doesn't mean they actually are.
If they have a choice between people who overtly want to move more power to the state, and those who say they don't but sometimes do, they're going to pick the latter.
Why? Because, money for the most part. If you can't see the money incentive then it's about control. And if you can't control yourself, compel those who can to do so, it's even cheaper.
Lets also not forget about fair use -- right now the TOS on Youtube and Twitch counts cases of legitimate fair use, like using a 10-20 second segment of a taylor swift song in a gaming montage, as an automatic DMCA strike. Slowly but surely they have eroded the definition of fair use to basically mean there is no such thing as fair use in practice. Complain about that shit instead?
Except that is what I see both on and off the internet. That is why I raised the question. Especially where there is a distinction between Hosting provider and transit provider. It would be more appreciated in this case to be writing to the site's host and not Cloudflare. ( Unless it is hosted on Cloudflare workers then we would have argue it differently ) Or as OP have pointed to the different about banks. It is all about different layer of stack, which people often seems to lump it all together.
DMCA is completely separate issues. But I do agree DMCA is being misused a lot.
It used to be perfectly legal for companies to openly refuse to hire or serve black people, or even let them in the building.
Many people felt this was morally wrong, even though it was legal. And now we're talking about something that is illegal.
If your company freely does business with a company like this, would you really be surprised and shocked that people would also judge you for doing for business with them?
Wouldn't you expect a company to do the right thing and refuse to work with openly racist and/or criminal companies?
If a newspaper was printing false ads from a person impersonating a company and committing fraud, wouldn't you expect them to stop printing the ads?
Yes, it isn't optimal, but the advantages of hosters not carelessly taking down other sites makes hosting a few bad apples worth it.
You get half your wish as wedding dresses aren't covered by any intellectual property laws except for big designer dresses which use Trademarks. Copying the dress design itself is expected and a regular part of the fashion industry.
Hard to work that into a car analogy but what if a rental car is returned obviously with bank robbers and they want another one telling you they are going to rob another bank
If a bank manager went down to Hertz by themselves and demanded someone's information, they obviously wouldn't get very far. There are established legal processes to follow.
Just like the physical world, if you want to compel Cloudflare to identify one of their customers, you have to use the legal system.
Yeah. Copyright is nonsense in the 21st century where copying is trivial. It's holding us back.
In centuries past, if you wanted to infringe copyright at the same scale we do today, you'd need expensive stuff like printing presses and a viable business model that pays for the costs of running an industrial copying process. That's what made copyright enforceable: you'd need to be a major industry player in order to infringe copyright and such centralized operations are easy targets for litigation.
Now everyone's got computers that can make and distribute a virtually unbounded amount of copies of anything to anyone within the network and there's pretty much nothing people can do about that.
I wish HN would introduce a "please no analogies that compare digital stuff with physical" rule because such things turn conversations into a mess
And no, I attack this method not because I don't agree with the conclusion of comment I was replying to, it's because I hate analogies.
How comparing cloudflare to ford and then saying "wouldn't that be ridiculous if Ford got sued if a criminal bought a car" can be accepted by anyone as a valid argument? Yes, it would be ridiculous but that's it
A car is manufactured and sold once to a customer, which then goes on a road rampage. (physical, discrete)
A website is continuously served and maintained by a provider to a customer, which then uses it for shopping scams. (virtual, continuous)
A spreadsheet serial key for an offline app is sold by the developer to a customer, which then uses it for embezzlement. (virtual, discrete)
Some legal questions: Is the manufacturer/provider liable? Did they know the product/service was purchased with the intent to harm? At what point can the manufacturer/provider be considered an accomplice? The product was sold already, what can they do about it? The service is still being provided, should they stop it?
I'm wondering how long until we see the physical, continuous scenario, exactly like the road rampage, but with a connected car. Should the manufacturer disconnect that car? Should they remotely disable it?
Very complex legal and ethical questions ahead in our times.
Is this the analogy you were going for?
If someone told UPS a package has drugs in it, they'd say, "that's nice, talk to the sender" and then deliver the package. If someone tells Cloudflare, "that content is illegal", they say, "that's nice, talk to the site owner".
Would they? Or would they turn the package over to the police?
Isn't more simple and correct that you contact police directly, present the evidence, have the authorized person to decide if the thing you claim is illegal or that the evidence is convincing then intercept the package.
Like in the case with a website, some dude complains that some other dude stole some css, now you need a detective to find the real author, licenses and then detect if is fair us ... this seems to be a job for police/justice. It is not a clear case like you are hosting an entire Disney movie.
https://www.justice.gov/usao-ndca/pr/ups-agrees-forfeit-40-m...
IF they cache content, then they do store that content though, that's the whole idea behind caching.
I was once locked out of my Cloudflare account, and I couldn't contact them because to do so... required an account /* facepalm */
FYI, the way around this is to send an email to support@cloudflare.com. This isn't mentioned anywhere on the public-facing website.
A truly bizarre way to treat paying customers.
According to OP, it should be possible to get Cloudflare to tell you the originating IPs. I am not sure the mechanism though. From article:
> But here, the parties agree that Cloudflare informs complainants of the identity of the host in response to receiving a copyright complaint, in addition to forwarding the complaint along to the host provider.
I would think the origin IP would be needed for the hosting provider to identify their customer though? And the judge seemed pretty sure that the complainant could effectiely take it up with the hosting provider... still, there are lots of opportunities for misunderstanding here in case to judge to article to us. Not sure exactly what cloudflare will give you!
That's incorrect. Anyone can fill out the web reporting form here: cloudflare.com/abuse -- absolutely no Cloudflare account needed.
Sadly, the most they can really do (about their regular Cloudflare Proxy clients, at least) is reveal to you the unmasked hosting info of the origin site; at which point you’ve got to start another process for reporting a TOS violation to the origin’s hosting provider.
There are some methods for discovering the IP address of the origin server hidden behind Cloudflare. No guarantees but IME, many origin IPs are easily discovered.
TIL Cloudflare is also a registrar[1], Might be even the cheapest. I was wondering why the parent wasn't able to find who the site belonged to through just WHOIS and sending a abuse request to the registrar, Still Cloudflare should be forwarding the abuse report not sure what's the case here.
Can anyone tell share their experience with Cloudflare registrar? When compared to something like Namecheap? Also can different Cloudflare accounts for separate products use same credit cards for using the registration service?
By “reached out”, I assume you don't mean “filed a DMCA takedown notice and, when they failed to take down the infringing material, filed a contributory copyright infringement lawsuit seeking both damages and a permanent injunction against Cloudflare making the infringing content available.”
But I wonder why not? If there is a good reason not to, though, its probably also the reason that Cloudflare knows they can ignore you.
Cloudflare not being forced to take down content due to claimed copyright infringement seems exactly in line with protecting the internet and freedom of thought and creativity as a whole.
I'd love to know why people are against it.
They can still choose to take down copyright infringing material, but they're not obligated by power of the gun / legal / monetary / use-of-force rammifications.
Edit: disclosure: of course I'm not a lawyer, etc, blah blah.
Cloudflare has great utility that benefits a lot of us, but I think some day we will realize how much this centralization is a tradeoff that hurts the internet as a whole, no matter how cool the people are who work there.
What's the trade-off here? They protect you from DDoS attacks and it's great, vs they don't and your site goes down? I don't really understand what's being traded off here.
• They see – and usually HTTPS MitM, all the traffic. (I trust them not to abuse that… just about.)
• When Cloudflare goes down (which it does), lots of stuff goes down at once. Your redundancy is for nothing.
• Centralisation of power enables abuse of power; no matter how good you are, you will abuse your power. I (a generally well-meaning person) have relatively little power, so my small abuses basically harm nobody. Cloudflare has massive power, so its small abuses can harm tens of people each.
• Their CAPTCHA walls reduce accessibility, discriminate against Tor users, and make Cloudflare-“protected” sites unusable on a wide variety of systems. Since Cloudflare's the only Cloudflare, a webmaster who doesn't like this basically has to lump it.
Like it or not those features exist to fill actual needs from the sites Cloudflare protects.
Cloudflare's CAPTCHA is now hCaptcha, which uses Cloudflare. If you want to get an “accessibility token” (or whatever) to bypass the inaccessible CAPTCHAs, you may have to first complete CAPTCHAs.
See the strong-IP case from the Copyright Alliance, who can at best muster an "it depends":
There are some mixed messages out there about whether fashion designs are eligible for copyright protection. Some experts would say “no,” others would say “yes,” and they’re both right it depends.
https://copyrightalliance.org/education/qa-headlines/copyrig...
In the US, such protections are still only at the "being considered" stage as best I can tell:
The major amendment, of course, would be the extension of design protection to fashion designs, by amending § 1301(a) to provide that “A fashion design is subject to protection under this chapter” and by amending § 1302(b) to include “an article of apparel” in the definition of “useful articles” subject to protection.
https://www.copyright.gov/docs/regstat072706.html
As the Copyright office's discussion notes, there are non-expressive protections in the specific case of ship hull designs (also in chip masks). But fashion itself has remained largely a copyright-free zone.
The proposed language did not enter into US law as evideced at Cornell's USC server:
https://www.law.cornell.edu/uscode/text/17/1301
Cloudflare has secured this round without challenging the copyrightability of the alleged infinged works themselves, but probably also has that arrow in their quivver should they need to invoke it. The court's decision here is actually a broader protection for Cloudflare (it would apply against any infringement claim), though it doesn't invalidate the plaintiff's IMO questionable fashion-based copyright claims.
This victory adds to the impression that Cloudflare is a safe front to present content that would be taken down if hosted directly.
We understand that a "Front organization" for criminal activity isn't something to tolerate in bricks & mortar businesses - why is it allowed on the internet?
So while I don't particularly care for the wrongs of copyright takedowns, Cloudflare (or other US-based edge networks) surely shouldn't become a bulletproof legal shield for any person or company who can hide their origin?
(and Cloudflare still extend their services to the booter sites from whose illegal activities they've sold protection from! But that's not important right now...)
If you want a society where it's even possible to take down "low-hanging" content, and where physical enforcement of that takedown might span international boundaries, the legal goalposts sometimes need to move.
And I feel like if we don't help move the technical and legal goalposts in a sympathetic manner - like recognising that a caching edge proxy is part of a site's hosting setup - we end up being part of the problem & pushing governments into more draconian solutions.
(I'm not sure why the litigants in this case were targeting Cloudflare, but I assumed because they have no other idea who is hosting these infringing sites)
So e.g. what does a legislature do if internet architecture has completely hardened towards privacy, such that edge proxies, whois, Facebook or whoever don't allow some visbility into the ultimate owner/publisher of a piece of content? They legislate what they can touch - the manufacture of the devices in our hands and on our laps, or the configuration of the access networks we all have to use.
Accept that restricting the flow of information is a stupid idea.
> But here, the parties agree that Cloudflare informs complainants of the identity of the host in response to receiving a copyright complaint, in addition to forwarding the complaint along to the host provider.
I used to run a hosting company in the UK, and we have a precedent from 1996? where once a hosting company is informed of a libellous statement served from its network, it can be held jointly liable for it as publisher.
So it became quite common for UK hosting companies to take down sites on the slightest hint of a libel complaint.
And I (irresponsbibly) used to enjoy fielding these complaints, filtering out the chancers who were never going to sue, and telling them to get lost, bccin'g the customer. Legal indemnity is a nice service and our customers appreciated it.
eastdakota has done the same on a larger stage, and made more of cf's neutral, not-a-hosting-company, can't-catch-us attitude which plays well here. (and I'm not unsympathetic - except for the nazis and booters). But when cf are taking double-digit percentages of all internet traffic, they're can't & won't continue fielding every complaint in court.
They aren’t really anonymous - CF knows who they are.
> This victory adds to the impression that Cloudflare is a safe front to present content that would be taken down if hosted directly.
Not really, in the article it says that CF will notify the hosting provider of the infringing material.
Can you guess who never cut the service (but other two react very quickly)?
https://storage.courtlistener.com/recap/gov.uscourts.cand.33...
Knowing you aren't liable on the content owner side for particular content means the DMCA takedown process is irrelevant to you.
The fact that such a denial wouldn't necessarily block access to the content at the origin server is irrelevant. Moreover, the holding also inexplicably ignores the fact that many origin servers only allow access to their desired CDN anyway. This is actually a very common configuration to avoid having the origin server being DOSed.
If I were the plaintiffs, I would almost certainly appeal this ruling to the 9th Circuit - and after hiring a much better attorney.
"[R]emoving material from a cache without removing it from the hosting server would not prevent the direct infringement from occurring," Chhabria wrote.
That's just patently untrue.
A web site using Cloudflare's services isn't available to the Internet once Cloudflare stops providing services, until the site's hosting is meaningfully reconfigured.
You can't say it's just caching, because you can't access the site in any reasonably normal way via any method other than going through Cloudflare. That's just plain old bullshit.
Removing it from the cache does nothing except making Cloudflare drop it. If Cloudflare "removes material from their cache" it DOESN'T prevent any infringement, because the request will hit the main server (and possibly Cloudflare will cache it).
If cloudflare kicks them off, that's different than just "removing material from the cache" which seems to be what the argument is.
Let me add onto this, even w/o Cloudflare, that STILL won't stop infringements, as other CDN's or even no CDN can be used. It just clears Cloudflare of guilt/responsibility they may have.
> The plaintiffs did not prove that the faster website-load times enabled by Cloudflare "would be likely to lead to significantly more infringement." Additionally, Cloudflare removing infringing material from its cache would not prevent users from seeing the copyrighted images. "[R]emoving material from a cache without removing it from the hosting server would not prevent the direct infringement from occurring," Chhabria wrote.
The claim was that the caching of the copyright infringing content is an issue. Cloudflare said "that can't be the issue".
You took the last sentence of the second paragraph out of its context.