The SymPy/HackerRank DMCA Incident
asmeurer.com
asmeurer.com
> It’s important to understand, however, that GitHub’s hands are tied in many ways here. If they do not follow the notice and counter notice procedures exactly as outlined in the DMCA law, they risk losing their safe harbor status with the US Copyright Office. Were this to happen, it would be completely disastrous to GitHub as a business.
I believe this is a bit of an exaggeration, because there is no such thing as "safe harbor status with the US Copyright Office". (The author might be thinking of the fact that providers have to register a designated agent with the Copyright Office, for service of infringement reports, in order to benefit from the law.)
The DMCA safe harbor is a legal defense against copyright infringement, and it operates on a case-by-case basis. If GitHub fails to respond to a particular takedown request as it's required to, it loses the ability to assert the safe harbor defense for the allegedly infringing material identified in that request. It does not mean it somehow loses the DMCA protections for any other material that it hosts.
In practice, this means that GitHub employees can make mistakes, or the company can deliberately choose to stand up to superficially-valid DMCA takedowns that it thinks are frivolous, without necessarily posing an existential risk to the entire company.
We all seen the Oracle vs Google lawsuit... sure they can choose to stand up to frivolous DMCA takedowns, but it doesn't means there won't be a frivolous lawsuit that follow.
It just not worth it, why takes that risk when taking something down protect you from it?
I mean, that's clearly the stance that most platforms are taking.
The "why take that risk" would be -- to stand up for your user's rights or interests, against takedown requests that are frivolous or invalid. Github actually has occasionally taken that stance.
@teraflop's point is that a company can choose to take that risk on a case-by-case basis -- say in cases you think are especially frivolous and thus also especially unlikely to be a legal liability -- and the risk borne is only with regard to that case, it does not imperil the ability to use the DMCA safe harbor defense in other cases.
(Github seems to be unusual in having already decided to take that risk a couple times on a case by case basis, I think? They can be commended for it, and encouraged to do it more, or have transparent standards for when they will do it, or whatever).
(Note that in the USA someone can file a frivolous lawsuit against you anytime. In this case, even if you respond to all takedown requests there's certainly no guarantee someone can't file a frivolous lawsuit against you anyway. It just shouldn't get very far, and will get thrown out quickly, if things work right, which certainly sometimes they don't, unjust things happen).
https://en.wikipedia.org/wiki/Viacom_International_Inc._v._Y....
https://en.wikipedia.org/wiki/Google_LLC_v._Oracle_America,_....
In practice, the complainant probably finds it more cost-efficient to (0) ignore your counter-notice, and (1) refile their original complaint, unaltered, restarting the DMCA process from zero. If GitHub reinstated your work, they'll simply take it right back down again, like a yo-yo.
Much cheaper than lawyers.
https://github.com/github/dmca/search?q=TheRayTracer
This is what the process looks like when you're not HN-front-page support tier.
(I'm not affiliated with these parties; I stumbled on this set of DMCA interactions while reading the previous HN story last week).
[1] https://github.com/github/dmca [2] https://github.com/github/dmca/blob/master/2022/03/2022-03-1...
I suppose they could take this a step further by making students sign a confidentiality agreement for assignment solutions, which is legally stronger than a honor code agreement. I won't be surprised if this becomes a thing in the future.
Some DMCA claims do indeed mention "The repository [from the student] contains code provided to complete assignments [georgia tech]" ([1]). But the claim at [2] does not mention this. It only says "This repository contains Georgia Tech class assignment solutions." under the section "Please provide a detailed description of the original copyrighted work".
[1] https://github.com/github/dmca/blob/master/2022/04/2022-04-0...
[2] https://github.com/github/dmca/blob/master/2022/03/2022-03-1...
The mind game is: The assignment is most likely produced with a solution, but published without (lets say else it would not be 'assignable'). For deterministic solutions, could you copyright it without publication?
> I am part of the Georgia Tech [private], and I have found code solutions for a class at Georgia Tech. Whenever student turn into their code assignments they agree to the Georgia Tech Honor Code stating they are not cheating or allowing others to cheat by sharing Georgia Tech’s assessment materials. The assignment materials were provided to students so that they could complete their tasks and isn't to be shared with others.
Some teachers might check for plagiarism but it's not hard to make enough changes to any body of code to make something like a diff test in an automated submission pass. Automated solution testing seems to be the norm in computer science courses as well, so it has become relatively easy for students to pass courses with good grades using this approach. There are some ways to avoid some of this, for example having in-class tests where students have to write code out with pencil and paper under a time limit while being observed, but that's only part of the grade usually.
"I have a good faith belief that use of the copyrighted materials described above on the infringing web pages is not authorized by the copyright owner, or its agent, or the law."
and
"I swear, under penalty of perjury, that the information in this notification is accurate and that I am the copyright owner, or am authorized to act on behalf of the owner, of an exclusive right that is allegedly infringed."
This takedown does not seem to have been in good faith or accurate, if only because of the following:
> The notice also stated “the infringing website is not willing to remove our client's work”, which came as a surprise to us since, at no point in time prior to receiving this notice had we received any communications from HackerRank or WorthIT Solutions.
Are there any consequences against whomever at WorthIT signed the DMCA request? If not, how come?
[1]: https://law.stackexchange.com/questions/51541/has-anyone-bee...
If you choose to forego the entertainment therein, the TL;DR is essentially that the time and cost of pursing a case, and enforcing it, means that the threat is worthless as a counter-balance.
They do seem to be given the benefit of the doubt, which is fine, but if they're not pushed towards improving their automation its just going to stay a nightmare for everyone else.
I’ve never used HackerRank but this made sure I will never use them in the future.
> They need to be sued with the help of NumFOCUS lawyers.
This seems like it could be costly and quickly easily eat away at the small amount of revenue they take in (something like $5MM, mostly from grants and donations) compared to supporting open source projects that are desperate for support.
Notice in the words of the CEO how he still doesn't think it's wrong to submit takedowns to code they don't hold any copyright over. At least he's honest about his bad intentions, so that's better than the drivel some tech companies come up with when they reach the front page of HN.
These guys are exactly what's wrong with copyright law and nobody has the time, interest, and resources to fight them.
The damages in this case are probably less than $25K.
I mean there should be given the amount done on e.g. youtube, but if you obviously don't own copyright on something, it'll be considered malicious and you'd get prosecuted yourself.
In theory yes, in practice no
I feel like it's important to raise the volume of this statement. Just how often does the "we will donate to X for our mistake" promises blow over? Inversely as frequently as is required for PR upkeep, most likely (and given that nobody keeps tabs on this: they always blow over).
We desperately need more DMCA countersuits. There is currently no practical downside for filing fraudulent claims (irrespective of what legal downside should exist). If SymPy/NumFOCUS are in the position to retaliate, I really hope that they do.
(1) abusing the DMCA (2) lying in the DMCA message
I want that HackerRank is made an example and that this sets a precedent for all other DMCA trolls. Please follow through with this for all other open source projects that can be targeted the same way.
Lawsuits are a mediocre vehicle for channeling rage.
Realistically (though I'm no lawyer), the $25,000 they've already accepted is far more than a court would plausibly award them, for the tangible damage of half a day's downtime on GitHub.
Often they can even be zero. I had a district attorney send me a very rude letter recently (under non-disclosure) saying that he didn't give a fuck if I won a case against the county because he loses cases all the time. He said that even when he loses he gives zero shits because he'll get in front of the jury when it's time to figure out damages and paint the plaintiff as such an asshole that the jury will award zero damages. I believe him.
And it was a real e-mail... Great way to train your customers to be phished in the future, GH.
* PayPal's links go to paypal-communication.com
* 3DSecure, where random third party web sites ask for bank credentials
* Some banks call customers without being able to meaningfully accept a callback, with negative consequences if you don't react to their call
I've used it to pre-screen candidates with very basic code questions. It filters out a lot of people who are either lying or just don't believe they will have to ever write any code.
This allows me to consider a much wider range of candidates outside top tier schools and employers.
Getting the perjury clause of the DMCA upheld would of course have a chilling effect on sending take-down notices in such a frivolous manor.
Disclaimer: a) I am not a US citizen b) TGIANAL
Keeping in line with your analogy, I mean.
I definitely won't tell you guys to copy the orignal HackerRank questions and solutions to other self-hosted git services once in a while
The affected content was the documentation of opensource projects, which is not even something they own.
That in itself should be illegal.
Hats off to Vivek.
However, I still think it's a damn shame that HackerRank needed such a high-profile incident before reconsidering their shady arrangement involving probably-automated DMCA takedowns against GitHub repositories. Either they didn't know what that would incur on open source repositories hosted on GitHub and other platforms, or they just didn't care about it as long as it wouldn't cause a huge fuss for themselves (which it did in this case).
As a YC backed company, it seemed like almost everything on HackerNews was known about within the company when I was there.
This could just be another case of a problem being solved by hitting the news and making enough waves.
Sure they did the right thing, but it was still their active wrongdoing and I won't attribute their reaction to them being decent people. I'm tired of all the DMCA abuse, and reverting it for once isn't worthy of special praise. It makes HackerRank better than other DMCA abusers, but DMCA abusers they still are.
To me it looks like a well calculated PR action. I'll change my mind when they make it up to other teams they wronged.
It felt like many on HN didn't buy it either, and it is a pattern seen so often with many a company.