It also sets a pretty worrying precedent. What is the advertisers start claiming uBlock Origin messes with their copyright?
It also sets a pretty worrying precedent. What is the advertisers start claiming uBlock Origin messes with their copyright?
The question is: Is it really DRM if they provide access to google for free? After all, this is the loophole that these addons use. They pretend to be a crawler, or they block some kind of javascript the bots don't parse.
"Article 6 of the Copyright Directive requires that Member States must provide 'adequate legal protection' against the intentional circumvention of 'effective technological measures' designed to prevent or restrict acts of copying not authorised by the rightholders of any copyright."
More here: https://en.wikipedia.org/wiki/Information_Society_Directive#...
Ok. Mozilla is in the US, so they are choosing not to host this as hosting it may cause them to be violating the DMCA and subject to criminal prosecution.
> Is it really DRM if they provide access to google for free? After all, this is the loophole that these addons use. They pretend to be a crawler, or they block some kind of javascript the bots don't parse.
That's pretty clearly working around the intent of the access controls, yeah.
Is it? Youtube-dl had the following argumentation [1]:
For a subset of videos, YouTube employs a mechanism it calls a "signature." Here is our understanding of how it works: when a user requests certain YouTube videos, YouTube's servers send a small JavaScript program to the user's browser, embedded in the YouTube player page. That program calculates a number referred to as "sig." That number then forms part of the Uniform Resource Locator that the user's browser sends back to YouTube to request the actual video stream. This mechanism is completely visible to the user simply by viewing the source code of the player page. The video stream is not encrypted, and no secret knowledge is required to access the video stream. JavaScript is a ubiquitous technology found on millions of websites and understandable by numerous software programs. Any software capable of running JavaScript code can derive the URL of the video stream and access the stream, regardless of whether the software has been approved by YouTube. To borrow an analogy from literature, travelers come upon a door that has writing in a foreign language. When translated, the writing says "say 'friend' and enter." The travelers say "friend" and the door opens. As with the writing on that door, YouTube presents instructions on accessing video streams to everyone who comes asking for it.
Why shouldn't this apply to this addon? They are not decrypting anything, they don't have secret knowledge to access the article and plaintext JS is anything but unreadable bytecode. If you can merely change your referrer to "facebook.com" or your user agent to "googlebot" to get the article text, then it is hardly any serious DRM. This addon is NOT sharing cookies or using stolen logins. If publishers really wanted to stop people from freely accessing the articles, they could just make a login-wall or token-validation like the German publishers spiegel.de, bild.de etc.And yes, ROT-13 wouldn't be an adequate protection either.
[1] https://github.com/github/dmca/blob/master/2020/11/2020-11-1...
Bypass Paywalls Clean is, by definition, solely to subvert paywalls and thus copyright.
youtube-dl is a general purpose YouTube video downloader. You are not working around any access controls, since the videos are free and available on the web. Furthermore, you could use it to download a video you yourself created, or you were granted explicit permission to download. Just because it happens to work for copyright-protected videos is not relevant, since the tool is not specifically for working around copyright.
A soft paywall that can be removed by modifying HTML elements on a page doesn't seem like an actual control for copyrighted material, since the server has already provided you the entirety of the copywritten work and it exists on your computer in plain text (within markup). That they're choosing to do that is on them. I am lawfully accessing their website and how I interact with the local copy of data that they send me is 100% my business as long as I'm not redistributing it.
The thing is, a lot of us here have the understanding that "encryption equals technical protection", and that's not quite true. The law was drafted to talk about any sort of copyright enforcement mechanism, not just ones that employ cryptography. For example, we could imagine a legal argument in which the Linux linker's license check[0] is considered to be a DMCA 1201 technical protection measure, and proprietary modules that lie about their license[1] or modules that wrap proprietary code[2] would be considered circumvention tools.
If you're thinking, "wait, Linux is GPL, the courts should interpret that to override any spurious 1201 claims"... well, version 2 didn't explicitly mention the DMCA, which was signed a good decade after GPLv2 was released. Version 3 fixes that by explicitly saying none of this code is a DMCA 1201 technical protection measure. But this is Linux we're talking about. Linus Torvalds views the TiVo clause as changing the deal, which he does not want to allow, so they're never relicensing to v3, and so this legal argument can still stand.
And yes, advertisers have already used this legal theory to harass uBlock Origin. This is specifically why they don't block paywall enforcement scripts. The developers were threatened with a 1201 suit if they didn't back down.
There's other examples of things which could be retroactively turned into DMCA 1201 circumvention devices as well. Remember those old right-click scripts that yelled at you if you tried to open the context menu? Well, the purpose of blocking that was to keep you from copying the content on the page, which under this legal theory makes it a DMCA 1201 circumvention device. Doesn't matter if it's hilariously easy to disable, or if browsers already disable it. If copyright owners can just will technical protection measures into existence, rather than them being very specific and obvious things like media encryption or software license keys, we're screwed.
[0] When loading a kernel module, Linux checks a license string field. If the license is not a GPL-compatible one, the linker will refuse to resolve "GPL-only[1]" symbols for that module, and it will also mark kernel bug reports as "tainted", i.e. "please don't bother LKML about it unless you can repro it without proprietary code in kernel space."
[1] Linux ships with a special GPL exception that says that the user-space API does not trip GPL copyleft. So the symbols that proprietary modules are allowed to access are ones that are equivalent to user-space.
[2] One particularly egregious example was to store nulls in the license string, e.g. "GPL\0 for everything in the GPL folder" (which was empty).
[3] e.g. NDISWrapper