Gpt4free repo given takedown notice by OpenAI
github.com
github.com
It seems this gpt4free was basically hijacking 3rd parties services that use GPT-4, bypassing the official OpenAI APIs in order to avoid paying for inference. Of course, that means that the hijacked 3rd parties are the ones footing the bill...
I'm not surprised they have been issued a takedown notice.
A bit like we are footing the bill for openai's training data.
They were referring to the fact that everything ChatGPT is built on is other peoples work. Beyond the actual building of the model details, there is nothing that ChatGPT owns. All the content they use to train, all of the art they use to train. Everything is stolen/used without permission. Obviously there is more to it than that, because you published it on the internet. But that's a different topic.
ChatGPT-4 is built on real peoples time.
Strangly enough, it's only interested in promoting permissionless innovation when it stands to profit. It plunders the commons, and gives nothing unencumbered back.
All intellectual property is inherently stolen. Just let it go.
I don't see any world where it matters in the slightest. When it comes to how we deal with currently available training data nothing will change, first because of politics but also because people want the LLMs superpower more than they want to protect IP of a few individuals. And I firmly believe that no human training data that has not been produced and publishes today will play any significant role in future AI development.
We are simply too slow.
I'll bet if someone outside of our IP jurisdiction figured out a way to reliably and thoroughly reverse engineer the most complex commercial software from binaries so people could spit out a working, fully-customized copy of a commercial application from a prompt, and the entirety of the software development market would soon collapse, the tenor of this conversation would be very different.
Maybe the people with the very ethically defensible stance that private property is theft would be totally fine with OpenAI knocking down your home to build their new headquarters without compensating you? Imagine the progress! (hint: they probably wouldn't be ok with it)
None of this stuff exists in a vacuum. None of it.
But no matter how I or anyone else feel about the car or how bad it is for the environment, or how much we dislike the noise they impose on us, it's simply not going to bring back the horse.
There just is no conceivable future. It's dead.
Beyond that, the technology is just the catalyst. It's a tool. The problem is what people are doing with it. That's an ongoing behavior that can be changed-- not a bell you can't un-ring.
I won't claim to know what's in your head, but most people I've encountered who rebuff complex topics with idealistic platitudes don't really think the topics are that simple. They're avoiding confronting the negative consequences of a behavior they have no intention of changing to avoid damaging their moral self-image.
Artists are already starting to completely paywall their content.
How far do we let AI scraping and incorporation go? Just say "fuck it" until there's nothing left to scrape other than content also made by AI?
>Just say 'fuck it' until there's nothing left to scrape other than content also made by AI?
Sounds good to me! There will always be people making free art, and AI will make this much easier.
The thing that I think people are missing is that AI-generated content CAN be used to improve AI models. There is no requirement that the input data is created without AI.
Furthermore, AI-generated content on the internet is not random; it is curated content. Generally speaking people don't post every image they generate with Stable Diffusion, they only post the best images. If you consider engagement metrics and user feedback (upvotes etc), they can be a valuable and useful part of a training set.
I fear our views on this issue are wholly incompatible.
My concerns mostly lie with the fact it's owned largely by $MSFT rather than a more "open source" contributing to society entity. But again that's a much different topic.
It shouldn't have a place, but so long as people require the ownership of their own concepts to gain food and shelter, it has to.
I am all for training AIs, but at least exhibit some self-consistency in your arguments!
Your argument is a reductio ad absurdum to "everything is made of atoms and no one ones atoms, ergo no one owns anything."
That's news to me.
Now that doesn't mean you can't license your work for exclusive use by humans and explicitly forbid AI training data in the license applied to your work, but you'd have to do that when you publish it, not retroactively.
However, if AI ends up being as mainstream as the average HN user is claiming, are you sure you aren't shooting yourself in the foot to not have your brand and product info not included in that data set if it replaces search engines?
Is it any different from a Google crawler? They put ads on your content on the SERPs after crawling it.
Eh?
> I've never been billed.
Curious how much people's bills are inflated by ai crawlers constantly sucking their data and how much in revenue is lost since traffic is not brought to their websites. And since there's no way to stop this theft, since most of them don't honor robots.txt, people are forced to remove content. Perhaps those charged for bandwidth are losing some dime right now.
It's the punchline of a vaguely racist old joke involving Lone Ranger and Tonto. I have to admit that I also often think of when somebody uses "we" inappropriately to make their opinion or experience appear universal.
(But as seen here, you can't really just drop the punchline into a conversation.)
What specific US laws do folks think that repo (or running/using the software in that repo) might have been violating? (I agree it seems likely that it's _some_ law, I'm not challenging that just asking if anyone has a legal analysis they want to share).
[0] https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
In theory, they could probably use DCMA to go after anyone using the terms (right or wrong). In practicality, they used it as a tool to go after this particular one because they didn't like what they were doing.
Although, after digging into the story, it looks like they may have also operated an illicit app store containing cracked IPs, so that situation is a little murky.
[1] https://www.nintendolife.com/news/2023/04/nintendo-hacker-ga...
However, this is on Github. Github specifically has a "DMCA Takedown Policy" [1]. I don't believe they have any other policy or procedure involving a "takedown notice". But sure, I could be wrong, or the notice on the repo could be not quite right about what's going on.
Other companies, even big ones, will just take down anything a big corporation asks them to, with no written policy or a written policy basically saying that's what they'll do, while using language implying the DMCA (like "takedown notice"), when that's not what they're doing at all. But Github has actually been pretty good at actually doing this according to the procedure spelled out in DMCA, and not just randomly for whatever another big corporation might want. And being clear about what they're doing why if they're doing something else.
[1] https://docs.github.com/en/site-policy/content-removal-polic...
> We got a takedown request by openai's legal team...
Did Github take a separate action somewhere?
> Xtekky initially told me that he hadn't decided whether to take the repo down or not. However, several hours after this story first published, we chatted again and he told me that he plans to keep the repo up and to tell OpenAI that, if they want it taken down, they should file a formal request with GitHub instead of with him.
> "I believe they contacted me before to pressurize me into deleting the repo myself," he said. "But the right way should be an actual official DMCA, through GitHub."
https://www.tomshardware.com/news/openai-sends-shutdown-lett...
I do imagine OpenAI has something in their terms where you're not allowed to use their APIs unless you agree to their terms, which includes payment and not using other accounts than your own (fraud). So maybe that's it?
Here's the project description from the README:
Have you ever come across some amazing projects that you couldn't use just because you didn't have an OpenAI API key?
We've got you covered! This repository offers reverse-engineered third-party APIs for GPT-4/3.5, sourced from various websites. You can simply download this repository, and use the available modules, which are designed to be used just like OpenAI's official package. Unleash ChatGPT's potential for your projects, now! You are welcome ; ).
Source: https://github.com/xtekky/gpt4free/blob/6719bee133ce8202129e...That's a great reason for it to go somewhere.
You have to run the code to violate the terms of use, which is primarily used to bar you from the service for misusing it.
You are protected in your speech from the government. Commercial law does and will still apply. Arbitrary company decisions happen all the time, and GitHub makes it clear that they won’t refrain from deleting repos for whatever reason.
Yeah in all seriousness people trot out perceived constitutional infringements about 500x times more than it actually happens.
You are actually very protected in documenting security flaws, and even republishing them.
I am unsure of who you think enforces laws... as far as I know OpenAI doesn't have their own police force yet.
They can sue you of course, but they generally can't demand compliance with takedowns in this case without first going to a judge and requesting a court order.
There is no "commercial law" unless you mean UCC.. which doesn't apply here.
Hint, that C letter is important!
But idk because i'm not a lawyer and we have copyright and ip laws so clearly congress can pass SOME laws that prohibit speech. Free speech absolutism is weird to me
However, this seems more like an issue of corporate policy than law.
Github needs to have some policy that ends up with them taking down repos that actually host illegal content, they don’t have any legal obligation to host files, so they can respond to takedown notices by just taking down the files. This wouldn’t be the government forcing them to take down files, it would be them deciding not to try and parse the law very closely. But this is different from having an area of law where the constitution doesn’t apply, and it bears repeating, because the constitution is really important and the idea that there should be some sort of cutout where it doesn’t apply is bad for society.
Something we should grapple with as a society is whether poorly written, ambiguous laws should be interpreted as the government taking action by essentially forcing companies into be over zealous in their corporate policy.
So? That’s not what the first amendment applies to. You do not have first amendment rights in civil cases. This is not “an idea”. It’s just how it is. See libel.
> So? That’s not what the first amendment applies to.
Yes it is.
> You do not have first amendment rights in civil cases.
Yes, you do; that’s why US defamation law is more limited than the common law it derives from, and where Fair Use as a judicial application of the First Amendment came from before it was codified in statute.
> See libel.
Libel is a perfect example of how you do have First Amendment rights in civil cases. Here's a long list of cases applying the First Amendment in the libel/defamation context:
https://www.mtsu.edu/first-amendment/encyclopedia/case/63/li...
...is the government.
In theory. In practice we see in the Twitter files, the new rule is that government agencies are free to send takedown requests to social media platforms for speech that disagrees with our (abhorrent) foreign policy.
Where in the Twitter files did it show that social media platforms would be punished with jail time or violence or anything if they refused to obey the government's orders?
Because unless you can demonstrate the government was putting a gun to Twitter's head and would not take no for an answer, that isn't a "new rule" it's literally just the government making a request. Which they and anyone else is and has always been allowed to do. And which social media platforms have sometimes refused without reprisal. I mean, I see speech that disagrees with American foreign policy all the time on social media. No one's being sent to the camps for it. It doesn't even get censored.
Not to mention that the requests constituted a gross 1st amendment violation.
IAAL and am unaware of any case law that holds that the mere act of requesting material be removed from publication is a First Amendment violation.
Do you have any case law to cite?
> GitHub makes it clear that they won’t refrain from deleting repos for whatever reason.
What actions or speech do you think Github has taken that makes that clear?
In general, I have seen Github stick to only taking things down according to the actual DMCA law, more than most companies that take things down pretty much whenever anyone asks them to.
Github has a DMCA Takedown Policy [1], that is better than most companies. Most companies policies -- if they even transparently publish them at all, which they often don't -- go well beyond what the DMCA requires in what they will take down. Compare to eg YouTube [2], which isn't really using a DMCA process at all, doesn't really have a transparent policy at all, and does not allow you to counter-notice. Github's policy is way better than most; but maybe there are occasions where they have been known not to follow their own policy, is that what you're saying?
From what I've seen, github has actually made it much more clear than most companies that they won't just randomly take things down for arbitrary reasons, but have a clear and transparent policy based on the DMCA. But maybe there are things I don't know.
In this particular case, though, someone else pointed out to me in another part of this thread -- it's not totally clear Github is even involved. From the text on the repo, it seems possible that OpenAI contacted the repo owner directly, and the repo owner decided to change the text of the repo README to say that, and that may all that has happened? If Github had actually done a "takedown" according to their usual procedures, I think the repo wouldn't be there anymore? But it's not really clear what's going on, or even what the repo owner _claims_ is going on, unless we have more info than appears in the linked repo README. It's not currently clear that Github is involved at all.
[1] https://docs.github.com/en/site-policy/content-removal-polic...
[2] https://www.eff.org/issues/intellectual-property/guide-to-yo...
Github has deleted Iranian / Russian / etc. Repos before purely for political reasons. GitHub belongs to Microsoft, and Microsoft has a stake in OpenAI. Seems like a reason to me.
I don't like the US law much either, personally. I just don't consider a US corporation complying with US law to be a demonstration they will do arbitrary things for "any reason", it's sort of the default I expect from corporations and very predictable. If there's an example of a US corporation that chose to intentionally violate those sanction laws as an ethical stance, I'd love to find out more about that, and the outcome, too! I would imagine they would be penalized by the US government.
Microsoft was in fact recently so penalized [4], but I don't think it had anything to do with github, and I definitely don't think it was an ethical stance, just a mistake/profit-motivated one, or because these laws are a mess and hard to comply with. But I expect US corporations to try to comply with US laws, and don't consider doing so to be arbitrary or unpredictable "any reason".
[1] https://www.zdnet.com/article/github-starts-blocking-develop...
[2] https://github.blog/2019-09-12-global-software-collaboration...
[3] https://techweez.com/2022/04/18/github-suspending-accounts-r...
Bank of America used it to make people who simply changed the account number in their URL bar the criminals instead of them, who were completely incompetent at securing access to their customer's accounts. What previously would have been arguably criminal negligence.
It placed intent above competence - but only for those who can afford lawyers.
And here it is again, being abused the same way.
Hot take: It should be repealed completely.
(Somewhat tangential, the "networks as a 3D space you travel around in with locations you visit" analogy does more harm than good. It's not what's happening and it results in muddled thinking.)
[1] https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
Calling it illegal is utterly insane. It’s just a different user-agent and they’d prefer people use their official ones. OpenAI literally controls the keys so if they don’t want someone using an alternate mechanism, they can and will just ban the account.
Knowingly using a private API without authorization can fall under CFAA, contract law, copyright law, trespass to chattel, etc -- and you can issue a C&D and/or sue for whatever is relevant.
https://en.wikipedia.org/wiki/Goatse_Security#AT&T/iPad_emai...
https://www.praetorianprefect.com/2010/06/114000-ipad-owners...
And CFAA is limited by Van Buren.
If someone bypasses authentication I understand but if your api is open on the public internet on purpose, you don't get to randomly declare what's private and what isn't.
Whoo whoo, go easy on the straw man, man.
Actually, the law says that the Terms of Service is a legally-binding contract unless you can prove any provision is legally considered unconscionable. However, if that happens, all provisions except that provision still bind. It is illegal to break a legally-binding contract, and you can be sued or taken to arbitration at a minimum in a civil court for "breach of contract." And that's before any Computer Fraud and Abuse Act or Digital Millennium Copyright Act violations.
Yes, corporations don't sue users for "breach of contract" almost... ever. It's expensive, risky, has low compensation for doing so, and is just bad PR. But they legally always can.
But then of course... CFAA and DMCA. The DMCA in particular, for example, doesn't consider the strength of the lock in the criminality. DVDs can be cracked with 7 lines of Perl since 2001, but it's still a DMCA violation.
These aren’t reverse engineering the OpenAI API, they are reverse engineering the APIs of public services that in turn call the OpenAI API.
I’m not sure under what theory OpenAI would even sue.
> But then of course... CFAA and DMCA. The DMCA in particular, for example, doesn't consider the strength of the lock in the criminality.
The DMCA only applies to technology addressing copyrights, and CFAA seems inapplicable to consuming the backend APIs used by publicly accessible services because that’s just use of authorized access by a different manner, outside of CFAA scope under the Van Buren precedent.
No, it doesn’t.
It says they can state the terms of a contract if all the requirements of contract formation have been met, which are more than just the absence of unconscionable terms.
It's amazing how the repo phrases this like "having an OpenAI API key" is something that's gatekept, rather than something you get by making a free account. (You may not be able to use it, but the more honest phrasing of "don't want to pay for your own API usage" is apparently too transparent for what this is offering.)
I’m not saying this makes the above repo right, but it is gatekept.
And is this a DMCA takedown? It's not actually specified in the readme update and I would have thought that the repo would have been hidden by now if it was one. Plus I'm not sure what they'd be claiming copyright on here (the API maybe?)
Gpt4free uses API vulnerabilities that ultimately proxy to OpenAI's API with someone else's OpenAI credentials so that you don't have to pay for it. That's the whole gimmick.
These API endpoints aren't public service open relays which seems to be what you're trying to claim in your analogy:
The whole point of the project is that they are. It's a compilation of public, free APIs that have been found. Those issues you linked are from people who don't understand that it's expensive to run a free relay for a paid service.
When you're so loose with words, it's impossible to even have a discussion.
https://github.com/xtekky/gpt4free/issues/153
ora.sh takedown request #125
We got a takedown request by openai's legal team...
here is a lil poem you can read in the meantime, while I am investigating it:
A little boy sat, in his humble abode.
He tinkered and toyed with devtools galore,
And found himself curious, eager for more.
He copy-pasted requests, with glee and delight,
A personal project, to last him the night.
For educational purposes, and fun it was too,
This little boy's journey had just begun anew.
Now far away, in a tower so grand,
A big company stood, ruling the land.
Their software was mighty, their power supreme,
But they never expected this boy and his dream.
As he played with their code, they started to fret,
"What if he breaks it? What if we're upset?"
They panicked and worried, their faces turned red,
As visions of chaos danced in their head.
The CEO paced in his office so wide,
His minions all scurrying to hide.
"Who is this child?" he cried out in fear,
"Who dares to disrupt our digital sphere?"
The developers gathered, their keyboards ablaze,
To analyze the boy's mischievous ways.
They studied his project, they pored through his code,
And soon they discovered his humble abode.
"We must stop him!" they cried with a shiver,
"This little boy's making our company quiver!"
So they plotted and schemed to halt his advance,
To put an end to his digital dance.
( I did not write it )
discord: https://discord.com/gpt4freeOpenAI issues DMCA to GitHub, GitHub passes it along to the user, user... has the right to ignore it and leave all of the content up and update the README with a poem?
But this may be some other C&D, the repo owner says they got a “takedown” without mentioning DMCA; there is no reason to assume this means Github got a DMCA notice.
Just because there is a way to obtain a resource doesn't make it yours automatically..
Is is entirely impossible to imagine a culture where walking unbidden into private property is very normal but pinging someone electronically without a common understanding is an intrusion?
It's more like having a tap with a sign over it saying "free gas", then getting mad when people use it.
This was ~2 months ago, and I'm fortunate enough to have a direct contact at OpenAI who I complained to. He came back promptly and told me it was a mistake and the takedown notice was retracted. I also changed the twitter bot's logo to be purple instead of green to avoid future issues.
What Exceptions Does DMCA Section 1201 Have To Allow Reverse Engineering?
Section 1201 contains an exception for reverse
engineering, as well as security research, encryption
research, and the distribution of security tools, all of
which may support reverse engineering. However, these
exceptions are drafted very narrowly. If your research
might implicate section 1201, consult a lawyer to see if
you can do your work in a way that is allowed by one of
the relevant exceptions or by an exemption periodically
granted by the Copyright Office. The following factors
are relevant to whether you are entitled to a reverse
engineering, research or security exception. However,
meeting any or all of these factors will not necessarily
protect your work. The list is offered just to give you
an idea of the kinds of things that distinguish
permissible from impermissible reverse engineering:
You lawfully obtained the right to use a computer
program;
You disclosed the information you obtained in a good
faith manner that did not enable or promote
copyright infringement or computer fraud;
Your sole purpose in circumventing is identifying
and analyzing parts of the program needed to achieve
interoperability;
The reverse engineering will reveal information
necessary to achieve interoperability;
Any interoperable program you created as a result of
the reverse engineering is non-infringing;
You have authorization from the owner or operator of
the reverse engineered software or the protected
computer system to do your research;
You are engaged in a legitimate course of study, are
employed, or are appropriately trained or
experienced, in the field of encryption technology.
You provide timely notice of your findings to the
copyright owner.
https://www.eff.org/issues/coders/reverse-engineering-faq#fa...https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A...
On the other hand, it contains some traps that can be used to put some limits back in, such as the last lines here: (emphasis mine)
"(15) The unauthorised reproduction, translation, adaptation or transformation of the form of the code in which a copy of a computer program has been made available constitutes an infringement of the exclusive rights of the author. Nevertheless, circumstances may exist when such a reproduction of the code and translation of its form are indispensable to obtain the necessary information to achieve the interoperability of an independently created program with other programs. It has therefore to be considered that, in these limited circumstances only, performance of the acts of reproduction and translation by or on behalf of a person having a right to use a copy of the program is legitimate and compatible with fair practice and must therefore be deemed not to require the authorisation of the rightholder. An objective of this exception is to make it possible to connect all components of a computer system, including those of different manufacturers, so that they can work together. Such an exception to the author's exclusive rights may not be used in a way which prejudices the legitimate interests of the rightholder or which conflicts with a normal exploitation of the program."
To clone from this:
wget https://web.archive.org/web/20230428163410embed_/https://litter.catbox.moe/gc4o73.bundle
git clone gc4o73.bundle gpt4freeAnd developers can use their time much more productively to improve one of the many open source alternativez
Is "work" defined anywhere by law or by precedents? I just genuinely don't know. It seems to me that depending on that, the OpenAI API might be considered "work" just like a copyrighted manuscript. I'd also think there must be some other laws forbidding hacking, but DMCA must have a fast track everywhere.
This is gold and crucial for democratization of AI tools.
But as for your comment, i see it rather as opportunity to make it only with Opt-in by the companies themselves. That way it will actually make it even win-win situation for them for Marketing and Ads (with lower price).
Security researchers put a lot of emphasis on responsibly disclosing vulnerabilities. The maintainers of this project could have easily done the same, but they didn't
Thank you OpenAI for playing a role in me finding an alternative!
It's still available on github.
Just that people keep obnoxiously naming their projects after them for visibility.
Imo this is exactly how this kind of polite takedown should be used. If it highlighted it to you great because at least you know for sure it's not OpenAIs product.
gpt4free means "gpt for free" and also predates GPT-4. I don't think it was meant to be obnoxious or cause confusion.
But it's clear and obvious to me that they saw GPT2 then GPT3 and thought well let's pun on it with GPT4.
First line of the wiki you link
> Generative pre-trained transformers (GPT) are a family of large language models (LLMs),[1][2] which was introduced in 2018 by the American artificial intelligence organization *OpenAI*
Emphasis added.
GPT4Free is an API reverse engineering and proxy project which exposes an API to use GPT4 by proxy through GPT4 based services like the search engine Phind.
Essentially you are using the reverse engineered services OpenAI credits to access GPT4 instead of using your own OpenAI account.
For those ootl, here's the previous thread where OP was given a lot of advice from the HN community to change the name https://news.ycombinator.com/item?id=35608437
GPT4Free is an API reverse engineering and proxy project which exposes an API to use the real GPT4 by proxy through GPT4 based services like the search engine Phind.
To the CrabLang folks,: this is why you care about trademarks. So when someone does this you can protect your project from scammers.
EDIT I might be conflating GPT4all with this… which doesn't make the situation any better and kinda proves my point. This type of scam is confusing and deceptive. And this one seems actively malignant.
Yes but often FOSS projects and their developers do not have the money or desire to: enforce any trademark or license, apply for the trademark itself, or market the trademark in any meaningful way.
https://theholmesfirm.com/takedown-notices-why-trademarks-an...