In the US, subpoenas come from the Justice Department (either state or federal depending on the crime for which evidence is being sought). The court that issued the subpoena is on it, and the person or entity being served, has the right to see why some government agency felt it could aid in the uncovering of a crime that had already been committed. The person or entity then has the opportunity to challenge that in court prior to complying with it. This is sometimes informally called "quashing the subpoena." From my sister-in-law who is a defense attorney, the most common result of challenging a subpoena is to get what it asks for narrowed down to just what is plausibly responsive.
In the article, this response: As a result we are currently developing new data retention and disclosure policies. These policies will relate to our procedures for future government data requests, how and for what duration we store personally identifiable information such as user access records, and policies that make these explicit for our users and community. Is good practice for limiting what a subpoena can request (you can't give what you don't have).
At Blekko we logged access records in such a way that we could use PII for 48 hours and then it was deleted. The CTO, Greg Lindahl, is a huge privacy advocate and this sort of architecture made it possible to get information to improve our ranking and service without compromising people's privacy. In practice I don't think any agency could go from "we have a suspect" to "issue a subpoena" in 48 hrs so it was a useful way for us to stay out of the crosshairs. The most interesting event was the FBI asking for information on IP addresses that had accessed their honeypot CSAM site. That turned out to be some of the machines in the crawling cluster. Given that the site was outside the crawl "horizon" and didn't rank (very few sites linked to it) it didn't even make it into the cache for rank analysis. But in that case the turn around time was impressive. Of course that is because they were just using their own logs to generate subpoena requests.
Watch out for smaller jurisdictions that might have “you should have expected” laws that says your 48hr window is too short.
Had a jurisdiction said, "You should have expected ..." I expect our response would have been, "We have published what we retain, me meet conform to federal and state laws you knew ahead of time we wouldn't have more than 48 hrs worth."
That said, jurisdiction when it comes to the Internet is always kind of "weird". Did you use the web service in your house in Columbus OH, or did you use the web service on a server in a data center in California? Also as I recall our TOS also had a requirement that any legal action be brought in California but I don't think we ever tested that in court.
The NSA and SS can get quite testy about it and make you wish you were dealing with the FBI.
What usually happens is the large corporation lays out a case like "yt-dlp is responsible for billions in damages" and they press the DOJ to investigate and prosecute.
[https://archives.fbi.gov/archives/news/testimony/intellectua...]
There is an applicable federal criminal law.
> Introduced in the House as H.R. 2265 by Bob Goodlatte (R–VA) on July 25, 1997
> Committee consideration by United States House Committee on the Judiciary and United States Senate Committee on the Judiciary
> Passed the House on November 4, 1997
> Passed the Senate on November 13, 1997
> Signed into law by President Bill Clinton on December 16, 1997
Before that, it would involve something like literal film, which didn’t scale well, and was too expensive and difficult for a typical person to do at home. It still happened, but was VERY niche.
With VHS/VCRs, someone could spend a couple thousand dollars and make hundreds of bootleg copies of any blockbuster video out there from their garage, and it was easy to literally go to Blockbuster(tm) and get an copy to duplicate without being tracked. Easy money. Folks would sell them out of the back of (literally) vans, or through friends, or via flea markets, etc.
It’s still super prevalent in Asia, using DVD/Blu-ray’s.
In the US, it then eventually got applied to the internet, because it was even easier and more scalable using computers, and harder to track down the culprits.
It’s all about money in the end of course.
> "Records of all Python Package Index (PyPI) packages uploaded by..." given usernames
> "IP download logs of any Python Package Index (PyPI) packages uploaded by..." given usernames
I don't think they'd want a list of packages uploaded by a given user if they were after yt-dlp devs. They'd be asking for a list of maintainers of a given package.
You are wrong.