Publishers carpet-bomb IPFS gateway operators with DMCA notices
torrentfreak.com
torrentfreak.com
Since I wrote the post about the DMCA takedown notices the other day, someone kindly offered to provide alternative hosting for hardbin.com that should be more resilient to bogus DMCA takedowns, so happily hardbin.com is back online (but not operated by me any more).
Also I emailed Sean Lang (the guy with the github repo with dozens of example DMCA emails from these guys) and it turns out that in the last few months he also took his IPFS gateway offline because dealing with the takedowns was too much trouble.
I was able to stay on top of the takedowns by writing a script to create & deploy nginx block rules for each URL in the DMCA emails. Obviously I had no time for manual review of the URLs. But I guess that didn't matter and Hetzner got annoyed with all the emails and decided my business wasn't worth the trouble.
I ask because I'm building a web site currently hosted on Hetzner that will provide access to files that have fallen into the public domain, but also files that for all intents and purposes appear to copyright orphans. I will take down anything where an entity asserts a valid copyright against anything where a mistake has been made, but I don't want Hetzner just arbitrarily shooting down my site.
Now they send DMCA notices to myself, Cloudflare, and Hetzner. I think the goal is to annoy as many people as possible. Even after I shut off my IPFS gateway they continued sending notices.
Anyway, if you're hosting anything that might generate a DMCA notice, don't use Hetzner. They will kick you off even if you're complying with the DMCA process. Also, they make you submit a statement on abuse.hetzner.com for every single DMCA notice that gets sent to them. If you don't submit the statement in 24 hours they threaten to block your IP address. It is extremely tedious and annoying.
Wait... isn't the point of paying cloudflare to prevent DoS attacks?
I guess if you want to do a DoS attack, send a few bogus DMCA notices to Cloudflare first to get the real IP of the server they're supposed to be protecting. Then you can hammer the server directly without Cloudflare getting in the way.
Not to mention a bogus DMCA takedown which has its own penalties.
Does it? It'd be nice if penalties happened more often to the groups that spam out DMCA takedowns.
Hahahahahaha..
Cloudflare exists to get in the way of your users from accessing your site and you who are trying to run a site. They claim to be an anti-DoS service but I've never seen any evidence they actually do that. I still get Cloudflare messages a plenty that the website is down. And of course that moronic time waster where it wants me to perform a captcha constantly without actually serving the captcha.
Don't know why it didn't work for you, but there are a few things that can trip up ops.
Cloudflare saved us immeasurable time vs manually configuring firewalls and blackholes and honeypots and open-source lists -- all for $20/mo. It was an amazing service. And they blew their competitors at the time out of the water (Imperva, etc.)... much higher quality blocking at like 1/10 the cost.
If you see a Cloudflare message that the website is down, well, chances are the website is down. If they set it up a certain way, Cloudflare may have been able to cache some pages beforehand, or not... but either way, it's probably not Cloudflare's fault. The site probably would've been down even more often without Cloudflare, just without the CF error page. (That said, DNSSec is a pain and can often cause issues with Cloudflare and other proxies)
As for hCaptcha, I don't think I've ever had an issue with it (besides being unable to tell what something was, I mean)... did you have JS turned off or strict third-party blocking, perhaps?
https://en.wikipedia.org/wiki/Cloudflare#The_Daily_Stormer
(Not trying to take sides here -- it's a messy, complex topic -- just trying to recount the history as I remember it, hopefully somewhat correctly)
They defended them for a long time, and then banned them shortly after one of the Stormer admins started bragging that they had Cloudflare in their pocket.
It seems like those notices were made in bad faith. It would be nice if they faced some punishment.
Perhaps one should send regular take down requests to ones own host complaining about ones own website and point at example.com/<php echo $website[0]; ?> as the proof. Then change hosts if they chose to act weird on it.
I read "good" things about Hosted Network Pty. Ltd who in 2018 had a complaint response time near 20 days. "Worse" in the industry.
Any recommendations?
The lowendtalk forums are a good place to find any number of hosters that will fill your need.
The goal is to burden the recipient with overhead costs that it becomes impractical or cost-prohibitive to participate.
What are the consequences of ignoring these notices?
If you ignore them, it’s basically as if the DMCA never existed and they can just sue you. And without the DMCA, you are liable if it’s some random user uploading copyrighted content to your website.
Pretty sure jes is in the UK though, and it's not the sort of thing you'd ever be extradited over... so not really sure why the notices matter. I guess some hosting providers are more sympathetic here than others.
That infamous treaty has turned the Special Relationship into full-on vassalage.
Running an IPFS gateway doesn't make me any money and even consulting a lawyer is way outside my hobby project budget.
I mean it obvious that it's not, but are you willing to test how far they can reach when you have stories like of Peter Sunde and Kim Dotcom to see what happens?
So... DMCA is infamous for its lack of protections against misuse, and I'm not a lawyer, but that's gotta actually qualify as perjury, surely?
In other words: it doesn't matter your gateway logs shows that no one ever requested a file with a specific content hash, because should one eventually request that content hash from your gateway, they'd get the file in question.
Honestly, until reading the headline, it never occurred to me what now I realize is stupidly obvious: the promise of p2p content-hash-based distribution is that it's robust and censorship-resistant, as the targeted data isn't bound to specific places, but rather is automatically mirrored and made available across the entire network. The flip side of the data being accessible from any point in the network, however, is that... the data is accessible from any point in the network - meaning that every point individually is distributing everything that's in the entire network, and is potentially liable for it all.
I think that's why DMCA safe harbor exists, and it could be argued that an IPFS gateway is acting as an OSP (in fact, it's almost text-book[1]).
Though, at this point, it seems that DMCA is skewed almost exclusively in favor of rights holders (or indeed anyone simply claiming to be a rights holder), that unless you're Comcast or Verizon or something, you're not going to get much sympathy from the legal system by claiming to be an OSP.
In contrast, IPFS gateways are running on a "pull" model. Anyone can come to the gateway, and pull through it anything that's stored anywhere in the IPFS network. This is meaningfully different, in the same way "users could post illegal/infringing content to YouTube" is different from "there exist illegal/infringing content on YouTube already posted, available to anyone who know the ID to put in the URL". In the former case, possibility of "bad" upload doesn't create a problem until such upload actually happens; in the latter case, possibility of a "bad" download is a problem even if, so far, no one actually downloaded the "bad" thing.
> I think that's why DMCA safe harbor exists, and it could be argued that an IPFS gateway is acting as an OSP
I don't have any argument against that. I assume this wasn't tested in courts yet, and the rights holders are exploiting this uncertainty, expecting that no IPFS gateway operator will try to contest the DMCA claims.
IPFS in contrast would be a CDN. It actually hosts content, that's the point, it's a massively distributed filesystem. I can see that creating new legal arguments separate from pure network infrastructure.
> expecting that no IPFS gateway operator will try to contest the DMCA claims.
Unfortunately, even if you have a case, there are substantial legal costs involved.
I thought this was clarifying it well:
This is meaningfully different, in the same way "users could post illegal/infringing content to YouTube" is different from "there exist illegal/infringing content on YouTube already posted, available to anyone who know the ID to put in the URL".
But maybe it's not, or maybe I'm making a category error here?
The content itself is stored on IPFS nodes which "pin" the content they wish to persist on the network. I think there would be grounds under DMCA to ask IPFS pinning services to stop pinning copyrighted materials, but going after the gateways seems misguided and a misuse of DMCA, as they're only acting as a proxy.
If you take IPFS for what it was designed to be - one big, distributed, content-addressable file system, then each individual IPFS gateway is effectively a server that serves that entire file system.
Whether or not this is abuse of DMCA, I can't tell, though I feel it indeed is. It does make sense from practical point of view, though. From the point of view of the rights owners, IPFS by itself is, at the moment, too small and too nerdy to be of significance - however, gateways are projecting IPFS into the Internet inhabited by general population, and in doing that, they look like servers serving content. They're good targets because they're how most people would access copyrighted material stored in IPFS.
IPFS gateways don't host any files, they act in the exact way that xoas comment talks about.
> They don't host content, they don't discriminate, they just route traffic.
Indeed an IPFS gateway does not "host" content either, it merely shifts bits around in the same way a proxy or VPN shifts bits around. It's not correct to say that when you're connected to a VPN that your VPN provider is hosting Google or Netflix, it's the exact same with IPFS gateways.
The only difference between IPFS gateways and a proxy in that sense is that a proxy serves the client HTTP content from a HTTP source whereas an IPFS gateway serves HTTP content from an IPFS source.
Equivalently imagine a proxy that could proxy traffic from any publicly accessible FTP server to HTTP. Is it correct to say that the proxy is hosting the content that resides on the FTP? No, it's not. The FTP server is hosting the content and the proxy is piping it to clients from FTP->HTTP without storing anything.
Lindsey Ellis did an exhaustive series of videos on exactly this topic (https://www.youtube.com/watch?v=K3v5wFMQRqs); yes, you can sue over false DMCA filings, but it's expensive and time-consuming and you may run out of money in the process.
https://www.aclu.org/documents/text-digital-millennium-copyr...
> ”(3)ELEMENTS OF NOTIFICATION.-
> ”(A) To be effective under this subsection, a notification of claimed infringement must be a written communication provided to the designated agent of a service provider that includes substantially the following:
[...]
> ”(vi) A statement that the information in the notification is accurate, and under penalty of perjury, that the complaining party is authorized to act on behalf of the owner of an exclusive right that is allegedly in-fringed.
But that makes it completely trivial to abuse. But like... for everyone. What prevents a person from returning the favor? Say, if one of the folks in the article decided to make a list of parties involved in this farce and inundate them with DMCA notices for something they have nothing to do with. Either that's legal, in which case it can be used against the initial aggressors, or it's not, in which case they're equally liable.
Edit: Okay, I read to the bottom of the post that pointed me to that text: https://law.stackexchange.com/questions/51541/has-anyone-bee... and it does in fact list "at least two" civil suits that look really similar to the situation we're discussing here.
The perjury bit not applying doesn't rule out there being other forms of liability from incorrect DMCA notices - it just strikes out the most visible and severe one. For instance if you wrote up a fake notice, based on a work you owned but targeting an unrelated URL, you could be sued for some sort of fraud or tortuous interference, even though you didn't run afoul of the perjury provision. The problem is commercial DMCA mills have the standard corporate veil where nothing is any one person's fault to hide behind. So even though it might be technically possible to take them to task, it's much harder to argue something like gross negligence.
However the corporate veil I'm referring to goes beyond the legal doctrine. I'm referring to the protection that comes from having a bunch of people doing something, so that errors get written off as constructive emergent behavior rather than pinned on singular willful actions. If an individual set up a script that generated a bunch of DMCA notices based on the possibility of infringement with no verification, then signed the requests and sent them off, they'd likely find themselves in court and pinned with a finding of bad faith (regardless of say having set up an LLC or not). Whereas when a group of people does the same thing, each only contributes part of the action, they all point fingers at each another for who's responsible (A: "I said the output of the script had to be verified", B: "I wasn't responsible for the output of the script", C: "I thought everything I got from B had already been verified"), and any argument of willful bad faith becomes much harder.
If you don't present evidence, and you know that you do not have evidence, and it can be shown that you knew you did not have evidence when you, then that's intent to defame (or obstruct). And also such a pattern of defamation with intent and intimidation may qualify as an OC protection racket?
(Plaintiff could not have had knowledge of which content defendant was authorized to archive or fair use, and plaintiff knew that they hadn't such information when they harassed and intimidated defendant and so plaintiff had criminal intent.)
I ask in the context of ActivityPub, Mastodon, Lemmy, Kbin, etc. I'm writing software for ActivityPub and i want to ensure self-hosted instances have the tools to respond and manage to legal .. threats (or w/e) like DMCA. Likewise i don't even know what is good advice for people to manage these notices. Of course there's also all the other undesired things too, CSAM, etc. Hosting user content is tough, heh.
As someone invested in getting people to self host more of their life in ways like ActivityPub, that also then means more exposure to this type of .. stuff. Not sure what the current consensus even is, tbh.
It does not always matter if those are actually legit if they look credible enough and thus, if someone hates you very much, it can be used as a weapon to kill your instance.
This can be somewhat remedied by hiding your hoster via something like e.g. Cloudflare, if having a middle men is acceptable.
Instead i think it will shine with many small instances. 500-30k maybe? Still similar issues with federating, but less so than hundreds of thousands of 1person instances.
I'm focusing on what i'm calling micro instances, 50-1000 range i suspect. So we'll see.
Letting this happen IMHO is clearly a breach of IEEE's own rules. This goes against the public and has serious side effects. Nobody with a bit of knowledge on networking (which I hope exists within IEEE) should seriously think that those gateways are hosting the content.
If someone with a role in IEEE reads this they should really stop this rogue firm they contracted before they seriously destroy some part of the internet some people rely on.
[1] https://www.ieee.org/about/corporate/governance/p7-8.html#:~....
And by all means, an exit node is distributing content.
Is Cloudflare distributing content by caching torrent sites? Is it possible to run a public proxy without distributing copyrighted content?
In my opinion, this line of reasoning is absurd.
This is from a slide deck on how to "protect" content, apparently by someone working for a law firm. Assuming the firm is US-based, this is literally suggesting to get immigration services to check out a suspected "wrongdoer".
Lawyers huh... I just can't even.
https://news.ycombinator.com/item?id=36425433 ("Did I receive fraudulent DMCA takedowns?", 3 days ago, >150 comments)
- randomize the url list
- ask for evidence of copyright violation of a specific url number
- if human does not answer, claim they acted in bad faith
- give them 14 days to respond
Win/win. Gotta game the system, and increase the cost/effectiveness ratio.
So it's apparently not going to be effective to counterclaim as it cost you more to do this than they lose.
My proposed responder can be easily automated. It might cost them no money in court, but it costs them human salaries - and that's the point.
We have to make DMCA takedowns an unfeasible business model to change the status quo of bad actors.
If a law firm or solo lawyer is not identifying themselves properly in a DMCA takedown request, which is a legal document, what happens? Does anyone know?
Many services like Twitter or Chrome Web Store will at best put your content back up a few weeks (or months) later after you file a counter-notice; in some cases they will just nuke your account after a few notices even if the notices were bogus.
https://www.dmlp.org/legal-guide/responding-dmca-takedown-no...
Fraudulent takedown notices and fraudulent responses create liability. There's probably room for a "no-win, no-pay" law firm that bills $500/hour to handle fraudulent DMCA takedown notices. Bonus points to them if they donate half their income to the EFF.
There might be a developing environment in which to monetarily fight that abuse.
I don't think any browsers have IPFS built in. For IPFS to be at its most useful (as in, your computer exchanging data with the network and actually participating in it), you need things like port forwards or IPv6 pinhole support, and I don't think that's something many people will do.
Edit: Brave supports IPFS natively these days. Go to brave://settings/web3 and set "Method to resolve IPFS resources" to "Brave local IPFS node".
In terms of block stores we support local disk, or S3 compatible.
You can log in through any peergos instance (including localhost) and your writes are persisted directly to your instance. The whole thing is also independent of DNS and the TLS CAs (except of course if you use a public web interface)
- TXT record with an IPFS content identifier
- A record pointing to an IPFS gateway that ran on my laptop (and was restricted to only serving my own content)
- fallback A records that pointed to the public IPFS gateways
i could publish new content from my laptop, and as long as i had one other reader who browsed it via native IPFS (i did), then i could pretty safely not worry about my own uptime.
that was pretty useful to me at the time who had no clue how to be a sysadmin and keep good uptime and whatnot.
Arweave is better suited to archival storage. There are options for participants to ban particular types of content which may be illegal to host in their jurisdiction. This was designed to prevent the spread of CP, terrorism related info, etc. but that means it is also susceptible to DCMA issues too.
Peergos kinda do it but maybe it's only for the transport and it uses S3 or something like that.
> Arweave is better suited to archival storage
Thanks, I'll take a look.
I wish there was more exciting ipfs news beside nfts.
EDIT: Arweave seems to be part of the crypto/web3 thing I'm not a fan of.
Even if you make an IPFS browser extension, you could still get complaints and Google might still take it down, no? Are there any IPFS mobile apps that don't require sideloading?
You have a chance of getting away with anything else on the Web, but anger the Copyright Gods and there's nowhere you can hide.
There’s no legal pathway to taking down the software. Only the gateways which aren’t necessary for IPFS.
This is basically copyright holders sending DMCA to trackers. Trackers haven’t been necessary for using torrents but it makes them more accessible.
Is it something like MAD?
The USA does make it very easy to sue someone, and when that someone is the government you can force practical changes that can affect a large number of people with your litigation. It might not get you any monetary benefit (it certainly hasn't for me), but that might also be a bonus.
I would love to be legally able to practice law because then I could represent other people who can't afford a lawyer, as it is I can only sue for myself without a lawyer. The issue is that people think you only need to pass the bar exam, which I'm pretty certain I could do tomorrow if I brushed up on real estate, trusts, wills etc (my suits are all civil rights, torts, criminal defense). BUT, only four states allow you to take the bar exam without a law degree. And those four states still need apprenticeships. Which makes it really hard to become a "real" lawyer these days.
Also unlike MAD large corporations do regularly engage in fierce IP battles. Like Apple vs Samsung. I do see the pro arguments, but overall I find it doubtful if if it's a net positive for humanity to have strict IP laws at all.
The American approach is the world's approach as far as rule-of-law countries go btw.
So you just have to own the thing you claim is infringed, you do not have to be correct that the items you target with the notice are actually infringing upon your work. That stops me from claiming to own Mickey Mouse and sending notices against it. It does not stop me from claiming something I actually own copyright to and sending spurious notices to non-infringing works.
Now, there might be some minor monetary liability for costs incurred by a completely bogus notice, but they're probably not large enough to sue over without ending up losing more money on the suit than you win in most cases, so it's relatively untested, though I think there may have been a settlement or two over such claims.
I'm aware of numerous cases where this was not the case, but I haven't ever seen anyone ever prosecuted for making a false statement in regards to a DMCA notice. Does anyone know of an actual case where someone faced legal jeopardy for a false DMCA notice?
Someone is using ChatGTP to look for infringing content. DMCA notices are being sent on the basis of AI hallucinations.
"Implement Allow Lists and Block Lists" (2018) https://github.com/ipfs/notes/issues/284
"IPIP 298: (allow|deny)lists for IPFS Nodes and Gateways" (2022) https://github.com/ipfs/specs/pull/340
The ciu-online.net application doesn't check whether or not the content is accessible through your server before sending a notice. It sends notices for all content that might be on the IPFS network.
You'll get annoying emails no matter what.