So... DMCA is infamous for its lack of protections against misuse, and I'm not a lawyer, but that's gotta actually qualify as perjury, surely?
So... DMCA is infamous for its lack of protections against misuse, and I'm not a lawyer, but that's gotta actually qualify as perjury, surely?
In other words: it doesn't matter your gateway logs shows that no one ever requested a file with a specific content hash, because should one eventually request that content hash from your gateway, they'd get the file in question.
Honestly, until reading the headline, it never occurred to me what now I realize is stupidly obvious: the promise of p2p content-hash-based distribution is that it's robust and censorship-resistant, as the targeted data isn't bound to specific places, but rather is automatically mirrored and made available across the entire network. The flip side of the data being accessible from any point in the network, however, is that... the data is accessible from any point in the network - meaning that every point individually is distributing everything that's in the entire network, and is potentially liable for it all.
I think that's why DMCA safe harbor exists, and it could be argued that an IPFS gateway is acting as an OSP (in fact, it's almost text-book[1]).
Though, at this point, it seems that DMCA is skewed almost exclusively in favor of rights holders (or indeed anyone simply claiming to be a rights holder), that unless you're Comcast or Verizon or something, you're not going to get much sympathy from the legal system by claiming to be an OSP.
In contrast, IPFS gateways are running on a "pull" model. Anyone can come to the gateway, and pull through it anything that's stored anywhere in the IPFS network. This is meaningfully different, in the same way "users could post illegal/infringing content to YouTube" is different from "there exist illegal/infringing content on YouTube already posted, available to anyone who know the ID to put in the URL". In the former case, possibility of "bad" upload doesn't create a problem until such upload actually happens; in the latter case, possibility of a "bad" download is a problem even if, so far, no one actually downloaded the "bad" thing.
> I think that's why DMCA safe harbor exists, and it could be argued that an IPFS gateway is acting as an OSP
I don't have any argument against that. I assume this wasn't tested in courts yet, and the rights holders are exploiting this uncertainty, expecting that no IPFS gateway operator will try to contest the DMCA claims.
IPFS in contrast would be a CDN. It actually hosts content, that's the point, it's a massively distributed filesystem. I can see that creating new legal arguments separate from pure network infrastructure.
> expecting that no IPFS gateway operator will try to contest the DMCA claims.
Unfortunately, even if you have a case, there are substantial legal costs involved.
I thought this was clarifying it well:
This is meaningfully different, in the same way "users could post illegal/infringing content to YouTube" is different from "there exist illegal/infringing content on YouTube already posted, available to anyone who know the ID to put in the URL".
But maybe it's not, or maybe I'm making a category error here?
The content itself is stored on IPFS nodes which "pin" the content they wish to persist on the network. I think there would be grounds under DMCA to ask IPFS pinning services to stop pinning copyrighted materials, but going after the gateways seems misguided and a misuse of DMCA, as they're only acting as a proxy.
If you take IPFS for what it was designed to be - one big, distributed, content-addressable file system, then each individual IPFS gateway is effectively a server that serves that entire file system.
Whether or not this is abuse of DMCA, I can't tell, though I feel it indeed is. It does make sense from practical point of view, though. From the point of view of the rights owners, IPFS by itself is, at the moment, too small and too nerdy to be of significance - however, gateways are projecting IPFS into the Internet inhabited by general population, and in doing that, they look like servers serving content. They're good targets because they're how most people would access copyrighted material stored in IPFS.
IPFS gateways don't host any files, they act in the exact way that xoas comment talks about.
> They don't host content, they don't discriminate, they just route traffic.
Indeed an IPFS gateway does not "host" content either, it merely shifts bits around in the same way a proxy or VPN shifts bits around. It's not correct to say that when you're connected to a VPN that your VPN provider is hosting Google or Netflix, it's the exact same with IPFS gateways.
The only difference between IPFS gateways and a proxy in that sense is that a proxy serves the client HTTP content from a HTTP source whereas an IPFS gateway serves HTTP content from an IPFS source.
Equivalently imagine a proxy that could proxy traffic from any publicly accessible FTP server to HTTP. Is it correct to say that the proxy is hosting the content that resides on the FTP? No, it's not. The FTP server is hosting the content and the proxy is piping it to clients from FTP->HTTP without storing anything.
Lindsey Ellis did an exhaustive series of videos on exactly this topic (https://www.youtube.com/watch?v=K3v5wFMQRqs); yes, you can sue over false DMCA filings, but it's expensive and time-consuming and you may run out of money in the process.
https://www.aclu.org/documents/text-digital-millennium-copyr...
> ”(3)ELEMENTS OF NOTIFICATION.-
> ”(A) To be effective under this subsection, a notification of claimed infringement must be a written communication provided to the designated agent of a service provider that includes substantially the following:
[...]
> ”(vi) A statement that the information in the notification is accurate, and under penalty of perjury, that the complaining party is authorized to act on behalf of the owner of an exclusive right that is allegedly in-fringed.
But that makes it completely trivial to abuse. But like... for everyone. What prevents a person from returning the favor? Say, if one of the folks in the article decided to make a list of parties involved in this farce and inundate them with DMCA notices for something they have nothing to do with. Either that's legal, in which case it can be used against the initial aggressors, or it's not, in which case they're equally liable.
Edit: Okay, I read to the bottom of the post that pointed me to that text: https://law.stackexchange.com/questions/51541/has-anyone-bee... and it does in fact list "at least two" civil suits that look really similar to the situation we're discussing here.
The perjury bit not applying doesn't rule out there being other forms of liability from incorrect DMCA notices - it just strikes out the most visible and severe one. For instance if you wrote up a fake notice, based on a work you owned but targeting an unrelated URL, you could be sued for some sort of fraud or tortuous interference, even though you didn't run afoul of the perjury provision. The problem is commercial DMCA mills have the standard corporate veil where nothing is any one person's fault to hide behind. So even though it might be technically possible to take them to task, it's much harder to argue something like gross negligence.
However the corporate veil I'm referring to goes beyond the legal doctrine. I'm referring to the protection that comes from having a bunch of people doing something, so that errors get written off as constructive emergent behavior rather than pinned on singular willful actions. If an individual set up a script that generated a bunch of DMCA notices based on the possibility of infringement with no verification, then signed the requests and sent them off, they'd likely find themselves in court and pinned with a finding of bad faith (regardless of say having set up an LLC or not). Whereas when a group of people does the same thing, each only contributes part of the action, they all point fingers at each another for who's responsible (A: "I said the output of the script had to be verified", B: "I wasn't responsible for the output of the script", C: "I thought everything I got from B had already been verified"), and any argument of willful bad faith becomes much harder.
If you don't present evidence, and you know that you do not have evidence, and it can be shown that you knew you did not have evidence when you, then that's intent to defame (or obstruct). And also such a pattern of defamation with intent and intimidation may qualify as an OC protection racket?
(Plaintiff could not have had knowledge of which content defendant was authorized to archive or fair use, and plaintiff knew that they hadn't such information when they harassed and intimidated defendant and so plaintiff had criminal intent.)