My open source API client was taken down by a phony DMCA complaint
github.com
github.com
Without knowing details about this (and not providing legal advice) this may be how it would work:
If the claim is in fact BS, go lawyer up. File a counter notification, wait 10 days and your content will be put back online (unless they file an injunction to keep it offline), then you file suit against the alleged infringer for the statutory damages of $150,000 per false alleged infringement claim. Likely they'll settle out of court for some number less than their legal costs/time.
Pay your lawyer, use the rest to fund your project.
Go out for a pint, and tell the story to tell on how your project was funded by out witting a scammer.
So, I'd say, don't lawyer up yet. File the counter-notice and if they come after you, then get a lawyer and publicity.
No wonder we see so many idiotic claims.
In one instance I personally saw, a lawyer sent a false DMCA and they signed it under penalty of perjury for their client. This resulted in a clarification of the perjury that the lawyer may have placed themselves in, and threats to bring it up with the state bar association. Personally I doubted the guy was even accredited in the first place, but the DMCA related harassment stopped promptly.
The only part that is perjury is if you don't actually represent the client you claim to. Assuming the request isn't from a random person pretending to represent a company they don't, the request is not perjury regardless of how frivolous and unwarranted it is.
I understand that you want to extend professional courtesy to the lawyers and programmers involved, and by all measures, I think you should do so. However you must understand that the DMCA takedown procedure is not a human; it is a legal robot. By invoking DMCATakedownBot, they have not extended you proper courtesy, and probably the correct action is to file the counter-notification.
Your counter-notification can point out that the original legal letter to GitHub was largely not a 'notification of claimed infringement' under 17 USC § 512 (c) (3) (A) [the "safe harbor"/"takedown" requirement of GitHub] -- because it claimed that the injury was a violation of 17 USC § 1201, which is not about copyright infringement. You should point out that there is a claimed infringement in this notice -- "He has taken proprietary source code from inside of our application" -- but that this claimed infringement is outright false, you have not copied any source code from inside of their application. So the 'safe harbor' DMCA takedown notice (§ 512) is probably not a proper venue for the legal discussion to occur. Rather, the proper venue is described in § 1203; they should bring a civil action against you in a US district court for the actual damages and any additional profits of the violator, or statutory damages per violation.
You can then add to this notice something about how you'd much rather attempt to sort this out in a one-to-one discussion with the aggrieved programmers at the company, rather than in court. You can also tell them that section 1203 (c) (5) allows a court to remit the total award of damages if you can prove to the court's satisfaction that you were not aware and had no reason to believe that your acts constituted a violation.
Since this is not legal advice so much as "advice on what you can say to lawyers to get them off your back", I will recommend that you read the relevant laws here:
http://www.law.cornell.edu/uscode/text/17
I also recommend that if they do sue you under section 1203, you contact a lawyer. You might also consider contacting a copyright lawyer right now, if it's not too much hassle.
http://torrentfreak.com/groovesharks-future-in-doubt-after-s...
I wonder if by that token you could find a security exploit in an API that causes undesired behaviour (e.g. elevated privileges) and claim you're simply accessing an undocumented API?
Or another way of looking at it - does accessing an undocumented API constitute hacking/unauthorized access? (which is probably an even more serious violation than copyright infringement in most countries)
(disclaimer: I don't even know what this particular API is doing, or what's the alleged infringement, I'm just wondering about the principles in general)
Computers do what they're programmed to do, they do what you told them to do, if you didn't want your computer to respond to a buffer overflow by writing over the stack and executing a sequence of commands that escalated the defendant to an administrator, you shouldn't of programmed that feature in.
When you inserted that string directly into that SQL command, you gave your users access to a wide range of features. Now all of a sudden you don't like that feature any more because someone used it? You gave the users the ability to ask for arbitrary tables in your database, why should a hacker go to court for asking for a "user table"? Shouldn't you be the one in court?
That's how I saw things when I was ~15, anyway. I still kinda think that way... Though I've figured out that just because someone left their safe open, doesn't mean you get to steal the gold.
True. Though on the other hand, if somebody figures out they they get free sodas when they hold down both the coke and sprite buttons, as far as I am concerned they get to have their free soda.
> > Though I've figured out that just because someone left their safe open, doesn't mean you get to steal the gold.
> True. Though on the other hand, if somebody figures out they they get free sodas when they hold down both the coke and sprite buttons, as far as I am concerned they get to have their free soda.
So, if the safe is left open, you don't get to take it, but if you press buttons that unintentionally make it open up, you get you have your free gold? uh.
Just don't take money that the teller, automated or otherwise, does not volunteer. Regular safes and vaults, with no teller, have no agency and are not capable of giving you money.
I wonder what's going to happen to philosophy if/when we hit the event horizon.
Then again, I'm pretty sure that company lost their case. How can you claim that it's not documented if you provide HTML and Javascript example code?
Looking through wikipedia's description, it looks like anti-circumvention isn't even in the same section of the act as the the rules for taking down infringing content.
Its not an "internal API" if it is publicly accessible and doesn't require credentials other than the user's own. Did this API client have stolen creds embedded?
Sending requests to servers must be likened to finding publicly posted data. E.g, Buildings 1, 2, and 3 all have neat flyers, so you look at building 4's flyer. Oops, that was a felony.
If your power adapter is in glass case 1, and I curiously glance at glass case 2 and see the undergarments was I wrong?
Combination locks are locks and are designed to prevent access.
Web servers are online. They provide responses to web clients. There are established methods to control access to what a client can and cannot access.
If it's online, and responding to my client, and not giving a 401 or 403 or etc status code then it's hard to understand why just visiting example.com/example1.jpg example.com/example2.jpg makes someone a federal criminal at risk of years in prison.
Unfortunately, groovr appears to circumvent internal copyright protections for content hosted at Grooveshark. The groovr library offered a way to get, and subsequently allow you to easily download, song mp3s via a call (groovr.getSongFile). It was able to provide these services by using our internal authentication methods and internal API.
Grooveshark offers a public API (http://developers.grooveshark.com/) which allows you to search for content, authenticate users, view popular music, and more, all for free. Developers are encouraged to register for a key and use our content for their applications.
Grooveshark PR clearly thought that by rolling out a "one of us" developer to make a "shucks, it sucks, but what choice did we have?" type statement, the wider dev community would be pacified and wouldn't keep asking the hard questions.
One day they will learn.
Your tweet[1] says you don't know if anyone reached out to them. Another tweet[2] sure makes it sound like this is a technical issue of how they're doing something, rather than what they're doing.
If you "handle developer relations", why weren't you involved before the notice was sent? Why didn't you reach out to the developers before your lawyers reached out to github?
This does not sound like "handling developer relations".
[1] https://twitter.com/jameshartig/status/337309949317238784
[2] https://twitter.com/jameshartig/status/337336039502934017
Either way, you must have read it by now and are negligent in being here discussing this if you haven't, so, do you agree with its claims? If not, which ones are wrong?
Was actual proprietary source code taken as the notice claims? Do you guys even know what source code is? How was this source code accessed?
What is the hash of the git repo that contained it, and which lines are yours? (If you need to check, it's okay - there appear to be many new mirrors you could reference.)
This may seem harsh, but you've had someone's website removed and accused them of a crime. Put up or shut-up. In response to this post.
I tried Google, Yahoo, Bing, the Coral CDN, Gigablast and WebCite).
package.json: http://webcache.googleusercontent.com/search?output=search...
It appears that Groveshark innacuraltley filed a DMCA.
However it appears that the orriginal poster is in violation of DMCA, for DRM Violations. The DMCA provides groveshark protection against your "API" which is actually a way to circumvent grovesharks DRM.
While Groveshark didn't state this in the orriginal DMCA, they can file another and have you taken down for correct issues.
Your "API" does violate copyright law.
All of the folks I worked with saw it as their mission to support both independent music and independent software development. Everyone in the office brainstormed ways to help broaden their fan bases. (For example, giving artists Flattr accounts & letting them live-broadcast their music as they chatted with fans.) At the same time, many of the Grooveshark engineers I know contributed to open-source projects in their free time.
The API has never allowed users to download songs, and it seems clear to me (by browsing the comments in the code on Github) that one element of the project in question performed that function. That seems to be the crux of this problem.
Again, I'm not qualified to speak on behalf of Grooveshark, but I know from experience that its engineers are extremely supportive of these kind of open-source projects.
groovr.getSongFile songs[0].SongID, (err, file) ->
###
file.url is an mp3 url you can download
the file object also contains some meta info like song length
###
That indeed confirms what the Grooveshark developer was saying on the DCMA notice comments. Even though the API doesn't provide the MP3 file directly, it's trivial to get it through this function call.Could that be any clearer?
From someone elses comment, looked at the google cache of your github repo,
> groovr.getSongFile songs[0].SongID, (err, file) ->
might have been the part they have a problem with?
It provides only basic search functions of course, but it is publicly documented and I'm sure Grooveshark can't complain if you use it. I wrote a Go package for it years ago (literally, 2010 I think) and it still works fine. You get tinysong.com shortlinks, which lead to the song on Grooveshark.
"Repository unavailable due to DMCA takedown"
Source: a Sony DMCA takedown request did this with my github repo.
Might be a way to get a free private repo ;)
* Please don't do this. Github has always been so nice, especially regarding DMCAs.
Absolutely. Pushing to DMCA'd repos might actually be necessary in some cases, and if this is abused github may be forced to disable this for everybody. Still, pretty neat; thanks for trying it out!
That's how it (the DMCA) works.
| you're giving them 10 days to start a real
| legal battle by going to a court
To be clear, that's 10 days before the content goes back up to take you to court to prevent it from going back up. Nothing stops them from suing you over it after the content is restored.I don't see myself ever creating anything that would get taken down but I imagine most people don't when it happens to them.
Any time I hear about DMCA it seems so very one sided that there is just about no recourse.
1) Most of the time they don't know your real identity from your (e.g.) YouTube username. IIRC, you have to use your real name or contact information when filing a counter-notice.
2) If they sue you, the content stays up until they can convince the judge to order it to be taken down.
The point of the DMCA was to allow for things to be taken down quickly, and then sorted out in court later if need be. The content is taken down quickly. If you push back (counter-notice), then the (claimed) content owner has 10-14 days to start court proceedings to keep it down; otherwise, it goes back up. None of this precludes a suit being filed at any point.
The real issue with this process is that there is little relief for negligence in filing DMCA notices. All you have to do is have a good-faith belief that you are the content owner, and this violates your rights. So acting like you're ignorant of the law is actually a defence against being held accountable for filing a bogus notice.
If bogus DMCA notices were punished more often, and people were required to consult a lawyer before firing at the hip (e.g. people that don't understand copyright law, and just say, "I don't like X take it down! DMCA!"), then maybe it would be working better.
The meaning of the counter-claim is not, "I agree, I removed the stuff, sorry", the meaning is, "I disagree, put the stuff back up. If you don't like it, take me to court."