How Turtl has no idea when you're sharing copyrighted stuff
turtlapp.tumblr.com
turtlapp.tumblr.com
"We hold that one who distributes a device with the object of promoting its use to infringe copyright, as shown by clear expression or other affirmative steps taken to foster infringement, is liable for the resulting acts of infringement by third parties."
- Justice Souter, writing on behalf of the Supreme Court of the United States in MGM Studios, Inc. v. Grokster, Ltd.
if the intent is to illustrate security and encryption, there is no reason to invoke "copyrighted material" at all.
I don't see anywhere that they are claiming their business is for copyright infringement, in fact, it doesn't seem like it's for mass distribution at all unless you give out your key, and then you just defeat the point of the service.
[0] I am not saying it is good or bad, right or wrong.
[1] Observing, not judging.
It doesn't really matter what you or I think anyway. If it came down to being sued by a copyright holder, a blog post like this is definitely not going to help their case.
Sharing copyrighted material is not a crime unless is an illicit sharing, that is, when you do not hold a license that allows you to do so. So there are many exceptions such as: when you download a song that explicitly allow copies for any of your own devices; the same applies when you are the copyright holder, or when the license does not cover the country where you live.
Some people are looking for data protection in the cloud (trading the risk for the convenience). If companies like Turtl or SpiderOak didn't exist myself, and many others, would be forced to rely on similar solutions that are self-hosted. Is that intent? I don't think so. That would imply me locking my vehicle or house at night is some sort of indicator of nefarious activity.
What really annoys me is that people go off the handle about intent and fall back to "the law" being the overriding position in these sort of arguments. Bull shit. I have content I've created that I don't want to share with the world. I shouldn't have any shame or feeling of guilt associated with protecting my assets (digital or physical).
"Read between the lines" - give me a break. I hope that's not everyone's first perspective when they read positions as such. It's that line of thinking that's shifting us to a "guilty until proven innocent" mentality of usage of the Internet.
He wasn't talking about everyone's first perspective. He was talking about a judge in a copyright infringement lawsuit's final perspective.
You risk being held liable for contributory infringement if you advertise infringement as a possible use for your product.
There really is no other way to read that case, and despite technical differences between Ginsberg (really, really bad) and Breyer (really, really good), all 9 justices on the court agreed with that basic idea. Advertise infringing uses? Get held liable. What this means is one really should shy away from saying things that may be taken as advertising infringing uses.
You can read the whole thing at http://www.law.cornell.edu/supct/html/04-480.ZS.html
Please do so.
"Everyone's" first perspective is not what should matter to you if you're evaluating legal risk; which is the context of the advise being offered here. When a civil suit is brought against, you, the standards of proof are entirely different than criminal, and these standards are ignored to the author's peril when constructing a message like the one linked here.
To get specific, when someone brings a civil suit against you, the first bar they must pass is relatively low. Once they have passed this bar, they can wrap you up in a very expensive lawsuit for a very long time. I know because I've been in this circumstance for the last four years. Before an actual trial, you get the opportunity to challenge the suit in a variety of ways. A judge gets to decide whether the plaintiff's complaint passes the tests for your challenge. If they do, the trial proceeds, and ultimately you end up in front of a jury.
This is the part where you're gambling -- with huge sums of money at stake -- when it comes to copyright. It doesn't matter if "everyone" decides to read between the lines; it only matters if the selected jury does. That is a gamble of epic proportions. Both lawyers are jockying to select a jury that they feel will fall on their side of the case, but keep in mind that the standard of proof in civil trials is a "preponderance of evidence", not "beyond reasonable doubt".
It seems as though only actors which are threatened by true privacy have a position, and that position includes significant wealth, political power and greed. Those actors set a precedent based on already won battles which don't seem to revolve around facts but, again, money and power. Everyone else is then left to spend "huge sums of money" to defend a position that was never unconstitutional in the first place.
Frustrating.
It seems that one of the challenges of these services is that in order to avoid the copyright goons everyone you know, even those folks you only know by some IRC handle, have to be willing to go to jail for you. Because otherwise one of them will get turned, they will then be pressured to get you to indict yourself. This is how it worked against Anonymous, and how it works on most disobedience rings (civil or otherwise). One of your friends will share with you a folder that has copyrighted material in it, once they are sure you have accessed it they will re-iterate that some (or all) of the material there is copyrighted. At this point the most common thing that happens is that thinking they are 'safe', someone will say something stupid like 'don't worry, its our secret' or something like that.
And almost simultaneously the door will explode open as the SWAT guys come in and put them in cuffs and read you your rights. All because someone you thought you knew, was unwilling to spend time in jail rather than help the FBI with their investigation.
Law enforcement has a number of tools (many dubious like the CFAA) which they can employ against you, and they will.
The best you can hope to achieve is to keep a solid (and I mean solid, no slip ups anywhere) public front of respecting the copyright holders rights and your willingness to protect them. Otherwise you will be served papers to decrypt other buckets and you will be sent to jail for contempt if you do not facilitate rooting out copyright infringement on your service. Not even keeping your servers and company in a foreign country will help unless it is a country which doesn't care about its relationship with the US.
As a Turtl user, you'd have to be careful about who you share with (or accept shares from). We even outline this on our security page (https://turtl.it/docs/security#when-is-turtl-not-secure).
It seems at some point the app you're using becomes irrelevant and what you actually do with it becomes much more relevant (such as a bittorrent client).
> why not just email someone a copyrighted file? Once the
> file is downloaded to their email client, they are in
> the same position as they would be in if you shared it
> via Turtl.
Not exactly, there have been a couple of ultimately unsuccessful cases which are similar (but not exact) with people getting mailed kiddie porn and the federal agents tried to arrest them when the mailman handed over the letter/package.The successful prosecutions I've read about involved three things, 1) an opportunity, 2) an awareness of the legality, and 3) the follow through even when there is no reasonable doubt.
Bittorrent is a good example here, and cassette tapes are as well. All of the outward facing material from these folks are focused on legitimate uses of the service, it doesn't keep people like cassette makers from being sued, but it gives them a pretty credible defense. In the linked article you mentioned using Turtl specifically to avoid copyright enforcement, a judge or jury reading that could be persuaded that you intended to facilitate copyright infringement and that intent would make you liable for any copyright infringement that occurred by anyone using the Turtl service. The point I was trying to make is that you are doing the prosecution's job for them when you write
"So how does Turtl deal with copyrighted material?
We don’t. We don’t know what you’re storing. Neither do copyright holders. Neither does the government.
That’s how we like it =]"
It will not be difficult for a prosecutor to use your words to a Jury and show that you like that people can violate copyright with your service and that you made the service so that they could.
And once the prosecution has made the jury understand that, you will be convicted of abetting copyright infringement and either broke for the rest of your life paying off an infringement judgement from hell, or serving time in prison.
All for stuff other people did using your service, because you made it so they could. See how that works?
Child porn is strict liability (meaning, there's no requirement to show you did anything on purpose). The law generally doesn't require that you be aware of the legality of what you're doing ("ignorance of the law is no excuse").
Now, it's easy for me to believe that if you can show affirmatively that you received child porn by accident, for example through the unknown-to-you malicious actions of others, the judge might let you off, but that's not actually encoded in the law; the federal agents you mention have an accurate view of things.
Can you point out a case where someone knew they were in possession of or receiving child porn, but got off because they were under the impression it was legal?
Kind of like destroying someone's reputation via sybil attacks, on an app like lulu or yelp or whatever. The NSA had slides on how fake victims could write blogs about being raped or mistreated or whatever.
The classic Japanese serial novel Musashi ( http://www.amazon.com/Musashi-Epic-Novel-Samurai-Era-ebook/d... ) includes a fairly disturbing subplot about the protagonist's reputation being trashed by a little old lady of no significance who follows him around insulting him to anyone who will listen. Despite the fact that no one knows her, and many significant and influential people know (and like) him, this prevents him from landing a respectable job.
The mail service has a remarkable ability to track mail packages, even those not sent by certified or registered mail. Additionally, police stations log all calls received--there's no such thing as an anonymous call. The use of a pay phone, prepaid cell phone, or online burner number is a huge red flag--it supports the recipient's defense that someone is attempting to ruin their reputation. Plus, almost all child pornography cases are coordinated with a special DOJ task force, due to the international scope of this offense.
Once it's been established that the recipient is being framed, the police--and the FBI--turn their attention to finding the actual perpetrator. The use of the postal service makes the frame-up a federal crime.
This is actually how the FBI actually cracked one of the more infamous child porn rings a few years ago--some idiot tried to frame his neighbor over some stupid dispute and they traced it back to him quite easily.
> The evidence that petitioner was ready and willing to commit the offense came only after the Government had devoted 2½ years to convincing him that he had or should have the right to engage in the very behavior proscribed by law.
Jacobson was let off on grounds of entrapment; the reasoning was that the government specifically persuaded him to do what he otherwise wouldn't have done (or at least, what it could not be reasonably shown that he otherwise would have done). It's not obvious that that has much to do with whether he was or wasn't aware that child porn was illegal; the fact that the entrapment campaign included political literature protesting government intrusion tends (IMO) to suggest that he was.
Legality does get coverage as an issue, but it seems to be mostly (again, all I did was read the wiki article) as a way to show that Jacobson wasn't a suitable target for the entrapment campaign in the first place; the argument went that buying legal child porn doesn't demonstrate that he's likely to buy the same child porn after it becomes illegal.
Now, it's easy for me to believe that if you can show affirmatively that you received child porn by accident, for example through the unknown-to-you malicious actions of others, the judge might let you off, but that's not actually encoded in the law; the federal agents you mention have an accurate view of things.
If you can show affirmatively that you received child porn by accident, the judge will let you off, because there wasn't any intent to possess child porn. Moreover, the prosecution will go after the person who sent the porn to you, and will likely recommend a good civil attorney for your lawsuit against that person.
But yes, if you want to run a file sharing site whose main purpose is uploading copyrighted material, you had better avoid leaving a paper trail containing anything damaging.
I'm not in need of their service, but they will never have me as a serious client after a blog post like this.
There have been posts here before about alternative services getting a 51% customer increase on days where a breach in security or general trust is broadcasted to the world.
They do. They send data over HTTPS from the Dropbox client, and they store it "encrypted" on S3, but they hold the encryption keys and also have full access to the unencrypted data while it's in memory on the servers.
Turtl encrypts all data with the user's personal key before it leaves the client, meaning the server has no access to the unencrypted data.
As far as hashing in the client, that's true, we actually could do that, and it might be a viable option if we ever implement public file sharing. Right now, all sharing is person-to-person (and private).
This app is largely a response to the overreach of the US government. While I believe in fighting for our constitutional rights politically, private solutions are also a viable means of protest.
We probably will have liability issues down the road. Nobody said this would be easy. However, being completely transparent and publishing all our code open-source will help mitigate a lot of these issues. On top of this, by making the clients able to secure their own data, the company itself can respond to any government information requests without actually revealing any customer data.
In the Post-Snowden world, I think it is.
This being said, shouting "yes we can do this if you share copyrighted works!" means begging to be sued by the content provider on a contributory infringement basis. Hence it is far better to point to non-infringing uses, and general privacy features.
- Encryption works by blocks and do not generally hide the size of the plaintext.
- Once I get the encrypted material, I thus approximatively know the size of the original file within a few bytes (uncertainty is due to padding to block size).
- I collect a few candidates files with size in the right range (There might be only one but it's still deniable).
Knowing your login information and the algorithm used to "derive the key from the login information", can't I encrypt the candidate and test against the encrypted material ?
I'm not sure how much more clear I can be. Turtl doesn't know your login information, and doesn't know any of the keys derived from your login information. That's the point of the login...it's a familiar way people use to authenticate themselves with a service, but with the added benefit that it's actually generating a master key for them.
Also, not sure how many files there are floating around the internet (and off of it) but it's quite a bit, so comparing file sizes isn't going to give any real information (at least in regards to copyright protection).
If I were to launch a service like this, I would describe this issue in terms of general privacy, and the fact that the nobody else has any idea of what is going on. With Snowden, the obvious point is that it is private from the NSA.....
The correct way is to create a (signed) package of your app so that it pulls in no external scripts or files. Makes updates a pain (no free auto-upgrades you get from the web) but makes the app a lot more difficult to attack.