Qualcomm issues DMCA takedowns for 116 GitHub repositories, including their own
ausdroid.net
ausdroid.net
I believe the text of the DMCA is written to cause this. If you are an ISP, and you don't want to be liable for infringments, you have to take things down after receiving a DMCA takedown notice. The end.
You can put it back up after the user has followed the right procedure to challenge and assume liability themselves. I admit I'm not sure exactly what procedure the DMCA outlines for this.
I think what ISP's _could_ do is facilitate user's filing challenges more easily. But they've got to take it down after receiving a takedown request, that's pretty much what the law says (or else the ISP can be sued for the copyright infringement too).
Theoretically you can sue someone for issuing a takedown request in bad faith. Perhaps ISP's could help their users do this too, but it could get sticky for them.
The fact is that while section 512(f) of the DMCA provides consequences to misrepresentations by those making takedown requests, it is damned impossible to actually enforce that.
Now, I guess an ISP _could_ individually evaluate each DCMA takedown request, decide that some of them are completely illegitimate and there was in fact no infringing material, and thus that they have little legal risk to leaving it up, and probably nobody's going to take them to court over it, and if someone does, the ISP will probably still win and they're willing to deal with it.
I think it's pretty obvious that it's not really reasonable to expect a business to do this (by assigning an actual lawyer to evaluate every request? By trusting less trained/certified people to make the determination? Even paying them minimum wage it's probably not affordable), although it would be pretty exciting if one decided to anyway.
http://www.diynetwork.com/about-us/dmca-digital-millennium-c...
But yes, effectively, it is not reasonable for a company to ignore the takedown request.
This needs to be done by larger companies. Right now all a person has to do is claim copyright infringement, and companies take down. There is a guy on Ebay who claimed he owned the copyright to a old watch making school workbook(Chicago School of Watch Repair). Well he didn't own the copyright, but Ebay wouldn't even bother to look into it. There should be clear penalties for falsely claiming ownership to a copyright? I understand small companies caving in, but larger companies should do a little due diligence?
Yes, see, that's the law. That's the way the DMCA is written. If someone files a DMCA takedown, companies have to take it down (or risk liability themselves). Right.
To change it, Congress would need to change it, there's nothing larger companies can do.
You know, like a mad-lib "Your site has our content askjdh12312312.avi on the link yourtube.io/5h0rtur1/ and must be removed to comply with yadda yadda yadda".
It's probably five kinds of illegal and three kinds of immoral, though.
Bot or not, this is an intentional action by Qualcomm. Github should push back against this if it wants to remain credible in the open source community. Are there some general provisions in the law that allow it to respond to abuse (which this is a clear case of) with their own lawsuit?
Of course, the Qualcomm repository should be pulled. Permanently.
They're the employees who will have to get in and make changes to the system and they work for the companies that have to make noise and say no to the DMCA issuers.
If they blanket exclude their own employees of the policies everyone else has to abide, well, that'll say something won't it. There seems to be no negative effect of making false DMCAs so play that game.
Unprosecuted crimes (e.g. the perjury one must commit to file a false DMCA notice) have a strange way of suddenly becoming prosecuted crimes when people act in blatant disregard for the law.
So if you say, "I'm requesting you take this down because it infringes on Star Wars and I'm an authorized agent of Disney" when you have no relation with Disney, you're up for perjury.
However, if you say, "I'm requesting you take this down because it infringes on blahblah.avi and I hold copyright to blahblah.avi" which is true, then no perjury penalty. Even if blahblah.avi has nothing to do with the github repo being taken down. "Oops, my bad, honest mistake, wink wink." The person on the receiving end of the DMCA still has to jump through all the hoops to get their own copyright material reinstated.
So if you do your bot right, there's no penalty. None at all. If there is, I'd love to know about it, because these bots need to die in a fire.
> Qualcomm is the owner of an exclusive copyright for each of these documents. Cyveillance is authorized to act on behalf of Qualcomm, and has a good faith belief that the publication and/or disclosure by your web site is not authorized by Qualcomm, any of Qualcomm’s agents, or the law. I certify, under penalty of perjury, that the information in this notice is accurate.
The pertinent document: https://github.com/CyanogenMod/android_device_sony_huashan/b...
[1]: https://github.com/github/dmca/blob/master/2014-07-02-Qualco...
Recently I found that one of my popular posts on startups had been boosted without permission or credit by some wannabe-accelerator in Texas. I filed a DMCA request and their host took the page down promptly. It just worked.
I'd hope Github is doing some basic checks on requests like this. But I don't want them to try to become a mini-court. We already have a perfectly good court system for resolving ownership disputes.
You're not allowed to do that without losing the safe harbor provisions of the DMCA. Anything that shows up that matches the format must be obeyed. That's why counter-notifications exist.
Certainly I don't see anything in the law itself that prevents them from verifying that the notice actually comes from the entity claimed, or saying, "Hey buddy, are you sure you really own that?" Which is all I meant by basic checks.
Are you aware of some case law that demonstrates otherwise?
On what do you base your guess? Because as I understand it, your guess is 100% wrong.
One, if I read the safe harbor stuff correctly, then if you ignore a DMCA notice it means you can now be sued for hosting the content. If a host decides they are willing to run that risk, I believe they can happily ignore a DMCA notice.
Two, basic business knowledge. YouTube partners with a lot of the major media companies, and taking down large volumes of their stuff in a way that looks dumb would harm their partnerships. Companies are very reluctant to bite the hand that feeds them.
Three, if someone could take down everything on YouTube by forging a zillion DMCA notices, I expect some enterprising troublemaker would have done it long ago just for the lulz.
Ok! Your turn. What's your evidence? Because that's what I asked for before and nobody replied.
Also, I have heard of this happening with people sharing open source software on bit torrent. This isnt the original article I read but the closest one I could find.[1]
[1] http://max-technology.blogspot.com/2008/12/open-source-torre...
Even in a notice and takedown system, the time required to act on the notice could be increased to ensure that the target has an opportunity to counternotice, and the counternotice could be made immediately effective, rather than effective with a delay.
But the opportunity for counternotice seems like a great idea, perhaps including some discretion for the hosting company. When the DMCA was written, they would have had to allow for a relatively long period. But now that we all have the internet in our pockets, it seems like a few days or maybe a week would be plenty of time.
Patent trolls are ok too ?
http://www.theonion.com/video/nations-parents-release-annual...
http://www.urbandictionary.com/define.php?term=perfectly%20g...
While I agree with the sentiment, this statement is a bit extreme. Especially since it's a distributed system so you're not exactly losing your work. Also, you can get it back online if you jump through the flaming hoops. In reality there is no better option for hosting OSS code right now than GitHub.
You're right that your code isn't permanently lost, but you're wrong that GitHub is the only option or even the best option for hosting your code. GitLab and gogs are incredible pieces of software and if your needs are small, you can even just use cgit or the built-in gitweb tool. DigitalOcean is one host that can trivially provision GitLab instances.
I've hosted my own git server for about a year at https://stealthis.ca. It costs less money than GitHub's cheapest plan and supports unlimited mirrors and private repositories with any amount of collaborators. It also has never went taken my code offline, ever, for any reason. You can guess what'd happen if somebody sent me a DMCA request.
/*
* This file was originally distributed by Qualcomm Atheros, Inc.
* under proprietary terms before Copyright ownership was assigned
* to the Linux Foundation.
*/
http://webcache.googleusercontent.com/search?q=cache%3Ahttps...Most of other repos seem to use some sample code from SDKs.
http://webcache.googleusercontent.com/search?q=cache:https:/...
In the legal profession you have to do someone extremely egregious to see any action taken against you. Just look at examples like Jack Thomas, or Prenda Law. It took extreme actions for Bar Associations and Courts to even consider the idea that a lawyer might not be acting in good faith.
2. Diebold probably spent significantly more than $125k just in defending the lawsuit, so the end result of forcing them to pay out $125k is more of a moral victory than anything else.
3. The Diebold case had the benefit of the content itself (internal emails discussing issues with voting machines) being unquestionably in the public interest.
No, it's much more important than that. If you win, it would establish legal precedent, which would make companies think twice before pulling this type of shenanigans in the future.
"A statement that the information in the notification is accurate, and under penalty of perjury, that the complaining party is authorized to act on behalf of the owner of an exclusive right that is allegedly infringed."
"A physical or electronic signature of a person authorized to act on behalf of the owner of an exclusive right that is allegedly infringed."
The EFF filed an amicus brief (https://www.eff.org/files/filenode/Hotfile.EFF_.Amicus.Brief... ) arguing that this kind of takedown was illegal. Warner Brothers, unsurprisingly, disagreed (http://www.scribd.com/doc/184407656/warnperj542724ff-69be-42... ), with the primary argument being that the perjury language only refers to the claim that the agent is authorised on behalf of the copyright holder to act on their behalf, and not on the claim that copyright is being infringed.
https://github.com/sonyxperiadev/prima
Lets hope this pisses off enough people to actually go after Qualcomm for such an egregious mis-use of the DMCA.
https://github.com/github/dmca/blob/master/2014-07-02-Qualco...
As you can see there's a lot of stuff that is unlikely to be copyrighted by Qualcomm in there, like .conf config files.
Given one lawsuit can cost hundreds of thousands of dollars in litigation even for the winning side, it would be impossible for any ISP to operate in a climate where they could be dragged into every argument over content rights. Github is not the authority. They don't know if the code is inferring or not, so the DMCA says they can defer the authority (and liability) to those who should know, the ones who put the code up in the first place.
It is unreasonable to expect Github to vet every open source project, and it is also unreasonable for Github to bare any legal responsibility just because one of their users, or a litigious copyright holder did something wrong. The DMCA Safe Harder is designed specifically to account for this.
Although technically possible it is not legally possible to issue a DMCA take down by bot, since a bot can not provide: a statement by the copyright owner, a statement of the accuracy of the notice, or a statement under penalty of perjury that the complaining party is authorized to act on behalf of the owner.
[My opinion is, if a real person uses a bot and then makes these statements under penalty of perjury, then every time that bot makes a mistake we (the tech community) should be filing Amicus curiae[1] with the court that they have perjured themselves. If you are a technically competent person you cannot honestly make a statement that your bot has not made any mistakes without human review.]
The weakness of the DMCA Safe Harbor arises not in the above issues but rather in the fact that the DMCA requires that materials be taken down immediately before response by the allegedly infringing party[2]. To balance that (to some degree) if the allegedly infringing party follows the procedure to have the materials restored, then the ISP must restore the materials in 14 days unless the complaining party has shown evidence they have filed a case.
In other words if a complaining party fails to immediately follow with a lawsuit the materials MUST be restored.
This is not, in fact, true. The provider is not required to restore the materials. The provider is, however, no longer protected from any liability to the user whose material was taken down that would have existed without the DMCA if they don't restore the material in response to a proper counternotice, but most proviers have already structured their contractual relationships with users so that they have no liability for that in the first place, so they don't need the safe harbor from the user, only the one from the copyright owner.
Which is the real source of asymmetry -- the safe harbor is superficially symmetrical, but one side is protecting from liability that doesn't exist in the first place, so there is no incentive for compliance.
If the copyright owner does not bring a lawsuit in district court within 14 days, the services provider is then required to restore the materials to it's location on its network.
Edit: You cannot contractually exempt yourself from portions of the DMCA. It either applies, and you are protected under the Safe Harbor provisions, or it doesn't and you are not.
Here's why it's dangerous for the ISP:
If I'm a copyright holder and find infringing materials on your service I will issue a take down notice.
You take the materials down. All good you think.
Nope. I then sue you (you've got more money then the infringer anyway).
You say "but, but, your honor we complied with the DMCA"
But I say "oh no you didn't you don't allow for your users to file counter-notices. Time for the court to decide."
And now we're in trial, because you don't have DMCA protection.
Is it an absolute fact this will happen? No, but the problem is it could happen, and that is exactly the liability the ISP is trying to avoid. And why, just so they can be an asshole to their users? There is absolutely no upside to exempting yourself from the counter-claim procedure.
Its really not.
Unlike with copyright owners, the ISP usually has the advantage in terms of resources and ability to maintain a legal challenge when compared to users.
Unlike with copyright owners, the ISP usually has a contract with users which already allows them to take down any material, for any reason, in their sole discretion, making the DMCA safe harbor superfluous.
Unlike with copyright owners, even if there were liability to users, that liability would (under well-established contract principles) be almost certainly limited to no more than the amount the user had paid for the service for the time in which the material was improperly kept down.
> But I say "oh no you didn't you don't allow for your users to file counter-notices. Time for the court to decide."
How does that have any bearing. Each half of the DMCA safe harbor expressly applies based on whether or not you did the act you are required with regard to the party with liability in that case. So, the fact that you didn't do something with regard to some other party on the opposite side of a DMCA notice/counternotice exchange in a different case is irrelevant.
> Is it an absolute fact this will happen? No, but the problem is it could happen
Anyone could theoretically raise any argument no matter how little basis it has in the law, but that doesn't make it a real substantial risk.
My point is that the DMCA can be used as a get out of a lawsuit free card only if you comply with it. In all other cases you are exposed to a 'question' of compliance which requires the involvement of a finder of fact. That equals risk to me, and again to what end?
However, if you comply fully with the DMCA you cannot theoretically or otherwise raise any argument against the ISP under copyright infringement or unlawful takedowns, period. Move away from complete compliance with the DMCA and yes you can still 'argue' that you are protected but you must pay to make that argument in the course of a suit. That to me is a liability, even from a winning position. Plus you are also exposing yourself to broader actions by cilvl liberties and other organizations working for the 'users' rights who did not agree to your questionable contract.
That is a lot of risk to assume, for what purpose exactly? Laziness?
Edit: Personally though I agree the DMCA is a poor tool for the job and needs to have much stronger teeth in favor of the users (read: citizens).
Its not an issue of "contractually exempting themselves from law". There's no law providing general liability to a user for an ISP taking down material. The only liability that would exist for doing so would be for breach of contract. Which would mean that there would have to be a contractual obligation not to take down the material for there to be a need for the DMCA safe harbor. Which ISPs routinely already avoided, before the DMCA even existed, by having contracts which expressly included provisions indicating that the ISP could take down material in their sole discretion. As regards to the user facing side, the DMCA safe harbor is, therefore, usually irrelevant. (There are no doubt some exceptional cases with atypical contract schemes where the contractual relationship is different -- but they aren't usual ISP or other content host to typical public user agreements.)
> My point is that the DMCA can be used as a get out of a lawsuit free card only if you comply with it. In all other cases you are exposed to a 'question' of compliance which requires the involvement of a finder of fact.
That's almost 100% backwards. Asserting an immunity to liability based on compliance with the DMCA is asserting a defense which requires the involvement of a finder of fact -- compliance with the DMCA is a question of fact. But whether question is relevant requires there to a basis for legal basis for a claim under which you could be held liable before considering the DMCA safe harbor -- which is often what is missing on the user-facing side.
> However, if you comply fully with the DMCA you cannot theoretically or otherwise raise any argument against the ISP under copyright infringement or unlawful takedowns, period.
Incorrect. You get to raise the argument first. The provider/host can then use its compliance with the specific DMCA safe harbor provisions relevant to its liability to you as a defense against that claim, and if it does so, it is immune from any liability. But they don't have to show that they "comply fully with the DMCA", they have to show that they complied with the requirements related ot the claim being advanced. If you are a copyright owner, they show that they complied timely with the takedown notice to get out of the copyright claim. If you are a user, they show that they complied with the counternotice to get out of whatever claim (presumably, contract-based) that the brought. But you first have to have a claim that doesn't get thrown out as a matter of law before raising the DMCA safe harbor defense even matters.
> That is a lot of risk to assume
Really? A lot of risk? Can you name one case where a succesful lawsuit was brought against any content host, ISP, etc., for failure to restore content subject to a DMCA counternotice? Or even for policies that involve more drastic than takedown penalties -- like contract termination -- for suspected copyright violation without any advance notice or opportunity to respond?
Ah well, like I said we disagree on the risk. In which I mean the cost of doing business, not the danger of losing a lawsuit. I think you've missed my point, and are conflating 'legal certainty' and 'winning argument'. Also you avoided addressed why a service would act against their own users in such a way, even if the perceived risk is small. (By the way I would argue many if not most, DMCA related litigation in which ISPs have lost shows that failure to comply strictly with all aspects of the DMCA was the ISPs downfall, please forgive me for not including citations ;)
Nevertheless, you have excellent points as to why we need to replace the DMCA, and why there may be a perception that there is less risk in ignoring a restoration demand then complying with it.
For example 512 requires that: "the transmission, routing, provision of connections, or storage is carried out through an automatic technical process without selection of the material by the service provider"
Demonstrable proof of non automated selection such as failure to comply with a lawful counter-notice voids the ENTIRE protection.
Companies such as Vimeo have lost protections under the DMCA safe harbor provisions for exactly this reason.
Has this ever been done successfully? I found an example in Disney v. Hotfile[1] but it was eventually settled out of court and not in Hotfile's favour.
An honest mistake shouldn't constitute perjury, but the shotgun approach is not acting in good faith.
This may or may not be such a case, but is calming your code is flawless under penalty of perjury an honest mistake?
find a case, even one, where there has been a significant penalty for incorrectly issuing a dmca request
I said it is my opinion that we as a technical community should try to help the court. Wether we have before, or wether it was successful or not, doesn't enter into it.
Deleted comment
I really hope so. And I really hope they need to file an official challenge, and then wait two weeks, to get it back again. Like everyone else.
That's the best part of the story, they let a drone takedowner loose and actually shot themselves with it.
https://code.google.com/p/mobile-research-lab-nid/source/bro...
https://android.googlesource.com/kernel/msm/+/android-msm-ma... It looks like there was a Qualcomm Augmented Reality SDK that originated these files.
https://developer.qualcomm.com/mobile-development/add-advanc...
A lot of them looks like SDKs and stuff
Good to know not to waste one second with their products
You wouldn't normally check a JDK into a repo.
This is different from when its say a song. Its not hard to look at the song and say "yep thats metallica".