Popcorntime is leaving GitHub
status.popcorntime.io
status.popcorntime.io
But this: https://github.com/github/dmca/blob/master/2014-07-11-MPAA.m... ... this is great marketing for popcorntime. It shows it working and giving an experience that looks very much like Netflix.
Seems like the MPAA have given popcorntime some free marketing.
Reading the DMCA notice though, does it really apply to a repo of code?
Their argument is that it can access infringed content (but so could a web browser, or network media player, etc) and that MGM vs Grokster means that "the distribution of a product can itself give rise to liability where evidence shows that the distributor intended and encouraged the product to be used to infringe". But if Github can be considered the distributor of the product (rather than just the hosting company for source code) then I'm not sure Github have ever intended or encouraged use of the product to infringe, or indeed whether Github have any interest in the use of code hosted in repositories by them.
Do Github just roll over on DMCA requests? Or will they challenge ones like this where an entity is requesting a takedown even though the code itself contains no infringed content and Github have not encouraged use of the code to infringe?
Because Netflix takes forever to get the latest movies, and is filled with terrible straight to dvd movies! :)
My parents use Netflix and I recently got a request from them to set them up to access US Netflix. I didn't even know they were aware of the difference, but they are, and they're sick of the crap that shows up on our side of the boarder.
Not Netflix' fault, and I'm elated that they're pressing the ISP issue, but there are valid concerns about content as well.
At any rate, I don't think the implication is obvious.
Netflix claims they are just using the product made available to them since the content publishers issue "rental-only" discs with inferior quality product. Apparently Netflix lacks the buying power to influence the quality of product they can make available to their customers.
http://blogs.indiewire.com/shadowandact/films-on-spike-lees-...
https://help.github.com/articles/dmca-takedown-policy#b-coun...
And then it would then be incumbent on the users to fight that?
They're not hurt at all by popcorntime going down.
That said, yes the DMCA can be abused. The check against that is the same check that exists against other kinds of fraud: it's illegal.
> A statement that the complaining party has a good faith belief that use of the material in the manner complained of is not authorized by the copyright owner, its agent, or the law.
(emphasis mine)
Of course the third case is a very dangerous game to play, if you're DMCA-trolling (filling false notices) you're guilty of misrepresentations which is covered by 17§512 (f):
> Any person who knowingly materially misrepresents under this section—
> (1) that material or activity is infringing, or
> (2) that material or activity was removed or disabled by mistake or misidentification,
> shall be liable for any damages, including costs and attorneys’ fees, incurred by the alleged infringer, by any copyright owner or copyright owner’s authorized licensee, or by a service provider, who is injured by such misrepresentation, as the result of the service provider relying upon such misrepresentation in removing or disabling access to the material or activity claimed to be infringing, or in replacing the removed material or ceasing to disable access to it.
17§1201 a.2:
No person shall manufacture, import, offer to the public, provide, or otherwise traffic in any technology, product, service, device, component, or part thereof, that— (A) is primarily designed or produced for the purpose of circumventing a technological measure that effectively controls access to a work protected under this title;
17§1201 a.3.A:
to “circumvent a technological measure” means to descramble a scrambled work, to decrypt an encrypted work, or otherwise to avoid, bypass, remove, deactivate, or impair a technological measure, without the authority of the copyright owner; and
In order to maintain safe harbor, Github is only required to remove things in response to a valid DMCA notice.
They are welcome to push back on invalid ones with no fear of anything.
Invalid DMCA notices do not give any notice, so they wouldn't even be in trouble under the red flag provisions.
Which is a dangerous bet to make, if they mis-classify a request as invalid they've lost their safe harbour and can be sued. It's easy to understand why they'd take the content down straight.
Github definitely has compelling incentives to remove content on receiving a DMCA notice. If they receive a notice that they think is completely bogus, they do have the option of not responding to it.
Plus they'd definitely lose.
I believe that's exactly what the DMCA requires that GitHub do. If GH want to continue to get the advantages (for them) of the DMCA (i.e. safe harbour protection), they need to just follow it without question.
But PT is pretty awesome if you live in an EU country where Netflix is not available
It really is wildly inferior to the US version and I think I'll be cancelling as soon as the GF has finished the few shows she does like on it.
Source: PT dev
Many countries don't have Netflix yet. Or have crippled versions of it.
Most specifically, GitHub has no legal standing to challenge a takedown request. The uploader of the targeted content is the only one who can challenge.
There are basically zero places online hosting content from 3rd party entities which do not honor DMCA takedowns. Given the size of copyright violation penalties, ignoring them is tantamount to corporate suicide.
This is false. I was personally involved in one very large one (190k+ source code projects) where we pushed back on clearly invalid legally (but not syntactically) DMCA requests all the time, such as for trademark violations, or claims for source they didn't own, or ...
Github does not appear to be a worsening monoculture (though it is, in a lot of ways, a monoculture).
Are there zero such places outside the United States?
Github is legally required to do so, if they don't they're legally on the hook. The whole point of DMCA Title 2 (the Online Copyright Infringement Liability Limitation Act) aka DMCA 512 is to create safe harbour for service providers (protect them from liability), but to claim safe harbor requires:
1. not financially benefiting from infringing activities
2. not be aware of obviously infringing activities before being noticed
3. act expeditiously to remove the purported infringing material upon receiving a notice
Point 3 has two clauses: purported infringing material means the service provider must not make any attempt at judging whether the infringement is real, if he does that he becomes liable because he's injected his own judgement in a case previously between the copyright owner and the purported infringer.
The first clause has not been tested in courts (for precision), it's generally assumed to mean "under 24h" or at least "as soon as feasible" (e.g. ops may not be available over week-end). The service provider is not supposed to contact anybody before taking material down although he is free to notify the purported infringer before or while taking the content down (as long as takedown remains "expeditious").
Github can challenge a DMCA request, but in that case they lose their safe harbor provision and are on the hook if the DMCA was valid.
This DMCA notice is obviously invalid, as it is a claim not that the source code identified infringes copyright, but that activities performed by users of a program that is compiled from source code that can be found on github, infringes.
It's not even a remote indirect claim. There is nothing about the source code, as source code, that infringes.
Just because you can make out a possible copyright claim against someone in court does not mean you can form a valid DMCA notice about it :)
Followup after actually reading the law. 17 USC 512(c)(3)(A)(iii) provides that a notice includes "Identification of the material that is claimed to be infringing or to be the subject of infringing activity..."
Popcorn Time is the subject of infringing activity, and hence this would be a valid takedown notice.
You also don't "lose" safe harbor, right? It's applied on a case-by-case basis.
I acknowledge that one very good reason to be careful about this stuff is to stay out of court, regardless of the fact that Github would inevitably avoid liability.
In this case, what is being alleged is that Popcorn Time is being used for infringing activities. If Github had not responded to the DMCA notice, it could be successfully argued in court (remember, it's a jury of laymen that make this decision) that Github knew that PT was primarily used for an infringing purpose and continued to host PT despite this knowledge. This could have exposed Github to a finding of willful infringement, which carries the aforementioned $150k penalty. (Github and PT would both be defendants in such a case, but as the deeper pockets Github would be the primary target and the one required to pay up in the event of a loss.)
The statute on its face doesn't require actual facts of infringement to be included in the notice, only a good faith assertion that infringement (or use in infringing activities) is occurring. Consequently, that allegation is sufficient for purposes of the DMCA notice. Indeed, that is the holding of the cited cases, which are included with the notice to show that courts have found that a good faith belief of infringement is sufficient.
Actually, they do. Look, I'm a lawyer who, among other things, helps process DMCA requests. The service provider does not have to comply with obviously invalid DMCA requests to maintain safe harbor. In particular, things that are not properly the subject of a DMCA request are invalid requests, no matter how "well formed" they otherwise seem.
Alternatively, under 512(c)(3)(B)(ii), github could have asked them if they were the authorized owner of popcorn time, or otherwise attempted to get them to clarify.
"Popcorn Time is the subject of infringing activity, and hence this would be a valid takedown notice. " Err, no. Subject of infringing activity is talking about websites that host files for users, not source code to programs that, 65 steps later, may possibly be used to infringe.
As 512(c) itself says, it is "for infringement of copyright by reason of the storage at the direction of a user of material that resides on a system or network controlled or operated by or for the service provider"
IE direct hosting.
(one of the other subsections deals with linking sites, and that clearly doesn't apply either)
Please explain how github's storage of source code of popcorn time, alone, is somehow infringement of copyright (hint: there is no legal theory where it is, any more than there is a legal theory that owning the machinery to a printing press is).
It's way too remote a connection to be "the subject of infringing activity", and no court has ever held otherwise.
As for whether they get to make this decision, in order for it to be a valid DMCA notice, it has to be directed at something valid to be filing a notice for under 512(c). It isn't. It's not a valid notice, no matter how formal it looks.
Additionally, it requires "A statement that the complaining party has a good faith belief that use of the material in the manner complained of is not authorized by the copyright owner, its agent, or the law."
The material complained about is popcorn time. They cannot possibly validly make a statement that popcorn time is not being used as authorized by the copyright owner, it's agent, or the law, as the use is clearly authorized by the copyright owner of popcorn time.
Instead, they made a statement that operating and further evelopment of popcorn time causes a bunch of stuff that, later on, may cause something unauthorized by the copyright owner.
Here is the exact statement the MPAA made: "occurring by virtue of the operation and further development of the GitHub projects Popcorn Time, and Time4Popcorn (the “Projects”)."
This is not a valid claim under 512(c) or 512(d), and i'd challenge you to find a case that says "operation and further development of a project" is the proper subject of a DMCA notice under 512(c).
The proper thing for the MPAA to do, if they wanted it down, was file a contributory or indirect infringement case against github.
Who sadly doesn't have an email address in his hn profile (although maybe you're just in house at a larger entity, vs. available for startups).
There's no way they have any good faith belief they own the copyright to (or are authorized by its holder to act in their stead about) the material explicitly named.
I'm just going to assume that their lawyer is smart enough to not have filed a DMCA notice, as such, and just send a thuggish letter instead.
This language also refers to computer programs, such as Napster, et al., and by extension to the websites that host them.
If your employer is willing to gamble on its safe harbor exemption by making its own judgment about whether the substance of a notice is adequate, that's fine. If a copyright holder decides to pursue a matter further, your employer may be willing to accept the legal cost of defending itself in court from an invalid copyright infringement claim it shouldn't have had to fight in court. But most websites and businesses aren't in the same position, and would rather just avoid court (and the attendant costs) altogether by accepting a DMCA notice that is, on its face, valid under the law as presently written.
Instead, they made a statement that operating and further evelopment of popcorn time causes a bunch of stuff that, later on, may cause something unauthorized by the copyright owner.
Until recently, the PopCorn Time website, hosted by github, provided executable files that would provide access to infringing content on startup. It's an even worse example of contributory infringement then Napster or Kazaa were; those programs at least required the user to search for infringing material first.
The proper thing for the MPAA to do, if they wanted it down, was file a contributory or indirect infringement case against github.
They can't do this until and unless GitHub fails to properly respond to the DMCA notice. The whole point of the safe harbor is that a content hoster is protected from infringement actions so long as it responds to DMCA notices. Maybe you should work on the litigation side before you talk about the mechanics of how things work once a court gets involved?
No, it doesn't. Napster itself was not the subject of a DMCA take down It was the subject of a copyright lawsuit. Nobody filed DMCA notices about the hosting of Napster binaries. Napster in fact, sought protection under 512 for other reasons.
"that is, on its face, valid under the law as presently written."
I don't know how many times i have to say this DMCA notice is not valid on it's face.
Do you think if i file a DMCA notice, and tell you to take down something because it is infringing my patent or trademark, that it is a valid DMCA notice?
Assuming not (because if yes, there is simply no hope for this discussion), what legal difference do you believe exists between that, and a DMCA notice also not targeted at something statutory to DMCA, like this one?
"They can't do this until and unless GitHub fails to properly respond to the DMCA notice. "
False. This assumes they were going to sue for direct infringement of a user hosted file. They weren't.
Expecting Google, GitHub, or anyone else to protect you when you are writing an app/service like popcorn time is dumb. But that is a different argument than the one being made here.
The question here was whether ISP's or hosting services can ever push back. They can.
Which is surprising, considering the integration opportunities around other services like https://cloud-playground.appspot.com/playground/
But if the PT devs were smart, they'd put it back up as a generic streaming torrent client setup to run public domain videos out of the box.
I don't understand how playing an unlicensed torrent makes the source code to the software infringe on the DMCA. Shouldn't they also send pictures of the computers which are running Popcorntime to the computer manufacturers and tell them that they are infringing for enabling Popcorntime? And pictures of the running software to GNU for creating the compilers that compiled the code?
Because when all you have is a hammer, all of your problems begin to look like nails.
The DMCA gives the MPAA a hammer to go after copyright infringement. It is significantly easier to just apply that hammer to the hosting company of the software to try to make the software go away than it is to apply that hammer to the actual copyright infringement (one application vs. thousands of applications). So they just apply the hammer to that which they can apply it.
When I first learned about Tor and the way it worked I always figured there would be a Tor equivalent of Github out there. The recipe for building such a site is pretty straight forward. Add a tor:// URI to git and there ya go.
That end users of popcorntime can use it to violate copyright (although it's not a circumvention tool per se) isn't Github or popcorntime's problem.
The ideal, since notice can be email, is to notify the infringer of a DMCA complaint and let them counter respond very quickly, to minimize any service interruption.
There are maximum response times, but no minimums. The entire process can be turned around from notice to "dude, you have DMCA" to "oh, hell no" inside an hour. (EDIT: Actually, this is incorrect. To do this requires various hacks, or accepting liability as the service provider.)
The secret is usually providers actually want to get rid of their DMCA-attracting clients for commercial/cost reasons, so they rarely are willing to make the process of response particularly efficient.
(The counter also requires disclosure of intensive amounts of personal data, which the initial notification does not, but that's probably the smallest problem with the DMCA system.)
See 512(g)(2) B and C of the DMCA for cites.
(Thankfully, I've never been the one to actually handle DMCA issues from the service provider side myself.)
> People aren't going to share patches via email to each other.
Why not?I thought you cant distribute, or have a binary form of program to downloads for your users, but source code of it should be allowed.
Have I misunderstood the story or have things changed?
It found that the source code could violate the DMCA even considering free speech. The court forced him to take the DVD decryption source code down.
Wouldn't it help to just publish a BitTorrent sync url somewhere and host the bare git in that that folder so that it always updates and syncs directly to the cloud?
They shouldn't want safe harbor then.
It's like wanting Google to be the legal shield for everyone committing copyright infringement on their sites. It's not remotely economically feasible.
These battles wouldn't even be fought "on behalf of their users", because the entities taking them to court would also be taking the end users to court.
What happens when little assholes like this target something bigger, for example Linux? After all it can be used for all sorts of downloading.
http://eur-lex.europa.eu/legal-content/en/ALL/;ELX_SESSIONID...
To maintain the benefits of limited liability for their users' actions, a service provider must "act expeditiously to remove or to disable access to the information concerned" upon "obtaining actual knowledge or awareness of illegal activities". The easiest way to make a service provider aware of illegal activities is to notify them with evidence, like the identity of the copyright holder, identification of the original works, and attestation that the copyright holder did not authorize the copies, which are the exact content of a DMCA notice.
So, send a letter (provide awareness of illegal activity), remove the content, and the host can't be sued. That goes for all EU member states; the deadline to implement this directive into local law was back in 2002. Five non-EU-member states implemented it as well. That's in addition to the nearly 100 signatories to the WIPO treaty.
It's true that the format and timeframes of the DMCA system are more formal than the EU directive's requirements, but no matter what part of the world you look in, almost every developed country has formalized such a system in order to limit liability of content hosts for their users' action so long as they take down material under certain conditions. Some of the EU countries did formalize notice-and-takedown procedures of their own even though it wasn't required.
http://en.wikipedia.org/wiki/Notice_and_take_down#European_U...
If you want to stop random contributory or indirect infringement, they should have actually sued in court.
I'm sure github just didn't want to start a war.
17 USC 512(c)(3)(A)(iii) provides that a notice includes "Identification of the material that is claimed to be infringing or to be the subject of infringing activity..."
Popcorn Time is the subject of infringing activity, and hence this would have been a valid takedown notice.