“I'm wiping this repository away”
github.com
github.com
Just saying.
If you develop a web service and make it accessible from the public internet, what restrictions should you be allowed to place on its usage? And what should the consequences be for individuals trying to bypass those restrictions?
Whatever you want. Public API access =! protected right.
> And what should the consequences be for individuals trying to bypass those restrictions?
Denial of future access by technical means.
However, providing the tools that allow instituting legal restrictions is a big can of worms; property rights just don't apply cleanly to client/server communications.
The solution is to require API accounts, which you can then monitor and terminate with prejudice. Tie the account to something unique-ish, or difficult to constantly cycle (SMS? check provider, deny if Google Voice, Twilio, has to be a physical carrier if we're talking messaging client).
The law may eventually catch up to tech. Maybe.
Similarly when someone uses a server in a way you don't like you send 'people with guns' to resolve any disputes, because in this case lawyers are believed to be cheaper than changing the server.
This isn't about the ideals of law and power, it's about getting people to stop doing things you don't like, apparently WhatsApp chose a reasonably effective strategy.
Not everything is special simply because it's digital.
Imagine if Windows Server had been SaaS; Samba would never exist, Mac OS X and Linux couldn't operate in a Windows environment.
Where property law falls down is when we consider what it is you're selling -- access to a service, or a fully controlled end-to-end service agreement where you assert control over both the client and server.
If it's the latter, does this create a healthy market, or does it create something that could never exist before: the ability to create a "natural monopoly" on an individual customer level. That is, once people are invested in your platform, the cost to compete for that person is so high that it creates a nearly unassailable barrier to entry?
Pre-SaaS, if someone wanted to compete with Microsoft Office, they could invest the effort supporting the Office file format to ease customer transition.
Post-SaaS, if Google Docs, Office 365, et al disallow data/API access to third-party clients, supporting your competitors' existing customers becomes impossible.
Anything else basically ends up a) not working and b) requiring government intervention of one sort or another, eventually, and that harms everyone.
Have Oracle's attacks on open source software [1] affected their ability to hire and retain talent?
Is there any example where bad behavior by a large organization [2, 3] meaningfully affected its ability to buy the talent it needs?
[1] http://www.wired.com/2010/08/oracle-attacks-opensource/
I know that I have had the opportunity to apply to work at the NSA. When I was looking for job opportunities after college I perused lists of government jobs, including positions at the NSA. I know that today, I would not apply to work there. I'm one person, but I know many engineers of a similar mindset and read about many more, so I assume it's a trend. I definitely don't know what rate of potential applicants conform to this mindset, but I know some do (me, the people I know like me, and voices I've heard on the internet).
Therefore, I can meaningfully argue that they would have a harder time hiring. Of course I might be wrong but that's what you get when you operate with incomplete data.
However, it takes a special type of odd personality to work there (doing amazingly cool stuff but not being able to talk about lots of it). The personalities that fit there well don't fit elsewhere very well.
Source?
I think NSA employs over 30k people. You're going to make a baseless claim that they all share one common personality trait, making them a poor fit for any other possible place of employ, in the whole world?
Really?
We know, for a fact, that the vast majority of NSA employees are willing to subject themselves to enhanced scrutiny (limited travel), behavioral controls (they will discuss your porn and online accounts), and submission to a fairly arbitrary set of rules (such as polygraph tests) that have no proven connection toward their job or efficacy.
Okay, so, we HAVE demonstrated that NSA employees do share at least one common personality trait that is reasonably unusual in the general population.
Perhaps I was being a bit overzealous and should provide a bit of exception. People who stay with the NSA for very long don't fit elsewhere very well.
Now, this probably doesn't apply to those who don't have security clearances. But then, you're basically claiming that the NSA is just like a standard employer--and that's not normally what people think of when they think of "working for the NSA".
I'm not sure this part is true. "submission to a fairly arbitrary set of rules" sounds like every job.
> that's not normally what people think of when they think of "working for the NSA".
Most people working for the NSA aren't working as a "Jason Bourne"-type (which is what we think of as "working for the NSA).
I would claim the NSA's very much like a standard employer... but with a (significantly) more heavily enforced NDA.
That makes a huge difference.
(long-form: https://www.reddit.com/r/mildlyinteresting/comments/2j7jo4/r...)
Just saying.
In a longer term, open solutions prevail. OTOH it might be not the moment yet for WhatsApp. Compare the stance of Microsoft in 2005 and 2015.
In related news: "Facebook drops hint about MAJOR changes to WhatsApp – and you are NOT going to like it" [1]
[1]: http://www.express.co.uk/life-style/science-technology/57826...
A second question is: so you have the right to build a client. Do you actually have the right to run that client against their service? Is that "unauthorized access"? It makes sense that you can control who accesses your computer system; controlling how they do it seems murkier to me.
That's something that courts have been trying to figure out. The most famous case, of course, is Oracle v. Google.
I think the biggest thing here was the usage of WhatsApp and the name WhatsAPI.
Aside from an overloaded meaning of the term "API", the two situations have very little in common.
I don't know enough about the CFAA to say whether providing the tools to exceed authorized access counts as an additional violation. But it would be reasonable to assume that creating the tools required (sporadic) efforts to exceed authorized access.
Another practice would be changing the '1' to a '2' in the URL http://www.example.com/1.pdf, since the computer running www.example.com is a 'protected computer', and you didn't get authorization to access 2.pdf on the server.
"Protected computer" is basically any server. The CFAA defines it as any computer used or affecting "interstate or foreign commerce", which works out to be most of the internet, thanks to CDNs and the practice of centralized data-centers.[2]
[1]http://www.huffingtonpost.com/2015/01/20/obama-hackers_n_651... [2]https://www.law.cornell.edu/uscode/text/18/1030
One important consideration is whether your state, local, or national laws consider possession to be prima facie intent to commit a crime. http://lockwiki.com/index.php/Legal_issues
It's hard to picture a 'legal' use for something that is tied to a proprietary API.
Also, TOR was funded with illegal uses in mind. Beneficial to the US government, perhaps even legal with the US, but illegal in their intended application.
In what way is browsing the internet without someone recording your every move illegal? You may choose to use the anonymity for illegal purposes. But you may also choose to use your car or house for illegal purposes and no one says that these should be illegal.
Tor was, in part, made for countries where that is illegal.
As for bans on knives and such, I consider such bans just as unjustified.
Their service is their software. They have control over it. If they wish to impose technical limitations to how it may be accessed and by whom, that is entirely their prerogative. Nothing in the law can tell a company or a user otherwise, short of subpoenas for customer data or some such like that.
I think the larger legal issues come from the fact that circumventing these technical limitations can lead to to degradation of value and security for a company's customers due to derivative products created via this unauthorized client -- much like what has happened with SnapChat and third-party services retaining snaps. If systematic unauthorized access to a system could serve to diminish the value and trustworthiness of a company and its brand, you're damn right they will legally pursue those enabling it.
But developing the tool isn’t illegal in any way.
But the situation here is that the customer is offering its consent to use their data on another platform or application.
The same holds for rooting android/iphones and making them do what you want. Not getting into legal details, you should own your data across services and your hardware that you buy.
Adding technical barriers is one thing, suing and interdependent group of people trying to learn the API and building tools on top is completely unfair.
I mean if they made it for themselves and didn't share it maybe there wouldn't have been a problem, but I still wouldn't spend my time reversing a closed protocol without expecting the hammer to drop at some point.
I'm not clear on whether you can write a client for someone else's protocol, but I can say for sure that I have every right to incercept and block any and every request that the official app makes, despite SSL. I pay for my internet connection, not the app developer.
Since that happens pretty much every time you write a line of code, I would say it's a pretty important question. Whether or not you distribute said software, whether you distribute it in binary or source form, and whether you charge for said software are all interesting confounding variables and it would be extremely interesting to delve into whether those factors impact the result.
Keep in mind this is simply software which sends and receives packets over a network. The server has no obligation to response, and there is no "linking" of libraries. Let's assume that none of WhatsApp's code is being distributed (assume a clean room implementation of the API, not decompiled from WhatsApp source)
I wonder if things like if WhatsApp included a magic string in the header, and then claiming copyright of that string, if that could also impact the legal result.
If the owner says "don't do that" and you do it anyway, even if there are no technical limitations, you are committing a crime in the eyes of federal law.
Even if they don't tell you no and you just start poking around and accessing random (or guessed) API fields, it's still a federal crime since you "circumvented" their exposed interface.
> It makes sense that you can control who accesses your computer system; controlling how they do it seems murkier to me.
"How" can be difficult in a web context (browser vs. crawler), but in other contexts such as a mobile-only app with a proprietary API, they can say you're "hacking" their system if you access their system without directly interacting with their app (again, even if there are no technical limitations). Basically, just do this: http://static4.businessinsider.com/image/54db994569bedd6e65f...
If gaming companies are able to use such absurd interpretations of IP law to win $7 million judgments against people who modify clients in-memory on end-user machines, then I'm sure a company with the capital of WhatsApp can destroy any open source developer that they want to.
[1]http://en.wikipedia.org/wiki/MDY_Industries,_LLC_v._Blizzard....
[2]http://legal.ceilingfansoftware.com/
[3]http://services.runescape.com/m=news/g=runescape/jagex-vs-ib...
Seems like game companies can argue (and IMO be correct) that bots are damaging to the game and community. Technically you're "just" injecting code into their software to make it operate differently but they typically have a EULA to prevent this.
Spam? On Whatsapp? I've never heard of such a thing.
"This is venomous0x's and other contributors information. They developed it on their own and have no contract with you, and as such are free to do with this information as they see fit. Your lawyers, who are under contract with a local Bar Association may be in violation of their contract if they continue to make some outlandish claims concerning the law. We shall not be hearing from you again in this matter."
The number of cases handled by this method now, today, in the USA is far larger than the number handled by courts.
The government run the courts in a very inefficient way that makes the costs of lawsuits very high, and take forever and less reliable than arbitration.
Worse, courts interpret the laws often in a way that favors the government. EG: Courts are not actually neutral in the way that arbiters are. (Remember many judges are hired via election, many more are appointed by elected politicians and these politicians re-electability depends on who they appoint... at the federal level the judgeships are highly political.)
A lot of big problems, like copyright and patent disputes, could be resolved more quickly via an arbitration method (where the possibility of getting an arbiter who actually understands the technology issues at hand is a possibility.)
Second, arbitration among entities with vast differences in power is not fair because the more powerful entity will tend to have greater control over who they pick, thus corrupting the process.
I seem to remember that some 250 years ago there was a revolution where part of the discontent was about proper access to the justice system. The insurgent party won and they wrote such things as right to jury trial into the constitution.
Time to have another revolution, isn't it?
And the arbitration process will inherently be biased. Which party picks the arbitrator? Pays them and has a long-term relationship with them? Not the customer.
So yes, the customer may have a long-term relationship with the arbitrator and may even pay them. It depends entirely on the situation. (For example, I know an arbitrator that I have used in the past and would be willing to use again.)
https://github.com/venomous0x/WhatsAPI/tree/16a6349a1fbc9e9a...
And all pull requests - add .patch to the URL to pull it out as a diff - see https://api.github.com/repos/venomous0x/WhatsAPI/pulls?state... and
Currently trying to figure out how to transfer issues and comments over as well.
This one found via a recent merge-request is current to 9/2014.
He didn't actually even wipe the history.
(I'm not saying I want them to do that -- just curious why the lawyers aren't using that technique.)
If WhatsApp is invoking other, non-copyright theories, a DMCA takedown related to those theories would be invalid.
Still, most platforms have somekind of program like eBay's Vero service that is used to report and enforce violations of its terms of service that trademarks and copyrights not be used without permission. Which would have been the better way to go in this case.
It sounds good, we'll do this basically free for you and collect our own fees from violators. But they don't know just how much damage these groups can do to their credibility. Rolex is another company that has lost my business forever with their scam.
The law states you have to send a letter. The scam part is in demanding money or profits made from a perceived violation of IP. Companies that do that crap can die in a fire.
https://github.com/venomous0x/WhatsAPI/tree/fd07b49a459cda25...
... and it didn't work, causing only "brief downtime", probably because it didn't actually fall under the DMCA.
Just another reason the DMCA is fundamentally broken.
It was mostly used by websites offering a web based chat interface for WhatsApp and by spammers.
https://github.com/venomous0x/WhatsAPI/tree/fd07b49a459cda25...
The "non-circumvention" clause in the DMCA is often used to go after people reverse engineering DRM, but I fail to see how it would be applicable in this case.
1) can do Chat+Voice securely, 2) works on Windows, Mac, iOS and Android?
Now I'm only waiting for Google to completely kill XMPP access to Talk/Hangouts. That will be... frustrating.
"Immediately take steps to preserve all documents,
tangible things and electronically-stored information
potentially relevant to the issues addressed in this letter."
I'm not a lawyer and don't know how enforceable it is, and I doubt that WhatsApp would take any action once the repository is no longer a concern, but I'm curious if there are any comments about this.However, even if they did keep the source code, there are issues and other information on github that would not be preserved. I think it's safe to assume this information is very relevant to litigation involving a scenario such as this one.
Even if that wasn't a factor, the court may get the idea that the repository was wiped in order to destroy evidence. Convincing them otherwise may be technically challenging.
If a defendant is so warned and destroys evidence, then the trial court may impose sanctions such as an adverse inference instruction (essentially, instructions to the jury that any evidence not produced by a side should be inferred to be damaging to that side's case). So any lawyer who stayed awake during civil procedure is going to make sure that they keep that option alive in the event they decide to sue.
IANAL, but unless it's a court or other public body telling you to do something, you are under no obligation to do anything whatsoever. Lawyers use scary words to intimidate and scary regular people but until the courts are involved, they're just posturing. In doubt, always ask a real lawyer before doing anything rash.
(Finding forks of this is really easy; for example, you could go to the Pull Requests tab, and check some of the authors there.)
EDIT: Immediately in people-time, not some git mechanism :-)
Specifically, git is a DVCS/DSCM (distributed version control system/source code management system), which means that each "checkout" of the repository that exists is a complete clone of the original, including the full commit history and a cryptographically verifiable codebase.
In this world the "master" repository is simply a convention: everyone agrees that <insert person here> has the "master". But in reality everyone's copy is a peer of every other.
Sharing between repositories can be done any number of ways. Github is convenient, but originally email was the way code moved between copies. In fact, I host a number of my own private repositories over straight SSH.
So Github is a useful piece in the puzzle, but fortunately it's not a single point of failure in any way.
Correction: the clients are open source.
Any context would be appreciated.
It's easily as good as WA and truly multi-platform.
(Disclaimer: totally unconnected to Telegram).
http://security.stackexchange.com/questions/49782/is-telegra...
Now, could there be side channels they would use to pressure and bully him into giving up? Sure. But I would love to hear more from this venomous developer.
No matter how bigger WhatsApp gets, I am glad there are some alternatives.
As the saying goes: "don't roll your own crypto, unless you're a professional cryptographer, and even then…". Telegram are not cryptographers but decided to roll their own anyway and have come in for not a little flack as a result.
Search for "telegram app crypto criticism" and you'll find plenty of examples of this.
Is Telegram secure? I'm not qualified to answer that, but I understand enough to be sceptical.
And tell their friends to do the same.
It's easy for me because I don't use it but I suspect that for some it will be difficult, imagine telling your girl friend that you are deleting Whatsapp and that she can't contact you that way any more.
Combining them together should not be a copyright infringement of "WhatsApp."
I've seen numerous application turned down for using generic terms like this.
Probably the one and only time I'll say the government does a good job.
"Whats" isn't a generic term in the computing field. "WhatsAPI" isn't a dictionary word, it's a colocation of Whats and API, the first element being chosen specifically to render association with WhatsApp. The use of WhatsAPI differs in only one letter from the trademark.
IMO provided they headline the fact they're not associated nor extraordinarily authorised by WhatsApp then there would be no actual trademark issue; the law I suspect will see it quite differently.
“WhatsApp Messenger is a cross-platform mobile messenger that replaces SMS and works through the existing internet data plan of your device. WhatsApp is available for iPhone, BlackBerry, Android, Windows Phone, Nokia Symbian60 & S40 phones. Because WhatsApp Messenger uses the same internet data plan that you use for email and web browsing, there is no cost to message and stay in touch with your friends.”