Indian Programmer Exposes Code Injection, Gets a Cease and Desist from Injectors
techcrunch.com
techcrunch.com
Thejesh has accused Indian Airtel and Flash Networks Layer8 of something that may be a crime (depending on the particulars of Indian law) and is definitely a scandal. Specifically, the accusation is that Flash Networks Layer8 wrote a piece of malicious software and that Airtel injected it into customers' network connections. Thejesh republished the injected script on GitHub.
Flash Networks sent a nasty letter to GitHub asking them to take down the evidence, claiming that their malicious software is copyrighted. GitHub complied.
In most countries you are forbidden to take photos in a private setting without permission, and in some even in public.
wvenable's comment is on point. Just as public websites aren't public domain, publishing information delivered on request might not be legal.
You might claim fair use if you published it as part of an article, but probably not on GitHub which is intended for using and editing code.
For example, even if you are worried about personal data, you can still publish a fingerprint if you don't identify the individual.
But that begs the question, as ad injectors are probably not illegal.
[1] http://www.cardozo.yu.edu/sites/default/files/Eldar%20Haber,...
In fact, it doesn't sound like it was even going to be used to inject ads except for offering users to upgrade to larger plan when they were near their data expiration.
I agree that any code injection is shady and unwanted but you're just making stuff up.
> “This is a standard solution deployed by telcos globally to help their customers keep track of their data usage in terms of mega bytes used. It is therefore meant to improve customer experience and empower them to manage their usage. One of our network vendor partners has piloted this solution through a third party to help customers understand their data consumption in terms of volume of data used.”
The same thing was claimed about various malware in the past, which was found capable of doing all kind of weird things way beyond "improving customer experience".
"3.unauthorised modification of computer material, punishable by 12 months/maximum fine (or 6 months in Scotland) on summary conviction and/or 10 years/fine on indictment;[8]"
Does India not have something similar on the books.
i can probably patent a full auto gun, even if it's illegal for me to have one
But... since copyright automatically applies to all works, yes, I think it does and should apply to illegal code (and every other code or work out there).
Having said that, I don't particularly see much morally objectionable with what this guy did in this case, even if its not legal.
I brought a few examples (like antiviruses). How publishing security research even into the public repository with the code of malware that's involved wrong? Fair use should cover it. If it's indeed illegal, then all antiviruses are illegal too, because not only they publish - they redistribute that said code.
Antivirus software isn't distributing the copyrighted virus, and I can't begin to wrap my head around the conception you must have of how they work, in order to think they do. Copyright is utterly irrelevant to the relationship between computer virii and antivirus software.
Why not? Many of them include patterns for detecting viruses, which literally contain originals in some way (partially at least). There are tons of malware types, including one that's not polymorphic.
Regardless, even if they include malware in full, it should be perfectly fine under fair use. I.e. that malware souldn't be protected by the copyright in such case (because it's for the purpose of security).
Think of it in criminal law terms: it's like the "affirmative defense" that having a medical marijuana card gives you in states that have such programs. Pot is still illegal, but if you get caught with some, and have a card (and are compliant with the restrictions of your local MMJ program), then the charges are dismissed.
It doesn't change the law; it changes how the law applies to you.
It doesn't remove them, it just says that that they aren't even applicable in that case. I.e. there is nothing to remove when it's not there to begin with.
I agree that it's somewhat poorly defined that's why there can be different ways to view it. See https://w2.eff.org/IP/eff_fair_use_faq.php
Approach of "affirmative defense" doesn't sound logical to me. Approach of limiting copyright applicability makes more sense. I.e. fair use defines some borders beyond which copyright can't reach.
In other words, distribution of a copyrighted material isn't considered fair use until a judge says it is.
That's an interpretation of what fair use is. Another one says that it defines public rights, as in limiting the reach of copyright. I.e. it defines exceptions to where copyright applies (and this makes perfect sense to me, unlike the other interpretation). I.e. it defines uncopyrightable scenarios.
The problem is that the law itself is not clearly defined, that's why it becomes a matter of interpretation and is given to judges to handle. May be copyright reform can fix this making this an explicit right in the law to avoid this ambiguity.
But it is.
So, there's how you appear to think it works, and there's how it works in the world outside your skull. It turns out, that things in the real world are sometimes sloppy, or inefficient, or illogical, or just plain weird; just because something makes "more" or "perfect" sense to you doesn't begin to make it correct.
So where did presumption of innocence go? I know it's tossed out all the time in copyright (that's the core of the whole DRM approach), but it's not supposed to be that way. If they claim that copyright is violated, they need to prove it (i.e. violation and lack of fair use), and not those who say it was fair use need to prove they have that right.
And if you say that's what's going on in practice (presumption of guilt) - then the whole system is seriously perverted and requires deep fixing.
Which might be an interesting discussion to have, if you were aware enough of how things actually worked to understand the difference between civil and criminal court proceedings. "Presumption of innocence" exists in criminal cases. The kinds of suits that copyright holders tend to engage in over things where the defense argues Fair Use are overwhelmingly civil. (Seriously, has there ever been a criminal copyright infringement prosecution where the defense argued fair use? If so, how did that work out for them?)
Please stop spouting off about how shit should be based solely on an embarrassingly broken a priori idea of how the things you're railing against work, and try to understand how they really, actually work. I promise you that, if nothing else, doing so will better enable you to fight the fight you seem to believe so much in.
Either way, I'm not going to argue any more with you, if you continue to insist on engaging from broken premises. Enjoy the rest of your day.
The DMCA favors copyright complainants but it also completely absolves providers of liability. So it's a messy compromise.
That's right, but you have to defend against what they should prove to the court. But @rosser is claiming that it's not even applicable in the civil law. That's really surprising to me (IANAL just to be clear), so I want to understand why.
This is why, for example, a criminal defense of insanity must be proven by the defense — and why such a defense is risky. The defense is stipulating to the fact that the defendant committed the act, but arguing the defendant didn't have the requisite mens rea to make their actions a crime. That eliminates the State's burden to prove that they did it, and assumes the burden of proving the defendant's state of mind/lack of culpability at the time.
In a civil case, the question is more one of "Here's why Shmerl is responsible (and, consequently, liable) for what happened." The facts (that Shmerl did whatever, to whomever, at whatever time) are often stipulated to. The positive assertion being made by the plaintiff against him is the degree of liability.
Consider the oft-mocked case of Liebeck v. McDonald's. No one disputed for a second that she bought the coffee at McDonald's, that it was the temperature it was, or that it was spilled. That wasn't remotely the question. Rather, the question was, "Should they have known better, to a degree that makes what happened to her their fault?"
Does that distinction make sense?
But they have to prove that those facts constitute a violation of copyright, don't they? And that's not given, since that should mean they have to prove it's not fair use (since fair use can be viewed as a right). If it's not viewed as a right, then what you said is correct. But how it's viewed is decided by the judge ad hoc (since the law is ambiguous). Or there is some other logic there?
1. The server has no access restrictions for the Javascript URL, presumably. So, if you trust the server's configuration to match the owner's intent, then the owner was saying "this page is intended for public consumption."
Which is to say, importantly, not only for their customers to view in exchange for their subscription fees (which would put the ad-injector script under license of whatever TOS the customers agreed to), but rather for anyone to view who has no prior relationship with them, for any purpose.
This is the "reproductions are allowed of works of artistic craftsmanship (buildings, sculptures, etc.) that are permanently situated in a public place or in premises open to the public" argument.
2. The owner never put a copyright claim against anyone else making copies of this work. Like the Internet Archive's copy of their website, say (if there is one.) That would suggest this takedown notice is a motivated use of copyright law to attack someone, rather than business-as-usual of them enforcing their IP.
Judges don't like it when you have a history of not caring about people doing something you could have complained about. They take that as evidence you don't care.
3. Fair use! This is a:
• transformative use (it's visible source code, not an executing program!),
• of a small part of their copyrighted work (it's just the Javascript!),
• intended for a purpose that could be said to be both parody (revealing a previously-unnoticed essence of the original work through transformation) and edification (teaching people that the network is doing this thing.)
There's probably even more arguments than these. I hope the poster takes some of them to Github with a counter-takedown to get their repo back up.
That argument did not help weev with AT&T. If they are distributing the code, they are allowed to do that as the copyright owner. That's why it's called copyright. But that doesn't grant anyone else the right to distribute the content. By your argument, any content posted anywhere publicly on the Internet is not subject to copyright restrictions. Which is clearly not the case.
> The owner never put a copyright claim against anyone else making copies of this work.
It's unlikely they are aware of anyone else distributing their work. This may be the only unauthorized distribution of this work so far.
> transformative use (it's visible source code, not an executing program!),
There is nothing transformative about this.
> of a small part of their copyrighted work (it's just the Javascript!),
It must be very small; an excerpt. This is not an excerpt of the program.
> There's probably even more arguments than these.
If they're of the same quality they're unlikely to make a difference. These are poor arguments. Fair use never* applies to copying a complete work.
* It's perhaps possible; but this case certainly doesn't qualify.
[1] “This is a standard solution deployed by telcos globally to help their customers keep track of their data usage in terms of mega bytes used. It is therefore meant to improve customer experience and empower them to manage their usage. One of our network vendor partners has piloted this solution through a third party to help customers understand their data consumption in terms of volume of data used. As a responsible corporate, we have the highest regard for customer privacy and we follow a policy of zero tolerance with regard to the confidentiality of customer data. We are also surprised at the Cease & Desist notice served by Flash Networks to Thejesh GN, and categorically state that we have no relation, whatsoever, with the notice.”
scott@arciszewski.me
Fuck censorship.
Error 526 Ray ID: 1f474c500f7a0ef1 • 2015-06-10 18:56:46 UTC Invalid SSL certificate
Regardless, I have other domains/sites for mirroring content. ;)
even though I see the same error when going directly to https://arciszewski.me/ does not.
My guess is that arciszewski.me is not on the certificate because it is not meant to host web content, only the subdomains do.
I was using the WiFi at the Bangalore or Mumbai airport one day when I realised that half of the websites appeared broken in some way. I looked into the code and realised that the WiFi provider was injecting JavaScript ad codes in all the web pages I was visiting.
I talked to some people about it, but no one seemed perturbed. Such invasions of privacy are a hallmark of Indian companies. Even more perturbing is the lackadaisical attitude of consumers towards such breaches; most them don't think it's wrong.
On a slightly un-related note: India has a national DND registry, for preventing marketers from spamming users' phones. I have filed over a dozen DND complaints and appeals over the last year, with Airtel and Vodafone, against major e-commerce Indian companies. It's amazing the extent to which these operators would go to suppress the issue. None of my complaints were resolved, and I still get spammed. People tell me - It's just a bunch of messages. Ignore them.
That's a very weirdly-opinionated statement. Isn't GitHub legally required to obey the DMCA request?
http://thenextweb.com/in/2014/12/31/vimeo-github-30-sites-bl...
I'm guessing they reject obviously spurious and incomplete/ill-formed ones.
(Sometimes the DMCA agents screw up even worse. For instance, there's evidence that some of them forget important keywords sometimes, and end up issuing a takedown on all the top links for searches like "download".)
But more generally -- yes, it's a huge problem that the DMCA has few consequences for "spray and pray" takedowns. While there are some provisions in the law for damages against knowingly issuing an invalid takedown, it's incredibly hard to prove (I'm not sure if it's ever happened!), and in any case, it doesn't apply if the takedown was simply sent in error. Even if you make that error repeatedly, and don't do anything to prevent it.
if you are innocent, you don't need safe harbor because well, you're innocent!
but just like every criminal case in the usa where law representation is far from fair and free, its often better to accept the guilty while being innocent just to avoid the legal costs.
that's why dmca stinks. it forces your hand even more to just assume guilty for the low cost of censoring someone else in favor of someone that can pay a legal battle.
>an Indian Airtel customer, Thejesh GN, discovered that the carrier had begun using Flash Networks Layer8 “monetization” (read “ad injection”) solutions.
>However, like so many ridiculous cease and desist letters, that hasn’t stopped Flash Networks lawyer Ameet Metha at Solicis Lex from trying to scare Thejesh
>Airtel, for their part, told Storypick that they have nothing to do with the C&D:
I'm curious if the above copyright infringement would stand in court or not... Copyright infringement normally does need intent and I'm not sure if this is really intent or not.
I'd love to hear a more professional analysis on this angle.
The problem with injecting code into html is that it "adapts" the work, and adaptations requires copyright permission.
A lot of pages aren't https yet though.
Edit: Here's the link: https://letsencrypt.org
The only way I see out is to hurt these companies as much as possible. Boycotting their services on a large scale, so they get to know that they are not the king here.
I got on instagram.com (when it was still served over HTTP) one day and noticed an alignment issue. I believe reddit also had the issue. It was caused by a rogue iframe that was being injected into the page.
After some investigating the iframe domain was owned by my ISP. I sent emails to some of the higher ups telling them they should stop and the problem disappeared after about a month, and wrote a chrome extension to block the domains in the meantime. Not really sure what their idea was but it goes to show that you can't trust your ISP anywhere in the world (or anyone on the internet for that matter).
(I mean, they are abusing the system, but not in that particular way.)
Perhaps an "us" as opposed to "them" pre-supposition on the part of writers wherever they are?
So a U.S.-based press outlet might write this:
"The Game of Thrones cast includes British actors Kit Harrington and Emilia Clarke"
But a U.S.-based press outlet would probably not write this, because it is assumed their audience is American and the "default" nationality is American unless stated otherwise:
"The cast of Seinfeld includes American actors Jerry Seinfeld and Julia Louis-Dreyfus"
In the case of the OP, TechCrunch is an American based outlet with a heavily American-skewed audience. If this case involved an American programmer who exposed the flaw, it might not be in the headline, but it would likely be stated in the body text since the story deals with two foreign-owned entities and the readers could likely be curious about the affiliation of the programmer.
The guys that were from Russia and tried on wall street were referred as Russians too.
http://www.mid-day.com/articles/10-interesting-facts-about-f...
>On the 31st birthday of noted American programmer, software developer and co-founder of the social media giant Facebook we look at some interesting trivia about the man and his creation...
"It took a long time for the international media to pick up on the story,
so I spent a long time following the Kampala hashtag on Twitter and
checking my e-mail," said Jonathan Gosier, an American programmer
living in the country.
And: http://www.bbc.com/news/technology-21280943 There's a buzzword, coined by the American programmer Ward Cunningham,
for the problems hidden in computer systems as a result of corners being
cut: technical debt.
Also: https://www.google.com/search?q=%22american+programmer%22+si...