Hacker News new | past | comments | ask | show | jobs | submit login
YouTube-dl's repository has been restored (github.blog)
2636 points by fusl 11 months ago | hide | past | favorite | 658 comments

It seems like EFF fought for youtube-dl and GitHub used their letter as legal firepower to bring the repo back online. If GitHub were fighting for the developer they would have funded the attorney, right? Though from their blog post it does look like they are taking steps to fund defense in the future as well as other steps to improve the situation.

Reading EFFs claim is pretty interesting, they state that saving a copy of a video is only one function of youtube-dl. I think the biggest problem is the name is called "youtube download", it is sort of difficult to downplay that saving a copy is only one function when the name implies it is the main purpose of the program.

AFAIU the argument is more that youtube-dl is effectively a web browser and doesn’t do anything that a web browser doesn’t do. Further, it does not include any “secret” key for DRM circumvention like might be bundled with e.g. Chrome in the case of Widevine, where browser vendors agree to protect the secret key.

that's how understood it as well:

"youtube-dl stands in place of a Web browser and performs a similar function with respect to user-uploaded videos. Importantly, youtube-dl does not decrypt video streams that are encrypted with commercial DRM technologies, such as Widevine, that are used by subscription video sites, such as Netflix."

"We presume that this “signature” code is what RIAA refers to as a “rolling cipher,” although YouTube’s JavaScript code does not contain this phrase. Regardless of what this mechanism is called, youtube-dl does not “circumvent” it as that term is defined in Section 1201(a) of the Digital Millennium Copyright Act, because YouTube provides the means of accessing these video streams to anyone who requests them. As federal appeals court recently ruled, one does not “circumvent” an access control by using a publicly available password. Circumvention is limited to actions that “descramble, decrypt, avoid, bypass, remove, deactivate or impair a technological measure,” without the authority of the copyright owner."

I wonder where the phrase “rolling cipher” actually comes from. Did the RIAA just make it up?

The (English) phrase is used verbatim in the (German) 2017 LG Hamburg claim and verdict. It is not explained there, nor did the claimant explain where they got it from. I’m assuming that it’s based on a misunderstanding of “rolling codes” [1], an actual cryptographic technique, which isn’t applied here (the only overlap is that the “s” parameter of the YouTube video URI varies for certain videos; and, well, the key in rolling codes also varies).

Interestingly that verdict also claims that URL encoding is a valid, effective encryption measure (I’m not kidding! See [2]; the German word here is “Prozentcodierung”, i.e. percent-encoding).

The court in question (LG Hamburg) is infamous in Germany for its technically illiterate, consistently laughable verdicts in IT-related cases (this isn’t a recent thing — it’s been going on for about two decades).

[1] https://en.wikipedia.org/wiki/Rolling_code [2] http://www.rechtsprechung-hamburg.de/jportal/portal/page/bsh...

I would be curious if YouTube's code contained any phrases at all considering it gets minified.

Me too and it would be interesting if such phrases would be valid if not human readable.

Right, but the law makes no mention of secret keys, it just says you can't go around anything that controls access to a copyright work; and you can't provide tools to do so. The actual legal definition of tools covers both actual technical purpose as well as marketed purpose. Rebranding, say, OBS as "Recorder for YouTube" and talking about how you can use it to get around YouTube's downloading protections by screencapping the entire video would possibly constitute a 1201 violation.

There's also another question of law, though: does 1201 apply when only the intent of the DRM has been circumvented, as opposed to it's technical scope? In other words, does pointing a camera at a monitor constitute circumvention of DRM under section 1201? Most DRM can't actually validate, say, that a human is watching instead of a camcorder. (Let's ignore pesky things like Cinavia which are more akin to post-piracy frustration techniques, and easily circumvented with any kind of Free media player.) Likewise, YouTube's rolling cipher can't really validate that it's not sitting inside of an instrumented browser that will dump whatever URLs it grabs. Our hypothetical OBS rebrand wouldn't actually be a 1201 violation unless the law specifically covers things that DRM can't technically enforce but would like to.

The rebuttal to your reasoning is in the letter. Basically a federal judge has previously ruled that utilizing a publicly available password is not circumvention of a copyright protection mechanism. The code containing the "sig" (as google calls it) or "rolling cipher" (as RIAA calls it) is available to anyone by viewing the JavaScript. This sig / cipher being public means it is not a copyright protection mechanism.

The detail of the “publicly available password” case [1] is quite interesting. It’s not directly analogous to the YouTube system, but as the EFF points out, the RIAA’s reliance on German law has its own problems.

> When Petrolink learned that one of its largest customers, EOG Resources, might switch over to Digidrill’s visualization service, Petrolink took action. Instead of paying Digidrill for access to the corrected drilling data via LiveLog, Petrolink obtained a laptop running DataLogger – along with the corresponding USB security dongle – and then, after realizing DataLogger used an open source Firebird database, managed to gain access to the database by using Firebird's default administrator username and password. Armed with this access, Petrolink developed a program named “RIG WITSML” (dubbed “the scraper” or “the hack”) that could be installed on an MWD company’s computer running DataLogger in order to – in real time – query corrected drilling data from the DataLogger database and transfer that information to PetroVault for visualization. Petrolink then began installing this RIG WITSML program on MWD computers running DataLogger at more than 300 well sites.

[1] https://www.courtlistener.com/opinion/4765801/digital-drilli...

> This sig / cipher being public means it is not a copyright protection mechanism.

I can see this as ending up with Youtube being forced to require sign-ins. Massive expense for Google. Then Youtube-dl adds one parameter for the password, and we're back to square one.

Youtube wasn't behind the DMCA takedown, though. Do they even care about youtube-dl?

Google quickly kills any iOS/Android app that offers offline playback functionality for YouTube, so I can't imagine they love youtube-dl. They probably only haven't made a stink because it might attract more attention to a tool primarily only known about in techhead circles.

I think the difference is that offline playback and background playback on iOS/Android can be unlocked through YouTube Premium so those apps directly interfere with YouTube's bottom line. YouTube-dl I don't really see as directly competing with that because it's not trivial to download a YouTube video from it to your phone.

You can use Firefox mobile and the "Video Background Play Fix" addon to disable the browser APIs that allow the background play blocking antifeature.

Alternatively, the NewPipe app available on F-Droid can be used to both play videos in the background and download them.

And given how unlikely people are in the wider non-technical audience to god-forbid, run a command line program, I guess they really just don't care.

They do take easily accessible apps that use youtube-dl under the hood pretty seriously. I guess it depends on how much of an effort it is for them vs how much of their bottom line ytdl is cutting into.

> Do they [YouTube/Google] even care about youtube-dl?

A downloaded video doesn't generate ad revenue.

Yes it does. I go to the page (ad), copy the URL, and youtube-dl.

More critically, Youtube relies on network effects and people using it. Part of the reason we share family videos, educational content, and other things is so it's, well, shared. For me, the reasons to use Youtube-dl are:

1) People in bandwidth-constrained settings. If I post my videos, and colleagues in some countries can't watch them, I'm going elsewhere.

2) Remixing. If I can't make collages of family videos, I'm going elsewhere.

Youtube can serve masters like me, where it's an effective platform for sharing videos I want people to watch, and where the goal is dissemination. It can serve masters like the RIAA and the MPAA, where the goal is monetization and control. It will have a hard time serving both.

I suspect if it tries, people like me will go to someone who caters to us. A YouYesYouNoNotTheRIAAYesYOUTube. If we do, I think there will be enough of a network to start to syphon people off, and eventually, cat videos and Aunt Alice will be on YYYNNTRYYT.com, while corporate video will be on DRMed Youtube.

At that point, we'll have a replay.

>I go to the page (ad), copy the URL, and youtube-dl.

Youtube-dl has an integrated search function, so you actually don't have to open the video in a browser at all.

That's secondary to the rest of your comment, but I thought it was worth noting.

Perhaps more importantly, the number of people using youtube-dl because it allows you to watch videos without ads almost certainly pales in comparison to the number of people just using adblockers. Youtube-dl makes you wait.

there is no waiting when youtube-dl is used from mpv or similar.

Downloaded videos often get remixed into other videos that generate ad revenue. Commentary, reaction videos and compilations are substantial parts of youtube.

i often watch youtube videos from mpv exactly to get away from those distractions.

How many people downloaded Shake It Off with youtube-dl vs. the people who watched it from the official YouTube app or stock Google Chrome? youtube-dl does not nearly threaten their revenue in any tangible way.

Yes, but is there any indication that they work against youtube-dl in some specific way? Adversarial actions like changing youtube to render youtube-dl non-functional?

Youtube has to listen to the RIAA's demands because music and music videos are a huge portion of their traffic. The music industry could decide to move all that to Spotify if they chose.

Yea ha ha.

They took that poison pill already, I really, really doubt they ever new pop music stops being part of youtube in the future, the audience is too large. It would be like them taking music off of the radio because people could record it on reel-to-reels. They might stomp around a bit and try to use the law to get what they want, but when push comes to shove the big labels will keep their music on youtube.

The RIAA/NARM/etc. needs YouTube WAY more than vice-versa.

No they cannot. Music videos that aren't on Youtube don't generate much in the way of traffic anywhere else. Artists have tried it and failed.

They absolutely need eachother and can't afford to be nasty to eachother.

I am not that afraid that google would require sign-ins for everything. Even google with its massive market dominance should be pretty scared of given such a clear opening for a competitor, and being accessible without a login is a huge feature in order to get market share quickly compared to a competitor that does not.

Not to mention, all that ad revenue.

People will literally just give up and straight up do something else if content is behind a auth-wall.

You already have to sign in to view some videos, don’t you? Does YT-dL not have a way to handle those right now?

It does, but it's broken.


The developers are not responding to the issue, and from what I understand it is borderline impossible to fix, because there is an entire security team behind the Google login protection. The only workaround is to login with a browser and copy the cookies from it to youtube-dl.

> The only workaround is to login with a browser and copy the cookies from it to youtube-dl.

That's really easy to do with postman.

"Postman" seems like a pretty generic name.

Looking quickly online, maybe you're meaning this one?


I'm pretty sure that is what they mean, yes. It is a nice tool. Lets you write HTTP(S) templates with parameters and whatnot, save them in groups, send them, handle the response, etc.

Funny. I initially read that as “The Postman” - kind of like “The Batman.”

And your response is regarding whether it should be referred to in the definite article.


It just works. Every time. It’s gotta be one of the most unappreciated tools out there right now.

Why not simply create a youtube-login command that does nothing but launch an electron instance that lets you login into youtube and then returns the cookie?

youtube-dl could then call that command to obtain the cookie.

There’s a good chance that behavior would result in a CAPTCHA.

The idea, I think, is that it literally launches a browser to let a human do the whole thing.

You can automate fetching Chrome’s cookies. This is generally very useful for scraping.

https://github.com/blackjack4494/yt-dlc is maintained by someone who responds to issues.

Do you? I've never tried to watch any that have required it.

Maybe there's Red-only content that isn't advertised/recommended to non-subscribers?

Content with a certain age threshold triggers login. The last time I looked at this, embedding these videos was still possible without logging in. So there are definitely ways in accessing the content without authentication.

Hm. If embedding works maybe my ad-blocking is sufficient; or I just haven't come across any that require it. I mostly just watch woodworkers/machinists/electronics/etc. Sort of conceivable it could be age restricted but would also be surprising.

There's also members-only content on some channels that requires a paid subscription to access.

It's already there, you can authenticate using a cookie file if you want.

Or they just start to use Wildvine protection for their videos

i am already getting a "please log in" nag screen almost every time i open a video link (i block all cookies from youtube).

What is considered publicly available?

I suppose right clicking and selecting view source is ok, but reverse engineering a code out of a hardware chip isn't?

Because any kind of DRM basically has a key in the possession of the user. There are just different levels of difficulty to read that key.

as well as marketed purpose

Yes, it would be problematic if, for example, Samsung was marketing their latest flagship as "Our dark-light technology means you can take nearly pixel-perfect video of movies while you watch them in the movie theatre!"

> Likewise, YouTube's rolling cipher can't really validate that it's not sitting inside of an instrumented browser that will dump whatever URLs it grabs.

What is the criteria for differentiating between youtube-dl and a "browser"?

In this case a “browser” is a YouTube client that copyright holders are happy with, because it doesn’t provide any simple way of saving offline copies.

I agree. But that's not a viable legal definition.

There are exceptions. Access for the disabled is one of them and youtube-dl can very much be the basis for an accessibility tool.

Just re-upload it and change the readme to define "youtube-dl" and "Youtube Digital Library"

I called this a couple of times[1][2] so it is nice to finally see someone else make this argument. It seems obvious to me.

[1]: https://news.ycombinator.com/item?id=25006577

[2]: https://news.ycombinator.com/item?id=24997072

If a program had its own implementation of widevine, why wouldn't you also be "effectively a web browser" ?

Sure, it would be "effectively a web browser". But it would also require a secret key. If the program is not licensed to hold the key, that could be considered circumvention.

Other browsers have the key, why would this one be different ?

Because they have a license.

So if a program used a licensed browser as an intermediary to obtain Widevine-protected content, would that be circumvention?

I even sidestepped the obvious of loading widevine.so, running it, symbolic execution, etc. It's mostly a thought experiment to show how everything is stupid in the end.

I'm afraid in a few months/years, we'll see the hardware security level to become mandatory for Netflix, etc. And then YouTube.

In the old days, someone who wanted to send you this kind of content would build and sell hardware for you to receive and play it (like a DVD player).

Online streaming services have, in part, scaled so quickly because they run on the general-purpose computers that people already own. So they don't need to bear that hardware cost. These general purpose computers have been fertile soil to grow and nurture the seeds that software companies scatter to the winds.

How interesting it would be if it comes full circle with specialized hardware being required on each PC to receive the content stream.

That kind of "pull the ladder up behind you" strategy would be a natural thing for today dominants players to try. They benefited from an open playing field, but now they no longer need it. If they succeed, they have established a massive moat to stave off competition. If they manage to get it into standards and legislation, then undoing it would require a tectonic shift. Google is especially well positioned for this - Chrome, Google Search, Android and Youtube being potentially very effective places to do DRM media gatekeeping. "don't be evil" had to go from their mission statement. Maybe "universally accessible" will be next...

The way they do it is to bake DRM mechanisms into platforms. Intel ME, AMD PSP, Apple T2 chip/SE, those secondary computers bear the DRM hardware features, so end product manufacturers don’t have to handle it.

It's still going to be hardware everyone already owns, just with specific features. It's not a separate purchase of a dvd player, you're buying a phone that has the licensing chip built in

And HDCP is already a thing for authenticating screens.

Loading widevine.so (extracted from a ChromeOS image) and running it is exactly how Kodi reproduces DRM-protected videos.

Isn't the Widevine password essentially public as it is distributed to the client where it was extracted? Or was the Widevine key somehow stolen from Google's private repository?

There are multiple widevine keys, some are in CPU memory (shipped with the client software), some are in trusted enclaves on devices. Some of the trusted enclave keys have been dumped from hardware (nexus 6 for one, iirc) and eventually those keys were revoked or downgraded

IMHO, if it is on the client, it is public.

I wonder if the RIAA will now be putting pressure on YouTube to use the same DRM as Netflix, so that when a video is downloaded they can’t use this ‘it’s just a browser guv’ defence because there would then have to be some circumvention to make it work.

That's a DMCA argument (I'm not hacking).

But it doesn't really work: If you protect your house with no lock, not even a door, but just a little rope with a sign on: "Do not jump over or duck under this ribbon, or cut it!", that's, for the DMCA, enough - so you get into fun games where you claim that, say, a long random unique key that is right there in the HTML youtube.com serves which links to the video is a 'security measure' and that 'I shall read the URLs in this <video> tag and download what I find there instead of showing it on the screen' is 'circumventing this'.

How far can you stretch the meaning of 'circumventing access-control measures' before, in court, you lose your argument? I don't think anybody quite knows yet, but surely github doesn't want to be on the hook for it without microsoft's legal team and management signing off on the risk.

Furthermore, separate from DMCA's hacking provisions, there is simply the concept of who is responsible for any copyright infringement caused by stuff github hosts. As per 17 USC §512 (the so-called 'safe harbor provision'), the idea of claiming 'hey I just host this stuff, I'm not responsible for this, why dont you take it up with whomever uploaded this' is codified: You can do that, but it does mean that you _MUST_ take down the content in response to a takedown notice, and if you don't, then you are now liable any infringement that content makes.

The idea is that the owner of the data files a counterclaim notice, at which point the hoster (github) is free to re-host everything without opening itself up to liability, but only if, as per 17 USC §512, they do so 'no less than 10 days and no more than 14', and github did it in 1 day, so whoopsie there I guess.

At that point it does turn into a fight between claimer and counterclaimer: The idea behind those 10 days is that the supposed real content owner can then go file in court against the counterclaimer; merely filing a lawsuit is enough: Show that to the hoster (github), and they can no longer re-enable the content without then being liable for infringement by doing so.

You can't file a counterclaim until your content is removed.

Yeah, that means an utter bozo can take your content down for at least 10 days and there is nothing you can do about this. The DMCA is not particularly well designed in this manner (it doesn't protect against trolly crud well, and getting a barratry verdict in the US is borderline impossible). But that's how it works.

In github's shoes, the fact that youtube-dl doesn't infringe is relevant only insofar that they are willing to ride that notion allllll the way to the gavel in the ensuing court case, because they will be defendants if they ignore the takedown request. Presumably they weren't going to just do that without at least a close look by microsoft's legal team, and a signoff from the big wigs for the likely millions this will cost, given that US law in these matters is... well, have you ever seen one of those shows where 2 people are on a beam and trying to knock the other one off with a giant q-tip? US law is like that, except the ends of the q-tips are moneybags.

> "Do not jump over or duck under this ribbon, or cut it!", that's, for the DMCA, enough - so you get into fun games where you claim that

No. There must be an effective technological measure (objectively, according to the state of the art); see https://www.law.cornell.edu/uscode/text/17/1201 (a)(1)(A): No person shall circumvent a technological measure that effectively controls access to a work protected under this title.

This law article is utterly hilarious and self-contradictory. No-one should be able to circumvent "a technological measure that effectively controls access", by definition. If someone does circumvent a measure intended to control access, this proves that the measure was not, in fact, effective, thereby rendering the entire article inconsequential.

The lock at your door is also assumed to effectively control who can open it, but as we know keys can be dupplicated. However, it is not possible to copy it without access to your original key and the necessary effort. This is sufficient for the legislator. It would be different if you hung your key on the outside of the door a priori, like Youtube does.

It's possible to duplicate your key from the lock.

You need access to the key hole, a blank, and a file. The lock leaves scratches on the blank until it's been file down to the right spot

Ok, obvously I have too little experience in picking locks; or maybe you have different locks than we in Switzerland.

GP was speaking metaphorically, following your (GGP's) metaphor. For some reason, you abandoned the metaphoric level and misunderstood this to be about real keys and locks.

For many and most physical keyed locks, you can decode the lock with special picks or impressioning tools. It can be pretty time and skill intensive though.

I don't believe that Github actually needed the EFF's writing for this, or that they don't have the necessary technical expertise themselves. That is probably rather a protective assertion not to lose face. But at least they seem to have learned something from it now and want to review such requests technically before they (unjustifiably) act.

Github links to the EFF letter [0] in the DMCA repo.

This letter spells out in clear, convincing and explicit detail why the RIAA was wrong.

Profit-making Github and Microsoft could have performed this analysis and championed developers themselves, but it was the non-profit EFF that actually did the work.

EFF deserves more credit than just a link for fighting against this shit.

[0] https://github.com/github/dmca/blob/master/2020/11/2020-11-1...

The EFF is probably more qualified to respond to this, actually, since they have some of the most experienced lawyers there are when it comes to defending fair-use/free-as-in-freedom works from malicious DMCA notices. Microsoft's best play is just paying them, which other comments indicate they are doing.

The EFF isn't just some non-profit, it's the premier legal entity defending internet freedom. This is squarely in their wheelhouse.

> since they have some of the most experienced lawyers there are when it comes to defending fair-use/free-as-in-freedom

And why would one assume that Github or MS do not have such experts? They undoubtedly have the technical know-how, and the primary findings in the letter are of a technical nature, or even obvious to technically savvy people. And the court decisions referred to are not about fair use or free-as-in-freedom.

Because Microsoft's goals are not directly aligned with fighting DMCA and similar legislation. It takes more than being technically savvy to fight legislation like this; actually, I would say being technically savvy but not experienced will leave you in an unfortunate spot because you'll see through all the copyright stuff but be unable to effectively fight it in court.

The question was rhetoric. They have huge legal departments all over the world. Copyright, licensing and patent contract law are among the most important areas for these companies.

Yes, I've read it. That's why I came to my conclusion. Btw. nearly all of the facts in the referenced letter were expressed in HN discussions just a few hours after the takedown. From my point of view they were obvious.

I agree that they were obvious and, as you say, the HN conversations show that they occurred to many technologists. That said, I think there is an argument to say that the EFF was better qualified to write the letter. The reason being that MSFT wants to look like an impartial content host (to avoid being liable) and the EFF is explicitly an advocacy group. If MSFT advocates for content on that platform, it could be portrayed as a conflict of interest by the RIAA lawyers. I completely understand the optics of EFF doing the heavy lifting on this one.

> If MSFT advocates for content on that platform, it could be portrayed as a conflict of interest by the RIAA lawyers

Well, that's what they are actually doing now; factually, it does not matter whether there was a letter by EFF or not; they should have come to the same conclusion even without the EFF; moreover, Github/MS are not accountable to the RIAA; conflicts of interest are not an issue here; in fact, to meet the due diligence a hoster would have to check whether a DMCA request meets the formal requirements and is well substantiated, otherwise the hoster could even be liable to pay damages to the unjustifiably blocked project.

This. Github is acting like the knight in shining armor, but they really didn't do anything except respond to the backlash their complicit no-questions-asked removal caused.

On the contrary, they’re doing a lot, including establishing a $1M legal defense fund for developers and a technical team to review the validity of anti-circumvention DMCA notices. It seems like they’re doing a lot more than just paying lip service to EFF / developer freedom, and they should be commended for it.

They’re correcting a wrong because their reputation took a big hit in the dev community. Now there’s big talk of the dangers of not self-hosting your repo and the monoculture of using GitHub.

Although it probably has good intent, this is largely PR.

Or they just panicked with the RIAA request and needed time to regroup. Cynicism doesn't have to be a hobby.

Being a rube isn't a great hobby either, that's why "fool me once ..." is a famous saying. As are the various versions of "who benefits?".

Pretty decent rules of thumb.

And at a higher level ... who cares if they did it maliciously or because they "panicked", you can't ever know that anyway and either one means you can predict what they will do in similar situations.

This isn't the first frivolous DMCA request GitHub complied with. A company owned by one of the largest tech companies in the world doesn't need to "panic" about something like this.

Sounds like cynicism is your hobby, buddy.

That's not what cynicism means.

Even if largely PR, that's still a million dollars.

After Nat's cynically duplicitous comments and actions, it's hard to view this as anything other than PR. A $1 million expense is not a big advertising expense for github. It was a $7.5 billion sale. Microsoft spend 0.013% of that on this PR piece.

I can't imagine the fallout from this didn't wipe several times that off of github's valuation.

If github had done this before the EFF letter, it would have been something else. With the EFF letter, they have zero liability to reinstating the repo, and are borderline legally required to do so.

We should still incentivize correcting wrongs over letting them stand.

Open question to HackerNews: are there big tech firms that give lobbying money to free software lobbyists?

Feel free to highlight them here.

I'd rather cut this problem off at the head than sit around and establish legal defense funds if possible. I'm glad GitHub and Microsoft could help contribute to this victory though.

> I'd rather cut this problem off at the head

I don't understand what you mean by this! I know it's an expression or a way of saying something, but I don't understand what you mean

"Removing outdated or poorly written laws by paying off Congress is more effective than funding lawyers to litigate their misuse on a case by case basis forever"

I'm guessing RIAA's lobbyists are more powerful than an EFF lobbyist. By powerful, I mean have deeper pockets.

We need stop the existence of mafia like extortion rackets that claim they protect artists but in fact they line their own pockets and pockets of the labels and at the same time artists can't afford to even eat well.

Now that musicians make proportionally more from live shows (the recorded music is just the advertisement for the the show), the idea that anti-piracy is for the artists themselves is even more preposterous.

UBI + no anti-piracy would clearly be a huge improvement for the vast majority of artists and art itself. Let's just do that.

Not all artists can do shows - e.g. disabled, but I believe true fans will buy a record. I wouldn't like someone like RIAA to pressure someone into paying just because they downloaded my song to check it out (and I wouldn't see the money anyway). These days we have great technology and companies like Spotify can pay artists directly. Labels these days can only provide financing (on mafia like terms) and influence gate keepers, but this is also changing. You can totally make a commercial grade record on your own without label involvement, same with videos, merch etc. and even gigs.

They are suggesting lobbying to change the law, rather than struggling with current law in court.

Don't lobby. go to your local caucus and change it from within. Note that I said Caucus: even in a primary state there is some form of caucus where the party decides things. You want to be in this system, this is where the party platform is decided on. This is where the people who are working behind the scene to elect someone make the plans. In turn this is where politicians go to find people who will work for them. Which in turn means this is where you can have a one-on-one meeting from the standpoint of someone important to listen to. (when you spend a few Saturdays knocking on potential voters doors for someone that someone listens to you)

If both parties get anti-DRM legislation into the platform in random places you can be assured they will listen. If both parties see their big supporters as against something they will listen. Politicians do not want money, contrary to what you might think: they want a power, and in this country that means they need votes. Money (for ads) is one way to get votes, but real humans doing real work is at least as powerful.

This sounds hopelessly naive. At the risk of starting a political flamewar, it’s really not possible for any individual to effect large scale change to policymaking beyond the hyper local level. It’s especially impossible to go against massive lobbying interests like the RIAA.

You alone yes. However if everyone reading this works at the problem...

Could you imagine getting HN to agree on what the definition of Open Source is?

If someone wants to do that bit I'd say go ahead. Don't tell people not to pursue lobbying though.

After the last four years I have now blocked all social media and all american news sources in my house with the expressed intent of not hearing a word about politics, news, etc... It has taken a massive toll on how I feel day to day, I found my personal relationships waning, and made me feel uncomfortable meeting new people. I'd rather pay someone to involve themselves with this kind of world, not be involved in it myself.

You start of saying don't lobby and then suggest a course of action that is lobbying.

Lobbying is not the same thing as campaign fundraising

The meaning is to deal with a problem before it grows worse. There are a lot of variances to the expression, 'cutting it off at the head' 'Nip it in the bud' 'Cutting the problem at it's roots' They're all references to killing something before it grows more difficult to deal with.

Nipping in the bud is preventing a problem from getting worse.

Cutting the head off the snake is about removing the point of control from an organisation.

Thank you for correction.

I feel like the problem is already fully-realised in this case, so you can't "nip it at the bud" but have to stop the full-form yes? That goes along with "cutting it off at the head" moreso in my opinion.

"cut he/she/it/them off at the pass"

Pretty sure Google is ensuring employees to give money to EFF.

They should use the power of Chrome to discourage the use of DRM on the web instead.

I know you are dead serious and I agree, but this made me laugh at how such an obvious answer can be so absurd to the company itself since it's their window to the world of users. You and I would say that is their leverage in the fight of abusive DRM, yet they would argue it is what allows them to survive.

Given that Google is the author of the main browser-based content decryption module in use (Widevine), and Google also has a bunch of content provider partnerships to maintain, and they run YouTube, which in some ways relies on content owners not getting pissed off and suing it out of existence (content owners are the reason YT has ContentID, not because of any legal requirement)... I don't think it's in Google's best financial interest to fight against DRM. So they won't do that.

> I don't think it's in Google's best financial interest to fight against DRM. So they won't do that.

Yep, it's much cheaper to ensure employees to give money to EFF ;)

Whenever you watch a video you are downloading it. youtube-dl merely gives you control over where that stream goes, whether it's to a hard disk or to a media player like the regular Youtube.

> Whenever you watch a video you are downloading it.

Why is this comment downvoted? It's highlighting one of the most common misunderstandings that laypersons have regarding video download/streaming. Most people think that you can "view" content on the internet without downloading it. In this context, a tool which purports to "download" content, you know... sounds like it's nefariously doing something that the "viewing" tool (like a web browser) doesn't do.

This may be completely true in a technical sense, but that's not how the law works (see https://ansuz.sooke.bc.ca/entry/23). And while the same bits pass through your connection, this equivalence already breaks down right away: There is clearly a difference between persisting a media file to disk vs having it ephemeral in browser memory.

>There is clearly a difference between persisting a media file to disk vs having it ephemeral in browser memory.

Is there? When "streaming" video, there most certainly is a copy of the bits being stored on a disk to ensure that the video "stream" plays cleanly and without interruption.

Are you making the claim that "streamed" video is never buffered/stored on disk? That's an odd claim to make. I'm no expert on video streaming, but I would be very surprised to find that all video streams are only stored in RAM and not on disk.

I may well be wrong about that. Perhaps someone more knowledgeable could chime in.

That's again exactly the technical detail fallacy the comment you replied to is arguing against. No, they are not making the "odd claim" you suggest. They suggest that laws make the difference when deciding about infringement. E.g. by explicitly excluding temporary copies created while watching as intended, where it doesn't matter how the OS and the browser handle the memory internally, but a thing that results in a file on disk the user keeps is clearly different. (Similarly to how software being copied into swap-backed memory while you run it is not an illegal copy, whereas copying the file elsewhere might)

Certainly with DRMed video it is common for the video to never be buffered/stored on disk. Sometimes a few seconds is, but even that is uncommon, and more likely it would simply be retained in RAM now.

With more secure DRM systems the OS literally never gets access to the video buffer, protected by hardware, in order to even send it to disk.

An interesting question along these lines arose recently in relation to an Australian password disclosure law that related to accessing “computers,” which was used to compel disclosure of a smartphone passcode. To HN readers and the digital forensics people who pull data off smartphones, they’re obviously computers. But the judge was not convinced that a law written to allow access to “computers” in the early 2000s was intended to allow access to smartphones today, which contain far more personal information than the typical personal computer of 20 years ago. After all, if you asked someone “do you have a computer?” they would be unlikely to say yes based on their possession of a smartphone. And if you ask someone who streamed a YouTube video whether they “downloaded” it, I think in most cases the answer would be no. That’s why the tool is called “youtube-dl,” even though it is now used for streaming as well.

> There is clearly a difference between persisting a media file to disk vs having it ephemeral in browser memory.

yes, at some point actual human intentions must come into play. you can't defend stuff like CP by saying "it's just some EM pulses, what's the big deal?". or "no I'm not invading your privacy with my IR camera, you are broadcasting in the IR spectrum!".

in this case the implementation does blur the line a little bit. what if the browser's memory gets swapped out to a page file on a (spinning) hard drive? even if the cache gets "deleted" after closing the tab, it might be quite a while before the sectors containing that protected sequence of bits get overwritten. is this infringement?

I agree there is a legal/practical/moral difference between streaming and downloading something. But there's no need to obscure the technical difference by downvoting people when they point it out.

The point is that youtube-dl does more than just download videos. It can also be used for downloading metadata. I use -J to download metadata formatted as JSON.

Is that metadata protected by some sort of mechanism? Or is it just not queried by default using one's browser? I.e., is youtube-dl calling a public, unsecured API, or is it circumventing some sort of copy protection?

Because if it's just querying for metadata that anyone can already query for...your point seems immaterial as to the legality of the tool?

They're saying that sure, the name youtube-dl might well imply it's specifically for downloading things from YouTube, but that doesn't mean it's specifically for downloading video from YouTube.

How much of that metadata is not normally downloaded alongside the video?

Plenty of it? I regularly download the metadata and subtitles of entire channels or playlists so that I can search for specific words or phrases in thousands of hours of video. I know of no other way to accomplish this.

Subtitles are a perfect example of data that any normal browser downloads if you click CC, and can even be ^F'd if you click ‘Show Transcript’ on YouTube, but just happen to be orders of magnitude more useful if you control where they download to. I think you’re proving globular-toast’s point.

Subtitles are not video, so no. And I'd like to see you visit a thousand video pages with an RIAA approved browser and ^F on each of them. Nice joke!

Why should subtitles and video be considered so discretely? Are subtitles not copyrighted the same way as the audio and video portions of the work?

Beyond subtitles, there is certainly video metadata that youtube might have a claim on but the RIAA does not.

The principles are essentially the same, but they are discrete copyrights which could be owned by different people.

Thank you so much for writing this comment!

I've been in several situations where this would have been incredibly handy, but never realized it was possible.

`youtube-dl --write-sub --write-auto-sub --sub-lang en --skip-download [URL]` (Then just use grep)

There's all kinds of cool stuff you can do with youtube-dl. For example 'ytsearch20:kittens' will get a playlist of the first 20 search results for 'kittens'.

This sounds incredibly powerful. Wondering if c-span is on youtube and properly close captioned.

According to their FAQ, c-span.org's search uses closed captioning to facilitate search (but they don't provide copies of those transcripts.) Perhaps that might suite your needs though.

EEF deserves every penny of donation they receive.

The EFF might deserve it more though

Couldn't agree more: https://supporters.eff.org/donate/

not sure if you noticed, but the parent comment was joking about your typo -- you said EEF, not EFF :)

Oh! I see... well... my bad... ¯\_(ツ)_/¯

GitHub is owned by Microsoft, who is a member of the RIAA who created this legal action.

For Microsoft to pay for the lawyers to take it down (via their RIAA membership payments) and also pay for the lawyers to keep it up seems... rather silly.

From the outside in, there are a lot of aspects of the legal system that look like this - welfare for lawyers. Unfortunately, fixing it requires changing the law and we've made of practice of sending a lot of lawyers to Capitol Hill who are very sympathetic to the needs of lawyers. It's probably the biggest self-perpetuating interest group there is.

Lets assume, for once, that what they wrote, is what they stand for.

I think this is a very very good / exemplary reaction.

Why didn't they start with youtube-dl though? They will defend developers and err on their side "going forward" but no not that one?

Surely they already had the legal manpower when the youtube-dl removal started making waves. The fact that they did nothing for over three weeks and are publishing this blog post right after the issue was fixed by someone else (EFF) makes it hard to believe their "changes".

In large organisations, with lots of tape actually getting the ball rolling on what is proposed with all the sign offs, funds allocated, people/resource allocated for the tasks.... It takes months, not weeks.

They probably published this off the back of a signed off proposal and may start implementing off the back of it early next year.

My daily work is often not adhoc or that fast;

I'm not sure why this is so unrelatable to you but for me, daily business is, that things just take 1-3 weeks.

Legal manpower still means, that people interrupt their current tasks, which they properly have plenty of, to reprioritize something, others might even not care about at all or never heard of.

I stay with my statement and i have enough live experience, that i don't expect a 3 minute solution and answer from github.com

I didn't expect any "3 minute solution", but realistically they didn't even have to get the problem fixed. They could have pledged to assist youtube-dl by now, helped them file a counter-notice sometime this week (surely they can get 1 lawyer's time for pressing PR matters), and figured out how to deal with the human resource situation over the coming months.

Instead they found a million dollars (!!!), wrote a blog post with explicit commitments, but then waited on somebody else to step up. It just doesn't add up.

Someone on github had to care for this project; Then someone with the proper level had to care for this and understand the situation.

Then you need meetings.

You need to 'coordinate' your message or whatever.

You need to talk to the legal department and stuff.

What is not 'adding up'?

And why is it an issue that it took a little bit?

I agree with you completely. Someone high-up needs to care for this to get going.

GitHub's CEO claimed he cared, October 27: https://twitter.com/natfriedman/status/1321221940774723584

The fact that he didn't get a coordinated message or anything at all in the following three weeks shows how much he really did.

When Microsoft and the RIAA square off, the letter of the law isn’t really the battlefield. The battlefield is influence with the US Senate, and the EFF, while well regarded, is a Sancho Panza compared to Microsoft.

Microsoft won't square off with the RIAA since they're part of it.

So Microsoft sent a bogus DMCA takedown request to Microsoft, and the non-profit EFF had to respond to keep Microsoft from suing Microsoft?

Microsoft also has a program for matching employee donations to non-profits, so its likely Microsoft has also given money to the EFF as well.

I guess that's one way to put it :-D 2020 sure is a strange year.

How has youtube not sent a cease and desist for the name youtube-dl?

They would most definitely have a case that the name makes it appear to be a youtube product. Would a cease and desist for the name only somehow imply that google has no issue with the functionality?

Because I know not protecting your trademark can lead to dilution. And by issuing takedown notices, they are showing that they are aware of the existence of this usage of the youtube trademark.

Youtube has to realize that a significant amount of content that people watch on its site is reaction, commentary, compilations, and other recycled content.

I think its for this reason that they don't go after these projects very aggressively.

It's just arbitrary. There's prob even a low-sev ticket somewhere in Youtube's issue tracker to take out youtube-dl. They can do it at any time.

That they haven't done it (make youtube-dl's life harder) yet just means they might do it tomorrow, not that they don't care.

> If GitHub were fighting for the developer they would have funded the attorney, right?

By expressively taking the side of the accused (such as paying their attorney), Github could have opened themselves to being liable for whatever youtube-dl does.

Having the EFF as an independent party sidesteps that issue.

Honestly, the name is problematic. Why do some developers insist on bad names? Stop the bad names .. unpronounceable crap like xoyx-mp4, zycx10 should also be avoided .. what's wrong with vidl, or something simple like that? .. I'm half joking, but it's worth underscoring.

They literally had a test case in the repo for circumventing copy protection on youtube.

I'm somewhat baffled they managed to get the repo reinstated given that's very much a violation of the DMCA.

The argument is that it doesn’t do anything that a web browser doesn’t do already, and there’s established precedent that it’s not “circumventing copyright” if it requires no secret knowledge.

To be honest, I had no idea youtube-dl did anything else other than download YouTube videos. What other functions does it have?

"Downloading" doesn't mean "saving a copy" (unless you count "saving a temporary copy of its chunks in RAM"...). Most of my youtube-dl usage comes from its mpv integration, so the video is simply streamed directly for playback.

It supports a lot of video sources [1], not just Youtube.

[1] https://github.com/ytdl-org/youtube-dl/tree/3f1748b9445e9d93...

I was suprised today that it supports downloaded videos on reddit too.

It support a gigantic amount of website, including audio one. Most of the time, I use it to have an offline copy of a podcast, radio show or some video that I might need to look at wherever I am not guarantee to have an internet connexion (very useful when travelling). It also has a lot of useful option like downloading the audio only of a video, choosing the quality of the video/audio which might be hidden in the website you are trying to watch it from, download subtitle (this is just so useful), you can pass ffmpeg options also to post-process the video in one go, ... There is just so many thing you can do with it. One last example : one of my computer really struggle to watch video/stream directly from the browser (for whatever reason), but with youtube-dl I can stream directly to VLC/MPV and it use 1/10 the CPU comparing to watching the same video in the browser.

youtube-dl is a networked multimedia swiss army knife supporting many operations and manipulations of audio, video, metadata, and auxiliary content from many video and audio hosting sites and platforms, as well as serving as an access layer for several playback tools, including mps-youtube, mpv, and VLC.

It supports audio-only sites too. I personally sync my favourites on Mixcloud with it.

An important point:

There are many videos on YouTube that are 100% legal to download.

Also their examples in their docs for youtube-dl included copyrighted content ...

I'll let the lawyers debate that whole thing, but IMO I think that was a bit of a mistake / bad idea. Granted, fixable, but maybe a lesson of something to avoid.

Actually it seems more like the EFF had nothing to do with it at all and the unit test patch is the reason it was restored - just like Github says in the blog entry.

i have ytdl bound to some macros on my browser, so i can stream videos outside of the browser for accessibility reasons

Add to this that the original author recently posted a story about the origins of the youtube-dl script admitting it was designed to do:- download YouTube videos and name the downloaded files appropriately.


Under DMCA, neither writing a script like youtube-dl nor using it is prohibited (making an unauthorised copy of a video could be fair use).FN1 Section 1201 however prohibits distributing the script to others. Thus, the author of the script who "releases" (distributes) it is not necessarily the only one who might be violating the DMCA. Any recipient of the script who distributes it further, e.g., Microsoft, could be violating the DMCA as well.

FN 1. Section 1201 prohibits distributing technology that is designed to circumvent either "access controls" and/or "copy controls". Similarly, the act of circumventing "access controls" is prohibited. However, the act of circumventing "copy controls" is not explicitly prohibited. Making unauthorised copies, e.g., downloading YouTube videos, is subject to the defense of fair use. It is arguable that youtube-dl is only designed to circumvent "copy controls". As others in the thread point out, there are generally no "access controls" on YouTube videos, e.g., password protection. There could be exceptions. If youtube-dl is designed to circumvent geographic or age restrictions, would those be considered "access controls".

Aside from DMCA concerns, Google's Terms of Service for YouTube would appear to prohibit use of youtube-dl:

"The following restrictions apply to your use of the Service. You are not allowed to:

1. access, reproduce, download, distribute, transmit, broadcast, display, sell, license, alter, modify or otherwise use any part of the Service or any Content except: (a) as expressly authorized by the Service; or (b) with prior written permission from YouTube and, if applicable, the respective rights holders;

2. circumvent, disable, fraudulently engage with, or otherwise interfere with any part of the Service (or attempt to do any of these things), including security-related features or features that (a) prevent or restrict the copying or other use of Content or (b) limit the use of the Service or Content;

3. access the Service using any automated means (such as robots, botnets or scrapers) except (a) in the case of public search engines, in accordance with YouTube's robots.txt file; or (b) with YouTube's prior written permission;"


Would these TOS be enforceable if challenged. #1 makes no allowance for fair use. What do you think.

> It seems like EFF fought for youtube-dl and GitHub used their letter as legal firepower to bring the repo back online.

I'm at least one of those who requested EFF to take a look on "The RIAA’s attack on YouTube-dl is not a DMCA 512 infringement" thread.[0,1]

[0] https://twitter.com/app4soft/status/1320617082866847746

[1] https://news.ycombinator.com/item?id=24888234

A gem in the EFF's letter (https://github.com/github/dmca/blob/master/2020/11/2020-11-1...)

> To borrow an analogy from literature, travelers come upon a door that has writing in a foreign language. When translated, the writing says "say 'friend' and enter." The travelers say "friend" and the door opens. As with the writing on that door, YouTube presents instructions on accessing video streams to everyone who comes asking for it.

For those that haven’t experienced the joy of Tolkien’s writing, this is a reference to the Elvish inscription on the Doors of Durin in The Fellowship of the Ring, that is simultaneously a riddle and literal instructions on entering.

Fun fact, that inscription also contains of the few continuity errors in published Tolkien material. It starts with:

> The Doors of Durin, Lord of Moria

but as the Tolkien Gateway explains:

> The name Moria means "Black Chasm" and was a derogatory description of the place which the Dwarves did not like, and was given after Durin's Bane took over the city in the Third Age. It is therefore a mystery why that name appears on an inscription made in the Second Age, and made in consent with the Dwarves.

The most common "mitigating explanation" I see is that Tolkien, the "translator," perhaps used the name the reader would be most familiar with (Moria) instead of the city's real name (Khazad-dûm) when transcribing the door's inscription.

Another fun fact is that, the doors were built in cooperation between Elves and the Dwarves. Celebrimbor (also the guy who made all the rings except the one) and Narvi.

The friendship between an Eleven and Dwarven kingdom was kinda rare.

And thus, speak friend and enter

This is going quite deep, is there any chance that Tolkien actually planned for these?

Definitely. Enmity between elves and dwarves is a deep theme in Tolkien's world. The Silmarillion presents several in-universe historical events responsible for that enmity. It's also foreshadowed by "God" (Eru) when he grants life to the dwarves.

Friendships between the elves and dwarves are as a result considered very special, which is why Gimli and Legolas's friendship in The Lord of the Rings is such a big deal.

Is it accurate to say more than 90% of HN readers have seen that movie?

What movie? I think you mean, “read the book.”

Not OP, but I think he was referring to The Lord of the Rings: The Fellowship of the Ring (2001)[0] which grossed $887.9 million and won 4 Academy awards[1].

[0]: https://www.imdb.com/title/tt0120737/ [1]: https://en.wikipedia.org/wiki/The_Lord_of_the_Rings:_The_Fel...

> Not OP, but I think he was referring to The Lord of the Rings: The Fellowship of the Ring (2001)

OP referenced "over 90% of HN readers", who are notoriously out-of-the-mainstream nerds[0], so he probably was referring to The Lord of the Rings (1978) [1] which grossed $33.7 million (which seems a lot less than the 2001 film, but is pretty similar as a multiplier on its budget.)

[0] https://www.example.com/what-you-thought-this-was-a-real-sou...

[1] https://en.wikipedia.org/wiki/The_Lord_of_the_Rings_(1978_fi...

Bravo :)

Havent seen film or read book. We aren't all fans of fantasy or sci-fi genre.

Of course not. That's why they said 90%. You could argue it's 50% or 23.2832%. But there is a percentage of HN which has seen the movie if the OP has seen it.

Obviously there's a percentage that hasn't seen/read it if you haven't either.

It means both:

Speak, friend, and enter.

Speak "friend" and enter.

Without punctuation it would be a pun in addition to being a riddle and the instructions.

I personally agree, but there are some interesting counter-examples. For example, if someone discloses the credentials to an account but says nobody is authorized to use those credentials, I think it violates the CFAA to use those credentials. Even more-so if they only tell you their username, but the password can be inferred without direct disclosure (e.g., if the username is "thepasswordishunter2").

CFAA covers unauthorized access to computer systems - the only case I know of where CFAA was used to prosecute something akin to a DMCA 1201 claim was Sony suing Geohot for putting a tweezer to the RAM on his PS3. It's a novel legal strategy (in case you don't think DMCA 1201 is broad enough), but it was never entirely litigated in court as Geohot settled the case. I still don't think it would have passed muster in court, as it was akin to arguing that someone had violated the CFAA by hacking into their own computer that they forgot the password to. (Either that, or Geohot was poking at PSN and Sony knew this - I never followed that particular case thoroughly)

It's been a while since I've read about it, and I'm not a lawyer, but my recollection is that geohot said he deliberately kept his PS3 offline once it was compromised, and Sony's counterargument was (in effect, via some truly mind-bending equivocation) that geohot compromised the PS3 (the abstract computer for which authorization presumably proceeds from Sony) as opposed to his PS3 (the specific computer for which authorization presumably proceeds from geohot). Since the PS3 interacts with PSN, geohot had thereby gained unauthorized access to a computer used in interstate and foreign commerce.

It's one of those arguments for which I have a hard time deciding whether it's fiendishly clever, gratuitously obfuscated, or jaw-droppingly stupid.


Looks like they've removed the tests for RIAA member videos as the only change, which I assume helped get this restored: https://github.com/ytdl-org/youtube-dl/commit/1fb034d029c8b7...

And not even purged from the repo, it's still in the history if needed. Seems like the copyright holders making a big fuss over nothing really.

I have become convinced that the RIAA lawyers emerge from their crypts every few years, generating a slew of copystrikes to justify their retainer fee.

Maybe their purpose was Widevine. The youtube-dl takedown was a way to distract the attention. I don't think we should rejoice until Widevine is back.

The widevine-l3-decryptor takedown wasn't filed by the RIAA

I am out of the loop. What happened to Widevine?

Some guy wrote a tool to intercept the keys for level three on windows. Most streaming services offer only low-quality streams with level three, but big G dmca'ed the repo and most forks. Mirrors are still up all over, though; here's one: https://github.com/kipyegonmark/widevine-l3-decryptor

They are looking for that one time where people are either not paying attention or are too exhausted to care. What is the saying? We have to win every little battle, but all they have to do is win once.

> generating a slew of copystrikes to justify their retainer fee.

Considering how they were able to change social media to favor the copyright owners, I'm betting whoever is paying them feels the fees are justified.

> We have to win every little battle, but all they have to do is win once.

"Today we were unlucky, but remember we only have to be lucky once. You will have to be lucky always."

-Provisional IRA after almost assassinating Thatcher in a bombing

That's exactly what they do. Troll everyone they can reach.

This software makes it easy for people to download copyrighted movies and the RIAA attorneys (at least some) are acting in good faith to prevent people from breaking copyright law and causing their client damages. Can someone argue against me please?

(genuinely contribute to discussion by arguing against my own biases, call me a moron instead of downvoting)

Creating or providing a tool and using a tool are not the same action. Likewise, since there are legal fair use scenarios of copyrighted materials (short clips, criticism, satire, academic, etc) so even using the tool isn't inherently against the law and the person creating or providing the tools can't know and legally doesn't need to know the end user's intentions.

Copyright lawyers working for the highest profile abuser of copyrights absolutely know the very basics of copyright law and are therefore acting in bad faith.

So, similar to Popcorn Time then WRT providing vs using? The RIAA lawyers are bringing cases that are disingenuous, because they already know they're covered by fair use?

So to pick a worst case scenario, a pirate uploaded _Spiderman_ to Youtube with the intent of letting people get _Spiderman_ for free using this software. In that case, it's the uploader that's legally liable? Does the RIAA have a case?

Drug paraphernalia is still a crime in most places. Not sure what the equal to "spice grinder" here is.

Drug paraphernalia has a specific use (or at least, let's assume that for the sake of argument), but youtube-dl is more like a crowbar that has legal and illegal uses.

If I have a crowbar I can legally use it all day long for construction purposes. As soon as I'm caught breaking into a house with a crowbar, it's classified as burglar's tools. At no point is the hardware store or crowbar manufacturer liable for a burglary for selling me a crowbar.

I don't know what the laws are on possession, but before marijuana was legalized it was far, far easier to buy a bong than the weed to smoke in it. I'm wracking my brain to try to think of a piece of drug paraphernalia that is illegal to sell or illegal to possess in the absence of the drugs themselves.

In the state I live in it's illegal to to be in possession of any paraphernalia. Thats why you cant buy a bong anywhere, but can buy a water pipe at every corner store headshop.

That being said it's a petty misdemeanor that does not result in any jail time until your third infraction.


Anna Purna in Berkeley, CA used to have this sign: "these are water pipes not Bongs! You will be asked to leave" (c1995)

if there is no residue then classifying it as "drug paraphernalia" would be in bad faith

That piracy causes client damages is a debatable point. Studies have shown those who pirate software, movies, television, etc., will rarely use or consume that content if they didn't pirate it. I know way back when, when I pirated stuff voraciously, if I couldn't find something I just never read/saw/used it. Not once in my life have I spent days or weeks trying to pirate something only to turn around and pay for it. Some (not all) studies even show that in the case of software, piracy in some cases leads to legitimate use, i.e. purchasing.

Now there's no doubt that piracy violates copyright law. We can debate whether or not that's a good thing, whether the laws in question are just, etc., until the end of time. But it's not a foregone conclusion that piracy has any negative economic impact on copyright holders.

https://gizmodo.com/the-eu-suppressed-a-300-page-study-that-... there's study that says piracy actually boosts sales.

Git+your OS make it easy to acquire this software, Your browser and OS collude together to make it easy to run it, The elecric supply to your house makes it easy to run the computer that runs the OS, ...

Do you really want a world where this scumbags should go after everything that "makes it easy" to do illegal activities?

By this right, Zoom/ Google Meet / Teams have screen recording that would allow for this as well. How deep should we go down this hypothetical rabbithole?

Even if we take that as a given, my response would be: "Yes, so what?"

The software also a long list of legitimate uses, as was demonstrated by the various prominent users that spoke up.

I can use the camera on my phone to record a copyrighted movie, and thus circumventing the DRM, or just use a device like this: https://www.amazon.com/StarTech-com-USB3HDCAP-Video-Capture-... (analog VGA is probably preferred here, for lack of HDCP support).

And that is only necessary if we're talking about some modern DRM that makes your OS work against you, so you can't directly capture with OBS or something.

We're gonna ban all of those now?

An awful lot of tools provide the opportunity for their users to break the law, and yet we still sell those tools and place the onus of following the law on the users. While guns are the obvious example, lockpicks are widely and freely available, as are a whole host of other items with which one could commit nefarious deeds.

Copyright law seems to be one of the only areas in which the fact that someone Could use a tool to commit a crime seems to be grounds for criminalizing the tool and not the act.

I wonder if RIAA lawyers believe themselves productive members of society, or if they recognize themselves as the parasites they are.

This line of questioning on Startup News is quite amusing to me, I must say. How many of us can really pretend to make society a better place?

All who live in silicon Valley of course. You seem to have forgotten that "making world a better place" is a mantra repeated across the entire IT. I presume if Facebook employees actively think that, so can RIAA lawyers

At least some of us don't try to actively make it harder/worse. So that's a plus.

I'm convinced the companies considered as 'evil' now didn't think they would at first either. Something something unintended consequences.

I mean Reddit; bastion of free speech or platform for hate speech? (they cracked down on that over the years) Dropbox; File synchronization and sharing platform or child porn exchange? Airbnb; Great way to find an affordable place to stay and / or rent out unused room, or platform for dodgy landlords that scam people with pretty pictures? Coinbase: Platform for libertarian wet dream crypto exchange, or platform for laundering your ill-gotten gains?

Just to name a few YC examples. Everything can be used for bad things and make the world a worse place, and they don't always do the right thing.

But who goes into being an RIAA lawyer position thinking it’s going to be good at first? You have to have believed in the RIAA’s stance from the get-go because it hasn’t really changed.

I was at the Grammy’s one year and at the industry lunch the day before, I wound up at a table with a bunch of lawyers for the labels and the RIAA. It was an interesting position for me to be in, as someone who has been quite critical vocally of their positions and tactics since I was a teenager.

Anyway, everyone was cordial and professional and we didn’t really get into debate too much — and I was clearly the odd woman out, not a lawyer or in agreement with their position — but I walked away from the lunch with the belief that at least most of them absolutely believe they are fighting against what they see as abuse against copyright and ownership and that they see themselves as protectors of the industry, and to a lesser extent, artists. Now, I disagree that their tactics really succeed and would argue that ignoring the push of technology has hurt the music industry and especially artists, but I also accept that it is valid for people to have a completely different view from me. And it’s important to be exposed to that on occasion.

I’ll also say, as I was waiting for my Uber to take me to my next meeting, I saw valet bringing out $200,000 cars for many of the people I had politely been debating with earlier. I’m sure the money doesn’t hurt.

Not unlike my friends who work for tech giants that many of us find abhorrent but get $400,000 in stock grants a year.

Yep. You’ll often find there is nuance to these debates and people will justify their side by blowing the upsides out of proportion and minimizing the downsides.

They’re rent-seeking, and probably view themselves as necessary redistributors of wealth, like landlords, but for copyright enforcement and expansion instead of housing.

Some probably think they are "protecting content creators" or some bs

Or you have to be a morally and professionally substandard lawyer who cannot find a better job.

> Everything can be used for bad things and make the world a worse place

Right, but the RIAA aren’t just making new abusable things, they’re actively abusing existent ones.

Having reddit crack down on hate speech makes it a corporate shill-chamber/chicomm focal point, along with an anti-1A and against American-rights. The evil is always there with these companies brother.

These are good questions /examples, except Coinbase? I'm sure there's something else that could be applied, but doesn't seem it's a place to launder money. They were the first to supply IRS/Treasury Department with detailed records of every customer transaction.

I mean, while it is the nominal purpose of the site, it's not like all of us here actually work in startups.

Personally, I do programming for psych research students & faculty at an undergrad institution.

It's not like working at a startup—or having money as your first, last, and only moral compass—is a prerequisite to post here.

Not everyone here is directly involved in the startup culture and yes, technology and disruption can get shady. But "at least I'm not a lawyer" is a low, low bar to clear.

> But "at least I'm not a lawyer" is a low, low bar to clear.

A lot of people wouldn't be able to get any justice at all if it weren't for lawyers. Lawyers work for the ACLU and EFF too you know.

I work on managed databases. I actually do think that is a positive effect on the world, like many other obscure but important pieces of infrastructure.

Eh, I don't think that's fair. Lots of people here make society a better place, as do the companies and organisations they work for/contribute to.

Sure maybe you could argue that Facebook and Google don't make the world a better place. Maybe a bunch of other FAANG companies.

But not everyone here works for one of those. I don't, and I'd say my work probably improves society in a certain sense (depending on whether web development/UX design/usability work does that).

I am not, but I am not fucking it up for others.

Well anyone who voluntarily enters into a work for hire arrangement is making society a better place. The employer wouldn't have done it unless they were benefitting and likewise for the employee. What is important is doing something people want.

That is definitely not the case. There are plenty of employers making things worse. One of my first jobs was for a telephone fundraising outfit. We'd cold-call people, manipulate and like to them, so they'd donate money for our charity of the week, and keep 85% of it.

Making society better requires actually making society better. You have to weigh the total societal positives against the total societal negatives.

OK let me qualify my answer. Voluntary financial arrangements are beneficial to society that do not harm others. The government in capitalistic systems enforces the rule that you can't harm one another arbitrarily. So an assassination contract would be illegal. Also, defrauding people with cold calls of their money is illegal. In short, LEGAL voluntary arrangements in a free market are beneficial.

That's progress, but you haven't accounted for negative externalities or the varying shades of "voluntary" that exist. Both of which occur in pretty much any job people take these days.

This is the Just World Fallacy. It's not necessarily true that spending money benefits society. You can spend money to harm society, with or without intention.

An assassin is a work for a hire arrangement.

And this is just one (extreme) instance of “person A pays person B to destroy person C's value, for net harm”. Imo, the only failing of capitalism is that one can profit by destroying other people's wealth (though this is probably splitting hairs, given how varied the ills that come from that).

Everybody has their price. For some people, it's low enough that they'll actually do the evil things and not lose sleep over it.

yeah unlike us hackers who are saving the world with targeted ads and food delivery

Technology has had an impact on nearly any industry you can think of. As such, there is no shortage of tech work outside of ad tech. Ten years ago I worked on ad tech shit for Amazon, but I quit when I realized that made me a parasite.

I don't work in food delivery, but I'd say getting a pizza from point A to B is a hell of a lot more productive than being a lawyer for the RIAA.

Appified pizza delivery is rent seeking.

There is zero need for a multinational between hungry people and food delivery. Inserting them raises costs, lowers service quality, and lowers revenue to restaurants.

Off topic, but I would like to note this thread's congruence to Snow Crash:

  There's only four things we do better than anyone else:
  microcode (software)
  high-speed pizza delivery

I was thinking more along the line of the people who actually deliver the pizza. It's an honest job, unlike being an RIAA lawyer or ad tech programmer. But next to either of those, even delivery app developers are saints.

> There is zero need for a multinational between hungry people and food delivery. Inserting them raises costs, lowers service quality, and lowers revenue to restaurants.


Everyone I live with went from not ordering any food to using UberEats weekly because it's so much more pleasant than interfacing with every restaurant directly, having to carry cash to pay and tip, having on easy way to answer "what's open right now?", etc.

All these restaurants are getting money they would have never received from me had the app never existed. And everyone I know uses UberEats and will sheepishly admit they use it way too often.

You should talk to people who use UberEats before you assume it provides zero value to anyone, not sure what else to say. Maybe you can do the same for Uber as well.

Snowcrash was kinda crazy in how it predicted where things would go.

Yeah, same. Years ago I did work for a medical advertising company. They were lovely, smart, creative people. But the more I thought about it, the more I didn't want to aid for-profit manipulation of people. I've stayed away from ads since, and never regretted it.

Exactly, I'm not fan of these type of lawyers, but they aren't even close to the same level of damage being done by people who work at places like Facebook.

I'm sure it's the usual case of a large enough salary helps you to forgot what a piece of shit you are.

It reminds me of the famous quote by Upton Sinclair: “It is difficult to get a man to understand something, when his salary depends on his not understanding it.”

While I agree with you, I'm pretty sure that a lot of people are grateful about food delivery given current events. At the very least, it kept some people employed and businesses in operation.

Let’s acknowledge the widespread digestive benefits of yogurt247.com

For sale! Finally, I can realize my yogurt-on-demand startup dreams.

In their self view they ensure that artists earn money for their living, thus allow artists to survive. And there is some truth to it. Finding the right balance is hard ... but in my view they "rights holder industry" is too strong indeed.

I think its probably similar to medicine in that there is a gigantic industry of middlemen that suck money out of the system and make far more than the actual service providers

"The Value of Everything" by Mariana Mazzucato. Great book. Central thesis: there are value creators and value extractors. Value creation is very connected with most people's idea of "progress". But value extraction is parasitic, and dominates more and more of contemporary economies.

I'd agree. If copyright wasn't valid after death + 70 years

Of course they don't do only that, they also have to spend their time crafting abusive contracts and extensions in detriment of artists and in favour of big recording companies.

I'd be interested in seeing how much money from their suits gets to the artists, or even to distributors - or what effect on revenue their deterrence causes.

Right, these lawyers are parasites sucking blood not just from society in general, but also blood from most of the artists ostensibly represented by the RIAA. If any artists come out ahead from anything the RIAA's lawyers do, it's only the elite already-wealthy ones.

For German GEMA (which is working a bit different from RIAA, so can't be fully conapred) there are some numbers on Wikipedia, till 2012: https://de.m.wikipedia.org/wiki/Gesellschaft_f%C3%BCr_musika...

They made 820 million € in revenue, 128M€ are their "costs", 692M€ of that 15% are their fees, remainingnis split between labels and artists and artists got 316.5M€, thus a quite low fraction ... and in German law the creator is theoretically stronger positioned than in US copyright.

(Now this isn't 100% fair as analysis, as some of the payments to labels go to artits, as well and labels also do some marketing etc benefiting the artist ... and then there is this weird distribution mechanism where a successful artist gets over proportionally more ... but in the end: "small" artists only get a very tiny part of the cake)

To clarify: GP asked about "how much money [recovered from the lawsuits] gets to the artists". The revenue you're quoting is mostly not from lawsuits, it's regular license fees paid by broadcasters and event organizers.

It's not really a secret. The music industry has always been about concerts: radio play (or streaming, which uses the same revenue model) doesn't pay anything and artists get pennies on the dollar for record sales. The RIAA represents record labels more than artists.

They see themselves as the last bastion of decency in a world full of violation.

This is neither here nor there but Nobel Prize winner Gerard 't Hooft has written an opinion piece on wrong-way drivers in science who seem convinced that everyone else is going the wrong way [1] (it's in Dutch unfortunately, but then the Dutch the word 'spookrider' (lit. 'ghostrider') is a lot cooler than 'wrong-way driver' IMHO).

It's a concept that's somehow always stuck with me whenever I hear about people who seem convinced everyone else is wrong.

[1]: https://webspace.science.uu.nl/~hooft101/spookrijders.html

I think he is right. But I don't like his tone.

The whole writeup is a tantrum on why you should stick to "well known" facts. Which sounds to me too much like asserting the truth of things without questioning them. Yes, there are a lot of fools out there whith a spookrijder complex that are a detriment to science. And I would assume a well-known professor would rightly get tired of their emails.

He only shortly adresses at the end that radical ideas are precisely what is needed for progress in science.

I do not think this dismissive mentality does the situation any good. If someone comes with a radical but stupid idea, you need to first recognize the merit in the idea, and then show why it is wrong. Bashing someone with "you cannot create free energy" will only encourage him to waste his time trying to prove you wrong.

I suspect a lot of these spookrijders are curious and fairly smart people, but who's ideas where offhandedly dismissed by a teacher one too many times.

Yeah but sometimes it really is everyone else that is wrong. For example, when most people used to think the world was flat.

'Everybody' thinks RMS is wrong. He has the worst case of Cassandra's curse I've ever heard of.

But I think it tends to not work like this. Incidentally, the flat earth thing is mostly a myth; literate people have know the earth is round since the ancient Greeks figured it out. Columbus was ridiculed for thinking the Earth was smaller than it really is (his critics were right) and the only reason his trip didn't end badly for him is shear dumb luck in running into another continent in his quest to reach Asia the looooong way around.

Doubly lucky because if not for that continent he likely wouldn't have made it all the way, a trip about four times further!

What is RMS?

Richard Stallman

That educated people believed that the Earth was flat is largely a myth. Not only people knew the Earth was round since antiquity, but they also had a good idea about its diameter.

Heliocentrism was a bit more debated but for good reasons. Early heliocentric models were actually worse than contemporary geocentric models to calculate the motion of planets.

All that to say that "everyone else is wrong" doesn't happen often in practice, at least not among educated people. And when that happens, either the evidence is solid and it is generally well accepted or it is not, and there is no reason for others to accept it. The burden or proof is for the one who makes the claim.

To go back to heliocentrism, the reason it is the prevailing theory right now is because the model has been refined and now, it matches observation better than older models based en epicycles. It is not because of some philosophical reason about our place in the universe.

> That educated people believed that the Earth was flat is largely a myth.

And this is one of those rarer times that everyone is wrong who believes this myth, although maybe they are uneducated too.

All this is to say go team iconoclasm.

Spookrijder translates literally into ghostrider, which is a lot nicer than wrong-way driver.

The joke here goes that on the radio there is an all-bands emergency announcement about a ghostrider on A2, the main artery of the country, between Amsterdam and Utrecht.

In one of the vehicles on that road someone mutters 'A ghostrider? Bloody idiots, there's thousands of them!'.

The term ghost rider exists in english as well I think.

At least I could find several articles talking about ppl going the wrong way after searching for it + wrong direction.

I'm not a native speaker however

I mean, if we believe it benefits us to have copyright laws, then obviously it benefits us to have copyright lawyers, and the rest is just implementation details. I'd wager 99% of people believe copyright laws are a net good.

> I'd wager 99% of people believe copyright laws are a net good.

If asked, a majority might say that (though IMHO nowhere near 99%). Their actions indicate otherwise, however, and a person's beliefs are better judged by their actions than by their words.

Everyone thinks they're saving the world. I'm sure the RIAA sleeps soundly knowing they're defending the rights of creative individuals to make a living and holding the line against the scourge of amoral nihilistic pirates.

> Everyone thinks they're saving the world. I'm sure the RIAA sleeps soundly knowing they're defending the rights of creative individuals to make a living and holding the line against the scourge of amoral nihilistic pirates.

Amoral Nihilistic Pirates would be a great name for a band.

Just sayin'.

I'm much more cynical. They know they're bastards but they make far far too much money to care.

Everyone is the hero in their own story. Few people actually gleefully play the scoundrel. The ability humans have to self-rationalize is amazing. And even when folks are doing something they know is wrong, often it gets justified in the balance: the victim deserved it, the perpetrator is Robin Hood and proceeds will benefit those who need it more, the action makes up for a historic injustice, etc ...

People may not play the scoundrel much, but I see plenty of people playing the ronin, the soldier of fortune. E.g., the contract programmer on a 6-month gig where they know the project is fucked, but as long as the check clears, it's not their problem. The sysadmin who doesn't much care what's on the servers. Plenty of others, for sure.

I doubt it. Every time there's an article on here about the latest outrage from $FaceGoogzon there's no shortage of well-paid rationalisers in the comments. I'd expect the same is true of the RIAA. Especially among their legal team: there are far more unseemly clients than the RIAA out there.

There's plenty of people out there who simply do X for financial payout Y.

As a matter of fact, the financial services sector thrives with such people

Yup. After the mortgage bubble burst, I saw a lots of posts from people in the industry who knew something was wrong, but as long as they kept making commissions, they weren't going to question anything.

I don't really think so. I think a lot of people are just doing something because it's a job. And a lot of people are sound with being sheep and just following the rules because they exist, and don't like the discomfort that comes with questioning everything on a deep level.

> I wonder if RIAA lawyers believe themselves productive members of society, or if they recognize themselves as the parasites they are.

At least one way they could rationalize their actions is by taking an outlandish but not uncommon view of property rights: that no one would bother to create anything without being able to profit from ownership of it, and the more they can profit the more they'll create.

There's also the even more outlandish view that whatever the market does is good for society by definition, so if the market pays you to do something you can assume it's beneficial to society.

I think if people are paid well enough, they can convince themselves that the harm they do is a net positive because it demonstrates that the system needs to change.

I wonder this about a large majority of corporate lawyers who somehow seem like members of a parasitic species which has found a host which they can exploit for resources by inducing changes in their behaviour, comparable to the way the Toxoplasma parasite makes mice less scared of cats [1].

[1] https://www.pnas.org/content/104/15/6442

Things could be much worse; it's remarkable they don't sue about being called a parasites.

It's a shot across the bow, to achieve a chilling effect. They've achieved a few weeks of downtime, for now, and sent a message to the project that they're being watched. It might well not be the end of hostilities.

I think you may be right about the fight not being over, I don't think they actually achieved any downtime. Youtube-dl didn't stop working for me while the takedown was in effect, and was even updated during that period.

Seems to me they got much more of a Streisand effect than a chilling effect! ;-)

In terms of usage, yes. In terms of development, we'll have to see. I am an optimist, but I have to recognise that good devs tend to skew away from opensource projects that are in lawyers' crosshairs, because they bring more trouble than fame.

The way I read it, the test cases weren't really the problem. The RIAA was alleging that the purpose of youtube-dl is to circumvent DRM and they try to back this statement up by pointing out that copyrighted works are being downloaded in the test cases.

Here is a bit of a discussion about it by seemingly knowledgeable people:


> > the source code expressly suggests its use to copy and/or distribute the following copyrighted works owned by our member companies: > > Icona Pop – I Love It (feat. Charli XCX) [Official Video], owned by Warner Music Group Justin Timberlake – Tunnel Vision (Explicit), owned by Sony Music Group Taylor Swift – Shake it Off, owned/exclusively licensed by Universal Music Group

> Complainants are "confused" about actual infringement (which is prohibited by copyright law), and creating a method for infringing copyright. Under DMCA and US copyright law, copying is infringing, programming is not infringing. The complaint does not clearly allege unauthorized copying of another person's intellectual property, and their complaint is based on the theory that certain programming actions constitute copyright infringement. I don't actually think they are confused, I think they are testing the boundaries.

Hmm they seem to be taking it from the approach that RIAA was sending a takedown on the grounds that youtube-dl was infringing on the copyright of their members, but that doesn't seem to be what the actual takedown claims. Instead it's requesting takedown on the grounds that youtube-dl is breaking protection measures in violation of 1201, and the answer given doesn't really address that except to say that breaking protection measures isn't infringement (which wasn't what they claimed in the first place).

EFF represented youtube-dl to get the repository reinstated, and their lawyers instead tried to prove that YouTube doesn't have DRM, and that the test cases provided were neither suggesting other people to infringe, nor infringing themselves (falling under fair use). The full response is here: https://github.com/github/dmca/blob/master/2020/11/2020-11-1...

> Seems like the copyright holders making a big fuss over nothing really.

This should be the conclusion. Since they have won nothing with such whole noise. Only increase more the OSS wave.

My experience has been that Github doesn't ever purge commits from the history. Even when you rewrite the history, all the dangling commits are still there and can be access. I've yet to find a way to force Github to do a gc so such commits are removed. Without Github running a GC on the repo, the commits will not be removed.

You can contact their support to do it for you, for example in the case of pushed secrets.

Pushed secrets in public repos are automatically archived by third parties so removing commits containing them would not be enough to prevent their use, just rotating the secrets is the way to go here.

https://twitter.com/andrzejdyjak/status/1324360905237372929 https://news.ycombinator.com/item?id=25013756

That shouldn't be necessary. Something as fundamental should be made available as some sort of API.

They don't understand technology, and in this case I don't think they should be told...

I guess that if they want to run those tests they can cherry-pick that commit, run the tests and then drop it

Fantastic compromise.

Arguing that you have a right to break RIAA DRM is much harder that taking it out entirely.

I use this for downloading national archive videos off youtube, I'm very happy about this news

Is there a way to get equivalent tests on non RIAA videos?

Shouldn't these tests be considered fair use since they are arguably necessary to validate interoperability?

Yes, and I unfortunately still see no argument related to the DMCA's provision that breaking copy protection is legal if you have a license to use the work. In this case, a license to use it via a specific browser is not mentioned, so you can rightly download it with anything.

This was the suspected cause for py-kms's reinstatement but as it related to Windows licensing.

> Looks like they've removed the tests for RIAA member videos as the only change

And even that was more likely to allow certain somewhat too loud organizations to save face, not out of legal necessity.

It would have been fantastic if every test using RIAA copyrighted music had been replaced with public domain sources. Or, better yet, videos the maintainers created and uploaded themselves.

That won't work, because Youtube applies the particular sort of protection that those tests exercise only to copyrighted music.

Interesting. Do you know how hard it would be for someone to upload a bunch of original videos with same copyright as the videos in question?

As far as I know, that's impossible. The particular DRM applied to those test videos is ONLY available to large partners like Vevo.

Which is why they were in the test suite.

Just about all music you can find online is copyrighted. I think you mean that it applies the protection only to music where the copyright is held by a large organization.

Yes, yes, it was short for "registered with Youtube's copyright filter".

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact