I still don't see why anyone is responding to DRM circumvention DMCA takedowns. The DMCA is very clear about the penalties for a circumvention tool needing a court order, and the section on takedowns does not mention circumvention.
I sometimes wonder if I'm missing some relevant change in law or case law, as the sections seem easy to read as somebody who isn't a lawyer.
I wondered about it myself but I think there's reason for that. DMCA safe-harbor and takedown process only apply to copyright infringement. However DMCA 1201 restricts "manufacture, import, offer to the public, provide, or otherwise traffic in any technology, product, service, device, component, or part thereof [...]". You might want to process circumvention notices not because they are real DMCA notices, but because you are potentially trafficking anti-circumvention tools, you have no safe harbor for that, and you probably want to take it down ASAP to limit your liability.
This means that if there is DRM on a DVD, even though it is legal to make a backup of the media you own it is illegal to bypass the DRM. There is no copyright infringement, but you have broken the law.
Yes, bypassing DRM is against the law unless you're doing so for one of the approved reasons. What content you're bypassing DRM to access is unimportant.
If someone says they're going to sue you, and it's black-and-white that they'd win the suit, then it's pragmatic for all parties concerned to just skip the time & cost of a court appearance, and just do the thing the court would otherwise force you to do.
In a sane world, civil suits between firms should really only go ahead if the case's result is ambiguous, and the courts in this case would almost certainly side with the takedown request - and moreover would be pissed at Github for wasting the court's time on it.
If a GitHub user fails to respond to a DMCA request, and GitHub doesn't remove the content in question, GitHub as a service provider would then become party to the complaint under the copyright safe-harbor rules (a suit that GitHub would definitely lose, and can have fairly drastic downstream consequences for their status as a safe-harbor going forward).
It's not that users are irrationally responding to DMCA requests when they don't need to, its that as a service provider, GitHub defaults to a stance where a claimant's DMCA is automatically processed if a repo author doesn't reply within 1 working day. This effectively means that for DMCA requests of all types on GitHub, "no response" is synonymous with "I'm guilty of infringement, plaese take down the content".
A DMCA claim response in GitHub is admissible as testimony should the case ever make it to court, and therefore carries the penalty of perjury (both parties are informed of this before opening/responding to the claim in the GitHub UI). So unless the repo author is absolutely certain that they're not hosting DRM circumvention software, they have little-to-no recourse but to allow the takedown request to go ahead.
You're conflating copyright infringement and DRM circumvention.
All of the safe harbor provisions and takedown measures have to do with hosting copyright infringing material. They make no mention of needing to do anything if you're hosting DRM circumvention technology.
By your logic, I could submit DMCA takedowns over libel and the service provider would have to take it down despite it being obvious that libel is not part of the safe harbor provisions.
DMCA takedown notices have become a sort of gentlemen's agreement to avoid either party ever having to go to court where they could both end up spending lots of money.
I sometimes wonder if I'm missing some relevant change in law or case law, as the sections seem easy to read as somebody who isn't a lawyer.