back
137 comments
I'm the hardbin guy.

Since I wrote the post about the DMCA takedown notices the other day, someone kindly offered to provide alternative hosting for hardbin.com that should be more resilient to bogus DMCA takedowns, so happily hardbin.com is back online (but not operated by me any more).

Also I emailed Sean Lang (the guy with the github repo with dozens of example DMCA emails from these guys) and it turns out that in the last few months he also took his IPFS gateway offline because dealing with the takedowns was too much trouble.

Yeah, I took ipfs.slang.cx down after Hetzner threatened to kick me off their service.

I was able to stay on top of the takedowns by writing a script to create & deploy nginx block rules for each URL in the DMCA emails. Obviously I had no time for manual review of the URLs. But I guess that didn't matter and Hetzner got annoyed with all the emails and decided my business wasn't worth the trouble.

Sounds similar to a SLAPP: Strategic Lawsuit Against Public Participation

The goal is to burden the recipient with overhead costs that it becomes impractical or cost-prohibitive to participate.

> because dealing with the takedowns was too much trouble.

What are the consequences of ignoring these notices?

But you are in the UK, the DMCA had no legal standing there. Did you host on a US service?
> “The weird thing is, [the system used] doesn’t actually verify that a given file is available through my server before sending a DMCA request. I’ve looked through the traffic logs, and the vast majority of the files listed in these takedown requests have never been requested in the history of my gateway. I haven’t checked all of them, but I’ve checked a lot,” Lang says.

So... DMCA is infamous for its lack of protections against misuse, and I'm not a lawyer, but that's gotta actually qualify as perjury, surely?

The way IPFS works though, isn't it by definition that any file you can get from one gateway, you should eventually be able to get from any gateway?

In other words: it doesn't matter your gateway logs shows that no one ever requested a file with a specific content hash, because should one eventually request that content hash from your gateway, they'd get the file in question.

Honestly, until reading the headline, it never occurred to me what now I realize is stupidly obvious: the promise of p2p content-hash-based distribution is that it's robust and censorship-resistant, as the targeted data isn't bound to specific places, but rather is automatically mirrored and made available across the entire network. The flip side of the data being accessible from any point in the network, however, is that... the data is accessible from any point in the network - meaning that every point individually is distributing everything that's in the entire network, and is potentially liable for it all.

NAL. According to some youtubers I have seen who ran into this sort of frivolous claim, you can apparently send counter-notifications to those people, and that sets up some liability on their side if their DMCA takedown was indeed frivolous and they continue to pursue it. It does seem like a lot of work to send all those counter-notifications, though.
> but that's gotta actually qualify as perjury, surely?

Lindsey Ellis did an exhaustive series of videos on exactly this topic (https://www.youtube.com/watch?v=K3v5wFMQRqs); yes, you can sue over false DMCA filings, but it's expensive and time-consuming and you may run out of money in the process.

It doesn't. With the DMCA being a corrupt law wholly bought and paid for by the content cartels, the "perjury" bit only applies to someone falsely claiming to be authorized by the imaginary property owner.
IANAL, but I believe perjury can only happen under oath. This seems more like a bluff.
Related, what's "modern best practices" in both software (ie what to write) and operator (ie you are running software, and need to do something with DMCA)?

I ask in the context of ActivityPub, Mastodon, Lemmy, Kbin, etc. I'm writing software for ActivityPub and i want to ensure self-hosted instances have the tools to respond and manage to legal .. threats (or w/e) like DMCA. Likewise i don't even know what is good advice for people to manage these notices. Of course there's also all the other undesired things too, CSAM, etc. Hosting user content is tough, heh.

As someone invested in getting people to self host more of their life in ways like ActivityPub, that also then means more exposure to this type of .. stuff. Not sure what the current consensus even is, tbh.

One thing you have to be aware is that there are many hosters (like e.g. Hetzner, which is excellent otherwise IMO) who will drop you like a hot potatoe (i.e. blackhole your server in the best case, terminate your account in the worst) if they recieve multiple DMCA notices (or abuse notices in general) for your IP / Server / VPS.

It does not always matter if those are actually legit if they look credible enough and thus, if someone hates you very much, it can be used as a weapon to kill your instance.

This can be somewhat remedied by hiding your hoster via something like e.g. Cloudflare, if having a middle men is acceptable.

Isnt the beauty of activity pub that you can tenat an instance juat for yourself? That could avoid a lof ot the legal headaches. You could also make it invite only through yourself, your instance doesnt need to be big if everyone elses is.
The solution is to make instances publish their block lists and import these block lists to the self hosted instances.
>To uphold the highest standards of integrity, responsible behavior, and ethical conduct in professional activities. (IEEE Code of Ethics) [1]

Letting this happen IMHO is clearly a breach of IEEE's own rules. This goes against the public and has serious side effects. Nobody with a bit of knowledge on networking (which I hope exists within IEEE) should seriously think that those gateways are hosting the content.

If someone with a role in IEEE reads this they should really stop this rogue firm they contracted before they seriously destroy some part of the internet some people rely on.

[1] https://www.ieee.org/about/corporate/governance/p7-8.html#:~....

The IEEE has no power to stop people from doing things. It's a professional society, not a licensing/regulatory body.
Copyright law doesn’t talk about hosting content. It talks about distributing content.

And by all means, an exit node is distributing content.

"Law enforcement - I.C.E. referals"

This is from a slide deck on how to "protect" content, apparently by someone working for a law firm. Assuming the firm is US-based, this is literally suggesting to get immigration services to check out a suspected "wrongdoer".

Lawyers huh... I just can't even.

I have no love for lawyers, but Immigration and Customs Enforcement has, for better or worse, a role in these issues.
Related:

https://news.ycombinator.com/item?id=36425433 ("Did I receive fraudulent DMCA takedowns?", 3 days ago, >150 comments)

The part that caught my eye in the presentation was that it suggested the possibility of digging into someone’s immigration status and reporting them to ICE. It shocks me that a private corporation would get someone deported for doing something that’s not illegal.
Read about what private corporations did in the 40s and 50s to maintain land in Central America and the Middle East. Hundreds of thousands of people died and democracies were replaced by dictators so Chaquita didn’t have to sell land being repossessed under imminent domain. Simile story in Iran with Standard Oil. Getting someone deported is pretty low on the list of atrocities corporations would do to make a buck.
These are very large corporations with very large profits to protect. It's awful to think about but not surprising in the least.
Immigration and Customs Enforcement. Customs applies to digital goods, too.
How about a counter strategy?

- randomize the url list

- ask for evidence of copyright violation of a specific url number

- if human does not answer, claim they acted in bad faith

- give them 14 days to respond

Win/win. Gotta game the system, and increase the cost/effectiveness ratio.

Maybe we should create a fund to sue those illegal DMCA requests back
I don't know if it's true, but in another comment thread, it was mentioned that if you truly are the owner of the copyright, filing a DMCA takedown against someone who didn't actually have a violation is not perjury and thus have no real consequences (cept perhaps to say 'sorry bro').

So it's apparently not going to be effective to counterclaim as it cost you more to do this than they lose.

At least in the USA, it is a requirement that any legal representation by a corporation, be done by an actual lawyer.

If a law firm or solo lawyer is not identifying themselves properly in a DMCA takedown request, which is a legal document, what happens? Does anyone know?

You can basically do anything you want as a large corporation when it comes to this stuff. The law doesn't have any teeth, as a smaller player you can't do anything about bogus DMCA notices or legal violations.

Many services like Twitter or Chrome Web Store will at best put your content back up a few weeks (or months) later after you file a counter-notice; in some cases they will just nuke your account after a few notices even if the notices were bogus.

I recommend they hire an expensive law firm to process the requests, and a few contractors, then send the bills back to the reporter (one per request). I recon if more recipients do this it'll become expensive to carpet-bomb and they'll want to do some modicum of review on their side before sending these out.
You can bill for subpoenas and warrants but I've never heard of billing for DMCA takedowns. It's a cost of doing business.
How's the progress on an IPFS browser client that doesn't require a gateway?
You can download the IPFS desktop app and browse IPFS freely without the need of a centralized gateway. Brave can use the desktop app for its native IPFS support. If you intend to use it to share anything, you need some extra setup, though.

I don't think any browsers have IPFS built in. For IPFS to be at its most useful (as in, your computer exchanging data with the network and actually participating in it), you need things like port forwards or IPv6 pinhole support, and I don't think that's something many people will do.

Edit: Brave supports IPFS natively these days. Go to brave://settings/web3 and set "Method to resolve IPFS resources" to "Brave local IPFS node".

Or progress on useful stuff like an encrypted Dropbox clone or something. Everytime I see ipfs stuff it's about silly crypto things.
If someone hosts a JavaScript app on their webserver that accesses IPFS using WebRTC or something, won't they still get DMCA-bombed? It's not like these lawyers care where the files are actually hosted, and there are effectively no consequences for indiscriminate DMCA-ing.

Even if you make an IPFS browser extension, you could still get complaints and Google might still take it down, no? Are there any IPFS mobile apps that don't require sideloading?

You have a chance of getting away with anything else on the Web, but anger the Copyright Gods and there's nowhere you can hide.

Is there a societal benefit to US approach to lawsuits where anyone can sue anyone for anything?

Is it something like MAD?

Wondering, where is that red line where publishers cross and someone introduce complete resilient and super simple solution to this whack-a-mole.
Isn't filing a false DMCA takedown perjury, which is a criminal (rather than civil) matter?
Here's my completely-unsourced conspiracy theory:

Someone is using ChatGTP to look for infringing content. DMCA notices are being sent on the basis of AI hallucinations.

Any lawyers think that there's a case against the publishers for these harassing, inappropriate notices?
People operating IPFS gateways might benefit from using NOpfs, pulling the official public gateways badbits.deny list:

https://github.com/ipfs-shipyard/nopfs

Is there an easy way to comply with an accountable, non-oprressive-regime e.g. at least CSAM IPFS block list?

"Implement Allow Lists and Block Lists" (2018) https://github.com/ipfs/notes/issues/284

"IPIP 298: (allow|deny)lists for IPFS Nodes and Gateways" (2022) https://github.com/ipfs/specs/pull/340

I'd like to be able to run something like an IPFS gateway if I could be reasonably certain I'd never get any annoying legal notices or attention. Are there any community maintained hash tables of verifiably unencumbered content that I could use as the basis of a filter?
What is preventing a class action for frivolous DMCA notices?
Could this not be construed as vexatious litigation?
We need a cloudflare for DMCA DOS attacks.
“I did some bash-fu to extract the IPFS hashes from the emails and grep for them in my nginx logs, and was surprised to find not a single match,” Stanley explains. “None of them have ever been accessed, and of the ones that I checked, none even worked.”