29 ms·
Heh, I didn't expect to get much attention for this. I thought it would be funny to push a merge commit between the 2 repo's latest commits. As a result, the gi
by Stephen304 6y ago
Heh, I didn't expect to get much attention for this. I thought it would be funny to push a merge commit between the 2 repo's latest commits. As a result, the git history is accessible from the dmca repo if you know the commit hashes. Since I didn't rebase, all the commit hashes were preserved with signatures. Another fun discovery is that deleting my fork of github/dmca didn't affect the PR like I thought it would, so it seems a mirror of youtube-dl's commits are stuck in the ether until GH deletes my PR and garbage collects the repo.
- mmastrac 6y agoThis is such a great hack. I approved the PR, naturally.
- Iv 6y agoNote that a hack is not a fix. All of you, write to your representatives about that if you care. In EU when they were going to put some similar laws we all organized and wrote massively to the parliament and they backed down. It is a lot of effort but it works.
- gizmo686 6y agoAnd what should we ask for? There is stuff to complain about with the DMCA, but the core process is reasonable. Someone claims copyright infringement by a user, and the website takes the content down. The user claims no copyright infringement, the website restores the content. The website is immune from liability, the alleged copyright owner can settle things in court with the user if they want to.
- saagarjha 6y agoThe problem is that there is no penalty for fraudulently issuing claims.
- corobo 6y agoOther than it being a felony in the US to issue a false claim with a jail time of up to 5 years aye
- jjeaff 6y agoYou should ask for immunity for tools that could potentially be used to infringe copyright, but that are not actually infringing copyright. If guns don't kill people, people kill people, then certainly congress can accept that software doesn't pirate copyrighted works, people pirate copyrighted works.
- scollet 6y agoI get the analogy, but guns are typically purposed for lethality. Software is not typically purposed for piracy. Maybe "trying to hit someone with your car"? Not sure.
- stevefan1999 6y agoActually I found the statement "guns don't kill people, people kill people" very oxymoronic. Sure one might argue that if you have the intent to kill, it's not necessary for one to use a gun, you have alternatives such as grenades, knives, chainsaw or even your bare hand if it's lethal enough. This is how you derive that "the gun is not evil, it's the people who are" statement. But guns, under the category of firearms (not only guns, what about rocker launchers?), are almost-certainly designated to kill, and what is the top priority of firearm? Aim to be the most efficient killing machine. So if you use a gun, it's not necessary that you are going to kill people, but it is very likely that you are imposing a threat to do so, regardless of if you're attacking/defending. Therefore, trying to apply the gun analogy to current state of youtube-dl is an injustice to youtube-dl, as you compared an intrinsically evil entity to another.
- boomboomsubban 6y agoYou missed the relevant part of the DMCA for this takedown, which makes bypassing "anti-circumvention' measures a crime. That section has caused nothing but problems.
- leeoniya 6y ago> There is stuff to complain about with the DMCA, but the core process is reasonable. it absolutely is not in any way reasonable. you must take down the content without question and then, after filing a counter-notice wait 10-14 days minimum before it can be restored [1]: "After a counter notice has been received, a service provider must wait 10-14 days before they can reactivate the claimed infringing content." frivolous complaints can completely cripple a business with little risk to the supposed claimant. https://odinlaw.com/what-is-a-dmca-counter-notice/ https://odinlaw.com/what-is-a-dmca-counter-notice/
- TheDesolate0 6y agoYou must or they can take M$ to court, which M$ would crush RIAA.
- m11a 6y agoThat is, to be fair, an aspect that could be improved on. However, how do you do this? For example, perhaps a large-business exemption where they are required to follow through with legal proceedings if a claimant files a counter-notice (so they can't do the whole claim, counter-claim filed, they don't follow up, like with PopcornTime, usually because the DMCA was bogus). But then this encourages further litigation, so it discourages people taking the risk to file a counter-claim. But unless they follow through with legal action, nobody can assess if the initial notice was "fraudulent". It's a real thorny problem.
- tgsovlerkhgsel 6y agoThere are many possible solutions, e.g. - A company that files a fraudulent request loses DMCA rights (that way, it doesn't have to be proven repeatedly, just once) - Liability for false takedowns w/ punitive damages, criminal liability with actual enforcement for malicious attempts or even negligence. Potentially a deposit requirement once a false claim has been made.
- nybble41 6y agoThose are good ideas, but the first one should have been: - Nothing at all happens until a unbiased court issues an injunction. In other words, the process that was in place before the DMCA was passed.
- WhyNotHugo 6y agoFor one, you could ask for due process, or the right to defend yourself before the takedown is executed. Right now, DMCA is an accusation AND a sentence bundled into one. There's no review of its validity, you're instant guilt unless proven wealthy.
- sergeykish 6y agoBut what part of it is copyrighted? URL? It does not contain copyrighted text, audio, video. Information is on the plain sight, it is like banning base64. Any general purpose computing should be taken down as well. Browsers has DRM, as I know youtube-dl can't download Netflix, Youtube Premium etc.
- yoz-y 6y agoFor one I’d like there to be some punishment for repeated abuse of DMCA. GitHub policies state that repeat offenders can get their accounts suspended/deleted. Why can’t repeat offenders (RIAA) get banned from the system at least? Some increasing back off after a rejected claim was posted? Anything that would make it un-economical to just spam the system with notices wherever you like it because there is no downside to it.
- Meph504 6y agoI wonder if anyone has written something to find and independently assess the validity of these bulk false DMCA take downs. Honestly, I'm guessing a ambitious law firm could actually make a good class action suit against these offenders. Seems like broad, real damages could be justifiably demonstrated.
- seg_lol 6y agoIf only we could retool SCO for a force-for-good? Weren't there environmental laws that a private party could sue an offender over and would get a portion of the federal fines? Seems like a free-market solution that the right would get behind. :)
- Iv 6y agoReform copyright. It was based on the assumption that taxing copy production is a reasonnable way to fund creation. It was an incredibly good system in the days of the press where making copies requires heavy capital investment. It is hilariously wrong nowadays when everybody own a copy-making machine in each pocket.
- nybble41 6y ago> It was an incredibly good system in the days of the press where making copies requires heavy capital investment. It was never a good system, but it was certainly less obviously broken and destructive to society then than it is today.
- mschuster91 6y agoFuck no, they didn't back down. Hundreds of thousands marched across Germany, in Munich where a friend of mine organized it was one of the largest rallies in recent histories - and all for vain, we got the upload filter crap regardless of all the promises.
- saddlerustle 6y agoWhat? Pretty much every EU member ratified the same WIPO treaties and so have almost identical laws to the DMCA.
- joeblau 6y agoI don't understand what's going on here. Can you explain?
- deleted 6y ago[deleted]
- Stephen304 6y agoI might not be able to explain well, but from what I understand about how github works, when you fork someone else's repo, github only stores 1 tree but you have your own set of tags / branches. This led to an issue that was probably fixed where if you set a repo to private, anyone who had a clone could guess commit hashes from their fork's remote. Another interesting thing about git is that you can have 2 root commits (the Linux kernel has 4 root commits iirc). Because of these 2 "features", when I clone dmca and run `git pull some_ytdl_git_mirror master --allow-unrelated-histories`, I end up with a giant source tree that consists of both repos joined by a merge commit. Because no rebasing happened, no history was changed and it can be pushed without force permissions. Now that all the youtube-dl commits are in the same tree as the dmca repo, you can access them regardless of what fork you've cloned via `git fetch origin <hash>`. I hope that makes sense?
- dannyw 6y agoThis seems like a security issue, no?
- hvdijk 6y agoIt is a security issue if the presence of a commit or tree in a repo is supposed to be enough to get GitHub to nuke the repo, as this then allows malicious users to convince GitHub to nuke any repo they like, but GitHub can instead deal with this more sensibly and not make it a security issue.
- kortex 6y agoSeems to me like you could ddos a repo this way, though I guess that would be true of any pr spamming?
- MrStonedOne 6y ago>Another fun discovery is that deleting my fork of github/dmca didn't affect the PR like I thought it would Making the pr will put the branch in the target repo under pull/<number>/head the commit will forever be referenced
- davvid 6y agoIf you have a clone of the dmca repo, run: git config --add remote.origin.fetch 'refs/pull/*:refs/remotes/pull/*' git fetch origin You'll now have all of the PR refs in "remote" `pull/<number>/head` branches. git log pull/8142/head git log 416da574e
- fireattack 6y agoJust curious, why is this possible with an unmerged PR? Just a weird setup on GitHub's end?
- est31 6y agoIt's due to how git works. In order for git tools to compare and otherwise work with two commits, both commits need to be in the same repo. If "forking" a repo on github really cloned it in their infrastructure, they'd require far more data. So all forks of a github repo point to the same repo, only with different branches. Note that git clone only clones the actually present branches of the upstream you point it to, but on the backend, all branches of all forks are present.
- brodie 6y agoThis isn’t simply because of how Git works. You can configure Git to look in multiple places for repo objects. For whatever reason, the GitHub devs either didn’t know this, or they didn’t want to implement their forking and pull request systems this way. As someone else mentioned, this may be an intentional design to make it simpler to implement pulling down remote PRs from the destination repo.
- est31 6y ago> You can configure Git to look in multiple places for repo objects. What do you mean by multiple places for repo objects? Do you mean multiple remotes? The remotes are fully inside your local database if you run commands like git pull or git remote update, they are just not in your checkout. Commands like git show <commit hash> work on commit hashes in those remotes as well, even if it's not in one of your local branches. Or do you mean configuring git to use multiple .git/objects directories? I haven't heard of that feature, can you give a link?
- brodie 6y agoThe feature’s called alternates. You can use it on-the-fly without modifying any repos by using the GIT_ALTERNATE_OBJECT_DIRECTORIES environment variable. If you want the effect permanently, there’s the .git/objects/info/alternates file. For HTTP remotes, there’s apparently a .git/objects/info/http-alternates file as well (no idea how that works though). I’m assuming these files allow multiple alternates as the environment variable does.
- gamblor956 6y agoThe end result will be GitHub taking down this repo and possibly blocking PRs. Congratulations on making life difficult for other people.
- userbinator 6y agoCongratulations on making life difficult for other people. Tell that to the RIAA... It's funny to see the Streisand Effect happen with this one.
- gamblor956 6y agoUS copyright law has teeth for stuff like this. If the RIAA goes after the OP for statutory damages, he's basically fucked for life. And they love to make examples of people. Did everybody forget Kazaa and Limewire?
- deleted 6y ago[deleted]
- toyg 6y agoNot remotely on the same level. Kazaa and Limewire were moneymaking companies with fairly undefensible behavior from a legal perspective. This is an individual using a website the way it’s supposed to be used, for documentation purposes. A judge would “expeditiously” send the RIAA packing with a large bill for defendant’s legal fees.
- gamblor956 6y agoRight, it's not the same level. Kazaa and Limewire faced theoretical liabilities in the billions. That doesn't mean that the programmers of youtube-dl, or those who choose to engage in spreading the program, can't be held liable for much lower levels of damages which are still financially ruinous for an individual even if they're small on an absolute basis. I've been on the other side of an RIAA lawsuit, and their lawyers are aggressive. They offer a carrot settlement, but if that settlement is declined they will beat you with a stick and offer no mercy.
- JMTQp8lwXL 6y agoWould closing the PR be enough to remove it, or does it actually have to be deleted? I didn't think PRs could be deleted, only closed.
- Stephen304 6y agoI don't think so, if you look at the other closed PRs, you can find some where the owner also deleted their fork like I did. Despite that you can still access the commits they wanted to merge.
- Arnavion 6y agoClosing will not be enough. Even deleting the fork that made the PR will not be enough. (The PR remains open and the commit URLs automatically get updated to point to the parent repo, just like the URL that was submitted.) Users can't delete PRs but GitHub can. They do it for PRs reported as spam, etc. Regardless, what's needed here is not just deleting the PR (and the fork) but also doing a GC (as Stephen304 said), which too is something only GitHub can do.
- AdamJacobMuller 6y agoThis is hilarious, well done. I realized something while :+1:-ing your PR: I was thinking about how digg deleted my account over posting the AACS key, I really couldn't care less if Microsoft deleted my account over it. Very interesting considering that even just 2 years ago I never would have done this for fear of my account being deleted. All of my work and personal projects are moved to gitlab (the CI/Kubernetes/etc integration are just too good to pass up). I know a sample size of 1 has an effectively 100% error rate, but, I think Microsoft is losing mindshare with GitHub. Stuff like this doesn't help. I could see a small company like GitLab needing to toe the DMCA line, but, Microsoft has the deep pockets and could have built some major community will here by handling this better. Unfortunate that they didn't. Anyway, fun hack, I wonder how long it will last, or will they merge it? It must be the most approved PR in GitHub history at this point!
- Stephen304 6y agoHaha thanks, yeah I do wonder whether my account may be impacted. Best case they just delete the PR and garbage collect the repo. Worst case I get the final push to use gitlab.
- jcranmer 6y ago> I know a sample size of 1 has an effectively 100% error rate, but, I think Microsoft is losing mindshare with GitHub. Stuff like this doesn't help. I could see a small company like GitLab needing to toe the DMCA line, but, Microsoft has the deep pockets and could have built some major community will here by handling this better. Unfortunate that they didn't. If MS didn't comply with the DMCA takedown notice, then the RIAA could go to court and get an injunction to force it down. Depending on how spiteful the RIAA and the judge are feeling, the injunction could be worded to take down the entirety of GitHub over a single repository. And the impact of actions like these is to make it more likely that such an expansive injunction is sought or granted.
- saagarjha 6y agoRIAA taking down all of GitHub would instantly pit them against all of Microsoft, and make every developer who already hates their guts to pick up the pitchforks and march. They won't try doing it.
- dheera 6y agoWhy github/dmca? Why not e.g. tensorflow or numpy or some other package that people actually depend on?
- saagarjha 6y agoIronic.
- jonahx 6y agoAnd if GH deletes, and anyone else opens a new PR like you did, then those commits would remain until a second GH admin intervened, and so on?