Slashdot Mirror


German Court: Open Source Project Liable For 3rd Party DRM-Busting Coding

Diamonddavej writes "TorrentFreak reports a potentially troubling court decision in Germany. The company Appwork has been threatened with a 250,000 Euro fine for functionality committed to its open-source downloader (JDownloader2) repository by a volunteer coder without Appwork's knowledge. The infringing code enables downloading of RTMPE video streams (an encrypted streaming video format developed by Adobe). Since the code decrypted the video streams, the Hamburg Regional Court decided it represented circumvention of an 'effective technological measure' under Section 95a of Germany's Copyright Act and it threatened Appwork with a fine for 'production, distribution and possession' of an 'illegal' piece of software."

14 of 178 comments (clear)

  1. "effective technological measure" by mwvdlee · · Score: 4, Insightful

    You keep using that word. I do not think it means what you think it means.

    Doesn't the concept of "effective" mean that code breaking the DRM cannot exist?

    --
    Slashdot social media options: AIM, ICQ, Yahoo, Jabber and Mobile Text. Why no MySpace?
    1. Re:"effective technological measure" by fuzzyfuzzyfungus · · Score: 4, Interesting

      One would like to think so; but the courts haven't (CSS is how broken now, and for how long?) I assume that the argument is that it's 'effective' because you still need a specially designed tool to break it, not unlike a lockpick. What isn't clear, under that reasoning, is why essentially all file formats of remotely nontrivial complexity don't count as 'effective technological measures', since virtually nothing in digitized form is remotely human readable without specialized software transformation. Your odds of turning an RTMP stream into video with your brain are basically as good as your odds of doing the same with an RTMPE stream, and neither are high.

    2. Re:"effective technological measure" by Anonymous Coward · · Score: 4, Interesting

      German speaking guy here. You're absolutely right, I have the exact same opinion, but they really use this "wording" (sorry if I didn't get that expression right). It's stupid. I believe that it is written like this deliberately. So they can use any $drm scheme, doesn't matter how cheap, it could be as cheap as, any 12 year scriptkidde can circumvent it, if it says $drm, you can be sued for the circumvention of it. Or the other possibility is, they really just have no idea. Maybe they compared drm to the physical world. Burglers can smash in your window just like that, enter your house and steal everything of value/easily movable. Doesn't mean they couldn't be sued for it, because security doors + windows are an effective counter measure against burglars.

    3. Re:"effective technological measure" by Kjella · · Score: 5, Insightful

      A book written in Greek and a book written in English using a cipher are both gibberish to me, but understanding one depends on a parser and the other on a decryption key. In short the understanding of "effective technological measure" seem to be that the protocol is trying to use a secret (CSS key, AACS key, HDMI key etc.) to protect the content. So if you took any file format and wrapped it in AES with a static key with no memory protection whatsoever then decrypting it in any other program would be a DMCA violation, geeks all get caught up in "effective" but in context it just means a measure intended to have that effect specifically to exclude all other attempts at interpreting a protocol as "cracking" it.

      --
      Live today, because you never know what tomorrow brings
    4. Re:"effective technological measure" by sumdumass · · Score: 4, Informative

      The law is a direct result of the WCT or WIPO Copyright Treaty. The judge is likely interpreting "effective" within respect to that. It is under article 11 I think but i'm on my phone right now and it is a bit hard to check.

      Anyways, i believe effective would mean anything non trivial or ancillary at the time of creation. So if a cipher is so easy to break that they teach doing so as part of security lessons, using that couldn't be effective. But requiring something that isn't known or readily done could be if it isn't blatently obvious.

    5. Re:"effective technological measure" by squiggleslash · · Score: 4, Informative

      Well perhaps, but to play Devil's advocate: this isn't a game.

      There are two parts to DRM when combined with an anti-circumvention law. The first is the one that exists anyway: to attempt to make it as difficult as practically possible for someone to gain unrestricted access to the raw content. The other - which the DMCA (and its apparent German equivalent) adds - is to add legal liabilities for creating, possessing and/or using the tools, however easy, that break that encryption, should they ever come into being.

      Us nerds have a tendency to misread laws and assume that rather than it being a reflection of the intent of the authors, that the language used is arbitrary and written by dolts to be interpreted in the widest possible context. Specifically we look at words like "effective" and rather than interpreting it in the context of the rest of the law, we go off on tangents and ask whether something is effective using other definitions within different contexts.

      Is, for example, CSS effective? Well, I'd argue it is in context. It requires you use a specialized tool, designed specifically to break CSS, in order to access the content. It meets the definition in context. It doesn't meet the definition if you change the subject and say "Well, in 1998 it protected content, but does it now? Is it easy to find the tools needed to circumvent it?", but that's not the definition of effective that's implied by the context of the legislation - which is why better lawyers than us are not making that claim when protecting, say, Real Networks.

      As for ROT-13.... well, maybe it is, maybe it isn't. My guess is it wouldn't, because ROT-13 doesn't require knowledge of any secrets beyond the fact it's being used to begin with, and the "tool" used to decrypt it is already built-in to a billion email, USENET, and so on clients. At the very least, if SuperdooperRayVD 4K discs in 2020 are encrypted using ROT-13, they'd have great difficulty persuading judges that millions of pre-existing USENET clients from the 1990s are illegal.

      --
      You are not alone. This is not normal. None of this is normal.
    6. Re:"effective technological measure" by Kat+M. · · Score: 4, Insightful

      Section 95a (2) of the German copyright law defines specifically what an effective technological measure is. It specifically includes "encryption, scrambling or other transformation". It does not require that the encryption etc. need to be unbreakable, just as a physical lock does not have to pose an unsurmountable barrier in order to make breaking it illegal.

  2. Re:Does the copyright need an owner? by mwvdlee · · Score: 4, Interesting

    Open source licenses use copyright.
    Only the owner of a copyright can enforce it.
    If somehow copyright would be assigned to a non-existant entity, nobody could enforce it and it would effectively become public domain.

    --
    Slashdot social media options: AIM, ICQ, Yahoo, Jabber and Mobile Text. Why no MySpace?
  3. contributions to open source products should be by Chrisq · · Score: 4, Insightful

    contributions to open source products should be just like posts to websites. If someone posts something illegal then the authorities should issue a "take down" notice to the project. If they remove it then only the original poster should be liable.

  4. Hamburg regional court by dunkelfalke · · Score: 4, Informative

    is known for its cowtowing to the intellectual property holders. That is why they try to go to that particular court if they sue for copyright infridgement.

    --
    "It's such a fine line between stupid and clever" -- David St. Hubbins, Spinal Tap
  5. The owner/admin is (broadly) responsble... by Stolpskott · · Score: 4, Insightful

    In the world of athletics, the athlete is responsible for verifying beforehand that any substances entering their body are free from performance-enhancing drugs and a range of other substances. In this case, that same rule seems to have been applied to software - the admins are responsible for code entering the body of the application.
    Aside form anything else, my opinion is that someone on the project should have oversight of new code submissions before they are committed to the main codebase. If that is not happening here, then this is a lesson in stupidity for the admins. If it is happening, then the admins really are facilitating, because they have explicitly allowed that functionality into the application. Flipping the coin again, if the admins explicitly allowed the content without realizing what it does, then they have commited code without understanding the purpose or impact of the code, and we are back to the lesson in stupidity again...

  6. unreviewed code by feds · · Score: 5, Insightful

    Actually this is worrisome for the open source community not because they ended up in court but because Appwork accepted code without reviewing it and actually without even knowing what it does. How can they assure users that installing the application they don't become part of a 15 million users botnet?

  7. Hamburg Court by Tom · · Score: 5, Interesting

    he Hamburg Regional Court decided

    You can stop reading there.

    This particular court is the laughing stock of the german legal system, and its decisions are routinely overturned at the higher courts. They are famous for "creative" interpretations of the copyright laws.

    Source: I live in Hamburg, Germany and I've been following copyright-related civil rights matters for more than a decade.

    --
    Assorted stuff I do sometimes: Lemuria.org
  8. Ok You Clowns Here is the scoop. by deviated_prevert · · Score: 4, Interesting
    The warez in question is a java app with binaries available to be loaded at time of install from a script. So the setup starts with a set of jars that get extracted. YOU CAN INSTALL IT TO /HOME and view the entire process which downloads more binaries as the install takes place, at least on Linux if you install unpriviledged it will just install in a created directory and do everything from $ directory without requiring logging elsewhere or so you can easily track everything the software does.

    I ran Wireshark on it and it does not do the ET phone home crap that most spyware does so it is what the writers say it is.

    If you boot it up and do not leave it in the sys tray it does not leave active processes hanging around. HOWEVER you can run it as a background process to snoop your RTMPE and have them automatically download the vids. On youtube it downloads the whole smash including the webM html5 streams and all available vid size pieces of a vid including any mp3 or other audio files.

    Best stream ripper out there IMO. EAT MY SHORTS MPAA, RIAA and all your ill begotten drm bullshit nonsense. This video is a great one and as a result I will order her works online she is one hot guitarist! Fantasia la Traviata a little beyond the reach of most musicians, eat your heart out if you like guitar!

    --
    This message was not sent from an iPhone because Peter Sellers really was a deviated prevert without a dime for the call