[00:00.000 --> 00:01.400] Please don't take this as legal advice. [00:03.140 --> 00:04.760] And I'm Christopher Mooney. [00:05.440 --> 00:09.560] You can reach me at chris.dod.net or follow me on Twitter. [00:10.240 --> 00:14.600] I have a computer science degree from the University of Southern Maine, which is where I met Tiffany. [00:15.520 --> 00:22.720] And I'm currently a software engineer at craigslist.org, although I have to say that this talk may not reflect craigslist views. [00:24.200 --> 00:30.440] I'm also the current acting executive director of Project DOD, which is a 501 nonprofit organization. [00:31.360 --> 00:35.620] And most of the abuse case examples that we're going to give you today come by way of that. [00:36.660 --> 00:43.780] Lastly, if you guys were at DEFCON last year and any of you attended the Subverting the World of Warcraft API talk, that was me. [00:44.880 --> 00:48.000] It was way more upbeat, I think, than this talk will be. [00:48.960 --> 00:52.620] And unlike a lot of legal talks that I've seen, I'm not going to read you the whole DMCA. [00:52.720 --> 00:56.740] I'm not going to talk statute, but I will briefly tell you about what the DMCA is. [00:56.880 --> 00:58.360] It's the Digital Millennium Copyright Act. [00:58.560 --> 01:03.420] It's being used in ways that I don't think the drafters intended for it to be used. [01:03.620 --> 01:08.740] It's a free speech, disclosure of security vulnerabilities, innovative research. [01:09.020 --> 01:12.180] And the ACTA is something that isn't in effect yet. [01:12.260 --> 01:13.180] It has not been passed. [01:13.380 --> 01:21.680] But the countries that are going possibly, if this does happen, that are going to be affected by ACTA will have chilling effects similar to the United States. [01:21.680 --> 01:22.420] So it's important. [01:22.580 --> 01:29.820] And one of the reasons we're talking about this is if you should tell your lawmakers if you're not thrilled about the ACTA now before it is passed. [01:31.800 --> 01:32.260] All right. [01:32.620 --> 01:35.100] What we're going to do is I'm going to give you some hypothetical examples. [01:35.460 --> 01:39.280] And then we're going to ask you, is this fact or is it fiction? [01:39.440 --> 01:40.200] Can this really happen? [01:40.200 --> 01:45.100] The first thing here and how the DMCA affects you if you have a company. [01:45.540 --> 01:48.900] Let's say you have a software company and you're going to launch a product. [01:49.180 --> 01:50.120] It's really big for your company. [01:50.800 --> 01:55.220] Someone else, as happens often when you have innovative products, has something that's almost exactly like yours. [01:55.420 --> 01:55.960] But not exactly. [01:56.480 --> 01:57.440] Your company is quick. [01:57.680 --> 02:01.960] You want to be first to market because those are their first to market or usually have the best market advantage. [02:02.440 --> 02:09.900] However, you just discovered that your ISP has been flooded with DMCA takedown notices about your software, about your source code. [02:10.740 --> 02:11.440] What happens? [02:11.880 --> 02:14.440] Most, if not all, of your company site is removed by your ISP. [02:15.100 --> 02:17.900] And the day you plan for launch, you have no online presence. [02:18.460 --> 02:20.360] And if you're an online computer company, that's a big deal. [02:20.580 --> 02:21.800] You miss being first to market. [02:23.160 --> 02:30.340] Silencing discussion of security vulnerabilities is one that I know a lot of people in this room are familiar with and something that is important to me and Chris when we discuss these things. [02:30.340 --> 02:32.900] But let's say in this hypothetical, you're a security researcher. [02:33.560 --> 02:35.500] You are into all the O-Day stuff. [02:35.720 --> 02:37.780] And you have a vulnerability disclosure. [02:38.280 --> 02:44.420] And you're about to do the O-Day, but you hear someone else is doing something similar to you, as often happens in this community, I know. [02:44.580 --> 02:50.820] And to slow down the other researcher, you decide to file multiple DMCA takedown notices to his ISP. [02:51.300 --> 02:54.360] And you let the ISP just figure out if they're legitimate or not. [02:54.700 --> 02:55.620] So the result? [02:55.960 --> 03:00.580] Your competitor's blog, social network accounts, and his company's sites are doing the same. [03:00.640 --> 03:02.240] You post your O-Day, he does not. [03:04.040 --> 03:05.240] Chilling online critique. [03:05.460 --> 03:07.840] This is what's very key to the case we're talking about today. [03:08.080 --> 03:11.060] You've been injured by medical techniques implemented by a physician. [03:11.400 --> 03:14.300] You would like for other doctors and patients to know how this harmed you. [03:14.500 --> 03:18.500] You want other people to research how to make it better, how this cannot happen to other people. [03:19.000 --> 03:23.140] So this doctor who performed this medical technique on you has had books. [03:23.140 --> 03:23.820] He's published books. [03:23.900 --> 03:26.760] He's been on TV, broadcast TV. [03:27.100 --> 03:33.900] And you use proper fair use techniques, citing references, and you take little bits of his book and say, this is the problem here. [03:33.960 --> 03:34.840] I didn't agree with this. [03:34.860 --> 03:35.660] This is how it hurt me. [03:35.880 --> 03:36.540] The result? [03:36.780 --> 03:44.560] Your blog and all critique mentioning the doctor's name is offline because your ISP has so many takedown notices that it comes right down. [03:45.320 --> 03:50.060] No one can discuss the online negative effects that this doctor has caused. [03:51.500 --> 03:52.700] So here's the question. [03:52.880 --> 03:54.080] And we'll answer it toward the end. [03:54.160 --> 03:55.180] Is this fact or fiction? [03:56.140 --> 03:57.040] That's a good question. [03:58.220 --> 03:58.700] All right. [03:58.760 --> 03:59.920] Here's the little spiel about... [03:59.920 --> 04:01.340] This is what the DMCA is. [04:01.440 --> 04:03.960] And I look at two different aspects of the DMCA in the research I do. [04:04.100 --> 04:10.580] I research legal reverse engineering techniques, which, as you know, are extremely difficult to get right legally to get it right for the reverse engineering. [04:10.780 --> 04:14.160] If you work for a company, they care very much about the clean room, dirty room type of technique. [04:15.260 --> 04:22.980] So that's one aspect of the circumventing anti-circumvention measures, such as breaking encryption to be able to look at copyright or even patented code, which you know is in the... [04:22.980 --> 04:25.640] It is something that you could look up on the USPTO site. [04:26.240 --> 04:35.700] Now, this, on the other hand, we're talking about, in this case, about DMCA takedown notices for copyright infringement, alleged copyright infringement. [04:35.820 --> 04:38.180] But this was signed into law by President Clinton in 1998. [04:40.220 --> 04:43.440] This is a staggering percentage that we had here. [04:43.440 --> 04:46.760] But 37% of DMCA takedown notices are invalid. [04:47.540 --> 04:52.520] Google made a submission to... New Zealand was looking at drafting some laws similar to the DMCA. [04:52.800 --> 04:56.600] And Google decided that they were going to take a stand and say something about it. [04:57.100 --> 05:02.780] What's amazing is 57% of these invalid takedown notices were filed by businesses targeting competitors. [05:02.780 --> 05:06.340] So this is being used as kind of like an offensive market technique. [05:08.460 --> 05:10.340] Okay, here's the ACTA. [05:10.600 --> 05:11.900] I'm sure you've heard about it. [05:12.000 --> 05:14.900] But what's interesting about the ACTA is not a lot of people know about it. [05:15.060 --> 05:18.440] It was all negotiated behind closed doors, even by President Obama. [05:18.680 --> 05:22.740] And this is something that doesn't have enough discussion in the public as I think it should. [05:23.340 --> 05:28.600] This is an intellectual property type of organization that's outside of any other country's jurisdiction. [05:28.600 --> 05:31.620] It's its own thing outside of WIPO, WTO. [05:32.320 --> 05:35.460] And some of the things that are very interesting about this are at the bottom. [05:35.620 --> 05:37.960] It increases searches at the border. [05:38.820 --> 05:44.780] And the communication between different law enforcement groups is going to be heightened for that as well. [05:45.000 --> 05:52.360] But it addresses the reason that all these countries are getting together is they say that intellectual property infringement is on the rise internationally. [05:52.360 --> 05:55.560] So they're trying to get something into which all the countries agree. [05:55.820 --> 06:00.960] But it was originally for like people making like fake Gucci purses, whatever, and selling them in China. [06:01.540 --> 06:08.100] But it also extends to generic medicines, which can be dangerous if those are not from the company you think they're from. [06:08.300 --> 06:10.680] And online copyright infringement, such as music and software. [06:12.940 --> 06:14.440] Proposed party to the ACTA. [06:14.660 --> 06:15.320] Yeah, here they are. [06:15.500 --> 06:17.360] And the United States is up there as well. [06:17.580 --> 06:22.580] And if you go to the URL, and it's going to be in our slides, you can look at the recent draft that was prepared. [06:22.700 --> 06:24.460] This is the most recent I've been able to find online. [06:24.780 --> 06:30.200] Now, before this stuff was leaked, which was...this is one that was actually prepared for public release. [06:30.200 --> 06:35.760] But the leaks were the only ways that we were able to figure out what the ACTA was, and what was going on with it. [06:35.940 --> 06:37.340] Because there really was no public discussion. [06:39.520 --> 06:41.000] So a couple notes about the talk. [06:41.600 --> 06:45.580] There are different types of ISPs, and to try and clarify what we're talking about. [06:46.180 --> 06:50.760] We're not talking about the last mile Internet service provider, the one that gives you access to the Internet. [06:50.940 --> 06:54.120] The ISPs we're going to be talking about in this look a lot more like hosting providers. [06:54.680 --> 06:57.620] Facebook, Twitter, Google. [06:59.320 --> 07:01.480] And most of our questions are rhetorical. [07:01.760 --> 07:03.560] That's for the smart guys in the audience. [07:05.860 --> 07:07.840] So why is this talk relevant? [07:08.100 --> 07:09.920] The DMCA has been around for 10 years. [07:10.200 --> 07:16.200] Well, in our observations of Project DOD, abuse is on the rise. [07:16.200 --> 07:25.300] So in the last two or three years, we've seen lots and lots of users fleeing corporate hosting providers because they were kicked off without the ability to file a counter notice. [07:26.200 --> 07:32.340] And it's also extremely relevant because there's a bunch of other legislation in different countries. [07:32.600 --> 07:34.380] Like Canada has the C32. [07:34.960 --> 07:36.760] There's the digital economy bill in the UK. [07:37.020 --> 07:39.380] And, of course, the ACTA, which Tiffany just talked about. [07:39.380 --> 07:41.180] But all of these have takedown provisions. [07:41.560 --> 07:49.920] And it seems like the activist community out there that's trying to stop things is not as much focused on the takedown provisions as they are about things like digital locks. [07:50.400 --> 07:57.540] And we want to see if we can at least make the community aware that these things are a problem going forward. [07:59.380 --> 08:00.500] Whoops, wrong direction. [08:01.780 --> 08:03.460] So who is Project DOD? [08:03.460 --> 08:08.660] Well, it's an all-volunteer run, 501c3 charitable nonprofit, so there's no employees. [08:09.120 --> 08:13.720] But it looks a lot more like an open-source development project, which I'm sure plenty of you guys are familiar with. [08:14.620 --> 08:16.380] It's also funded by donations. [08:17.660 --> 08:27.940] Its biggest project right now is a hosting project that started about 12 years ago, originally providing hosting services to the needy and the impoverished back when hosting was really expensive. [08:28.160 --> 08:30.060] And over the years, hosting became more of a commodity. [08:30.060 --> 08:37.280] And as it did, the margins for profit for a normal hosting account started to get thinner and thinner. [08:37.620 --> 08:45.240] And so all of the content that was a bit troublesome wound up getting kicked off of ISPs because they didn't want to deal with it. [08:45.300 --> 08:46.500] There wasn't enough profit involved. [08:47.000 --> 08:51.660] And so we've slowly over the years gravitated towards this censorship-resistant hosting model. [08:53.600 --> 09:06.080] And as of now, a bunch of us are working on trying to build a censorship-resistant service infrastructure that uses jurisdiction hopping to remedy some of the problems that we're going to talk about in this talk. [09:07.500 --> 09:10.660] I'm also going to note that Chris and I are here on behalf of Project DOD. [09:10.660 --> 09:14.320] I'm a pro-boto attorney for Project DOD, and I have been for a few years. [09:14.640 --> 09:16.460] And Chris is a developer founder of DOD. [09:16.980 --> 09:28.620] And what we're here to talk about, this is the case that got us really actively involved in talking about censorship and really addressing issues such as, like, Tor hidden services, is this case. [09:28.840 --> 09:30.360] It's Project DOD versus Federici. [09:31.400 --> 09:33.780] We're going to talk about the DMCA takedown abuses. [09:34.380 --> 09:38.740] IT departments do not want to handle the floods of, you know, takedown notices they're getting. [09:38.920 --> 09:50.140] And with that high percentage of 37% of them, as it turns out, according to Google being invalid, that's a lot of stuff for them to sift through to see what's actual copyright infringement and what's just we want to silence and critique online. [09:51.580 --> 10:01.840] What's great about this case, and one of the reasons that we call this a vehicle case in law, and we're hoping that it will be, is that this case is not just about, like, copyright infringement. [10:02.000 --> 10:07.300] Like, you've copied, like, 12 different people's works and put it in your book and just published it with your name on it. [10:07.420 --> 10:08.200] This is different. [10:08.380 --> 10:17.280] This is the case in which this is about talking about medicine, science, you know, discussing things that are important for innovation and for making things better. [10:17.660 --> 10:21.160] We're not able to do that because of all the takedown notices our clients have gotten. [10:21.160 --> 10:29.100] So we're trying to find technological workarounds because we've reached a bit of a boundary with how far we can take it with the law. [10:29.420 --> 10:31.640] We've had great help from the Electronic Frontier Foundation. [10:31.800 --> 10:35.000] Corinne McSherry there has been a great advisor to us on this project. [10:35.160 --> 10:38.960] And so have a couple of attorneys in Portland, Maine, because that's where we started with our jurisdiction. [10:39.900 --> 10:43.760] They were, yeah, they're great procedural type of attorneys. [10:45.080 --> 10:51.240] Okay, two questions we have is, if our medicine is based on science, what does it mean for society if the peer review process is censored? [10:51.420 --> 10:57.800] If you can't talk about, hey, I don't like this process, I don't like this procedure, or hey, there's a security vulnerability, I'd really like to discuss this. [10:58.780 --> 11:01.040] That's going to be pretty chilling for speech. [11:01.520 --> 11:05.320] And if open discussion isn't able to happen, we're not going to be able to make things better. [11:06.680 --> 11:14.300] So I'm briefly going to give a little background on the dispute between Federici and this group advocates for children in therapy. [11:14.780 --> 11:19.180] But it'll just be fast so that we can get to the point where they wind up joining DOD. [11:19.780 --> 11:22.980] So Federici is an alleged attachment therapist. [11:23.500 --> 11:28.220] And basically he has a proposed treatment for something called a reactive attachment disorder. [11:28.880 --> 11:36.820] And the treatment is a sort of holding therapy that looks like, you know, you basically restrain the child, pin them against their will. [11:36.820 --> 11:43.360] And at some point they break down and the theory is that they'll reform a bond that they didn't form when they're younger. [11:44.780 --> 11:48.820] So Advocates for Children in Therapy is this group trying to stop this practice. [11:49.280 --> 11:51.480] They say it's tantamount to torture. [11:53.000 --> 11:57.360] And so they've been fighting this actively for years and years. [11:58.620 --> 12:05.600] Just to give you guys some context, I don't know if you've ever seen the Law and Order episode about this girl that was smothered in a blanket during some weird rebirthing process. [12:05.600 --> 12:16.040] So that is based on... loosely based on this case with Candace Newmaker, which is a young girl that was killed as a result of this therapy. [12:18.180 --> 12:25.540] So Federici basically legally engaged advocates for children in therapy for libel and slander years and years ago, before they ever got to us. [12:26.040 --> 12:33.900] And so Advocates for Children in Therapy restructured their page to basically allow people to draw their own conclusions. [12:33.900 --> 12:40.700] And the reason they did that is because truth is a protection against libel and slander. [12:40.980 --> 12:44.540] And so I want to give you an example of what the restructured page looks like. [12:45.420 --> 13:00.200] And you'll see here that basically you have a set of quotes, and you have a citation down at the bottom with page number, the book that it's in, another set of quotes, and page number, and the book that it came from. [13:00.500 --> 13:05.740] Now, those of us that went to school certainly know that this is what we were taught to do when we quote things. [13:06.240 --> 13:09.820] And I think that this is clearly fair use. [13:12.400 --> 13:14.200] So, enter the DMCA. [13:14.640 --> 13:20.580] So Federici says, oh, well, this is my copyright, so I'm going to send DMCA takedown notices for it. [13:21.020 --> 13:26.160] And he files some DMCA takedown notices with a Ma and Pa hosting shop for Advocates for Children in Therapy. [13:26.400 --> 13:31.220] And Advocates for Children in Therapy is kicked off immediately without the ability to file a counter notice. [13:31.700 --> 13:33.660] And as a result, they move to Network Solutions. [13:34.340 --> 13:36.820] Well, Federici files a takedown notice to Network Solutions. [13:37.080 --> 13:38.340] And what does Network Solutions do? [13:38.520 --> 13:45.360] They also do not allow them to file a counter notice that, remember, this is the content, right? [13:45.740 --> 13:52.340] So they wind up leaving Network Solutions and finding Project DOD. [13:52.560 --> 13:55.240] And briefly, here's the procedure of all the stuff that we had to go through. [13:55.480 --> 13:58.240] Me and a couple other pro-dueno attorneys were very busy with counterclaims. [13:59.400 --> 14:03.500] So Federici files a takedown notice and the whole site is requested to come down. [14:04.280 --> 14:05.440] We allow for a counter notice. [14:06.200 --> 14:08.120] The content's down for 10 business days. [14:08.320 --> 14:17.620] And we'll talk about it in the talk while this 10 business days is pretty much tantamount to a denial of service attack if you just keep filing these takedown notices over and over again for the exact same content. [14:18.200 --> 14:20.560] So the content comes back up after the 10 days. [14:20.660 --> 14:22.360] Upstream provider gets harassed. [14:22.920 --> 14:27.200] EFF steps in to back the provider, which was fantastic, and they were okay with that. [14:27.200 --> 14:36.460] And Federici has other doctors send the same takedown notices, doctors meaning psychologists, that type of medical professional, for the same pages for over three months. [14:36.680 --> 14:38.020] And portions of that site are down. [14:38.220 --> 14:41.940] So during a long period of time, either the sites were down or parts of it. [14:42.080 --> 14:44.940] So the up and down time was really disruptive for the clients. [14:45.200 --> 14:45.340] Yeah. [14:45.500 --> 14:50.060] And this is all so the ISP in this case, Project DOD, can maintain its safe harbor. [14:50.580 --> 15:00.880] I also wanted to point out that our big contribution to censorship resistance is number two up here, which is simply that we allowed the counter notice procedures to happen. [15:01.620 --> 15:03.780] None of the other ISPs appear to be doing this now. [15:04.600 --> 15:06.620] So six months go by, we don't hear anything. [15:06.960 --> 15:11.240] Federici has an attorney file a takedown notice for the same content, exactly the same content. [15:11.460 --> 15:13.440] We use 512 to stop Federici. [15:13.920 --> 15:16.820] And 512 is about, like, misrepresentation of copyright. [15:17.000 --> 15:19.340] You're not supposed to be able to just file off... [15:19.340 --> 15:26.220] Well, you're not supposed to be able to file off these DMCA takedown notices and say, it comes down, I don't care what it is, you know, just take it down. [15:26.500 --> 15:32.700] But if we can catch him under 512F, we can get attorney fees paid for, which is what we were all hoping for. [15:33.300 --> 15:37.280] So arguments are made in Maine, and Maine dismisses for lack of personal jurisdiction. [15:37.640 --> 15:46.180] That's a whole other issue, but Federici files another DMCA takedown notice, the third one for the same element, and we are pursuing this Federici in Virginia. [15:48.100 --> 15:54.800] Okay, and one thing to mention about the DMCA, when Chris mentioned the safe harbor, do you want to talk a little bit about what the safe harbor means for an ISP? [15:56.440 --> 15:57.080] Yeah, sure. [15:57.540 --> 16:00.120] So basically, the safe harbor is that... [16:00.780 --> 16:01.460] Well, okay. [16:01.580 --> 16:17.200] So for ISPs, right, the entire point of the takedown provisions, and in fact, takedown provisions in all these other pieces of legislation, is that they tie this disinterested third party, the ISP, they tie the liability to the content that the user hosts as a contributory infringer. [16:18.640 --> 16:19.980] So it basically... [16:20.860 --> 16:21.660] Yeah, sure. [16:21.660 --> 16:38.700] If the ISP wants to waive the safe harbor provision, which Project DOD has done multiple times, and we've just taken it on in court instead, if we would lose that case, we could be contributory liable for the damages, the ISP meaning Project DOD. [16:39.380 --> 16:41.840] So common abuses for the DMCA takedown provisions. [16:42.100 --> 16:43.860] We've learned that fair use is not the magic bullet. [16:44.140 --> 16:47.220] And not only is it not, but fair use is difficult. [16:48.620 --> 16:51.480] We've found that it's very difficult defense for some of this. [16:52.640 --> 16:56.820] But statutory waiting period is a tad amount to a denial of service attack. [16:57.460 --> 17:01.000] And backdoor takedowns, what we're calling that, is when you just keep going... [17:01.000 --> 17:11.460] If you file DMCA takedown notices all the way up the stream for the ISP, if one doesn't do it, you just keep going all the way up and just really flooding their IT departments with these takedown notices. [17:11.460 --> 17:13.560] It's an endless chain attack. [17:13.760 --> 17:15.720] That's what we're experiencing right now. [17:16.440 --> 17:22.180] And leveraging a 5-1-12 counter notice to discover one's identity is another thing that's very tricky in this case. [17:22.680 --> 17:28.980] In this case, the attorneys, especially the female attorneys working on this case, experienced a lot of online harassment. [17:29.920 --> 17:34.560] And we knew it was related to this case because the postings were all about the psychologist. [17:34.560 --> 17:39.740] And it was meant to be anonymous, but some of the trails have led it to be not anonymous. [17:39.740 --> 17:42.040] And we found out some information about that. [17:42.280 --> 17:46.920] But there's some women who wanted to join in this suit, but they're afraid. [17:46.920 --> 17:50.960] They're afraid because of the harassment and the libel that we're experiencing online. [17:51.500 --> 18:04.160] So there are people who were interested in joining the case, but they're afraid that their identity is going to become public and that then they'll have a lot of libel to deal with like some of the other we have had for representing Project DOD. [18:04.680 --> 18:06.080] And the ISP's liability. [18:06.580 --> 18:06.660] Right. [18:11.180 --> 18:11.660] Okay. [18:11.900 --> 18:12.280] Sorry. [18:12.520 --> 18:15.660] Provisional 5-1-12, we briefly mentioned that. [18:15.740 --> 18:33.260] But what's important with this that's going on right now, EFF is on this case called Lentz versus Universal, which this is in the Ninth Circuit in California, and they're saying that fair use is a necessary element for notification, meaning you should have to consider fair use when you file these takedown notices. [18:33.500 --> 18:35.140] But right now, that is not the case. [18:35.380 --> 18:36.440] It's not happening like that. [18:37.000 --> 18:41.320] Fair use is hard to determine, is one of the issues that we're having as well. [18:41.660 --> 18:44.960] And therefore, fair use is hard to use as a defense against the DMCA, a takedown notice. [18:45.780 --> 18:48.440] And from our experience, don't try it. [18:48.600 --> 18:49.300] It's not working. [18:49.500 --> 18:49.840] It should. [18:50.040 --> 18:50.620] Legally, it should. [18:50.720 --> 18:52.640] But we're having a lot of trouble in the courts with this. [18:53.320 --> 18:55.440] And 5-1-12 is hard to use. [18:55.440 --> 18:57.800] So we have a jurisdictional problem with this as well. [18:58.520 --> 19:06.900] So some examples that Project DOD has experienced with clear violations, or I'm sorry, clear, fair use, and then receiving DMCA takedown notices. [19:07.300 --> 19:14.060] In 2005, we hosted Walmart-foundation.org and 700-club.org. [19:14.280 --> 19:20.520] These were satires, political satires of the sites that they were spoofing. [19:20.520 --> 19:26.940] They were made by a couple of art students at Carnegie Mellon University that were taking a subversive media class. [19:27.400 --> 19:30.300] And they were up on us for about two weeks. [19:30.660 --> 19:37.620] And then both users received DMCA takedown notices, one from Walmart, one from the Christian Broadcasting Network. [19:37.620 --> 19:42.560] And they really struggled with whether or not they wanted to file a counter notice. [19:42.780 --> 19:49.620] But they wound up not doing it because they would have to defend fair use against all the legal might of Walmart and the 700-club. [19:51.140 --> 19:57.480] And clearly, as we've shown, Project DOD versus Federici is also an abuse case of fair use. [19:57.480 --> 20:06.540] Except that the significance here is that we received those takedowns after the lens versus universal finding, which I don't want to say doesn't mean it doesn't have as much teeth. [20:06.720 --> 20:09.520] But I don't know if it's changed the playing field as much. [20:10.440 --> 20:13.800] The statutory waiting period is a denial of service attack. [20:13.940 --> 20:14.980] That's the way we're looking at it. [20:15.080 --> 20:16.280] It's equivalent to that. [20:16.720 --> 20:20.900] Upon receiving the counter notice to maintain safe harbor, we got to take the stuff down for 10 days. [20:21.320 --> 20:24.120] And that has been very difficult for our clients and for speech online. [20:26.420 --> 20:42.420] And so, of course, the Federici case, he figured this out and he had a bunch of his colleagues send DMCA takedown notices for content on the site because the site talks about a bunch of different people and the same sort of templated stuff. [20:42.800 --> 20:51.320] And so for different... so for over a period of like two or three months, different parts of their site was down as a result of this denial of service attack. [20:51.560 --> 20:53.340] And that's 10 business days. [20:53.340 --> 21:01.200] So maybe you can argue a business day is every single day of the week, but it may be defined as half a month at that point. [21:01.740 --> 21:14.620] And mind you, for some of the content that was coming down, these are people who have been in recovery groups from the hold down, the attachment technique, and also parents whose children have died or been injured by this technique. [21:14.620 --> 21:24.860] They haven't been able to express their concern about these techniques online because we kept getting these periods of time when it all came down. [21:25.920 --> 21:33.120] So there are backdoor takedowns is another way that the DMCA can be abused. [21:33.300 --> 21:48.120] This is that if we receive the DMCA takedown and we decide we're going to respond and allow the person to counter notice at any given point, there's nothing in the statute to prevent someone from going to our upstream provider and sending those people takedowns as well. [21:49.480 --> 22:07.760] So, you know, the de facto process out there at this point is to do an ERIN lookup on the IP address and use the abuse information there in order to contact the ISP and even some smaller ISPs don't have their abuse information registered in ERIN for their ISPs. [22:08.640 --> 22:23.320] And so the real danger here is sort of like the danger in the late 90s of media consolidation is that you have a couple large providers that essentially start to become the people that are dictating whether or not content stays up or stays down on the Internet. [22:24.000 --> 22:32.020] And just a side note to anybody that's hosting virtual private server hosting could be problematic since the content resides on that server. [22:32.340 --> 22:39.940] So if you have a set of policies, they may not matter since your upstream provider is likely going to exercise editorial control. [22:41.000 --> 22:44.860] So some examples of these takedowns that we've seen. [22:47.040 --> 22:51.860] Well, let's say over the last 12 years, we have a bunch of them, but there's one that stands out. [22:52.200 --> 22:57.940] And we've been kicked off of tons and tons of providers as a result of this, of the policy conflict. [22:58.680 --> 23:04.920] But we were on one provider that we were co-located with an ISP who was on above net. [23:05.180 --> 23:08.300] So it was two, above net was our two hop up upstream provider. [23:09.320 --> 23:13.200] And we were hosting, I don't know if some on the East Coast, you guys know what hack block is? [23:13.320 --> 23:14.040] Hackblock.org. [23:14.480 --> 23:17.540] So anyway, it's basically a hacking group. [23:18.880 --> 23:21.980] And much in the same way that like the hacking spaces are. [23:22.160 --> 23:23.260] And they have a zine that they publish. [23:23.560 --> 23:29.200] And they were talking about a person who was trying to get their members thrown into jail. [23:29.660 --> 23:34.080] And so they disclosed a bunch of dialogue or conversations from this guy. [23:35.440 --> 23:38.980] And then above net received a DMCA takedown notice for it. [23:39.280 --> 23:43.680] And told us we had to take it down, but didn't allow us to follow the process of counter notice. [23:44.620 --> 23:48.080] And so the interesting thing is we told them, okay, take it down. [23:48.240 --> 23:53.240] And what they did is they replaced in their zine, they replaced the section with the takedown notice, which is pretty common practice, right? [23:53.340 --> 23:58.560] You get something taken down, you put the takedown notice in its place so that people can see that you're being silenced. [23:59.120 --> 24:05.160] Well, we then received another DMCA takedown notice for the original DMCA takedown notice. [24:07.840 --> 24:15.140] And... but rather than above net look at it and say, oh, well, this is clearly abusive, they actually were really livid with us. [24:15.280 --> 24:24.440] They were like, we're not going to play this whack-a-mole game, like take it off, or we're going to shut you off entirely, which would mean sort of transitively that they would shut every user that we host off, all the domains that we host. [24:25.860 --> 24:31.140] And so today we have a much more functional relationship with our upstream provider in the project duty versus Federici case. [24:31.580 --> 24:36.860] Silicon Valley web host, which is who we're hosted with for that particular case, maintained their common carrier status. [24:37.220 --> 24:39.600] And this is because there are different classifications for ISPs. [24:40.120 --> 24:45.440] And one of the classifications is what we are, where is where the content resides. [24:45.560 --> 24:48.880] And there's another classification, which is the sort of common carrier status. [24:49.020 --> 24:56.260] And they have no obligation under the law to comply with the takedown and counter notice procedures. [24:57.540 --> 25:01.300] And the EFF stepped in to back up our upstream provider even when the abuse got really heavy. [25:02.420 --> 25:04.220] This is an endless chain attack. [25:04.440 --> 25:06.900] And for the pro bono attorneys, it's become tiring. [25:07.460 --> 25:10.020] After the full process, it's kind of like rinse, repeat, rinse, repeat. [25:10.080 --> 25:10.760] It just keeps happening. [25:10.760 --> 25:11.920] It's the same stuff. [25:12.080 --> 25:13.340] It comes down for 10 days. [25:13.640 --> 25:16.880] And it takes a lot of time to make sure that the new notices are indeed new. [25:17.440 --> 25:23.080] And if you ever heard of, you know, double jeopardy, this is like equivalent of like dodeca jeopardy or something. [25:23.240 --> 25:24.680] I mean, we just get the same stuff. [25:26.040 --> 25:28.060] Yeah, and this happens in the Federici case, of course. [25:28.800 --> 25:33.080] You know, I'm just going to mention that it is really time consuming because we lose our life. [25:33.200 --> 25:36.300] I mean, we lose our safe harbor if he just puts one thing in there. [25:36.400 --> 25:37.320] That's a little bit different. [25:38.060 --> 25:40.200] So, of course, it takes a ton of time. [25:40.200 --> 25:45.560] And I think you guys are starting to get an idea of why ISPs don't want to follow the counter-notice procedures here. [25:45.920 --> 25:50.540] They're for-profit organizations that just can't afford it. [25:50.600 --> 25:52.260] Or they probably could, but... [25:52.260 --> 25:54.540] And losing the safe harbor provision is a very big deal. [25:54.840 --> 26:00.340] And for Project DOD, this is one of the only organizations I have ever seen that says, okay, you know, bring it on. [26:00.440 --> 26:03.200] We're going to say we don't want the safe harbor provision. [26:03.320 --> 26:04.080] We're going to take you to court. [26:04.080 --> 26:06.640] It's expensive, especially if you don't have pro bono attorneys. [26:08.300 --> 26:11.620] So, leveraging the 512 counter-notice to discover one's identity. [26:11.780 --> 26:13.340] I mentioned this before, but... [26:13.880 --> 26:15.740] This is what's a little bit unfair about this. [26:15.940 --> 26:19.260] And it's unfair because counter-notices require personal identifying information. [26:19.680 --> 26:27.520] And if you do get a DMCA takedown notice, this is one of the ways that you can do a counter-notice without having to hire an attorney, at least if you want to take care of it yourself. [26:27.680 --> 26:31.300] But a project I worked on during law school is chillingeffects.org. [26:31.400 --> 26:32.720] And that's run through Harvard Law School. [26:33.020 --> 26:34.400] And it was... [26:34.400 --> 26:35.520] They have actually... [26:35.520 --> 26:38.260] You put in some information about who's sending you the takedown notice. [26:38.440 --> 26:40.880] It fills out the form for you, and you sign it and send it. [26:41.240 --> 26:43.740] So, that's how you do a counter-notice. [26:43.980 --> 26:45.220] The takedown notices... [26:45.220 --> 26:49.380] Well, that's not on chillingeffects.org, but I'm sure you can find those online if you wanted to file those. [26:49.480 --> 26:51.260] But we're dealing with the counter-notices here. [26:51.260 --> 26:57.640] So, they require personally identifying information, but notice that the takedown notices themselves don't require this information. [26:58.020 --> 27:00.620] So, it's the kind of thing where we... [27:00.620 --> 27:04.380] If you don't want to reveal some of your client's identities for the ISP, it's a problem. [27:05.540 --> 27:06.080] And the... [27:06.080 --> 27:06.420] Sorry. [27:06.780 --> 27:07.260] The... [27:07.260 --> 27:10.060] Section 512 requires a court order to release identity. [27:10.720 --> 27:10.960] So... [27:10.960 --> 27:11.200] Right. [27:11.380 --> 27:12.200] And that would be for the... [27:12.200 --> 27:13.340] That's a pretty high bar there. [27:13.700 --> 27:13.840] Right. [27:14.580 --> 27:16.780] Is that for the issuer of the takedown notice? [27:18.240 --> 27:29.820] The issuer of the takedown notice, the alleged right holder, can file a 512H request against the ISP in order... [27:29.820 --> 27:35.080] And they have to go through a court order to get the person identifying information of that person. [27:35.280 --> 27:38.080] Yet, a counter-notice doesn't require that same... [27:39.000 --> 27:40.320] It's sort of a loophole, right? [27:40.320 --> 27:41.240] It's like... [27:41.240 --> 27:41.520] So... [27:41.520 --> 27:41.660] Anyway. [27:41.820 --> 27:42.620] What we saw... [27:42.620 --> 27:44.640] And this is an entirely separate case. [27:44.820 --> 27:47.720] We also host a domain called stopchildtorture.org. [27:48.360 --> 27:49.520] And these people... [27:50.100 --> 27:52.060] This is the same person, Federici. [27:52.200 --> 27:55.820] These people have been kicked off all their providers and they've landed on us at this point. [27:56.080 --> 28:04.480] And stopchildtorture.org basically was pointing out an NBC video that was made about this practice way back in the day. [28:05.440 --> 28:15.020] And comparing some of the takedown techniques shown in the video with this facedown takedown process that security guards at school were using that they were told they should no longer use. [28:16.120 --> 28:17.580] And they were just... [28:18.500 --> 28:23.740] The person who runs the site was linking the two things together and saying that these things might be potentially lethal. [28:23.900 --> 28:26.700] Anyway, we got a DMCA takedown notice for it. [28:26.700 --> 28:33.520] And the wording of that notice was, and if this person wants to file a counter notice, they need to put their personally identifying information in there. [28:34.080 --> 28:39.720] And that was too much of a barrier for the user on our service so that the content went down. [28:40.360 --> 28:45.900] Although I will say that user did wind up moving it to a service called VideoWeeds, which is... [28:46.520 --> 28:49.760] It's in a different jurisdiction and therefore it doesn't have to comply with the DMCA. [28:49.980 --> 28:57.840] And some of the clients that are related to this case as well are journalists working on, you know, major magazines that you can buy in the newsstands where they're... [28:57.840 --> 29:01.740] The magazine is being... getting DMCA takedown notices from Dr. Federici. [29:02.000 --> 29:05.860] So he's silencing even the journalists working for magazines if they have an online blog. [29:06.300 --> 29:12.040] So we're beginning to get a lot of attention about the takedown... or the hold down technique. [29:12.200 --> 29:12.320] Sorry. [29:13.600 --> 29:13.980] Okay. [29:14.060 --> 29:16.120] ISP liability is significant failure of the DMCA. [29:16.320 --> 29:17.700] And Chris and I will both talk about this. [29:17.820 --> 29:19.620] But the alleged right holder, the alleged infringer. [29:20.720 --> 29:24.380] Passionate arguments should be made by those that most directly affected by the content. [29:24.520 --> 29:25.120] Yeah. [29:25.120 --> 29:25.740] So, yeah. [29:26.200 --> 29:33.160] You should be able to say what you have to say about information that's copyrighted. [29:33.240 --> 29:34.620] Because there are two things... [29:34.620 --> 29:38.980] Well, one of the two things that are most important about copyright law is you should be able to critique and parody. [29:39.340 --> 29:47.620] And you should be able to use small parts of the copyrighted material for fair use, for analysis, for sharing with others. [29:49.520 --> 29:49.920] Yeah. [29:50.300 --> 30:00.240] And, of course, what we've seen is that ISP is motivated in a profit industry that the de facto response has been to just censor their users to kick them off their services. [30:02.060 --> 30:03.740] Oh, actually, I wanted to make one more note. [30:03.740 --> 30:12.540] But it's easy for hosting users to switch to a service like DoD because they're sort of diverse and there's a bunch out there at this point. [30:13.120 --> 30:16.700] But it's not as easy for users on Twitter or Facebook to switch. [30:16.700 --> 30:23.760] And we have another user that switched to us for hosting that had all of their Twitter accounts and Facebook's accounts DMCA'd. [30:24.000 --> 30:28.380] And they're trying to fight against, like, spammers and scammers on the Internet. [30:28.620 --> 30:31.040] And these people DMCA'd all of those accounts. [30:31.180 --> 30:34.020] So now they've lost all of their ability to social network at all. [30:35.460 --> 30:41.980] And I think the future is going to see this problem getting much worse unless the statutes are changed or we take action. [30:42.420 --> 30:45.280] So just some examples of what we've seen. [30:45.280 --> 30:56.080] So ISPs that have kicked their users off without the ability to counter notice would be WordPress, GoDaddy, Network Solutions, and a bunch of smaller providers. [30:56.740 --> 31:05.060] We have a bunch of... we have use cases or we have users that have been through cases for every single one of these. [31:06.940 --> 31:09.060] So can technology fix these problems? [31:10.000 --> 31:13.340] Well, there might be a couple technical solutions that we can talk about. [31:13.340 --> 31:15.560] But I want to give a quick overview of Tor hidden services. [31:15.980 --> 31:20.340] And I want to thank the Tor people for letting me use the images of the hidden service protocol in the slides. [31:21.860 --> 31:27.100] I'm going to assume that you guys all have knowledge of how Tor circuits work just for now because we don't have time to cover it. [31:27.880 --> 31:33.040] And then we're going to talk a little bit about a jurisdiction hopping solution and maybe a little bit about direct action. [31:33.040 --> 31:37.380] And I'm going to speed up a bit so that you guys can get some questions because it's going to be a handful. [31:37.740 --> 31:40.880] So let's assume that the user here is Alice and the ISP is Bob. [31:41.320 --> 31:44.100] So Bob's going to pick a bunch of introduction points in a Tor network. [31:44.240 --> 31:51.060] So he's going to build a circuit, pick some introduction points, and then he's going to take a public key and list it in a directory service. [31:52.680 --> 32:05.760] That directory service, or I should say Alice or the user, can look up the identifier, the Onion identifier in the directory service, and she can also pick a relay point. [32:06.800 --> 32:07.780] Or a rendezvous point, sorry. [32:08.760 --> 32:21.880] And then Alice is going to contact one of the introduction points and forward a message on to Bob saying that, you know, oh, hey, I'd like to meet you at this rendezvous point to build a secure connection to you. [32:22.500 --> 32:31.400] And so Bob sends back this token and the public key and whatnot, meets at the rendezvous point, and the two of them establish a secure connection. [32:32.000 --> 32:38.960] So with this network, you essentially can build an entire secure connection from user to client. [32:39.240 --> 32:43.500] I'm sorry, from user to server without releasing the identity of either. [32:45.380 --> 32:49.260] And this is really attractive, but there's a spectrum of users, right? [32:49.460 --> 32:55.080] So on one end of the spectrum, we have all the users that are okay with commodity hosting. [32:55.640 --> 33:00.760] And then on the other far end of the spectrum, we have all the users that are probably going to die if they release their content. [33:01.620 --> 33:09.520] And Tor is really, really good at this set over on the other side, because there are some limitations to how fast Tor can work. [33:10.000 --> 33:21.740] And as you can see from the protocol I just ran through, any of you that use Tor or know anything about Tor or have used it in the past will agree that, you know, we make a little bit of a speed compromise when we use the network. [33:22.340 --> 33:25.680] And the protocol I just showed you actually has an even larger speed hit. [33:27.340 --> 33:30.500] So not all users are ready for that yet. [33:30.700 --> 33:32.360] And so there's this like spectrum in between. [33:32.680 --> 33:38.400] These are the users that want to just have fast hosting, but have suffered at the hands of DMCA takedown provisions. [33:39.040 --> 33:43.920] And so we're going to talk a little bit about how we solve the problem for those users. [33:43.920 --> 33:59.040] A couple additional notes are that the directory lookups for Tor are a bit obscure, and that's unfortunate, but not because it was a design choice, but because it may actually be a mathematical truth. [33:59.620 --> 34:07.120] There's this thing called Zuku's conjecture that says that these descriptors cannot be all three things at the same time. [34:07.220 --> 34:11.060] They can only have two of these three qualities, which is to be human, meaningful, secure, decentralized. [34:13.020 --> 34:16.060] And so there is a service called Tor2Web. [34:16.880 --> 34:19.280] And I hear the developer of Tor2Web is here today. [34:19.440 --> 34:23.980] And so if you're in the audience and you'd like to talk afterwards, I'd like to talk to you. [34:25.220 --> 34:25.980] Come on up. [34:26.300 --> 34:32.400] But so Tor2Web can be used to solve the sort of obscure Onion identifier problem. [34:32.700 --> 34:36.460] And you can think of it as a shim before that entire protocol that I showed you. [34:36.600 --> 34:41.040] It allows users to access hidden services through a pretty strong tool. [34:41.040 --> 34:43.400] It's a standard interface. [34:44.000 --> 34:48.600] And you can also use URL redirects to get rid of that obscure identifier. [34:49.200 --> 34:57.560] But this means that the central... you now have a central name authority, which means that you've done the trade-off of having something decentralized for something human meaningful. [34:59.020 --> 35:02.820] But we might be able to use jurisdiction hopping to solve that problem. [35:03.480 --> 35:13.360] Jurisdiction hopping is something that where you... if you have content that is not legal or something that you don't want to put in this country, there are other places you can put it where there isn't a problem. [35:13.480 --> 35:17.640] But one of the complications of this is you're going to have some legal complications and technical. [35:18.220 --> 35:18.940] Haven Co. [35:19.060 --> 35:26.820] in Sealand, Ryan Lackey was presented here, I think, two hopes ago about some of the failures they had with Haven Co. [35:26.880 --> 35:28.260] and some of the vulnerabilities they had. [35:28.440 --> 35:33.080] And some of the vulnerabilities were is... you really have to think about jurisdiction. [35:33.320 --> 35:36.900] When we talk about something being subpoena-proof, that's really difficult to say. [35:36.900 --> 35:40.360] With Haven Co., I think they were subpoena-resistant. [35:41.760 --> 35:46.940] But without getting into, you know, law of the sea and international law, regarding where Haven Co. [35:46.980 --> 35:47.580] was situated... [35:47.580 --> 35:48.200] Oh, Haven Co. [35:48.380 --> 35:51.180] is a platform in the North Sea off the coast of the UK. [35:51.480 --> 35:52.880] It used to be a gun platform. [35:53.220 --> 35:57.440] And they put... they had a... I think they were a hosting company. [35:58.000 --> 35:59.160] Sealand was the country. [35:59.160 --> 36:03.120] It was taken by adverse possession by some people in the 1960s for pirate radio. [36:03.700 --> 36:04.960] But Haven Co. [36:05.220 --> 36:12.260] was situated enough offshore from the UK before they changed what the boundaries were for the UK. [36:12.580 --> 36:15.500] Now they're... the UK says that they're within the UK waters. [36:15.800 --> 36:19.380] But this is what's complicated, is... do you have some content? [36:19.620 --> 36:20.960] How is it... how is it reachable? [36:20.980 --> 36:21.560] And that's why Haven Co. [36:21.620 --> 36:22.520] is an interesting example. [36:22.640 --> 36:28.760] But one of their biggest vulnerabilities was they were a hosting company, so content sat on those computers at Haven Co. [36:29.860 --> 36:33.380] And their Internet access was through some cables under the sea. [36:33.620 --> 36:38.140] They were, at one point, looking into satellite uplinks for Internet access, but that's very expensive. [36:38.280 --> 36:39.320] I don't think they ever got that going. [36:39.800 --> 36:43.600] But it... they're... the ISP... I mean, the Internet was coming from the UK. [36:43.720 --> 36:46.560] So if they really had a lot of issues, the UK was just going to turn that off. [36:46.660 --> 36:49.640] And whoever had all those computers hosted there, it was... it's going to go down. [36:50.240 --> 36:52.280] So that's how jurisdiction hopping works like. [36:52.280 --> 36:58.960] I know France has some really strict laws regarding particular... a particular speech about... [36:58.960 --> 37:01.160] like, for instance, Nazi paraphernalia is illegal in France. [37:01.380 --> 37:05.940] So it's... eBay had some issues with jurisdiction for people selling things such as that. [37:06.080 --> 37:07.100] It can't be sold in France. [37:07.300 --> 37:14.180] So eBay went through a lot of technical and legal jurisdiction complications on who can access those types of sites when you can't if you're from France. [37:14.180 --> 37:18.140] So that's the legal and the technical complications with doing jurisdiction hopping. [37:18.340 --> 37:22.060] And I've heard that... I know we... Iceland, Sweden have... are more... [37:22.060 --> 37:25.820] they're setting up some laws because they want to become havens for free speech. [37:26.300 --> 37:28.160] And it's... it's coming along. [37:28.160 --> 37:36.860] But I think it's not possible to say that anything is subpoena proof or warrant proof because you... oh, you... it's resistant, perhaps, just as we're censorship resistant. [37:37.420 --> 37:39.160] But yeah, it's... it's never proof. [37:39.380 --> 37:39.660] Yeah. [37:39.980 --> 37:45.780] And so the point is that, you know, different jurisdictions have different constraints on the content that can be hosted there. [37:46.060 --> 37:51.500] So a particular jurisdiction may be more sympathetic to a certain type of content than another particular jurisdiction. [37:52.100 --> 37:52.800] Are you ready? [37:53.200 --> 37:55.580] So this is going to be like... really fast. [37:55.720 --> 37:56.960] I'm going to go through a bunch of slides here. [37:58.020 --> 38:02.060] So what we're working on now is a censorship resistant infrastructure. [38:02.480 --> 38:06.040] We have development nodes in San Jose and Oakland and Sweden. [38:07.040 --> 38:08.580] Or we have access to a node in Sweden. [38:09.180 --> 38:17.060] So our hopes are that we can build some sort of censorship resistant infrastructure that allows people to jurisdiction hop to sympathetic jurisdictions. [38:17.460 --> 38:19.500] And to be... to be clear, what we're not... [38:19.500 --> 38:24.620] what we are not setting up is a place where you can put, like, illegal content overseas because it's illegal here. [38:24.800 --> 38:29.040] What we're doing is for... for cases such as, like, Dr. Federici's case. [38:29.360 --> 38:31.780] This is the... these are the types of clients that we host. [38:32.320 --> 38:32.460] Right. [38:32.460 --> 38:37.920] Where free speech is... really does involve, like, people talking about their children have died or, you know, some types of protest. [38:38.300 --> 38:40.000] That... that is... that... those are our clients. [38:40.000 --> 38:40.540] Right. [38:40.720 --> 38:42.460] So this isn't the battle for copyrighted movies. [38:42.700 --> 38:47.180] This is the battle for the casualties of that war. [38:47.800 --> 38:51.400] So this is all the people that are unfairly affected by this. [38:51.540 --> 38:52.520] We're preserving fair use. [38:52.660 --> 38:53.440] That's what we're trying to do. [38:55.840 --> 39:06.200] So, basically, I think that this is inevitably a stopgap solution at some point until we have something like Tor that is inherently secure and supports privacy and anonymity. [39:07.040 --> 39:15.100] But, you know, until we can... can move that into a domain where all users can use it, I think that... that we need a sort of transitional technology to get us there. [39:17.660 --> 39:19.320] So, we're gonna talk about cells. [39:19.880 --> 39:26.640] These are cells as in gorilla cells, being that there's no strategic asset for someone to go after to take down the network. [39:26.640 --> 39:30.080] And you guys are gonna like my diagrams, I'm sure. [39:31.120 --> 39:34.960] It's engineering paper with pencil and some bubbly cartoon things thrown on pub. [39:35.520 --> 39:45.020] So, you basically have the Internet and then we have cells like the San Jose cell, the Oakland cell, and the Sweden cell that are connected through a virtual private network. [39:45.940 --> 39:51.020] And content, essentially, needs to exist outside of any one jurisdiction. [39:52.200 --> 39:54.880] So, distribution of responsibility and isolation and control. [39:55.160 --> 40:02.520] This basically says that the admins in this particular infrastructure should only have control over the cells resources that they control. [40:02.860 --> 40:07.320] And that users should have control over where their resource is located. [40:07.460 --> 40:09.940] And I want you to think of a resource as a domain. [40:10.340 --> 40:15.140] It could be... I mean, it's any sort of service that you would provide as one of these types of ISPs. [40:15.140 --> 40:19.320] It could be a tour to web interface. [40:20.320 --> 40:21.920] So, you have a user. [40:22.640 --> 40:24.100] And a cell admin. [40:24.720 --> 40:25.320] And... [40:25.320 --> 40:25.940] Oh, good. [40:26.020 --> 40:26.500] You can read that. [40:27.020 --> 40:30.680] So, let's just say we have foobar.dod.net. [40:31.000 --> 40:34.980] And these are the places where foobar.dod.net is hosted. [40:35.580 --> 40:41.900] At any given point, the admin can turn off the access in a particular jurisdiction. [40:41.900 --> 40:44.700] So, say this admin has control over the San Jose and the Oakland cell. [40:45.160 --> 40:46.040] But not the Sweden cell. [40:46.720 --> 40:47.960] They can say, oh, no, sorry. [40:48.080 --> 40:49.920] This resource can no longer be hosted in these locations. [40:50.580 --> 40:52.260] And the user can do the same. [40:52.420 --> 40:53.940] They can say, oh, Sweden is way too far away. [40:54.020 --> 40:55.840] I don't want to offer my content in Sweden. [40:56.780 --> 40:58.300] So, please don't offer it there. [40:58.740 --> 41:02.540] They can also say, we have another case of an Australian user that needed to switch to us. [41:02.900 --> 41:05.500] But, by the way, Australia's laws are really messed up right now. [41:05.960 --> 41:11.200] And from what I hear, there's hardly any hope for them to try and turn that stuff around. [41:12.400 --> 41:15.820] So, yeah, I think this user could say, oh, I don't want to host this in Australia. [41:16.180 --> 41:17.640] And it'll host in another location. [41:18.700 --> 41:19.420] Redundancy of data. [41:19.600 --> 41:23.220] Of course, you need your data to be in more than one jurisdiction at a time. [41:23.340 --> 41:28.040] That way, we have that strategic asset principle that no strategic asset can be taken down. [41:30.440 --> 41:33.500] And that resources should be jurisdictionally resilient. [41:34.140 --> 41:36.960] You know, that is that there's jurisdictional diversity. [41:37.680 --> 41:39.080] And here's an important one. [41:39.200 --> 41:41.420] This is sort of the principle that Tor works on as well. [41:42.040 --> 41:47.680] Is that there should be no one organization like, say, Project DOD in control of the entire infrastructure. [41:47.880 --> 41:55.740] That it should be a diverse set of organizations, maybe multiple organizations in each jurisdiction that control the infrastructure, all connect together. [41:56.000 --> 42:01.300] So the policies of one organization don't affect the content in any particular way. [42:03.200 --> 42:03.640] So... [42:03.640 --> 42:04.800] Oh, this is going to be fun. [42:04.880 --> 42:08.260] I think you guys will like this since you're security researchers and this is a hacking con. [42:09.780 --> 42:20.500] So what we're going to do is a little thought experiment about what if we were to treat the DMCA takedown protocol flaws as protocol flaws. [42:20.960 --> 42:22.600] So I want to cover what those were. [42:22.780 --> 42:23.360] Again, just to refresh. [42:23.560 --> 42:26.200] They're the guilty until proven innocent 10-day denial of service attack. [42:26.660 --> 42:28.700] The backdoor takedowns, right? [42:28.820 --> 42:29.680] So going to the ISPs. [42:30.300 --> 42:40.940] The endless chain attack, which is, you know, where you're just constantly getting takedown notices and having to re-evaluate that content, ultimately I think will show that ISP liability has to go away in order for this type of censorship to stop. [42:41.980 --> 42:43.700] So I'm going to give you some rhetorical questions. [42:44.240 --> 42:45.400] What if we treat filing... [42:45.920 --> 42:46.440] I'm sorry. [42:46.540 --> 42:50.320] What if we treat the failings of DMCA as protocol failings? [42:50.480 --> 42:55.080] So the takedown provisions, what if we treat those as protocol vulnerabilities? [42:55.620 --> 42:59.320] And what if we treat lawmakers like software vendors? [43:00.100 --> 43:03.960] And what if proof of concept code could be used to highlight DMCA protocol flaws? [43:05.260 --> 43:13.140] So the responsible disclosure movement says basically a vendor releases a bug and a security researcher finds a theoretical vulnerability and informs the vendor. [43:14.000 --> 43:15.960] The vendor decides not to fix the bug. [43:17.920 --> 43:22.500] And so the researcher releases that in a white paper some way to the public. [43:23.220 --> 43:27.000] And then the vendor, you know, says publicly, oh, no, no, no, no, this is too theoretical. [43:27.180 --> 43:27.780] This will never happen. [43:27.900 --> 43:29.320] Like, nobody can actually pull this attack off. [43:29.500 --> 43:34.740] And so a researcher, maybe not the same one, decides to write proof of concept code for the exploit. [43:35.400 --> 43:39.820] And the vendor winds up hopefully fixing the bug. [43:40.680 --> 43:44.480] So the trick is, what if we treat the DMCA the same way? [43:44.840 --> 43:50.580] So let us imagine what happens if we have the same project DOD vs. Federici thing, except we amplify it. [43:52.620 --> 43:56.060] We're going to deposit an anonymous malicious actor named Mallory. [43:56.920 --> 44:11.260] And we're going to design or just use a bot network of nodes that can send well-crafted DMCA takedown notices and follow-up notices to multiple ISPs against multiple users. [44:11.840 --> 44:13.880] And again, this is all theoretical, right? [44:13.980 --> 44:17.240] We're just trying to highlight that there's a major protocol vulnerability here. [44:17.820 --> 44:32.440] And so what I want you to think of is kind of a web crawler that goes around and finds content on the Internet and then constructs these really well-crafted DMCA takedown notices and then fires them off in mass to these ISPs. [44:33.380 --> 44:36.280] And so there's a couple of requirements here. [44:36.440 --> 44:42.680] One is that Mallory, the person doing this, their identity has to be hidden in order to not suffer a 512F counter notice. [44:43.040 --> 44:46.820] The nodes that are sending cannot be tracked back to their controllers. [44:47.280 --> 44:50.360] That is, the things that are actually sending the nodes cannot be tracked back to Mallory. [44:50.900 --> 44:58.520] And the nodes themselves need to be exposed, otherwise there would be statistically interesting information that would show you where the... [44:59.220 --> 45:03.380] I'm sorry, would tell you that this stuff was coming, say, from a Tor network or something. [45:05.300 --> 45:08.600] So, abusive takedown notices should look a lot like legitimate notices. [45:09.180 --> 45:12.040] They can use random, legit-looking letterheads. [45:12.400 --> 45:14.720] You can get this stuff on like chillingeffects.org. [45:16.020 --> 45:22.400] You want to have some anonymous contact information, email address, say, prepaid phone number, or voip, something like that. [45:26.680 --> 45:37.900] And the notices should be sent not only to the first order ISP, which would be the ISP in the leaf node at any particular point, but all nth order ISPs. [45:38.160 --> 45:49.340] And this would happen whenever someone didn't respond to a notice or whenever the notice had been responded to and the content went back up, you'd want to escalate it up to the next ISP. [45:50.520 --> 45:58.140] And I also wanted to just point out that these things should be sent to search engines, too, because there's an interesting vulnerability in that. [45:58.900 --> 46:00.560] Search engines don't really have users, right? [46:00.660 --> 46:03.640] They crawl content, they find the stuff, they index it, and sometimes they cache it. [46:04.500 --> 46:07.520] And DMCA takedown notices can be filed to Google, for instance. [46:08.160 --> 46:10.700] And Google will actually remove that content from the index. [46:11.900 --> 46:15.040] But they don't have a user to inform so that a counter notice can be filed. [46:15.040 --> 46:21.660] So basically abusive attackers can remove content directly out of the index of search engines using that. [46:22.980 --> 46:24.820] So just really quick, this is how we would build it. [46:25.520 --> 46:28.260] So we're going to use something called Gearman, which is a distributed job processing framework. [46:28.460 --> 46:31.400] It has a bunch of clients, some job servers, and some workers. [46:33.000 --> 46:37.660] And over here at the client to job server interface and the worker to job server interface. [46:37.900 --> 46:39.160] This is not just going to work out of the box. [46:39.380 --> 46:41.420] It would have to be shimmed here to work with Tor. [46:42.520 --> 46:43.260] This is the stack. [46:43.460 --> 46:45.960] You have application code that can be written in C, PHP, whatever. [46:46.340 --> 46:48.580] It goes through a Gearman server, which is a queue. [46:48.580 --> 46:53.300] And then a worker listens for functions that are registered in there. [46:53.880 --> 46:56.120] And can process it also in a different language. [46:57.280 --> 46:58.880] And you can see the arrows here. [46:59.100 --> 46:59.440] This is where. [47:00.040 --> 47:03.400] So these locations, you'd have to sort of shim it into a Tor network. [47:03.660 --> 47:03.980] Okay, ready? [47:04.060 --> 47:05.140] Here comes another one of my cool graphs. [47:06.440 --> 47:06.880] Okay. [47:08.900 --> 47:11.260] So basically this is what it would look like. [47:11.400 --> 47:12.840] You have a takedown notice. [47:12.840 --> 47:15.160] You have onion network. [47:15.600 --> 47:17.020] You have a Gearman server. [47:17.680 --> 47:25.080] And then you have these two-way communications using hidden services through the Tor onion network to a set of zombie workers and some ISPs over here. [47:25.180 --> 47:26.760] And these zombie workers are exposed, right? [47:28.200 --> 47:32.760] So basically you see Mallory fires the takedown notice off. [47:32.920 --> 47:35.140] It lands on the Gearman job server. [47:35.540 --> 47:38.940] One of the workers comes by and says, oh, hey, I can take that job. [47:38.940 --> 47:45.520] And then the worker winds up firing this sort of abuse off at the ISPs. [47:46.100 --> 48:03.300] And because this is sort of a queuing system and you can move from state to state, you can essentially these workers over here, say if they file the first notice, they can then re-queue a job and just let it sit here and another worker will pick it up and you can move through the states of it whether or not you're escalating to an ISP... [48:03.300 --> 48:05.700] I'm sorry, whether or not you're escalating to an anth-order ISP or not. [48:06.420 --> 48:17.420] And the end result would be that service providers may actually decide they wanted to continue or to start following the counter-notice procedures since so many other users they just have to kick off their service. [48:18.040 --> 48:20.340] And again, remember, this is in mass, right? [48:20.500 --> 48:23.460] So this would be like spammers using this technique to just fire it off. [48:23.960 --> 48:26.680] But then there's still the 10-day denial of service attack. [48:28.900 --> 48:30.980] ISPs are probably not going to comply with that. [48:31.740 --> 48:34.820] And this abuse takes into account backdooring and chaining as well. [48:35.580 --> 48:44.420] So if the volume is great enough, ISPs may actually be forced to stop complying with takedown notices. [48:44.940 --> 48:52.940] That is, they can't make a good-faith attempt to comply with them, so they would actually have to stop. [48:53.200 --> 48:56.380] And ultimately, that would bring the law back into question. [48:56.380 --> 49:10.900] And I think that we could show, under an abuse like this, that no matter what, you'd have to rewrite the law to take out, I think in the very end, all of these particular statutes, which we'll talk about here, but also ISP liability. [49:11.220 --> 49:11.520] All right. [49:11.640 --> 49:14.660] Remove the 10-day denial of service attack. [49:14.840 --> 49:15.300] That's a problem. [49:15.440 --> 49:16.180] It takes a lot of time. [49:17.560 --> 49:30.020] Just shortly, this is... let me just say that without going through these slides, we don't have a lot of time, but if you're interested in making these changes, support chillingeffects.org, EFF, and our organization does this, Tor. [49:30.020 --> 49:38.060] But Chilling Effects is actually working to amend the DMCA, and one of the things that we're discussing in the amendments is you need to consider fair use. [49:38.180 --> 49:41.160] Before you send those takedown notices, if they're bogus and they just really... [49:41.160 --> 49:51.880] you're just doing it to slow down a competitor, to stop someone from releasing a bug that you want to do first, you should have some liability for that if you're just slamming the ISP up the stream as well. [49:52.080 --> 50:01.180] I think every time you go up the stream and it doesn't work, I think it should be like greater liability, because it's really adding a lot of time to the IT departments that don't want to handle this, especially with stuff that is just meant for, like, [50:01.340 --> 50:04.120] corporate strategic advantage being offensive using the law that way. [50:04.300 --> 50:06.200] This was not what the DMCA was intended to do. [50:07.020 --> 50:14.500] Yeah, so, you know what, we're close to the end, so what I'm going to do is actually just skip, you know, what would this future look like, what the future would look like, what it used to look like before the DMCA existed. [50:16.480 --> 50:17.560] It would look like the past. [50:18.580 --> 50:21.640] And so, you know, clearly, DMCA takedown provisions are flawed. [50:22.580 --> 50:25.560] There's a couple technical solutions that exist out there. [50:27.520 --> 50:30.680] And if anybody has questions, please feel free to ask. [50:30.860 --> 50:33.060] Also, notice the paper and slides are up online here. [50:33.260 --> 50:33.480] Okay. [50:33.640 --> 50:34.360] One question right there. [50:34.420 --> 50:34.960] Real quick. [50:35.540 --> 50:41.500] I just wanted to point out that ISPs do have the option under the DMCA not to remove. [50:41.660 --> 50:42.700] They'll incur liability. [50:43.000 --> 50:43.320] Of course. [50:43.320 --> 50:46.140] The DMCA doesn't actually require the removal. [50:46.420 --> 50:58.800] And some ISPs, including Google, actually do analysis of the takedown notices and don't necessarily remove automatically and will do fair use review and things like that. [50:58.900 --> 50:59.080] Right. [50:59.480 --> 51:00.620] So, it's still... [51:00.620 --> 51:02.700] Google actually does a decent job. [51:03.000 --> 51:03.200] Yeah. [51:03.360 --> 51:05.140] Other ISPs don't do as well. [51:05.420 --> 51:08.620] And we've also made that decision, too, to waive our safe harbor in certain cases. [51:10.700 --> 51:11.260] Thanks. [51:11.560 --> 51:11.780] Thanks. [51:13.000 --> 51:18.520] Are you supposed to swear under penalty of perjury when you file a DMCA takedown notice? [51:19.000 --> 51:20.840] So, isn't this just distributed perjury? [51:21.780 --> 51:24.180] Well, so that was the trick, right? [51:24.320 --> 51:25.740] Mallory's identity can't be found. [51:26.040 --> 51:28.780] So, it's distributed perjury, but who's Mallory, right? [51:29.200 --> 51:29.480] Okay. [51:29.640 --> 51:30.220] I'm just curious. [51:30.220 --> 51:30.320] Yeah. [51:30.380 --> 51:30.480] No. [51:30.580 --> 51:30.680] Yeah. [51:30.700 --> 51:31.040] Absolutely. [51:31.160 --> 51:31.260] Yes. [51:31.460 --> 51:32.240] So, swear. [51:33.000 --> 51:38.500] We swear under penalty of perjury, but the requests can't be tracked back to the person sending them. [51:39.900 --> 51:46.000] With the system that you guys were showing there, not the one through the denial of service, but the one where you have the servers all over the world. [51:46.380 --> 51:46.980] Oh, sure. [51:47.580 --> 51:50.640] Is the DNS updated dynamically? [51:51.080 --> 51:53.360] And does that bring any liability in effect? [51:53.560 --> 52:02.500] So, for example, the same way that 2600 got in trouble for DVD John's code, you know, what if you say, oh, we can't have this in the US, fine, we're going to put in Sweden, haha, F you, right? [52:03.120 --> 52:06.260] But now you're redirecting to Sweden, does that make you liable? [52:06.380 --> 52:09.320] Because you're saying, hey, the stuff's over here that you told us to take down. [52:09.440 --> 52:13.780] So, really quick, what we've done is we've shimmed it into the Tor onion routers, right? [52:13.980 --> 52:17.140] So, essentially, I mean, this is just a proposal, right? [52:17.220 --> 52:20.840] There are bot networks right now that are nearly impossible to figure out. [52:20.840 --> 52:24.420] But I was just saying that you could do this anonymously this way. [52:25.160 --> 52:29.200] And so, DNS actually can't be leveraged to find the identity of the hosting provider. [52:29.360 --> 52:31.800] That's what the hidden service protocol does, is obscure that identity. [52:31.920 --> 52:35.380] I meant the one where you're hosting a different place, not the one where you're attending. [52:35.580 --> 52:37.360] Oh, the one where I'm hosting different places? [52:37.480 --> 52:38.220] Oh, yes, yes, yes. [52:38.380 --> 52:39.920] So, this is just, this is what I said. [52:40.040 --> 52:41.580] This is a sort of stopgap solution. [52:41.900 --> 52:45.480] Sorry, I didn't actually get the point of the question there. [52:45.620 --> 52:49.700] Okay, so, yes, I guess they could, they can find your DNS. [52:49.700 --> 52:51.180] Maybe they can shut your DNS down. [52:51.320 --> 52:57.240] And this is why Tor is necessary in certain cases, is that DNS can be shut down. [52:57.460 --> 52:58.220] Yeah, you're right. [52:59.440 --> 53:02.100] You had a slide titled, Responsible Disclosure. [53:02.200 --> 53:03.000] Can you go back to that quickly? [53:03.360 --> 53:03.940] Oh, sure. [53:05.360 --> 53:09.520] I'd just like to point out that your step seven is wrong. [53:10.040 --> 53:15.300] Step seven is actually where the vendor sends a DMCA takedown notice to the researcher and takes his DEFCON talk down. [53:17.500 --> 53:19.580] Yes, that's very true, right? [53:19.580 --> 53:22.280] So, then the DMCA is used to silence that. [53:22.440 --> 53:37.480] Yeah, my question is, have you guys looked at using defamation and libel strategies against the authors or the agents for the takedown notices and possibly pursuing unfair business practices since there's a lot of this is commercial speech as opposed to free speech per se? [53:38.240 --> 53:39.600] I mean, I haven't. [53:39.600 --> 53:40.940] Yeah, we actually are. [53:41.320 --> 53:45.880] The libel we're considering is maybe even the group of attorneys that have had some issues with this. [53:46.060 --> 53:48.720] But libel is difficult. [53:49.000 --> 53:55.600] It can be difficult to prove, especially that someone maliciously went out to, you know, just to say things that they knew were untrue about someone. [53:55.600 --> 54:03.040] And actually, Dr. Federici has first, before he did found the DMCA at takedown notices, be able to get what he wants out of that. [54:03.240 --> 54:05.280] He did file multiple, many libel suits. [54:05.600 --> 54:06.760] They were not successful. [54:07.040 --> 54:09.200] So, that's why he switched the DMCA at takedown notice. [54:09.480 --> 54:09.940] Okay. [54:10.080 --> 54:13.340] And is this being applied for academic research currently right now? [54:13.340 --> 54:19.960] Because there is a longer tradition, more well-established for fair use in that. [54:20.260 --> 54:21.200] It is. [54:21.340 --> 54:26.840] And as a university professor, I can tell you from personal experience that fair use is dying. [54:27.020 --> 54:30.180] And even in academia, we're having a really difficult time with that. [54:30.280 --> 54:31.600] And I looked at, like, Ed Felton's work. [54:31.660 --> 54:37.680] I teach about that, what happened with him breaking some encryption, and discussing that, how he broke the encryption. [54:37.680 --> 54:40.000] That's a part of the DMCA that's the anti-circumvention measures. [54:40.000 --> 54:45.400] But talking about it, being able to talk about your research and teach your students to, you know, to do things better. [54:45.400 --> 54:47.200] This is where fair use is dying. [54:47.520 --> 54:49.200] And being able to discuss your research, it's hard. [54:49.620 --> 54:50.140] Thank you. [54:50.400 --> 54:51.360] So, it's 1.56. [54:51.580 --> 54:52.960] It doesn't look like there's any more questions. [54:53.180 --> 54:55.460] So, thanks everybody for giving us your time. [54:56.220 --> 54:56.460] Thank you.