DMCA - comply cannot be ignored


* the headline plays up the phrase “You can’t be pardoned”

If you post any media content on your servers, you must have come across DMCA complaints (colloquially “abuses”). DMCA is such an American law that is referred to by copyright holders demanding to remove content, block or give away a domain name, not to use logos, trademarks, etc.
If the law is valid only in the USA, is it necessary to fulfill these requirements while in Russia or can it be ignored? Often, hosting providers force their customers to comply with the requirements of copyright holders, even if there is no DMCA in their jurisdiction.

In the article we will analyze what DMCA is, in which cases it must be observed, and when you can not pay attention. Tell how vdsinacomes with such complaints. And also: how automatic complaint generators work, and how to monitor intruders on your server if you have to comply with the DMCA.

What is DMCA?


The Digital Millenium Copyright Act is a law that enforces copyright in the digital age. He was received in 1998 in the United States, and he acts, respectively, only in American jurisdiction.

The DMCA consists of two parts: the first, “protection against circumvention,” establishes the responsibility for circumventing encryption, and the second, “tracking and notification,” allows you to quickly remove copyright-infringing content from the network, without having to spend time and money on trials with the violator. If an illegal copy of a movie, album, game, or any other copyright object is found on the site, the copyright holder sends an authorized representative of the Takedown Notice service provider in which he sets forth his claims and, inter alia, confirms the sincerity of his intentions or “good faith belief” in that the content was maliciously “spiral”. Having received such a notification, the service provider either deletes the content while maintaining the backup copy or hides it from the search results.


Model webcams add the DMCA Protected logo on their broadcasts to make it easier to delete recordings from pirated sites.

But this often does not end the story, because the owner of the deleted content has the right to file a counter notification disputing the violation of the AP! This time, the poor service provider is forced to recover deleted files within 10 days, stock up on popcorn and wait for the conflicting parties to go to court or rest on their laurels.
DMCA is mandatory for all hosting providers in the USA, and often causes them a lot of headache, because in reality requests can arrive in hundreds every day, and all of them must be satisfied, even the most absurd. However, the service provider is relieved of responsibility for the contents of the pirated file or link, its task is only to ensure that the content is removed by takedown notice and report the fact of the request to the author.

Automatic complaints


Usually, copyright holders hire special companies that deal with the removal of their content on the Internet. A typical case is fresh film premieres: while the film is being shown in a movie theater, robots are scouring the Internet for “screens” and leaked copies of the film. In this period, copyright holders are particularly aggressive.

IP Echelon is the best known company for tracking and removing pirated content. Her services are used by Hollywood studios like Warner Brothers, Paramount and others.

IP Echelon has many tools for automatically searching for pirated content, including among distributing torrents. They download the pirate distribution themselves and collect the identifiers of all the seeds through the torrent tracker, after which they begin to methodically send them complaints demanding to remove the illegal distribution.


The copyright owner’s bot collects the IP addresses of all users downloading the torrent.

Here's what a typical automatic complaint about the distribution of a movie looks like, sent to the box of the abuse@owner of the IP address range from which the torrent was downloaded. (Your home provider in Russia receives such complaints in the thousands).
We are writing this message on behalf of Warner Bros. Entertainment Inc


We have received information that an individual has utilized the below-referenced IP address at the noted date and time to offer downloads of copyrighted material.



()



IP-Echelon
Email: p2p@copyright.ip-echelon.com
Address: 7083 Hollywood Blvd., Los Angeles, CA 90028, United States

— — Infringement Details — Title: Justice League
Timestamp: 2020-02-17T10:58:04Z
IP Address: xx.xx.xx.xx
Port: 61832
Type: BitTorrent
Torrent Hash: 8d12117f9ee5f259cbcc3afeb7238f46e228bfcf
Filename: Justice.League.2017.AMZN.WEB-DL.1080p.ExKinoRay.mkv
Filesize: 10573 MB
— —
This letter contains the name of the file and the distribution hash, to which there are complaints, the IP address and port of the client, as well as the exact time at which this sider was noticed. Based on this data, the provider can calculate the client and redirect the complaint to him, even if the client is behind the NAT th. This is done in some European countries.

Finding DMCA Intruders on a VPN Server


Automatic complaints from IP Echelon can be a big problem when renting servers in the USA.

A real case from practice: a VPN server for access to corporate resources. Employees connect to it from personal home computers, while the VPN server is also used to access the Internet, that is, it routes all traffic.

Corporate rules strictly prohibit downloading pirated content through a working VPN. But stably once a month, someone forgets to turn off the torrent client before connecting to the VPN, and as a result, the hoster receives a DMCA abus, which he immediately needs to be satisfied.
At the same time, there is no pirated content on the server itself; it is located on the employee’s personal home computer. As a result, I had to send notifications with the request to turn off the torrent client to all VPN users.

There was a task to accurately identify the user who distributes pirated content. Since the IP Echelon complaints contain the exact time and port number from which the torrent client was connected, we can log all VPN client connections with a time reference and find the intruder using these logs.

Added iptables rule:

iptables -t NAT -A POSTROUTING -s 10.0.0.0/24 -o eth0 -m conntrack --ctstate NEW -j LOG

Where 10.0.0.0/24 is the internal range of IP addresses of VPN clients.

Such a rule will save all created NAT translations to the system log, that is, external connections of our VPN clients with reference to the internal IP address.

This is what the kernel log entries look like:

kernel: IN= OUT=enp0s4 SRC=10.0.0.3 DST=1.1.1.1 LEN=61 TOS=0x00 PREC=0x00 TTL=64 ID=26834 PROTO=UDP SPT=10821 DPT=53 LEN=41
kernel: IN= OUT=enp0s4 SRC=10.0.0.3 DST=140.82.114.26 LEN=64 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=64837 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0

It can be seen that the VPN client with the internal address 10.0.0.3completed one DNS query and connected to HTTPS (port 443) to the address 140.82.114.26. Now, having received the abus, we can find the exact address of the intruder by the exact time and notify him only.

Should I obey the DMCA


DMCA does not apply to countries outside the United States. In the rest of the world, intellectual property claims are governed by local law or WIPO (World Intellectual Property Organization). The latter is more often involved in disputes regarding the removal of entire domain names from their owners than the removal of contentious content.

Therefore, if your company and hosting provider is not located in the United States, you are not required to comply with the DMCA .

However, some domestic hosters require their customers to respond to such complaints, and sometimes even block the client when they receive a second complaint. This behavior can be risky for customers, because anyone can send a complaint and paralyze the client.

Our company position:
VDSina.ru is a Russian company and operates in accordance with the legislation of the Russian Federation. When considering complaints, foreign legislation, including DMCA, does not apply, regardless of the location of the server. In support of their requirements, you can only refer to the legislation of the Russian Federation.

Oleg Sorokin, General Director of Hosting Technologies LLC
Tell us if you are faced with DMCA complaints and how you resolve this issue.


All Articles