FCC Set-Top Box Proposal Is About Copyright

Let’s clear one thing up right off the bat. Consumers are not entitled to high-quality TV programming.  It’s a business. If that business doesn’t make sense, the shows won’t be produced.

I know that seems obvious, but as with so many arguments made by technology companies seeking to hijack the distribution of works for themselves, this latest one  seems to proceed from a typical assumption that the “content” will just be there no matter what.  As I said in an earlier post on this same subject, if the producers and distributors are correct in their criticisms, the FCC set-top box proposal could provide consumers with new methods of acquiring a lot less content over time.

In a nutshell, the TV programming we enjoy is made available because the producers (copyright owners) enter into licensing agreements with distributors, referred to as Multichannel Video Programming Distribution (MVPDs). Generically we tend to call MVPDs “cable providers,” but MVPDs include satellite and various other ways to receive television programming that has been licensed from the copyright owners.  These licenses sit on top of a network of other licenses between the producers and their suppliers, advertisers, etc. For instance, the actors on a show not only receive fees for their performances but also have residuals and health & pension plans paid through SAG from those licensing fees that are paid by the MVPDs.

Not to say it’s complex, but Register of Copyrights Maria Pallante, in her 17-page August 3rd letter to the FCC, referred to “a constellation of arrangements between MVPDs and program producers.”  Pallante further states …

“… the copyrighted works that make up an MVPD’s multichannel video programming are produced and made available to the public only as a result of complex, private negotiations between content owners and MVPDs, and on the understanding that the MVPDs will make works available to the public in accordance with the terms of the resulting licenses. Typically, a violation of the license terms will constitute either copyright infringement or breach of contract.”

What the FCC says it wants to do is to unchain consumers from the dreaded box — that thing we rent from the cable companies to unscramble the channels, and which symbolizes whatever frustrations we might feel with the service, the pricing, or the lack of competition in the pay TV market.  I feel these frustrations myself, so on the surface, Chairman Wheeler’s proposal to give me options to watch TV more flexibly—through tablets, smart TVs, and other products sounds appealing.  But there’s a bug.

The proposal would mandate that the MVPDs make their programming and data available to third-party manufacturers of devices (surprise, Google is one of these), who would not pay license fees but would be free to distribute, brand, and monetize with advertising as they see fit.  The producers and the MVPDs have argued that this circumvents the aforementioned network of complex and costly licensing; and some producing interests have also raised the concern that because these third-parties operate on web platforms, a more seamless integration between legal and illegal viewing may exacerbate the adverse effects of piracy on the market.

The Electronic Frontier Foundation asserts that none of the criticisms of the FCC proposal made by producers and MVPDs implicate copyright law at all.  Mitch Stoltz of the EFF this week argued that the proposal is exclusively about allowing new technology products to come to market and to provide consumers with new choices.  Interestingly, despite his insistence that the proposal has nothing to do with copyright, Stoltz—and Cory Doctorow in a companion EFF post—refers to one of the most important copyright cases to support this position.

Sony v Universal (aka the Betamax case) is the reason consumers may use recording devices for “time-shifting” TV programs for their personal use; and these proponents of the FCC proposal appear to be arguing that Sony provides the only precedent needed to reject any further consideration of copyright in this matter.  Stoltz writes …

“Copyright gives rightsholders power to control copying, but not technology design. In fact, that sort of control is the antithesis of copyright’s purpose. Over thirty years ago, in Sony v. Universal, the Supreme Court refused to allow movie studios to “extend [their] monopoly” into “control over an article of commerce”—the videocassette recorder—“that is not the subject of copyright protection.” Today, you can search all 280 pages of the Copyright Act, and you won’t find anything that says a copyright holder has the power to control search functionality, or channel placement, or to decide who can build a DVR or video app.”

But here’s what Register Pallante says about Sony in her letter to the FCC:

“Sony itself focused on the distribution of an article of commerce where the seller had no ongoing relationship with the purchaser after the sale, and no connection to the content being exploited.  Nor did the Court address fair use where the device distributor was itself engaged in copying activities, as opposed to private home users. Both of these factors could conceivably be present with respect to devices and services under the Proposed Rule.  Nor have courts gone so far as to obligate rights holders to provide content in a manner that would facilitate time-shifting or other non-infringing uses.” 

So, maybe the FCC proposal has a little to do with copyright.  And that word obligate is an important one, referring back to my opening note that there is no right to TV programming.  Its production has to make sense as a business, and that only works because of copyright.

A rights holder of any work has the discretion to make decisions about the manner in which that work is distributed.  This is in fact fundamental to copyright’s purpose.  If you write an autobiographical novel about a serious subject, for instance, not even your publisher may blithely repackage it with a steamy romance cover (unless you sign those rights away) because they think it will sell better.  But that’s basically what the third-party manufacturers want to do.  They want the federal government to compel MVPDs to deliver programming and data to them, for which they will not pay a license fee but will be allowed to distribute, package, and advertise against the works in any way they see fit.

The implications of that business model go well beyond the scope of mere gadget-making, clearly falling into the purview of copyright law.  Kevin Madigan on Mister Copyright summarizes the distinction between the device and the model thus:

“The difference with the current navigation device manufacturers is that they will receive copyrighted TV programs to which they’ll have unbridled liberty to repackage and control before sending them to the in-home navigation device. The third-party device manufacturers will not only be able to tamper with the channel placement designed to protect viewer experience and brand value, they will also be able to insert their own advertising into the delivery of the content, reducing pay-tv ad revenue and the value of the license agreements that copyright owners negotiate with pay-TV providers.”

That’s not what VCR’s (and now DVRs) do, and I’d be surprised if any court had much patience for a party relying heavily on Sony to support the FCC proposals. Additionally, as reported, the EFF recently took the bold step of suing the federal government on the grounds that Section 1201 of the DMCA is unconstitutional. Perhaps their assertion that the FCC proposal has “nothing to do with copyright” presumes that they have already won this argument because Register Pallante recognizes a “tension” between the FCC proposal and the 1201 anti-circumvention measures in the DMCA ….

“The Proposed Rule would inhibit the ability of MVPDs and content programmers to develop, improve, and customize technological solutions to protect their content in the digital marketplace.  It would do so in part by requiring MVPDs to give third-party actors access to copyrighted video content and associated data according to one or more security standards prescribed by an outside organization rather than through their preferred (and potentially more secure) protocols negotiated between copyright owners and the MVPDs. In addition, the Proposed Rule suggests that the FCC might allow third parties to self-certify their compliance with whatever security standards are adopted.  The Proposed Rule would thus undermine content creators’ ability to choose how best to protect their content in the marketplace, as Congress intended in enacting DMCA.”

Between Stoltz’s latest editorial and the recent suit over 1201, it seems the EFF is increasingly uninterested in working with copyright law and is focused on efforts either to abolish it or simply pretend it doesn’t exist.  This post is not meant to suggest that I can endorse every business practice of every MVPD, but the EFF’s assertion that these parties are “cloaking” anti-competitive practices in false claims about copyright is misleading.  Moreover, it should be abundantly clear by now that if the name Google is on the list of providers seeking a new regime from a federal agency, then customer choice and free-market competition are likely not at the forefront of that effort.

EFF says Section 1201 of the DMCA is Unconstitutional?

Last week, the Electronic Frontier Foundation filed suit against the federal government, naming the DOJ and the Copyright Office as defendants.  The EFF filed on behalf of plaintiffs Dr. Mitchell Green, a computer scientist and researcher at Johns Hopkins; Andrew Huang, an engineer and inventor; and Huang’s company Alphamax LLC.  The crux of the suit argues that Section 1201 of the DMCA, which prohibits circumventing technical protection measures (TPM), or trafficking in devices used for circumventing these measures that are designed to protect copyrighted works violates the First Amendment and is, therefore, unconstitutional.

The most common type of TPM consumers tend to be aware of are applications like the software on a DVD that prevents or mitigates illegal copying of the contents; but TPM are increasingly used in a broad range of devices and products because, of course, computers and software increasingly run everything we touch. For this reason, 1201 applies to a wide range of classes of copyrightable works, including software itself, and so the debate over the law invariably conflates movies and medical devices or cellphones and tractors, which means the public dialogue can be rather confusing for most of us.

We read a brief assertion in an article by Cory Doctorow—or even an opposing view—and the nitty-gritty may be ten pages of complex analysis by the Copyright Office that few people will read let alone fully understand.  Meanwhile, consumers should keep in mind that absent the provisions in 1201, products like DVDs, iPods, and Kindles would simply not exist because rights holders would not have licensed their works for distribution on these platforms. And it is characteristic of the EFF and its colleagues to focus on the restrictive aspects of a legal framework while ignoring the productive ones.

In simple terms, it is illegal to circumvent TPM, whether the copyrighted material being protected is entertainment media like an eBook or it’s the software that runs a medical device or the systems in your car. The EFF’s criticism weighs heavily on the fact that it is a violation of 1201 to circumvent TPM even if the intent is not to infringe copyright, but there are also permanent and termporary exemptions in force, recommended by the Register of Copyrights, that allow for circumvention in a number of circumstances. Every three years, the Copyright Office reviews applications for exemptions, though this process itself has been called “onerous” by the EFF and others and is likewise implicated in the question of constitutionality of the 1201 statute.

As mentioned, there are three named plaintiffs in this suit, though one can think of Andrew Huang and his company Alphamax as representing the same interests.  But in an effort to keep this post under 2,000 words, I’ll focus on the complaint regarding Dr. Green and EFF’s broad complaint that the Copyright Office triennial review process is itself stifling free speech.

That Dr. Matthew Green’s Security Research is Being Stifled

Likely, the most compelling and easiest to understand complainant is that of Dr. Green, who conducts important research into, among other things, the security systems of automobiles. This was the focus of his application for an exemption to 1201 during the last triennial session.

Dr. Green explains on his blog that because the Copyright Office failed to grant the exemptions he applied for, that a project underway in the Fall of 2015 had to be conducted in a manner less efficacious and less thorough than the best method available. He also implies that the opposition to his application from the Business Software Association might have carried undue, industry weight in the decision-making process.  But a review of the Register of Copyright’s analysis and conclusions regarding the relevant class of exemptions reveals that the Copyright Office was substantially more sympathetic to the testimony of Dr. Green and his co-applicants than it was to the opposition arguments of either the software or automotive industries.

In fact, the Copyright Office, in its Final Rule issued on October 28, 2015, recommended a broad exemption for “good faith” research like the work being conducted by Dr. Green, but it also recommended a 12-month waiting period to implement this exemption.  Although this delay may be a source of frustration for researchers and the EFF, it was not proposed due to industry opposition to the exemptions. Instead, the Copyright Office recommended the one-year delay in deference to various federal agencies that had weighed in with concerns regarding some of the proposed exemptions.

For instance, the EPA stated that certain aspects of the work to be conducted could “slow or reverse gains made under the Clean Air Act.”  How?  I have no idea.  But neither does the Copyright Office because they’re not authorized to have an opinion about the environment. So because some of the concerns raised are outside copyright’s purview, the Register proposed  the delay in order to give other federal agencies time to review. That’s what they’re supposed to do, and neither Dr. Green nor the EFF appear to acknowledge that there is an extent to which this research is being slowed by federal agencies which have nothing to do with copyright or Section 1201.

Moreover, the timing of EFF’s big play to argue the unconstitutionality of the entire law is odd in light of the fact that the Copyright Office is largely in agreement with applicants like Dr. Green. In fact, the Copyright Office could not have been more clear in its agreement that the current permanent exemptions for security research are not sufficient to protect Dr. Green and his colleagues from liability.  But when the office called for recommendations to 1201 in the beginning of this year, neither the EFF nor any of its sister organizations filed comments with a view toward amending these permanent exemptions.

So, one question worth asking is why the EFF does not use its considerable resources to seek amendment(s) to the permanent exemptions rather than work toward the less likely outcome that the entire statute will be declared unconstitutional?  After all, as a practical matter, if the real interest is enabling people like Dr. Green to work at his best as soon as possible, fixing the permanent exemptions is a far more practical enterprise than the prospect of having the Supreme Court vitiating all of 1201 several years from now. This seems especially true when the Register already agrees that the current statutes are inadequate.

That the Triennial Review Process is Stifling Speech

Roughly one-third of the EFF’s complaint focuses on the alleged inadequacy of the triennial review process itself. Their contention is that the process is so cumbersome and slow that it fails to fulfill its purpose to provide an adequate counter-balance to 1201’s restrictions and also constitutes a prior restraint on speech by delaying applicants’ ability to engage in otherwise legal, non-infringing research or publication.

Two things seem odd about this section of the complaint.  The first is that it focuses on 1201’s alleged, broad infringement of the speech of filmmakers* and teachers despite the fact that the named plaintiffs in the lawsuit applied for exemptions having nothing to do with filmmaking or teaching.  The second is that the Copyright Office actually did recommend exemptions for a large number of requests pertaining to filmmakers and teachers, though, apparently these did not go far enough for the EFF, which scorns rejections—like an exemption for “narrative filmmakers”—as evidence that 1201 is stifling speech.  Of course, considering this particular class of filmmaker begs detailed analysis because the majority of narrative film uses are not generally fair uses. So, this part of the complaint begins to sound like EFF may be making its usual free speech mountain out of a copyright molehill.

Also, with regard to the alleged onerousness of the review process, the public should note that the process is a rather large task resulting in decisions that have far-reaching implications throughout the market.  Exemptions apply to everyone, not just the applicants.  So, when the CO said that it’s cool for a K-12 teacher to “rip” film clips from his DVD collection to bring into class to teach film or cultural studies, that circumvention is now kosher for all teachers doing the same thing across the country. So, because these rulings are not narrow decisions (like fair use judgments), it seems reasonable that reviews happen triennially and that applicants bear some substantial burden to argue their cases for various exemptions.  The CO’s complete review of the last round of applications is over 400 pages long.  How frequently should the agency engage in that level of detailed analysis and make recommendations that have considerable effect in the market, and which must conform to existing laws beyond the scope of copyright?

And once again, the timing of this complaint is curious because the Register earlier this year recommended that, going forward, all successful petitions not opposed in the next review cycle need not be re-litigated.  This is relevant because the EFF specifically cites the need to re-apply for exemptions every three years as evidence of undue burden, but it ignores the fact that the Copyright Office acknowledges the issue and is making recommendations to mitigate the problem.  So, the big question reprises:  Why is EFF more eager to try to strike down the entire law than it is to work with the Copyright Office to address some of the very flaws the Register agrees exist?

Based on just the complexities I have tried to articulate here—and which only scratch the surface—it seems unlikely the First Amendment complaint will make as much progress as it will make noise. Yes, we want to protect fair use for expression and the ability of researchers to ensure our safety and security while living with our computerized products. But the record indicates that the Copyright Office is in synch with these views.  We’ll see what the courts say.

DCA’s New Report on Enabling Malware

Enabling Malware

Andrew Orlowski reports at The Register that last week Google quietly suspended its legal action to “muzzle” an investigation by Mississippi Attorney General Hood into whether or not the search giant was abiding by the terms of its 2012, non-prosecutorial settlement with the government over illegal online sales of prescription drugs.  Any explanation of Google’s change in strategy or the future of that investigation are subjects for another day.  But the fact that AG Hood was ultimately not stymied—either by litigation or by a brazen attempt in the State House of Representatives to legislatively tie his hands—is probably good news for American consumers because State Attorneys General “often act as the de facto consumer protection arm in their respective states,” notes a new report published yesterday by Digital Citizens Alliance.

Following up on its December report, which presented a look into the scope of the malware hazard for consumers who visit content-theft sites, DCA and RiskIQ have again collaborated to begin looking at the hosting services that either inadvertently or knowingly support illegal sites, which then endanger consumers.  The hosting services in this regard are particularly relevant because they are not shadowy operators based in hard-to-reach geographies but are legal corporations with offices in the United States.  As such, the news that Google will now look to “cooperate with AG Hood” rather than remain on the offensive comes at a good moment for consumers.  This is because DCA notes that state AGs will be the first authorities who may choose to investigate US-operating hosting services to determine their role in fostering the dissemination of malware.

The December report called Digital Bait revealed the likelihood (about 30% in some cases) that users of content theft sites would infect their devices with malware, and the report also identified the various types of malware being deployed in order to steal information and/or assets from consumers.  Digital Bait also presented a glimpse into the dark web-based economy where criminals engage in transactions like selling the IP addresses of a girl’s computer or even a cybercriminal paying content-theft site owners to deliberately host malware on their sites.  The report contains some eye-opening statistics like the one from the DOJ, which states that 16.2 million American consumers have been victims of identity theft, incurring financial losses of more than $24.7 billion.

The report released yesterday, Enabling Malware, looks at two hosting companies, each of which responded very differently when DCA contacted them with their findings.  The first was CloudFlare, which is “known for its willingness to support, or at least overlook, illicit activities,” the report states.  CloudFlare is a hosting service that is specifically designed to mask the identity of site owners and of the true hosting site of any content, whether the content is legal or not.  The site’s blog reads, “Signing up for CloudFlare is like taking your number out of the phone book, and putting in CloudFlare’s number under your name.”

This type of service can be (and is) used by journalists or bloggers operating in locations with authoritarian governments or other hazards to free speech and reportage.  But it is also a natural hosting choice for content-theft site owners, thus earning the service the nickname “CrimeFlare” among cyber-security experts. DCA contacted CloudFlare with regard to its hosting sites like Putlocker and Animex, both of which were identified in the Digital Bait report as delivering malware to users.  CloudFlare did not respond until a day or two before the release of this new report and wrote the following:

“CloudFlare’s service protects and accelerates websites and applications. Because CloudFlare is not a host, we cannot control or remove customer content from the Internet. CloudFlare leaves the removal of online content to law enforcement agencies and complies with any legal requests made by the authorities. If we believe that one of our customers’ websites is distributing malware, CloudFlare will post an interstitial page that warns site visitors and asks them if they would like to proceed despite the warning. This practice follows established industry norms.”

In other words, CloudFlare is not going to do anything unless authorities make them.

The other hosting service DCA and RiskIQ looked at was HawkHost, whose support includes watchfreemoviesonline.top, which was found to have a 32% malware exposure rate in the research conducted for the Digital Bait report. When DCA contacted HawkHost, the company’s response was very different from CloudFlare’s, stating that the sites identified by DCA would be taken down because they “clearly violate our TOS/AUP,” according to CTO Cody Robertson. Additionally, executives at HawkHost have agreed to meet with DCA to discuss findings linking malware with content theft sites and to look for ways to better protect consumers.  DCA commends HawkHost, stating that they find the company’s response “an encouraging sign.”

DCA and RiskIQ will continue to study the link between content-theft sites and malware, as well as the legal hosting services that operate in the United States, which may be supporting malware-infested sites. These findings will be presented to State Attorneys General, who then have the authority to investigate the extent to which a particular hosting service may or may not be willfully turning a blind eye to illegal enterprise that is directly harming American consumers.  So, as mentioned, beyond any implications regarding the Google investigation itself, last week’s affirmation of AG Hood’s authority in that case is likely a good sign for protecting consumers in general from the chronic I-Didn’t-Know-Defense too-often employed by various OSPs.