My life as a criminal cookie clearer: Register vulture writes Chrome extension, realizes it probably breaks US law
- Reference: 1595333706
- News link: https://www.theregister.co.uk/2020/07/21/cookie_clearing_chrome_extension_dmca/
- Source link:
It's not a great loss to the world. The extension, which I called Bloom Broom, is about as basic as can be. I wrote it after completing the Chrome Extension Get Started Tutorial to see if I could complete a project of my own.
Specifically, I decided to create code that cleared the data stored in my Chrome browser by an unnamed website I'll call example.com, even though you can probably guess what the site might be from the extension's name. I wanted to see if I could bypass the website's soft paywall, which limits non-subscribers to reading only a few articles a month.
Unlike a hard paywall that grants access only to subscribers who have created an account, soft or metered paywalls provide visitors with limited access to content through gating mechanisms like browser cookies or storing values in browser-based databases.
This is phenomenally ineffective, not to mention annoying and non-consensual. Technically inclined individuals have got around soft paywalls for years by clearing particular cookies and browser data. Browser makers provide tools to do this manually and there are plenty of browser extensions that do so, often in the name of privacy or security.
Chrome provides an API for browser data manipulation, [1]chrome.browsingData . I had initially thought I could just call this API from a content script, one of several possible components in a Chrome extension that can be set to run when a specific website is visited.
But it turns out chrome.browsingData isn't accessible from a content script, so after googling about, I understood I would need to load the content script when visiting the target website and have the content script send a message to a background script, another possible Chrome extension component, to invoke the chrome.browsingData API there.
So I declared the appropriate permissions in the manifest.json file: ...
"permissions": ["*://*.example.com/*", "browsingData", "storage"],
"background": {
"scripts": ["background.js"],
"persistent": false
},
"content_scripts": [
{
"matches": ["*://*.example.com/*"],
"js": ["contentScript.js"]
}
],
...
And then wrote the code for contentScript.js ... chrome.runtime.sendMessage({ text: "Clear" }, function (response) {
console.log("Response: ", response);
});
..and background.js … function callback() {
console.log("Bloom Broom execution complete.");
}
chrome.runtime.onMessage.addListener(function (msg, sender, sendResponse) {
if (msg.text === "Clear") {
chrome.browsingData.remove(
{
origins: ["https://www.example.com"],
},
{
cacheStorage: true,
cookies: true,
fileSystems: true,
indexedDB: true,
localStorage: true,
pluginData: true,
serviceWorkers: true,
webSQL: true,
},
callback
);
}
sendResponse("BrowsingData cleared.");
});
The console.log statements (which print output to the browser console) aren't necessary but I wanted to make sure the extension worked as anticipated. And it did. I could visit the site I'm calling example.com as many times as I liked and its article limit would never kick in because the server found no evidence of my previous visits in my browser's storage system.
But I decided not to publish my extension because doing so explicitly to bypass a technical protection mechanism like a paywall is at least theoretically actionable under the law.
The digital arm of the law
Attorney Theresa Troupson, an associate in the Intellectual Property and Litigation & Trial practice groups at Russ August & Kabat in Los Angeles, said as much in a 2015 New York University Law Review article titled, "Yes, it's illegal to cheat a paywall: Access rights and the DMCA's anticircumvention provision."
[2]PDF
And she maintained that's a possibility in a phone interview with The Register .
"I do think, as I argue in the law review note, it's basically legally actionable under the DMCA because the DMCA is written in such a way that it could potentially implicate people for clearing cookies," she said.
The reason for this, Troupson argued, is that the DMCA's language is so overly broad that any means of accessing paywalled content without authorization falls within the statute's scope.
"Deleting cookies, using ad-blocking software, or other routes past the paywall could be said to 'deactivate' or 'impair' the paywall protecting the online news article," the article says.
Not everyone necessarily agrees with this interpretation of the law and it's unlikely that publishing a paywall bypass extension or simply deleting cookies would result in a lawsuit, unless a large amount of money were at stake.
Chrome extensions are 'the new rootkit' say researchers linking surveillance campaign to Israeli registrar Galcomm [3]READ MORE
Troupson said she's not aware of any paywall circumvention cases related to browser storage deletion. But in 2018 Mozilla did find enough cause for legal concern to remove a Firefox extension called Bypass Paywalls from its Add-Ons Store for alleged Terms of Service violations.
Whatever legal risk there is, it's not excessive, given that the Bypass Paywalls code has since been updated to work on Chrome and can be downloaded from GitHub. Also, the Mozilla Add-On Store nonetheless currently includes paywall busting extensions, as does the Chrome Web Store.
Troupson suggests stating that a particular bit of code was created specifically to bypass a paywall would increase the risk because intent matters.
But claiming cookie cleaning was carried out due to privacy or security concerns doesn't guarantee immunity under the DMCA. As Troupson's article notes, the DMCA's anti-circumvention provision lacks any intent requirement.
"The implications of this overbroad provision are troubling, especially for users' privacy and ability to use their personal computers as they see fit," the article states. "In effect, the DMCA codifies a requirement that users submit to cookie storage in order to gain access to certain copyrighted material.
"While it may be fair to require users to allow access protection technology to function properly, it is alarming that a user must either accept cookies he does not want or risk violating federal copyright law in the course of innocently browsing the Internet."
Clicking cookie acceptance popups, Troupson suggested, can be taken as consent to publisher terms over service, like not meddling with paywall mechanisms.
Er, remember the First Amendment?
In an email to The Register , Naomi Gilens, EFF Legal Fellow, expressed skepticism that cookie avoidance might be actionable. "People have a First Amendment right to browse the Internet anonymously, so it can't be a crime to lawfully use software that allows anonymous browsing, even if news sites don't like it," she said.
But Gilens allowed that uncertainty about the legality of cookie interference, something people do automatically via privacy extensions, is understandable given the vagueness of laws like the Computer Fraud and Abuse Act.
"News sites can solve the problem of paywall bypassing by not letting people read any free articles, but they can't stop it by using computer crime or intellectual property laws to block people from lawfully using available software to browse anonymously," said Gilens.
At least in the context of Chrome's cookie-crumbling Incognito mode, Gilens argues that the DMCA is not an issue.
"News websites are of course free to condition access to articles on payment," she said. "But if a news website chooses instead to allow access when viewers have no cookies, then there is not any measure in place that effectively controls access to the copyrighted works, so there's nothing that triggers Section 1201.
"The DMCA specifically contemplates that no one is required to implement any particular technology to interoperate with a DRM scheme – meaning that, in this instance, news websites can't require that browsers keep customers' cookies in order to make their DRM work. (Among other things, mandatory cookie retention would be a privacy nightmare.)
"In short: users aren't liable for 'circumvention' under the DMCA for accessing a news website through Incognito mode any more than they would be liable for accessing a news website from their phone or work computer in addition to their primary personal device."
Whether that interpretation would immunize the creation of software built to bypass a paywall may have to wait for actual litigation. Perhaps it's best just to hedge and call such code a privacy extension.
On a related note, Google earlier this year closed two privacy loopholes in Chrome that publishers had been using to enforce metered access. The ad biz advised disconsolate publishers to reduce their allotment of free articles, to require registration to view any articles, or to harden their paywall.
Troupson said she'd like to see copyright law evolve to address access in addition to copying, given the importance of streaming media.
"I think in general copyright protection has not kept pace with the way people use media today," she said. "I argue we need to rethink copyright as a field of law in general and find ways not just to protect copyright but to protect access rights." ®
Get our [4]Tech Resources
[1] https://developer.chrome.com/extensions/browsingData
[2] https://www.nyulawreview.org/wp-content/uploads/2018/08/NYULawReview-90-1-Troupson.pdf
[3] https://www.theregister.com/2020/06/18/chrome_browser_extensions_new_rootkit/
[4] https://whitepapers.theregister.com/
Don't need it
I still use Firefox v43, which allows you to pick and choose which cookies get stored from where, and stores that choice. Removed in v44.
Re: Don't need it
Instead of running an ancient version of Firefox, why not just install [1]CookieAutodelete ?
I run that as standard so only cookies on the allowlist are kept, the default is to remove cookies after a session.
[1] https://addons.mozilla.org/firefox/addon/cookie-autodelete/
Re: Don't need it
Another option is uMatrix - gives fine grained control over what you will let your browner do and read (and which cookies it will accept), on a per-URL basis. It’s a faff and takes time to set it up so that stuff you’re interested in still works, but if you want fine control it’s difficult to beat
Re: Don't need it
To view (and remove) individual cookies in the latest Firefox hit the F12 button to bring up the Developer Tools when the open tab is the site you want to clear cookies from. Click the Storage tab and expand the Cookies option in the left hand menu. Click the relevant site name and all cookies for that site will be listed in the main pane. Select any you want to remove and hit the Delete key.
"Removed in v44"
No, it's still there.
Go to Options, Privacy & Permission, Cookies and Site Data, click "Manage Permissions...". Here you can set which sites are always allowed to set cookies, which are always denied, and which can store cookies for the current session only.
My computer, my rules.
Fresh incognito window each time. Sue me, motherfuckers.
Re: My computer, my rules.
"Deleting cookies, using ad-blocking software, or other routes past the paywall could be said to 'deactivate' or 'impair' the paywall protecting the online news article,"
That's me. I delete cookies every time I close Firefox (checkbox in current Firefox options) and trackers aren't allowed to store cookies in the first place. I run uBlock Origin to block ads and other annoyances. If I run into a hard paywall I avoid the site.
DCMA has gotten far too big for its britches.
I clean out cookies many times per day. Just the other day I was considering learning to write an extension to auto-clear the rubbish for all sites except for those I have actually logged in.
erm...
https://github.com/iamadamdev/bypass-paywalls-chrome
Legal opinions
This article reminds me of the old joke.
Q. How do you get three different legal opinions on a subject
A. Get two lawyers to discuss it.
Re: Legal opinions
Or interview a single government minister
Doncha love those sites (like
Privacy regulations compliant in other words.
I believe.
I am not a lawyer.
Don't base any decisions on comments here.
Please don't sue me.
Or sew me. Or sow me for that matter.
Where's my coat?
Private browsing
Is private browsing (e.g. Safari) illegal as well, as that doesn't allow sites to store stuff between sessions?
Standard browser features can defeat these soft paywalls so I think it can be argued that they are no barrier at all. And, who is going to sue Google, Microsoft, Apple and Mozilla for including them?
The simplest way is 'open in private tab' or if you have Firefox with Containers (invaluable for keeping work + personal accounts on the same site separate) open in a container. Alternatively deleting the cookies form a particular site is more awkward but is a feature that is in all browsers and has been with us since the first cookies were baked.
Since these paywalls rely on cookies on MY computer I would counter that they placed the cookie without my permision so who should be suing who here?
I would counter that they placed the cookie without my permision so who should be suing who here? Remember the bit where they make you click accept cookies when you visit a website? That'd be the bit where they get permission.
Don't Feel Bad...
Everything breaks US law nowadays.
Re: Don't Feel Bad...
Read and understand the reason you can be fined and imprisoned for [1]picking up a feather . If more people do perhaps the problem will be solved ... next century.
[1] https://lawcomic.net/guide/?p=1008
Re: Don't Feel Bad...
I came across that issue a week ago... and promptly figured out how to identify the large feather I have on my desk, intended to use as a quill pen when I get around to it. Turkey. Ok, I'm safe. (Not all feather ownership is prohibited.)
Cool website, by the way.
Ah...the law of unintended consequences
You have to love how often this hits in areas which seemed to be very simple and clear. Clearing a cookie could be illegal because it tracks your usage while that cookie over there is unlawfully tracking your usage and you are encouraged to delete it.
Reminds me of an online banking Catch-22...a certain Spanish bank suggest installing Trusteer to help defeat ungentlemanly attacks such as man in the middle (also know as 'Variations on Verified by Visa') but while you can say no, this pops up every time you log in unless you allow it to set cookies. So you have a choice of trying to be secure or to clear these annoying adverts (no, AdBlock et al do NOT block it and it needs you to say No multiple times before it will set the 'do not ask again' cookie).
Congress Critters
Remember the DMCA was written by a group know for their venality and stupidity according to Mark Twain and Czar Reed. So the idiocies in the law should be expected both to keep the money (bribes) rolling in and the fact average Congress critter would have trouble carrying on a conversation with the vast intellect of a rock.
Alternative approach
Dear example.com
It has come to my notice that you are storing data on my computer. Please find attached my invoice for storage costs at 1 [currency unit of choice] per byte. Payment is due in 7 days. If this invoice is not paid all such existing data will be removed as will any further data you may attempt to store.
They can't complain about the consequences they were warned about and which result from their own inaction. They should consider themselves lucky that you didn't get a winding up order on non-payment.
Information cannot be contained
What would happen if, for every paywalled news article found, a quick Wikipedia stub with the bare essence of the restricted article was added?
Should do a lot more damage to the bottom line than just letting people read it who aren't going to pay in the first place, no matter the strong arm tactics tried. Whenever I see that pop up, reflex action ^W kicks in and goodbye tab (and a little memory is created of "don't bother with greedy site [X]", which gets reinforced every time this happens).
I know this doesn't work for proper written "art" type articles, but then again, you probably know paying for those in one way or another is the right thing to do? Myself, I won't pay for them if I can't get them in dead tree print form so I can share the ideas with friends / family, but others have looser standards. If the author uses non-tracking static ads (no JavaScript) and lets me save off a personal copy, then I'm also perfectly fine leaving those ads enabled in exchange for access to good quality written material. If not, well, there's an entire library of ideas (literally) that I can select from instead of the article beyond the rental-only paywall.
Threaten me with the DMCA for viewing something on my computer that you published online, however, and I hope your works die, still encrypted, in obscurity, and that your name (along with the decryption keys) is absolutely and utterly forgotten.
Strangely, if a site is greedy enough, I also remember not to sign up for their dead tree subscription version, where I might have otherwise. Odd that!
Contempt
Why should anyone residing in the civilised world beyond USA borders give a damn about the DMCA?
Re: Contempt
Because the USA has a long history of extraterritorial action?
not just to protect copyright but to protect access rights.
Seems an almost pointless crusade in a world where it's apparently illegal to "bypass" a lame-ass "protection" method that relies upon leaving rubbish behind on the user's machine; yet it's all too easy to spot a photo or whatever that one likes and "Share" it with the world. Just think how empty sites like Pinterest would be if all the material that wasn't created by the uploader was cleared out...
Meanwhile Orphan Works battle it out with the mighty Mouse for interesting ways to further break the concept of copyright that does exist, along with the wheeze of "licensing" content simply because it is supplied as a stream of zeroes and ones.
The whole thing is not fit for purpose.