Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Handle Copycats (License fraud) #539

Open
theScrabi opened this issue May 8, 2017 · 230 comments
Open

Handle Copycats (License fraud) #539

theScrabi opened this issue May 8, 2017 · 230 comments
Labels
discussion This needs to be discussed before anything is done meta Related to the project but not strictly to code

Comments

@theScrabi
Copy link
Member

theScrabi commented May 8, 2017

Follow these instructions if you want to report an app on the Google Play Store!


Hey guys, I happen to notice some new copycats which seemingly violate our License.

Once again, it's OK to copy NewPipe as long as you do not violate our GPLv3 License. Please inform yourself about GPLv3 before forking!!!

I already mailed some of the copy kiddies, but they seem to not react on it (like always), so my question is how should we handle these copycats in the future?

List of known and active copies/forks

In the Google Play Store

In the Huawei AppGallery

  • (to be added)

In the Samsung Galaxy Store

  • (to be added)

Other copies/forks

@ksh-b
Copy link

ksh-b commented May 8, 2017

Thats embarasing. How come they even stay on playstore.

https://support.google.com/googleplay/android-developer/contact/takedown

@theScrabi
Copy link
Member Author

I've tried that, but google does not seem to respond? Maybe I'm doing something wrong here. Howerver, I know that it works sice there was already a fork that got kicket out.

@yasinalm
Copy link

yasinalm commented May 23, 2017

don't worry, you don't need to to do anything. it is impossible(99.99%) a single app stays alive until 500 downloads. Play store takes care of it extremely very well as YT is his own too. they can earn 1-2$ but loose 25$ (account registration fee). So, it is not worth that much effort to do something. they punish themselves.

A few examples can be found but they won't live longer and the ads will be eventually ceased.

@theScrabi
Copy link
Member Author

Sure? audiorocket sem tho have more than 400k downloads.

@ericswpark
Copy link

ericswpark commented Jul 21, 2017

Unfortunately while copycats will always be there (I have some on my hands too) it's just easier for you to send a take-down notice to Google and let them deal with it.

That being said, Google hates your app so they might just not be taking it down in spite. Who cares, the average 99% of people in the world likes it anyway ;)

@theScrabi theScrabi changed the title Handle Copycats ?!? Handle Copycats (Licence fraud) ?!? Aug 1, 2017
@theScrabi theScrabi changed the title Handle Copycats (Licence fraud) ?!? Handle Copycats (License fraud) ?!? Aug 1, 2017
@TheAssassin
Copy link
Member

TheAssassin commented Aug 1, 2017

This list has been mined out of 600 MiB of parsed email data. If you can spot some of them, please get in touch with us.

Edit: These are package names I parsed from the ones in the field that was added a few weeks after the introduction of the bug reporting. For this and other reasons, this list is not complete, there might be more.

co.at.newpipe
com
com.akkayaxm.mscPlayer
com.cubic3.MyDownloader
com.dl.video
com.facecampt.free.music.player
com.FloTemp
com.gawo.rohgf
com.green.music
com.halara.trap
com.hvlapps.freemusicplayer
com.mp3musicdownloader.mp3.music.downloader
com.mp3musicdownload.music
com.mp3musicdownload.musicmp3
com.mp3music.newlife
com.mpool.mytube
com.musicmp3downloader.ilovemp3
com.musicmp3.newmusic
com.musicmp3.new\nmusic
com.music.paradise
com.mwiz.pingmusic
com.tenlishir
com.youtube.audiorocket
com.youtubed.ydownloader
com.youtubelistening.youtubebackground
com.youtubelite.floattube
com.zbm.probasse
idev4mobile.karaoke
idev4mobile.videotube
inc.players.youlayer
musicstream.videostream.newpipe
org.bardo.newpipe
org.le.keep_video
org.schabi.newpipe
org.schabi.vbl2013
org.schabi.videodownloader
org.schabi.youdownload
org.schabi.youdownloader
org.testng01.tubeb44

@coffeemakr
Copy link
Contributor

coffeemakr commented Aug 2, 2017

I've created a small script to check if they are on google play: https://gist.github.com/coffeemakr/8862e7903c4bea21b99c6a457268af71

The following packages are on google play:

A copyright violation can be submitted with this form:
https://support.google.com/legal/contact/lr_dmca?&product=googleplay
The description on how to fill out the form can be found here: https://support.google.com/legal/troubleshooter/1114905#ts=1115643%2C1115789%2C1117010%2C1697925

@theScrabi theScrabi changed the title Handle Copycats (License fraud) ?!? Handle Copycats (License fraud) Aug 2, 2017
@theScrabi

This comment was marked as outdated.

@TheAssassin
Copy link
Member

Beware that this is not even the whole list, only the ones we captured on a side-channel. But yes, it's quite an amount. Time to take half a day and send some DMCA takedown notices, @theScrabi.

@Zero3K
Copy link

Zero3K commented Aug 22, 2017

How about adding some code that checks the display/package name of NewPipe and if it has been changed, let the user know (and possibly refuse to work)?

@TheAssassin
Copy link
Member

Then you'd also notify the copycat and tell them "oh, I need to remove that piece of code". They're not that stupid, because they must obviously know how how to develop for Android to create realistic apps. This measure is rather pointless IMO.

@theScrabi
Copy link
Member Author

theScrabi commented Aug 22, 2017

The only thing we could do is making it harder for copycats to change the email address where the but reports are send to.

@Poussinou
Copy link
Contributor

Poussinou commented Aug 30, 2017

@theScrabi Did you feel the DCMA takedown notice, out of curiosity? It only takes a few minuts and Google reacts in a few days (I already tried with an other app) I can see that the apps haven't all been taken down.

I would like to add this one (MOD edit: removed) to the list made by coffemakr !

@TobiGr

This comment was marked as resolved.

@Poussinou

This comment was marked as resolved.

@theScrabi

This comment was marked as resolved.

@comradekingu

This comment was marked as resolved.

@theScrabi

This comment was marked as resolved.

@Poussinou

This comment was marked as resolved.

@theScrabi

This comment was marked as off-topic.

@Ostefanini
Copy link

Does play store will really help you in this war?
Play yt in background is something quite illegal for them...

@theScrabi
Copy link
Member Author

Well I wouldn't raise, there attention to much.

@ghost

This comment was marked as resolved.

@theScrabi
Copy link
Member Author

Report them. Thats the most we can do.

@heartlog

This comment was marked as duplicate.

@comradekingu
Copy link
Contributor

comradekingu commented Apr 29, 2023

What is going on with https://youdown.net/
Is anything actually different offered there?

https://hosted.weblate.org/projects/youdown/#information says "proprietary", which isn't compatible with the license.

@eclairevoyant
Copy link

What is going on with https://youdown.net/ Is anything actually different offered there?

Doesn't matter unless there's a copyright or license violation.

https://hosted.weblate.org/projects/youdown/#information says "proprietary", which isn't compatible with the license.

Probably mislabeled on weblate, it appears to be open source.

@nospace-here
Copy link

https://play.google.com/store/apps/details?id=com.tubepipe.newpipe

Similar logo and screenshots appear to be AI-generated

@nospace-here

This comment was marked as resolved.

@wb9688

This comment was marked as duplicate.

@theScrabi
Copy link
Member Author

theScrabi commented Jul 12, 2023

https://play.google.com/store/apps/details?id=com.tubepipe.newpipe

Similar logo and screenshots appear to be AI-generated

I notified google.

@librick
Copy link

librick commented Jul 31, 2023

Should the project README have a clear warning toward the top about NewPipe not being on Google Play? The existing text warns bad actors: PUTTING NEWPIPE, OR ANY FORK OF IT, INTO THE GOOGLE PLAY STORE VIOLATES THEIR TERMS AND CONDITIONS, but I think we could reword/prepend it to warn users specifically. Something like NewPipe is NOT on the Google Play Store! Do NOT download NewPipe from Google Play! Apps using NewPipe branding on Google Play are fake!

I looked up NewPipe on Google Play Store this afternoon and found the following:

All of which are using some variant of the NewPipe logo.
I flagged these apps from within the app store. Then I reported each one via the Google takedown form (https://support.google.com/googleplay/android-developer/contact/takedown). Under "Reason for flagging" I selected "Other objection" and in the text field I wrote:

This app commits license fraud against the NewPipe open source project and is likely malicious. See: #539

(I wrote out the full/unformatted issue link in the form, ignore the GitHub-specific issue linking). Thanks to the devs and community for being vigilant. I didn't know this was a problem until today

@opusforlife2
Copy link
Collaborator

to warn users specifically

Unfortunately, they are completely separate audiences. Potential users who manage to reach our ReadMe won't download clones. And users who download clones from the Play Store won't know to come to this repo.

@pokegamer5547
Copy link

Another copycat found called playtuber
https://play.google.com/store/apps/details?id=com.streamingnewpipe.videomusicnewpipe

@TobiGr
Copy link
Member

TobiGr commented Sep 17, 2023

https://m.onestore.co.kr/mobilepoc/apps/appsDetail.omp?prodId=0000727868&scYn=Y
Is there anybody who has access to "onestore" and is able to download the APK?
Please do not install the app if possible.

@Poussinou
Copy link
Contributor

@theo546
Copy link

theo546 commented Dec 19, 2023

This app may not be using NewPipe code directly, but they are using NewPipe name and logo
https://apps.apple.com/fr/app/newpipe-music-videos/id6450053445

@clavinet
Copy link

clavinet commented Mar 1, 2024

This app may not be using NewPipe code directly, but they are using NewPipe name and logo https://apps.apple.com/fr/app/newpipe-music-videos/id6450053445

I found this one as well today and even contacted Apple support about it, but there is only so much a user can do.

They asked me if I'm the developer so I suppose it would carry more weight if someone "official" from the NewPipe team would file a copyright infringement claim.

@AnthillSudoku

This comment was marked as duplicate.

@AnthillSudoku

This comment was marked as resolved.

@AnthillSudoku

This comment was marked as off-topic.

@appreviewandblocker

This comment was marked as duplicate.

@AnthillSudoku

This comment was marked as resolved.

@fillwithjoy1
Copy link

Unfortunately, they are completely separate audiences. Potential users who manage to reach our ReadMe won't download clones. And users who download clones from the Play Store won't know to come to this repo.

It doesn't help that we are outside the play store, so 90% of the audience will never discover this 😔

@niccokunzmann
Copy link

For the Apple App Store:

The Trademark holder would be able to complain as well as the copyright holder of the logo. If the logo is indeed derived, one could say that it violates the copyright license which is GPL if the app's source code is not revealed. It is advisable to register a trademark and add a TRADEMARK file to the project as well as guidance on how to properly fork and what to change.

You can file a copyright infringement report for the Apple App Store here: https://www.apple.com/legal/contact/copyright-infringement.html It states:

You can only make a DMCA complaint if you are the copyright owner (or acting on behalf of the copyright owner).

For me, it would help if there is an official statement by NewPipe saying what to do in this case on its website. Also, this is a Trademark violation.

@fillwithjoy1

This comment was marked as spam.

@onetimecontributor
Copy link

Hi. I would like to initiate update of the suggestion placed above in this thread.
Unfortunately, Google has reworked the process and https://support.google.com/googleplay/android-developer/contact/takedown now redirects to https://support.google.com/googleplay/android-developer/contact/policy_violation_report
If to set Suspected Policy Violation to Intellectual property, the form prevents submission ("You will not be able to submit this form") and requests to follow another process that is targeted only to the owner of copyrighted material ("To report content that you believe infringes your copyrights") and redirects to https://support.google.com/legal/contact/lr_dmca?product=googleplay that is hard to fill for non-owner of the material.

Has anyone figured out how to properly fill the form by someone that is non-owner (including references to legal basis, etc)?

@cyberboh
Copy link

cyberboh commented Nov 29, 2024

Another crap and impersonates ReVanced:
https://play.google.com/store/apps/details?id=us.videolite

Email provided by the "developer" in a review answer on the Google Play Store: [email protected]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
discussion This needs to be discussed before anything is done meta Related to the project but not strictly to code
Projects
None yet
Development

No branches or pull requests