• To chevron_right

      Pirate Streaming Portal Series.ly Has Domain Suspended, Rebrands Instantly

      news.movim.eu / TorrentFreak • 12:53 • 5 minutes

    Series.ly logoSeries.ly was once one of Spain’s best-known pirate link sites. The original operation dropped its piracy links in late 2014. In 2021, the domain was bought at auction by a new team, which says it isn’t part of the original one.

    “The current Series.ly is a separate project from the one that existed until 2015. We bought the domain at an auction in 2021 and we’re not part of the original team,” the operator tells TorrentFreak (translated).

    According to the operator, the new team liked the old site and wanted to bring back that experience. There was plenty of debate internally about whether to go ahead, especially because of what the original creators went through. The operator describes their legal ordeal as “deeply unfair” (translated).

    The new Series.ly, which requires a login to access, became reasonably popular. The site ranked among the 35,000 most-visited sites worldwide earlier this year, with nearly 90% of its traffic coming from Spain.

    That popularity didn’t go unnoticed by rightsholders, which haven’t given up on shutting it down yet. In May, film and TV producers’ group EGEDA filed a complaint with the Second Section of Spain’s Intellectual Property Commission, which falls under the Ministry of Culture, aiming to shut the site down.

    The Commission’s investigator checked a sample of 42 of the 110 titles that were listed in the complaint. Of these, 35 could be streamed or downloaded from Series.ly at the time. The Commission also ordered the site to remove the infringing content in July, but it says Series.ly never responded.

    From Google to a Libyan Registrar

    At the end of July, the Commission sanctioned a series of anti-piracy measures against the site, targeting third-party intermediaries. For example, the resolution requires Google and Bing to remove the site from their search results, while ISPs with a market share of more than 1% must block the domain name.

    The ISPs are also urged to redirect visitors to a government page. This informs users that the Commission blocked the domain “for having illegally facilitated access to content protected by intellectual property rights” (translated).

    The order also lists Cloudflare and Ukrainian hosting company Virtual Systems, whose Kyiv data centers were hit by Russian missile strikes last month, as well as Series.ly’s domain registrar, Libyan Spider Network. These measures apply to the current domain name, as well as new ones that the operator may use for the same purpose.

    The Commission’s order

    The Commission's order

    The Commission’s resolution needs court approval before it can be enforced. This came on September 28, when a judge at the Central Court of First Instance in Madrid concluded that the measures were proportionate, approving them as requested.

    The Libyan Registrar Acts

    Little more than a week later, at least one intermediary appears to have taken action. Earlier this week, Series.ly unexpectedly lost its domain name after the domain registrar, Libyan Spider, stepped in.

    WHOIS records show that series.ly was placed on ‘clientHold’, a status set by the registrar to take a domain offline. This pulls the domain from the .ly zone, which means that Series.ly no longer resolves.

    clientHold

    clientHold

    Libyan Spider hasn’t commented publicly, but the Series.ly operator says the notice cited the Spanish order. It reached them through the auction house that sold them the domain, which acts as a reseller for the registrar.

    “The reason they gave us was a Spanish copyright resolution and a court order authorizing suspension measures against the domain,” the operator tells TorrentFreak (translated).

    It is not clear whether the other intermediaries have taken action yet, but the court order remains valid.

    The site didn’t wait for the domain to come back. Series.ly’s operator confirmed to TorrentFreak that it swiftly switched to a new brand, Cinubo, which runs on a freshly registered .com domain.

    Cinubo.com

    cinubo website

    No Plans to Appeal

    The operator says it didn’t see the warnings before the domain was suspended. An EGEDA email it later found was sent to support@series.ly, while the address listed on the site is soporte@series.ly.

    The registrar’s heads-up also went unnoticed.

    “Our provider forwarded the notice to us quickly, but it went to an account we didn’t check regularly, which also received the catch-all mail for series.ly, meaning messages sent to any address on the domain. We didn’t see those notices in time,” the operator says (translated).

    According to the operator, Series.ly is a non-profit that hasn’t generated any revenue since it launched. The site doesn’t host any video files, and the links to other services are added by the community, he explains.

    “Our position is that complaints about those video files should be directed at the services that host or distribute them,” the operator says (translated).

    “We think it’s disproportionate that a complaint about content hosted by third parties ends up getting our entire domain suspended, including email and the personal library features.”

    For now, the operator doesn’t plan to appeal the Spanish order. The company behind the project is based in Nevis, which raises questions about the reach of the Spanish order, the operator argues.

    “We question whether a procedure handled in Spain justifies suspending our domain worldwide, which also affects email and services that have nothing to do with the works in question,” the operator notes (translated).

    This may not be the end of it though. The Spanish order also covers new domain names that are used for the same purpose, which could include the new Cinubo one. In addition, other intermediaries may take action as well.

    —

    Update October 9, 2026: A few days after it was suspended, the series.ly domain appears to be back under the control of its owner. The operator informs us that the registrar lifted the suspension, but stressed that the domain can no longer be used to link to copyright-infringing content.

    —

    A copy of the Commission’s resolution is available here (pdf). The court’s authorization can be found here (pdf). The Series.ly operator’s answers were provided in Spanish. The quotes in this article were translated by TorrentFreak.

    From: TF, for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Cloudflare Keeps 1.1.1.1 Out of Piracy Blocking, Escapes Penalties in France

      news.movim.eu / TorrentFreak • 1 day ago • 5 minutes

    cloudflare 1.1.1.1 logoOver the past two years, French courts have ordered a growing list of intermediaries to block access to pirate sports streams.

    In addition to regular ISPs, the orders now target public DNS resolvers, VPN services, search engines and CDN providers, all of which can help people bypass existing blockades.

    Internet infrastructure company Cloudflare has received several of these orders. In April, the Paris Judicial Court ordered the company to block 21 domains linked to pirate Formula 1 streams and 16 linked to MotoGP.

    The orders covered Cloudflare’s DNS resolver as well as its CDN. However, they didn’t prescribe how the sites should be blocked, only that access from France had to be prevented “by any effective means.”

    French pay-TV provider Canal+, which requested the blockades, concluded that Cloudflare’s efforts fell short. The broadcaster went back to court and, as first reported by L’Informé, it didn’t get what it wanted.

    Canal+ Requested €50,000 a Day

    In May, Canal+ asked the Paris court to add daily penalties to the April orders. It requested €50,000 per day for every site that remained accessible, and the same amount for every new site that media regulator Arcom reports to Cloudflare.

    From the order (translated)

    50k requested by canal+

    According to Canal+, Cloudflare had deliberately failed to comply with the site blocking orders.

    “[Cloudflare] allegedly circumvented the measures by only implementing the decision through its CDN service, which meant that only three of the 21 domain names listed by the court were blocked,” Canal+ argued, according to the court’s summary (translated).

    In the MotoGP case, Canal+ counted three blocked domains out of 16. In both cases, it added that two of the three blocked sites were back online a week later; one switched to a different CDN, while the other used a mirror site.

    Court Sides With Cloudflare

    On September 17, a panel of three judges ruled on both penalty requests. Cloudflare had pointed to technical constraints that only allowed it to comply through its CDN. It also stressed that the court had expressly left it free to choose which of its services to use, as long as it contributed meaningfully to the fight against sports piracy.

    The court first noted that the way Cloudflare implements the blocking orders is not in dispute.

    “It is undisputed that Cloudflare only implements the ordered measures by blocking through its CDN service, when the site uses that service,” the court writes (translated).

    CDN only

    CDN only

    Cloudflare told the court that this is incomparably more effective than DNS blocking. It added that the architecture of its public DNS resolver doesn’t allow for blocking, making such measures unreasonable.

    Canal+ had argued that Cloudflare only blocked 72.6% of the domain names the court ordered it to block. The court, however, saw the figure as evidence of a genuine willingness to help stop the infringements.

    The ruling doesn’t explain how this percentage relates to the three out of 21 blocked domains that Canal+ cited earlier.

    The court also concluded that Cloudflare can’t be blamed for the sites that switched to another CDN or moved to a mirror.

    “Cloudflare cannot be held responsible when the owners of the sites in question switch to another CDN or set up a redirect to a mirror site,” the court writes (translated).

    Not Cloudflare’s responsibility

    Not Cloudflare's responsibility

    Instead, it is up to Canal+ to ask the new intermediary to block these sites and to report mirror sites to Arcom, the court notes.

    Canal+ also argued that, under the EU Court of Justice’s UPC Telekabel Wien ruling, intermediaries must block effectively. The Paris court disagreed. In its view of the same ruling, intermediaries only have to take reasonable measures, which Cloudflare did with its CDN blocks.

    The court therefore rejected the requested penalties as neither necessary nor proportionate. In addition, Canal+’s request for €20,000 in legal costs was also denied.

    1.1.1.1 Stays Block-Free

    As a result, Cloudflare will not be penalized under these orders, even though its public DNS resolver is not blocking the sites in question. That is in line with the company’s long-standing claim that it doesn’t interfere with its DNS.

    In its recent transparency reports, Cloudflare repeatedly stated that it hasn’t blocked any content through 1.1.1.1, despite orders from French and Italian courts.

    “To date, Cloudflare has not blocked content through the 1.1.1.1 Public DNS Resolver,” the company’s latest report reads.

    From Cloudflare’s transparency report

    transparency report 1.1.1.1 not blocked

    Blocking through the CDN is another matter. According to the same report, Cloudflare geoblocked 1,238 domains in France in the second half of 2025, all under a single court order. In the first half of the year, it geoblocked 662 domains under seven orders.

    Cloudflare recently explained its position to the European Commission, in a submission to its Counterfeit and Piracy Watch List consultation, stressing that global public DNS resolvers should not be used to block or restrict access.

    Instead, it highlights its real-time pirate stream blocking program, which allows vetted rightsholders to flag pirate streams that run through its network. These streams are disrupted “within seconds,” Cloudflare says, without any DNS or IP address blocking.

    “For live content, where speed is crucial, Cloudflare has built real-time mitigation mechanisms that allow vetted rightsholder partners to flag infringing streams. When those streams are running through our network, we act on them in seconds,” Cloudflare informed the Commission.

    Stream mitigation

    Stream mitigation

    For now, Cloudflare can continue to block pirate sites through its CDN only, while its 1.1.1.1 DNS resolver remains untouched. Canal+ can still appeal the rulings, so it may not be the last we hear of it.

    Non-profit DNS resolver Quad9 faces a similar, potentially bankrupting penalty request from beIN Sports for not blocking pirate content on its DNS resolver. How the Paris court will view this will become apparent later this month.

    —

    Copies of the Paris Judicial Court’s rulings in the Formula 1 (RG 26/08243) and MotoGP (RG 26/08228) cases are available here (pdf) and here (pdf). Cloudflare’s submission to the EU Counterfeit and Piracy Watch List consultation can be found here (pdf).

    From: TF, for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Pirate App MovieBox Passes 300 Million Downloads as Rightsholders Alert EU

      news.movim.eu / TorrentFreak • 2 days ago • 3 minutes

    Last year, Nigeria’s copyright watchdog celebrated the suspension of MovieBox.ng, a pirate streaming site that drew tens of millions of visits per month.

    The site swiftly moved to a new domain, as we reported at the time, and its Android app remained widely available.

    However, the app is now drawing attention in Brussels. In submissions for the European Commission’s 2027 Counterfeit and Piracy Watch List, both the Motion Picture Association (MPA) and French TV company Canal+ report MovieBox as a large piracy operation.

    From 243 to 305 Million

    Both rightsholders highlight the same app distribution channel. In its overview of piracy apps, the MPA notes that MovieBox was downloaded more than 243 million times from Palm Store alone.

    Palm Store is the app store that comes preinstalled on Tecno, Infinix and itel phones. These brands all belong to Chinese phone maker Transsion, which sold 61.5% of all mobile phones in Africa in 2024, according to its own filings.

    Canal+ adds more detail. It notes that MovieBox switched to moviebox.ph after enforcement action against its .ng domain in 2025.

    According to Canal+, the app continued to grow after this switch. The site remains online today and the same is true for the app, which more than doubled its number of downloads in less than a year.

    “As of 16 June 2026, PalmStore reported approximately 243.3 million MovieBox application downloads, representing growth of approximately 108% since August 2025, with MovieBox continuing to rank as the number one application in the Entertainment category on the PalmStore platform,” Canal+ writes.

    From Canal+’s submission

    From Canal+'s submission

    The reported June count is already outdated. At the time of writing, Palm Store lists 305.6 million downloads for the app, an increase of more than 60 million in less than four months.

    305.6M downloads

    305.6M downloads

    MovieBox’s store listing explicitly promotes movies, TV series and live sports. “Enjoy free access to sports live streams right in our app,” the description reads, with a specific mention of Europe’s five biggest leagues. Its promotional artwork shows copyrighted shows and categories such as Marvel and Disney.

    Transsion’s Own App Store

    Palm Store is not an independent app marketplace. In a draft prospectus for its planned Hong Kong listing, Transsion describes it as its own app distribution platform, which had more than 180 million monthly active users on average last year.

    This prospectus also explains how the app store makes money. Transsion states that it typically charges third-party developers based on the number of installs that go through its distribution platform. Whether this also applies to MovieBox is unknown.

    ‘Closely Linked’

    Hosting an app in a store doesn’t mean that the store’s owner has anything to do with it. However, Canal+ suggests that the ties run deeper.

    “MovieBox has been closely linked to the Transsion / Transsnet ecosystem. Historical domain registration records identified Transsion-linked registration details for moviebox.ng, while technical analysis of the Android application revealed certificates signed under the Transsion name and references to Transsion-owned infrastructure and services,” Canal+ writes.

    Canal+ on Transsion

    Canal+ on Transsion

    The submission doesn’t explain what these registration details and certificates revealed. It also doesn’t state that Transsion owns or operates MovieBox.

    Canal+ further mentions Excellent Innovation Limited, a Hong Kong company it connects to MovieBox through domain registrations, SSL certificates, developer attributions and trademark filings. Palm Store indeed lists this company as the app’s developer.

    The MPA’s submission doesn’t mention Transsion at all. The Hollywood group merely notes that MovieBox is believed to be operated out of China.

    From the MPA’s submission

    From the MPA's submission

    Canal+ also has a more direct commercial interest in the matter. The French group owns MultiChoice, the pay-TV company behind DStv, which operates in the same African markets.

    Neither of the submissions mentions whether anyone has asked Palm Store or Transsion to remove the app.

    Before the Commission decides, the services that are reported will be offered a chance to respond.

    “The Commission will also make reasonable efforts to contact the service providers reported in the submissions and invite them to respond in writing to the allegations made against them,” the consultation document reads.

    The new list is expected to be released in the spring of next year. The Commission notes that a mention wouldn’t be a finding of wrongdoing or a confirmation of legal violations. It is simply meant to encourage operators and governments to take action against infringement.

    —

    A copy of Canal+’s submission is available here (pdf) and the MPA’s submission can be found here (pdf).

    From: TF, for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Denuvo Asks Court to Unmask Game Cracker ‘voices38’, Reveals Crypto Transactions

      news.movim.eu / TorrentFreak • 3 days ago • 3 minutes

    denuvo logoLast month, Denuvo filed a DMCA anti-circumvention lawsuit against the anonymous game cracker ‘voices38’ at a federal court in California.

    The Irdeto-owned company accuses the cracker of bypassing its Anti-Tamper protection on 26 games, including Hogwarts Legacy and Black Myth: Wukong.

    For now, Denuvo does not know who it is suing. The complaint listed voices38’s Discord user ID, a Reddit account, and seven Steam profiles, but no name. As the lawsuit unfolds, Denuvo hopes to change that, with the court’s help.

    In a recent filing, the company asked the court for permission to subpoena the platforms for information that could identify the cracker, ahead of the regular discovery phase.

    Subpoenas for Discord, Valve and Reddit

    In its ex parte motion, Denuvo explains that it reached out to the three companies directly, without success. Valve and Reddit replied that their privacy policies prevent them from sharing user data without legal backing and Discord didn’t respond at all. A subpoena is the next step.

    “Denuvo seeks leave of the Court to serve limited discovery on Discord, Inc., Valve Corporation, and Reddit, Inc. solely to determine Defendant’s true identity,” the motion reads.

    The proposed subpoenas show what type of information Denuvo is after. Valve, for example, is asked to hand over the registration data, names and billing addresses for seven identified Steam user accounts.

    One of the Steam profiles listed in the filing uses the name Enzo Favara, the main character of Mafia: The Old Country. That is one of the games Denuvo alleges voices38 cracked.

    One of the Steam profiles

    One of the Steam profiles

    Denuvo’s proposed subpoena also requests the payment methods and transaction histories of these accounts, as well as IP addresses with timestamps, device identifiers, and any linked accounts.

    Steam payment data

    Steam payment data

    The seven Steam profiles don’t show much activity, but Denuvo likely linked them to cracking activity associated with ‘voices38’.

    The proposed subpoenas for Discord and Reddit request detailed account data as well. Discord should list the servers the account is a member of and the roles assigned there. Reddit, meanwhile, is asked to produce all posts and comments by ‘voices38’, as well as the account’s subreddit memberships.

    Crypto Transactions on FixedFloat

    The motion also reveals new details. For example, it shows that Denuvo’s own investigation did not stop at these three platforms.

    In a declaration filed alongside the motion, attorney Ryan Morris writes that Denuvo uncovered cryptocurrency transactions by the cracker on the exchange FixedFloat. These crypto transactions involve Bitcoin, Ethereum, and Solana.

    From the declaration

    From the declaration

    The declaration doesn’t explain how Denuvo linked these transactions to ‘voices38.’ It also doesn’t say whether the transactions reveal anything about the person behind the handle.

    FixedFloat is an instant crypto exchange that promotes its service as hassle free, with “no registration and unnecessary details.” Despite mentioning it explicitly, Denuvo doesn’t ask the court for permission to subpoena the crypto platform, and the filing doesn’t say why.

    What’s Next

    It’s now up to Judge Haywood S. Gilliam Jr. to decide whether Denuvo can send its subpoenas to Discord, Valve and Reddit.

    Meanwhile, the lawsuit already appears to have caused some broader damage. Late last month, Tom’s Hardware reported that DenuvOwO, a group that released hypervisor bypasses for dozens of Denuvo games, had disbanded. A member reportedly said the lawsuit was a concern, while the CS.Rin forum removed links to the group’s releases.

    The person or group targeted in the lawsuit didn’t seem impressed when the complaint was filed. “All is fine. Everything will continue as normal,” voices38 wrote on Reddit, shortly after the news broke.

    voices38 comment

    Since then, however, no new ‘voices38’ releases have been posted. Whether that’s related to the lawsuit is unknown.

    —

    A copy of Denuvo’s ex parte motion for expedited discovery is available here (pdf).

    From: TF, for the latest news on copyright battles, piracy and more.

    • To chevron_right

      DNS Resolver Quad9 Rejects French Piracy Blocks, Weighs Exit as beIN Seeks Up to €580K a Day

      news.movim.eu / TorrentFreak • 4 days ago • 5 minutes

    quad9Since 2024, French courts have repeatedly ordered public DNS resolvers to block access to pirate sports streaming sites.

    Not every provider accepted this. For example, OpenDNS suspended its service in France in response to the first blocking order.

    Quad9 stayed in France. The Swiss non-profit foundation said that it had to block the targeted sites for all users worldwide to remain in compliance, and announced that it would appeal. Meanwhile, the blocking orders kept coming.

    In May, the Paris Judicial Court required Google, DNS4EU operator Whalebone and Quad9 to block pirate streams of WTA tennis matches for users in France. This order was requested by beIN Sports and initially listed six domains. According to Quad9, 52 more were added in two later updates, bringing the total to 58.

    Now, Quad9 is not blocking any of the domains. In fact, the foundation informed TorrentFreak that it never has. That is a conscious decision, and one that may come at a price.

    beIN Returns for Penalties

    beIN wanted financial penalties from the start. When it requested the blocking order, the broadcaster asked the court to add a penalty of €2,000 per day for every domain Quad9 failed to block. Quad9 was singled out specifically and the other DNS resolvers didn’t face the same request.

    The court declined beIN’s penalty request, explaining that nothing indicated at that point that the foundation intends to resist (“entende résister”) the order. If problems arose later, the parties could return, the court wrote.

    Penalty denied

    Penalty denied

    That is what beIN has done indeed. Quad9 informed TorrentFreak that the broadcaster went back to the Paris court to request penalties. According to Quad9, beIN now seeks €10,000 per domain, per day, which adds up to €580,000 per day for the 58 domains on the list.

    The case was heard before the Paris court last Thursday and a decision is expected to follow in three weeks. The potential penalties would apply from the moment the order comes in and run in the millions of euros per week.

    There are no public notes of the hearing that we know of, but Quad9 explained in detail why it is not blocking any of the domain names, despite facing the potentially bankrupting fines.

    The DNS Blocking Problem

    Technically Quad9 can block the domain names and avoid further pressure. However, the foundation says that it can’t limit the pirate site blocks to users in France, which is what the court order requires.

    The DNS resolver doesn’t collect user data. This means that it would have to rely on third-party databases that link IP addresses to locations to pinpoint users. That’s a problem, Quad9 argues, because these databases are incomplete or inaccurate.

    “There is no legally useful way for us to define a French user,” Quad9 tells us.

    The foundation has learned this the hard way. In Germany, where Sony Music took the DNS resolver to court and, according to Quad9, judges found that its attempt to limit a block to German users was not good enough. Quad9 eventually won the case on appeal, but that finding was never overturned.

    Convincing the Paris court will not be straightforward either. In the May order, the court noted that the defendants failed to show that limiting the blocks to French territory would be costly or technically impossible.

    Alternatively, Quad9 can block the domain names globally, as it said it would in 2024. It also did so in Germany in 2023, under the threat of penalties. When asked why it isn’t doing the same now, the foundation explained that the German block was a temporary measure while the case played out. It added that conditions in Germany were different, and that it approaches each case on its own terms.

    “We remain entirely confident in our core argument: DNS recursive resolvers are the wrong place to counter the problem of online piracy, and will result in significantly worse outcomes for the citizens of France,” Quad9 says.

    Quad9 is not the only party that raises these concerns. Earlier this year, a report published by the Internet Society warned that smaller DNS operators pay the highest price for blocking orders.

    “Large, well-resourced operators may be able to absorb the compliance costs, but smaller and non-profit operators risk being excluded from the market if they cannot afford the staffing and compliance infrastructure demanded by jurisdiction-specific blocking orders,” the report reads.

    Excluded from the market

    Excluded from the market

    Leaving France?

    If the court grants beIN’s request, Quad9 will have to take action to avoid millions of euros in fines per week. The foundation told us that it essentially has three options left then.

    Quad9 can implement a block for French users only, which it says would be inaccurate and still leave it open to fines. Alternatively, it can block the domains globally which, according to Quad9, would essentially extend French jurisdiction across the world.

    The final option is to stop serving users it believes are in France altogether, as OpenDNS did in 2024. How accurate that measure is remains to be seen as well.

    Quad9 says it has yet to discuss these options with its Foundation Council, noting that it must remain law-abiding without putting its own existence at risk.

    “Additionally, we are required by Swiss law to abide by our founding principles of privacy, security, and stability of the internet and how those principles are applied to our user community in a consistent and predictable manner in all areas,” Quad9 notes.

    ‘Recklessly Dangerous’

    The decision isn’t getting any easier now that France prepares to expand its blocking measures. In July, the French Parliament adopted a law that allows new domains to be added automatically during live broadcasts, with regulator ARCOM reviewing them after the fact.

    Quad9 sees this as a dangerous development, on top of an already quite concerning blocking requirement.

    “An unfettered, unencumbered and delegated power given to an unspecified list of commercial parties to block any content they desire seems to us recklessly dangerous, un-necessary, and counter-productive,” it tells us.

    The foundation believes that this will drive people to use less secure systems in unknown jurisdictions. At the same time, the costs associated with continued real-time updates would likely rule out any meaningful vetting, Quad9 adds.

    “Dynamic injection of false answers weaponizes the DNS against end users,” the foundation says. “This blocking method will be proven to be ineffective, wasteful, and will not achieve the goal of removing the content which remains as reachable as ever.”

    For now, the next step in this blocking saga is up to the Paris court. A decision on the penalties is expected to come in later this month and Quad9 will likely announce its response shortly after.

    —

    A copy of the May 13 order (RG 26/02207) is available here (pdf). We reached out to beIN Sports for a comment, but the company informed us that it will not comment on the ongoing procedure.

    From: TF, for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Two U.S. Site-Blocking Bills Compete Over VPN Rules and ISP Liability

      news.movim.eu / TorrentFreak • 6 days ago • 12 minutes

    congressFor more than a decade after the SOPA protests, pirate site blocking was a subject U.S. lawmakers preferred to avoid.

    That changed last month, when two site blocking bills were introduced in Congress within ten days of each other.

    The first, introduced by Rep. Darrell Issa, is the American Copyright Protection Act (ACPA) which would allow courts to order ISPs, DNS resolvers, and VPNs to block foreign pirate sites.

    The second is the DEFEND IP Act, introduced by Reps. Zoe Lofgren and Ben Cline in the House, with Senators Thom Tillis, Chris Coons, Marsha Blackburn, and Adam Schiff leading in the Senate. It merges Lofgren’s FADPA and the Senate’s Block BEARD proposal into the unified bill TorrentFreak reported on in April.

    At first glance, both bills look fairly similar. They use federal courts to target foreign pirate sites only, and both leave the technical blocking measures up to the providers. The differences are in the details, however, starting with which intermediaries can be ordered to block.

    ACPA (H.R. 10364) DEFEND IP Act (H.R. 10575)
    VPNs Covered Excluded (if exclusively a VPN)
    ISP threshold 100,000 monthly users or subscribers 50,000 subscribers
    DNS resolvers Covered Only public resolvers with over $100 million in revenue
    Pirate site test “Only limited” commercially significant purpose beyond infringement “No” commercially significant purpose beyond infringement
    ISP damages shield Yes, for all providers, from day one No
    Cost reimbursement Must be ordered, may be reduced; covers staff time At the court’s discretion; no overhead
    Rightsholder bond Yes No
    Overblocking compensation Up to $250,000 (rightsholder’s error only) None
    Courts Designated judge roster Any district court

    Who Has to Block?

    Under the ACPA, any broadband provider, DNS resolver, or VPN with 100,000 or more monthly users or subscribers in the United States can be named in a blocking order. Smaller services are exempt, as well as root nameservers and top-level domain registries.

    The DEFEND IP Act takes a different approach. It covers broadband providers with at least 50,000 subscribers, which effectively means that more smaller ISPs are covered. DNS resolvers, however, only qualify if they are public and have more than $100 million in annual revenue.

    VPNs are left out altogether. The DEFEND IP Act explicitly excludes services that exclusively provide VPN connections or similar encrypted routing, as well as DNS services that only work through encrypted protocols, such as DoH.

    That makes VPNs the clearest different between the two U.S. blocking bills. A VPN provider with 100,000 American users could be ordered to block pirate sites under Issa’s bill, while it would not be targeted by Lofgren’s version.

    Who has to block

    ACPA (H.R. 10364)§1601(6)(B) and (C)

    (B) INCLUSIONS.—The term ‘service provider’ includes providers of broadband internet access services, providers of domain name resolution services, and virtual private networks, but excludes root nameserver operators and top level domain registries.

    (C) EXCLUSIONS.—The term ‘service provider’ excludes—

    (i) any entity that provides services to fewer than 100,000 monthly users or subscribers in the United States; […]

    DEFEND IP Act (H.R. 10575)§502A(a)(1) and (6)

    (1) BROADBAND PROVIDER.—The term ‘broadband provider’ means a provider of broadband internet access service, […] that provides such service to not fewer than 50,000 subscribers.

    (6) SERVICE PROVIDER.—The term ‘service provider’—

    (A) means—

    (i) a broadband provider; or

    (ii) a provider of public domain name resolution services that has an annual revenue of more than $100,000,000; and

    (B) does not include—

    (i) an entity that provides domain name system resolution functions or services exclusively through encrypted DNS protocols;

    (ii) an entity that exclusively provides virtual private network services or similar service that encrypt and route user traffic through intermediary servers; […]

    Highlights added by TorrentFreak

    The ACPA wasn’t always this broad in scope. The discussion draft that we covered last year exempted any ISP with 1% or less of the U.S. broadband market. That excluded pretty much every provider with fewer than 1.2 million customers. The introduced bill dropped that exemption, adding smaller ISPs and VPNs as blocking intermediaries.

    What is a Pirate Site?

    Both bills rely on a three factor test to decide if a foreign site can be blocked. A site qualifies if it is primarily designed for infringement, if it is marketed to promote infringement, or if it has little legitimate use. The bills describe that requirement differently.

    The DEFEND IP Act requires that a site has no commercially significant purpose or use beyond copyright infringement. The ACPA, on the other hand, settles for a site that has only limited commercially significant purpose beyond providing access to infringing material. That is a lower bar.

    Pirate site test

    ACPA (H.R. 10364)§1602(b)(5)

    (5) the accused online service—

    (A) is primarily designed or provided for the purpose of providing access to material that violates an exclusive right or protection afforded under this title;

    (B) has only limited commercially significant purpose or use other than providing access to material that violates an exclusive right or protection afforded under this title; or

    (C) is marketed by or at the direction of the operator of the accused online service to promote the use of the foreign online service in committing a violation of an exclusive right or protection afforded under this title.

    DEFEND IP Act (H.R. 10575)§502A(b)(2)(B)

    (B) upon a showing by the petitioner that the foreign online location described in subparagraph (A)—

    (i) is primarily designed or primarily provided for the purpose of violating an exclusive right or protection afforded under this title;

    (ii) has no commercially significant purpose or use other than committing a violation described in clause (i); or

    (iii) is intentionally marketed by or at the direction of the operator of the foreign online location to promote the use of the foreign online location in committing a violation described in clause (i).

    Highlights added by TorrentFreak

    There is a second difference that’s more subtle. The ACPA targets sites that provide access to pirated material, which covers linking and indexing sites as well as hosts. The DEFEND IP Act refers to sites designed for the purpose of infringing, which is less explicit about sites that only link to content hosted elsewhere.

    Both bills also let rightsholders act before any infringement takes place. The ACPA covers operators who will violate a right, not only those already doing so. DEFEND IP does something similar for live events, allowing a site to be targeted when a transmission will likely infringe, and it lets courts issue designations ex parte, without hearing the site operator first.

    The Liability Shield

    The largest difference between the two bills has little to do with blocking itself. It relates to what happens to the piracy liability of ISPs and other providers after a site has been declared a pirate site.

    The ACPA includes a broad liability shield, which covers every service provider the bill applies to, whether it was ordered to block anything or not.

    “A service provider, whether or not named in an order issued under section 1604(d), shall not be liable for monetary relief for any claim of direct or secondary infringement of copyright arising from the service provider having provided or enabled, or continuing to provide or enable, access to a foreign piracy site, unless the service provider acted or is acting in active concert with the foreign piracy site to infringe the exclusive rights of any copyright owner,” the bill reads.

    This means that, once a court has declared a site a pirate site, no copyright holder can win damages from a provider for carrying traffic to it, unless that provider is actively working with the site. This provision takes effect on the day the bill is signed, which is six months before the rest of the law.

    The shield has expanded quite a bit since last year. Issa’s early discussion draft only protected providers that were named in an order, only against the rightsholder that obtained the order, and only for activity after the order was issued. The introduced bill dropped these limits.

    The DEFEND IP Act takes a different approach. It protects providers that implement an order in good faith, and it shields them from claims by the blocked site. There’s no piracy liability shield. In fact, the text specifies that nothing in the bill affects the DMCA’s safe harbors or the principles of secondary liability.

    Liability

    ACPA (H.R. 10364)§1610(b)

    A service provider, whether or not named in an order issued under section 1604(d), shall not be liable for monetary relief for any claim of direct or secondary infringement of copyright arising from the service provider having provided or enabled, or continuing to provide or enable, access to a foreign piracy site, unless the service provider acted or is acting in active concert with the foreign piracy site to infringe the exclusive rights of any copyright owner.

    DEFEND IP Act (H.R. 10575)§502A(i)

    (i) Rules of construction.—Nothing in this section may be construed to affect—

    (1) the applicability or interpretation of any other provision of law or principle of equity, including—

    (A) the requirements of section 512 or any other provision of this title;

    (B) principles of secondary liability; or

    (C) section 1651 of title 28; or

    (2) the limitation on the liability of a service provider under section 512.

    Highlights added by TorrentFreak

    Liability was a key point of contention in site-blocking discussions last year. In May 2025, Senator Chris Coons told a Senate hearing that progress was finally being made, but that Internet providers wanted something in return.

    “It finally feels like we’re making some real progress here on site blocking after years. One of the key roadblocks to getting a final deal is whether ISPs should benefit from immunity, both prospectively and retrospectively,” Senator Coons said.

    The MPA’s Karyn Temple responded that site blocking laws elsewhere had not led to lawsuits against ISPs, so there was little to protect them from.

    “ISPs have not routinely been sued for enforcing site blocking regimes. So, you know, I think in our experience, we don’t think that this is a provision that is necessary at all,” Temple replied.

    Sixteen months later, the bill Coons co-sponsors has no piracy-damages shield, while Issa’s has a broad one.

    Who Pays?

    Site blocking costs money, and both bills allow providers to recover some expenses from rightsholders. How much differs between the two proposals.

    Under the DEFEND IP Act, reimbursement is at the court’s discretion and only direct compliance costs can be claimed. Capital expenditures, infrastructure, overhead, and attorneys’ fees are excluded.

    “Upon motion by a service provider subject to an order issued under this subsection, the court may order the petitioner that sought the order to pay reasonable costs directly incurred by the service provider to comply with the order,” the bill reads.

    The ACPA is more generous. If a provider documents its costs, the court must order reimbursement. It can’t deny it, but the amount can be reduced. These costs can also include overhead that’s linked directly to the order, such as the salary costs of specialized staff for the time they spend on it.

    Costs

    ACPA (H.R. 10364)§1609(c)(1) and (d)

    (1) The reimbursement awarded may include any commercially reasonable cost actually and directly incurred by the named service provider to implement the order, including portions of overhead costs directly incurred specifically to implement the order, such as portions of salary costs for specialized personnel directly attributable to time spent on implementing the specific order at issue and not other orders or other tasks.

    (d) […] the court shall issue an order requiring the copyright owner to provide the reimbursement to the named service provider within a time period set by the court, except that the court may reduce the reimbursement to prevent imposing an undue burden on the copyright owner considering the resources of the copyright owner.

    DEFEND IP Act (H.R. 10575)§502A(c)(10)

    (A) IN GENERAL.—Upon motion by a service provider subject to an order issued under this subsection, the court may order the petitioner that sought the order to pay reasonable costs directly incurred by the service provider to comply with the order.

    (B) CONTENTS.—A motion made under subparagraph (A)—

    (i) shall include a detailed list of each cost described in that subparagraph;

    (ii) may not include costs for capital expenditures, infrastructure, overhead, or attorneys’ fees; and

    (iii) shall be filed not later than 60 days after the date on which the costs sought to be recovered were incurred.

    Highlights added by TorrentFreak

    The ACPA requires rightsholders to post a bond for each site blocking order, to cover any provider that is wrongfully enjoined. DEFEND IP doesn’t have this requirement.

    Overblocking is treated differently too. Under the ACPA, the operator of a legitimate site that gets blocked by mistake can claim up to $250,000 in compensation, provided the rightsholder caused the error. DEFEND IP allows site operators to ask the court to fix an order, without offering compensation.

    A Public Blocklist?

    Transparency is a key element to inform the public on site-blocking, but it is often lacking. In most countries, the public has no official way to find out what is blocked. The U.S. bills do offer transparency, at least on paper.

    The ACPA requires the Copyright Office to keep a public registry of all active blocking orders. In addition, rightsholders must also file a notice of each case at the Copyright Office, which is then published in the Federal Register.

    The DEFEND IP Act requires courts to notify the Register of Copyrights whenever an order is issued, amended, or rescinded, and those notifications are published on the Copyright Office website. Since courts can amend orders when a site moves to a new domain, those updates should be added to the public record as well.

    How useful either registry will be depends on what the orders contain. The bills don’t require domain names and IP addresses to appear in the published version. As TorrentFreak noted last year, publishing orders without those details creates a transparency illusion. The public sees that something is blocked but without further detail, which makes it hard to check for overblocking.

    The two bills also differ on who handles the blocking requests. The ACPA sends everything to a roster of district judges picked by the Judicial Conference. DEFEND IP leaves cases with any appropriate district court.

    Finally, it’s worth noting that two of the sponsors have limited time. Issa retires at the end of the year and Tillis’s term ends in January, so their bills have to move before the session closes. Whether the two will be merged, or one will simply overtake the other, has yet to be seen.

    —

    The full text of the ACPA (H.R. 10364) is available on Congress.gov, as is the DEFEND IP Act (H.R. 10575).

    From: TF, for the latest news on copyright battles, piracy and more.

    • To chevron_right

      LaLiga Wants Major VPNs on EU Piracy Watch List Over Affiliate Marketing

      news.movim.eu / TorrentFreak • 30 September 2026 • 5 minutes

    laligaEvery few years, rightsholders get the opportunity to tell the European Commission which pirate sites and services deserve a spot on its Counterfeit and Piracy Watch List.

    These submissions traditionally focus on torrent sites, cyberlockers and pirate IPTV services. In recent editions, however, intermediaries such as hosting companies and Cloudflare have been added to the mix.

    LaLiga takes this expanding reach a step further. In its submission for the 2027 edition, the Spanish football league asks for NordVPN, ProtonVPN, ExpressVPN and Surfshark to be listed.

    The 14-page submission targets a wide range of sites and services, including traditional piracy threats, but the VPN section is new. The league notes that it doesn’t take offense with the technology itself, but with how these providers are marketed by others through their affiliate programs.

    “The conduct that takes these services beyond neutral technical provision is the deliberate marketing of circumvention, conducted at arm’s length through affiliate programmes,” LaLiga writes.

    Geo-Unblocking Free Football Broadcasts

    LaLiga explains that publishers and influencers with affiliate deals publish guides, updated for the 2026/27 season, on how to watch its football matches for free using these VPNs. Those pages rank the providers and link to discounted subscriptions, while earning a commission on resulting sales.

    Some of these guides point out that football fans can use the VPNs to circumvent geoblocking, allowing them to watch free or cheap broadcasts in other countries. This isn’t linked to pirate streams, but LaLiga notes that it harms the territorial exclusivity of its licensing deals.

    “the loss of neutrality”

    affiliate marketing

    Guides of this type are not hard to find. We came across several Spanish-language pages, updated for the new season, that recommend connecting to a foreign VPN server to watch matches on free broadcasts abroad.

    These recommendations are published by affiliates, not by the VPN providers themselves. LaLiga’s submission doesn’t claim that the providers write the guides themselves, but it argues that the providers profit from them.

    Circumventing Pirate Site Blockades

    In addition to bypassing geo-blocking, the submission also flags guides that it sees as a more serious concern. These are affiliate pages that name pirate streaming sites and services, explaining that a VPN can bypass court-ordered site blocking measures.

    LaLiga says that anyone can verify this affiliate marketing activity, but the submission doesn’t name or link to a single guide or influencer that’s crossing a line.

    According to LaLiga, the publishers behind the guides are not always independent, linking the vpnMentor review site to Kape Technologies, which owns several VPN services.

    “Publishers of the guidance are in some cases not independent. Within one of the corporate groups identified above, VPN review and ranking publications are under the same ownership as the products they rank, a relationship those publications disclose,” the submission reads.

    Which of these publications include the guides LaLiga describes isn’t mentioned.

    Independence

    independent

    The submission also argues that some VPN providers have released marketing material timed around its match calendar. This is not backed up with examples, but in February a Spanish court in Córdoba reached a similar conclusion when it issued an ex parte site blocking order against ProtonVPN and NordVPN.

    Without hearing the VPN providers, the court reportedly concluded that both NordVPN and ProtonVPN actively advertise their ability to bypass geo-restrictions, citing match schedules in their marketing materials, while describing the VPNs as active participants in the piracy chain.

    The matter is not settled yet. In May, the same court refused to fine NordVPN for not complying, accepting that the targeted IP addresses of pirate streams changed frequently. The main proceedings are still ongoing.

    VPN Technology is Fine

    LaLiga asks the Commission to list the four providers because they allegedly facilitate access to blocked pirate sites and services. The league stresses that it’s not targeting the technology itself.

    “This request is based not on the provision of VPN services as such, but on the commercial exploitation and active promotion of their ability to circumvent court-ordered blocking measures,” LaLiga writes.

    The submission also opens with a disclaimer. “This submission does not assert any finding of legal liability against the entities named,” it reads.

    The main allegation hinges on the affiliate promotion angle, without naming any specific guides. Whether that will be sufficient for the European Commission has yet to be seen, especially since it is still contested in courts and among lawmakers whether VPN providers should be required to implement blocking orders.

    AFTVnews Downloader Short Codes

    VPNs are not the only general-purpose tools in LaLiga’s submission. The league also targets Downloader by AFTVnews, a popular app for Fire TV and Android TV devices that lets users download files by entering a URL or a numeric short code.

    LaLiga says it catalogued 341 of these codes, 262 of which lead to pirate apps. The league describes the codes as a curated catalogue, under the operator’s “exclusive editorial control.”

    “The ease and simplicity with which applications can be discovered and installed through this catalogue is itself demonstrative of its nature as an editorially-curated platform, distinct from the underlying distribution infrastructure,” LaLiga writes.

    AFTVnews, which boasts more than 100 million users, describes the codes as being “generated by the AFTVnews URL Shortener,” which suggests that they are created from links submitted by users.

    Downloader

    downloader

    Downloader has been targeted before. In 2023, Google removed the app from its Play Store following complaints from Israeli TV companies, and again after a DMCA notice from Markscan. The app was later reinstated.

    Whether the Commission will mention Downloader or any of the four VPN providers in its 2027 piracy watchlist has yet to be seen. The latest Counterfeit and Piracy Watch List, released in 2025, did not include any VPN services, but did mention various hosting providers, IPFS, and domain name privacy service Njalla.

    —

    A copy of LaLiga’s submission to the European Commission is available here (pdf).

    We reached out to ProtonVPN, the VPN Trust Initiative and AFTVnews for comment, but they did not respond before publication.

    Disclosure: TorrentFreak uses VPN affiliate links, but not in a circumvention context.

    From: TF, for the latest news on copyright battles, piracy and more.

    • To chevron_right

      IFPI Wants Open Source YouTube Downloader yt-dlp on EU Piracy Watch List

      news.movim.eu / TorrentFreak • 29 September 2026 • 4 minutes

    ifpi logoIn October 2020, the RIAA used a DMCA notice to remove the popular YouTube download tool youtube-dl from GitHub.

    The RIAA argued that the software circumvented YouTube’s rolling cipher technology. A few weeks later, GitHub reinstated the repository and set up a $1 million defense fund for developers facing similar claims.

    The music industry had more success in Germany, where labels won a lawsuit against Uberspace, the hosting provider of youtube-dl’s official website. In November 2024, the Hamburg Court of Appeal rejected the host’s appeal.

    While youtube-dl was never formally shut down, active development has been largely taken over by the open source fork yt-dlp. In fact, people who visit the original .org domain of youtube-dl’s former website are redirected to yt-dlp.

    The yt-dlp project launched in 2021 and has more than 16,000 forks and more than 190,000 stars on GitHub, making it the 32nd most-starred project on the site.

    IFPI Flags yt-dlp as “Major Problem”

    The music business is well aware of these developments and continues to see this type of software as a problem. In a new policy submission, music industry group IFPI highlights yt-dlp as a major problem, naming four developers by their online handles.

    The callout is part of IFPI’s submission to the consultation for the EU Counterfeit and Piracy Watch List. Among other things, it asks for yt-dlp to be added to the list of stream ripping services, alongside Savefrom.net and two Y2mate sites.

    “YT-DLP is a major problem for the music industry as it provides freely available open-source software that enables users to download and permanently store music and audiovisual content from licensed streaming platforms, including YouTube, without authorisation,” IFPI writes.

    A Major Problem

    a major problem

    IFPI’s overview describes the project’s history, its stream ripping capabilities, and the copyright-critical Unlicense it’s released under. The group also explains why the software is hard to stop.

    “Its open-source nature, extensive developer community and its widespread distribution results in the tool being difficult to contain and/or remove, while continuing to facilitate stream ripping at scale and depriving right holders, artists and licensed services from legitimate streaming and downloads.”

    Four GitHub Handles

    The submission identifies the project’s founder as GitHub user pukkandan, who it says was lead maintainer from 2021 to 2024. It also lists three current core maintainers: coletdjnz, bashonly and Grub4K. These handles are publicly listed on GitHub.

    From yt-dlp’s GitHub

    dlp

    This is the first time we’ve seen yt-dlp, or the original youtube-dl, named as a target in a Watch List or Notorious Markets submission.

    Besides the listing, the yt-dlp callout doesn’t ask for anything concrete. There is no takedown request, call for blocking measures, or any action against the developers. The submission also doesn’t mention that the software can be used for lawful purposes.

    Circumvention?

    The yt-dlp description does not mention the word ‘circumvention’ either, but the general stream-ripper intro does. IFPI argues that YouTube uses technical protection measures to prevent downloads.

    “Stream ripping sites are circumventing these measures that enjoy legal protections under the international treaties and EU law,” the submission reads.

    Legal protections

    legal protections

    The music group also cites the German youtube-dl ruling, where the court held the website’s host liable for aiding and abetting the circumvention of these measures.

    However, the submission itself describes the tool as “parsing webpage and player data, and interacting with platform-specific playback endpoints.” How circumvention potentially fits in there is not mentioned.

    Officially Hosted in the United States

    The European Commission’s Watch List highlights marketplaces and services outside the EU that reportedly engage in or facilitate piracy and counterfeiting. While the location of the developers isn’t discussed, GitHub is called out as the hosting platform.

    “Github is YT-DLP’s official source; it serves as the main platform for accessing the scripts latest updates, source code, pre-compiled binaries and installation instructions,” IFPI writes, while adding that forks and copies are also available elsewhere.

    GitHub is a Microsoft-owned company, based in the United States, which would make the yt-dlp repository US-hosted.

    AI ‘Ripping’ Threats

    IFPI’s submission is not limited to traditional threats. It also flags a newer type of ripping tool. AI music apps Rythmix and MusiQ AI allow users to paste a YouTube link and turn the recording into an AI cover song with a cloned artist voice.

    Rythmix

    Rythmix

    Both these tools are available in Apple’s App Store, and Rythmix is also on Google Play, where it was already downloaded more than five million times.

    In the months to come, the European Commission will go over all submissions and decide which of the proposed targets make it into the 2027 edition of the list. Whether that includes yt-dlp or the AI apps has yet to be seen.

    —

    IFPI’s submission to the EU Counterfeit and Piracy Watch List consultation, which includes a variety of additional targets, is available here (pdf).

    We reached out to the yt-dlp maintainers and GitHub for a comment on IFPI’s submission, but they did not respond before publication.

    From: TF, for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Unified U.S. Site Blocking Bill Targets ISPs and DNS Resolvers But Spares VPNs

      news.movim.eu / TorrentFreak • 28 September 2026 • 4 minutes

    blockedLast week, we reported that the American Copyright Protection Act (ACPA) puts virtual private networks on the list of intermediaries that could be ordered to block pirate sites.

    This wasn’t the only bill in the works. As expected, there’s now competition from a unified bill, officially introduced by Senator Thom Tillis and Rep. Zoe Lofgren: the DEFEND IP Act.

    Both lawmakers had already been working on similar legislation and the DEFEND IP Act merges Lofgren’s Foreign Anti-Digital Piracy Act (FADPA) and Tillis’s Block BEARD draft into a single bicameral bill.

    While the bill’s title works on its own, it’s actually an acronym for “Deterring Extraterritorial Foreign Exploitation of Networks Damaging Intellectual Property.” Senators Chris Coons, Marsha Blackburn, and Adam Schiff are co-sponsors of the Senate bill, while Rep. Ben Cline co-leads the House effort.

    “I am proud to work across the aisle on this smart, targeted approach to crack down on foreign piracy while protecting Americans’ free speech and access to a free and open internet,” Rep. Lofgren says in her announcement.

    DEFEND IP Act

    bill

    The Senate version of the bill, S. 5529, is now with the Judiciary Committee. Congress.gov has yet to publish the text, but Lofgren’s office has posted a copy of the House version of the bill, which allows us to take a closer look.

    VPNs Are Exempt

    Like Issa’s ACPA, the DEFEND IP Act allows copyright holders to obtain court orders that require intermediaries to block foreign pirate sites. The key difference is which intermediaries can be targeted.

    The DEFEND IP Act covers broadband providers with at least 50,000 subscribers, as well as public DNS resolvers with more than $100 million in annual revenue. The latter would likely include Google and Cloudflare.

    VPN services are not on the list, however. The bill’s definition of a service provider explicitly excludes “an entity that exclusively provides virtual private network services or similar service that encrypt and route user traffic through intermediary servers.”

    VPN Exemption

    vpn

    This is different from the ACPA bill, where VPNs are included. The word “exclusively” leaves some room for interpretation, however. The bill doesn’t explain how the exemption applies to companies that offer a VPN alongside other services.

    DNS resolvers get a similar exemption, but only if they provide their services “exclusively through encrypted DNS protocols,” such as DNS over HTTPS. This is a high bar and it likely means that major public DNS resolvers including Cloudflare and Google, which also handle unencrypted queries, would have to block on their encrypted services as well.

    Designate First, Block Later

    The blocking process itself follows the same two-step approach as Issa’s ACPA bill. The first step is for a federal court to classify a website as a “foreign digital piracy site.”

    To qualify, the site must be primarily designed for piracy, have no commercially significant purpose other than piracy, or be intentionally marketed as a piracy destination. Operators have 20 days to respond, but the court doesn’t have to wait for them and can issue an ex-parte order when the requirements are met.

    With the designation in hand, the rightsholder can return to the same judge and request a blocking order. The court then has to decide whether blocking is “technically feasible and effective” or whether there are less burdensome options available.

    Blocking orders remain valid for a year and can be renewed. When a pirate site moves to a new domain or IP address, rightsholders can ask the court to update the order.

    As with ACPA, the DEFEND IP Act also covers live streaming events, including sports. Rightsholders can request a court order when a live transmission “will likely violate” their rights, which means that a site can be flagged before the match starts.

    Hollywood Applauds, Public Knowledge Objects

    As with earlier proposals, service providers get several safeguards. Blocking orders can’t prescribe specific blocking techniques, providers are immune from liability when they comply in good faith, and they can ask rightsholders to cover part of the costs.

    Websites that are blocked by mistake can ask the court to modify the order. However, unlike Issa’s bill, which offers up to $250,000 in compensation, the DEFEND IP Act has no payout for collateral damage.

    The unified bill has broad industry support from the start, with more than a dozen organizations backing it, including the MPA, RIAA, Copyright Alliance, SAG-AFTRA, and the Directors Guild.

    “By enacting this legislation, our country can deploy a highly effective tool to protect creators and consumers from overseas digital piracy, all while safeguarding free speech and preserving the open internet,” MPA Chairman and CEO Charles Rivkin says.

    Public Knowledge, which also opposes Issa’s bill, sees it differently. The group views both site blocking proposals as part of the same push.

    “For the second time in as many weeks, rightsholders have convinced Congress to build out an expansive infrastructure for censorship rather than go after the root of the problem: operators of overseas piracy websites,” Public Knowledge writes.

    “Let us repeat: Applying blocking orders to global DNS resolvers causes global blocks,” the group adds.

    More than fourteen years after SOPA was shelved, two site blocking bills are now competing for support in Congress.

    Time is limited, however. Both bills expire when the current Congress ends in January. Rep. Issa is retiring and Senator Tillis is not seeking reelection, so neither will be around to reintroduce their proposals next year.

    Whether either proposal will get further than SOPA did remains to be seen.

    —

    A copy of the DEFEND IP Act, as published by Rep. Lofgren’s office, is available here (pdf).

    From: TF, for the latest news on copyright battles, piracy and more.