On October 23, 2020, the RIAA sent GitHub a letter on behalf of its member record labels, and GitHub disabled the youtube-dl repository the same day. The letter did not claim the code contained pirated files. It claimed the software itself broke technical protections around YouTube videos, a different statute aimed at a different kind of target. Twenty-four days later the repository was back online, GitHub had acknowledged the removal deserved more scrutiny than it received, and the notice had made youtube-dl the most famous downloader on the internet. The youtube-dl RIAA GitHub takedown is now the standard case study in what a DMCA notice can and cannot reach.
This guide walks the full arc: the statute the RIAA chose, why its argument collapsed, how GitHub reversed itself, and what that means for anyone filing a takedown today. The short version: the wrong legal tool, aimed at the wrong target, in the most public forum imaginable.
What happened, day by day
The RIAA's letter arrived at GitHub on October 23, 2020, through the same channel that handles ordinary takedown demands, GitHub's takedown process treated a §1201 letter much like any other notice, and the repository was disabled within hours. Two things then happened that the RIAA could not control. GitHub published the letter, as its process does, so the full argument was public almost immediately. And the software stayed available: Git distributes complete history, every existing clone was a full copy, and mirrors appeared on other hosting services the same day. Removing the repository told millions of people the tool existed while removing almost nothing.
The reversal came on November 16, 2020. GitHub reinstated the repository, announced changes to how it handles takedown demands, and created a fund for developers facing similar letters. The maintainers got their code back with the commit history intact. The RIAA got a headline it never wanted.
Why the RIAA reached for §1201 instead of §512
The everyday takedown runs on 17 U.S.C. §512. A copyright owner identifies infringing material, a song file, a movie rip, a copied article, and the host removes it quickly, because prompt removal is what preserves safe harbor. The statute is built for stored content at identifiable URLs.
youtube-dl hosted no content. It is code: a general-purpose downloader that works with YouTube and many other sites. Code that could be used to infringe is not itself a copy of anything, so a §512 notice against the repository would have been legally empty. The RIAA instead invoked 17 U.S.C. §1201, the DMCA's anti-circumvention rules, which ban offering tools built to defeat technological measures that control access to copyrighted works. Rights holders like §1201 because it reaches the tool itself, requires no proof that anyone actually infringed, and carries no fair-use defense, fair use enters only through the narrow exemptions the Copyright Office grants in its triennial rulemaking.
The theory had precedent. In Universal City Studios v. Corley, the DeCSS case, the Second Circuit affirmed an injunction against a website posting DVD decryption code. But later decisions narrowed §1201. In Chamberlain v. Skylink, the Federal Circuit required a genuine connection between the circumvention and copyright infringement, a tool that helps people use content they are already entitled to use does not qualify, and the Ninth Circuit drew a similar line in MDY v. Blizzard. The RIAA's letter was about to hit that narrowing at full speed.
The rolling cipher claim, and where it broke
The letter rested on two pieces of evidence. One was what it called YouTube's "rolling cipher", a mechanism it characterized as a technical protection measure, which youtube-dl's code partially reproduced in order to request video streams. The other was the repository's automated test suite, which fetched three specific music videos to confirm the parsing code still worked.
The Electronic Frontier Foundation, writing to GitHub on the maintainers' behalf, dismantled both.
The cipher argument misread the technology. §1201 protects measures that control access to works. YouTube's signature mechanism decides which software may request a stream; it does not decide who may watch the video. Anyone with a browser could view the cited videos without defeating anything. A request-signing scheme gates the API, not the content, and the Sixth Circuit had already rejected a close cousin of this theory in Lexmark v. Static Control, holding that a printer's cartridge-authentication handshake was a use control, not an access control. Calling a signature a cipher does not make it one.
The test fixtures were weaker still. Automated tests that fetch known URLs are how engineers verify code after changes; they say nothing about what users do with the tool. As EFF pointed out, at least one of the videos the letter cited had even been released under a Creative Commons license. The labels had authorized the very reuse the notice treated as proof of circumvention.
Substantial non-infringing uses and the Grokster gap
Traditional secondary-liability law was never going to reach this tool either. In the Betamax case, the Supreme Court held that distributing technology with substantial non-infringing uses is not contributory infringement just because some users infringe. Grokster later drew the limit: a distributor who actively induces infringement loses that protection. Nothing about youtube-dl induced anything. It was a general-purpose downloader with visible lawful uses, archivists preserving at-risk videos, journalists quoting material, accessibility work that depends on retrieving caption streams, creators saving their own uploads, and works released under Creative Commons licenses.
One trap for readers: that logic does not directly answer a §1201 claim. §1201 has no fair-use defense; its safety valve is the exemption process, which covers narrow categories like security research and preservation. What actually beat the RIAA was technical, no access control was being broken at all, plus evidence that collapsed on inspection. The lawful-uses argument still mattered, because it explained the overreach to a general audience in one sentence and kept public opinion behind the project.
That cuts both ways. If you are filing, a tool with visible lawful uses is a poor target unless the statute genuinely fits. If you are defending, lead with your strongest ground, here, the absence of a real access control, not the argument that merely sounds best.
The backlash, the counter-notice problem, and the reversal
Developers understood the precedent immediately: if reimplementing a service's request format counts as circumvention, then browser extensions, archival tools, security research, and interoperability projects of every kind are exposed. Forks multiplied, mirrors circulated, and even members of Congress criticized the takedown publicly. For an organization whose enforcement history had already moved from lawsuits against individual uploaders to lawsuits against tools, this was the first time the whole software industry watched the argument lose in real time.
The reversal came through a channel the RIAA probably did not anticipate: review by the host. Because the letter invoked §1201 rather than §512, the statutory counter-notice did not apply, that procedure answers content claims, and what happens after a counter-notice is restoration in roughly ten to fourteen business days unless the sender sues. There was no equivalent lever here. EFF's letter gave GitHub grounds to reconsider, and GitHub used its own discretion: it reinstated the repository, stating that the letter's theory did not survive review, and announced two commitments, closer scrutiny of §1201 claims before any repository is disabled, and a $1 million developer defense fund to help developers pay legal costs in DMCA disputes.
No lawsuit followed. Downloads and forks surged, the Streisand effect at full force, and the letter produced the exact opposite of its goal.
What GitHub changed after the youtube-dl takedown
The policy changes outlasted the news cycle. GitHub's published takedown guidance now treats §1201 claims against code as a distinct category that gets heightened review before anything is disabled. The episode also reset expectations on both sides: developers learned that a host can re-examine a notice, and senders learned that a demand aimed at code will be read by engineers and lawyers, not just processed.
Two caveats follow. GitHub is not a typical host, it can afford counsel to second-guess a trade group's letter, and its community can make reversal thinkable. Most hosts, from shared web hosts to registrars, remove first and sort disputes later, because prompt removal is what safe harbor rewards. Outside the U.S., takedown duties differ, Canada runs a notice-and-notice system, and the EU now works through the DSA, but no regime promises that anyone will audit your claim. Build the claim to survive an audit rather than hoping one happens.
And assume publication. Notices end up in public archives and are often reposted in full. The RIAA's letter was read within days by thousands of people looking for a flaw; they found several.
Lessons for anyone filing a DMCA notice
Aim matters more than force. The largest failure in this case was target selection. Copied content belongs in a §512 notice with exact URLs; the full walkthrough is in how to file a DMCA takedown notice. A tool you dislike is not content, and stretching §1201 to cover it invites a public, technical rebuttal, the most damaging kind.
Tools are not content. A takedown notice reaches material: files, uploads, copies. It does not reach capability. Software that can be used to infringe is not infringing material, and treating it as such is the exact mistake that unraveled over three weeks in public.
Assess fair use before sending anything. In the dancing-baby case, the Ninth Circuit held that a rights holder must consider fair use before demanding removal, and §512(f) shifts costs and fees onto senders who knowingly misrepresent. There are real situations where you should not file at all.
File like it's a press release. Notices end up in public archives, journalists collect them, and ambitious claims attract exactly the readers most able to refute them. The RIAA cited a Creative Commons video as evidence of circumvention. Someone was always going to check.
Plan the next rung before you need it. Know what to do when a takedown is rejected before you file, not after a public loss. Refile with better evidence, contact the upstream provider, or escalate deliberately, but decide the sequence in advance.
If your own videos are the ones being downloaded
Nothing here weakens a creator's options, and that is worth stating plainly. Someone using a downloader on your video is not what the DMCA's everyday machinery addresses. That machinery targets copies, and copies remain fully reachable.
For reuploads on YouTube, start with the platform's rights tools. Content ID and Rights Manager catch copies at scale, and a filed takedown adds a strike against the uploader; our YouTube takedown guide covers the forms and the sequencing. For copies on other sites, a §512 notice to the host, exact URLs, your originals, ownership details, still works quietly every day. For chronic reposters, invoke the host's repeat-infringer policies: a platform keeps safe harbor only if it terminates accounts of repeat infringers, and a documented history of strikes is what activates that rule.
The tools are another matter. YouTube's terms prohibit downloading without permission, a contract rule, not copyright law, and whether a downloader implicates §1201 depends on how it works. As the RIAA demonstrated, litigating that in public is expensive, slow, and often counterproductive. Spend the effort where the law is strong: the copies.
Frequently asked questions about the youtube-dl takedown
Is youtube-dl still available on GitHub?
Yes. GitHub restored the repository on November 16, 2020, with its full commit history, and it has stayed up ever since. Development continues, and yt-dlp, a fork begun earlier that year, has grown even larger. No replacement notice took the original down.
Can a DMCA takedown remove software like youtube-dl?
Not through the ordinary process. Section 512 targets hosted copies of infringing material, and code that is not itself a copy of a protected work does not fit. Removing a tool takes a §1201 anti-trafficking claim, which must show the tool is primarily built to defeat an effective access control, a far harder case to make in public.
Why didn't the maintainers file a counter-notice?
The counter-notice belongs to §512: a user swears under penalty of perjury that material was removed by mistake, and the host generally restores it within ten to fourteen business days unless the sender sues. The RIAA's letter invoked §1201 instead, so that lever was unavailable. GitHub reversed its own decision after re-reviewing the notice.
Did the RIAA face any penalty when the notice failed?
No legal one. The misrepresentation provision in §512(f) attaches to §512 notices, and this was a §1201 demand outside that framework. The costs were reputational and strategic: the takedown publicized the tool worldwide, united developers against the theory, and pushed GitHub to harden its review of exactly this kind of claim.
What should I do if my videos are downloaded and reposted?
Target the copies, not the tool. File a §512 notice against each reposted URL, attaching your original URLs and proof of ownership, and use Content ID or Rights Manager for reuploads on YouTube itself. The youtube-dl episode limits nothing in that process, removals of infringing copies work today exactly as they did before October 2020.
What to do next
- Classify the target first. A hosted copy is a §512 problem with a proven solution; a tool is a §1201 problem with a poor track record. Think hard before choosing that fight.
- Build the evidence file: exact infringing URLs, your original URLs, proof of ownership, dated records. An evidence checklist keeps the notice complete on the first pass.
- Match the notice to the platform. YouTube has dedicated rights forms; a random host has an abuse desk. Read the process before you write.
- If you are handling it yourself, the DIY takedown walkthrough covers drafting, the required declarations, and submission.
- If a notice is rejected or the volume outgrows your time, the guide to choosing a DMCA takedown service explains what to outsource and when.
