30 points jmpman 1 day ago 14 comments

I have a self playing piano, using a system called PianoDisc Protigy. They have an online store which sells music for their system, from various modern artists along with classics such as Bach and Beethoven. Last night I saw they had released some music from Eric Satre, a 19th century French composer, which I bought. Curious if I could have just used AI to create these files, I began experimenting with Astra and Fable. Feeding the output of one into the other to critique. After an hour of LLM discussion of Rubato and fermata, solenoid response times and proper sustain pedal technique, they settled on their ultimate version of Gymnopedie No 1.

I then asked Fable to compare it to the open source version I'd downloaded from Mutopia, which it promptly ripped apart. No sustain, zero rubato, upside down balance.

Ok, what about the version I'd just bought?

The PianoDisc versions are mp3s encoded with the right channel carrying MIDI to be played on the piano, and the left channel containing any accompanying music to be played through attached speakers (who doesn't want the harmonica on Piano Man?)

I gave the mp3 to Fable, which promptly decoded the format, identifying the right channel carrying MIDI using a 2004.5 Hz square wave.

It then went on to analyze the nuance of pedal lift and melody relative to the chords.

Fable then asked if I wanted it to build an encoder to write my own MIDI files into the right channel of mp3s.

Sounds great, and I instructed it to write the encoder.

What it came back with was a python encoder PLUS a decoder.

In the verbose explanation, it mentioned decoy notes.

Curious, I asked it to explain the decoy notes.

Apparently PianoDisc adds obfuscation into their format which is handled properly by their decoder, but would leave naively extracted MIDI unplayable on other systems.

Fable created an encoder which adds those decoy notes, and a decoder which removes them.

Am I allowed to publish the decoder? The encoder?

Redster 1 day ago | parent

IANAL, but it might be relevant to others trying to answer what jurisdiction you are in. (US, EU, CN, JP, elsewhere?)

Also, when you bought from PianoDisc, did you agree to abide by a certain jurisdiction's laws in your use of PianoDisc? And did you explicitly agree to not share any sort of decoder/encoder in any ToS?

jmpman 20 hours ago | parent

US.

https://store.pianodisc.com/pages/terms-of-service-and-condi...

I don't see details about them mentioning and decoder or encoder.

codingdave 11 hours ago | parent

> (k) to interfere with or circumvent the security features of the Service

IANAL. But I think reverse engineering their data structure, identifying a security measure - even one as weak as obfuscation, and publishing code to circumvent it is clearly against your license.

Elsewhereindeed 26 minutes ago | parent

I am also NAL, but out of curiosity does OPs post detailing the obfuscation transgress any laws?

If the security measures exist in plain sight, as they apparently do, are they allowed to be discussed?

I reckon that if OP posts the encoder/decoder software that'd be against some sort of license clause. However in the age of AI who cares about the software at this point? Anyone can prompt their own private version into existence.

Just thinking out loud here. I have not considered AIs use as personal "cheat engines".

brudgers 1 day ago | parent

You are free to interpret this comment as prohibition or as my blessing, but...

If it matters, ask your lawyer.

If it doesn't matter, it doesn't matter.

Or to put it another way, trademarks (you've mentioned two) and copyrights (it's a crapshoot) are complex. And in some jurisdictions (notably the US) anybody can sue anyone for anything.

Your risk aversion is yours, not someone else's. Your financial and legal wherewithal is likewise yours.

jmpman 20 hours ago | parent

I might just email the company. If they object, I won't make my GitHub repo public.

brudgers 9 hours ago | parent

They might object to the existence of the software and demand “its destruction.”

Or sue your ass…or file a DCMA takedown with Github.

Or all of the above.

The best likely outcome is probably “no.”

Because they have lawyers and that’s what lawyers do.

If you really really want to share the information, you might write a blog post with technical details without linking to any code. Sharing the blog to the “Facebook group” will let you assess community and corporate interest and make an informed decision.

Keep in mind that they could say yes and still do all that bad stuff anyway.

ungreased0675 59 minutes ago | parent

This seems like the worst possible advice. It will only bring negative attention and maybe legal repercussions.

georgemcbay 9 minutes ago | parent

> I might just email the company. If they object, I won't make my GitHub repo public.

If you do this, I can nearly guarantee they will either never respond as a best case scenario, or they will object.

There is effectively zero chance a company would give you any indication that you have their blessing. Even if they don't actually care one way or another they will make the assumption that giving you any kind of positive response is nothing but a negative for themselves in terms of future liability, etc

The phrase that it is "better to ask for forgiveness than permission" exists because of situations like the one you're in.

Just publish the repo. Don't contact them. If they C&D you, take it down if you don't want to deal with the legal repercussions.

NegativeLatency 50 minutes ago | parent

Personally I’d just do it

xgulfie 45 minutes ago | parent

I'm your lawyer, you should do it

arjie 44 minutes ago | parent

The nature of these tools is that your post and the device should suffice to replicate so in some sense you have already published the encoder and the decoder.

Giefo6ah 22 minutes ago | parent

If you live in the USA, the "decoy notes" may be considered an "effective technical measure" from the "Digital Millennium Copyright Act".

If you live in Europe, this restriction may be considered "gatekeeping" and exempted by the Digital Markets Act.

Don't bring attention to yourself by asking for permission. Publish your codec, and if the company cares about this they will send a cease and desist.

If you want the world to benefit from your code but you don't want to be responsible for it, try to adapt the codec to ffmpeg. The ffmpeg project is used to dealing with these matters, and will keep your codec working for eternity.

franky47 21 minutes ago | parent

typo: did you mean Erik Satie?

https://en.wikipedia.org/wiki/Erik_Satie