Synopsys, Inc. v. Ubiquiti Networks, Inc. was a lawsuit in the United States District Court for the Northern District of California, filed on 3 February 2017, in which electronic design automation (EDA) vendor Synopsys alleged that Ubiquiti Networks, its Hong Kong subsidiary Ubiquiti Networks International Limited (UNIL) and a Ubiquiti employee obtained evaluation licences for Synopsys software and then used counterfeit licence keys to run it without a valid licence.[1] Synopsys relied on “call-home” or “phone-home” data that its software transmitted, which it said showed counterfeit keys had been used more than 39,000 times.[2] The Ubiquiti companies counterclaimed that this monitoring was undisclosed “spyware”.[3] The parties settled in January 2019, and the court entered a consent judgment and permanent injunction against the Ubiquiti companies.[4][6]
Background
Synopsys licenses EDA applications, used to design and verify semiconductor chips, and controls access with a “License Key” system.[1] According to the allegations summarised by the court, a Ubiquiti project lead told Synopsys in September and October 2013 that Ubiquiti wanted to license several Synopsys tools. The parties signed a master non-disclosure agreement (MNDA), and on 26 November 2013 Synopsys granted Ubiquiti a 90-day, non-transferable evaluation licence for its VCS application on two computers in San Jose. In April and May 2014 Synopsys gave UNIL temporary keys for other tools, each limited to one or two concurrent executions on servers with specific host IDs and expiring in two to four weeks.[1]
Synopsys alleged that from 2014 the defendants used counterfeit keys “obtained or created through hacker websites” to run fourteen Synopsys applications at unauthorised locations, associated with at least 15 user names. It said it discovered the use in March 2016 and sent a cease-and-desist notice in May 2016.[1]
The dispute
Synopsys’s claims
The amended complaint pleaded three claims under the anti-circumvention provisions of the Digital Millennium Copyright Act (DMCA), 17 U.S.C. § 1201(a)(1), (a)(2) and (b), together with claims under the federal counterfeit labels statute, fraud, civil RICO and negligent misrepresentation.[1] The core claim, which Ubiquiti did not move to dismiss, was that using counterfeit and illicit keys circumvented a technological measure controlling access to copyrighted software.[1] Synopsys amended its complaint a third time in June 2018.[7]
Phone-home evidence
A magistrate judge’s discovery order described how the evidence was gathered. According to Synopsys, its software transmits basic information about computers using counterfeit keys, such as MAC addresses, IP addresses and server host names. Ubiquiti said only 626 of the roughly 39,000 recorded events came from United States IP addresses and the rest from Taiwan, so most of the conduct was outside the reach of US law. Ubiquiti acknowledged that it had installed the software on servers in Taiwan that employees reached remotely, and that the call-home data then reported the server’s host name, user account and location rather than the employee’s own computer. The court held that the Taiwanese computers were not outside the scope of discovery merely because of where they were located.[2]
The customer’s counterclaims
Ubiquiti counterclaimed for a declaration that mere use of the software, apart from any use of counterfeit keys, was not circumvention, and for breach of the MNDA.[1] UNIL later added claims under the Computer Fraud and Abuse Act (CFAA), California’s computer data access law, trespass, conversion, RICO and fraud. It alleged that Synopsys, with two related licence-compliance companies, placed undisclosed phone-home “spyware” in its products, collected IP and MAC addresses, user names, host names and other information, and used it to pressure suspected unlicensed users to pay licence fees. The Ubiquiti companies said they learned of this in May 2016, when one of those companies emailed Ubiquiti’s chief executive as Synopsys’s agent.[3]
Synopsys responded with evidence that anyone downloading its software had to click through a notice that “Licensed Products communicate with Synopsys services for the purpose of … detecting software piracy and verifying that customers are using Licensed Products in conformity with the applicable License Key”.[3]
Decision or outcome
In August 2017 the court dismissed the counterfeit labels claim and some of the RICO predicate acts, but otherwise let the DMCA, fraud and RICO claims proceed, refused to strike Synopsys’s defences to the counterclaims, and held that it had personal jurisdiction over UNIL because UNIL had fraudulently accessed software held on servers in California.[1]
In March 2018 the court dismissed UNIL’s counterclaims with leave to amend and refused Ubiquiti leave to add the same claims, as futile. It accepted that a vendor that uses hidden software to obtain information it is not entitled to could in principle “exceed authorized access” under the CFAA, even though the customer installed the software voluntarily. The claims failed because the companies had not pleaded at least USD 5,000 of loss beyond the cost of defending Synopsys’s claims, any impairment of their systems, or any economic value in the information collected; and the court found their fraud theory “implausible”. It declined to rule on the click-through notice at that stage, because the notice was evidence outside the pleadings.[3]
By late 2018 the parties had filed motions for summary judgment, sanctions for spoliation and exclusion of experts, and a jury trial was being prepared.[7] On 17 January 2019 the parties notified the court of a settlement.[4] On 24 January 2019 the court dismissed all claims and counterclaims with prejudice, each party bearing its own costs.[5] The consent judgment permanently enjoins Ubiquiti and UNIL from “accessing, using, distributing or selling any Synopsys products”, including licence key files, “without a valid license”, requires them to return Synopsys materials defined in a confidential settlement agreement, and keeps the court’s jurisdiction to enforce it.[6] The financial terms were not filed.
Significance for software licensing and SAM practice
The case was resolved without a judgment on the merits, so the rulings are pre-trial decisions of a single district court. They are still a detailed public record of how a vendor builds an unlicensed-use case from telemetry:
- Licence keys as access controls. The vendor treated running its software with counterfeit keys as DMCA circumvention, a claim the customer did not move to dismiss, and which sits alongside contract and copyright remedies.[1]
- Evaluation licences are narrow. The evaluation grants were limited by product, host ID, location, number of concurrent executions and duration.[1]
- Telemetry is evidence. Call-home data supplied the count of 39,000 events, but because it reported server rather than user details, the parties disputed where the use took place.[2]
- Monitoring disclosures. The dispute over undisclosed monitoring turned partly on a click-through notice in the download terms, which the court did not resolve.[3]
Lessons learned
- Using cracked or counterfeit licence keys can be pleaded as circumvention under the DMCA, separate from ordinary over-use. Synopsys’s section 1201(a)(1) claim was not challenged on the pleadings and was part of the case that ended in a permanent injunction.[1][6]
- Licensed software may report usage, host and user data to the vendor, and that data can become the vendor’s evidence. Synopsys’s download terms described communications used for “detecting software piracy”, and its case rested on that data.[2][3]
- Phone-home data records the server where software runs, not necessarily where the user sits. Both parties accepted that remote access to Taiwanese servers produced Taiwanese host and IP details even for a user in the United States.[2]
- Counterclaims attacking a vendor’s monitoring need concrete harm; they were dismissed here for failure to plead loss. The court required facts showing at least USD 5,000 of loss beyond the cost of defending the vendor’s claims.[3]