Live data from Hacker News

Disapproval of FCC regulations a significant blow against privacy protection

nytimes.com

171–180 of 242 posts

Re: Disapproval of FCC regulations a significant blow against privacy protection

#171
post #146

Earlier quoted context omitted.

The Supreme Court recognized on multiple occasions that we have a right to privacy. In this specific instance, protecting privacy comes at no cost to an ISP, as they simply do not collect or sell your data. They literally have to do nothing, as setting up the systems to collect and opening the channels to sell takes work. This nothnig more than money grab.

> The Supreme Court recognized on multiple occasions that we have a right to privacy. The right to privacy... from the government, not private businesses. There are privacy regulations which affect private business such as HIPAA. But these are not 'rights'. And just because they are regulated doesn't mean they are effective at the intended or worth the significant costs of implementation - which is the critique here.…

The first part you're correct about, so no argument there.

The second part sounds like a "private, free market" solution, which has had, at best, limited results. What's to prevent an ISP from simply prohibiting customers from using a VPN? If Netflix and Hulu can do this, why not Spectrum or Comcast? Your claims about ad-blocking can be used against you since there are companies that will prohibit you from using an ad blocker.

This is exacerbated by the fact that in many areas, there is only one ISP available, so there is no free market. Additionally, these companies will use any means to slow down or stop competition, so that's not an option. In this case, the government is the only organization that can effectively regulate these companies.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#172

Earlier quoted context omitted.

A better analogy would be FedEx selling your incoming and outgoing addresses and package weights to third parties, not necessarily the contents of your packages.

Why not the contents? What happens when most content is not over a secure connection such e.g. Over HTTP? Could they not inspect the content? It sure seems like they could. For most people most of the internet is still insecure.

They can and do. I recall instances where some ISPs even went so far as to inject advertising HTML directly into pages sent over HTTP.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#173
post #75

I want a privacy first router. Does such a product exist? Key features: - I pay a subscription for maintenance (so I'm not the product) say $10/mo - Automatically routes all traffic over a VPN. - Smart VPN bypass for performance-sensitive traffic like streaming video and gaming - Provides non-logging DNS service - Automatic advertisement blocking For VPN, DNS, and adblock I want the option to use servers & block list…

> I'm confident the maintenance hassle will eventually outweigh my desire for privacy. Nothing should outweigh your right for privacy.

Privacy is weighed against public safety all the time. The question is at which point does it become unreasonable. Warrantless searches of American individuals just so happens to be where we, as Americans, draw the line.

On the other hand, don't mistake my assault on the technical validity of your sentence for disagreement with its intent. We should be outraged.

Shame on us for having allowed this to happen, and for the dangerous precendent it sets for local monopolies to sell your information.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#174
post #170

If engineers would refuse to implement privacy invasions, they wouldn't happen. Do you work for Comcast, Verizon, AT&T, Time-Warner, CenturyLink, Charter, Cox, Frontier? Don't implement these things. Don't do deep packet inspection, don't log things that shouldn't be logged, don't put in MITM proxies and don't insert cookies in traffic that your customers expected to have unmolested. Explain your decision, and explai…

> If engineers would refuse to implement privacy invasions, they wouldn't happen.

That'll never work, as long as it's just a personal ethical thing. There's always someone who would rather take the money.

Now, if there was a professional organization or union with some teeth, which could enforce some kind of ethical code, then maybe "engineers" could do something about stuff like this. I'm not sure how it would work in detail, but it might involve pickets/walkouts of entire organizations engaged in unethical projects or expelling members who work on them in a way that negatively affects their future job prospects.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#175
post #74

Earlier quoted context omitted.

> I don't see how it's being blown out of proportion Really? Where was all the hyperventilating about the status quo on HN prior to when the protection was put in place? That's all I'm getting at, the reaction to being back in the dark ages of late 2016 seems a bit overblown in my opinion.

The ftc was the protection prior to the fcc. Now there is no protection. This is a regression.

FTC can still regulate ISP's after this bill passes, if I understand it correctly.

Edit: Nope, apparently this just nullifies the FCC rule, it's not an actual bill to change authority away from FCC. D'oh.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#176

Earlier quoted context omitted.

However, this headline is patently false, right? Congress didn't sell anything. They removed protections that were put into place late last year and hadn't gone into effect as far as I know. It's nearly impossible to find even one constituent who wrote to their Congresspeople asking for this law to be axed. It was a handful of lawmakers in Congress who accepted bribes, payments[1], and other kinds of lobbying from te…

I see where your argument is coming from. Lobbyists give money to politicians who push legislation that favors lobbyists. In a sense that could be construed as a 'sale'. But if we accept that premise, even in that case the only thing that was sold was the potential to infringe on privacy, not privacy itself. Congressional Republicans don't own my privacy. They can certainly make it easier for me to protect my privacy…

Yes, I don't think you should take the headline that literally - there's a touch of abstraction there. More literally, Congressional Republicans sold telcos a convenient legal avenue to violate your privacy. They didn't "possibly" make it harder... they added a massive new burden to your life if you care about your privacy. Read the other comments in this thread -- see how complex and incomplete the countermeasures seem to be, even for techies?

There are many ways the government protects your privacy such that you don't have to worry about it in X scenario. The Republicans sold one of those protections and added a new scenario to the list of things you have to worry about. The headline is pretty appropriate in context.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#177

Earlier quoted context omitted.

However, this headline is patently false, right? Congress didn't sell anything. They removed protections that were put into place late last year and hadn't gone into effect as far as I know. It's nearly impossible to find even one constituent who wrote to their Congresspeople asking for this law to be axed. It was a handful of lawmakers in Congress who accepted bribes, payments[1], and other kinds of lobbying from te…

Given that it's illegal for corporations to donate to candidates, I find your reference rather suspect.

I know that you know campaign finance is more nuanced than that.

It's perfectly legal for a corporation to donate to a Super PAC supporting candidate's reelection efforts.

And they're adding donations from individuals in the industry.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#178

Earlier quoted context omitted.

For the nerds among us this shouldn't be too hard. A Virtual Private Server can be rented for a few dollars a month. I have seen examples that charge less than $4 for unlimited bandwidth. Install VPN software on the server and become your own VPN provider. On your home router you can setup a point-to-point VPN connection and you're done - all traffic encrypted and bypassing your local telco. I assume that network-pro…

Mind divulging on some VPS providers? The one I've been looking at closely is https://www.vultr.com/ Their $2.50/month plan fits me well as my monthly traffic across all my devices (and home) is roughly 100GB. Pair that with https://github.com/trailofbits/algo and it's a reasonable setup.

I'm a fan of RamNode. I've been using them since they launched a few years ago without a hiccup.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#179
post #127

Earlier quoted context omitted.

> Oh how nice of Tom Wheeler to play the good-guy now. It took a lot of public outcry for him to change his tune about Net Neutrality. That's wrong. He was for net neutrality from day one at the FCC. You are probably thinking of the first net neutrality rule he proposed, which would have allowed for paid fast lanes, and interpreting that as somehow not being for net neutrality. When he proposed that rule that was abo…

> You are probably thinking of the first net neutrality rule he proposed, which would have allowed for paid fast lanes That was the second; the first he got passed did not, but it was struck down by the courts for exceeding the power the FCC had without Title II reclassification. The draft of the replacement might have allowed paid prioritization (it was clearly not intended to, but it was limited because it attempte…

The one that got struck down was passed before Wheeler was on the FCC.

Re: Disapproval of FCC regulations a significant blow against privacy protection

#180

Earlier quoted context omitted.

Three problems here. First being that the ISP is a permanent MITM. Second is that TLS will not protect the hostnames, which are sent in the clear so that servers can identify the correct certificate for a given connection. Likewise, DNS is not encrypted (though companies like OpenDNS do provide alternatives here).

Regarding the MITM, more specifically i meant able to compromise HTTPS. If i sit between you and your https site, can i read all of your traffic? I know very little about the nitty gritty of HTTPS, so forgive my ignorance, but i thought the most i could do was try to pass off a custom key (ie, spoof the key authority), but then the signing done from the https site (say, https://google.com ) wouldn't be valid based on…

It's not likely that they would attempt active attacks to decrypt your TLS web traffic. I'd assume they won't be able to read the full contents of those sessions.

STARTTLS on mail is a slightly different story, though I'm going to assume that most of the established compaines are smart enough fo avoid email snooping.

You might, however, be surprised at how much you give away via the metadata associated with your web browsing.

Post reply on HN