Live data from Hacker News

230, or not 230? That is the EARN IT question

signal.org

141–150 of 178 posts

Re: 230, or not 230? That is the EARN IT question

#141
post #136

I used the EFF form linked in the blog post to contact my representatives in California. I will also donate to EFF again. Privacy is important.

I did the same a few weeks ago. Here's the automated response from Feinstein's office:

> Dear [Name]:

> Thank you for writing to me to share your concerns about law enforcement access to encrypted communications. I appreciate the time you took to write, and I welcome the opportunity to respond.

> I understand you are opposed to the “Eliminating Abusive and Rampant Neglect of Interactive Technologies (EARN IT) Act of 2020” (S. 3398), which I introduced with Senators Lindsey Graham (R-SC), Richard Blumenthal (D-CT), and Josh Hawley (R-MO) on March 5, 2020. You may be interested to know that the Senate Judiciary Committee—of which I am Ranking Member—held a hearing on the “EARN IT Act” on March 11, 2020. If you would like to watch the full hearing or read the testimonies given by the hearing witnesses, I encourage you to visit the following website: https://sen.gov/53RV.

> The “EARN IT Act” would establish a National Commission on Online Sexual Exploitation Prevention to recommend best practices for companies to identify and report child sexual abuse material. Companies that implement these, or substantially similar, best practices would not be liable for any child sexual abuse materials that may still be found on their platforms. Companies that fail to meet these requirements, or fail to take other reasonable measures, would lose their liability protection.

> Child abuse is one of the most heinous crimes, which is why I was deeply disturbed by recent reporting by The New York Times about the nearly 70 million online photos and videos of child sexual abuse that were reported by technology companies last year. It is a federal crime to possesses, distribute, or produce pictures of sexually explicit conduct with minors, and technology companies are required to report and remove these images on their platforms. Media reports, however, make it clear that current federal enforcement measures are insufficient and that we must do more to protect children from sexual exploitation.

> Please know that I believe we must strike an appropriate balance between personal privacy and public safety. It is helpful for me to hear your perspective on this issue, and I will be mindful of your opposition to the “EARN IT Act” as the Senate continues to debate proposals to address child sexual exploitation.

> Once again, thank you for writing. Should you have any other questions or comments, please call my Washington, D.C. office at (202) 224-3841 or visit my website at feinstein.senate.gov. You can also follow me online at YouTube, Facebook and Twitter, and you can sign up for my email newsletter at feinstein.senate.gov/newsletter.

> Best regards.

> Sincerely yours,

> Dianne Feinstein

> United States Senator

I don't know why I still bother.

Re: 230, or not 230? That is the EARN IT question

#142

I thought it was interesting when Twitch partners started talking about a Twitch policy that seems to hold the partner responsible for moderating their own chat. That is, if you are a partner and you have community members posting prohibited content into your Twitch chat then you stand to pay the penalty through a ban or losing your partnership. You are forced to moderate your own chat thereby relieving Twitch of hav…

Up until very recently, Twitch's moderation tools have been total garbage. I can only assume that they put the chat moderation stuff into their partner contract so they can get rid of undesirable partners easily. "We hate you, and here is a message that your moderators missed so buh bye." I also think that partners are well aware of the possibility of Twitch getting rid of them at any time with no recourse; this is w…

> I also think that partners are well aware of the possibility of Twitch getting rid of them at any time with no recourse; this is why they heavily advertise their social media, Discord, and YouTube channels.

I believe this is just good self-marketing, not paranoia. If you're a content creator in today's age, you're going to be trying to get traction on every major platform. It's like in SEO, make sure all your site pages are linked to each other, aka "Make sure people can access all relevant content". It's a way to increase retention and traction, not a fail-safe for being banned.

Re: 230, or not 230? That is the EARN IT question

#143
post #139

> At a high level, what the bill proposes is a system where companies have to earn Section 230 protection by following a set of designed-by-committee “best practices” that are extraordinarily unlikely to allow end-to-end encryption. As diligently stated by Signal, EARN IT makes end-to-end encryption difficult, but not impossible. All relevant companies would like to prevent having to transition their current architec…

So the "best practices" under EARN IT are to be made by a committee of law enforcement agencies, with no congressional oversight.

What's your point?

Re: 230, or not 230? That is the EARN IT question

#144
post #139

Earlier quoted context omitted.

So the "best practices" under EARN IT are to be made by a committee of law enforcement agencies, with no congressional oversight.

What's your point?

Sorry, I could have stated this clearer. The point is that it basically gives law enforcement an extremely broad hammer for forcing service providers to design their systems however they want to help law enforcement, over their users. It would in practice make end-to-end encryption impossible to implement, not just difficult.

Re: 230, or not 230? That is the EARN IT question

#145
post #131

Earlier quoted context omitted.

> This misses the point, just because someone sometimes added me to their phone contacts and uses signal does not mean I want them notified when I start using signal too. It sounds like Signal is trying to solve a different problem than the one you have, so you should probably look for a different solution. IIRC, Signal's goal is easy to use mass-market E2E encrypted replacement for SMS messaging. If they didn't auto…

I can see how this would violate expectations if you installed it for one especially sensitive interaction. "Look at me, I'm doing tradecraft now!"

Perfect, meet Good, your mortal enemy.

Re: 230, or not 230? That is the EARN IT question

#146

Earlier quoted context omitted.

This is a hard problem. The evidence for this is the decades of failed attempts to get people to use pgp and other systems where I need to have a freaking party in order to figure out who I can message and how before I actually start communicating.

I would argue that's a failure of pgp, not sharing in general. People have less resistance to easy to use apps like whatsapp, riot, etc versus something like pgp.

WhatsApp piggybacks off phone contact lists and has several orders of magnitude more users than riot.

Re: 230, or not 230? That is the EARN IT question

#147
post #144

Earlier quoted context omitted.

What's your point?

Sorry, I could have stated this clearer. The point is that it basically gives law enforcement an extremely broad hammer for forcing service providers to design their systems however they want to help law enforcement, over their users. It would in practice make end-to-end encryption impossible to implement, not just difficult.

I see what you mean. That made me wonder what type of approach they would take for something that can vary so much and here’s what I found:

“EARN IT works by revoking a type of liability called Section 230 that makes it possible for providers to operate on the Internet, by preventing the provider for being held responsible for what their customers do on a platform like Facebook. The new bill would make it financially impossible for providers like WhatsApp and Apple to operate services unless they conduct “best practices” for scanning their systems for CSAM.

Since there are no “best practices” in existence, and the techniques for doing this while preserving privacy are completely unknown, the bill creates a government-appointed committee that will tell technology providers what technology they have to use. The specific nature of the committee is byzantine and described within the bill itself. Needless to say, the makeup of the committee, which can include as few as zero data security experts, ensures that end-to-end encryption will almost certainly not be considered a best practice.”

It seems that it would be in the best financial interests of large tech companies to try and revoke the bill if it’s passed. This is why I believe it will quickly be brought to the Supreme Court.

[0] https://blog.cryptographyengineering.com/2020/03/06/earn-it-...

Re: 230, or not 230? That is the EARN IT question

#148
post #118

Earlier quoted context omitted.

> I think it's simple. The US postal service uses postal inspectors to try and identify packages containing narcotics[0], and yet we don't make them liable for the packages they miss. Any attempt to moderate undesirable content on a website should not then make you liable for the content you miss. > [0]: https://www.uspis.gov/about/what-we-do/ Then what about sites that would use this to their advantage and half ass…

If you're ignorant or malicious the same thing happens: the government kindly informs you that someone is using your website to break the law, and then you can either do something or become clearly guilty of knowingly supporting them. (The government knows you know because they know they told you.)

They fix that case swiftly, then go on to ignore new cases?

Re: 230, or not 230? That is the EARN IT question

#149

Earlier quoted context omitted.

Up until very recently, Twitch's moderation tools have been total garbage. I can only assume that they put the chat moderation stuff into their partner contract so they can get rid of undesirable partners easily. "We hate you, and here is a message that your moderators missed so buh bye." I also think that partners are well aware of the possibility of Twitch getting rid of them at any time with no recourse; this is w…

> I also think that partners are well aware of the possibility of Twitch getting rid of them at any time with no recourse; this is why they heavily advertise their social media, Discord, and YouTube channels. I believe this is just good self-marketing, not paranoia. If you're a content creator in today's age, you're going to be trying to get traction on every major platform. It's like in SEO, make sure all your site…

It can be both.

Re: 230, or not 230? That is the EARN IT question

#150
post #63

Earlier quoted context omitted.

OK, so please do tell me how to sue `sk8rboy2020` on the forum then?

How do you sue the guy that shouted at you as they left the restaurant? Who stuck a defamatory sign on the electric pole? I don't see why the issues these present should move responsibility to the restaurant or electric company, however.

A better analogy is a community bulletin board, like at a library.

Just thinking aloud, what would I expect if my library’s bb was always covered in hate speech? Probably that the librarian would put it behind locked glass and moderate posts. Or take it down altogether. I’d hope for the former.

Post reply on HN