Live data from Hacker News

How the UK's online safety bill threatens Matrix

matrix.org

141–150 of 165 posts

Re: How the UK's online safety bill threatens Matrix

#141

Earlier quoted context omitted.

> The legislation has clearly been dreamt up by folks saying “ah ha! if we threaten the Facebook UK executive mangement team with jailtime unless they do better at filtering self-harm/CSAM/terrorism/etc then they will obviously get their house in order!”. Whereas in practice they crush their own UK-based startups instead. So frustrating. Isn’t that exactly what the GDPR did? I know I pulled my apps for fear of fines…

GDPR really isn’t that complicated for most purposes - it boils down to: tell your users what data you store; let them delete their data if they want; let them export their data if they want. Which is not exactly unreasonable - the only scary thing was being obligated to do it by law with threats of fines if you didn’t. It wasn’t that hard to put together, particularly if you’re a normal centralised website or app th…

> GDPR really isn’t that complicated for most purposes

You're coming at it from a position of knowledge and confidence. The guide produced by the Information Commissioner's Office for organisations has 48 sections/pages [1] and features a toolkit with 7 different self assessment quizes [2], plus an extra one to help small businesses [3]. Even the "What is personal data?" section of the site alone contains dozens of pages [4]. And obviously the regulation itself is pretty verbose [5].

Given the legal ramifications, it's a bit dismissive to say it just boils down to three phrases. Whether or not GDPR is reasonable (and I agree that it is), it's perfectly understandable that sole traders and small businesses are concerned about the resources required to understand and implement it - especially when even many large organisations currently flout it (through ignorance or negligence).

[1] https://ico.org.uk/for-organisations/guide-to-data-protectio...

[2] https://ico.org.uk/for-organisations/sme-web-hub/checklists/...

[3] https://ico.org.uk/for-organisations/sme-web-hub/checklists/...

[4] https://ico.org.uk/for-organisations/guide-to-data-protectio...

[5] https://www.legislation.gov.uk/eur/2016/679/contents

Re: How the UK's online safety bill threatens Matrix

#142
post #12

Earlier quoted context omitted.

GDPR, or CCPA, isn't all that costly as long as you stop thinking of user data as something for you to harvest, mine, resell and profit from. If you instead treat user data like a security liability, system designs and trade-offs will flow from there. They'll help ensure you design systems that minimise collection and anonymise things early, remove data promptly when no longer needed, and make it easy to audit what d…

It's possible for you to be in violation of GDPR without "thinking of user data as something for you to harvest, mine, resell and profit from". If it's "killing a few companies" and "a startup doesn't end up seeing the light" then "GDPR is doing what I'd like it to do." That's a pretty shitty opinion to hold. What did those companies and startups do wrong? I'm as tired of stupid startups as the next person, but I won…

> What did those companies and startups do wrong?

Well for one, they ignored users and the authorities asking them to stop their illegal data collection. No company is getting "killed" or even fined at all when they are not actively refusing to get compliant.

Re: How the UK's online safety bill threatens Matrix

#143
No-one is mentioning that this bill will compel platforms to host content they do not want.

https://www.gov.uk/government/news/landmark-laws-to-keep-chi...

> All in-scope companies will need to consider and put in place safeguards for freedom of expression when fulfilling their duties. These safeguards will be set out by Ofcom in codes of practice but, for example, might include having human moderators take decisions in complex cases where context is important.

> People using their services will need to have access to effective routes of appeal for content removed without good reason and companies must reinstate that content if it has been removed unfairly. Users will also be able to appeal to Ofcom and these complaints will form an essential part of Ofcom’s horizon-scanning, research and enforcement activity.

Re: How the UK's online safety bill threatens Matrix

#144

Earlier quoted context omitted.

It's possible for you to be in violation of GDPR without "thinking of user data as something for you to harvest, mine, resell and profit from". If it's "killing a few companies" and "a startup doesn't end up seeing the light" then "GDPR is doing what I'd like it to do." That's a pretty shitty opinion to hold. What did those companies and startups do wrong? I'm as tired of stupid startups as the next person, but I won…

> What did those companies and startups do wrong? Well for one, they ignored users and the authorities asking them to stop their illegal data collection. No company is getting "killed" or even fined at all when they are not actively refusing to get compliant.

Especially in the UK where ICO hasn't taken any GDPR enforcement action for like 6 months.

Re: How the UK's online safety bill threatens Matrix

#145

Earlier quoted context omitted.

> The legislation has clearly been dreamt up by folks saying “ah ha! if we threaten the Facebook UK executive mangement team with jailtime unless they do better at filtering self-harm/CSAM/terrorism/etc then they will obviously get their house in order!”. Whereas in practice they crush their own UK-based startups instead. So frustrating. Isn’t that exactly what the GDPR did? I know I pulled my apps for fear of fines…

GDPR is pretty harmless and relatively easy to implement I think

What was particullary easy implementing GDPR for you?

I found some areas particullary hard. Legitimate interest is a minefild and mostly can't be used, except e.g. delivery addresses. Finding GDPR compliant companies - with the US out of question - was also hard. Tracking and deleting data on request when storing in dozens of systems was hard - even returning all the data stored in dozens of external SaaS companies was hard (logging what you send them helps here, but doesn't address their tracking generation). They often don't give you everything you store with them back - deletion is often much easier. Tracking data in backups that needed to be cleaned on restore due to deletion requests was difficult to implement - easy in one, complicated in dozens of systems. Especially hard with AWS.

These are the most challenging I had on hand when implementing GDPR.

Re: How the UK's online safety bill threatens Matrix

#146

Earlier quoted context omitted.

Here you have someone directly sentenced for not disclosing their password: https://www.bbc.com/news/uk-england-hampshire-45365464

I mean, we can be doing this back and forth for a while, but again, to quote from the article: "Judge Christopher Parker did not accept Nicholson's "wholly inadequate" excuse that providing his password would expose information relating to cannabis." So basically he said "I know the password, but I'm not going to tell you". That's obstructing justice. My point is if you say you don't remember and maintain saying you…

https://www.legislation.gov.uk/ukpga/2000/23/part/III

The police think Bob has material that they need to see.

They think that:

    The key, password, code is in the possession of the person given notice.
    Disclosure is necessary in preventing or detecting crime.
    Disclosure is proportionate.
    The protected material cannot be obtained by other reasonable means.
They serve a section 49 notice.

Bob can ignore this. But that means he may be guilty of an offence under S53.

One of the defences available is to say that he's not in possession of the key. He'd have to persuade the court that either He'd forgotten the key or your encryption was set up in a way that he'd never had the key in a memorable form.

> For the purposes of this section a person shall be taken to have shown that he was not in possession of a key to protected information at a particular time if—

> (a)sufficient evidence of that fact is adduced to raise an issue with respect to it; and

> (b)the contrary is not proved beyond a reasonable doubt.

So, to answer your question: yes, a person could be prosecuted, and they'd have to prove they forgot the key. The prosecutors wouldn't have to prove that the key had not been forgotten.

Re: How the UK's online safety bill threatens Matrix

#147

Earlier quoted context omitted.

But at least GDPR /is/ tractable to implement at small scale. Whereas for the OSB: if you run a smallish but popular chat/blog/forum/etc service, there literally isn’t a solution for moderation which isn’t fiendishly expensive, privacy invasive, or both. The legislation has clearly been dreamt up by folks saying “ah ha! if we threaten the Facebook UK executive mangement team with jailtime unless they do better at fil…

> The legislation has clearly been dreamt up by folks saying “ah ha! if we threaten the Facebook UK executive mangement team with jailtime unless they do better at filtering self-harm/CSAM/terrorism/etc then they will obviously get their house in order!”. Whereas in practice they crush their own UK-based startups instead. So frustrating. Isn’t that exactly what the GDPR did? I know I pulled my apps for fear of fines…

It's very easy to make a checklist for GDPR compliance.

For the proposed content moderation it is pretty much impossible.

It's kinda like making a law that says you cannot make inappropriate jokes in front of the police. Who the hell gets to decide what is inappropriate? It's intentionally left vague to make everyone guilty and allow for selective enforcement.

Re: How the UK's online safety bill threatens Matrix

#148

Earlier quoted context omitted.

GDPR really isn’t that complicated for most purposes - it boils down to: tell your users what data you store; let them delete their data if they want; let them export their data if they want. Which is not exactly unreasonable - the only scary thing was being obligated to do it by law with threats of fines if you didn’t. It wasn’t that hard to put together, particularly if you’re a normal centralised website or app th…

> GDPR really isn’t that complicated for most purposes You're coming at it from a position of knowledge and confidence. The guide produced by the Information Commissioner's Office for organisations has 48 sections/pages [1] and features a toolkit with 7 different self assessment quizes [2], plus an extra one to help small businesses [3]. Even the "What is personal data?" section of the site alone contains dozens of p…

Okay, fair enough - I agree that GDPR is certainly scary and daunting. But once you get past that, it is still something that can practically be implemented by small businesses, and generally improves things for users.

My whole point here is that the Online Safety Bill cannot be practically implemented by anyone other than massive businesses, and even then it implicitly requires massive privacy violations. Which puts in a completely different class of problem to implementing GDPR.

Re: How the UK's online safety bill threatens Matrix

#149

> Whilst we sympathise with the government’s desire to show action in this space and to do something about children’s safety (everyone’s safety really), we cannot possibly agree with the methods. Respectfully, stop sympathising with authoritarians who want to take away your freedom. They are not good people. Good people aren't nosey. Good people don't deprive others of liberty. Neither do they class a whole group (In…

Yeah, this is clearly a case where the harm far exceeds the damage being prevented and this isn't even considering second order effects. If everyone starts circumventing government controls then real criminals will have an easier time to hide in the crowd, it's entirely plausible for this to cause more abuse of children.

Where are all the UK politicians that actually care about their people?

Re: How the UK's online safety bill threatens Matrix

#150

I realize this is about the least popular opinion you can express on HN, but I really strongly dislike the lack of engagement with the issue here. Online abuse, of all varieties, including sexual abuse, including of children, is not a boogieman. It is not marginal. It is not so rare as to be a rounding error. It is not enough for you, personally, to not want to partake in it. A person is not bad, or evil, or morally…

In that case we should stop the online safety bill entirely because it will only end up with more child abuse in the end!
Post reply on HN