Live data from Hacker News

The EARN IT act is back, and it’s more dangerous than ever

cyberlaw.stanford.edu

161–170 of 520 posts

Re: The EARN IT act is back, and it’s more dangerous than ever

#161
post #149

I know it's wildly off-topic but can someone please explain to me why there are still sites like this that are clearly well funded and professional that fail to have spent - what - 2-3 designer hours time ($150?!) on a simple mobile stylesheet? They almost definitely get 50%+ mobile traffic. What gives?

[deleted]

Re: The EARN IT act is back, and it’s more dangerous than ever

#162
post #49

Earlier quoted context omitted.

Until that becomes illegal. After all, torrent indexes are illegal, and they aren't directly pirating anything. Thus, supporting an end around, can be attacked as well..

Torrent indexes are illegal, and yet a lot of them exist very publicly. Pushing e2e encryption into the same category as them does not seem very effective.

The goal is to reduce common usage ; to make all which use encryption a criminal.

Re: The EARN IT act is back, and it’s more dangerous than ever

#163

Earlier quoted context omitted.

Edit: See thread below, the EARN IT act does not in any way reclassify the designation of social media companies under section 230 or solve the issues mentioned in this post with 230. The change to 230 just provides exceptions for CSAM. However, keep reading if you want background on 230 and why many people are trying to change it. I want to provide some background on section 230 which the EARN IT act proposes to ame…

EARN IT is tightly focused on the perceived issue of CSAM material, exploitive "grooming" of minors via the Internet, and the like. It would do zilch to incent large social media companies against using algorithms that implicitly promote outrage-inducing content, much of it naturally being fake news and misinformation. It would also make it harder for smaller, more independent actors to counter these dynamics - becau…

You are right. I just read the bill. I believe 230 needs to be amended and that the damage it provides is real. But, the EARN IT act does not fix that. I do think it's important for people to understand why 230 is bad. But again, this act does not remove the designation as an "interactive computer service." It just provides exemptions for CSAM. I added an edit up top.

When I read in the article:

> the EARN IT Act would, if passed, pare back online service providers’ broad immunity under a federal law called Section 230, exposing them to civil lawsuits and state-level criminal charges for the child sexual abuse material (CSAM) posted by their users.

I assumed it was reclassifying social media companies, which would have broad implications, under the stated purpose of CSAM. I wanted to provide background on why 230 should be changed, not on the content of EARN IT. But I agree it conflates two separate things.

Here is the bill for anyone else that wants to read it.

https://www.congress.gov/bill/117th-congress/house-bill/6544...

Re: The EARN IT act is back, and it’s more dangerous than ever

#164
post #73

Earlier quoted context omitted.

Sort of. Look up Western Unions role in the 1876 US election[1]. Stolen communications to support a specific candidate and a compromise between political parties on military presence sounds like a very precarious position for free society to be in. [1] https://arstechnica.com/tech-policy/2011/05/how-the-robber-b... (also referenced in Tim Wu’s The Master Switch)

One way to look at it then is that we have dealt with similar issues before and survived.

Not really. I mean logically would you also play Russian roulette repeatedly with no payout just because you haven't died yet?

Re: The EARN IT act is back, and it’s more dangerous than ever

#165
post #36

While this bill is strongly opposed by the Internet Society, ACLU, CDT, and EFF, the critiques I've read don't get much into the real "why" behind this legislation continuing to be pushed so forcefully. The pretext is, of course, "protect the children" and more generally law-and-order with a bonus side-helping of "stop those awful social media giants." While these justifications are (hopefully) obvious misdirection t…

E2EE is offered to all users, whether or not they are law-abiding. More precise is to say that E2EE is offered to users who are primarily law-abiding. Your points are well-heard, even by those in the IC. What isn't occurring, is a good-faith discussion on solving the issues faced by law enforcement and the IC related to the growing entropy of E2EE wielded at scale by folks, a large subset of whom are engaging in crim…

> What isn't occurring, is a good-faith discussion on solving the issues faced by law enforcement and the IC related to the growing entropy of E2EE wielded at scale by folks, a large subset of whom are engaging in criminal behavior.

How about a good faith discussion of the fact that crime rates are at historic lows, or the fact that many crimes (burglary, car theft) are never investigated, or the fact that surveillance is never going to solve, let alone prevent the real issues that people care about, like domestic violence, gun violence, or the epidemic of prescription pain killer addiction.

Focus on crime prevention, not more law enforcement empire building.

Re: The EARN IT act is back, and it’s more dangerous than ever

#166

Earlier quoted context omitted.

No we shouldn’t. Never. Get that idea out of your head. It can never be secure or safe. This path leads to bodies hanging from the town square.

So you want encryption so criminals who would have otherwise been hung to be able to evade the law? It is pretty clear to me how a government may not approve of encryption for this usage.

Yes. The state has no right to hang anyone. The state has no right to take a life. When you take away encryption, The Innocent and the Guilty are punished, the innocent disproportionately.

That’s the beautiful thing: we don’t have to care what the government thinks. We are 30y into the encryption wars, and they cannot put the genie back in the bottle. It just is.

Re: The EARN IT act is back, and it’s more dangerous than ever

#168

Earlier quoted context omitted.

then that's not encryption ... if it has a back door....

I'm not talking about a backdoor. I am talking about it being a part of the actual system design.

It's unclear what you're talking about then; edit and clarify. Even the most generous interpretation sounds like a backdoor.

Re: The EARN IT act is back, and it’s more dangerous than ever

#169

Earlier quoted context omitted.

Here's a thought. Private[0] keys could be held in escrow, with sss[1] being used to decrypt, publically. The sss shares could be held by different branches of government. (state,federal,exeecutive,legislative,judicial) Please shoot my idea down. [0] or 'backdoor' keys [1] https://en.wikipedia.org/wiki/Shamir%27s_Secret_Sharing (or similar)

Personally I think the company should also hold a key. They would use this key after verifying that a warrant is valid. I also think giving out hardware keys with rate limiting / logging features along with key rotation / revocation is essential to reducing abuse.

This is called a backdoor, whether you like it or not. Pinky-promising not to abuse the backdoor key doesn't make it not a backdoor. Backdoors will be abused by governments. Have we learned nothing from the Snowden leaks?

Re: The EARN IT act is back, and it’s more dangerous than ever

#170

We should design cryptosystems that include functionality that support warrants as opposed to being antiencryption and removing encryption.

> functionality that support warrants

A back door marked ‘staff only’ doesn’t actually know who is staff and who isn’t.

Post reply on HN