Live data from Hacker News

Earn-IT threatens encryption and therefore user freedom

fsf.org

111–120 of 209 posts

Re: Earn-IT threatens encryption and therefore user freedom

#111

Earlier quoted context omitted.

Do politicians even read these letters?

Wrote to a state legislator regarding a specific bill. They voted opposite of what I requested, then wrote back giving a synopsis of the bill and mentioning it passed without even mentioning their vote against the bill.

That's because voting literally doesn't matter. At all: https://represent.us/americas-corruption-problem/

There is nothing you can do if you live in a "safe" district.

If you live in a contested district, donate to their opponent, and send them a copy of the check, so that they can see it before they read the letter.

Re: Earn-IT threatens encryption and therefore user freedom

#112

Wrote to Dianne Feinstein of CA about being against Earn-IT act and got a letter back about how Earn IT act would prevent child sexual abuse material online. Sigh. As disappointed as I was in the response, I'm glad that EFF makes it really easy to reach out to reps. Took me less than a minute to send out my stance against the Earn IT act to my representatives https://act.eff.org/action/stop-the-earn-it-act-to-save-ou…

This is the copy/paste response I got from Duckworth: (Which is disappointing)

Thank you for contacting me about S. 3538, Eliminating Abusive and Rampant Neglect of Interactive Technologies (EARN IT) Act of 2022. I appreciate you taking the time to make me aware of your concerns on this important matter.

The EARN IT Act would establish a National Commission on Online Child Sexual Exploitation Prevention, which would be responsible for developing recommended best practices for providers of interactive computer services, such as email or cloud storage providers or social media services like Facebook or WhatsApp. These best practices would pertain to how best to prevent, reduce or respond to the online sexual exploitation of children, in particular the proliferation of online child sexual abuse material (CSAM).

This bill would also amend Section 230 of the Communications Decency Act of 1996. Section 230 in its current form creates a so-called “safe harbor” for providers of interactive computer services from legal or civil liability for the content posted on their sites. For example, if a user posts defamatory information on Twitter that individual may be sued and held liable, but Twitter as a company may not be held liable. The EARN IT Act would require these service providers to earn that safe harbor by complying with the recommended best practices developed by the Commission. Senator Lindsey Graham of South Carolina introduced the bipartisan EARN IT Act on January 31, 2022, and it was referred to the Senate Judiciary Committee.

The proliferation of child sexual abuse material has a devastating effect on its victims, their families and their communities. Like you, I believe there is no place in society for this material. However, some internet privacy advocates have expressed concern that the EARN IT Act may unintentionally drive CSAM purveyors into the dark net, where these horrific criminals would become more difficult to track, identify and ultimately build a case that is required for a successful prosecution. Please know that I will keep your thoughts in mind should a majority of the Judiciary Committee decide to favorably report S. 3538 to the full Senate for consideration.

Thank you again for contacting me on this important issue. If you would like more information on my work in the Senate, please visit my website at www.duckworth.senate.gov. You can access my voting record and see what I am doing to address today’s most important issues. I hope that you will continue to share your views and opinions with me and let me know whenever I may be of assistance to you.

Sincerely,

Tammy Duckworth United States Senator

Re: Earn-IT threatens encryption and therefore user freedom

#113
post #101
post #94

Earlier quoted context omitted.

The part of the bill that mentions E2EE (Section 5) is an amendment to the Communications Act of 1934, namely the famous Section 230 which contains: "No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider." So the EARN-IT act would seem to me to modify Section 230 to not apply in cases of child sexual expl…

In this case, your quote is only one third of the content. You are not quoting the first sentence or the last part, which is why the quote doesn't make sense. Your quote should read the following, where I've italicized the two parts you left out, "NO EFFECT ON CHILD SEXUAL EXPLOITATION LAW.—Nothing in this section (other than subsection (c)(2)(A)) shall be construed to impair or limit— any charge in a criminal prosec…

Yes, I skipped or paraphrased those parts of the bill to keep things short in a way that I thought made sense. But I think the message is unchanged with the full text. Namely that Section 230 would be amended to also state:

"NO EFFECT ON CHILD SEXUAL EXPLOITATION LAW. Nothing in this section [NB Section 230] (other than subsection (c)(2)(A)) shall be construed to impair or limit ... any charge in a criminal prosecution brought against a provider of an interactive computer service under State law regarding the advertisement, promotion, presentation, distribution, or solicitation of child sexual abuse material, as defined in section 2256(8) of title 18, United States Code;"

And so Section 230 protections to content providers would cease to apply* in cases of child secual exploitation law, I think.

* EDIT: Except for those points that would be added to Section 230 specifically regarding E2EE

Re: Earn-IT threatens encryption and therefore user freedom

#114
post #20

I feel like they missed the primary point which is that E2E encryption is the primary thing protecting everyone from hackers/criminals/other-governments. Without it the criminals WILL have access to your systems and data and then you can basically say goodbye to anything being valuable at all. Locking your door at night is a poor metaphor. A criminal can literally infiltrate and search through every unsecured compute…

>Locking your door at night is a poor metaphor. It is a poor metaphor because locks prevent invasion not enable privacy. Banning encryption is such an attack on privacy that it's closer to banning clothes and easing concerns by making looking at naked people illegal. Encryption is the fundamental unit of network privacy.

You can't have security without privacy.

Re: Earn-IT threatens encryption and therefore user freedom

#115
It's not even necessary to emphasize on user freedom. The safety aspect is more important to emphasize. Unencrypted or weakly encrypted communication is a severe threat to every (even very lawful and perfectly conventional) user safety and even national security. Limiting encryption is a gravely mistake for any nation in the modern word context. Only incompetent or malevolent policymakers can lobby it. Sure, universal right for strong encryption has its downsides but the opposite is not possible to afford anymore.

Re: Earn-IT threatens encryption and therefore user freedom

#116

Earlier quoted context omitted.

There's literally no difference. None. This was tried before with special locks that 'only the TSA had the keys to open'. The keys were posted online for anyone to make their own. It's also been tried commercially with various DRM and failed. There is no such thing as a 'government only, and only with a warrant' backdoor. There is either private or not private.

The problem with TSA keys is that they are all the same, can easily be cloned, and couldn't be rotated. It is possible to design a system where judges have their own hardware keys. Hardware keys can not be cloned assuming strong tamper protection. If a hardware key gets stolen it can be revoked as being valid and a judge can be issued a new one. DRM is different because the client ultimately has to have the keys to d…

Shot in the dark here? Which Government are you talking about? Saudi? Where being gay is a death sentence? No? How about the US where being Japanese was illegal? China's got the most people, perhaps we take a wold wide vote to see? Biggest land mass? Millionaires per population (the 1%)?

Who would control the creation of the keys? I mean which tech vender would control access to my android phones encryption? My phone was made in China, and the chips inside it were made in China. They also have the most people, so it seems fair they control the keys.

Re: Earn-IT threatens encryption and therefore user freedom

#117
post #92

Earlier quoted context omitted.

I know this isn't the point of your post, but what does your party affiliation mean in this context? I have known people from both parties who believed their party affiliation was central to their anti-authoritarian stance, and people from both parties who thought that their preferred form of good government would control people. Do you think your party loyalty made you a more likely target, or should have made you a…

Why do you go out of your way to protect medical information? If the government cared enough to get your medical information illegally, couldn't they just get it from your doctors? And if they did decide you were an "enemy", what good would knowing your medical information do?

It's mostly a matter of principle since I assume internet searches to be closer to a postcard than a letter. I could write about some health-related thing that is potentially embarrassing in a postcard, because I doubt the post office cares, or that my mail carrier reads postcards, but I'd probably prefer to put it in a letter delivered inside an envelope.

It seems like better practice to learn which sources tell mainstream, reliable information about things like bordetella vaccines and regular nail clipping, before I get really emotional about an anal gland that needs to be expressed or before my person finds a weird lump on my front leg.

More seriously, back to human medicine, I am disappointed that so many reputable medical information sources with read-only information prevent Tor network users from accessing their information even though malicious Tor users aren't able to add misinformation.

Re: Earn-IT threatens encryption and therefore user freedom

#118

Devil's advocate: encryption is also what's stopping users with locked-down devices (increasingly common and hard to avoid) from having freedom to run and/or modify the software they use. It's a tough situation. Encryption can be used for good or bad (and even the definition of what's "good" or "bad" encryption varies depending on who you ask). Unfortunately, I see it increasingly being used to oppress users, in the…

I'd imagine that companies would get licenses to use encryption in limited and restricted circumstances, such as for DRM or basic system security. The user won't be able to use strong encryption, but only backdoored or weak encryption to keep the average attacker out.

But I'd assume that license wouldn't be an easy thing to get. So it would be rich companies getting it.

It would price innovation out of the market.

Also, not sure what you mean by weak encryption. An average attacker now has access to decrypting tools out of the box (with a few Linux distros) so wep isn't stopping anyone really. Even noobs can be trained to crack with an hour of youtube.

Re: Earn-IT threatens encryption and therefore user freedom

#119
Banning encryption is basically banning certain maths. In a way, it's an affront on free speech, because it is explicitly saying speech must be done in a way that can always be eavesdropped.

An analogy I use to explain to people who don't have a technical background is, "Imagine if we made it law that every pen ever made was required to be chained to a special clipboard that makes a carbon copy of whatever the pen writes." Even when explained like that, it's clear how such a system could be bypassed and would only harm innocent users, but even worse is just how ridiculous it all seems, since this would all be because we can't subpoena a pen. Hopefully it's made clear that despite the subpoena being lawful, it simply doesn't make sense, and attaching this fictitious clipboard doesn't really help make it make more sense, since it seems even more ridiculous once it's made clear that you can't subpoena a pen. It's no difference than saying you can't subpoena math, and that's OK.

I hope as we progress technologically, every day users will understand encryption to the point where they can form their own analogies as to what a ban on encryption would even imply.

Post reply on HN