Live data from Hacker News

Ask HN: Online activities to be made impossible by the UK Online Safety Bill

news.ycombinator.com

61–70 of 110 posts

Re: Ask HN: Online activities to be made impossible by the UK Online Safety Bill

#61
post #55
post #35

While I'm not a supporter of the Online Safety Bill, I do find that the opprobrium that it has inspired is consistently hyperbolic. The Online Safety Bill bans nothing . What it does do is create a regulatory framework for the Office for Communications (aka Ofcom, HM Government's regulator for the communications industry) to operate and enforce. The regulatory framework is based around risk assessments, and sets out…

I’m reminded of the hyperbole - which I fell for - around the Regulation of Investigatory Powers act around the turn of the millennium. It provides a legal mechanism for authorities to require that individuals disclose encryption keys for encrypted data that was legally obtained or intercepted (i.e. with a warrant) by those authorities, and there are penalties (jail time) for refusing to do so. The worry at the time…

An interesting RIP case here: https://www.bbc.co.uk/news/uk-england-11479831

A person received a 16 week prison sentence for not disclosing a password. In the context, it’s possible that had he disclosed the password, police would have discovered material that would have attracted a far more severe punishment.

So one might argue that the RIP was too weak, and failed to compel disclosure of the password (four months in jail is light in the circumstances).

Re: Ask HN: Online activities to be made impossible by the UK Online Safety Bill

#62
post #35

While I'm not a supporter of the Online Safety Bill, I do find that the opprobrium that it has inspired is consistently hyperbolic. The Online Safety Bill bans nothing . What it does do is create a regulatory framework for the Office for Communications (aka Ofcom, HM Government's regulator for the communications industry) to operate and enforce. The regulatory framework is based around risk assessments, and sets out…

>Your Mastodon server or your Gitea server or your corner of the Tildeverse or whatever will never appear on their radar

Of course it will when your gitea or mastodon instance is in the right crosshair. Do we just surrender rights on a hope this time we can stay under the radar? If you are not a terrorist or a pedophile you have nothing to worry etc. When you disagree enough you will become a terrorist. That's the reality in my country because it works an have worked for centuries.

>Ofcom won't have the budget or the resources to go after individuals or small communities; they won't even know you exist. >Ofcom isn't going to audit your homelab for online harms.

Pinky promise?

Re: Ask HN: Online activities to be made impossible by the UK Online Safety Bill

#63
post #7

This might be useful from June, can’t vouch for correctness. https://www.taylorwessing.com/en/interface/2022/the-online-s...

My TLDR of that law firms info which could be a wrongful interpretation, in priority or execution order.

Any Non Specified Entity uploading any data which could be accessed by another Non Specified Entity with or without public access is bound by this bill.

Can be used or accessed from the UK. This might be the UK expanding beyond its borders here, because its a given if it not geo restricted it it could be used in the UK. VPN's/Tor may not be able to offer privacy from the state which is my opinion anyway.

Applies to all services with a "significant" number of UK users. No definition of significant so dont know if this is the same use of the word significant found in medical studies or not.

Definition of search engine is a service which can search more than one website or database.

Largest players now have a legal duty to prevent paid-for fraudulent adverts on their service and other regulated content.

Clarification on identifying the users of the service, ie profile pics and other identifying data.

Exempt specified entities:

--------------------------

Software like antivirus, antispam cloud/online submissions where said data is never likely to be used for communication purposes but might be analysed to improve the performance of said software function, ie reverse engineering stuxnet, latest spam techniques.

Published Content with commenting for the content, ie online newspaper comments. Posting a link, with or with comments, including like, dislike buttons and emojis of Published Content to another Non Specified Entity.

SMS & MMS messaging.

Services solely used for specific tasks like education, childcare and possibly health care.

One to One Aural (realtime speech and sound only guessing telephone) communication with identifying data allowed with no additional data communication functionality like visuals, text messaging. No mention of recording said Aural data.

Any public body carrying out their public duty.

Any internal business resource or tool, like company message boards, company chat facility's in all forms. No mention of recording data, would assume business includes official organisations like charities, but not clear.

No mention of private paid for programming language groups which can be accessed using a password of sorts and costs

Case by case reviews and changes made by the secretary of state so the exemption list will probably grow.

So my opinion on the above is if you are a big (US) tech service, you can self regulate, but little users will be watched by the UK state as no one can be trusted. Other laws apply where applicable.

Re: Ask HN: Online activities to be made impossible by the UK Online Safety Bill

#64
post #62
post #35

While I'm not a supporter of the Online Safety Bill, I do find that the opprobrium that it has inspired is consistently hyperbolic. The Online Safety Bill bans nothing . What it does do is create a regulatory framework for the Office for Communications (aka Ofcom, HM Government's regulator for the communications industry) to operate and enforce. The regulatory framework is based around risk assessments, and sets out…

>Your Mastodon server or your Gitea server or your corner of the Tildeverse or whatever will never appear on their radar Of course it will when your gitea or mastodon instance is in the right crosshair. Do we just surrender rights on a hope this time we can stay under the radar? If you are not a terrorist or a pedophile you have nothing to worry etc. When you disagree enough you will become a terrorist. That's the re…

I've read the bill, and know what it stipulates. Of course, if you don't want to take my word for it, you can download the 302 pages of legislation and check it yourself: https://bills.parliament.uk/bills/3137

Re: Ask HN: Online activities to be made impossible by the UK Online Safety Bill

#65
post #36
post #11

Earlier quoted context omitted.

> My experience with online activists' predictions of imminent dystopia is that they generally turn out to be extremely overblown. The questions in my opinion then become, Is it the law preventing these? Is it some people not yet seeing why they should do it? Are they purposefully not doing it initially to calm people? If they don’t want to be able to do it, it could be rephrased.

If you operate an online service, you don't have any actual obligations under the Online Safety Bill until Ofcom taps you on the shoulder. Considering that Ofcom is also responsible for regulating ISPs, all broadcast media, the EM spectrum, the telephone network and the Royal Mail, I don't think they'll have the resources to go after anyone but the social media giants.

> I don't think they'll have the resources to go after anyone but the social media giants.

Or anyone who criticizes those in power

Re: Ask HN: Online activities to be made impossible by the UK Online Safety Bill

#67
post #31

Earlier quoted context omitted.

Sure, it could be made to work, and it might even be able to keep up with your reading speed. VoIP codecs are heavily optimized for human voice and have just a few kilobits of bandwidth. The analog phone network, before it went entirely digital, had a much higher bandwidth which is why modems were able to reach 56kbps. Phone calls in the 1980s were often crystal clear, almost on par with a broadcast radio station. Ce…

Say I wanted to communicate with others in the best possible quality, which platform is best?

Depends on what you mean by quality, how much you're willing to pay for it, and what's actually available.

If quality means low latency and low jitter, and you can get T1/E1 digital telephone service, circuit switched end to end, that's almost certainly the lowest practical latency and jitter. It'll cost real money and you might not like the 8000Hz 8-bit sampling. ISDN calling is pretty much the same thing, but you only get two voice lines instead of 24 or 25.

If that's not an option, but low latency is still important, a solid wired connection with g.711 SIP is pretty close, but packets are 20ms of samples, so that adds to your baseline latency. G.711 is basically the same codec as used for t1. And internet jitter is probably not zero, but if your connection is well provisioned it's often not that bad.

If you want a wider audio band, maybe try to get SIP with G.722.2 (AMR-WB), this is the same codec used for 'HD Voice', and I don't think it adds too much delay.

Re: Ask HN: Online activities to be made impossible by the UK Online Safety Bill

#68
post #61
post #55

Earlier quoted context omitted.

I’m reminded of the hyperbole - which I fell for - around the Regulation of Investigatory Powers act around the turn of the millennium. It provides a legal mechanism for authorities to require that individuals disclose encryption keys for encrypted data that was legally obtained or intercepted (i.e. with a warrant) by those authorities, and there are penalties (jail time) for refusing to do so. The worry at the time…

An interesting RIP case here: https://www.bbc.co.uk/news/uk-england-11479831 A person received a 16 week prison sentence for not disclosing a password. In the context, it’s possible that had he disclosed the password, police would have discovered material that would have attracted a far more severe punishment. So one might argue that the RIP was too weak, and failed to compel disclosure of the password (four months i…

This guy went to prison for a year and 2 months, for not disclosing his Facebook password: https://www.bbc.co.uk/news/uk-england-hampshire-45365464

He was accused of murder. Ultimately, he was found guilty and sentenced to 33 years: https://www.hampshire.police.uk/news/hampshire/news/news/201...

And then there's the other direction, which I must confess I thought would have involved the RIP Act but ultimately didn't, instead it used anti-terrorism legislation.

A French employee of radical French publishing house that the French government is very cross with, arrived in Britain for a book fair. He was arrested and held for 24 hours using anti-terror legislation. The cops also confiscated his phone and laptop, and held onto them for more than 10 weeks, and they threatened him "with never being able to travel overseas if he failed to hand over a password to his confiscated iPhone and MacBook": https://www.theguardian.com/uk-news/2023/jul/21/police-watch...

The general concern is that France is not allowed to do that, so asked Britain to do it for them, and Britain did it. There wasn't even a hint that he'd broken the law in Britain, and all that was wanted was for the French government to get ahold of the contents of his phone and laptop. Perhaps this is the only reason (that they had absolutely nothing on him) that they didn't twist the knife and use the RIP Act to imprison him simply for not unlocking his devices for them: https://www.theguardian.com/uk-news/2023/apr/19/french-publi...

Re: Ask HN: Online activities to be made impossible by the UK Online Safety Bill

#69
post #43
post #40

Earlier quoted context omitted.

It sounds like you're chiding others for complaining about the bill, and excusing this because the bill "only" enables mass surveillance and anti-privacy measures, rather than stipulating them. Might be I'm reading you wrong on this, but that's what I'm taking away. > What this all means is that the bill will only have the effects that the government has said it will in its press releases. I don't really believe that…

I am chiding people, not for complaining, but for misunderstanding the surrounding context. Legislation is only as powerful as those enforcing it. > And it seems Apple and others don't believe it either. Yes, Apple, Google, Microsoft, Signal, Meta, and all the other big players else who has turned up to the committee hearings will have their activities curtailed. Individuals running Minecraft and Mastodon servers for…

IMO your analysis has a massive flaw.

>Legislation is only as powerful as those enforcing it.

While this is generally true, it doesn't necessarily stop the provisions within the bill being used as a political weapon to wield against someone.

In other words, just because it's generally not used against small fry, doesn't mean it won't be used as a club against a particular small fry that's a thorn in the side of someone politically or judicially connected.

Re: Ask HN: Online activities to be made impossible by the UK Online Safety Bill

#70
post #35

While I'm not a supporter of the Online Safety Bill, I do find that the opprobrium that it has inspired is consistently hyperbolic. The Online Safety Bill bans nothing . What it does do is create a regulatory framework for the Office for Communications (aka Ofcom, HM Government's regulator for the communications industry) to operate and enforce. The regulatory framework is based around risk assessments, and sets out…

You seem to know more than me. I host a fringe e2ee messaging system in the UK that I run under under an LTD. Am I affected?
Post reply on HN