Live data from Hacker News

230, or not 230? That is the EARN IT question

signal.org

131–140 of 178 posts

Re: 230, or not 230? That is the EARN IT question

#131
post #7

Earlier quoted context omitted.

They use Intel SGX to keep themselves from being able to access their users' contact lists. Still, one has to possess and reveal a valid phone number to use the service. This must help to grow the user base.

This misses the point, just because someone sometimes added me to their phone contacts and uses signal does not mean I want them notified when I start using signal too.

> This misses the point, just because someone sometimes added me to their phone contacts and uses signal does not mean I want them notified when I start using signal too.

It sounds like Signal is trying to solve a different problem than the one you have, so you should probably look for a different solution.

IIRC, Signal's goal is easy to use mass-market E2E encrypted replacement for SMS messaging. If they didn't automatically notify people's contacts, then most of them would probably continue to SMS or use FB messenger, etc.

Re: 230, or not 230? That is the EARN IT question

#132

Earlier quoted context omitted.

No, and they wouldn't be by any informed understanding of the law. That's not how the law has ever worked in any developed society. Generally, law has both the concept of intent and reasonableness. As such, a company that inadequately polices malicious and abusive content because that content is wildly profitable (hi Google and Facebook), we should have the legal ability to fine these companies into oblivion, because…

> No, and they wouldn't be by any informed understanding of the law. You are misinformed about the history of 230. 230 was proposed exactly because the law was interpreted the way you're saying it wouldn't be. From Wikipedia below, added emphasis mine: > This concern was raised by legal challenges against CompuServe and Prodigy, early service providers at this time. CompuServe stated they would not attempt to regulat…

[deleted]

Re: 230, or not 230? That is the EARN IT question

#133

EARN IT is pretty disingenuous in how it is designed, of course, but I am all for making it harder and harder to retain Section 230 immunity: It's a mistake that we allow it in the first place. We should indeed continue to erode the eligibility for Section 230 to the point that either the limitations of remaining eligible for immunity makes it easy for competitors to produce better offerings without immunity, or that…

While we're at it, we should also get the phone companies. I'm sure that the people who want to say bad things about me online are also telling people over the phone. How can they allow this!?

Re: 230, or not 230? That is the EARN IT question

#134
post #107

Earlier quoted context omitted.

So this is the thing that is really confusing me: isn't Signal like CompuServe? Signal doesn't moderate my content and in fact can't; so why would a repeal of Section 230 matter to Signal? And like, yes: maybe the people at Signal personally care... but that's not how this article is written. I feel like most of the people who are super knee-jerk pro-230 are ignoring this precedent you have pointed to of CompuServe:…

I think so, at least in theory. In practice, I suspect that would eventually get challenged in court. But (IANAL), I also suspect that you're right, and a platform like Signal would fall under the same category as CompuServe and could make a strong argument for itself using that case. Here's where it gets tricky though -- Signal is kind of an anomaly, and there are a lot of platforms being built that both moderate co…

I personally think you would be surprised at how much of what we currently have could continue to work in a world without Section 230. Right now, people are just taking a cheap shortcut of "let's just hire some moderators to moderate it", and enjoying it as it gives them control over narrative (letting them choose when to apply a firm hand in moderating and when to be lazy about it: there are just so many examples of companies abusing their moderation power in ways that have nothing to do with politics, along with issues of both subtle and not so subtle racism and misogyny--such as bans on photos of women breastfeeding--being perpetuated by the current system). I bet most of what we have right now could continue to work, albeit with pretty major architectural changes to the web... ones which admittedly might not still be conducive to large players extracting rent for hosting and organizing everything (maybe with more decentralized client-side mechanisms as opposed to centralized server-side mechanisms for helping people navigate content); and, what doesn't translate, was maybe not worth preserving in the first place. Either way, it seems to me like we should be having an honest conversation about the details of what we have and what we like and what we need to keep pulling it off, so we can figure out what the tradeoffs are, and this article from Signal equating a loss of Section 230 with somehow not being able to have end-to-end encryption is the exact opposite of that: it is more misinformation being thrown at an already giant mess of misunderstanding.

Re: 230, or not 230? That is the EARN IT question

#135
post #131

Earlier quoted context omitted.

This misses the point, just because someone sometimes added me to their phone contacts and uses signal does not mean I want them notified when I start using signal too.

> This misses the point, just because someone sometimes added me to their phone contacts and uses signal does not mean I want them notified when I start using signal too. It sounds like Signal is trying to solve a different problem than the one you have, so you should probably look for a different solution. IIRC, Signal's goal is easy to use mass-market E2E encrypted replacement for SMS messaging. If they didn't auto…

I can see how this would violate expectations if you installed it for one especially sensitive interaction. "Look at me, I'm doing tradecraft now!"

Re: 230, or not 230? That is the EARN IT question

#137
> At a high level, what the bill proposes is a system where companies have to earn Section 230 protection by following a set of designed-by-committee “best practices” that are extraordinarily unlikely to allow end-to-end encryption.

As diligently stated by Signal, EARN IT makes end-to-end encryption difficult, but not impossible. All relevant companies would like to prevent having to transition their current architecture over to a design that fits the specification laid out by EARN IT. This is quite understandable as this would bring with it a heavy cost, but if push comes to shove, that’s what they’re going to have to do. I expect that we’ll be hearing a lot more about this issue over the coming months. If this bill is passed, it will quickly be challenged in the Supreme Court.

Re: 230, or not 230? That is the EARN IT question

#138

Earlier quoted context omitted.

I don't follow. I'm sending (or trying to send) messages to my contacts. If I know their phone number, I'm going to try to initiate a Signal conversation with them. So I ask the Signal server for a signed prekey. Your argument is that Signal should not respond with "I don't know this person" and should instead respond with something indistinguishable from a "real" response. So they must send me something that looks l…

Signal server should respond with "I either don't know this person or they have not approved to be contacted by you". You should only get a prekey if they are in fact a signal user and have opted in to be discoverable by everyone or only by select people including you.

Ah, ok. So in that case, people would probably be have to be uncontactable by default (otherwise we'd be back to the current universe). Now you'll have to explicitly opt in to being contacted by every new person you meet. This is fine for some, but it's a massive usability tradeoff. Think about all the non-tehcnical people that Signal is intended to be used by, and imagine trying to teach them about Safety Numbers and a necessarily-opt-in contacting scheme.

Re: 230, or not 230? That is the EARN IT question

#139

> At a high level, what the bill proposes is a system where companies have to earn Section 230 protection by following a set of designed-by-committee “best practices” that are extraordinarily unlikely to allow end-to-end encryption. As diligently stated by Signal, EARN IT makes end-to-end encryption difficult, but not impossible. All relevant companies would like to prevent having to transition their current architec…

So the "best practices" under EARN IT are to be made by a committee of law enforcement agencies, with no congressional oversight.

Re: 230, or not 230? That is the EARN IT question

#140
post #134

Earlier quoted context omitted.

I think so, at least in theory. In practice, I suspect that would eventually get challenged in court. But (IANAL), I also suspect that you're right, and a platform like Signal would fall under the same category as CompuServe and could make a strong argument for itself using that case. Here's where it gets tricky though -- Signal is kind of an anomaly, and there are a lot of platforms being built that both moderate co…

I personally think you would be surprised at how much of what we currently have could continue to work in a world without Section 230. Right now, people are just taking a cheap shortcut of "let's just hire some moderators to moderate it", and enjoying it as it gives them control over narrative (letting them choose when to apply a firm hand in moderating and when to be lazy about it: there are just so many examples of…

> I personally think you would be surprised at how much of what we currently have could continue to work in a world without Section 230

Hackernews wouldn't.

I advocate for digital rights online; particularly the Right to Communicate[0]. But the Right to Communicate goes hand in hand with the Right to Filter[1]. Human moderation isn't a shortcut, it's the backbone of small, cozy forums and independent sites. Human moderation on a personalized scale is what makes smaller communities so much nicer than giant algorithmically curated platforms like Twitter or Youtube.

The way we marry the Right to Filter and the Right to Communicate is with systems like the Fediverse that make it easy for people to form new communities on the fly, to join and leave existing communities without any pain or fuss, and to copy their content around or download it out of data silos whenever they'd like to. While we give users that convenience, we also recognize that communities have an inalienable right to organize themselves and filter the content that they host and see. In this way, the Right to Communicate and the Right to Filter reinforce each other, filling in the problematic gaps and abuses that either right would have in isolation.

Section 230 is what makes that possible. Decentralization isn't magic. The law and the DOJ will attack community organizers and label them as publishers regardless of whether or not they are personally hosting the content in their communities. It doesn't matter what architecture you use; if you're going to have an open community someplace, that community needs to be able to enforce its own rules and norms. And Section 230 will make them liable if they attempt to do so.

And even outside of the Fediverse, so much of the Internet matters.

To hear you very lightly say something like:

> and, what doesn't translate, was maybe not worth preserving in the first place

I'm almost not sure how to respond to a claim like that. HN isn't worth preserving? IRC channels aren't worth preserving? Matrix isn't worth preserving? Self-publishing storefronts, independent forums, and comment sections on blogs aren't worth preserving? Email isn't worth preserving?

> Signal equating a loss of Section 230 with somehow not being able to have end-to-end encryption

For Signal, no, maybe not. For a lot of other services, including the vast majority of the Fediverse, yes. I think your reading of Signal's status as a distributor is pretty reasonable. But don't jump from that reading to saying that this won't have an impact on encryption.

Signal is a zero-knowledge, closed communication platform. It's not decentralized, it has essentially no moderation of any kind, and it has no communities of any kind. An open community with its own norms, memes, and content standards is not zero-knowledge about the content it's hosting. A law that meant that only closed, blind systems like Signal could make use of E2E encryption wouldn't eliminate all encryption, but it would restrict a large number of platforms from using encryption to make themselves more private and more secure.

[0]: https://anewdigitalmanifesto.com/#right-to-communicate

[1]: https://anewdigitalmanifesto.com/#right-to-filter

Post reply on HN