Live data from Hacker News

230, or not 230? That is the EARN IT question

signal.org

161–170 of 178 posts

Re: 230, or not 230? That is the EARN IT question

#161

Earlier quoted context omitted.

They fix that case swiftly, then go on to ignore new cases?

Law enforcement, typically tasked with enforcing laws, would not ignore the new cases. Individual citizens enforcing laws themselves is nice but overall we don't depend on vigilantes.

Parent presumably means if the person in the moderator position ignores new cases.

To which it seems like a fair response would rely more on free speech perspectives.

Essentially, can it be said that the majority of the platform is used for illegal activities? Or are the illegal activities a minority of some other, lawful activities?

I'd want a system where Reddit is in the clear, but CreditCardSkimmersChat is not.

Re: 230, or not 230? That is the EARN IT question

#162
post #161

Earlier quoted context omitted.

Law enforcement, typically tasked with enforcing laws, would not ignore the new cases. Individual citizens enforcing laws themselves is nice but overall we don't depend on vigilantes.

Parent presumably means if the person in the moderator position ignores new cases. To which it seems like a fair response would rely more on free speech perspectives. Essentially, can it be said that the majority of the platform is used for illegal activities? Or are the illegal activities a minority of some other, lawful activities? I'd want a system where Reddit is in the clear, but CreditCardSkimmersChat is not.

> Parent presumably means if the person in the moderator position ignores new cases.

Which is what they're supposed to do. They're not the police, the police are the police.

> Essentially, can it be said that the majority of the platform is used for illegal activities? Or are the illegal activities a minority of some other, lawful activities?

This doesn't work because it ends up prohibiting the lawful things anyway. You have a platform that promises witch hunts and the innocent victims of witch hunts get evicted from there, and you have a platform that promises no witch hunts and those people go there but so do all the witches and then you get calls to shut it down because there are many witches. You're left with nowhere for the innocent victims of witch hunts to go.

> I'd want a system where Reddit is in the clear, but CreditCardSkimmersChat is not.

They tried this with SESTA and it was a monumental failure. It turns out when you do this, CreditCardSkimmersChat.com goes away and is replaced with CreditCardSkimmersChat.ru and all that does is make law enforcement's job harder.

You want CreditCardSkimmersChat.com to carry on existing, because that's the place you send your agents to camp out in the chat with a logger and execute a warrant to have their ISP capture all their traffic, and investigate anybody who shows up from your jurisdiction, and collect stolen credit card numbers to report to the credit card companies before they can be used for fraudulent purchases.

You don't want to shut it down because once you know it exists it's a honeypot with a previous reputation for not being a honeypot, and all shutting it down will do is cause it to reappear in Russia or on Tor or at a new site you haven't rediscovered yet meanwhile lots more credit card fraud is happening, which only makes law enforcement's job harder and less effective.

It's like finally discovering the phone number of the crime boss and calling the phone company and ordering them to disconnect their phone.

Re: 230, or not 230? That is the EARN IT question

#163
post #153
post #48

Earlier quoted context omitted.

The GDPR does not explicitly account for scale in practice, but pretends you're a $300 million dollar business, with the resources to do proper GDPR compliance, which is why the response of many small businesses is to stop serving europeans. And these businesses had nothing to do with privacy invasion, such as classes you pay for, paid note taking apps an so on.

While in theory you are right, there is a distinction. GDPR makes business more difficult, but it codifies a human right to privacy that, much like worker safety, should have been implemented anyway. The present regulation does the opposite. It ultimately implies that any company that does not comply with the insane US post 9/11 laws on large scale spying, extrajudicial sanctioning and, arguably, racial and ethnic di…

Whatabouting about the GDPR doesn't address any of the criticism of it, I wasn't talking about the EARN IT act in my comment.

I bet many agree here any that those US laws and actions are bad too. I really care about privacy myself also, more than the typical tech worker looking at the actions of my coworkers compared to me.

If there was GDPR casual or GDPR lite for small businesses, kind of like small business taxes where hiring an accountant once a year for a few thousand euros was enough, then I don't think people would be up in arms about the GDPR.

If GDPR-casual was good faith level of actions where all you did is kept a log of privacy data clearing requests, like a copy of an email and a copy saying you did it back, and then did a best effort cleanup, I don't think anyone would care. It's the very large compliance burden that GDPR imposes, with a lot of liability gotchas everywhere if you don't implement bureaucratic detail #2929 that put people up in arms. And if you say that it isn't like that, it shows you haven't really looked at what is required by the GDPR or tried to implement it in your company.

Re: 230, or not 230? That is the EARN IT question

#164

Earlier quoted context omitted.

This misses the point, just because someone sometimes added me to their phone contacts and uses signal does not mean I want them notified when I start using signal too.

I don’t get it. If they have your number, this person can already message you.

A phone number does not proactively provide information. Should I have to use a professional suit and tie profile picture because my boss' boss might use Signal? What about LGBT people in potentially hostile environments? Etc

Re: 230, or not 230? That is the EARN IT question

#165
post #57

Earlier quoted context omitted.

Perhaps the parent is downvoted not because of the underlying content of the message, but because of the black/white framing. Every tool has a barrier to use, and even with a strong commitment to security/privacy, Signal seems to have decided that it's more beneficial for their users know which one of their friends are on Signal, than there is potential for abuse. Further, there may come a time where this calculus ch…

> Signal seems to have decided that it's more beneficial for their users know which one of their friends are on Signal I feel the reason might be more as a way to promote more widespread use of Signal itself, rather than directly serving their users.

Signal relies on the user's contact list so that they don't have to store signal users in their servers.

Re: 230, or not 230? That is the EARN IT question

#166
post #141
post #136

I used the EFF form linked in the blog post to contact my representatives in California. I will also donate to EFF again. Privacy is important.

I did the same a few weeks ago. Here's the automated response from Feinstein's office: > Dear [Name]: > Thank you for writing to me to share your concerns about law enforcement access to encrypted communications. I appreciate the time you took to write, and I welcome the opportunity to respond. > I understand you are opposed to the “Eliminating Abusive and Rampant Neglect of Interactive Technologies (EARN IT) Act of…

She should have been voted out of office in the last election. Her performance as a representative for CA has been incredibly abysmal. The way she handled the Kavanaugh allegations really changed my mind about her.

She seems like an old time Senator, steeped in politics but out of touch with the reality of the state she represents.

Re: 230, or not 230? That is the EARN IT question

#167

Why is legislation like this being presented.. Its simple.. Less people are looking. Of course this bill is intended to do what we all want. The writing is on the walls. To many people sit around in their passive lifestyle and pass the care to someone else... Doesnt matter who just as long as they dont need to get off the couch and stop scrolling fakebook. This passes... Youll see 1984 realllll soon... I wish more pe…

The premise of 1984 was that the government COULD watch what you were doing at any given time. In certain respects we're already past that and technologies like Signal are trying to move us out of that Orwellian world.

Re: 230, or not 230? That is the EARN IT question

#168
post #118

Earlier quoted context omitted.

I think it's simple. The US postal service uses postal inspectors to try and identify packages containing narcotics[0], and yet we don't make them liable for the packages they miss. Any attempt to moderate undesirable content on a website should not then make you liable for the content you miss. [0]: https://www.uspis.gov/about/what-we-do/

> I think it's simple. The US postal service uses postal inspectors to try and identify packages containing narcotics[0], and yet we don't make them liable for the packages they miss. Any attempt to moderate undesirable content on a website should not then make you liable for the content you miss. > [0]: https://www.uspis.gov/about/what-we-do/ Then what about sites that would use this to their advantage and half ass…

The same thing that we do with every kind of organization. We demand adequate controls, incentives, whistleblower protection, paper trail (auditability and accountability for the higher ups), documented internal policies and sticking to them. (And demand that they pay for external audits, mock cases, red team tests, and so on.)

This sort of works. And it can be made very effective. (Basically by criminalizing grossly negligent auditing and spending public money on enforcing it, the whole structure snaps into place eventually.) Currently financial organizations are allowed to be lax, because audits are lax, because the banking license authority doesn't give much of a shit.

Re: 230, or not 230? That is the EARN IT question

#169

Earlier quoted context omitted.

That analogy is flawed because USPS doesn't know what's in the packages, but you know exactly what's on your forum.

Not if it's end-to-end encrypted, which is exactly the topic here. With this bill it's highly likely that policing will be required of services providing end-to-end encryption too, which then makes that encryption impossible while complying with the "best practices".

Also, even if the content itself is 100% public, there's no way site owners can be expected to assign someone to monitor every discussion in real-time. Even just investigating content flagged by other users can easily turn into a full-time job for a moderate-size service.

Re: 230, or not 230? That is the EARN IT question

#170
post #63

Earlier quoted context omitted.

How do you sue the guy that shouted at you as they left the restaurant? Who stuck a defamatory sign on the electric pole? I don't see why the issues these present should move responsibility to the restaurant or electric company, however.

A better analogy is a community bulletin board, like at a library. Just thinking aloud, what would I expect if my library’s bb was always covered in hate speech? Probably that the librarian would put it behind locked glass and moderate posts. Or take it down altogether. I’d hope for the former.

If you put it behind locked glass, people are going to stop posting much of anything on that bulletin board. And dealing with the rest is going to take up too much of the librarian's time, distracting from other duties. It's a reasonable approach for official communications from the library, but not for a community forum.
Post reply on HN