Live data from Hacker News

Your compliance obligations under the UK’s Online Safety Bill

webdevlaw.uk

161–170 of 480 posts

Re: Your compliance obligations under the UK’s Online Safety Bill

#161
post #148
post #132

who also has skin in the game about being on the receiving end of the most horrific online abuse Do people just not get educated in online literacy anymore? An adult getting abused online is like getting third degree burns because you laid your hand on a hot burner and refused to take it off. If people saying mean things to you is disturbing your groove so much you're calling it "abuse" maybe you should stop reading…

> An adult getting abused online is like getting third degree burns because you laid your hand on a hot burner and refused to take it off This analogy is broken on quite a few levels. When did the internet become a hot burner? The internet is not designed to get hot - it's not a cooking device. If your laptop consistently got so hot it burned your lap, you'd try to fix it, not say "of course it does that". > If peopl…

Why would you expect the internet to be governed by different laws to in-person behaviour?

Because you can't instantly erase someone from your perception in person to person interaction. Online you can even proactively protect yourself, such as by adding words and phrases you don't like to your blocklist. Suppose I decide I don't ever want to interact with someone who still uses the word "retard". My computer can preemptively block those people on my Twitter, my email, even pages containing the word on my browser. It takes only seconds to wipe entire categories of people and opinion from every facet of your online experience.

Re: Your compliance obligations under the UK’s Online Safety Bill

#162
post #5

It seems to me that the solution to all the woes of this bill is to just not allow any content to be shared . That basically eliminates this being a problem for 95% of all companies.

Correct, taking down all of one's websites is the easiest way to comply with this bill.

That, and hiring a large number of lawyers, paying regulatory fees, etc.

Re: Your compliance obligations under the UK’s Online Safety Bill

#163

Can someone explain why this won't result in a renaissance for peer to peer and e2e encrypted chat/forums/social media etc.? When government or industry makes it nearly impossible for consumer needs to be met we inevitably see a grey and black market spring up to meet those needs. My prediction is that if legislation like this becomes widespread we'll see a freely distributed application rise to prominence among a ga…

> won't result in a renaissance for peer to peer This horribly written law can easily be interpreted to apply to ISP's as well - so if the ISP is allowing these peer-to-peer systems that allow "unsafe" content to be shared, they're liable for it too, or they have to shut down the peer-to-peer systems. Which again, is the point - to turn the internet into the easily regulable cable TV that they already understand.

I keep hearing this but there is a big difference between the public facing platform and the pipe to my house.

Where is the law vague? Your ISP is not a platform. I feel like this is a scare tactic.

Re: Your compliance obligations under the UK’s Online Safety Bill

#164

> If a British child could merely type your URL into a browser, the site is in scope. Seems incorrect, no? The visit is more important than just typing URL. Worst-case scenario I will check your IP and if its in UK/GB scope, you will see "Unable to browse this site due to your-stupid-anti-blah-blah-UK-policy"

Well, they'd have to press enter. Once that happened, it sounds like you'd have to run through certifications to make sure that the phrase "your-stupid-anti-blah-blah-UK-policy" isn't potentially harmful to minors, and then also (at a minimum) put in business processes to make sure that the approved text didn't change.

Then, moving forward, whenever you changed any (unrelated) business process, you'd need to re-up your business process certifications.

Re: Your compliance obligations under the UK’s Online Safety Bill

#165

Earlier quoted context omitted.

As an American visiting the UK and the EU, I got to see what the GDPR has done to the online experience over there for the first time. Wow, does that suck. I see about 20% of the "cookie track consent" popups Stateside that I saw browsing from the EU.

So you prefer being tracked without you knowing rather than being asked and easily opt out?

Personally, yes. I think most of what the GDPR intended to accomplish could have been accomplished more easily by public education campaigns and broad cultural adoption of no-track plugins. That would have done a lot less damage to the user experience than naively assuming that if one pushed the educational burden onto sites, the sites would cease to do the tracking that triggered the educational burden rather than just bother their users forever with government-mandated information placards.

Especially given that what constituted "tracking" was so broad that a lot of sites took the "better safe than sorry" approach because it was cheaper than a full audit of their tracking and a lawyer to interpret whether, say, Apache logs that show IP address constitute "tracking."

Re: Your compliance obligations under the UK’s Online Safety Bill

#166
post #132

who also has skin in the game about being on the receiving end of the most horrific online abuse Do people just not get educated in online literacy anymore? An adult getting abused online is like getting third degree burns because you laid your hand on a hot burner and refused to take it off. If people saying mean things to you is disturbing your groove so much you're calling it "abuse" maybe you should stop reading…

I don't think you've really experienced online abuse. If you get in an argument with someone and they start saying nasty things, then it's simple to disengage. You just stop replying and you don't go back to the thread. In this scenario, your comment makes sense, but you should count yourself very lucky if this is the worst you've experienced. Personally, I pissed off a cult leader and she sent her followers to haras…

Not a coordinated campaign like yours but I've been doxxed and had half a dozen death threats.

A "professional" abuser knows all about VPNs and will just keep creating new email addresses.

You had no luck with keyword filters? You have my sympathy.

Re: Your compliance obligations under the UK’s Online Safety Bill

#167
We're all sitting here shaking our heads wondering how we got here.

The answer is we demanded it.

Instead of parents taking responsibility for what their children see on their phone, we tried to push a parental responsibility into the service provider, that they're simply unable to logistically comply with.

This is the end result of trying to solve a problem in meat space with legislation. Everyone that sat around going "Hurr hurr XKCD! Slippery slope! Seat belts and road safety!" are complicit.

Re: Your compliance obligations under the UK’s Online Safety Bill

#168

If this applies to every site that hosts user generated content then that's nuts. When the internet first started, part of the appeal is that you could just make stuff without people looking over your shoulder, asking for forms, etc. Seems that the internet we created today is technically the same as the one from before, but now with governments throwing up red tape at every corner. Makes me wonder what a site like H…

right now or say 10 years ago til now, before the whole encrypted chats came into the picture, how many people have been convicted of CSAM in the UK, USA or somewhere else? is it in thousands? millions? if people were not getting convicted left and right before encryption, why is suddenly encryption the #1 enemy?

Because its not about the children, it never was.

Re: Your compliance obligations under the UK’s Online Safety Bill

#169
If I, a US citizen, started an online service that attracted Ofcom attention, what binds me to following UK regulations? The article mentions "extraterritorial enforcement", but what does that mean? Will the US extradite me to the UK if I don't put monitoring in place? Will I get arrested if I visit the UK? Will they try to sue me in US court?

I mean realistically if it became a problem I'd just IP-block all of the UK because they're small, but I don't understand what the legal framework for "extraterritorial enforcement" even is.

Re: Your compliance obligations under the UK’s Online Safety Bill

#170
post #113

Earlier quoted context omitted.

I'll admit, I haven't read the entire article - but the obvious question to me - using your example of HN - what authority does the UK have over a website hosted in another country at all? They can pass all the rules they want, but how do they propose to enforce them on a company that does not operate in the UK? If that was possible, wouldn't CCP or Russia be ordering websites all over the world to shutdown to contro…

Our government can't enforce rules on foreign owned websites, but they can force ISP's to block them.

Which is fine, the UK users and economy will be the one losing really.
Post reply on HN