Live data from Hacker News

IP blocking the UK is not enough to comply with the Online Safety Act

prestonbyrne.com

161–170 of 418 posts

Re: IP blocking the UK is not enough to comply with the Online Safety Act

#161

[flagged]

Starmer’s government may have also forgotten that its nuclear deterrent is on lease from the US.

Something about this feels off. It’s clearly not in the interest of the UK diplomatically given the current US admin. Are the people on the UK side of the cross-Atlantic CISA/State/Ofcom “counter-misinformation” op still blindly running their scripts as if the US elections never happened? It sure feels that way.

Re: IP blocking the UK is not enough to comply with the Online Safety Act

#162

Earlier quoted context omitted.

Then no country should have legal authority over companies operating in the country but based internationally. You could earn a lot of money by selling unregistered firearms, pipe bombs or drugs over the internet and sending it over the border. "If country B doesn’t like it, block the mail in question". Saying only the country of origin can regulate activity done in another country creates a legal worm-bucket with va…

> "If country B doesn’t like it, block the mail in question" That’s actually how it works? Unless you have an extradition agreement, or military overmatch, or you are willing to expend some diplomatic leverage, you are typically not getting a citizen out of a foreign country. The government complains about this all the time with goods from SE Asia, and sometimes they seize fake designer goods and make a lot of noise…

just because a law is difficult to enforce doesn't make it not exist. There are laws for this, and they are enforced. If you aint caught its not illegal?

Re: IP blocking the UK is not enough to comply with the Online Safety Act

#163

Earlier quoted context omitted.

> no internet regulation can hold for any subject No Internet regulation can hold extraterritorially . You leave out the obvious and most important case: the country where the Web site or whatever is located enforcing its own laws. Which is actually how all law has mostly worked from day one. > Openly selling stolen personal credentials or botnet usage? Piracy? Reselling personal information without disclosure? If yo…

> Which is actually how all law has mostly worked from day one. Internet but not for any other commerce. If you sell products to someone in the EU, you are liable to EU laws about that product category and commercial activity. The internet is the only exception, and that has caused a lot of problems. IP block is the currently the only reasonable way to apply laws to internet based commerce. It has its flaws in accura…

> Internet but not for any other commerce. If you sell products to someone in the EU, you are liable to EU laws about that product category and commercial activity. The internet is the only exception, and that has caused a lot of problems.

I don't know the state of play now, and I do know that things have gotten more that way over time. But the traditional approach to international product sales is that the importer is responsible. That originally meant the person who physically brought it into the country. As common carriers became more common, it meant the person who ordered the thing. That's occasionally been leavened by some consideration of whether the seller specifically targeted customers in the receiving country. And nowadays there's more of a tendency to start "blaming" sellers in some cases, probably because nowadays "importing" something is often a retail order from a specific consumer, as opposed to somebody bringing in a shipping container on spec to resell. Maybe some of those changes are appropriate, but it's just not true that physical goods have always been treated the way you want Web sites treated here, or even that they're mostly treated that way now.

> IP block is the currently the only reasonable way to apply laws to internet based commerce.

"IP block" works in both directions.

If you want to keep something out of your country, you should be responsible for blocking it, not the other way around. That's not necessarily easy, but it's less costly in total than demanding that every Web site enforce every country's regulation... and it has the advantage of putting the cost of a regulation on the people imposing it, which is where it belongs.

> It has its flaws in accuracy; but ISPs could easily create a system to make them more reliable for IP lookup.

From your use of the word "easily", I conclude that you personally would not be among those responsible for making that work.

> Arguing that websites cannot be regulated outside of country of origin is an insane position to take with even the minimal level of hypothetical reasoning of what that would imply.

First, you can in fact "regulate" by blocking, without trying to extend the reach of your laws outside of your border. Your claim that a regulator is left totally powerless is just false.

Second, in practice, that "hypothetical" is pretty close to what we have now, and even closer to what we had 10 years ago. The world did not end.

> UKs laws are dumb, but they should be free to enforce them for websites operating in the UK

Sure, as long as we recognize that "operating in the UK" properly means "is physically located in or controlled from the UK" and not "happens to be accessible to people in the UK". The latter definition would indeed be insane.

Re: IP blocking the UK is not enough to comply with the Online Safety Act

#164
post #153

[flagged]

You're saying that the UK's porn laws are "actively attacking the sovereignty" of the US in a way that is comparable to breaking a military alliance. Do I have that right? Further, you're implying this activity is NOT something that the US has historically and regularly done to other countries, including its allies in NATO?

Of course I am. A military alliance is contingent on the other party remaining an ally. Even Democrats would expect NATO to be dissolved if by some shenanigans Putin was elected PM.

That the US abuses it's position as the primary military power on earth to violate other nation's sovereignty is wrong and might matter "in the final calculus" but doesn't change how wrong this UK action is in isolation. It does bring up another absurdity particular to interactions between the US and UK which is that the US extended an insane amount of courtesy of not "finishing the job" once it was the predominant world power.

Re: IP blocking the UK is not enough to comply with the Online Safety Act

#165
post #84

You shouldn't even be expected to geoblock. If I'm operating a Web site in country A, I should not have to care about country B's laws unless I am taking specific action intended to attract users in country B in particular . That's doesn't mean just to target the whole world, either. If you don't want your citizens to access something in another country, take it up with your citizens. It was obvious from the minute t…

I don’t understand the IP location criticism at all. At least for my experience across Europe all locations that are being reported by the common databases are within 250km of the actual customer.

Maybe this is very european of me but 250KM is outrageously far. Dublin to Belfast is like 130KM. If it says they're in Seville (in Spain) within Comedically far.

Re: IP blocking the UK is not enough to comply with the Online Safety Act

#166

It is getting really hard to follow their logic. A some point, if you do not have any relationship with the UK, go as far as blocking its residents but they still want you to abide by their law, aren't they just declaring war on the entire world? This is something very deranged that have become very common with the world "becoming smaller": somes will go on a rampage for something happening on the other side of the p…

Of course not. But this is very useful to a) show they are enforcing this shiny new law and b) lay the legal groundwork that blocking it on their side (thruough UK ISPs) is warranted.

Re: IP blocking the UK is not enough to comply with the Online Safety Act

#168
post #156

Earlier quoted context omitted.

You check the country the ASN behind the IP belongs to.

ASN is even worse, honestly. If I'm behind starlinks AS then I'm American? AWS, I'm also American? Level 3? American. Colt leased line in my office in Madrid, apparently I'm English.

You are whatever your VPN exit node is.

Re: IP blocking the UK is not enough to comply with the Online Safety Act

#169
post #113

Earlier quoted context omitted.

It is a reply. I am not responsible for checking the locality of an IP address. Indeed, I can never do so with one hundred per cent accuracy. It is Not My Problem. Governments that expect some content or other blocked can damn well do it themselves, in their own legal system. They cannot compel someone else to spend his time, talent, or treasure to enforce their petty rules. If they go after one of their own for requ…

It is a reply... that you chose to send despite being fully aware that by doing so you might be reaching out across borders because that's how the internet and your contracts with your service providers works. Governments can do whatever they damn well please in their own territory. Including arresting you if you ever visit because you violated some law that they wrote that applies to people in the rest of the world,…

The US will enforce most UK court judgements. I'm not sure how administrative fines work; there might be a need to involve a court first, but once that's done the US will [on edit- may] enforce them.

The US will not enforce UK judgements or fines if enforcing them is contrary to the US' own laws, including its Constitution. SCOTUS ultimately decides when that's the case.

So it's really, really relevant to whether a non-US actor like Ofcom can actually collect fines from people inside the US. That's a separate question from what the UK government can do to people from the US who actually enter the UK, and an important one.

Re: IP blocking the UK is not enough to comply with the Online Safety Act

#170
post #84

You shouldn't even be expected to geoblock. If I'm operating a Web site in country A, I should not have to care about country B's laws unless I am taking specific action intended to attract users in country B in particular . That's doesn't mean just to target the whole world, either. If you don't want your citizens to access something in another country, take it up with your citizens. It was obvious from the minute t…

I don’t understand the IP location criticism at all. At least for my experience across Europe all locations that are being reported by the common databases are within 250km of the actual customer.

IP locations work great for probably a reasonably large chunk of services.

But it's the edges that get you.

I moved home a few years back, connected a new service with the same ISP.

They have an IP pool that is labelled as for one state (Victoria, Australia) but is also used for their services in Tasmania.

So now I have to fight every major website (Google, Amazon, Maxmind, etc) that does GeoIP lookups that I'm not in Victoria, I'm 500-800KM away.

Google was very confused for about 12 months because when I moved I also brought my wifi gear and so it would give me a precise location of my old address because it used wifi geolocation.

Post reply on HN