Live data from Hacker News

The House just voted to wipe out the FCC’s landmark Internet privacy protections

washingtonpost.com

201–210 of 534 posts

Re: The House just voted to wipe out the FCC’s landmark Internet privacy protections

#201

Does anyone know if this works retroactively? Is every data-hungry company soon going to know all of our past browsing behavior?

It's been legal to do so since 2015 and through next December at a minimum. That is the status the new administration inherited.

Re: The House just voted to wipe out the FCC’s landmark Internet privacy protections

#202

Earlier quoted context omitted.

You're correct and I edited my comment. I suspect that that may just be a tactic to save face in vulnerable districts rather than a sincere desire to oppose the bill.

That's a good point. Are the Republicans who voted against the bill relatively unpopular with their constituencies?

Hard won congressional seats will often sit out or sometimes even vote against their parties legislation but coordinate their votes inch a way that ensures that their parties legislation still passes.

Say you have 54 democrats in the senate, and a democratic president 4 democrats that had difficult races can abstain or vote against the bill while 50 democrats can vote for it, with the vice president being the tiebreaker.

Re: The House just voted to wipe out the FCC’s landmark Internet privacy protections

#203
post #169

Earlier quoted context omitted.

> not to mention tamper with Modifying the SNI hostname in transit is pointless - the client still knows what hostname they sent. Changing the SNI hostname would only cause the server to send back a different certificate, which would immediately be noticed by the client.

And break the connection. Mission accomplished.

If you can tamper with the connection and "breaking the connection" is "Mission accomplished", SNI isn't going to make any difference. You can just drop all the packets, and be done w/ it.

Re: The House just voted to wipe out the FCC’s landmark Internet privacy protections

#204

Before getting all spun up, I'd dig a little deeper on the issue than what the WaPo does in this piece. These regulations were only voted on late in 2016 and never went into effect. To do the regulations, the FCC reclassified the internet as basically ye olde telephone system, which then made it subject to their purview based on laws created in the 1930s. This is classic overreach. Congress never gave this authority…

The problem with this line of reasoning is that it somehow assumes that if the FTC were still regulating this then the Republicans would have left it alone. And that's nonsense. It doesn't matter who is regulating it, what matters is that you have a certain privacy, and soon you won't. That's all this is about.

Re: The House just voted to wipe out the FCC’s landmark Internet privacy protections

#205
post #182

Could and should have been filibustered in the Senate edit: note Senate....

Democratic Senators need to be careful what they filibuster. Absurdly, it only takes a majority vote for the Senate to change the rules to disallow filibusters. Then again, the vote to change the rules to disallow filibusters could itself be filibustered. But, the Senate, despite all that, could (on motion) declare the filibuster unconstitutional, and only require a simple majority vote to affirm it. Man, our Congres…

  Then again, the vote to change the rules to disallow filibusters could itself be filibustered.
That's what the Wikipedia article says, but I don't think that's correct. Otherwise, I think the Republicans would have filibustered Reid's invocation of the "Nuclear Option" that changed Senate rules to disallow filibusters on Federal judge appointments.

Re: The House just voted to wipe out the FCC’s landmark Internet privacy protections

#206

Earlier quoted context omitted.

You can't just say the regulations are old and therefore invalid because they're old. Remember, the telephone industry was regulated because telephone companies merged and cooperated to create regional monopolies and destroy competition, all at the expense of consumers. Comcast, Time Warner and the like have all been doing the same.

You also can't just say that the internet is the same as POTS. The FCC has scarcely been better than these companies. It has a history of being a revolving door for companies. Consider what RCA/FCC did to Armstrong back in the day. https://en.wikipedia.org/wiki/Edwin_Howard_Armstrong Just because the FCC does something doesn't mean its good, legal, or whatever. It's just what 3 of 5 unelected, unaccountable appointee…

The FCC's reclassification of ISPs under Title II does not assume the internet is the same POTS. It's a classification, not an equivalance.

Re: The House just voted to wipe out the FCC’s landmark Internet privacy protections

#207
post #75

Earlier quoted context omitted.

Business level service would permit and not throttle VPN. For consumer products, it will (probably) be an add-on. Whether they block or throttle or do both, is a market opportunity each ISP will decide.

Curious: if you're an ISP, how do you tell the difference between me VPNing into my Big Tech, Inc. and me VPNing into Private VPN, Inc?

Not necessary (and presumably not possible). Each end point pays extra for VPN.

Re: The House just voted to wipe out the FCC’s landmark Internet privacy protections

#208
post #179

Earlier quoted context omitted.

Please describe a way to do SSL without the domain being visible that can work for most sites. What would you encrypt the hostname with ?

I would not use SSL. Why spend time learning and fiddling with something that is so flawed? If I was serious about encrypting traffic I would use CurveCP. SSL is simply a nuisance I tolerate to read the www. Every minute I spend learning about it is wasted time... because I could be spending that time learning about something better, like CurveCP. The spread of SNI has just made SSL even more annoying.

Reading a bit about CurveCP isn't enlightening; it seems to be a UDP protocol that uses elliptic curve cryptography for encryption and authentication. But that, by itself, doesn't explain how it solves the problem that SNI solves better.

Say a client is speaking CurveCP with another party; how do they authenticate the other end? What if the other end has limited resources (such as IPv4 addresses) and needs to serve multiple entities, how do the client and server distinguish or determine which entity to authenticate to/for/with?

Re: The House just voted to wipe out the FCC’s landmark Internet privacy protections

#209

Please do not complain into the echo chamber of comments here. Please take a moment to support the EFF, call your representatives, and speak to friends and family. EFF: https://www.eff.org/ Find your reps: https://tryvoices.com/

support the EFF Not to say that most of what EFF does isn't valuable, but this privacy exposure has been going on for over a year and a half already . Why didn't the EFF call attention to it until now?

The court case over the FTC's authority was decided last August, and the FCC issued new regulations in October.

Re: The House just voted to wipe out the FCC’s landmark Internet privacy protections

#210
post #19

This, right here, is the consequence of the withdrawal from politics many geeks advocated very strongly in an earlier time. "Everything is corrupt, it doesn't matter"... turns out to only be a viable philosophy when things mostly work well enough . What we have in protections and freedoms were purchased through a ton of hard work by prior generations: the liberty to slack and think that it just works ok is a nice sid…

No, this is a consequence of the republicans being in power.

The Democrats also have policies that are... poor, particularly around the internet. This is a cross-party problem.
Post reply on HN