Live data from Hacker News

Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

signal.org

201–210 of 357 posts

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#201
Is it possible the child nudity detection could be done on-device, fully private? This wouldn't amount to surveillance.

The statistics on global child porngraphy rings are quite shocking. The UK is a big market consumer for these images/streams.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#202
post #24

So, in this order: 1. You need a camera on your computer to allow a third party to verify your age before viewing adult content 2. It applies to social media too 3. It applies to your operating system too 4. Unless you age verify, the law demands your computer must be powerful enough to run an AI, or be internet-equipped and send your private photos to a third party, to detect and prohibit nudity. It must be capable…

So this is ill defined.

However the original proposal was pretty much aimed at phone manufactures. It is perfectly possible for current gen phones (and previous gen) to detect nudes in camera. Infact most phones do that already in order to adjust the exposure, its just you dont see that.

The problem for the UK is that they are not legislating technically. The original proposal was tightly scoped. The problem was, because of the way government runs in the UK it was shelved. Now that its not, the original scoping has been mashed, as its been blended with an child social media ban (quite what makes them think social media is ok for elder millennials++ is also interesting)

If they actually decided to make laws like they did for building materials or cars (ie all phones must conform to EU/BS standard x/y/z) then life would be much easier for everyone. But alas we have forgotten how to govern. something must be done now

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#203
post #38

I sometimes wonder whether the people in the tech industry who worked on things like secure boot, attestation, and DRM saw this as the inevitability open source advocates always saw it as. Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means? Did they think they could lock things down to ex…

My impression is that people who can work on stuff like that are the kind who just take the stuff in the world for granted. "This is how the world is, we need digital restrictions so now we need to implement them." "I don't have a say about whether DRM or remote attestation is standard business practice or not, it is just how it is." This is akin to how two kinds of people respond to law. The first kind think "This i…

> The first kind think "This is the law, we must follow it" and the other kind think "This law doesn't make sense, we must change it".

Indeed. I can't understand the people who blindly believe any law is good just because. Stop, think. Is the law good? What's good about it? What's bad about it? Can it be abused? Then maybe it should be changed?

I advocate that every law should have an annual review to catalog every case where it has been applied. How many were sensible positive outcomes? How many were unintended consequences? How many were clear abuses of the letter of the law? Every legislator should vote on the record based on that annual review to either renew or cancel the law.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#204

I sometimes wonder whether the people in the tech industry who worked on things like secure boot, attestation, and DRM saw this as the inevitability open source advocates always saw it as. Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means? Did they think they could lock things down to ex…

> Did they think

Having argued these topics for decades, I think that a lot of people just truly can't foresee the inevitable consequences. I don't know why, the consequences seem obvious but because they are not spelled out, many people say it won't happen.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#205

Earlier quoted context omitted.

Does the law really require third party? Because having on-device functions configurable by parents doesn’t seem terrible at all.

It absolutely doesn't. However, the argument doesn't work when it's about connecting the "is the user a kid" bit to the existing and constantly running object recognition (phone cameras already run skin detection all the time to set white balance), so people invent "third parties" and "report people to authorities".

But "Is the user a kid" is already a switch that I (a parent) switch on in the device and that the kid in question can't switch off. That bit seems like a solved problem?

Why would anything else even be needed in that space? The interest of parents and tech companies likely align here.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#206

I sometimes wonder whether the people in the tech industry who worked on things like secure boot, attestation, and DRM saw this as the inevitability open source advocates always saw it as. Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means? Did they think they could lock things down to ex…

It isn't TPMs nor attestation nor DRM making this possible. It isn't secure boot either. It's walled gardens with secure boot -yes, secure boot- that the consumer can't bypass. Secure booting isn't the problem in an enterprise setting -- of course we _want secure booting_ in the enterprise. It's consumer devices that can't be jail-broken that are the problem. Although even then, the silly age verification laws and th…

> Although even then, the silly age verification laws and the people pushing them don't even care if the OSes run on walled garden devices.

Believe me, the people writing the age verification laws care a great deal whether the age verification can be turned off by the device owner.

The whole exercise would be pointless if teenage device owners could turn the censorship off.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#207

Earlier quoted context omitted.

Then you are the first kind. Since the law will not change, you will continue to follow it.

> "This is the law, we must follow it" and the other kind think "This law doesn't make sense, we must change it". There's zero point in changing the law if you don't expect it to be obeyed and enforced. Those positions are not opposites.

If you don’t expect it to be obeyed or enforced, then I would say that means it should be fast tracked to be changed. “Show me the man, and I’ll show you the crime.”

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#209
post #203
post #38

Earlier quoted context omitted.

My impression is that people who can work on stuff like that are the kind who just take the stuff in the world for granted. "This is how the world is, we need digital restrictions so now we need to implement them." "I don't have a say about whether DRM or remote attestation is standard business practice or not, it is just how it is." This is akin to how two kinds of people respond to law. The first kind think "This i…

> The first kind think "This is the law, we must follow it" and the other kind think "This law doesn't make sense, we must change it". Indeed. I can't understand the people who blindly believe any law is good just because. Stop, think. Is the law good? What's good about it? What's bad about it? Can it be abused? Then maybe it should be changed? I advocate that every law should have an annual review to catalog every c…

> I can't understand the people who blindly believe any law is good just because. Stop, think. Is the law good? What's good about it? What's bad about it? Can it be abused? Then maybe it should be changed?

I think many people have an expectation that (all) laws are just and needed because... somehow they're the law.

In reality, laws can be unjust, unnecessary, biased, and completely arm-wrestled together by people strictly following an agency of their own. Other laws are put together by sheer ignorance and lack of thinking beyond mere good intentions. The first question shouldn't even be "is this law fair" but "was this law made fairly".

It creeps me that people treat laws as axioms whereas they're just polished and reinforced opinions. Sure, many laws we can agree on, and many others that don't agree on aren't worth changing, but you should always question the law and question where it came from before choosing to accept it.

I can see the same pattern with technology such as the various digital restrictions management (DRM) schemes.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#210

I sometimes wonder whether the people in the tech industry who worked on things like secure boot, attestation, and DRM saw this as the inevitability open source advocates always saw it as. Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means? Did they think they could lock things down to ex…

> Did they think, as they worked to transfer final say from users to corporations, by technical means... Your argument is flawed here. The truth is that measures such as secure boot do have real security benefits. They can be misused, like any technology can be, but that is not an inherent feature of the tech, but rather how it is implemented. And as the developers of such measures are not a monolith, it is unfair to…

> They can be misused, like any technology can be, but that is not an inherent feature of the tech, but rather how it is implemented. And as the developers of such measures are not a monolith, it is unfair to paint them as merely trying to exert control.

You can argue that exerting control is a good thing - a clever scam artist convinces a vulnerable user to paste an attack at the command line, and the benevolent OS vendor uses their control makes the attack impossible, no matter what the scam artist tells the user to do. A greedy software maker produces a spyware-laden, cookie-stealing update and asks the user to enter the admin password to install the update. The benevolent OS vendor uses their control to make such malicious updates impossible, even with the administrator password entered.

But even if the control is being used exclusively for good, it is, ultimately, control.

Post reply on HN