Live data from Hacker News

Your compliance obligations under the UK’s Online Safety Bill

webdevlaw.uk

211–220 of 480 posts

Re: Your compliance obligations under the UK’s Online Safety Bill

#211

Earlier quoted context omitted.

Don't worry, blocking p2p is the next step and is extremely easy to do. China has done it already and it's very effective: * Force every service provider to register their IPs and domains (for CDN use) * Force every ISP to do stateful firewalling and block every attempt to establish a new connection unless the destination IP is on a whilelist maintained by the government. Problem solved.

Autonomous pirate satellite internet

High altitude balloon laser net

Re: Your compliance obligations under the UK’s Online Safety Bill

#212

> If a British child could merely type your URL into a browser, the site is in scope. Seems incorrect, no? The visit is more important than just typing URL. Worst-case scenario I will check your IP and if its in UK/GB scope, you will see "Unable to browse this site due to your-stupid-anti-blah-blah-UK-policy"

The whole article is written like this - hyperbolically presenting the least generous reading she possibly can of the proposed law. > [A pretty reasonable set of questions that companies must consider regarding how children might be harmed on their service] > "you’re probably curled up in a ball crying" No actually, I wasn't. Filtering out the breathless commentary, the actual proposals don't seem that bad...? Certai…

Do you think prosecutors won't use the least generous reading of the law?

Re: Your compliance obligations under the UK’s Online Safety Bill

#213
post #195

Earlier quoted context omitted.

Don't worry, blocking p2p is the next step and is extremely easy to do. China has done it already and it's very effective: * Force every service provider to register their IPs and domains (for CDN use) * Force every ISP to do stateful firewalling and block every attempt to establish a new connection unless the destination IP is on a whilelist maintained by the government. Problem solved.

It’s very effective because people just use (illegal) streaming services instead :-) Otherwise one can run p2p over VPNs, like for many other things.

[deleted]

Re: Your compliance obligations under the UK’s Online Safety Bill

#214
post #169

If I, a US citizen, started an online service that attracted Ofcom attention, what binds me to following UK regulations? The article mentions "extraterritorial enforcement", but what does that mean? Will the US extradite me to the UK if I don't put monitoring in place? Will I get arrested if I visit the UK? Will they try to sue me in US court? I mean realistically if it became a problem I'd just IP-block all of the U…

In theory yes, in practice the US basically never extradites people to the UK and if they tried you would probably have a good defence (against extradition) under various parts of the constitution.

Re: Your compliance obligations under the UK’s Online Safety Bill

#216

Earlier quoted context omitted.

Don't worry, blocking p2p is the next step and is extremely easy to do. China has done it already and it's very effective: * Force every service provider to register their IPs and domains (for CDN use) * Force every ISP to do stateful firewalling and block every attempt to establish a new connection unless the destination IP is on a whilelist maintained by the government. Problem solved.

Wifi mesh nets in the city. Sneaker nets in between

Matrix over avian carrier

Re: Your compliance obligations under the UK’s Online Safety Bill

#217

Earlier quoted context omitted.

If this UK bill passes, I'd simply return HTTP 451 with a note that although the UK is blocked from my site, VPNs are not.

Promoting VPN usage could be construed by the UK courts as an attempt to commit subterfuge or dodge jurisdiction. They will not take kindly to this. You really want to make it perfectly clear that you want nothing to do with Britain as long as they have crazy laws on the books. Related point: if you're intending to get out of GDPR, blocking the EU doesn't really help, because the law applies on the basis of citizensh…

> If an EU citizen accesses your website in America, that's still within GDPR scope.

No, that's not correct. You have to be clearly intending to (not just incidentally happening to) offer goods or services to an EU data subject.

> ship things to the EU

This wouldn't be enough to make the GDPR applicable. You'd have to be specifically targeting EU customers in some way, such as allowing users to pay in euros - not just incidentally selling some stuff to folks who live in the EU. Your other examples (such as having EU business assets) hold because they would make you an EU entity.

Re: Your compliance obligations under the UK’s Online Safety Bill

#218
post #171

As someone from the EU, with no money or anuthing coming in from the UK, why would I even care about this? The GDPR has teeth only because the EU is big enough to make companies care. It is a watered down version from some privacy rights compared to the old laws in my country. But the old laws were ignorde by US tech because why wouldn't they. So as the UK left the EU, they are now a small country in the computer wor…

If the article is to be believed, then simply ignoring this law would open your company's leadership up to criminal liability in the UK. This probably doesn't matter too much, assuming they never fly through Heathrow or something.

Imagine if they fly through Stansted. That's a punishment in itself!

Re: Your compliance obligations under the UK’s Online Safety Bill

#219

Earlier quoted context omitted.

Brits don't have freedom of speech AFIK. it was never in their social contract.

We had it through negative liberty, opposed to positive liberty. The approach was that everything was permitted except that which is forbidden. So, instead of a 'right to' free speech, rather we _would_ have no laws restricting freedom of speech (libel and incitement excepted). This was the understanding that would've permeated Parliament, the courts, the palace, and the hearts and minds of everyone who understood it…

The constitution's amendments are different from other laws. Instead of restricting the people, it restricts the government power. It is there to make it harder for the government to devolve into a tyrannical one. The historical context (the US fighting against the monarchy of England for independence) is why it's there and it explains many of its regulation (including the right to bear arms, which was needed in order to fight against England).

The UK doesn't have it, which makes it a lot less stable, as seen in 1997

Re: Your compliance obligations under the UK’s Online Safety Bill

#220
The article says:

"Is it possible for your site, service, or app, which allows content to be shared and/or people to communicate with each other, to be accessed by any adult or any child within the UK?

Then you’re in scope.

NB “accessed” doesn’t necessarily mean that a user can set up an active account on your service. If a British adult can merely download your app on the app store, the app is in scope."

However, the draft bill doesn't seem to say that. I found the draft here: https://www.gov.uk/government/publications/draft-online-safe... (and note that the article doesn't seem to link it, which seems odd).

The bill says:

"In this Act “user-to-user service” means an internet service by means of which content that is generated by a user of the service, or uploaded to or shared on the service by a user of the service, may be encountered by another user, or other users, of the service.

That seems reasonable to me. There are more details, but as far as I can see, the ability to merely download an app does not put it in scope contrary to the claim in TFA.

I now find myself doubting the the other claims made by this author.

Post reply on HN