Live data from Hacker News

Your compliance obligations under the UK’s Online Safety Bill

webdevlaw.uk

271–280 of 480 posts

Re: Your compliance obligations under the UK’s Online Safety Bill

#271

Earlier quoted context omitted.

In theory yes, in practice the US basically never extradites people to the UK and if they tried you would probably have a good defence (against extradition) under various parts of the constitution.

Weird how it only goes one way, isn't it?

It's not really weird. We have rights guaranteed to us in the United States that no other country has, so it makes sense we would not extradite.

Re: Your compliance obligations under the UK’s Online Safety Bill

#272
post #135

Earlier quoted context omitted.

Conservatives all over the world dream of setting up a chinese-style firewall in their countries. They are angry that it was first done by a clearly authoritarian regime which brings some resistance to the idea, but otherwise, in the name of fight against terrorism or child pornography, they would have set it up already.

From what I can tell it’s more the progressive wing of most countries who are pushing for authoritarian censorship of the internet. Just look at Canada

I agree that the Liberal's current push to degrade Canadian's privacy is worrisome - and their excuse is "we need expanded surveillance powers to make sure your privacy is protected..."!?!

I disagree that this is a partisan thing however. Whether it's Canada, the UK or anywhere else it seems each party in power just pushes for more surveillance and more censorship, just using different excuses to justify their actions.

For example, Harper's conservative government put forth bill C-13 (online crime excuse) and C-30 ('think of the children' excuse), which arguably laid the way for much of the spying apparatus that is currently in place against Canadian citizens. And while Obama allowed the NSA's warrantless internet surveillance program, Trump extended it until 2024.

All governments want to spy on you, and all governments want to be able to control what you say, period. They just want you to beg for it first.

Re: Your compliance obligations under the UK’s Online Safety Bill

#273

Earlier quoted context omitted.

In theory yes, in practice the US basically never extradites people to the UK and if they tried you would probably have a good defence (against extradition) under various parts of the constitution.

Weird how it only goes one way, isn't it?

Well in this specific case it would be pants-on-head stupid because this person committed no crime while under UK jurisdiction.

Like how would it even work if Alabama made it a crime for anyone in the world to have an abortion, extraditions all around?

Re: Your compliance obligations under the UK’s Online Safety Bill

#275

If UK government really cared about children, and not about surveillance and censorship, they would solve the problem another way. The only way protect children online is to ban them from Internet. Children should not have access to normal laptops and smartphones, instead they should use "kid phones". Such phones would allow children to communicate only with people approved by parents or teachers and visit only appro…

The truth of cause, it is about control. The kids part is to allow for a moral panic that the government needs to "save the kids" from. It would be profitable if you could charge a monthly fee for a kids specific social network that parents had control over who the kids could chat to and what news they could read.

The funny thing is that if I created a phone that had a kids mode lock-down (with kids friendly appstore, social media, browser and education content) with a monthly fee and no-ads. The government would scream that I was harming competition and locking people out by daring to charge for a product that would be expensive to operate.

Re: Your compliance obligations under the UK’s Online Safety Bill

#276

Earlier quoted context omitted.

Weird how it only goes one way, isn't it?

It's not really weird. We have rights guaranteed to us in the United States that no other country has, so it makes sense we would not extradite.

The US extradites people, including US citizens. That is required from the federal government by extradition treaties that are signed voluntarily by the US (in exchange for extradition _to_ the US). It is uncommon because they require escalations through the Department of State and not many crimes are serious enough to justify extradition.

Re: Your compliance obligations under the UK’s Online Safety Bill

#277
post #273

Earlier quoted context omitted.

Weird how it only goes one way, isn't it?

Well in this specific case it would be pants-on-head stupid because this person committed no crime while under UK jurisdiction. Like how would it even work if Alabama made it a crime for anyone in the world to have an abortion, extraditions all around?

States aren't allowed to have treaties with foreign countries, so no country could have an extradition treaty with Alabama even if Alabama wanted to and that country agreed to it (in exchange for something has Alabama has to offer?).

Re: Your compliance obligations under the UK’s Online Safety Bill

#278
post #264

Earlier quoted context omitted.

Autonomous pirate satellite internet

Men with guns. Yeah, they can't 100% win. They don't need to. In fact, even if they did 100% win, they'd still find reasons to need to crush some people just to keep people reminded of who has the guns.

The “men with guns” bit cuts both ways, though.

Re: Your compliance obligations under the UK’s Online Safety Bill

#279
post #254

Does anyone have a tldr? Respectfully to the author, I don’t have the patience to read through this blog post full of metaphores and anecdotes. So what happened?

tldr: In the name of "protecting the children," the British government wants to create an ultra-efficient police state so they can instantly hoover up information about every British user of the Internet, on a scale that would make the Chinese government blush.

Like the Chinese, they propose to put executives of ISPs and websites in jail if they fail to assist the government in the creation of this police state.

Unlike the Chinese, part of the plan is to make a few companies [more] fabulously wealthy: Namely the biggest tech giants like Alphabet and Meta who can afford the enormous costs of compliance, as well as certain homegrown British companies who specialize in estimating a user's age by using AI to analyze the size of a user's head in a webcam image.

Super-important points:

1. This is not about "adult content" websites. It covers just about any website that uses technology more advanced that static HTML files, regardless of content.

2. The provisions apply to any website worldwide that can be accessed in Britain.

3. The provisions make it effectively impossible to browse the Internet anonymously in Britain. The government also wants browser makers to make special British versions of browsers to assist them in deanonymizing users.

4. The cost of compliance for any small business will be so astronomical that GDPR compliance will seem trivial by comparison.

Re: Your compliance obligations under the UK’s Online Safety Bill

#280
post #269

Earlier quoted context omitted.

Very few websites comply with GDPR. Based on recent interpretations, it's essentially impossible for any US-owned or US-hosted site to comply with GDPR. The EU is just being extremely selective about its enforcement. If they ever decided to follow the law to the letter, most of the Internet would have to disconnect the EU. Theoretically the EU could make clones of all international sites like China has with Baidu and…

Regarding GDPR, citation needed - do you have actual links you can share to those claimed "recent interpretations", and whose in particular they are? I'd be quite interested to see them, if true ,which I seriously doubt - for the time being, as an EU citizen, my understanding is, and continues to be, that it's totally possible for US corpos to adhere to GDPR; it would just require some money and effort to be spent by…

They're decisions by the governments of Germany, France, and Italy:

* https://rewis.io/urteile/urteil/lhm-20-01-2022-3-o-1749320/

* https://www.cnil.fr/en/use-google-analytics-and-data-transfe...

* https://www.gpdp.it/web/guest/home/docweb/-/docweb-display/d...

So far they've just been enforced against companies that use Google Analytics, but the reasoning behind it has been that having users connect to a US server enables that server to know EU users' IP addresses (which are legally PII), which would be subject to US government subpoenas to collect such, and the US government has not agreed to handle data in compliance with the GDPR, therefore it's illegal to have users connect to any US servers. It has nothing to do with "hoover[ing] and hoard[ing]" data.

The only way for an American website to comply would be to form a separate company not subject to US control at all. However, at that point it's not really an American website, since no data or control can go to the US.

Theoretically you could use some international service to handle all primary routing and get users to waive their rights under the GDPR before connecting to your website proper, but I'm not aware of such a service at this time.

Post reply on HN