Live data from Hacker News

Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

haddadi.github.io

31–40 of 164 posts

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#31
post #28

Earlier quoted context omitted.

It'll be a matter of installing the app "from unknown source" then?

Can't do that on iOS.

Technically you can, but the hoop jumping isn’t ideal.

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#32
post #20
post #16

Earlier quoted context omitted.

It's not going to be enforced that way even if that's what the text says. Although it might get spicy if one of the megacorps decides the legal risk is real and withdraws from the UK market.

If it is implemented as per the legislation, the UK would need to be disconnected from the global internet, and most activity economic or otherwise would cease overnight. I should really retract my original position, things in the UK would be very different. Honestly, it kind of needs to happen properly, otherwise people will never learn. Allowing these half baked pieces of legislation to pass and then not implementi…

Given what has happened previously and all the bickering about "the blob", I suspect this simply won't be implemented except for possibly a token target.

Has anyone checked if the legislation has the special clause for "prosecutions require permission from the Attorney General"? (i.e. politically motivated prosecutions only - this has been seen before)

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#33
post #19
post #8

Earlier quoted context omitted.

What would happen in the ideal world: - All online messenger providers (Whatsapp, Signal, Telegram) e.g. withdraw from the UK market. Meta and Google gave a taste for this after Canadian link law. - UK needs to come up with a crappy homebrew messenger ecosystem no one uses. Maybe a messenger.gov.uk? - People download applications with privacy and sideload them to their mobile phones, keep going with their business as…

Closing the sideloading hole on Android then becomes the next step. It's already a nonissue on the most popular device. Eventually the sale of devices that don't include cryptographic controls to prevent terrorists from misusing them to evade terrorist surveillance will be outlawed.

Remember that the Play Store uses encryption to download apps to the phone. If the law is enacted then this encrypted channel will technically need to be compromised too, which Google might also object to. If Google withdraw the Play Store from the UK, then what are they supposed to do?

This law doesn't just apply to messenger apps. It applies to almost every single act you perform on the internet. Everything will be mandated to be broken, including your browser. If you run a web server using https, you'll be breaking the law. If you ssh to another computer over the internet, you'll be breaking the law. If you connect to a VPN to access a work/university/school network or indeed a commercial VPN, you'll be breaking the law.

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#34
post #18

Earlier quoted context omitted.

E-commerce will still happen, just with lessened security.

Or non-lessened security, and selective enforcement. Of course this is for "terrorists", not businesses.

Unlikely. The police will not renounce capabilities to track down all things a suspect ever bought.

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#35
post #24

Earlier quoted context omitted.

There's a general "bad" when law are enacted and then not enforced, especially if it's a law that most people would naturally break because it's a silly law. It allows the authorities to persecute chosen individuals while not actually achieving anything that the law as written looks like it should be trying to achieve. And this is a silly law. Everyone will break it, every time they use an encrypted communication, wh…

> then when they want to crush someone they're certain to find some law that they have broken like this one The will get a prosecution after catching red-handed a mass murdering terrorist or a pedo with kids locked in their basement because they did an online shop which "used encryption". The authors will claim victory, without these protections we couldnt lock these people up, the Sun and the Mail readers will lap i…

Don't forget the victim surcharge.

Remember that Al Capone was jailed for tax evasion.

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#36
Total lack of response to this letter will speak volumes about the essential nature of this UK Government. The UK Opposition Party's view as of last January is here: https://www.theguardian.com/technology/2023/jan/01/labour-pl....

Background: https://www.theverge.com/23708180/united-kingdom-online-safe...

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#37

Earlier quoted context omitted.

It'll be a matter of installing the app "from unknown source" then?

Which, unfortunately, is a rather risky situation considering for instance all the rogue ChatGPT-branded extensions and apps people downloaded without a second thought to their legitimacy. We have been conditioned to view branding as the certificate of legitimacy, and that simply is not true for the Internet where branding can be copied and pasted in seconds.

I doubt they still do it but for whatever reason for a while WhatsApp loads to offer it's APK on its website.

Bet it saw very few installs wonder if we'll go full circle.

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#39
post #36

Total lack of response to this letter will speak volumes about the essential nature of this UK Government. The UK Opposition Party's view as of last January is here: https://www.theguardian.com/technology/2023/jan/01/labour-pl... . Background: https://www.theverge.com/23708180/united-kingdom-online-safe...

Looks like the opposition's stance is even worse.

Labour's Lucy Powell:

“The weakened bill will give abusers a licence to troll, and the business models of big tech will give these trolls a platform.”

So the Labour government will get to decide who's a "troll," and whether they're de-platformed AKA cancelled.

Likewise Labour's desire to curb "legal but harmful" speech means that Labour will get to decide, on an ongoing basis, which speech is "harmful." It won't be defined in law, so the definition will be completely subjective, and ripe for corruption and chilling suppression of innocent people.

Post reply on HN