Live data from Hacker News

Imgur pulls out of UK as data watchdog threatens fine

express.co.uk

661–670 of 735 posts

Re: Imgur pulls out of UK as data watchdog threatens fine

#661

Earlier quoted context omitted.

If you are serving the UK market, you follow UK laws. It's that simple. In this case they are misusing UK children's information, that's a no-no in a country that has actual consumer protection laws. I'll wait for the EU to catch up on this too. While the UK and EU (and US) like to pass stupid laws, in this case it's just an American company misusing citizen's data and not giving a crap. Good riddance.

"Serving a particular market" is ridiculous. Just adding Paypal to your website should not require you to understand 200 odd legal jurisdictions. This needs to end asap.

If I sell a product to a US citizen I have to pay US income tax despite not being in the US, my business not being in the US, and not creating the product in the US.

I then have to hope the US has a tax treaty with my country in order to attempt to recoup the costs.

Is that fair?

Re: Imgur pulls out of UK as data watchdog threatens fine

#662
post #555

Earlier quoted context omitted.

> What about I sell advertising packages to a US company from my US HQ but someone in the UK views and advert on my site and therefore generates me 0.001¢ - debatable. Not entirely sure what is debatable about this situation. You quite unambiguously derived revenue from a UK citizen here, although not much. If you didn’t want that revenue, then don’t display ads in the UK. If that makes serving traffic to the UK unec…

OK, so if I'm a blogger making a few hundred dollars a month from adsense on my blog, I'm actually subject to every single jurisdiction on the planet unless I actively (and completely!!!) block access from there?

This is why a lot of content is hosted on large platforms that handle this risk for you. But if you don't collect any personal data on those users your exposure is minimal but technically some jurisdiction could claim you allowed access to "illegal content" under their law.

Most of these jurisdictions can't actually do anything about it, but they can claim they will. The UK might actually be in this situation.

Re: Imgur pulls out of UK as data watchdog threatens fine

#663
post #74

Earlier quoted context omitted.

If you mean the opinion polls, I don't have any to hand, but there have been a few articles submitted to /r/ukpolitics since the Online Safety Act took effect detailing opinion polls showing that the UK Government's regulation of internet content has been well-received by the wider public (although the userbase of that subreddit has vociferously disagreed).

You are probably talking about the YouGov poll. The poll asked a clearly leading question IMO. You can get any result you want by asking leading questions on polling. This was of course satirised by Yes Minister. https://www.youtube.com/watch?v=G0ZZJXw4MTA I can counter any of the iffy polls by simple point to the official online petitions service. There were a huge number of signatures to revoke OSA and two million…

The Bristol young lib dems oppose it, but the parliamentary party doesn't think it goes far enough. The Bristol lot are great, I talked to them about it, but they're unlikely to change things on the national level.

Re: Imgur pulls out of UK as data watchdog threatens fine

#664
post #348

Earlier quoted context omitted.

> why would I be subject to their laws? For the same reason that a person under British jurisdiction is subject to its laws. I mean, laws, including British ones, exist for a reason. And usually, that reason isn't "because they're British," and this reason makes sense regarding to non-residents as much as it does to residents. > Just because it's accessible globally means I now have to factor in every possible regula…

> Unfortunately, international laws and international cooperation are not yet sufficiently developed, and extradition requests for such reasons are not a common occurrence yet. Unfortunately? You’d prefer that the owner of a UK pro-LGBT site could be extradited to Uganda over some anti-gay law? Should BBC reporters be sent to the gulag for writing an unfavorable article about Russia? The fantasy world you’re imaginin…

> You’d prefer that the owner of a UK pro-LGBT site could be extradited to Uganda over some anti-gay law? Should BBC reporters be sent to the gulag for writing an unfavorable article about Russia?

Indeed, a good argument against globalization and international law. So yeah, fortunately, international laws and international cooperation are not yet sufficiently developed, and extradition requests for such reasons are not a common occurrence yet.

Re: Imgur pulls out of UK as data watchdog threatens fine

#665
post #629

Earlier quoted context omitted.

Thanks. And out of curiosity, could you name some positive things the Internet has enabled? I'm also curious how you think we could have rolled it out better to have avoided those things.

-->could you name some positive things the Internet has enabled This interaction? Honestly much much harder to list the positives. I think much more regulation much much earlier. Cypto-currency should have been shut down immediately never allowed to grow. Same with Uber and AirBnB. Social media companies should have been banned from during algorithmic feeds and been required to moderate content much better.

> This interaction? Honestly much much harder to list the positives.

Well while I appreciate that, I'd urge you to dig a little deeper; I'm sure you can think of many things. The Internet has enabled creativity, the sharing of knowledge, scientific advancement, and international cooperation & communication (I'm speaking mainly between citizens) on scales unimaginable a few short decades ago, to name just a few things!

Certainly, there are issues that comes with it - and we can and should solve them! - but ignoring the massive good it brings is not good. I'd also point out that many of the issues you outlined certainly predate the Internet, and were in fact much easier to accomplish - genocides happened and were easier to hide (or at least shape the narrative of) when information was a lot harder to distribute. People believed in all sorts of crazy things too, with little or no hard evidence.

Re: Imgur pulls out of UK as data watchdog threatens fine

#666

Earlier quoted context omitted.

All solved problems. Phones can have passcodes, fingerprint readers, facial recognition (for parents face) to keep kids off them. Devices can have multiple user accounts, each with different purposes and applications. On my linux laptop, I have two accounts, one for work & one for personal, with distinct applications and configuration. If all else fail, each manufacturer can product a simple device that can only chat…

Lol. One of my colleagues had Child Services round, as their daughter had told her school he was abusing her, because he confiscated her mobile (that he was paying for). Good luck "parenting" any child in this day and age, when any seemingly minor things you think you can do as a parent, lead to that sort of outcome. How'd you keep a kid off the internet, when they're happy to say anything to the authorities get that…

And what happened when child services came? Exactly nothing.

I'm a parent, and it's hard, but 0% of it is hard because of the government meddling in my parenting.

Re: Imgur pulls out of UK as data watchdog threatens fine

#667
post #544
post #497

Earlier quoted context omitted.

There are several US news websites that are completely blocked in the EU and UK since GDPR came into effect, because it was easier than caring about data collection. Probably many of them adapted since then, because everyone realized GDPR has no teeth and most websites that are not global platforms are not compliant.

The ironic thing is that in the UK/imgur case: >The ICO also confirmed that companies could not avoid accountability by withdrawing their services in the UK. Wonder if it could also apply to American news sites (and Japan's 5ch/2channel, I was told they engage in this as well).

No, they claim they can't "avoid accountability" by withdrawing services in the UK. What Imgur cares about is where its staff live and work and pay taxes, which is America. The odds that America will cooperate in going after Imgur if they just block the UK go from slim to none.

Re: Imgur pulls out of UK as data watchdog threatens fine

#668
post #267

There's an opportunity for a service like CloudFlare here give people a simple toggle that manages geoblocks on legal liability factors. It's way too much for every organisation to individually track every country's laws day by day in case just by being accessible there you incur a liability. And it sounds like the UK would have just self-selected out of the list of "safe" countries. If something like this was in wid…

> in case just by being accessible there you incur a liability. This is a dangerous precedent though that IMO everyone should fight against. It's how we get the balkanization of the internet, and the death of it as a global network. TBH we also shouldn't put the onus on blocking "unsafe" countries on the website owners, nor an intermediary like CloudFlare. If a nation wants to block certain content, let the nation de…

It's how we get the balkanization of the internet, and the death of it as a global network.

That ship sailed at least a decade ago.

From small instances like your employer blocking certain web sites (Google Translate, seriously?) to China's Great Firewall to nations restricting access in certain regions (India, many others), to nations restricting access to certain web sites (Turkey, many many others), to entire countries taking themselves entirely offline (Afghanistan, most recently).

Re: Imgur pulls out of UK as data watchdog threatens fine

#669
post #127

Earlier quoted context omitted.

You are sending data into the UK, hence you have to abide by their laws regarding said data.

or what?

I’m explaining why UK law applies. Prosecution and enforcement are separate topics.

Re: Imgur pulls out of UK as data watchdog threatens fine

#670

Earlier quoted context omitted.

I still don't understand how someone is supposed to benefit from such a thing. If I want to use some service, I'll sign up for an account with it. The only thing a centralized ID is going to do is let the service correlate me with a different account on a different service, which is exactly the thing that I don't want. How is someone supposed to benefit from a thing whose only function is to reduce the friction again…

You're mistaken, the proposed system isn't centralized. The IDs only exist in the wallet. The wallet uses Digital Verification Services (DVS) to poll APIs in front of the data the government already holds on you. These services check details you enter against that data and return cryptographic signatures for each. The wallet puts these together as IDs in a bespoke way, depending on what you need to prove. You can hav…

> You're mistaken, the proposed system isn't centralized. The IDs only exist in the wallet.

That's a password manager or authenticator app. You don't need a government to do anything to have that.

> Some of these signed proofs can be disclosed using Zero Knowledge Proofs (a cryptographic means of demonstrating something without demonstrating anything else) which would actually make it harder to 'correlate' you in the way you describe.

People always bring this up as a theory, but most of the ZK systems don't actually do this, e.g. they give you a bitstring that "doesn't identify you" but they know who you are when they give it to you, and you're meant to present it to a third party who could collude with the service who does know who you are to map it back to you.

In other words, the ZK proof is an attempt to bamboozle people with complicated math rather than something that really works.

The only way to actually prevent this is to make the data the user presents to the second service indistinguishable for all users meeting the qualification, i.e. if you're over 18 then you get a secret, everyone over 18 gets the same secret, and then the second service just gets the secret and compares it, and you rotate it with some interval which is at least a week. (You can't rotate it continuously or you get timing attacks; even once a week is giving up a non-trivial amount of entropy because you can narrow down the user to the people who have requested the token in the last week and repeat the process every week that person uses it to keep winnowing it down.)

But the proposals don't ever seem to do that, most of them don't even use ZK proofs or don't use them properly.

> Another thing to bear in mind, the ID is backed up by the Data (Use and Access) Act 2025 which reinforces data protection laws and actually wards against the use you describe.

You can't fix this by making it illegal because you don't have a mechanism to identify when they're doing it. You give them data that could identify you and then whether they use it for that happens behind closed doors.

Then you get all of the chilling effects even if they're not (currently) doing it because with no way for people to corroborate, people have to assume that they are. And on top of that, you've now deployed a system that ties everyone's activity to their identity and then it's just the stroke of a pen before they're doing it openly, or it comes out that they're doing it illegally but nobody does anything to stop it a la Snowden.

Post reply on HN