Live data from Hacker News

230, or not 230? That is the EARN IT question

signal.org

71–80 of 178 posts

Re: 230, or not 230? That is the EARN IT question

#71
post #53

Earlier quoted context omitted.

> Section 230 is a failure because Section 230 removes any financial incentive for platforms to moderate responsibility. What in the world does "moderate responsibility" mean? It's their site, they get to decide what goes on it as long as it's legal. If it's not legal, it has to be removed anyway! > If I report harmful content on Twitter or Facebook or Google, we need a system that ensures I receive a non-automated,…

>If it's not legal, it has to be removed anyway! Isn't that the original intent of section 230? Because these websites couldn't possibly moderate all possible user submissions for illegal content, that when illegal content is discovered that liability is held with the user and not the website hosting it?

Yes, that's the point of 230. It doesn't make anything legal that wasn't before, or illegal that was legal before. It simply assigns the responsibility of illegal content to the party that created it. Which is just a reasonable application of common sense.

I simply do not understand the motives behind people who want to abolish 230 - they would turn the internet into a stark split between heavily moderated websites, looking out only for their own liability because should they lay a finger on anything, they are culpable for everything - and unmoderated hellholes. Maybe they enjoy the hellholes and want more sites like that? Misery loves company.

I suspect most of the posters arguing against 230 are:

* Uninformed about what the law actually does

* Purposefully antagonistic and contrarian, or part of a coordinated troll campaign to sow discord

* Folks who have a bone to pick with big tech and will support any law, no matter how ridiculous, thinking it would cause big companies grief

* Spiteful that their post got moderated off a popular platform, and want websites to be forced to broadcast their content (despite this being a clear 1A violation of the company's rights)

* Really, truly, think that sites on the Internet should be either a wasteland or approval-only-posting, and you have to pick one

In any case, this kind of discussion around 230 is kind of burying the lede of the EARN IT act, which is a desperate attempt at not only further eroding 230 protections after the monstrosities of FOSTA/SESTA, but to allow the government to take away these common sense protections from a site unless they capitulate to government spying.

Which really should be the focus here, but somehow we're all distracted in the comments dismantling the faulty "platform or publisher, pick one!" argument again.

Re: 230, or not 230? That is the EARN IT question

#72

Earlier quoted context omitted.

This is the standard scream of incumbent players when they want to discourage regulation. It both ignores the fact that what's "reasonable" for an incumbent monopoly and a small startup are different, and that the law generally accounts for scale.

Does it "generally account for scale"? Citation needed. The GDPR has a fine structure of up to 4% of world-wide turnover or €20 million. Whichever is HIGHER. That means for any company doing less than say, €20 million in revenue and found to be non-compliant, GDPR gives the legal authority to fine them out of existence. I only mention GDPR as a specific example because of the familiarity here, but the general pattern…

Context matters:

The fines must be effective, proportionate and dissuasive for each individual case. For the decision of whether and what level of penalty can be assessed, the authorities have a statutory catalogue of criteria which it must consider for their decision. Among other things, intentional infringement, a failure to take measures to mitigate the damage which occurred, or lack of collaboration with authorities can increase the penalties. For especially severe violations, listed in Art. 83(5) GDPR, the fine framework can be up to 20 million euros, or in the case of an undertaking, up to 4 % of their total global turnover of the preceding fiscal year, whichever is higher. But even the catalogue of less severe violations in Art. 83(4) GDPR sets forth fines of up to 10 million euros, or, in the case of an undertaking, up to 2% of its entire global turnover of the preceding fiscal year, whichever is higher.

https://gdpr-info.eu/issues/fines-penalties/

Re: 230, or not 230? That is the EARN IT question

#73
I thought it was interesting when Twitch partners started talking about a Twitch policy that seems to hold the partner responsible for moderating their own chat. That is, if you are a partner and you have community members posting prohibited content into your Twitch chat then you stand to pay the penalty through a ban or losing your partnership. You are forced to moderate your own chat thereby relieving Twitch of having to do so (and presumably giving them some plausible argument that they are enforcing some level of site wide moderation).

It was interesting to see the reactions of these streamers since they aren't typical business people or legal experts. There was quite some debate amongst them about the fairness of the streamer being held responsible for random trolls that entered their chats. When I considered the viewpoint of individuals instead of corporations it did expand my view of responsibility/accountability.

Re: 230, or not 230? That is the EARN IT question

#74
post #18
post #12

Earlier quoted context omitted.

Contact Discovery is not seen as privacy invasive, I guess. It says, X has Signal, but that's it. So I see how it is, strictly speaking, broadcasting 'private' information, but it is hard to care terribly. I'm far more concerned by the privacy of my conversations than the fact I at one point installed signal.

But it means they have slurped all your contacts. How are they stored? Who are they shared with? etc

The DO NOT slurp your contacts.

They invented a way to do contact discovery in a secure way: https://signal.org/blog/private-contact-discovery/. From the article:

"Using this service, Signal clients will be able to efficiently and scalably determine whether the contacts in their address book are Signal users without revealing the contacts in their address book to the Signal service."

This is why Signal gets so much benefit of the doubt from the cryptography/security/privacy community. Their default approach to these problems is conservative in favor of the user until they can invent the technology needed to support a feature with security/privacy.

Re: 230, or not 230? That is the EARN IT question

#75
post #56

Earlier quoted context omitted.

You’re conveniently ignoring that the percentage-based fine structure in itself is almost literally “accounting for scale”. The minimum (of the maximum) set by the “whichever is higher” clause is needed to remain effective with non- and low-revenue entities. Something like Clearview (universal face recognition but startup with little revenue) would otherwise be free to ignore the law. If your small company does enoug…

> These fines also aren’t assessed arbitrarily: there’s a specific list of factors to take into account, and all decisions are subject to judicial review under the established principles of proportionality. You hope bureaucrats do not act mechanistically and do not apply proportionality, but over and over again in recent history you see that exact behavior. Which is why no business trusts a statement of 'they'll be m…

> You hope bureaucrats do not act ... nothing is effectively stopping them from not being nice other than some platitudes

One argument goes something like this:

The state always reserves the right to extinguish you, either by execution or permanent non-judicial incarceration, regardless of laws.

We all can only always hope state-level actors don't abuse their powers.

Whether they are or aren't at any particular time is somewhat subjective.

Re: 230, or not 230? That is the EARN IT question

#76
post #69
post #64

Earlier quoted context omitted.

This has been my blocker to using Signal or Telegram also.

With Telegram at least, you do not have to share your contacts with the app. You can build up a Telegram-specific list of contacts based on who you message on the platform.

This is the inverse of the issue. I don't want everyone that has my phone number to be able to see/add me on telegram. That would require those users not to upload their contacts, which is out of my control.

Re: 230, or not 230? That is the EARN IT question

#77
post #12

Earlier quoted context omitted.

Contact Discovery is not seen as privacy invasive, I guess. It says, X has Signal, but that's it. So I see how it is, strictly speaking, broadcasting 'private' information, but it is hard to care terribly. I'm far more concerned by the privacy of my conversations than the fact I at one point installed signal.

See, there's an apparently archaic concept in software called user preference - they could ask people upon joining if they want to be contact-discoverable or not.

And that's fair! It's not perfect. And, ignorantly, I would assume it'd be easy to add, so they probably should.

But I can understand why this is a trade-off they'd make in terms of your comfort level (relatively rare to care about this) vs. massive use-ability and onboarding gains.

Re: 230, or not 230? That is the EARN IT question

#78

Earlier quoted context omitted.

> No, and they wouldn't be by any informed understanding of the law. You are misinformed about the history of 230. 230 was proposed exactly because the law was interpreted the way you're saying it wouldn't be. From Wikipedia below, added emphasis mine: > This concern was raised by legal challenges against CompuServe and Prodigy, early service providers at this time. CompuServe stated they would not attempt to regulat…

But in a world where we feel it was backwards that moderators were punished and unmoderated platforms weren't... Congress decided "let's just make everyone immune" was the right way to go? And again, I think the examples here are missing the same concept that Section 230 fails to recognize: Profit, as I discussed here: https://news.ycombinator.com/item?id=22816016 It seems like the author of Section 230 failed to rec…

I don't like this malware example. Yes Section 230 protects Google from that and yes google is in a position of trust for the content they serve up but there's something wrong with your stance.

The point in your old lady's chain of actions where a law was and should be considered broken was when the malware ads were injected, not before. You can't go that far up the chain, there are too many proxies, too many people with intents that are not obviously malicious. People should be given the benefit of the doubt in most cases.

In addition, in your profit explanation that you linked to you stated that if the service can't scale up human interactions to match with complaints then that service shouldn't exist. That's laughable. To do so would make service owners so vulnerable to automated complaints that legitimate ones would never make it through, that goes for up and down the business scale. What your proposal ends up doing is creating a non-anonymous internet by necessity.

Re: 230, or not 230? That is the EARN IT question

#79

EARN IT is pretty disingenuous in how it is designed, of course, but I am all for making it harder and harder to retain Section 230 immunity: It's a mistake that we allow it in the first place. We should indeed continue to erode the eligibility for Section 230 to the point that either the limitations of remaining eligible for immunity makes it easy for competitors to produce better offerings without immunity, or that…

> Section 230's supporters constantly push hilariously insane narratives about it's importance, suggesting that without it companies would be inherently violating the law any time one of their users violated the law,

Can you explain in your own words what you think Section 230 actually does? Because yes, without it, that was very much the case (see Stratton Oakmont, Inc. v. Prodigy Services Co.) unless the company decides not to moderate at all, which is not an Internet that most of us want.

Re: 230, or not 230? That is the EARN IT question

#80
post #74
post #18

Earlier quoted context omitted.

But it means they have slurped all your contacts. How are they stored? Who are they shared with? etc

The DO NOT slurp your contacts. They invented a way to do contact discovery in a secure way: https://signal.org/blog/private-contact-discovery/ . From the article: "Using this service, Signal clients will be able to efficiently and scalably determine whether the contacts in their address book are Signal users without revealing the contacts in their address book to the Signal service." This is why Signal gets so much…

Thanks. That's actually great, I was wrong.
Post reply on HN