Live data from Hacker News

230, or not 230? That is the EARN IT question

signal.org

91–100 of 178 posts

Re: 230, or not 230? That is the EARN IT question

#91

Earlier quoted context omitted.

There would be no key change because there would be no initial key, signal facilitates contacts anyway the only difference is that the sides have no ability to control with whom it takes place. Messages to non-contacts will not be sent because there would be noone in your contacts to send them to, hence indistinguishable.

I don't follow. I'm sending (or trying to send) messages to my contacts. If I know their phone number, I'm going to try to initiate a Signal conversation with them. So I ask the Signal server for a signed prekey. Your argument is that Signal should not respond with "I don't know this person" and should instead respond with something indistinguishable from a "real" response. So they must send me something that looks l…

Signal server should respond with "I either don't know this person or they have not approved to be contacted by you". You should only get a prekey if they are in fact a signal user and have opted in to be discoverable by everyone or only by select people including you.

Re: 230, or not 230? That is the EARN IT question

#92
post #31

Earlier quoted context omitted.

> If I report harmful content on Twitter or Facebook or Google, we need a system that ensures I receive a non-automated, competent response That seems extremely prone to being DOS-ed by bots or a brigade of complaint-heavy users.

If a platform can't scale to handle content moderation requests, it shouldn't exist at scale. Presumably a company shouldn't be responsible to respond to bot submissions, and could potentially ban complainants who abuse the system. (Although doing so would potentially open them to legal recourse if they were banning someone for filing legitimate reports they just didn't want to deal with, for example.) There are reas…

> If a platform can't scale to handle content moderation requests, it shouldn't exist at scale.

Agreed. This whole "we got so big chasing crazy growth that making us responsible for cleaning up our own mess would make us lose money" argument is very tiresome and one that I can't see holding any water outside of tech.

Re: 230, or not 230? That is the EARN IT question

#93

Earlier quoted context omitted.

At least that requires the other person to have my contact saved, and actively try to reach me. I don't clear out my contact list frequently, so I don't want old contacts to be PROACTIVELY messaged about me joining Signal... if they are looking for me, fine.

How does it require them to actively try to reach you ?

Because it requires the customer to try to send a message to the contact. They would have to continuously do that if they wanted to be notified when I joined.

This is very different than Signal doing it automatically when I join.

Re: 230, or not 230? That is the EARN IT question

#94
post #6

Earlier quoted context omitted.

How would a messaging app work without contact discovery? You try a friend's number, and see if the message goes through? Well if that's what you want, then you can do this for all your phonebook numbers, and all the ones that go through are on Signal, and all the ones that error are not. Oops, you've reinvented contact discovery.

> How would a messaging app work without contact discovery? "Hey, add me on telegram, my username is @andrewzah". This isn't a hard problem. I don't know why we decided apps hoovering up our contact lists in exchange for convenience was so important. For an app that touts itself as private and secure, I still had to explain to my brother why giving it his contact list wasn't a good idea.

This is a hard problem. The evidence for this is the decades of failed attempts to get people to use pgp and other systems where I need to have a freaking party in order to figure out who I can message and how before I actually start communicating.

Re: 230, or not 230? That is the EARN IT question

#95
post #11
post #6

Earlier quoted context omitted.

How would a messaging app work without contact discovery? You try a friend's number, and see if the message goes through? Well if that's what you want, then you can do this for all your phonebook numbers, and all the ones that go through are on Signal, and all the ones that error are not. Oops, you've reinvented contact discovery.

I guess I just don't value "contact discovery" as a feature? I just don't see it as a casual thing the way the target users of these apps apparently do. I want to explicitly control, per any form of communication, each person who is to be made to know that I operate that form of communication and whether or not that form of communication with me is open to them. I do not want to open up a new app and have a large pop…

In order to do this, the signal server must maintain a list of who is allowed to talk to who, otherwise the list of people available on signal can be obtained through enumeration.

This is a privacy trade off. Some services chose to keep this list. Signal chose to use phone numbers.

Re: 230, or not 230? That is the EARN IT question

#96

Earlier quoted context omitted.

MapQuest did nothing wrong in this example. The problem is the fake sites that are taking the top spot in search results above the legitimate MapQuest link when you search Google for MapQuest, and Google refuses to delist them. And of course, Google lets people buy ads for other companies' trademarks, which is a whole different ball of issues. (MapQuest is a popular one for malicious sites to pretend to be because mo…

What does this have to do with Section 230?

The moment someone points out Google makes a huge amount of money on scams and malware, and due to Section 230, can't really be held responsible for it.

Re: 230, or not 230? That is the EARN IT question

#97
post #77

Earlier quoted context omitted.

See, there's an apparently archaic concept in software called user preference - they could ask people upon joining if they want to be contact-discoverable or not.

And that's fair! It's not perfect. And, ignorantly, I would assume it'd be easy to add, so they probably should. But I can understand why this is a trade-off they'd make in terms of your comfort level (relatively rare to care about this) vs. massive use-ability and onboarding gains.

What you call "comfort level" is in fact the primary value proposition of a tool like signal and the fact that they have chosen to compromise on it to drive adoption is symptomatic of the many things wrong with the setting in which this decision was made. Not unlike calling out the EARNIT senators on using child abuse justifications in bad faith to promote the agenda of censorship and surveillance.

Re: 230, or not 230? That is the EARN IT question

#98

Earlier quoted context omitted.

If a platform can't scale to handle content moderation requests, it shouldn't exist at scale. Presumably a company shouldn't be responsible to respond to bot submissions, and could potentially ban complainants who abuse the system. (Although doing so would potentially open them to legal recourse if they were banning someone for filing legitimate reports they just didn't want to deal with, for example.) There are reas…

> If a platform can't scale to handle content moderation requests, it shouldn't exist at scale. Agreed. This whole "we got so big chasing crazy growth that making us responsible for cleaning up our own mess would make us lose money" argument is very tiresome and one that I can't see holding any water outside of tech.

Exactly. There's an exclusive mindset in tech that it's okay to automate human problems and then just say there's nothing they can do when automation isn't adequate. Other businesses have huge percentages of their workforce tackling problems that tech companies just say they're not responsible for, like content moderation, customer service, etc.

Re: 230, or not 230? That is the EARN IT question

#99
post #70

Earlier quoted context omitted.

OK, so please do tell me how to sue `sk8rboy2020` on the forum then?

Sue John Doe, and ask the court to issue a subpoena to the forum for identifying information, and then to the ISP, and once you have that, add the account holder as a defendant to the suit. It's not fast, and it's not easy, but such is life.

Proxy server usage would skyrocket if this became common - as it should.

Re: 230, or not 230? That is the EARN IT question

#100
post #70

Earlier quoted context omitted.

Sue John Doe, and ask the court to issue a subpoena to the forum for identifying information, and then to the ISP, and once you have that, add the account holder as a defendant to the suit. It's not fast, and it's not easy, but such is life.

Proxy server usage would skyrocket if this became common - as it should.

Whoever is running the proxy can also get a subpeona. If you run it yourself the ISP will know who you are. Someone is paying to access the internet, so they probably have records.
Post reply on HN