Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I find myself consistently disappointed when reading blog posts like this. I generally agree with the principles that the EFF advocates for, but it's hard to see this post as anything other than rage-bait. I can't trust it to be an accurate source of information on what this bill actually does.

For example, I've repeatedly seen claims that this bill would effectively outlaw end-to-end encryption, but the bill explicitly protects companies that offer encryption from liability.

>None of the following actions or circumstances shall serve as an independent basis for liability of a provider of an interactive computer service for a claim or charge described in that paragraph:

>(i) The provider utilizes full end-to-end encrypted messaging services, device encryption, or other encryption services.

>(ii) The provider does not possess the information necessary to decrypt a communication.

>(iii) The provider fails to take an action that would otherwise undermine the ability of the provider to offer full end-to-end encrypted messaging services, device encryption, or other encryption services"

When I look to the EFF for an explanation about why this language isn't sufficient, I get this:

>The bill clearly leaves room to impose forms of "client-side scanning"

Going back to the bill, the phrase "client-side scanning" doesn't appear anywhere in the text despite the EFF implying that they're quoting from the bill. If they're not quoting from the bill then what exactly are they quoting from? This is the kind of thing that makes me unable to trust them to be accurate, which makes posts like this effectively useless to me since I feel the need to independently verify all of their claims.



Client side scanning came out of the discussion around this bill the last time it was proposed. That it isn’t in this bill doesn’t mean it isn’t in politicians’ heads, and if this gets passed there is then significant precedent for extending it, as a small extension doesn’t seem as big as a full-scale government invasion of citizens’ privacy (i.e. this bill).


I don't believe the transition from "set up a commission to recommend best practices" to "mandate regular scans of everyone's phones and report the results to law enforcement" would be viewed as a small extension.


I wish I were as optimistic as you, but experience has shown me I can’t be, on this topic.


Perhaps the unspoken argument is that client-side scanning will be made into a best practice, and websites and apps that don't implement it will be exposed to liability.


So, I think the bigger issue is that those things may not serve as an independent basis for liability. But (B) then says that those things may be considered as evidence if they’re otherwise admissible (under the Federal Rules). In other words, encryption by itself does not expose them to liability, but those who might get sued could have encryption used against them as evidence that they “knowingly” possessed, transmitted, etc. CSAM. If robust encryption makes it more difficult to identify or stop CSAM trafficking, and a service refuses to compromise its encryption, that could be used as evidence against them.

That’s the fear, anyway.


Rage bait is by far the EFFs most powerful tool. Of course they're going to reach for it first.


The EFF seems to be going the way of many advocacy groups, where as time goes by their positions on the things they advocate for become less nuanced and they stop taking into consideration how those things fit into the big picture.

An example of this is the National Rifle Association (NRA). They used to think that carrying guns around in public should be restricted and require licensing, and that dealers should need to be licensed, and that some kinds of guns should be restricted.

For the EFF the thing that made me think that they are going down that road was during the controversy over Apple's plans to scan for CSAM. Apple had actually announced two things: (1) scanning on-device for CSAM in material about to be uploaded to iCloud, and (2) scanning on-device of devices with parental controls enabled to block messages that contained content that might be harmful to children.

Most of the discussion was about #1, both from the EFF and from everybody else. #2 was much less discussed.

Here's how #2 worked in the case where you have a child who is 13 or older with a phone on your family plan and you have enabled scanning.

1. I send your kid pictures of my dick.

2. The software temporarily blocks that and gives your child a modal dialog telling them it blocked something because their parents think it might be harmful, and asking the child if they want to go ahead and view the material.

3. If the child says no the material remains blocked and nothing else happens.

4. If the child says yes my dick picture is unblocked and nothing else happens.

If your child is under 13, here is how it goes:

1-3: same as the 13 and above case.

4. If the child says yes they are given another modal asking of they are sure and reiterating that their parents think the material may be harmful, and telling them if they do elect to view it their parents will be notified. They are again asked if they want to proceed to view it or not.

5. If the child says no, the material remains blocked and nothing else happens.

6. If the child says yes my dick picture is unblocked, and the parents are notified.

The EFF objected to this, on the grounds that #6 violates my privacy since I sent my dick pictures to your kid, not you, and did not consent to you getting access.

WTF? It used to be that a big argument from privacy groups against server-side scanning to protect children is that children shouldn't be getting to the bad parts of the net in the first place, and keeping the kids away was something the parents should take care of with things like time restrictions and parental control software.


This. The EFF used to be a force for good, but they are now free speech and privacy extremists backed principally by a tech industry that simply doesn't want to be liable for their negative impact on society.

The EFF will not ever support a regulation on big tech behavior.


[flagged]


You're literally denouncing the 4th amendment. You're saying that all of us must submit to warrantless and broad searches because the statistics says that at least some crime must be occurring. Absurd.

Or is it that there is an intermediary involved? Are you saying that banks that offer safety deposit boxes are responsible for their contents? Also absurd.


So 1984 style listening devices and cameras in every home is the obvious solution right? Houses are where a lot of abuse happens. Scanning doesn’t even stop abuse from happening, just the possession and distribution of it.


Thank you for illustrating my point about the poisoned well. Say "Don't participate in crimes" and it gets morphed into 1984.


Most people aren’t doing crimes. Roads are used to traffic drugs but we don’t hold the state accountable nor do we setup checkpoints within country to inspect cars for illegal material because some % of cars do.

If your point is that privacy advocates aren’t considering the negative aspects of technology I’m sure they have but see these efforts as a reach towards more state surveillance.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: