[HN Gopher] Ask HN: Online activities to be made impossible by t...
       ___________________________________________________________________
        
       Ask HN: Online activities to be made impossible by the UK Online
       Safety Bill
        
       I thought it might be interesting to compile a list of things which
       it might be impossible (or at least very difficult) for a private
       individual to do under the Online Safety Bill.  Starters for ten:
       1) Minecraft / MineTest server 2) IRC server 3) Mastodon server 4)
       BBS 5) ... please continue  I'm not fully sure about all this - as
       I understand it, if you allow chat or user generated content, you
       become a private service provider, and then have a host of
       responsibilities including annual audits of whether a significant
       proportion of your users are minors. If they are then you need to
       use a (commercial?) age verification tool and monitor everything
       assiduously. Difficult to see most people being able to satisfy
       those requirements.
        
       Author : b800h
       Score  : 164 points
       Date   : 2023-07-29 11:31 UTC (11 hours ago)
        
       | ta8645 wrote:
       | Comment section on your personal blog?
        
         | jonatron wrote:
         | Exempt under "Schedule 1 -- Exempt user-to-user and search
         | services"
        
           | ta8645 wrote:
           | Is a comment section user-to-user, though? On its face, it
           | seems more user-to-public, since it's not a private user-to-
           | user transmission. If blog comment sections are exempt, it
           | would seem Reddit is exempt too.
        
             | jonatron wrote:
             | Reddit is user generated content, so isn't exempt.
             | 
             | "provider content" means content published on a service by
             | the provider of the service or by a person acting on behalf
             | of the provider.
             | 
             | It's unclear if there's a difference between hosting your
             | own blog, or using a blogging service, because the bill is
             | terrible.
        
       | pmlnr wrote:
       | One scenario is that Whatsapp and Apple leave the UK market,
       | another is that nobody going to do anything about the "law",
       | which is rubbery enough to be ignored. I'm quite curious how it's
       | going to go down.
        
       | austin-cheney wrote:
       | Why isn't VPN to an out of country relay a solution?
       | 
       | At any rate situations like these are what partially motivated me
       | to write something like this:
       | https://github.com/prettydiff/share-file-systems/blob/master...
        
         | OJFord wrote:
         | I assume:
         | 
         | 1) we're talking about the legal situation, not what would be
         | physically possible;
         | 
         | 2) that it applies to citizens, not server location (otherwise
         | affected companies wouldn't be saying they'll exit the UK
         | market, they'd just serve UK users from a further away but
         | friendlier 'edge')
        
         | tm2t wrote:
         | I don't think it would be legal either since VPNs require
         | encryption, too. Maybe some kind of proxy?
        
           | b800h wrote:
           | It's important to distinguish this from the encryption
           | provisions of the bill. This part of the bill is distinct and
           | means that social sites will need to verify ages of users and
           | fill in lots of forms while they're at it.
        
             | loufe wrote:
             | ...for now.
        
             | tm2t wrote:
             | I see. Thanks for the explanation :)
        
         | [deleted]
        
         | yuumei wrote:
         | Because of cloud flare and the like. If you have spent any time
         | on a VPN you know the issues with captchas destroying the
         | internet
        
         | rovr138 wrote:
         | Costs would be one. That's yet another cost you have to take
         | on.
        
       | ChrisKnott wrote:
       | My understanding is that the OSB creates a responsibility for
       | Ofcom to create a regulatory system for discouraging online
       | harms.
       | 
       | Has Ofcom actually said what these regulations will be?
       | 
       | Is there any reason to expect them to be as dystopian as you
       | predict? The interim codes of practice that the government
       | published don't even apply at all to individuals. They also
       | acknowledge that smaller companies should not be expected to be
       | subject to the same level of regulation as large companies.
       | 
       | My experience with online activists' predictions of imminent
       | dystopia is that they generally turn out to be extremely
       | overblown. Hopefully that's true this time as well.
        
         | Silhouette wrote:
         | _Is there any reason to expect them to be as dystopian as you
         | predict?_
         | 
         | Previous laws relating to policing and investigatory powers
         | have been widely criticised by civil rights groups for their
         | overreach and lack of effective oversight and safeguards. We
         | now know that some of those laws have in fact been abused in
         | ways the critics predicted.
         | 
         | Secondary legislation has been widely criticised when used as a
         | vehicle for government ministers to make rules with statutory
         | authority while bypassing the usual requirements for
         | Parliamentary scrutiny and approval of new laws. Our Home
         | Secretary is currently attempting to use secondary legislation
         | to implement controversial immigration policies after
         | essentially the same measures were already explicitly blocked
         | by Parliament when they were put forward via primary
         | legislation.
         | 
         | So yes - there are unfortunately plenty of precedents both for
         | broad legal powers being abused and for secondary legislation
         | being used to circumvent our normal democratic processes for
         | scrutinising and approving controversial measures.
         | 
         | There also seems to be no good reason to assume that the
         | regulator that would be given these new powers and
         | responsibilities actually has the necessary resources or
         | expertise to understand the issues and perform their new role
         | properly.
         | 
         | None of this looks encouraging and for rules that could have a
         | profound effect on (among other things) our personal safety and
         | the democratic integrity of our country it seems fair to
         | question whether passing a very broad law that delegates the
         | implementation details to a regulator that may or may not be
         | competent to regulate these areas is really a good idea.
        
           | ChrisKnott wrote:
           | > _" Previous laws relating to policing and investigatory
           | powers have been widely criticised by civil rights groups for
           | their overreach and lack of effective oversight and
           | safeguards. We now know that some of those laws have in fact
           | been abused in ways the critics predicted."_
           | 
           | What are you referring to here?
        
             | Silhouette wrote:
             | Take RIPA for example. Local authorities have literally
             | deployed drones for covert surveillance. They have invoked
             | powers under the Act in trivial cases such as fly tipping,
             | dog fouling and deciding which school catchment area a
             | child fell within. In some cases they were subsequently
             | criticised for it or even found to have acted unlawfully
             | but that obviously doesn't mean that the intrusion didn't
             | happen or that the victims of that intrusion weren't
             | distressed and possibly harassed as a result prior to some
             | formal legal action going their way often at a much later
             | date.
             | 
             | There is absolutely no legitimate justification for local
             | authorities dealing with those kinds of issues to have
             | access to the kinds of lawful surveillance and intrusion
             | powers that RIPA is primarily concerned with. Even if you
             | accept that those powers are justified and necessary in
             | cases such as imminent national security threats or
             | investigating organised crime that still doesn't explain
             | why so many organisations that are not the police, security
             | services or perhaps HMRC need them.
        
         | b800h wrote:
         | The bill itself doesn't appear to exempt anyone. From Taylor
         | Wessing:
         | 
         | "[following amendments] The OSB continues to apply to any
         | service that enables content generated, uploaded or shared by
         | one user to be encountered by another user (user-to-user
         | services) or that allows users to search more than one website
         | or database (search services)."
        
           | ChrisKnott wrote:
           | It actual exempts several categories (email servers etc).
           | 
           | My point is that there is no reason to think the regulations
           | that eventually come into force for services which aren't
           | exempted will be as ridiculous as you suggest.
           | 
           | I agree that the OSB gives Ofcom the power to regulate
           | Minecraft servers, but those regulations must be reasonable
           | and proportionate so I don't believe that it will affect a
           | private individual running a private server, as you appeared
           | to suggest.
        
             | b800h wrote:
             | Yeah agree about point to point services. Email and SMS and
             | voice.
             | 
             | What I don't see is the bit where it says that the audit
             | responsibilities are limited to certain people or
             | companies.
             | 
             | If you could point to the "reasonable and proportionate"
             | bit in the legislation that would be interesting to check
             | out.
        
         | rovr138 wrote:
         | > My experience with online activists' predictions of imminent
         | dystopia is that they generally turn out to be extremely
         | overblown.
         | 
         | The questions in my opinion then become,
         | 
         | Is it the law preventing these? Is it some people not yet
         | seeing why they should do it? Are they purposefully not doing
         | it initially to calm people?
         | 
         | If they don't want to be able to do it, it could be rephrased.
        
           | ChrisKnott wrote:
           | By way of analogy, the government might make a law that
           | allows, in secondary legislation, the setting of a driving
           | speed limit.
           | 
           | These activists are claiming that the government is secretly
           | intending the speed limit to be 1mph. The government are
           | trying to ban driving!! The activists are demanding the
           | _enabling legislation_ be amended so that the speed limit,
           | when set, must be no lower than Xmph.
           | 
           | But all this does is force all regulation to be done in
           | primary legislation.
           | 
           | The debate about what the regulations should be is separate
           | to there being a regulatory system at all.
           | 
           | It is right that the primary legislation just lays out in
           | broad terms that the regulations must be "reasonable" and
           | "proportionate" etc because it's only real purpose is to
           | allow those regulations to be challenged in court in future.
        
             | CamperBob2 wrote:
             | Like unreasonably low speed limits, the purpose of
             | legislation like this isn't to be enforceable against
             | everyone. It's to be enforceable against _anyone_.
        
             | LocalH wrote:
             | I'd like to offer a different analogy.
             | 
             | Encryption in communication is, to me, akin to the locks on
             | the doors of your residence, on safes or other secure
             | containers. It protects your privacy from prying eyes who
             | want to snoop on what others are doing.
             | 
             | The activists are claiming that the government wishes to
             | require that all locks be unlockable by one of a range of
             | secret "master" keys, so that they can ensure you're not
             | privately doing anything illegal. Not only that, but the
             | government also wishes to institute a compliance regimen to
             | ensure that all locks are indeed actually openable by these
             | master keys.
             | 
             | Given the historic behavior of _all_ governments, I don 't
             | trust them _not_ to claim the most powerful interpretation
             | of the laws and regulations that are instituted. Maybe not
             | at first, but it _will_ happen, because it has _always_
             | happened this way.
        
               | cjs_ac wrote:
               | What the government actually wants is for service
               | providers (as in, social media companies, not ISPs) to
               | monitor everything happening on their service to make
               | sure that no one is coming to any serious harm. How
               | providers do that is up to them.
               | 
               | The government doesn't care about the technology; it's
               | all about corporate processes, and they're going to
               | regulate it one corporation at a time. If you're not
               | important to be asked to appear before a House of Commons
               | Committee, you're not going to come to Ofcom's attention.
        
               | janoc wrote:
               | > How providers do that is up to them.
               | 
               | Sure. You are either demanding the impossible - or
               | effectively banning encryption use because there is no
               | other way how to comply with what the law demands,
               | despite it ostensibly not banning anything.
               | 
               | So that's rather disingenuous argument, IMO. The problem
               | is that the governments not only don't care about
               | technology, they don't understand it either. And tend to
               | imagine and demand things that are about as realistic as
               | a square circle - but it is a law, we don't care how you
               | do it, it is your problem!
        
               | cjs_ac wrote:
               | There's a subtle but crucial difference. Service
               | providers are free to offer end-to-end encrypted chat,
               | but have to take responsibility for anything that's
               | transmitted through that service. This means that
               | services like Signal and WhatsApp will have to leave the
               | UK, but I'm free to run my own service for just myself,
               | my friends and my family.
               | 
               | I would prefer the bill not to be enacted, but I can live
               | with it.
        
             | b800h wrote:
             | That's not my understanding of the legislation. I see no
             | exemptions from the child access provisions. The criterion
             | is "any site with a significant number of child users" or
             | where _additionally_ OFCOM decides to intervene, and where
             | significant is not defined.
             | 
             | And of course you seem to have to perform an audit to
             | determine how many child users you have in order to be
             | exempted.
             | 
             | Again, this is my reading of the very complex bill. The
             | article from Taylor Wessing seems to concur though.
        
               | ChrisKnott wrote:
               | But all the provisions service providers are expected to
               | implement have a "reasonable" or "proportionate"
               | qualifier, no?
               | 
               | And the actual, practical meaning of these
               | responsibilities will be defined in a yet-to-be-published
               | Code of Practice...?
        
           | cjs_ac wrote:
           | If you operate an online service, you don't have any actual
           | obligations under the Online Safety Bill until Ofcom taps you
           | on the shoulder. Considering that Ofcom is also responsible
           | for regulating ISPs, all broadcast media, the EM spectrum,
           | the telephone network and the Royal Mail, I don't think
           | they'll have the resources to go after anyone but the social
           | media giants.
        
             | cvwright wrote:
             | > I don't think they'll have the resources to go after
             | anyone but the social media giants.
             | 
             | Or anyone who criticizes those in power
        
             | throw16180339 wrote:
             | Unless there's a political advantage in enforcing the rules
             | against opposing party news sources, online forums,
             | critics, etc. Tell me with a straight face that Boris
             | Johnson's government wouldn't have done this given the
             | opportunity.
        
         | SXX wrote:
         | > Is there any reason to expect them to be as dystopian as you
         | predict?
         | 
         | Bill description on UK Parlament website:
         | 
         | https://www.parliament.uk/business/news/2022/april/have-your...
         | 
         | >The Bill has five policy objectives:
         | 
         | > to increase user safety online.
         | 
         | > to preserve and enhance freedom of speech online.
         | 
         | > to improve law enforcement's ability to tackle illegal
         | content online.
         | 
         | > to improve users' ability to keep themselves safe online.
         | 
         | > to improve society's understanding of the harm landscape.
         | 
         | I guess UK government has solved all the issues include
         | salaries inflation and ever rising price of living so they can
         | finally go "preserve and enhance" freedom of speech.
        
       | endigma wrote:
       | Source code hosting; Gitea or Gitlab or Gogs etc all have UGC.
       | The interesting part to me is I'm not sure how this helps the UK
       | citizens who are using the internet be any safer, all you'd have
       | to do is access the rest of the internet to circumvent this.
        
       | osigurdson wrote:
       | Certainly the online activities that the bill is meant to address
       | will still continue. Criminals don't care about following the law
       | unfortunately.
        
         | IshKebab wrote:
         | While I think this law is bonkers, "then only criminals will
         | have guns" style arguments are _terrible_ counterpoints.
         | 
         | They depend on a 5 year old's view of the world where there are
         | "good guys" and "bad guys" and nobody is a bit in-between. They
         | also use the same oversimplification that economists are famous
         | for - that everyone has perfect information, acts completely
         | rationally, has infinite motivation, etc. etc.
         | 
         | In the real world, criminality is a spectrum and difficulty is
         | a real thing.
        
           | pas wrote:
           | offtopic: economists use these models in places where even
           | these oversimplified ones work pretty well
           | 
           | and usually the issues with results are not because
           | information asymmetry
        
       | amriksohata wrote:
       | I read the title and thought that the legislation had gone
       | through already! Might be worth tweaking
        
         | b800h wrote:
         | Good shout, I'll try to squeeze in something within the
         | character limit.
        
       | mellosouls wrote:
       | (Ask HN: List...)
        
         | b800h wrote:
         | Good point. Done.
        
       | intunderflow wrote:
       | Does it matter? The UK can't enforce anything outside its
       | borders. Just putting another nail in the coffin of UK tech
       | startups that aren't in Financial Services.
        
         | b800h wrote:
         | It matters if you're in the UK and you're a tech hobbyist.
        
           | intunderflow wrote:
           | In my opinion the UK has always been against that group and
           | others who stick out, and that's not going to change in the
           | future.
           | 
           | Unfortunately if you're a tech hobbyist in the UK your best
           | option is to leave, especially if you're any good with
           | technology. There are plenty of other countries that will
           | treat you far better than the UK ever would.
        
             | b800h wrote:
             | Absolutely not true historically. We were brilliant in the
             | early 80s, largely thanks to Mrs. Thatcher.
        
               | timsneath wrote:
               | Agree. She was a polarizing figure in the UK, but the
               | newly-installed Conservative government of the early 80s
               | certainly moved fast to respond to both the threat and
               | the opportunity of the coming information revolution. In
               | partnership with the BBC, they instituted the Computer
               | Literacy Project which comprised education, television
               | programs, subsidized computers for schools, and of course
               | the BBC Microcomputer.
               | 
               | For those who want to read more, there's a great archive
               | site here: https://clp.bbcrewind.co.uk/history and an
               | interesting book from MIT Press
               | (https://mitpress.mit.edu/9780262034036/now-the-chips-
               | are-dow...) which covers this period.
        
       | cjs_ac wrote:
       | While I'm not a supporter of the Online Safety Bill, I do find
       | that the opprobrium that it has inspired is consistently
       | hyperbolic.
       | 
       | The Online Safety Bill bans _nothing_. What it does do is create
       | a regulatory framework for the Office for Communications (aka
       | Ofcom, HM Government 's regulator for the communications
       | industry) to operate and enforce. The regulatory framework is
       | based around risk assessments, and sets out specific risks (of
       | the sort that most people would agree need to be minimised).
       | Ofcom is empowered to decide that internet services are within
       | scope, and then demand to see policies relating to ameliorating
       | those risks within a service.
       | 
       | The regulatory framework does specify that end-to-end encryption
       | is incompatible with the reduction of these risks. However, we do
       | have to play the ball and not the person of unspecified gender
       | here.
       | 
       | We are, after all, talking about the UK here. The phenomenon of
       | 'those whom the law protects but does not bind, and those whom
       | the law binds but does not protect' is still very much in effect
       | here. This legislation has also been proposed by a government
       | that responds to increasing crime (caused by insufficient police
       | officers) by giving those police more powers (that they don't
       | have the resources to exercise).
       | 
       | Ofcom has wide-ranging responsibilities: it regulates the press
       | and broadcast media, it allocates EM spectrum bands, it regulates
       | the telephone network, and regulates the Royal Mail. Like all
       | organisations in the Home Civil Service, it is staffed by a core
       | of 'generalists' with humanities degrees, assisted by a small
       | cadre of 'specialists', who are put back in their cupboard once
       | they've given their opinion.
       | 
       | What this all means is that the bill will only have the effects
       | that the government has said it will in its press releases. Ofcom
       | will go after the big social media companies and the likes of
       | 4chan. Your Mastodon server or your Gitea server or your corner
       | of the Tildeverse or whatever will never appear on their radar.
       | Ofcom won't have the budget or the resources to go after
       | individuals or small communities; they won't even know you exist.
       | 
       | In the UK, an energy bill or council tax bill is an important
       | identity document, necessary for opening a bank account, because
       | any time someone starts talking about identity cards, the readers
       | of the _Daily Telegraph_ start muttering about the Gestapo. Ofcom
       | isn 't going to audit your homelab for online harms.
        
         | GordonS wrote:
         | It sounds like you're chiding others for complaining about the
         | bill, and excusing this because the bill "only" _enables_ mass
         | surveillance and anti-privacy measures, rather than stipulating
         | them. Might be I 'm reading you wrong on this, but that's what
         | I'm taking away.
         | 
         | > What this all means is that the bill will only have the
         | effects that the government has said it will in its press
         | releases.
         | 
         | I don't really believe that for a second. Whenever sweeping
         | powers are introduced, there is scope creep. Just look at how
         | anti-terrorism laws have been abused. And it seems Apple and
         | others don't believe it either.
        
           | cjs_ac wrote:
           | I am chiding people, not for complaining, but for
           | misunderstanding the surrounding context. Legislation is only
           | as powerful as those enforcing it.
           | 
           | > And it seems Apple and others don't believe it either.
           | 
           | Yes, Apple, Google, Microsoft, Signal, Meta, and all the
           | other big players else who has turned up to the committee
           | hearings will have their activities curtailed. Individuals
           | running Minecraft and Mastodon servers for their friends
           | needn't worry.
        
             | ac2u wrote:
             | IMO your analysis has a massive flaw.
             | 
             | >Legislation is only as powerful as those enforcing it.
             | 
             | While this is generally true, it doesn't necessarily stop
             | the provisions within the bill being used as a political
             | weapon to wield against someone.
             | 
             | In other words, just because it's _generally_ not used
             | against small fry, doesn 't mean it won't be used as a club
             | against a particular small fry that's a thorn in the side
             | of someone politically or judicially connected.
        
               | candiodari wrote:
               | You even forget the danger here. Like in France, where
               | they voted in the right to let Macron and the police
               | forces delete someone's French citizenship without
               | judicial oversight. And that's ... kind of OK? I still
               | don't agree with it, but yeah _these_ people have shown
               | that they 're not going to abuse it on a large scale.
               | 
               | But with 10% more votes, this power will go into the
               | hands of Le Pen ... and everyone, including Macron, knows
               | what will happen.
               | 
               | (hell, I kind of suspect this is intentional on Macron's
               | part. He wants to get re-elected by making the
               | alternative to electing him catastrophic. It worked last
               | time, sure, but obviously it needs to become more
               | catastrophic if he's to be reelected)
        
             | generalizations wrote:
             | > Individuals running Minecraft and Mastodon servers for
             | their friends needn't worry.
             | 
             | Because they're too insignificant to matter, or because
             | they won't be covered by the law? It sounds like the
             | former, but you seem to imply the latter.
        
               | cjs_ac wrote:
               | It's a bit of both. The law states that Ofcom has to ask
               | you for your risk assessments, and they can't ask you for
               | those if they don't know you exist.
        
               | bbarnett wrote:
               | _The law states that Ofcom has to ask you for your risk
               | assessments, and they can 't ask you for those if they
               | don't know you exist._
               | 
               | Good lord! That's the same logic one may employ as a
               | criminal, say.. an inside trader!
               | 
               | Well of course you won't get nabbed, if they don't know!
               | 
               | So as soon as you do anything interesting, protest, stand
               | up for a right, displease a cop, upset the wrong
               | neighbour, you'll be noticed, eh?
               | 
               | What a great law!
               | 
               | Congrats, you made my neighbours wonder why I'm yelling
               | at myself(seemingly) again.
               | 
               | "Poor bbarnett, yelling in his empty house again, wonder
               | when they'll take him away Marge?"
        
               | janoc wrote:
               | You do realize that you "don't exist" only until one
               | pissed off neighbor complains to OFCOM about you after
               | your cat has pooped on their lawn one too many times?
               | 
               | This is a rather incredible mindset to have, IMO. Even
               | for me who doesn't quite subscribe to the constant Big
               | Brother panic.
               | 
               | This law gives the government a huge loaded gun that they
               | can use to blast pretty much anyone they please with. But
               | no worries, they aren't going to use it on you because
               | you are too unimportant?
               | 
               | And that still completely ignores the various collateral
               | damages - such as if encryption is effectively outlawed
               | because the regulatory hurdles associated with it are
               | simply too high to bother with (just look at how many US
               | websites rather block access from the EU instead of
               | having to deal with GDPR compliance), then even if you
               | aren't a target for the enforcement of this law your life
               | could be very badly affected when your service provider
               | gets hacked or your data get intercepted and some account
               | of yours gets hijacked.
        
               | monsieurbanana wrote:
               | I don't know if I'm missing some British humor here,
               | that's absolutely not bit of both, that's squarely
               | "because they're too insignificant to matter"
        
               | hanniabu wrote:
               | That's not a legitimate defense
        
               | mrd3v0 wrote:
               | I am amazed by how okay you seem with this. Wow.
               | 
               | Maybe it is me, who has already lived under a very
               | similar set of laws and know that corporations are always
               | the least hit by such laws. These are instruments that
               | infringe on basic individual rights such as right to
               | privacy. These instruments create systemic significant
               | incentives to corruption, totalitarianism, (corporate and
               | international) espionage, and so on.
               | 
               | Rights groups, activists, whistle-blowers, prosecuted or
               | rather marginalised minorities, and other legitimate
               | groups and individuals are going to be impacted by this.
               | 
               | Underplaying this is incredibly naive and downright
               | dangerous.
        
               | dharmab wrote:
               | This comment reads like a Yes, Minister scene.
        
         | hau wrote:
         | >Your Mastodon server or your Gitea server or your corner of
         | the Tildeverse or whatever will never appear on their radar
         | 
         | Of course it will when your gitea or mastodon instance is in
         | the right crosshair. Do we just surrender rights on a hope this
         | time we can stay under the radar? If you are not a terrorist or
         | a pedophile you have nothing to worry etc. When you disagree
         | enough you will become a terrorist. That's the reality in my
         | country because it works an have worked for centuries.
         | 
         | >Ofcom won't have the budget or the resources to go after
         | individuals or small communities; they won't even know you
         | exist. >Ofcom isn't going to audit your homelab for online
         | harms.
         | 
         | Pinky promise?
        
           | cjs_ac wrote:
           | I've read the bill, and know what it stipulates. Of course,
           | if you don't want to take my word for it, you can download
           | the 302 pages of legislation and check it yourself:
           | https://bills.parliament.uk/bills/3137
        
         | AlbertCory wrote:
         | [flagged]
        
         | golergka wrote:
         | I don't agree with this comment, but I upvoted it because it
         | brings a different perspective to HN, and therefore, improves
         | the quality of discussion.
        
         | collaborative wrote:
         | You seem to know more than me. I host a fringe e2ee messaging
         | system in the UK that I run under under an LTD. Am I affected?
        
           | cjs_ac wrote:
           | Disclaimer: I'm not a lawyer, just someone who read the bill
           | a couple of months ago because I was checking to see whether
           | the idea I have in the back of my head for a social media
           | platform was still viable. Heather Burns[0] is an actual
           | lawyer who's a leading authority on this.
           | 
           | The basic principle is that what people do online can have
           | negative consequences in the real world, and the bill
           | basically holds online service operators (such as yourself)
           | at least partially responsible for those negative
           | consequences. Operators need to demonstrate that they're
           | mitigating those consequences risk assessments and policies.
           | 
           | Judging by your profile, you're offering e2ee to family
           | groups, so your intended users are low-risk for sending
           | harmful content. However, your service is freely available to
           | anyone with the app, so it could potentially be used by
           | terrorist organisations, gangs or CSAM sharing groups. e2ee
           | services like this are pretty much the only service that is
           | outright incompatible with the requirements of the bill, so I
           | think you'll be in trouble as soon as Ofcom comes knocking,
           | if they do so. I think the chance of them doing so is small,
           | but that's just my personal opinion, and you will have to
           | make your own decisions.
           | 
           | The family tree and calendar features look like they're low
           | risk, and could be adequately covered by risk assessments,
           | but the file and photo sharing features are also problematic,
           | because (I think) they're encrypted.
           | 
           | You're very unfortunate to be at the intersection of the
           | three factors that could make Ofcom care about you:
           | 
           | * service freely available to the public; * arbitrary user-
           | to-user communication; and * no means of checking for harmful
           | conduct on your service.
           | 
           | The only way forward that I can see for you is to make the
           | backend a selfhost-only affair, which would make your UK-
           | based users responsible under the bill.
           | 
           | [0] https://webdevlaw.uk/about/
        
             | [deleted]
        
         | tailspin2019 wrote:
         | While I support some more measured analysis to counter the
         | hyperbole, you're making some strong assertions about what this
         | bill will and won't mean, and I don't think you can have any
         | more certainty about these than those people who are assuming a
         | far worse outcome.
         | 
         | Context matters, and given the context of where we are as a
         | country at the moment, how trustworthy our current government
         | has (not) turned out to be, and even where they are in the
         | election cycle - currently heading for being out of office for
         | a decade - not to mention them pushing to leave the European
         | convention on human rights, I'm a lot more concerned about the
         | potential dangers of this bill than I might have been in a
         | different context.
         | 
         | Even if you're right and I'm wrong, this statement seems a bit
         | naive! (with respect):
         | 
         | > the bill will only have the effects that the government has
         | said it will in its press releases.
         | 
         | Edit: I tend to put a lot of stock into analysis put out by the
         | EFF [0]. I think they said it well here:
         | 
         | > If it passes, the Online Safety Bill will be a huge step
         | backwards for global privacy, and democracy itself. Requiring
         | government-approved software in peoples' messaging services is
         | an awful precedent. If the Online Safety Bill becomes British
         | law, the damage it causes won't stop at the borders of the U.K.
         | 
         | [0] https://www.eff.org/deeplinks/2023/07/uk-government-very-
         | clo...
        
           | cjs_ac wrote:
           | Perhaps I am being naive, and I will confess that I'm not
           | entirely sure that the future will be as I predicted (but I'm
           | not going to edit my initial comment, out of respect for
           | those disagreeing with me).
           | 
           | But I will think this quote from one of the bill's most
           | dogged critics is illustrative[0]:
           | 
           | > ... this Bill, whatever DCMS and its ministers may claim,
           | is not a "fixing" Bill, one which has been designed to be
           | constructive and positive in order to fix problems. It is a
           | "getting" Bill, once which has been designed to be vindictive
           | and negative in order to get specific companies. OnlyFans in
           | this particular example, the usual suspects in others.
           | 
           | > The second is that this Bill has been designed by people
           | who are so out of touch that OnlyFans is their idea of the
           | average small digital business.
           | 
           | > And the third is that this Bill has been designed by people
           | who are so out of touch that they think the harms issues
           | raised by OnlyFans are the harms issues in the average small
           | digital business.
           | 
           | As for your distrust of the government, my opinion on this
           | comes from that same position. My complacency rests not on
           | their goodwill (because I don't think they have any) but on
           | their disinterest in actually understanding anything.
           | 
           | [0] https://webdevlaw.uk/2022/07/13/heres-why-your-project-
           | is-in...
        
             | tailspin2019 wrote:
             | > As for your distrust of the government, my opinion on
             | this comes from that same position. My complacency rests
             | not on their goodwill (because I don't think they have any)
             | but on their disinterest in actually understanding
             | anything.
             | 
             | Ok we definitely share common ground on this point then :)
             | 
             | I think it's worth remembering the equal amounts of - what
             | could have been described as - "hyperbole" by remainers
             | about what Brexit would really mean for the country,
             | leading up to that vote. Much of the concern expressed was
             | dismissed or downplayed, and though I voted to remain, I
             | too actually thought the case against Brexit may have been
             | made too strongly at the time. Well I was wrong about that
             | - and many leave voters would also agree now that a lot of
             | those forewarnings turned out to be correct, and in some
             | cases, worse than predicted.
             | 
             | Brexit has had the negative impact on the UK that it has,
             | due to two things. One of those is debatable; whether it
             | was actually a bad idea from the beginning - (I personally
             | think it was) and the second reason is not debatable at
             | all: its very poor implementation by the Government.
             | 
             | The Online Safety Bill also may turn out to be a terrible
             | decision for one or both of these same reasons: a) it was a
             | poor concept b) it was implemented badly by the government.
             | We only need one of those to be true for things to go
             | badly. I worry that both will turn out to be true.
        
         | jrmg wrote:
         | I'm reminded of the hyperbole - which I fell for - around the
         | Regulation of Investigatory Powers act around the turn of the
         | millennium.
         | 
         | It provides a legal mechanism for authorities to require that
         | individuals disclose encryption keys for encrypted data that
         | was legally obtained or intercepted (i.e. with a warrant) by
         | those authorities, and there are penalties (jail time) for
         | refusing to do so.
         | 
         | The worry at the time was that random data is indistinguishable
         | from encrypted content, so there might be times when people are
         | jailed when they don't even have the keys because there's no
         | encrypted data - just random bytes! Or, what happens if you
         | lose the keys?
         | 
         | The reality is that there's a court system that 'regulates' all
         | this. No-one is going to be jailed unless the courts find that
         | they are not providing keys they really do have. Of course, in
         | a conspiracy where the authorities and the courts are all
         | colluding, they could jail people pretending that they knew
         | they had the keys - but there are far easier ways for the
         | authorities to do this than some elaborate scheme with fake
         | encrypted data.
         | 
         | At the time I was fully convinced that it was a step down a
         | slippery slope to authoritarianism. Really, it was just
         | bringing the 'virtual' world into line with the physical one.
         | 
         | [I suspect there are a few here who were also around at the
         | time and still believe it's all a nefarious governmental plot -
         | I'd ask them to show where, in the 23 years since it passed,
         | harm - or suspicion of harm - has happened].
         | 
         | Now, maybe this is different. I certainly don't want end to end
         | encryption to be banned. But there's a bit of a 'cried wolf'
         | happening in my brain.
        
           | jl6 wrote:
           | An interesting RIP case here: https://www.bbc.co.uk/news/uk-
           | england-11479831
           | 
           | A person received a 16 week prison sentence for not
           | disclosing a password. In the context, it's possible that had
           | he disclosed the password, police would have discovered
           | material that would have attracted a far more severe
           | punishment.
           | 
           | So one might argue that the RIP was too weak, and failed to
           | compel disclosure of the password (four months in jail is
           | light in the circumstances).
        
             | amiga386 wrote:
             | This guy went to prison for a year and 2 months, for not
             | disclosing his Facebook password:
             | https://www.bbc.co.uk/news/uk-england-hampshire-45365464
             | 
             | He was accused of murder. Ultimately, he was found guilty
             | and sentenced to 33 years: https://www.hampshire.police.uk/
             | news/hampshire/news/news/201...
             | 
             | And then there's the other direction, which I must confess
             | I thought would have involved the RIP Act but ultimately
             | didn't, instead it used anti-terrorism legislation.
             | 
             | A French employee of radical French publishing house that
             | the French government is very cross with, arrived in
             | Britain for a book fair. He was arrested and held for 24
             | hours using anti-terror legislation. The cops also
             | confiscated his phone and laptop, and held onto them for
             | more than 10 weeks, and they threatened him "with never
             | being able to travel overseas if he failed to hand over a
             | password to his confiscated iPhone and MacBook":
             | https://www.theguardian.com/uk-news/2023/jul/21/police-
             | watch...
             | 
             | The general concern is that France is not allowed to do
             | that, so asked Britain to do it for them, and Britain did
             | it. There wasn't even a hint that he'd broken the law in
             | Britain, and all that was wanted was for the French
             | government to get ahold of the contents of his phone and
             | laptop. Perhaps this is the only reason (that they had
             | absolutely nothing on him) that they didn't twist the knife
             | and use the RIP Act to imprison him simply for not
             | unlocking his devices for them:
             | https://www.theguardian.com/uk-news/2023/apr/19/french-
             | publi...
        
       | pacifika wrote:
       | This might be useful from June, can't vouch for correctness.
       | 
       | https://www.taylorwessing.com/en/interface/2022/the-online-s...
        
         | b800h wrote:
         | Very useful, thanks.
        
         | darkclouds wrote:
         | My TLDR of that law firms info which could be a wrongful
         | interpretation, in priority or execution order.
         | 
         | Any Non Specified Entity uploading any data which could be
         | accessed by another Non Specified Entity with or without public
         | access is bound by this bill.
         | 
         | Can be used or accessed from the UK. This might be the UK
         | expanding beyond its borders here, because its a given if it
         | not geo restricted it it could be used in the UK. VPN's/Tor may
         | not be able to offer privacy from the state which is my opinion
         | anyway.
         | 
         | Applies to all services with a "significant" number of UK
         | users. No definition of significant so dont know if this is the
         | same use of the word significant found in medical studies or
         | not.
         | 
         | Definition of search engine is a service which can search more
         | than one website or database.
         | 
         | Largest players now have a legal duty to prevent paid-for
         | fraudulent adverts on their service and other regulated
         | content.
         | 
         | Clarification on identifying the users of the service, ie
         | profile pics and other identifying data.
         | 
         | Exempt specified entities:
         | 
         | --------------------------
         | 
         | Software like antivirus, antispam cloud/online submissions
         | where said data is never likely to be used for communication
         | purposes but might be analysed to improve the performance of
         | said software function, ie reverse engineering stuxnet, latest
         | spam techniques.
         | 
         | Published Content with commenting for the content, ie online
         | newspaper comments. Posting a link, with or with comments,
         | including like, dislike buttons and emojis of Published Content
         | to another Non Specified Entity.
         | 
         | SMS & MMS messaging.
         | 
         | Services solely used for specific tasks like education,
         | childcare and possibly health care.
         | 
         | One to One Aural (realtime speech and sound only guessing
         | telephone) communication with identifying data allowed with no
         | additional data communication functionality like visuals, text
         | messaging. No mention of recording said Aural data.
         | 
         | Any public body carrying out their public duty.
         | 
         | Any internal business resource or tool, like company message
         | boards, company chat facility's in all forms. No mention of
         | recording data, would assume business includes official
         | organisations like charities, but not clear.
         | 
         | No mention of private paid for programming language groups
         | which can be accessed using a password of sorts and costs
         | 
         | Case by case reviews and changes made by the secretary of state
         | so the exemption list will probably grow.
         | 
         | So my opinion on the above is if you are a big (US) tech
         | service, you can self regulate, but little users will be
         | watched by the UK state as no one can be trusted. Other laws
         | apply where applicable.
        
       | b800h wrote:
       | Interestingly, if you run a BBS through the telephone system,
       | you'll be immune, as the bill specifies "the Internet", but:
       | 
       | 1. I think the lines have jitter now they're over IP anyhow.
       | 
       | 2. Bit niche...
        
         | darkclouds wrote:
         | > you'll be immune, as the bill specifies "the Internet"
         | 
         | UK POTS is switching over to an IP based network, so does the
         | bill specify the internet or ip based network?
         | 
         | If you submit a GDPR to your local constabulary, every phone
         | call in the UK has a unique call identify much like a GUID now.
         | Its quite insightful seeing just how much info is given out
         | regarding the phone system capabilities via GDPR requests.
        
         | LeoPanthera wrote:
         | Has anyone designed a modem to work over VOIP? It would have to
         | cope with audio compression, jitter, dropouts, and so on.
         | 
         | On the other hand, it could assume much less noise than an
         | analogue phone line.
        
           | ozfive wrote:
           | This guy has a tutorial on running modems over VoIP.
           | 
           | https://area-51.blog/2021/01/16/getting-a-dial-up-modem-
           | work...
        
           | timthorn wrote:
           | Yes, making fax machines work over VoIP was important in the
           | early days. The G.711 codec was designed to support endpoints
           | that needed a full 64kbps datapath.
        
             | Denatonium wrote:
             | I've had much better success having fax calls work over
             | VoIP then I have getting data modem calls to work. My best
             | guess as to why is that fax calls have much less back and
             | forth, and as a result, they are less latency-sensitive.
             | Fax calls also usually negotiate at 14.4kbps, whereas data
             | modem calls often try to train at faster rates.
        
           | patmcc wrote:
           | This is a hilarious idea, I love it. Internet Protocol over
           | Voice over Internet Protocol.
           | 
           | Call it IPOVOIP.
        
           | bityard wrote:
           | Sure, it could be made to work, and it might even be able to
           | keep up with your reading speed.
           | 
           | VoIP codecs are heavily optimized for human voice and have
           | just a few kilobits of bandwidth. The analog phone network,
           | before it went entirely digital, had a much higher bandwidth
           | which is why modems were able to reach 56kbps. Phone calls in
           | the 1980s were often crystal clear, almost on par with a
           | broadcast radio station. Cell phones today along with VoIP
           | are a muddy unintelligible mess in comparison.
        
             | abwizz wrote:
             | the quality of analog phone calls hung on the quality of
             | the equipment, mostly the cables (and distance), whereas
             | the quality of voip (or volte for that matter) depends
             | mostly on the quality of the codec used.
             | 
             | ime both can be shitty or "crystal clear" but i totally
             | agree that having a cell phone call today, with worse
             | quality than an cross-continent analog connection in the
             | 80s is very depressing
        
             | janoc wrote:
             | >had a much higher bandwidth which is why modems were able
             | to reach 56kbps
             | 
             | That is actually completely false. The way that speed was
             | achieved was by using multiple bits per symbol encoding
             | (bitrate != baudrate), not by having some mysterious unused
             | bandwidth available. This was the case for speeds above
             | 4800bps up to 33kbps (V.34).
             | 
             | 56kbps (V.90) was only possible with PCM (digital)
             | modulation, while the actual symbol rate on the line was
             | still only about 8000Bd - i.e. about 8kHz, which is about
             | the maximum for a typical landline.
             | 
             | This is all due to how a typical phone line works and that
             | there is a very strong attenuation of higher frequencies
             | due to parasitic capacitance and inductance of the wiring.
             | 
             | I am not sure where do you live and what kind landline
             | phones you had but modern digital cell phone codecs are
             | light years ahead of the sound quality we had on land lines
             | in 80s, esp. when calling long distance.
        
             | kevin_thibedeau wrote:
             | Cell phones inject noise on purpose so you don't notice the
             | gaps in transmission when the other end is silent.
        
             | fbdab103 wrote:
             | Say I wanted to communicate with others in the best
             | possible quality, which platform is best?
        
               | toast0 wrote:
               | Depends on what you mean by quality, how much you're
               | willing to pay for it, and what's actually available.
               | 
               | If quality means low latency and low jitter, and you can
               | get T1/E1 digital telephone service, circuit switched end
               | to end, that's almost certainly the lowest practical
               | latency and jitter. It'll cost real money and you might
               | not like the 8000Hz 8-bit sampling. ISDN calling is
               | pretty much the same thing, but you only get two voice
               | lines instead of 24 or 25.
               | 
               | If that's not an option, but low latency is still
               | important, a solid wired connection with g.711 SIP is
               | pretty close, but packets are 20ms of samples, so that
               | adds to your baseline latency. G.711 is basically the
               | same codec as used for t1. And internet jitter is
               | probably not zero, but if your connection is well
               | provisioned it's often not that bad.
               | 
               | If you want a wider audio band, maybe try to get SIP with
               | G.722.2 (AMR-WB), this is the same codec used for 'HD
               | Voice', and I don't think it adds too much delay.
        
       | b800h wrote:
       | Should add MUDs, website guestbooks?
        
         | scandum wrote:
         | MUDs are easily hosted abroad. Problem solved.
         | 
         | This reminds me of UK's 90% tax rate, which caused many multi-
         | millionaires to leave the country.
        
       ___________________________________________________________________
       (page generated 2023-07-29 23:02 UTC)