If those in power decide to push forward by increasing the penalties, eventually running a Mastodon server will become as risky as getting caught for murder. At that point, it would be naive to run a Mastodon server locally, wouldn't it?
P.S. Mind you, the average consumer/user doesn't care as long as Facebook, Twitter, Instagram, and TikTok are up and running. Quotes like "they already know everything" and "do you have something to hide from the government?" will become ubiquitous in public discourse.
I’m kind of fascinated by the often simultaneously held beliefs of “America doesn’t make the world’s rules!” and “…EU does!” Countries can influence each other, sure, but if EU (US or Canada or Brazil) makes a law, it doesn’t apply to people not under those jurisdictions.
That's great if you never need to|want to travel.
What about the time you happen to end up in transit through an airport in a country where they've put you on their watchlist, they grab you airside and hold you for hours while they look at your devices....?
https://www.theguardian.com/world/2013/aug/18/glenn-greenwal...
Hypotheticals in tech pretty much always come true in the end. And especially fast these days.
The world is gearing up for something, and personally I smell a global war and a reshuffling of world powers in my lifetime.
I don’t know and don’t care because I don’t have to. I live in a sovereign nation and I’m not obligated to follow their rules, any more than their citizens are obligated to follow mine. That’s how countries work.
If my country signs a treaty with them, then I have to obey that specific law. Absent that, I don’t.
If they had all the things I’d ever said in my life time they’d probably execute me. I speak my mind all the time. That’s what terrifies me though, because in 20 years time they could be running the show. So why would I want to make it so easy for them to know everything I have ever said, why would I want that data stored about me.
[1] https://www.thorn.org/solutions/for-platforms/
Their website lists oracle, slack, ancestry.com and others
Unless you can point out links between the Hungarian government (who announced they will re-table the directive in a few months) and such companies, I'd say Occam stays with the security services.
The chat scanning stuff isn't a realistic proposal either for its intended purpose or for spying, it's just grifting.
As indicated in that article, the UK kinda sucks, so, like, don’t go there. Whatever, they don’t have any good beaches anyway.
Sadly outside summer the weather is usually to bad for them to be worth enjoying, but in summer they're pretty nice.
Of course not but if an American company in the US caters to EU users with, for example, a localized site it does absolutely apply to them. Same the other way around. Just because you or your server are too small to matter doesn't mean it is irrelevant.
America doesn't make the world rules is often said when they create one set of rules for them and another for everyone else (US can have warships near china but if it was reversed we would have a new Cuban crisis) and when they create rules in places they have the most power to create international laws that fit their world view but not their enemies. In a perfect world the US would have zero power and zero say a meter outside its borders.
The reason gambling/child porn/fincrime/etc are enforced across national boundaries is that everyone (at least, in the western world) respects those laws and absolutely will extradite. Cookie laws, anti-encryption laws, anti-(adult)-porn laws are not like this.
Try ignoring the GDPR, they will get upset at you really quickly.
I like the GDPR. I comply with the local CCPA version. I’m not legally obligated to follow the GDPR though. I’m unaware of any agreement the US has with EU that puts me under its jurisdiction.
I’d simply delete them, no problem.
For example, imagine you being arrested at Frankfurt airport because you posted something a year ago that falls under Strafgesetzbuch section 86a. You would need to review your entire post history going back years and compare it to the laws of every country you touch during your travels.
Doesn't this happen all the time? Wasn't David Irving repeatedly arrested and charged in many countries in continental Europe for things he said and wrote while abroad? (Not defending Irving's views, he's a noxious lying toad, but the principle here appears to be the same.)
Except the part where the CANZUK/US/EU blocs generally have reciprocal agreements and Interpol is perfectly empowered to enact international law inside of the US, as of 2009.
Choosing to take this stance in one of the Western Nations is foolish to an almost ignorant degree. If one of them feels you broke a big enough law, it's trivial (at best) to execute upon it.
Foreign national hackers are arrested all over the western world for offenses in other countries, for instance.
Extradition generally requires that the thing you're being extradited for would also a crime in the jurisdiction you're in.
For speech offences, this makes many foreign judgments unenforceable in the US due to the First Amendment, not to mention additional formal protections like the SPEECH Act.
The "average consumer" has been joking about their 'FBI guy' and freaking them out with weird porn or spurious Amazon carts for a decade now. We've hit the peaks of disillusionment, we've started down the road of exploitation and most of us are starting to worry that this trend of technological limitation is specifically intended to make us politically weak.
[0] https://www.washingtonpost.com/business/2021/09/17/navalny-g...
[1] https://apnews.com/article/canada-us-india-sikh-activist-kil...
If you descentralize, you democratize.-
Take the Chinese Great Firewall, for example. Yes, you can use technical means to circumvent it, but the effort required (and inevitably degraded performance) means that the median citizen does not.
The enormous success of Facebook, Twitter, Instagram and TikTok is because the average consumer/user can express themselves there and broadcast to the world. Normal people are actually participating in public discourse again, after most of a century of public discourse being one way with the government screaming into the citizens ear what to think and what to do, via radio and TV.
Federation is politics. Federation is about governance. It's about a place between centralized/authoritarian and distributed/anarchy.
> If those in power decide to push forward by increasing the penalties, eventually running a Mastodon server will become as risky as getting caught for murder.*
It's unlikely to be enforced globally. Every millimeter wrong that statement is, ever chance higher that connecting-with-one-another does try to get shut down on a broadscale, is another reason why we should be doing it, now, asap, and normalizing it.
As long as encrypted peer-to-peer communication exists on an open internet, there will be no way for a 3rd party to intercept this traffic, or for any government to control it. They can ban the use of specific software, but new software will always be written.
And enforcement doesn't need to be 100% effective to make a difference. Fairly simple measures are sufficient to deter and/or block well over 90% of the populace and force them into controlled channels, as China demonstrates.
it is called "war".
And the worst part is most of the internet have been cheering it on
Believing that all legislative issues can be solved that way is a fallacies. But some issues can totally be solved (or routed around) this way.
If your service becomes big and important enough, and if politicians hear enough from law enforcement and intelligence agencies that you're a major problem, then all of sudden, your "zero chance" becomes a "non-zero chance" if you ever need to travel to or through the EU, do any business there, etc.
Another case in point: cryptocurrencies. They were government-proof until they weren't, because ultimately, there are people running exchanges and mixers, as well as other counterparties, who can be threatened with prison and fines.
(As an aside, the legislators in the US broadly believe the same things about online communications than their EU counterparts, so the noose will keep tightening either way.)
At least I can contact my local legislators to campaign against it here.
Does American law apply globally if it says it does, absent any treaty making it so?
For practical purposes, what really matters is whether it can be enforced. So, for example, will your country extradite you if Americans demand it? Or, say, if you travel, will any of the countries that you pass through extradite you?
The reason why DPRK is a particularly bad example is because neither is a concern just about anywhere in the world. But for large and powerful political entities such as US and EU, it is a very real concern.
Federation certainly helps, in that Americans can run American instances and not worry if the EU dislikes it.
However, federation wouldn't help EU users much if the EU state decided to go for full-on Chinese style control, firewalling the foreign-hosted instances, banning the apps from the app stores, blocking access to payment infrastructure, jail for anyone found with the app sideloaded, PR campaign saying this app is used for child porn and encouraging people to turn in anyone they see using it to the cops, and so on.
Who won't avoid it is the hundreds of millions of Europeans who use WhatsApp as their primary means of telecommunication, many of whom don't even know what "end to end encryption" means, but effortlessly gain resistance to mass surveillance.
I really really wish Mastodon had E2E messaging. Non-techies are using it today. I’d much rather get my sibling set up on that.
You describe a situation where people can't reach everyone all of their family members in the popular ways, and Matrix offers a way to keep in touch you can guide them through and admin for them.
I've had speed and reliability issues with Matrix myself, so I wouldn't try to talk people into using it.
> just downloaded element x from f-droid and wowza it just.. loads instantly? can't believe i now live in the age of element being faster than discord
Anecdotally, ever since they dropped this feature, I have seen a significant reduction in Signal use among my own contacts.
Only the US and some dictatorships seem to do that.
If google don’t want to be subject to the gdpr they don’t have to do business in europe.
Howver their business is abusing the data of eu citizens, while getting other eu citizens to pay them for it.
> Each service required to install this “vetted” monitoring technology must also ask permission to scan your messages. If you don’t agree, you won’t be able to share images or URLs.
> As if this doesn’t seem wild enough, the proposed legislation appears to endorse and reject end-to-end encryption at the same time.
I absolutely will not run someone's server-side malware to look at the contents of all the messages my people transmit.
I have zero tolerance for CSAM. I can report, have reported, and will continue to report instances of it that I stumble across as part of my job moderating the server I host. Damned if I'm running EU's "vetted" software though. There's also approximately nil chance of American authorities attempting to force American entities to run EU software on their US-hosted servers. My doctor's office has an encrypted chat where I can ask my doctor questions. You think anyone's going to make them filter those HIPAA-covered messages through the EU?
There's pretty much zero chance that US would reject use and insight into private communication if EU puts it into law and forces upon messaging apps. We have literally pile of historical examples where FBI & co. were actively pushing for more of such data sharing programs. - So what exactly is your point? Where did you get an idea that you'll be running "EU software" and that US will defend you if you get into a CSAM suspected database list?
Since my server doesn’t do business in EU, I couldn’t care less about GDPR or other local laws, even the ones I think are good ideas.
American law doesn’t apply to someone running a server in Brussels. The converse is also true.
Except when the one running and renting out the server is Microsoft, Amazon, or some other US entity and the Patriot Act exists.
I’d have a different opinion about my service if I were hosting my server on Hetzner in Helsinki. Since I’m not, I don’t.
I'd say that is rather very relevant.
The Patriot Act is the foremost frontier in the ongoing dispute about the so-called Privacy Shield.
The GDPR explicitly permits "processing [as] necessary for compliance with a legal obligation to which the controller is subject" in Article 6.
Right to be forgotten still applies, there is just some limited data that will still be kept.
But it does require you to document that requirement and make sure that the data isn't shared beyond that requirement without consent.
HIPAA and GDPR aren't conflicting, they're orthogonal and cover different things.
Record retention laws win, as explicitly stated in the GDPR.
Same reason a murderer can't (successfully) issue a right-to-be-forgotten request to the cops investigating them.
(There's also "processing is necessary for the purposes of the legitimate interests pursued by the controller" as another exception, which allows, for example, your bank to retain the fact that you owe them $100k on your house still, even if you don't want them to.)
This is a fundamental aspect of GDPR and part of the central message in the regulation. Companies and organizations are only allowed to keep personal information if they have a legal allowed reason to do so, and must honor requests for deletions unless they have a legal reason not to do so.
What is and what isn't a legit reason depend on circumstance. What companies generally object with GDPR is that generate revenue through personal advertisement is not an legit reason to keep personal data.
Out of curiosity, could you give a few examples of incompatibilities?