It was obvious from the minute that idiots started creating IP location databases in the first place that people would demand that they be used like that... and those demands seem to be winning out.
It was obvious from the minute that idiots started creating IP location databases in the first place that people would demand that they be used like that... and those demands seem to be winning out.
What was known and not said when Parliament might have outlawed smoking in Paris is that there was literally nothing they could do to enforce such a law. Today the governments have options, hence the fight here. And many other places.
Basically all countries take that position legally. But there are norms and customs about how often you exercise it (as well as practical questions of power).
Extraterritorial regulation of Web sites is unfortunately in the process of being established as normal, but it's a bad norm. Not as bad as drone striking anybody who lights a cigarette in Paris (which could be made legal), but a bad norm nonetheless.
> It is the firm will of the Irish nation, in harmony and friendship, to unite all the people who share the territory of the island of Ireland, in all the diversity of their identities and traditions, recognising that a united Ireland shall be brought about only by peaceful means with the consent of a majority of the people, democratically expressed, in both jurisdictions in the island. Until then, the laws enacted by the Parliament established by this Constitution shall have the like area and extent of application as the laws enacted by the Parliament that existed immediately before the coming into operation of this Constitution.
(Which means the territory of what is now called the Republic of Ireland, that is, explicitly excluding any claim to Northern Ireland in order to comply with the Good Friday agreement)
Perhaps "Extraterritorial regulation" is bad wording. A country can regulate whether an extraterritorial website is distributed and or viewed within its borders but it has no legal authority force another country to close down a website that's operating legally within its jurisdiction.
The only remaining options are diplomatic action—request the site be taken down or war/by force. Whether we like it or not the only practical action is for a country to geoblock offensive websites at its borders.
Sadly, given the current state of world affairs, it seems to me geoblocking will become the norm almost everywhere.
The issue is they're doing this through might makes right rather than jurisdictional authority.
You have a website in one country, 99% of the content is legal in another country but it also contains a post by a user which is legal in the first country and not the second.
The second country then demands that the website remove the post -- for everyone, they don't even want it accessible via VPN -- or they'll have their ISPs block not just the entire website but also the entire shared hosting provider the website uses. The site which is entirely in the other jurisdiction can't withstand that much pressure and removes the post.
You now have a country censoring a post world-wide because they leveraged every company within their jurisdiction to enforce a law against one that isn't. That's extraterritorial regulation.
Hopefully this will break up the cartel of websites/distributors back into a decentralised web eventually.
They now seem to have backtracked on that and are using either the country the request came from or the country the account was set up from (both using IP geolocation)
PS The UK doesn't have free speech and never has. Free Speech was invented by the Dutch and the US was the first to put it in a founding document.
PPS I know of no government that thinks it can enforce their law outside of their borders against foreigners. That is outside the definition of sovereignty and something the UK government seems to have invented lately.
The USA does this quite regularly. Look at FATCA as one example.
Another example is that e.g. AWS Europe, even if every single one of its employees, board and what have it are all Germans, are still compelled to hand over their data if Amazon US is the parent company, under the likes of the CLOUD Act or FISA. That's a foreign entity comprised of foreign citizens and concerns the assets (data) of foreign citizens.
They weren't arguing for anyone's right to be corrupt in the first place though. If US citizens really have to pay extra taxes and have arduous reporting requirements then so be it, but why is the rest of the world dragged into that mess? This isn't a "dirty banks" issue; it's nearly impossible to get a bank account at any reputable institution as a US citizen abroad just because of the PITA of the reporting requirements. It's a mediocre law from questionable authority.
Sadly a lot of Americans hear "foreign bank account" and immediately think "tax evasion" without realizing there are a lot of ordinary Americans overseas who just want to pay the rent and save for retirement but can't because Uncle Sam follows us wherever we go for life.
Just one example: https://help.revolut.com/help/wealth/stocks/licences-regulat...
The problem here is that some twits did something like this once and since then everyone is saying "but look, they're doing it, why shouldn't we?" when they ought to be saying "we're all going to be imposing sanctions on that country until they stop doing that".
If someone is doing something, that's precedent -- but the precedent can either be "someone who does that can get away with it" or "someone who does that is not going to get away with it". And when making the decision, think through the consequences of everybody doing it to you if you allow it to be the first one.
Like the US did with Swiss banks?
“…the standard of justice depends on the equality of power to compel and that in fact the strong do what they have the power to do and the weak accept what they have to accept.” — Thucydides, 5.89 (trans. Rex Warner, Penguin Classics edition)
(half-remembered quote found using AI)
original source https://en.wikisource.org/wiki/History_of_the_Peloponnesian_...
Book 5, end of paragraph 89
Yeah about that …
Try looking up Gary McKinnon or Larry Love. The US has a history of this stuff, those are just a couple of examples. Hell, Kim Dotcom (NZ but same deal).
And that’s before we get into whatever the f*ck was happening at Guantanamo Bay.
> I know of no government that thinks it can enforce their law outside of their borders against foreigners.
Then you haven’t been paying attention.
The whims of its god-emperor/president. A lot of the enforcement is against US law.
I hold Russia as a whole accountable for Russia's recent war in Ukraine, it's their Responsibility to get rid of their leader when he started an unjustified invasion.
I hold the U.S. as a whole responsible for their successive presidents antics.
The US has asserted that right globally for quite some time, and literally threatened force against other countries to get them to actively support (not merely tacitly permit) such enforcement, even when it directly violated the constitutions of the countries involved (as well as simply doing armed enforcement without consent of the government iinvolved in other cases.)
This has been particularly notable since the outset of the “Global War on Terror”, but didn’t start there (it was a big part of US counter-narcotics policy long before the GWoT.)
Really, not a single one? Like, a really big obvious one? LOL!
The USA has been doing this for a long time e.g. Wikileaks and Julian Assange, Kim Dotcom etc.
We need to re-imagine the Parisian as an individual with exceptionally long arms lighting the tip of their cigarette in London...
I'm not entirely sure if you yourself understand the context or real meaning of that phrase, but for others at least, it was NOT meant to highlight that Parliament has a burning desire or real ability to legislate outside of its jurisdiction!
Just that it has the legal authority to create any such law, and that the legitimacy of a law is not dependent on its moral content. It's merely a paraphrasing/summary of H.L.A. Hart's legal positivism.
As I mentioned elsewhere in this thread, the entire founding political mythology of the United States is pretty much "The Parliament of the UK tried to regulate our freedom of speech without even giving us a vote, and that was intolerable." Specifically, the Stamp Act was seen as suppressing the right of the American colonies to engage in political speech. (This wasn't the only reason for the Revolutionary War, but it's one of the ones we still remember. We remember it in part because laws regulating the publishers of political pamphlets get complained about in political pamphlets.)
This isn't a political issue in the normal sense. It's more like Guy Fawkes and the "gunpowder treason and plot." The one thing that the "Tea Party" and the "No Kings" protestors can probably still agree about is that the Stamp Act was bad, because this issue is part of the fundamental political mythology of the country. "The British Parliament does not get to regulate our speech" is right up there with "The President does not get to wear a crown."
This is not a fight that the UK government can actually win, not in the long run. Any US politician who allows Parliament to regulate the speech of a US citizen will find themselves in the awkward position of British politician who proposed a national monument to Guy Fawkes. Allowing this is "Un-American" in these sense that it goes almost directly against our founding patriotic mythology and symbolism.
The UK should just accept the geo-IP block of the UK as a compromise, and walk away. This particular fight isn't worth it. Trust me on this.
More democratically-elected legislatures ought to say, “We don't give a shit about what our predecessors agreed to.” when it comes to treaties requiring restrictions on their own citizens.
Company A sells cryptocurrency in country A. Company B is a payment processor in country B. You in country A go to the country B merchant's website and enter your card info to buy something. Your card gets charged by company A to buy cryptocurrency, the merchant gets the money through company B and the transfer of cryptocurrency from company A to company B happens in software on a server somewhere and the user doesn't have to do anything.
Why is this either not happening or not sufficient?
We are building exactly this at Intercoin. I hate that most of crypto is zero-sum games. https://intercoin.org/currencies.pdf
Also Stripe is launching Tempo blockchain, USDC is launching Arc blockchain. Cool things are coming!
EDIT: I clicked on the PDF out of a sense of good faith interest and curiosity and I regret it. I hope you find something else to do.
I don't think that's true at all. You be taking payment by credit card, which doesn't require you to have any local presence.
I think your bigger risk is that you get a judgement made against you by a UK court, which a court that has jurisdiction over you is willing to enforce. I'm not sure under what circumstances that is the case, but I believe that it being the case with libel judgements has been an issue for a while (since plaintiffs can 'forum shop').
But you're offering an online product, plus you are taking money from people from all over the world, whose governments have different regulations and points of view, your own business charges differently for different countries, and credit card providers are bound to different fees and/or extra charges for international transactions.
It's not a simple solution.
This is quite obviously incorrect. I am a UK citizen, but live in the US. No company needs a UK presence to collect money from me.
But we're clearly far beyond that here.
I broadcast radio from my country, according to the rules of my country. If you tune in, and your country doesn't like it, they can enforce on you or broadcast something else on the same frequency if that's allowed by their rules.
You only have to have presence in the UK if you do some larger-scale commercial activity there (like X/Twitter), but of course you can easily sell goods and services to UK citizens without all that. But sites like 4cahn and SaSu don't even sell anything at all.
Please downvote the parent comment into oblivion.
Will the US embassy get involved? Of course. Will they get you released? Maybe, but it's not guaranteed. And you are in for a bad time regardless.
Or maybe China, for a US citizen who posted while on US soil, in a US website? https://www.reuters.com/world/exclusive-american-barred-leav...
Seems a little inconsistent, this delivery of Democracy.
Well not just the UK, but the comment you are replying to is about the UK.
> Seems a little inconsistent, this delivery of Democracy.
Ya. Also not a claim that the comment is countering. As a reminder of where you are in the thread, we are talking about the UK.
Source: https://gdpr.eu/companies-outside-of-europe/
1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
(b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
3. This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.
E.g. the website in this article https://news.ycombinator.com/item?id=45819635 does not work when you visit it with a European IP address. You get an error 451.I read the article and I remain confused.
I've just come to this story after seeing it on HN so I might have misunderstandings from being unaware of the background. Also, I neither reside in the US nor UK so I'd have not seen local media reports.
In short, I gather UK's Ofcom is threatening a US web site for online content that is lawful within the US's jurisdiction and unlawful in the UK as it contravenes the UK's Online Safety Act.
I am bewildered that Preston Byrne has even bothered to acknowledge Ofcom's correspondence let alone respond to it as the UK (Ofcom) has no jurisdiction over actions of any entity or person within the continental US—or for that matter the actions of those outside its borders unless, say, covered by treaty, etc.
That Preston Byrne responded to Ofcom seems strange given the fact that he is not only a lawyer but also head of legal and compliance at Arkham law firm, thus he ought to be aware that is client is shielded from UK law by virtue that the UK has no jurisdiction on US territory.
If I'd been Byrne I'd not have even acknowledged Ofcom's correspondence with a 'fuck off/cease and desist' reply but filed it in the trash can. (If there's some mitigating matter I've missed here let me know.)
It's clear to me the the UK's Online Safety Act stops at its borders so the UK has full responsibility for blocking websites that are physically outside its jurisdiction, similarly blocking or stopping its citizens from accessing accessing them.
It seems to me many of the younger internet fraternity are unaware that there's longstanding precedent for how such matters are handled. Back in the days of the Cold War before the internet some countries used to broadcast propaganda on HF/shortwave radio bands to those that were their political enemies and recipient countries would attempt to jam the broadcasts so their citizens would not be able to listen to them. For example, Communist USSR, China etc. would jam the BBC or the US's VOA (Voice of America).
Simply, if a country did not want its citizens to listen to the broadcasts of another country it was its responsibility to jam the incoming signals. It seems to me all that has actually changed since then is that nowady the unwanted broadcasts come via internet circuits.
Frankly, Ofcom has an unmitigated hide to threaten people who are acting lawfully within the US. That said, it's not unexpected, in recent decades the UK's been acting like a petulant bully, it seems to have forgotten that without it's empire it can no longer enforce its bullyboy tactics.
BTW, the matter of what content is or is not acceptable online is completely separate issue from Ofcom's behavior. Personally, from what I've gathered I'd find content on the SaSu website unacceptable and I can understand why many in the UK want it blocked but bypassing another country's sovereign authority is not the correct way to go about it.
I think it's important to fight these sort of things even in cases where they can't actually enforce it. For one thing, say one of the site operators in question have a need or desire to visit the UK at some point in the future, but can't, because there's some sort of legal judgment against them because of this. That would be a shitty situation.
On top of that, ignoring these sorts of things also ignores possible efforts by the UK to convince other governments (like the US) to adopt similar laws, or at least agree to some level of extra-territorial enforcement. Fighting these cases sends a signal to everyone involved. You mention the UK acting like a petulant bully: yes, sometimes a good way to counteract a bully is to ignore them, but other times it's good to fight back, even when the current bullying wouldn't be effective... because future kinds of bullying might be.
I'm aware of that, it's become an increasing trend over the past 40 or so years as diplomatic norms have broken down, changed or become more disrespected. If it continues we'll see even more tit for tat reprisals as respect for international law and authority continues to break down (we're now 80 years on from WWII and the world has almost forgotten lessons learned and the international order that arose from that conflict).
"…have a need or desire to visit the UK at some point in the future, but can't, because there's some sort of legal judgment against them because of this."
I remember a time when my passport was stamped in big purple letters "Not Valid for XYZ" country for reasons like that (I could not legally leave the county if that was my destination).
Matters would likely come to a head if say US passports were stamped "Not Valid for the UK". Moreover, it's incumbent on a country to protect its citizens who have done nothing wrong by their laws—hence a country should so warn its citizens beforehand, and stamping passports with large signs is very effective.
This is all part of a much bigger issue too big to address here. It's why I believe it's going to get much worse before it gets better. As I said elsewhere, I believe that with the increase in political and cultural differences brought about by rising nationalism we will see an increase in geoblocking everywhere. I find the trends shocking but there's stuff-all I can do about them.
Edit: I must emphasize that whilst I'm defending the right of law abiding US citizens against action by other governments, I'm not defending the US Government per se (some of it's actions of late I consider alarming). Again, these are separate issues.
Preston is not a legitimate lawyer and has never actually represented anyone. He only larps as an expert and spends an inordinate amount of time constantly trying to tell other lawyers how wrong they are, using his black-and-white god complex attitude.
When I said legitimate that's what I was referring to, not simply "passed the bar".
Not defending UK's idiotic laws, but this doesn't hold. If you cannot regulate websites outside of the country of origin, then no internet regulation can hold for any subject. Openly selling stolen personal credentials or botnet usage? Piracy? Reselling personal information without disclosure?
So there are effectively three options for internet regulation;
- Require websites to operate region by region with IP blocks for any non-target market. This is much of EU law is applied. If you put an effort to not serve EU costumers, you can skip following EU rules. "comply or leave"
- Any country can regulate any website regardless of origin, like the UK seems to push for. This is an insane proposal and could easily create geopolitical disputes. Great firewall and banning VPNs would be the only proper way to achieve what they seem to aim for.... which i wouldn't put past them by now.
- Give up regulating the internet entirely. Some level of regulation is valuable so I don't think this will ever work. There are simply some things illegal and deplorable enough to require laws.
You’re not going to extradite US site operators, period. Find another approach.
"If country B doesn’t like it, block the mail in question". Saying only the country of origin can regulate activity done in another country creates a legal worm-bucket with vast implications. It's also not how laws work currently in pretty much any other sector than the internet.
IP block should be sufficient to void the laws; That's how other EU laws work. If the UK wants more than than then they should just create a firewall. But saying the internet should be a fully unregulated hellscape is not a sensible position here.
That’s actually how it works? Unless you have an extradition agreement, or military overmatch, or you are willing to expend some diplomatic leverage, you are typically not getting a citizen out of a foreign country. The government complains about this all the time with goods from SE Asia, and sometimes they seize fake designer goods and make a lot of noise about it. But the people making the knockoffs just keep on making them, don’t they?
But this is the real issue. To what extent is a company "operating in" a country where it has no staff and no physical presence?
The principle that someone should become subject to the laws of a country they've never visited and where they have no assets just because they communicated with someone else who does live in that country seems questionable. Even if money is sent by the person living in that country to someone based elsewhere it still seems questionable.
Taken to their logical conclusion these kinds of arguments would kill off a lot of the value of the modern Internet (assuming they could be practically enforced). Can you even write a blog post any more if it might be controversial in any country in the world? Do you have to pay if you show ads next to that blog post and someone from the Sovereign Republic Of East Nowhere visits - but the Sovereign Republic Of East Nowhere has a law prohibiting online advertising as a social harm and imposing a fine of 1000% of global revenues generated through ads? What happens when the laws of two different countries are in direct conflict and one requires you to include an official warning of some kind alongside certain information on your blog but the other one prohibits such statements unless you're formally qualified to give advice in the field?
If you want to interfere with international trade or international communications at all then it makes far more sense practically - and arguably both morally and legally as well - to legislate so that your own people in your own country who are subject to your own laws are the ones who must or must not act in a certain way. If there's some kind of regulation on physical goods then make the person importing those goods responsible for compliance. If you want to tax international transactions then make the person in your country who is participating in those transactions responsible for declaring and paying the tax. But realistically this leads to a lot of non-compliance because your citizens don't have to be experts in international tax law so you can collect your $1.53 when they bought a new T-shirt from some online store based in another country and had it shipped.
Not sure I see how your logic has led you there. If a company (regardless of where they are headquartered) is operating in your country, then you necessarily have some sort of jurisdiction over it:
- If they are using servers or domain names hosted in your country, you can seize them.
- If they are making use of your country's financial system, you can ban them from that system.
- If they are shipping physical products to your country's residents, you can intercept those packages at customs.
- If any employees (or, better, officers) of that company are physically present in your country, you can fine or arrest them if they don't comply.
- If you have an extradition treaty with the country where they're operating, you can ask that country for help. If they decline, that's unfortunate for you, but that's life.
And right, in the end, if there's no "presence" aside from people in your country accessing foreign websites, then you can (given the right legal mechanisms) order ISPs in your country to block those sites. I don't see why any foreign-operated website should have any obligation to examine your laws and pro-actively block your residents from their site if needed; if you want your laws enforced on your residents, then... enforce them on your residents.
> But saying the internet should be a fully unregulated hellscape is not a sensible position here.
While I do see a few low-effort comments to that effect, I don't think that's a common opinion here. I don't even think the person you're replying to holds that opinion.
What the UK is doing is claiming, without having dealt with this via treaty that I am somehow responsible for keeping their citizens off my website. This is not something they can actually do. Now if they made a deal with my country that said that I had to in some way we'd be in a different universe. But currently they do not.
As I, and probably many others, see it. If they don't want UK citizens visiting 4chan or whereever they should control the flow of data through their borders better and punish their citizens for data smuggling if they vpn their way around it. It's no different than prohibited goods like automatic weapons. If I send someone in the UK a fully automatic ak-47 (which is legal in my juristiction) then I suspect UK customs will catch it at the border and possibly jail, or at least have a stern talking to the recipient.
No Internet regulation can hold extraterritorially. You leave out the obvious and most important case: the country where the Web site or whatever is located enforcing its own laws. Which is actually how all law has mostly worked from day one.
> Openly selling stolen personal credentials or botnet usage? Piracy? Reselling personal information without disclosure?
If you find a jurisdiction where those are all legal, then I guess you just have to block your citizens from reaching it, or punish them if they do. Not particularly tricky.
Internet but not for any other commerce. If you sell products to someone in the EU, you are liable to EU laws about that product category and commercial activity. The internet is the only exception, and that has caused a lot of problems.
IP block is the currently the only reasonable way to apply laws to internet based commerce. It has its flaws in accuracy; but ISPs could easily create a system to make them more reliable for IP lookup. Arguing that websites cannot be regulated outside of country of origin is an insane position to take with even the minimal level of hypothetical reasoning of what that would imply.
UKs laws are dumb, but they should be free to enforce them for websites operating in the UK. And websites should be able to leave the UK to avoid complying. This is a reasonable compromise that is already how both US and EU internet laws operate.
I don't know the state of play now, and I do know that things have gotten more that way over time. But the traditional approach to international product sales is that the importer is responsible. That originally meant the person who physically brought it into the country. As common carriers became more common, it meant the person who ordered the thing. That's occasionally been leavened by some consideration of whether the seller specifically targeted customers in the receiving country. And nowadays there's more of a tendency to start "blaming" sellers in some cases, probably because nowadays "importing" something is often a retail order from a specific consumer, as opposed to somebody bringing in a shipping container on spec to resell. Maybe some of those changes are appropriate, but it's just not true that physical goods have always been treated the way you want Web sites treated here, or even that they're mostly treated that way now.
> IP block is the currently the only reasonable way to apply laws to internet based commerce.
"IP block" works in both directions.
If you want to keep something out of your country, you should be responsible for blocking it, not the other way around. That's not necessarily easy, but it's less costly in total than demanding that every Web site enforce every country's regulation... and it has the advantage of putting the cost of a regulation on the people imposing it, which is where it belongs.
> It has its flaws in accuracy; but ISPs could easily create a system to make them more reliable for IP lookup.
From your use of the word "easily", I conclude that you personally would not be among those responsible for making that work.
> Arguing that websites cannot be regulated outside of country of origin is an insane position to take with even the minimal level of hypothetical reasoning of what that would imply.
First, you can in fact "regulate" by blocking, without trying to extend the reach of your laws outside of your border. Your claim that a regulator is left totally powerless is just false.
Second, in practice, that "hypothetical" is pretty close to what we have now, and even closer to what we had 10 years ago. The world did not end.
> UKs laws are dumb, but they should be free to enforce them for websites operating in the UK
Sure, as long as we recognize that "operating in the UK" properly means "is physically located in or controlled from the UK" and not "happens to be accessible to people in the UK". The latter definition would indeed be insane.
It would need to be set up by an extremely powerful country, either the US or an alliance of smaller countries through international treaty.
It would work as follows:
There'd be a "naughty list." Anybody on the list would be arrested upon entering a participating country. This would include past or current company employees (if employed after the listing date). Companies from participating countries would be prohibited from interacting with listed organizations in any way, under treat of sanctions. This would include VPN, cloud and hosting companies, ISPs, domain registrars, email hosts, payment processors and ad networks. This would provide basic site blocking.
Foreign companies wouldn't be subject to the sanctions, but participating countries would also put them on the list.
I am unaware of any prosecutions in this area.
https://ofac.treasury.gov/sanctions-programs-and-country-inf...
Good
It can, but instead of forcing other people to follow your laws, you have to block your country's residents from accessing the sites that break your laws.
I'm not saying I love this method either (China is famously very good at it, and I don't think their methods foster a healthy society), but I believe it should be the only lever you have. Forcing people outside your jurisdiction to follow your laws is a violation of another country's sovereignty.
As an aside, should I take pains to ensure any website I operate follows the laws of North Korea? Iran? China? Russia? Should we be complacent and accepting if HN were to be targeted by any of those governments because people here have undoubtedly said unflattering things about the leaders of those countries?
Of course not. But even though we're talking about a "friend"-type country here, it's not any different.
Comedically far.
Uni students have been know to drive for a drink at the pub at the next Uni north (at the time) over the weekend for a lark. That's 2000km, one way.
A serious undertaking by Australian standards is a drive to Perth. That's 5000km in a straight line, but of course you can't drive in a straight line to Perth.
I met a guy once who was the last leg of circumnavigating Australia on his push bike. It had taken him years, and it looked like it. I've never seen someone so wirey, so obviously fit. Yet he rode at a slow measured pace. That was no doubt a habit forced by the trailer his bike towed. I guess the trip was around 15,000km.
But it's the edges that get you.
I moved home a few years back, connected a new service with the same ISP.
They have an IP pool that is labelled as for one state (Victoria, Australia) but is also used for their services in Tasmania.
So now I have to fight every major website (Google, Amazon, Maxmind, etc) that does GeoIP lookups that I'm not in Victoria, I'm 500-800KM away.
Google was very confused for about 12 months because when I moved I also brought my wifi gear and so it would give me a precise location of my old address because it used wifi geolocation.
Also, Britain isn't important enough to make this stick against e.g. an American.
If someone writes me a letter asking a question about material that is prohibited in his own country, that is not my problem. It is his responsibility to comply with local law and that of local government to seize material that is illegal there. They cannot deputize me to act, unpaid and without consent, on their behalf.
That's what happens when you respond to a request after all. (Up to very minor nits, e.g. you might be paying a cloud provider instead of an ISP).
Governments that expect some content or other blocked can damn well do it themselves, in their own legal system. They cannot compel someone else to spend his time, talent, or treasure to enforce their petty rules.
If they go after one of their own for requesting something from me, whatever. If they block me, whatever. I suppose they're within their rights to do that.
The federal government "deputizing" or trying to chill private actors out of speech, out of doing business, etc. is a violation of Americans' first amendment rights; so held SCOTUS last year. No way in h--- are we letting some tinpot foreigner do so.
What you are describing is exactly what is going on here. OFCAM’s final action, if taken, is blocking at ISP level. All of the legal stuff is happening in the UK system.
I’m just sort of curious for your thoughts after learning that.
(Also, I’m curious about the SCOTUS decision, I.e. which one? I used to be a law nerd and got a kick out of reading oral arguments for the first time in years this week, would appreciate more material)
Murthy v. Missouri was generally a loss; 6-3 with Justice Barrett for the majority ruling states lacked standing, which is consistent with the Roberts court's informal policy of dodging. Alito dissented, joined by Thomas and I think Gorsuch, and that is worth a read. The more important one was NRA v. Vullo, a unanimous opinion from Sotomayor. Gorsuch wrote a concurrence as did I believe one other justice.
Governments can do whatever they damn well please in their own territory. Including arresting you if you ever visit because you violated some law that they wrote that applies to people in the rest of the world, or even you violated some law that a friend of theirs (i.e. a country with an extradition treaty) wrote to apply to people in the rest of the world. If those actions compel people to spend their time, talent, or treasure to enforce their petty rules then they can do that.
Whatever "actively reaching out" standard you are imagining doesn't exist in the first place. Even if it did though, you clearly violated it when you sent the reply to the request actively aware that it could go across borders.
SCOTUS (with an emphasis on the US) decisions seem rather irrelevant to non-US actors.
The US will not enforce UK judgements or fines if enforcing them is contrary to the US' own laws, including its Constitution. SCOTUS ultimately decides when that's the case.
So it's really, really relevant to whether a non-US actor like Ofcom can actually collect fines from people inside the US. That's a separate question from what the UK government can do to people from the US who actually enter the UK, and an important one.
If I were a UK citizen or resident, I'd probably be pretty pissed off that Ofcom was wasting money and resources on battles they are going to lose. Well, I suppose, since Ofcom is funded in large part by the UK-based businesses it regulates, if I were an officer, employee, or shareholder of one of those companies, I'd be pissed that they're wasting money paid by my company to fund them.
And even though Ofcom is not directly a UK government agency, there are certainly political costs to tilting at windmills for the UK government.
I think you're looking at it the wrong way. I'm not thinking about that at all. I do not care about that at all. I am not beholden to the laws of any other nation when I operate my website[0]. I don't care about "reaching out across borders". I don't event know the geographical origin of requests that hit my server, because I don't care, and I have no need or desire to hook up some sort of (error-prone) geoIP database to my logs in order to categorize requests. Once the HTTP response packets leave my server and hit the first router hop, I have no knowledge or interest in where they end up after that.
> SCOTUS (with an emphasis on the US) decisions seem rather irrelevant to non-US actors.
Not sure why you're bringing that up, as GP didn't mention SCOTUS at all. But as a US citizen and resident, SCOTUS' rulings are all that matter to me when it comes to what I personally do while at home. If SCOTUS says the content on my website is legal based on US law, then I don't really care whether or not it's legal in other countries[0, again], and I shouldn't really have to; life is too short to have to worry about that sort of thing.
[0] Sure, I agree with you that this could be a problem for me if I do break any of their laws, and then later decide I want to visit that country. It could also be a problem if that country has an extradition treaty with mine, and my country is for some reason incentivized to give me up.
As mentioned in my previous reply, this isn't how the internet works. There is no teleportation or ICBM delivering the packets. There is infrastructure spanning borders and the infrastructure is the thing that is ignoring the laws. The infrastructure has accurate geographic knowledge about the physical connections. The webserver doesn't have that information at all and must infer it. From the perspective of the webserver, the physical world might not exist at all. There is no such thing that can be described as awareness from the website operators perspective. IP addresses do not encode geographic information. The entire point of the OSI layer model is that the higher layers know nothing about the lower layers nor do they know anything about the physical location of the nodes.
Again, only the operator of the network has that information and the operator is located inside the UK. It is those network operators in the UK that are wilfully ignorant and aware of the things you claim a website operator from a far away country should be aware of.
Just think about how ridiculous your comment is if you sued someone in the US from the UK and brought up their awareness. How would you prove that they knew the location of every single router and fiber cable the packets are traveling through? That's what you're arguing here. You're arguing that there is full and complete awareness.
The network infrastructure is the thing that is performing the delivery that is actively reaching across borders. Not the webserver.
The entire HN submission is full of people saying that it is the UK networks responsibility to make sure that their laws are upheld and that anything happening inside US borders is simply people going above and beyond in assisting the UK in the pursuit of the enforcement of its laws. The geoblocks on the side of the webserver are a form of optional assistance and a sign of goodwill.
Meanwhile Ofcom seems to be of the opinion that this isn't enough yet they simultaneously do nothing about the violators physically located in the UK. This means they are going out of their way to make an unenforceable and impossible to implement law so that they can manufacture probable cause.
Website operators can give the UK a list of IPs to block, which would make it very easy for the UK to enforce their own laws even against VPNs, but it is only the UK that is capable of doing that, and they are shirking their responsibility onto those who can't do it on their behalf.
Second, where is the person writing the letter from? Mars? They're going to have a hard time finding a place where kidnapping and extortion are legal.
Third, the letter would in fact presumably be aimed at a specific person in a specific country... as would the kidnapping.
The company could be from china or Russia with little interest in diplomatic pandering for such a small incident.
Providing a user a service in exchange for payment is also aimed at a specific person in a specific country.
heck, if no laws can be applied across borders, it could be a website selling the service of fake extortion letters.
And don't mix up "difficult to enforce" with "legal". Constantly changing domains and hiding who is behind the service are efforts to avoid being caught by very real and enforced laws.
"Innocent"? That's a strange word to choose. Who cares what's "innocent"?
> It’s a choice, and has been the default for a long time, but it means one has chosen to speak outside the borders of their own country and that comes with rules, like them or not.
... or it means one has chosen to speak inside the borders of their country, and people outside those borders have chosen to import that speech. Web sites don't lob speech at you willy-nilly.
The bottom line is that that standard is impractical to implement, illiberal in its effects, and just generally a bad idea. For that matter, it's also at odds with most of the ways the world treats trade in physical goods.
If I'm not afraid of violating NK law — because I'll never, ever be there — then the same logic holds for the laws of every other country I won't be visiting.
If the government of their country believes that accessing my website is a problem for their residents, then the onus is on them to sort it out on their own, without my involvement. They are perfectly capable of ordering ISPs that operate inside their borders to block my website from their customers.
The fact that Ofcom hasn't just done something like this in the case of SaSu, 4chan, etc., shows that they are not actually interested in "online safety"; they're making political statements and are trying to throw their weight around like the bullies they clearly are.