272 karma · joined September 5, 2023
The Commerce Clause has been read very expansively since the Wickard v. Filburn[1] in the New Deal era. One of the current legal projects of the Federalist Society, the conservative legal movement the current Supreme Court majority stems from, is rolling this back, and limiting the power of the Commerce Clause. They argue that reading the Commerce Clause so expansively coupled with modern technological/economic change gives the Federal Government effectively unchecked power to regulate behavior, which was contrary to the intention/design of the Constitution. Supporters of the current status quo argue that reading the Commerce Clause too narrowly would make the modern economy unmanageable and ungovernable. It's an open question how far the current Supreme Court will go in paring it back, but they have started narrowing parts of this doctrine.[2]
(There are no prior cases on this in the context of AI generated content in the United States, because this is the first time this offense has been charged for AI generated content in the United States. That's why it's so newsworthy and why I posted it - it's going to set some precedent, one way or another.)
I personally find the much more interesting argument here to be about obscenity. The obscenity doctrine places "obscene" speech completely outside the protection of the First Amendment. Previously, the Supreme Court ruled in Ashcroft vs FSC that for CSAM to be illegal, it must at least meet the bar for obscenity, or it must be produced via actual exploitation.[3] This is the most similar case I am aware of.
Obscenity doctrine in the United States is... a bit of a hot mess, in my humble opinion. The current test is as follows:
> The basic guidelines for the trier of fact must be: (a) whether "the average person, applying contemporary community standards" would find that the work, taken as a whole, appeals to the prurient interest; (b) whether the work depicts or describes, in a patently offensive way, sexual conduct specifically defined by the applicable state law; and (c) whether the work, taken as a whole, lacks serious literary, artistic, political, or scientific value.
To be blunt, I don't think anyone really knows what that word salad means. What are the "contemporary community standards"? Who is the "community"? What does it mean to be "patently offensive"? According to whom? The whole thing that makes exclusions to the First Amendment tenable is that they need to be really, really clear. Otherwise ambiguity in the standard leads to curtailment of expression by a chilling effect.
Furthermore, there's also this ruling[4] - that as far as I can tell is still good law - which makes it unconstitutional to ban the mere possession of obscene material. I don't think that applies here, because in this case, the defendant is alleged to have distributed the material widely. Furthermore, it also stems from a "right to privacy" the current Supreme Court is rather skeptical of.
There's not really a conclusion to all this. The main point here is that something is happening and that will probably result in interesting decisions later on.
[1] https://fedsoc.org/case/wickard-v-filburn; held that Congress could bar farmers from growing wheat on their own land for their own consumption.
[2] https://www.nlc.org/article/2023/06/15/supreme-court-decides...; limited the related Dormant Commerce Clause doctrine.
The point of (d) is to create a jurisdictional hook for the US federal government. The federal government only has power over a limited number of offenses, including "interstate commerce" related offenses, but not most normal criminal offenses, which can only be criminalized by the states. So, for the federal government to regulate it, the easiest way is to only regulate things that involve interstate commerce somehow. In this case, downloading the Stable Diffusion model over the Internet probably creates enough of a hook, and this defendant is alleged to have done much more than that, so it's probably enough.
[1] https://github.blog/2020-12-21-get-up-to-speed-with-partial-...
[2] https://github.blog/2022-06-29-improve-git-monorepo-performa...
[3] https://arstechnica.com/information-technology/2017/02/micro...
"When the administrator uses a Microsoft account to sign in, the clear key is removed, a recovery key is uploaded to the online Microsoft account..."
Microsoft does not break down requests by key disclosure, but they do say in their most recent report for 2022 H2 that they released account content for 522 requests to US criminal authorities in that half. It does not note how many accounts were included in those 522 requests.[2]
[1] https://learn.microsoft.com/en-us/windows/security/operating...
[2] https://www.microsoft.com/en-us/corporate-responsibility/law...
My argument isn't that this isn't documented. It's that it is a bit counterintuitive.
My points are:
1) It would be best if Microsoft just asked if you wanted encryption if you create a local account. This is what Apple does in this situation. I imagine a large portion of the people who are creating local accounts on Windows 11 Home are the sort that want to manage their own keys.
2) If you are in that set of people, you should double check your setting if you never thought about it before, because it's easy to miss.
"Unlike a standard BitLocker implementation, device encryption is enabled automatically so that the device is always protected... When the administrator uses a Microsoft account to sign in, the clear key is removed, a recovery key is uploaded to the online Microsoft account, and a TPM protector is created. Should a device require the recovery key, the user is guided to use an alternate device and navigate to a recovery key access URL to retrieve the recovery key by using their Microsoft account credentials."
From https://learn.microsoft.com/en-us/windows/security/operating...
This is also how it's reported in the press:
"In fact, the mechanisms to do exactly that are already in place. Windows 11 Home and Windows 11 Pro both support automatic device encryption, with the Home version a more streamlined experience. You just have to sign into the machine with a Microsoft account, which nearly all people do during setup."
From https://www.pcworld.com/article/624593/is-your-windows-11-pc...
My main point is just that if you skip this, like a lot of privacy conscious people do, you might end up inadvertently not having encryption fully enabled.
The furthest this has gone that I’m aware of is the Dutch, alongside other EU authorities, has issued a fine to an American website, alleging that they subject themselves to EU jurisdiction by merely hosting information about EU citizens. This seems to me to be too far.
https://edpb.europa.eu/news/national-news/2021/dutch-dpa-imp...
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A...
I think this is going to inevitably create more and more tension between EU and American contexts, because hate speech is affirmatively legal in the U.S., most recently ruled under Snyder v Phelps.
- The EU has drastically scaled up regulatory requirements for tech businesses, starting with GDPR, running through the DSA, and probably eventually continuing through the AI Act and the proposed cybersecurity law. Because this is a community mostly centered around people who start or work at or invest in tech businesses, there’s a lot of frustration that the new regulations are making life harder.
- In this case, part of what the EU alleges is that Twitter is not doing enough to actively combat disinformation. People are concerned that what the EU wants in terms of combatting disinformation IS a speech-controlling agenda.
I’m not sure either argument is 100% correct, but I can understand why many are arguing that the EU regulations are going too far, both in terms of requiring too much work for too little gain, and in terms of jeopardizing Internet independence.
Section 8 paragraph 1 seems to clearly not require a service provider to block access in order to prevent copyright infringement if they meet its requirements. I understand that section 7 paragraph 3 leaves in place blocking remedies specified elsewhere in other laws. However, for the specific case of copyright infringement, this is clearly the narrowest most specific rule for blocking due to copyright infringement, and at least in American law that generally means it is the one that takes precedence for the infringement blocking case.
Also I read Section 7 paragraph 4 to just mean that public WiFi hotspots can be mandated to block infringing content if no other means is available.
Am I reading this wrong? I’m struggling because I’m not sure if my understanding of the German language or German law is wrong here.
I'm a big fan of tools like secretive[1] that can help solve this problem by using biometrics to shift the UX/security trade-off and thus make it feasible to always require some kind of authentication to sign a token with a key.
I'm not aware of any tools that do the same for Linux, and a quick Google search doesn't turn up much[2]. It does look like you can at least get a notification[3], though.
This could provide another layer of protection on the user's endpoint device in addition the network monitoring called out in the article. Defense in depth, and all that.
[1] https://github.com/maxgoedjen/secretive
[2] https://unix.stackexchange.com/questions/705144/unlock-an-ss...
[3] https://www.insecure.ws/2013/09/25/ssh-agent-notification.ht...
[1] https://www.xda-developers.com/android-q-apex-biggest-thing-... [2] https://www.xda-developers.com/android-10-custom-boot-animat...