News: 1599634874

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Don’t lump us in with Facebook, internet infrastructure companies warn European Union

(2020/09/09)


Europe’s two largest internet network infrastructure organizations have warned lawmakers not to lump the core network in with online platforms and apps when it comes to content regulations.

In response to the European Union’s Digital Services Act (DSA) [1]public consultation , the Regional Internet Registry for Europe (RIPE) and Council of European National Top-Level Domain Registries (CENTR), have sent a [2]joint letter arguing that “although the Internet is often perceived as a single technology, it comprises many different components at many different layers that each have a role to play in its functioning.”

RIPE represents the Internet Protocol (IP) address industry in Europe and CENTR the domain name industry.

The DSA is largely focused on content regulation, particularly how to limit illegal and damaging content. The goal is to update legislation made over 20 years ago to deal with the modern realities of dominating platforms like Facebook and Google, in much the same way that the US is looking at new laws around Section 230 of the Communications Decency Act as a way to get those platforms to take greater responsibility for the content that they host.

But despite many ordinary internet users often confusing Facebook or Google with the internet itself, RIPE and CENTR are keen to stress that it doesn’t go the other way. The actual core infrastructure of the internet is agnostic when it comes to content, they stress, and is designed to simply connect computers.

“We urge the European Commission to make a clear distinction between the Internet’s core infrastructure and the source of those threats - namely, the applications and content that run on top of that infrastructure - and to protect the Internet’s core infrastructure and operations from the potential for abuse as an unintended consequence of content regulation,” the response reads.

Effort

There have been countless efforts in the past few decades to get internet infrastructure companies to take on more of the burden of controlling infringing or illegal content on the internet.

But that’s the wrong path to go down, warns the industry. “Without a clear understanding and protection of the Internet’s public core in place, it will be far too easy to try to address illegal content by striking at the core infrastructure, including Internet routing and the Internet Protocol (IP) and DNS layers, rather than targeting the specific applications and content running on top of this infrastructure,” the orgs warn.

“While it can be easier to block IP addresses and domain names than it is to block specific content, the collateral damage that is likely to result from this ‘sledgehammer’ approach has the potential to affect large segments of the Internet that had every right to continue functioning normally.”

European Commission: Full-scale probe launched into data-slurping potential of Google's $2.1bn Fitbit buy [3]READ MORE

RIPE’s head of public policy Marco Hogewoning said in a [4]separate statement : “Our goal is to ensure that well-intentioned policies to protect users don’t unintentionally disrupt the Internet’s technical operations.

Besides the potential for notice-and-takedowns to be abused by bad actors, any intervention at the level of naming and addressing will almost certainly result in collateral damage. So, we need to make sure that actions taken that affect the core of the Internet are only used under very strict and limited conditions and that there are protections against any malicious behaviour.”

The most common example of this has been seizing control of internet addresses - domain names - on top of which websites containing infringing or illegal content has been hosted. This “can be very disruptive to the normal functioning of the internet,” warns the response, “and should be a last resort.”

They also warn against the proposed inclusion of a “Good Samaritan clause” that would protect providers who act in good faith to voluntarily and proactively take action against illegal material - similar to America’s Section 230 - arguing that it could “end up resulting in a perfect storm, whereby the Digital Services Act would simply make it too easy to abuse the process to take action against online intermediaries.”

Problem

It gives an example: “What would stop a bad actor from sending millions of automated notice-and-takedowns to a competitor as a kind of DDoS attack if there is no cost to her in requesting action against ambiguously defined ‘harmful’ content, and yet the receiver is obligated to take action under very strict deadlines or face major penalties?

“Or from hiding behind the Good Samaritan clause and pretending to act in good faith in order to remove content for her own nefarious reasons? To keep this from happening, there must be a balance of liability between those removing content or requesting content be removed, and those receiving the requests for action.”

RIPE and CENTR also ask for “clear definitions” or things like “harmful content” and “dis/misinformation” so it is possible to create clear policies “in determining whether to respond to takedown notices, including clear guidelines on when different service providers can and should take action.”

And they argued that “a higher burden of proof should be required for any action that would affect the core infrastructure or operations, as well as some measure of shared liability or another deterrent against malicious motivations.”

On a larger level, one of the biggest problems, the two orgs argue is that “there is a lot of ambiguity” in current European law about how the services provided by internet infrastructure companies are seen: are DNS delivery , or routing, of internet exchange points the same as other intermediaries like Google providing search results or Facebook hosting user content? They argue yes, and note, somewhat pointedly, ask that the core network “be protected from political intervention.”

The good news is that RIPE and CENTR feel they have a solution: a definition of what is the internet core network and core services should be developed and then that “public core” be looked at as a separate and different group when writing new rules and laws.

How not to make a decision

The bad news is that they propose using the “multistakeholder model” where everyone that is impacted by decisions gets a say in the final solution. That model has been used and promoted by the internet infrastructure and governance worlds for some time - as opposed to government-led or industry-led approaches - but it has proved notoriously slow and difficult and, arguably, its main success is that it stops anyone from changing the status quo because no one can ever agree on what changes need to be made.

The European Commission (EC) has long experience of the most high-profile examples of the multistakeholder approach within DNS overseer ICANN and within the Internet Governance Forum (IGF) and it’s fair to say it has often expressed frustration bordering on loathing for the approach.

Nevertheless, RIPE and CENTR argue that “only through this multistakeholder approach - which has served the development of the open, innovative Internet so effectively since its conception - will the European Commission be able to table legislation that will continue to best serve the needs of Internet operators and users.” ®

Get our [5]Tech Resources



[1] https://ec.europa.eu/commission/presscorner/detail/en/IP_20_962

[2] https://labs.ripe.net/Members/suzanne_taylor_muzzin/our-view-on-the-upcoming-digital-services-act

[3] https://www.theregister.com/2020/08/04/ec_probe_fitbit/

[4] https://www.centr.org/news/news/joint-press-release-new-digital-services-act-should-support-not-restrict-the-internet.html

[5] https://whitepapers.theregister.com/

"My Internet..."

Mike 137

"many ordinary internet users often confusing Facebook or Google with the internet itself" thanks to major content and application providers, (notably MS) seeming to do the same. But it is rather worrying that regulators apparently have to be reminded of the difference.

The infrastructure approach has caused problems in the past when self-appointed anti-spam agencies have blocked huge ranges of IP addresses because of a few miscreant IPs. For example, on several occasions and for quite some time in each case Tsohost has been entirely blacklisted by Plusnet because of this.

Is the problem simply that politicians don't have a clue?

Martin an gof

Much as some (many? most?) members of the public confuse Google with "the internet" and misunderstand the way things are plugged together, I get the distinct impression that the same is true of politicians, even those who have been put in charge of departments with specific responsibilities. I've long felt that having an education Minister with no experience of the education system other than attending Harrow thirty years ago (I generalise, but you get the drift) is a contributing factor to the utterly confused policies successive governments have had towards education in the UK, and similar arguments could be made for those with responsibilities for transport, health, defence, the environment and so on and so on.

It probably (in the UK at least - I believe some other countries might be better) stems from the sheer lack of suitably qualified candidates. There is a disappointingly small proportion of MPs who have qualifications or real-world experience in anything other than Politics or Journalism.

It has undoubtedly been entrenched by the tendency of those in charge to promote their mates - who probably went to the same school and likely as not studied the same courses at university, or at the very least joined the same cricket or rowing club.

It has definitely been exacerbated by the hostility of recent governments towards "experts", but I'm afraid this part of the equation has been around for a very long time in the general "PHB class" - in my very first (proper) job after leaving university, I was told by the newly-appointed "station manager" (i.e. top bod in the building), who had rather rapidly and unwisely been promoted from sales droid to head of sales and then to overall head of the outfit in the space of a couple of years, "I don't want you to tell me it can't be done, I just want you to do it!" It was rather difficult for me - as very much the junior in the building - to explain that I wasn't saying it couldn't be done at all, but that it couldn't be done as quickly and easily and cheaply as the manager wanted.

It's one thing when that attitude means that the manager's office has to "make do" without the fancy new 12V string lights to impress visitors for a couple of months, it's a completely other thing when it means that ministers ram through legislation which could have (and often does have) far-reaching and long-standing consequences, probably more so for the proletariat than for the ministers themselves.

Perhaps what we need is some kind of children's TV-style induction course for new ministers.

"Good morning minister. Now, it may seem like magic, but actually there is some very clever engineering behind the systems which allow you to take a picture of your cat with your mobile phone and almost instantly send it to thousands of other people. Oh, sorry, yes, 'engineering' is a very long word.

"Why don't we begin at the very beginning..." (cue cutesy tune)

Sorry, political rant over for a bit

M.

Re: Is the problem simply that politicians don't have a clue?

Alumoi

Of course politicians don't have a clue. They are the ruling class, they know what is good for the peons and they have the power to direct the engineers to make it happen.

It can't be done? Nonsense, I say it will be done, it WILL be done and damn the fallout. Think of the children/terrorist/mother nature/...

Re: Is the problem simply that politicians don't have a clue?

Julz

The competences that the political systems select for include things such as being able to raise/have loads of money to give to your party. Be friends and have influence with all of the correct people for any given definition of correct. To be able to give a credible interview while defending the indefensible and simultaneously not saying anything of substance that could be used against your party at a later date. Being arrogant enough to believe that you have the right to make decisions for others while conveying the the air of being one of the people. There are others but you get the idea.

While none of these actually exclude experience outside of politics, those who are steeped in the inner machinations of the relevant political system will always be at an advantage. Shit but hey :(

Peter Galbavy

Surely if the Chinese can do it with the Great Firewall, then why shouldn't European network operators?

A rock and a hard place

Pascal Monett

While I perfectly agree that my fiber connection should not fall under the same rules as this post, if you tell me that ICANN is your model for managing things, well, let me just say that I cannot agree with that on a fundamental level.

The multistakeholder approach may be a nice idea when everything is working well, but if things turn into a Gordian knot, somebody has to take an axe to it and be done with the issue. When gangrene sets in, you cut off the limb. It's the only way to be sure.

Now the question is : are we at the point of gangrene ? I don't think so, but please do not give me ICANN as the model. Gangrene has not only set in the limbs, it has taken over the entire body and should be purged with fire.

And I'm talking literally purged with fire.

Anonymous Coward

“What would stop a bad actor from sending millions of automated notice-and-takedowns to a competitor"

I cringed at that one. Courts would stop them. Because the law, unlike what they pretend to believe, is not applied mechanically, it's interpreted by actual human beings, maybe not all perfect, but certainly with quite a few able to notice obvious bad faith use of the law (and of course, there are also laws addressing bad faith use of the laws).

So fine, I agree with their worries, they need to be addressed, but no need to add to the FUD.

Frederic Bloggs

"Courts would stop them", maybe in six months or, more likely not at all, because I doubt there is a single "Judge William Alsup" style judge - who actually understands the issues - in the UK Judiciary.

Even if there are, there is a good chance that they would recuse themselves because they know more about the subject than they should and therefore might be biased.

Sigh...

The wise man seeks everything in himself; the ignorant man tries to get
everything from somebody else.