This particular article (not the subject) looked suspicious to me, since I didn't see it contain a link to the EARN-IT bill. I respect that it was created by the FSF, but they really should link to the bill's text.
The bill's text is here. [1] I don't think it does anything that is stated in the article. It's stated purpose is to create a commission that will create recommendations that nobody will have to follow. It actually says that. Then, in Section 5, (7)(A) it explicitly says that it won't affect end-to-end encryption - it says that companies won't need to stop using E2EE and there won't be any liability created for using E2EE.
In general, I am against regulation, but this bill doesn't do what the article claims it will do. Yes, it is absolutely politicking, but it doesn't seem to do much of anything outside of wasting time and resources.
The part of the bill that mentions E2EE (Section 5) is an amendment to the Communications Act of 1934, namely the famous Section 230 which contains: "No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider."
So the EARN-IT act would seem to me to modify Section 230 to not apply in cases of child sexual exploitation law, importantly "any charge in a criminal prosecution brought against a provider of an interactive computer service under State law regarding the advertisement, promotion, presentation, distribution, or solicitation of child sexual abuse material". However despite this amendment, using E2EE would not "serve as an independent basis for liability of a provider", whatever that means.
This seems more notable to me than the whole "creating a committee to create best practices" sections but I could be misreading or misinterpreting the bill honestly, I'm no expert.
In this case, your quote is only one third of the content. You are not quoting the first sentence or the last part, which is why the quote doesn't make sense.
Your quote should read the following, where I've italicized the two parts you left out, "NO EFFECT ON CHILD SEXUAL EXPLOITATION LAW.—Nothing in this section (other than subsection (c)(2)(A)) shall be construed to impair or limit— any charge in a criminal prosecution brought against a provider of an interactive computer service under State law regarding the advertisement, promotion, presentation, distribution, or solicitation of child sexual abuse material, as defined in section 2256(8) of title 18, United States Code;"
Yes, I skipped or paraphrased those parts of the bill to keep things short in a way that I thought made sense. But I think the message is unchanged with the full text. Namely that Section 230 would be amended to also state:
"NO EFFECT ON CHILD SEXUAL EXPLOITATION LAW. Nothing in this section [NB Section 230] (other than subsection (c)(2)(A)) shall be construed to impair or limit ... any charge in a criminal prosecution brought against a provider of an interactive computer service under State law regarding the advertisement, promotion, presentation, distribution, or solicitation of child sexual abuse material, as defined in section 2256(8) of title 18, United States Code;"
And so Section 230 protections to content providers would cease to apply* in cases of child secual exploitation law, I think.
* EDIT: Except for those points that would be added to Section 230 specifically regarding E2EE
My interpretation is, the bill will remove liability shield for “online publisher” for CSAM. This then effectively means that no online platform may use end to end encryption to protect their user, for fear of liability.
Individual user, and those who own the content of their website, are free to use E2E if they choose to, whatever benefit that still gives.
Anticipation of this law feels like why Apple went through its CSAM debacle. Expect to see more content scanning after this passes. The CSAM DB Apple was said to be using will likely be “best practice” in how online service may get liability shield back.
I too don’t like how HN, FSF, EFF jumps straight to “encryption ban”. It spells fear that too much nuance will weaken their argument.
The bill's text is here. [1] I don't think it does anything that is stated in the article. It's stated purpose is to create a commission that will create recommendations that nobody will have to follow. It actually says that. Then, in Section 5, (7)(A) it explicitly says that it won't affect end-to-end encryption - it says that companies won't need to stop using E2EE and there won't be any liability created for using E2EE.
In general, I am against regulation, but this bill doesn't do what the article claims it will do. Yes, it is absolutely politicking, but it doesn't seem to do much of anything outside of wasting time and resources.
[1] https://www.congress.gov/bill/117th-congress/senate-bill/353...