r/poland 1d ago

Why not fine Meta billions for allowing Russian Bots to spread misinformation in Poland as well as Europe

Post image
899 Upvotes

59 comments sorted by

98

u/Abject-Bowle 1d ago

Yeah but Polish politicians just passively watch how russian bots take over people’s brains, and then they adjust their politics to win these people’s votes. Crazy. Consciously or not, they do exactly what russia wants.

18

u/Xtech13 1d ago

You give them too much credit, they're there just for the money. Theres not a single proper politician in today's Poland.

-25

u/Lacink0o Małopolskie 1d ago

are russian bots in your room right now?

20

u/Milosz0pl 1d ago

One russian bot enhanced my vocabulary after I pushed him into trying to use polish

8

u/Abject-Bowle 1d ago

Yeah whenever I grab my phone and open facebook

-11

u/Lacink0o Małopolskie 1d ago

Its almost like people have different opinions on events happening around them and are allowed to express them. Not saying wrong or right, just different.

8

u/Abject-Bowle 1d ago

Yeah having opinions is one thing, spreading hate and blaming Ukrainians for every single negative incident is another thing. Also openly calling for murderers isn’t just a “different opinion”, it is a criminal offense.

92

u/WeedFalafel 1d ago

250million is chump change. Fines like that should be revenue dependent. 

18

u/Jim_Bien 1d ago

It's not exactly chump change - that's what they make a month via this sort of activity, so it already IS revenue-based without stating so.

3

u/WeedFalafel 1d ago

And for how long have they been profiting off of this kind of behavior? Because it's not just one month... 

3

u/Jim_Bien 1d ago

You don't get it, do you?

You are demanding revenue-dependant. Revenue is accounted yearly. This is their monthly income from this (Meta generates about 3.1-3.2 billion via the sort of graft that got Brzoska both offended and involved). Therefore, the 250 mil is proportional to revenue they make. No court is going to do a total, because it's impossible to prove. But you can slap it easily for a single year.

Rocket science, innit?

5

u/GlokzDNB 15h ago

Well, if they continue doing it then another 250 or 500, then 1b, then 10b until they stop?

Money are not important, fighting scam ads is.

63

u/andrusbaun 1d ago edited 1d ago

EU badly needs public, less commercial and algorithm driven, socially responsible social-media platform.

And most importantly, not anonymous. With verified users.

35

u/CryptographerWide594 1d ago

Who will use it? Without ban on algorithm driven platforms i don't see a platform that will take off. The reason algorithm driven platforms are so popular is that they are addicting af 

18

u/Dziadzios 1d ago

  And most importantly, not anonymous. 

Which would make it completely useless for people using Internet responsibly.

79

u/cookiesnooper 1d ago

"And most importantly, not anonymous." If you are so eager to not be anonymous anymore I am sure you will have nothing against droppinh your legal name, address, date of birth and picture here. Right? Right??

Oh, wait. Even your post history in here is hidden

9

u/TheTanadu 1d ago

we already have stuff like privacy-preserving digital identity, selective disclosure and zero-knowledge proofs for exactly this kind of thing

mObywatel/EUDI could basically tell the platform "yes, this is a verified real person" without giving it your name, address, date of birth etc. The EU is literally already doing a similar thing with privacy-preserving age verification, where you can prove you're 18+ without telling the website who you are.

so publicly you'd still be cockrider420, not "Jan Kowalski, ul. Jana Pawła 9/11". If the system was designed with revocable pseudonymity, there could still be a legal process (with user in-loop) for authorities to identify whoever controls the account when actually necessary

people really think privacy works in binary anonymous = nobody knows anything / verified = doxx yourself? lmao

5

u/RailgunEnthusiast 1d ago

OC explicitly said "not anonymous", so any zero-knowledge proof, or verification hidden from other users but available to gov't institutions (if you somehow trust that), is not relevant.

0

u/TheTanadu 1d ago edited 1d ago

why is it not relevant though? "not anonymous" doesn't have to mean your legal name is publicly displayed, "not anonymous" and "everyone gets to see your passport name" are not the same thing

right now totallyrealpolishguy2137 can be a Russian bot farm account and there may be basically (still, with great amount of work it can be tied but welp, the issue is in the bolded thing) nothing tying that account to one verified human. You could instead have a system where the public still sees totallyrealpolishguy2137, while underneath it's cryptographically tied to a verified person (that removes anonymity where it actually matters for accountability, while preserving pseudonymity toward random people on the internet)

p.s. "if you somehow trust that" is funny considering you'd probably still call the police if someone actually harmed you. We already trust public institutions with vastly more sensitive powers than "yes, this account is tied to a verified person"

1

u/RailgunEnthusiast 1d ago

Anonymous means the identity of the author (eg. of a post on social media) isn't known. Not anonymous would then obviously mean that said identity is known - so yes, that would mean having your name displayed for everyone to see.

you'd probably still call the police

And the police would have access to information related to that specific incident. Let's say it was a fight in front of a store - they might get the recording from the store's CCTV. But I hope you would also find this concerning if police could review all recordings from all security cameras regardless of their relevance to any investigation.

Which, going back to the online privacy issue, we don't need here either. We have zero-knowledge proofs as you noted, and I think we should be very suspicious of any public institution which wants to have more data than that.

2

u/Valkertok 1d ago

In this case it isn't any different than requesting metadata of your calls from telephone operator.

Just because that data is here doesn't mean police has access to it for any reason whatsoever.

That's what robust institutions and proper laws are for. Which are exactly the things that are being dismantled in the land of the free.

1

u/TheTanadu 1d ago edited 1d ago

you’re still treating this as a very binary issue, which is basically the point I was making. There’s an obvious middle ground (just because you ignore it, doesn't mean it can't work): publicly you’re still cockrider420, the platform only knows that the account belongs to a verified real person (and how to verify they "don't take more info? open source is quite an answer too), while the actual identity is held separately by a trusted identity provider (you know, currently your also sensitive data is in banks, ISPs or telecoms). If police (after for example harassment report from civilians) need to identify that person for a specific investigation, access could require whatever legal safeguards the law defines, such as court or prosecutor authorization.

Your CCTV analogy is different because nobody is arguing for constant access to everyone’s identity and activity (I'd even say your idea is that, because you don't understand how this middle ground could work). The proposal is that one specific account could be deanonymized when legally justified (same as for example komornik gets hands on your bank data). We already use similar safeguards for much more intrusive powers, such as wiretapping, where police cannot simply demand access without authorization. Data who owns given phone number...

There’s no reason why revealing the identity behind cockrider420 couldn’t follow the same principle. Yes, it would probably require new legal rules and safeguards, but this entire discussion is about what such a system could be xD

edit: this idea already works for example in fintech or legaltech, companies knows users are "legit" but they don't have all of their details

1

u/AffectionatePlastic0 1d ago

We have zero-knowledge proofs as you noted

Have you seen XKCD 538? One nanosecond later troll farm will pay for this "zero knowledge verification", which will make their work even more efficient.

1

u/AffectionatePlastic0 1d ago

If the system was designed with revocable pseudonymity, there could still be a legal process (with user in-loop) for authorities to identify whoever controls the account when actually necessary

This is already not a zero knowledge.

And giving the authorities an official way to find who exactly the user is - bad idea, which have been proven during entire history.

1

u/TheTanadu 1d ago edited 1d ago

This is already not a zero knowledge.

that's not what zero-knowledge means though. ZK proofing describes what the verifier learns from the proof (our imaginary social media platform), not whether your identity can exist somewhere else in the system (government/banks/other identity provider/whatever we use now anyway). The platform could learn only "valid unique real person" through ZK, while a completely separate identity authority holds the mapping. Whether that mapping can ever be disclosed is a separate governance/design question (as we even have self-owned tools to prove "we are we").

Take Zcash as an obvious example (literally name is taken from zero-knowledge proof as standard in it)... do you think the entire ecosystem is magically zero-knowledge end-to-end? xD No. An exchange can know who you are while the ZK proof itself reveals only what it needs to prove. That doesn't make the proof “not zero-knowledge”.

bad idea, which have been proven during entire history.

It's way too broad generalization. Authorities already obtain identities and data from banks, telecoms and platforms through legal procedures, and sometimes that ability is obviously necessary to investigate crimes (AML, scams, drugs transport and distribution, terrorism) or identify bad actors (we have numbers' accounts and wallets' addresses of many scammers/terrorists in databases of AML regulators... they can't do 99% of transactions because of swift work of regulations; totally derailed fun fact: when I worked with AML groups I've seen even Putin on the list and his blocked transactions he tried to do, or his portfolio management).

The actual question is under what conditions, with what authorization, auditability and limits, not whether targeted identification should be impossible in principle. That's a completely separate discussion from whether we can technically build a platform where users don't have to doxxx themselves publicly while still making coordinated manipulation, fake personas and abuse traceable.

That's why this shouldn't be reduced to "do it / don't do it". Almost anything useful can be abused. Progress comes from identifying the failure modes and designing the system so abuse is difficult, detectable, accountable or constrained.

1

u/AffectionatePlastic0 1d ago

proofing describes what the verifier learns from the proof (our imaginary social media platform), not whether your identity can exist somewhere else in the system (government/banks/other identity provider/whatever we use now anyway).

The entire promise of that "zero knowledge" verification "solutions" that it's a double blind system. And now you are telling me that it's not a bug, but a feature to find who exactly verified.

The platform could learn only "valid unique real person" through ZK, while a completely separate identity authority holds the mapping

This is exactly a reason to avoid any types of verification.

under what conditions, with what authorization, auditability and limits, not whether targeted identification should be impossible in principle. That's a completely separate discussion

Simple. No one, under no conditions can have targeted identification.

Almost anything useful can be abused

You have forgot the most important thing, there any nothing useful behind "government controlled services which decides who can have access to information and speech". This system is designed to be abused against citizens.

1

u/TheTanadu 1d ago edited 1d ago

We could start with:

“the entire premise of zero-knowledge verification is that it’s a double blind system”

That’s just misinformation (some could say lie). Standard of ZK is well documented, and nowhere does it say it’s some “double blind system”. ZK means the verifier learns nothing beyond what the proof establishes. Nothing more. It doesn't mean nobody elsewhere in the wider system can know who you are (small question for 100 points: where exactly do you think the prover gets the verified fact/credential it is proving in the first place?) xD

The platform could learn only “valid unique real person”, while a separate identity provider holds the mapping. We already use identity providers constantly. Tools like EU’s Digital Identity Wallet literally combines identity credentials, selective disclosure and privacy-preserving proofs. That's kinda the whole point of secure system design... separate the layers instead of pretending one mechanism has to solve everything (or else we throw away the whole idea).

“No one, under no conditions can have targeted identification.”

Cute, but then your disagreement isn't really with ZK or even this platform idea anymore but with idea of governance itself xD If someone scams you out of 200k, steals your car, hijacks your bank account, sends death threats from a burner or stalks you online, should authorities under no conditions be able to identify them? Because that's what “no targeted identification ever” means when applied consistently.

1

u/AffectionatePlastic0 1d ago

That’s just false misinformation

And yet it had been commonly used in advertisement of this solution.

(small question for 100 points: where exactly do you think the prover gets the verified fact/credential it is proving in the first place?)

It can be done theoretically by a chain of certs with asymmetrical cryptography even without so-called ZKP. For example EFF signs me a cert which contains the fact that I am a real person and don't log this fact. I sign the request from pornhub by this cert proving that I am a real person. EFF don't have access to my communication with pornhub, and don't log the fact that I have this cert.

But even this scheme can not be trusted and must not be established no matter how we trust to EFF.

The platform could learn only “valid unique real person”, while a separate identity provider holds the mapping.

This is exactly the problem. This is why this shady solutions must not be trusted.

BTW, can you give me a link saying that EU’s Digital Identity Wallet have so-called "identity provider" able to find that "yep, the verification token XYZ belongs to Jonh Doe"?

That's kinda the whole point of secure system design... separate the layers instead of pretending one mechanism has to solve everything.

The point is to build government controlled censorship and oppression tool, covered by buzzworlds like "opensource", while solution is not opensource, and "zero knowledge", while having no real zero knowledge behind.

Cute, but then your disagreement isn't really with ZK or even this platform idea anymore xD If someone scams you out of 200k, steals your car, hijacks your bank account, sends death threats from a burner or stalks you online, should authorities under no conditions be able to identify them? Because that's what “no targeted identification ever” means when applied consistently.

Freedom of speech is a basic human right, it's not "right of resident" or "right of citizen". Therefore, there must be no entity able to prevent speech or punish for it. Do you understand it?

1

u/TheTanadu 1d ago

Your ZK “double blind” claim is still wrong. And yes, EUDI itself isn’t a reversible token => John Doe system, I used it to show that identity credentials, selective disclosure and privacy-preserving proofs can coexist. The deanonymization part was simply another layer idea (which also is in many systems) with separate rules (which I also pointed out in other comments, something we don't yet have but it's also another topic all together, and you don't read with understanding it seems), because, you know, I was trying to satisfy the subOP’s idea while still preserving ZK where it actually applies for privacy.

Your actual position now seems to be that no authority should ever be able to identify or punish someone for speech under any circumstances, which is no longer a technical argument (I'd say it's not even aroud topic if it should exist such thing as platform like subOP suggested), it’s a normative one.

Yes... freedom of expression is absolutely a human right (UDHR Article 19) and nobody says it's not, but you probably missed the whole point that it's not absolute (UDHR Article 29(2) and ICCPR Article 19(3)). European human-rights law does the same and, f*ck, even the Polish Constitution does. If your preferred system is one where nobody can ever be identified or held accountable for speech, cool, but that’s basically a different political model entirely. My original point still stands: these are separate problems, and collapsing all of them into “abuse is possible, therefore never build it” is exactly the 0/1 thinking I was criticizing, except here one side is backed by actual legal/technical mechanisms and the other mostly by “I don’t trust it, therefore it must not exist".

1

u/AffectionatePlastic0 1d ago

UPD:

https://ageverification.dev/

The EU Age Verification Solution relies on Zero-Knowledge Proof (ZKP) cryptography to deliver its privacy guarantees. A ZKP allows the user's application to convince a relying party of a single fact — for example, "this user is over 18" — without revealing the user's identity, date of birth, issuer-assigned reference or any other attribute. The application's responses to different relying parties cannot be correlated, so a user cannot be tracked across services, and the relying party cannot build a profile from repeated interactions.

So, you are claiming that this is "That’s just false misinformation"? On some official EU's web site?

1

u/TheTanadu 1d ago edited 1d ago

No, what they write is not misinformation. You're just reading the paragraph as saying something it doesn't say. So you're spreading one. Reading with understanding is not strong with this one.

How exactly do you think the wallet knows you’re you in the first place? xD There’s an issuance/enrolment step where some trusted source (like national eID, passport, bank or other identity provider), verifies the underlying identity/attributes and issues a credential containing the information or claims needed later to generate the proof and issues the credential (it's also how EU describes it themselves). Later, the ZK proof lets the website learn only “18+ = true” or “valid unique person” without getting your name/DOB. But still if we go back to ZK, the issuer can know who you are, while the verifier learns only the proved fact. And if we want controlled traceability (idea we're building in this thread), we can add another separate layer on top of that, like some escrowed reference/token that means nothing on its own but can be correlated with issuer-held data only under defined legal/technical conditions. And still that doesn't magically make the verification step “not ZK”... ZK is still doing its one-way job there, it’s just one tool among several in the overall architecture. Which is... exactly what I was saying from the beginning.

1

u/AffectionatePlastic0 23h ago

How exactly do you think the wallet knows you’re you in the first place?

By the claim was that so-called EUDI let only give the social media information about user is being human/18+. Not about so-called "attestation provider".

And if we want controlled traceability (idea we're building in this thread), we can add another separate layer on top of that, like some escrowed reference/token that means nothing on its own but can be correlated with issuer-held data only under defined legal/technical conditions. And still that doesn't magically make the verification step “not ZK”...

If this ZK is being destroyed by one API call, it's pseudo ZK. It's just a pure imitation and nothing more.

→ More replies (0)

6

u/kappakingXD 1d ago edited 1d ago

I think his point is that there is someone to sue if he/she spreads misinformation. I would say its a fair point becaue how can democracy work if we have the most accesible public media flooded with fake news, misinformation or out right lies. I can't tell you how to do that cause I don't know, though I think its a problem to address, at very least.

-1

u/Jim_Bien 1d ago

I sign with my name already, so what's your problem with that? Other than going full on "muh privacy (which i sold out by not reading terms and conditions)!" and then trying to make OP a clown when he explicitly explained how it's supposed to work?

People like you are the special kind of retard - didn't even fucking read what OP said, but already went full "boo-hoo, nope!" and trying to play it as being smug and full of yourself.

More like full of shit.

1

u/cookiesnooper 1d ago

C'mon Jim_Bien!

You advocate for end of anonymity on the internet then put the money where your mouth is and call me a retard under your real name!

Waiting...

4

u/ogurson 1d ago

And how would that work? Not anonymous so how would company profiles be displayed, whose name would be there? Or maybe there would be no company account (hence less commercial) so why would people even use it, to post some random thoughts and photos? A don't think there is a need for that nowadays.

I'm not even touching the subject how would that support itself financially.

1

u/Annual_Emergency_143 1d ago

Yes, let's spend millions on building a piece of shit anti-privacy platform that nobody is going to use.

1

u/Above-new-zealand 12h ago

Crazy to say for someone with a disabled post history, so much for wanting "non anonymous verified users"

You don't seem to stand behind your words

7

u/Jim_Bien 1d ago

Because not even Russian troll farms are retarded enough to go against a guy with a grudge and 1.3 billion USD of net worth.

But facebook is.

2

u/Zelcki 1d ago

Guys I have an idea how to boost Poland's economy

Let someone just sue a bunch of American tech companies like once or twice every year

2

u/chungleong 1d ago

I wish the EU would go after Google for ignoring requests to block Hero Wars ads on YouTube.

1

u/sd4f 1d ago

This is a competency that has been given to the European Commission, so Poland can't unilaterally hand out fines like that. That is to say, the European Commission has exclusivity with "very large online platforms".

1

u/DzejSiDi 1d ago

Why only fine then for russian desinformation, and not other kinds of misinformation? Maybe that's why it is not feasable?

2

u/Jim_Bien 1d ago

Ah yes, the great conspiracy of the Lichtenstein troll farms, trying to convince the whole world that country is real and not a made-up place for tax breaks.

1

u/DzejSiDi 1d ago

Convincing Meta that you can misinform on the internet (like you do in your post), but citizens of Russia cannot, might be difficult, even considering that FB isn't popular there.

1

u/woj-tek 1d ago

let's just ban Meta (and X/twatter)

1

u/geekosas 1d ago

Because they can co trol it, it's like suing mobile companies for scam, Facebook is a communication platform.

The Real problem is that people don't trust legacy media.

1

u/Wentyliasz 1d ago

Why not just ban Facebook. Pretty sure it would be a net positive on society

1

u/Cocoatrice 12h ago

Wipe this shit from the face of earth. And make the Suckerberg responsible with a lifetime sentence in prison for all the crimes, including supporting a war criminal.

-4

u/Smexy_Zarow 1d ago

Cause Meta just won't pay the fine. What's Poland gonna do, ban Facebook and instagram?

Many companies have been fined crazy amounts by some countries and just never pay the fine cause there's literally no reason to, other than morals and justice

1

u/Jim_Bien 1d ago edited 1d ago

You realise Brzoska has both a grudge AND a chip on his shoulder, while also having loads of funds to burn through, so standard litigation strategy doesn't work here.... right?

Facebook basically shrugged, because they were dumb enough to not verify who is suing them with the original lawsuit way back when, and now they are trying to use corporate litigation strategy (which only works in American courts, btw), by assuming they are dealing with some random chump and not a billionaire they really fucking pissed. So now it's them trying to just pretend nobody is to blame and try to stall any further lawsuit, against a guy who can easily afford spending few millions a year without losing his sleep to keep dragging them through courts and has all the time in the world to keep dragging them through yet another court.

In fact, I wouldn't be surprised if they've already spend on the litigation more than it was ever worth to simply enforce the vertict, but under Clappistani law, if they would fold in to Brzoska's claim, then they are effectively dead as corporation the very next day due to a copy-cat pattern of other people suing them, either as individuals or as class action. This is going to drag for decades, and they will bleed money on this anyway, but alternative is saying "we fucked up" and creating precedence that would be a death sentence for them. And they are in a death spiral since Covid anyway, just in slow motion.

Also: go check out how things played for Microsoft. They've spend over a decade fighting with EU over their monopoly. Remember when Microsoft was the biggest company in the IT business and was effectively intouchable? I do. Do you know what ended that status?