W3C home > Mailing lists > Public > public-credentials@w3.org > January 2022

Re: Human rights perspective on W3C and IETF protocol interaction

From: Steve Capell <steve.capell@gmail.com>
Date: Wed, 5 Jan 2022 18:45:39 +1100
Message-Id: <44B4BCDF-BA5B-48C1-8A50-FDA494E6D455@gmail.com>
Cc: Adrian Gropper <agropper@healthurl.com>, GNAP Mailing List <txauth@ietf.org>, W3C Credentials Community Group <public-credentials@w3.org>
To: Bob Wyman <bob@wyman.us>
Good questions bob 

I don’t know the answer to them but suspect that UN charter is a good place to start 

All I want to say is that I’m with Adrian in principle.  I’m sure most of us are disappointed about what the web has become through selfish commercial and political interests that have centralised power into the hands of a few.  If any standards group is positioned to help fix that then surely it’s this group with its focus on decentralisation. 

I can imagine some kind of equivalent of the owasp top 10 for security - but focused on ensuring the rights of the individual are baked into the protocols and standards 


Steven Capell
Mob: 0410 437854

> On 5 Jan 2022, at 3:48 pm, Bob Wyman <bob@wyman.us> wrote:
> Adrian,
> Given that you're starting a new thread, I would appreciate it if you could do some context setting and clarifying:
> What do you mean by "Human Rights?" Hopefully, you won't consider that a foolish question. The issue is, of course, that since Internet standards are developed in a multicultural, multinational context, it isn't obvious, without reference to some external authority, what a standards group should classify as a human right. Different cultures and governments tend to differ on this subject... As far as I know, the "best" source of what might be considered a broad consensus definition of human rights is found in the UN's 1948 Universal Declaration of Human Rights (UDHR). 
> Does the UDHR contain the full set of rights that you think should be addressed by standards groups? If not, are there additional rights that you think should be considered? 
> In his document, Human Rights Are Not a Bug, Niels ten Oever refers to the UN Guiding Principles for Business and Human Rights, which adds to the rights enumerated in the UDHR a number of additional rights described in the International Labour Organization’s Declaration on Fundamental Principles and Rights at Work. Given that you appear to endorse ten Oever's report, do you also propose the same combined set of rights? (ie. UDHR + ILO DFPRW?)
> Some have argued that the Internet introduces a need to recognize rights that have not yet been enumerated either in the UDHR or in any other broadly accepted documents. If this is the case, how is a standards group to determine what set of rights they must respect?
> What specific aspects of the issues being addressed by this community group give rise to human rights issues? Also, if you accept that one or some number of documents contain a useful list of such rights, can you identify which specific, enumerated rights are at risk? (e.g. if the UDHR is the foundation text, then I assume privacy issues would probably be considered in the context of the UDHR's Article 12.)
> Are you suggesting that this group should formally address the issue of rights, with some sort of process, or just that we should be aware of the issues?
> ten Oever suggests that "Those who design, standardize, and maintain the infrastructure on which we run our information societies, should assess their actions, processes, and technologies on their societal impact." You apparently agree. Can you say how this should be done?
> The UN Guiding Principles for Business and Human Rights describe a number of procedural steps that should be taken by either governments or corporations. Are you aware of a similar procedural description that would apply to standards groups?
> I think it was in the video that it was suggested that, in Internet standards documents, "a section on human rights considerations should become as normal as one on security considerations." Do you agree? If so, can you suggest how such a section would be written?
> bob wyman
>> On Tue, Jan 4, 2022 at 9:05 PM Adrian Gropper <agropper@healthurl.com> wrote:
>> This is a new thread for a new year to inspire deeper cooperation between W3C and IETF. This is relevant to our formal objection issues in W3C DID as well as the harmonization of IETF SECEVENT DIDs and GNAP with ongoing protocol work in W3C and DIF.
>> The Ford Foundation paper attached provides the references. However, this thread should not be about governance philosophy but rather a focus on human rights as a design principle as we all work on protocols that will drive adoption of W3C VCs and DIDs at Internet scale.
>> https://redecentralize.org/redigest/2021/08/ says:
>>> Human rights are not a bug
>>> Decisions made by engineers in internet standards bodies (such as IETF and W3C) have a large influence on internet technology, which in turn influences people’s lives — people whose needs may or may not have been taken into account. In the report Human Rights Are Not a Bug (see also its launch event), Niels ten Oever asks “how internet governance processes could be updated to deeply embed the public interest in governance decisions and in decision-making culture”.
>>> “Internet governance organizations maintain a distinct governance philosophy: to be consensus-driven and resistant to centralized institutional authority over the internet. But these fundamental values have limitations that leave the public interest dangerously neglected in governance processes. In this consensus culture, the lack of institutional authority grants disproportionate power to the dominant corporate participants. While the governance bodies are open to non-industry members, they are essentially forums for voluntary industry self-regulation. Voices advocating for the public interest are at best limited and at worst absent.”
>>> The report describes how standards bodies, IETF in particular, focus narrowly on facilitating interconnection between systems, so that “many rights-related topics such as privacy, free expression or exclusion are deemed “too political””; this came hand in hand with the culture of techno-optimism:
>>> “There was a deeply entrenched assumption that the internet is an engine for good—that interconnection and rough consensus naturally promote democratization and that the open, distributed design of the network can by itself limit the concentration of power into oligopolies.
>>> This has not proved to be the case.”
>>> To improve internet governance, the report recommends involving all stakeholders in decision procedures, and adopting human rights impact assessments (a section on human rights considerations should become as normal as one on security considerations).
>>> The report only briefly touches what seems an important point: that existing governance bodies may become altogether irrelevant as both tech giants and governments move on without them:
>>> “Transnational corporations and governments have the power to drive internet infrastructure without the existing governance bodies, through new technologies that set de facto standards and laws that govern “at” the internet not “with” it.”
>>> How much would having more diverse stakeholders around the table help, when ultimately Google decides whether and how a standard will be implemented, or founds a ‘more effective’ standardisation body instead?
>> Our work over the next few months is unbelievably important,
>> - Adrian

Received on Wednesday, 5 January 2022 07:46:00 UTC

This archive was generated by hypermail 2.4.0 : Thursday, 24 March 2022 20:25:28 UTC