Live data from Hacker News

How the GDPR Will Disrupt Google and Facebook

pagefair.com

281–290 of 362 posts

Re: How the GDPR Will Disrupt Google and Facebook

#281
post #217

Earlier quoted context omitted.

This makes me very nervous about data loss. If I accidentally wipe the hot database then I've effectively deleted all my backups. It also makes corporate ramsomware attacks much easier.

So keep a backup of your hot database in S3 or something, and make a workflow by which you can periodically update it. Or make a write-only backup of your encryption keys every day and only keep the backups for a week (or a month, or whatever the legal requirement is). Complying with this requirement will require us as an industry to make some changes to how we store user data. But the amount of work each company nee…

I don't mean this to come across as disparaging, but for people saying things along the lines of "Its a hassle, but no moreso than any other requirements we deal with on a daily basis.", I can't believe you have any experience with data recovery at a large company.

A fundamental axiom of data recovery is that you don't really ever "delete" anything, because accidentally losing data is considered such a horrible problem. So virtually all backup systems consider backups fundamentally immutable, because everyone knows how just one small bug in something designed to modify a backup could fuck the whole thing.

I don't really disagree with the spirit of the law, but I think the backups problem to honestly be pretty much a technical impossibility for large companies, it will basically just get ignored (the backups part at least).

Re: How the GDPR Will Disrupt Google and Facebook

#282
post #63

Earlier quoted context omitted.

> We as European businessmen were and still are unable to generate the same kind of innovation as the US Tracking people around the internet. To follow them everywhere they go and save their personal information, their political ideology, etc. It is not innovation, that's just stepping over personal rights. > I don't think it is about ethics, it is about control. Yes. About giving back control of citizen privacy to t…

>If you give away freedom for economic gain, you don't deserve either one. What gives you the right to deny others the right to trade their personal information as they see fit?

You make it sound as though the majority of Facebook users were making a conscious decision to trade personal information, whereas the usual thought process is "it's free! and everyone's doing it!".

Re: How the GDPR Will Disrupt Google and Facebook

#283

Earlier quoted context omitted.

This is very easy to work around. Associate each user with an encryption key and store in a separate database which backed up with some retention time. It shouldn't be huge so that's not a big problem. Encrypt all data related to the user with this key. When you make a backup, this data is stored in the same encrypted form. When you delete user, just delete his record together with this key. After this the user's dat…

Unless I'm misreading you, you've just created a more complicated version of things. How do you delete the immutably backed up keys? You've gone from: backup.bak to backup-encrypted.bak and backup-keys.bak

Obviously, you can't keep insisting on immutable backups. Instead, you'll have to modify a single key in the backup file to become invalid.

This does make your backups slightly less reliable, because it's one more thing that touches them, but if you do a sane implementation and exhaustively test it, the risk is manageable.

I'm also not sure you really need to keep that many backups of this file. Replicate it and make sure you can roll back when your replication is borked, but if you really need to restore your database from months ago, using a newer list of encryption keys shouldn't be a problem.

Re: How the GDPR Will Disrupt Google and Facebook

#284
post #200

Earlier quoted context omitted.

That's strange - so it doesn't protect the data EU citizens give out when using free services?

It does in most situations. For instance Facebook is free but Facebook still sells into the European markets and through that it triggers. Through either VAT registrations, B2B sales or any PE registration GDPR becomes a requirement.

So, to clarify, if I self-host services (e.g. XMPP or mail or Git repos) and I give user accounts to my friends (whom, like me, live in the EU) for free, I'm not subject to GDPR because I'm not a business?

Re: How the GDPR Will Disrupt Google and Facebook

#286

And if you think GDPR is a toothless joke, let's take a look at the defined fine stucture. It is pretty simple, only 3 levels (strikes for the fellow Americans): Strike 1 - Stern warning letter Strike 2 - 2% of your TOTAL GLOBAL REVENUE Strike 3 - 4% of your TOTAL GLOBAL REVENUE (or 20mil EUR, whichever is higher) And now you know why GDPR is a board level topic. Keep in mind that the EU/US Safe Harbor agreement got…

Throwaway account. I have national sales responsibilities for one of the majors. Think IBM/Microsoft/Oracle/etc leading a sales team of 74 reps. You'd be surprised at how LITTLE sales we've generated from GDPR. We've been providing free GDPR assessments for the past 1.5 years for over 200 accounts as lead gen opportunity and very little sales have resulted. It all boils down to companies simply don't believe the fine…

> It all boils down to companies simply don't believe the fines will be enforced given just how expensive the fines are.

It sounds like a goldmine for the EU government. If they install a group of people chasing for noncompliant companies, they will pay for themselves.

Re: How the GDPR Will Disrupt Google and Facebook

#287
post #277

Earlier quoted context omitted.

Throwaway account. I have national sales responsibilities for one of the majors. Think IBM/Microsoft/Oracle/etc leading a sales team of 74 reps. You'd be surprised at how LITTLE sales we've generated from GDPR. We've been providing free GDPR assessments for the past 1.5 years for over 200 accounts as lead gen opportunity and very little sales have resulted. It all boils down to companies simply don't believe the fine…

The fine doesn't absolve you of responsibility for complying. If you're fined you have to pay up AND you have to comply. Otherwise they'll just fine you again, as they did to Google.

Nevertheless, a 4% fine is very low, given the low frequency of fining. Tech firm margins are much larger than this; so while it's clearly unethical to do so, it may be more profitable to simply accept the fines as a kind of tax for as long as possible, and to continue to profit from all that data until things get really dire. In actuality; a firm wouldn't need to choose quite so starkly to flaunt the law; simply failing to invest and dragging your feet looking for impossible have-it-all solutions might well be enough to get away with a few fines until you really try to get your act together.

If you will; it's the difference between the VW approach and those of (as it appears anyhow) all the other carmakers. They're all cheating; most simply were wise enough to avoid doing so explicitly.

Data protection is also harder to enforce than emissions; and just look at how laughably incompetent emissions enforcement is to get an idea of how seriously you're likely to get caught if you happen to collect too much private information.

I expect the same here as in emissions: no real compliance for years (if not decades), and when enforcement comes, it won't be the regulator that actually catches even egregious wrong-doing. I mean; the high-profile players will play lip-service of course, but that's it.

Re: How the GDPR Will Disrupt Google and Facebook

#289

So, are ad clicks "personal data" ? That would basically destroy all adtech startups.

I'd imagine the host website needs to ask for the permission to share specific data with a third party named XYZ Startup, that will use that data for language/country segmentation or whatever is they do, and if the user denies that right then random ads are shown instead.

Re: How the GDPR Will Disrupt Google and Facebook

#290
post #275

> The critical question for both businesses is whether users will click “yes”, when asked to consent. Yes, users will click yes on basically anything. Facebook could put up a message that says "In order to proceed, click yes to give us half the money in your checking account" and the majority of Facebook users will still click through. Look at EU cookie warnings. Did any of those warnings noticeably impact anybody's…

Clicking yes might not even be necessary: I recently went to a laywer-oriented event (IANAL) that discussed the GDPR and it had a cheerful talk about "Alternatives to Consent" The talk listed all the possible ways the law allows you to store/manipulate user data without requiring explicit consent... There are a shocking number and iirc they apply basically whenever you have a direct consumer relationship with some co…

IANAL, just currently wading through GDPR material.

As I see it the most relevant processing conditions for companies offering a service and storing / processing data without gaining explicit consent are likely to be 6(1)(b) - Processing is necessary for the performance of a contract with the data subject or to take steps to enter into a contract 6(1)(c) - Processing is necessary for compliance with a legal obligation

My understanding is that these are far from a blank cheque to store / manipulate arbitrary personal information. Specifically, the storage and use of data in question must be provably fundamental to either provision of the relevant service in (b), or meeting legal obligations in (c).

So yes, a company providing you a service will gain the right to store certain customer details demonstrably necessary to provide that service - say hosting your email. It won't however allow arbitrary use of such data to e.g. provide targeted advertising, since such use is not fundamentally required for performance of the service. This would require a specific opt-in (and from what I recall, a failure to opt-in cannot interfere with the provision of said service - not so clear on this however).

Post reply on HN