Live data from Hacker News

How Airlines don’t care about privacy: Case Study Emirates.com

medium.com

161–170 of 177 posts

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#161
post #147

Earlier quoted context omitted.

I'd say the more direct response is that with Wikipedia there is no product, in that sense of the word.

There most certainly IS a product! The only way I can imagine that you came to believe there wasn't is that you were confused by the fact that they give their product away. Does Encyclopedia Britannica's website "britannica.com" have a product? Is Encarta a product? Of course they are, and so is Wikipedia, unless BY DEFINITION you exclude any "product" not exchanged for money from the definition of "product". And by…

It's something that's produced, but not something sold (like Encarta). Accordingly you're right that it is a product.

In the informal sense in which we talk about users "being the product" I'd call it not quite right, since there's nothing sold. The user doesn't have to worry as much about ulterior motives.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#162
post #139

Earlier quoted context omitted.

Where they are based doesn't matter. If they are collecting revenues (taking payments) from EU clients, it applies. That includes generating ad revenues from EU based eyeballs. When it comes to on-ad-generating, free websites, it remains to be seen how bold EU regulators get. It'll be hard to penalize or prosecute such websites, and there are enough violations in the fat cats anyway, so I'm guessing those free websit…

> That includes generating ad revenues from EU based eyeballs. That would be fairly hard to enforce against a company that doesn't have a physical or legal presence in the EU. In general, I'm disturbed by governments trying to enforce laws beyond their border just because their citizens are somehow involved by sending information over the internet. In some fields, it's a legal minefield just to comply with the rules…

> In general, I'm disturbed by governments trying to enforce laws beyond their border just because their citizens are somehow involved by sending information over the internet.

Isn't it simple enough to geoblock areas if European customers are somehow too hard to serve?

> In some fields, it's a legal minefield just to comply with the rules of one country, much less several. This won't be a major difficulty for big players with high-paid lawyers and compliance departments, but it could easily kill startups, some before they're even launched.

As the topic is GDPR: a privacy first approach is not rocket science. I'm sure any startup with even the remotest chance of success can follow the basic principles without undue complications.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#163

Earlier quoted context omitted.

Well, the General Data Protection Regulation (GDPR) will become enforceable in May (for all people in the EU). As far as I understand, Emirates is risking big fines if they they don't fix this by May 25.

I can only hope for the EU that their economic incentive remains strong enough to prevent foreign companies from totally pulling out, resulting in the EU market becoming bleaker and bleaker. And it's not even the current companies that I worry most about - they often have already invested too much to withdraw because of this - it's the new companies that may flat out refuse to enter the EU market. The GDPR is yet ano…

> Note: I'm not saying Emirates will pull out because of this, they won't. I'm also NOT against the GDPR and I totally understand the need, I just wish it would be regulated on a more universal level. Same with copyright regulations.

What could be a more universal level than EU that could actually enforce something like GDPR? US is rather anti-privacy these days, which I found interesting as they are extremely individualistic at the same time. The only even remotely suitable body is WTO, and that won't happen.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#164

Earlier quoted context omitted.

Sounds like KLM: https://www.klm.com/travel/us_en/prepare_for_travel/on_board... This is on a strictly opt-in basis. I guess it's an interesting alternative to Tinder if you're going to be stuck on a plane. (Disclaimer: I've never tried it myself)

Apparently on Virgin Airlines there are chat rooms on the planes. Those have only two practical use cases: dating, and trolling: https://twitter.com/KrangTNelson/status/959907806622121984

Something people seem to miss every time this comes up.. every airline I've seen this on (Qantas, Emirates, Cathay Pacific, American Airlines, etc).. require you to enable receiving messages before someone can send you a message.

Thus you can't just randomly message any seat on the plane until they turn it on.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#165

Browsers need to take a hardline stance on external content and stop allowing pages to load anything whatsoever from external domains. But they won't, becuase one of them is Google.

I agree with your sentiment but this would break every website that uses a CDN for static assets.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#166
post #32

Earlier quoted context omitted.

All 142m Americans?

Yes: https://www.reuters.com/article/us-equifax-breach/equifax-fa...

"Yes" isn't a valid answer to the question. There are a lot more than 142 million US citizens.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#167

Browsers need to take a hardline stance on external content and stop allowing pages to load anything whatsoever from external domains. But they won't, becuase one of them is Google.

I agree with your sentiment but this would break every website that uses a CDN for static assets.

It would, that's the point. You'd give them time to fix it, like you give notice before visually indicating HTTP is insecure or deprecating SHA-1 certificates.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#168

Earlier quoted context omitted.

Well, the General Data Protection Regulation (GDPR) will become enforceable in May (for all people in the EU). As far as I understand, Emirates is risking big fines if they they don't fix this by May 25.

I can only hope for the EU that their economic incentive remains strong enough to prevent foreign companies from totally pulling out, resulting in the EU market becoming bleaker and bleaker. And it's not even the current companies that I worry most about - they often have already invested too much to withdraw because of this - it's the new companies that may flat out refuse to enter the EU market. The GDPR is yet ano…

GDPR concerns a human right (civil rights in USA-parlance). Are you stating that human rights are a nuisance?

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#169

Earlier quoted context omitted.

I can only hope for the EU that their economic incentive remains strong enough to prevent foreign companies from totally pulling out, resulting in the EU market becoming bleaker and bleaker. And it's not even the current companies that I worry most about - they often have already invested too much to withdraw because of this - it's the new companies that may flat out refuse to enter the EU market. The GDPR is yet ano…

GDPR concerns a human right ( civil rights in USA-parlance). Are you stating that human rights are a nuisance?

The preamble of the GDPR states that it regulates the fundamental right to privacy, not the human right to privacy. The human right to privacy is much lower level than the fundamental right to privacy.

To repeat myself: I'm [also] NOT against the GDPR and I totally understand the need, I just wish it would be regulated on a more universal level.

Re: How Airlines don’t care about privacy: Case Study Emirates.com

#170

Earlier quoted context omitted.

I can only hope for the EU that their economic incentive remains strong enough to prevent foreign companies from totally pulling out, resulting in the EU market becoming bleaker and bleaker. And it's not even the current companies that I worry most about - they often have already invested too much to withdraw because of this - it's the new companies that may flat out refuse to enter the EU market. The GDPR is yet ano…

> Note: I'm not saying Emirates will pull out because of this, they won't. I'm also NOT against the GDPR and I totally understand the need, I just wish it would be regulated on a more universal level. Same with copyright regulations. What could be a more universal level than EU that could actually enforce something like GDPR? US is rather anti-privacy these days, which I found interesting as they are extremely indivi…

Right, it's a universal regulation that applies to about 6% of the world population. But you make a good point, it is very hard to regulate this on a higher level. I'm just saying that the EU shouldn't expect every foreign company to accept and play by their rules, especially if it's only relevant to a fraction of their customers. What this may lead to is companies refusing to serve the EU and EU residents forced to resort to shady VPN companies to access their services - as they already do to circumvent copyright regulations - eventually resulting in less privacy and loss of VAT and other revenue for the EU.

Again, I do not want to paint an overly bleak picture - and I do support regulations like this one - but my feeling is that, due to the lack of a universal solution, this GDPR won't have a better fate than the current copyright regulations: beneficial for some, but at the cost of more internet fragmentation and discrimination. It's almost like lawmakers consistently forget that the internet doesn't stop at borders.

Post reply on HN