Live data from Hacker News

GDPR: Removing Monal from the EU

monal.im

381–390 of 957 posts

Re: GDPR: Removing Monal from the EU

#381

Earlier quoted context omitted.

Just curious (to you or anyone else affected), would you be willing to give up your rights under the GDPR, with regards to this company specifically, to regain access? Do you believe you should have a right to trade these rights of yours or is it in the general good that companies cannot offer an easy GDPR opt out?

If the result of the GDPR is that only big companies, employing as much lawyers as developers, will be able in the future to provide the tools I need, then yes I would be willing to give up my rights under the GDPR. Because what is the alternative, if all small messenger provider have to give up everybody will be using FB? Is that better for privacy then the current state?

> Because what is the alternative

Wouldn't a better alternative be to design a messenger that complies with GDPR? Simple user accounts that can be deleted at the request of the user, peer-to-peer encryption (and where possible, communication), a "storage cabinet" for each user where encrypted data end in when the user is offline (with an encryption/decryption key that is generated client-side and transmitted while both users communicate) and can easily be deleted and i think this covers most uses.

This is just an idea that i came up with right now, but if you start your design with the goal to store as little data as possible and anything you store needs to be both encrypted and easy to delete, then i believe you can come up with several ideas for most issues.

It also helps to see this as respecting the users' privacy and giving them control, as opposed to a development burden :-P.

Re: GDPR: Removing Monal from the EU

#382
post #355

While Monal is privacy focused, it is also free, open source and run by a single person — me. I simply do not have the resources or the time to jump through the regulatory hoops required by the EU. As a new and small construction company we simply don't have the resources to comply with all the building codes and the related paperwork. I just can't afford to meet all food safety requirements, I just want to provide f…

I made this software program that listens on a port on my computer, located in Springfield, IL, USA. I allow other people to connect to this program over the internet, which terminates at a connection I pay Comcast to provide me. I log their IP addresses (on my server that I own which resides in the United States) because I'm curious where my users are coming from. Someone from Europe is claiming that I owe them some…

>I wouldn't give away my personal observations stemming from something I did publicly and for free.

No, you'll just sell it to the highest bidder. And enough people do this in such an underhanded way that the EU decides to regulate the shit out of you. So maybe you should have asked permission before recording identifiable people's behavior or otherwise earned their trust. Instead of being shady and myopic about it.

Re: GDPR: Removing Monal from the EU

#383

This is a ridiculous over-reaction based on an extremely shallow interpretation of the GDPR. If you are running a small business and you feel that you won't be able to operate your business because of the GDPR consider all those other laws that you have to be in compliance with as well. If that's your attitude towards legal compliance then you should probably shut your business down completely rather than to hope tha…

Businesses hate regulation and uncertainty because it just adds to their costs. Large companies just eat the cost. For small businesses it’s practically impossible to be in compliance for all laws. But if the risk of not being compliant is too high and the reward is too low then they will choose this.

> For small businesses it’s practically impossible to be in compliance for all laws.

This is just ridiculous, patently false and making an excuse for reckless behaviour. Only specific laws apply to your business domain and if you aren't complying with them then you are wilfully breaking the law and putting your customers and the general public at risk.

Own a cafe ? You should be cooking in a safe manner. Sell a car ? It shouldn't kill people. Run a website ? Make sure your user's privacy is respected.

Re: GDPR: Removing Monal from the EU

#384

Earlier quoted context omitted.

TIL in some states they do emissions checks (although in a lot of states motorcycles are totally exempt from those anyway). And no, they don't do safety inspections of "specially constructed vehicles". And based on the ones I've seen, I can't imagine a world in which they'd pass. [1] [1] http://bosshoss.com/supersport-bike/

However, at least some states (probably most) require a minimum level of insurance from a carrier licensed in the state. There's nothing that requires those carriers to provide insurance to vehicles that don't meet their minimum requirements.

They vary wildly. Some states (washington used to be this way when I lived there) don't require insurance for motorcycles at all. But yeah, private companies can often make their own rules.

Re: GDPR: Removing Monal from the EU

#385

Earlier quoted context omitted.

> citation needed Every statement issued by EU regulators to date. > I have always been respectful and even never required emails on signups. Good. > I am not 95% there because there is a ton more to do. Such as? > In fact i am at 5% because i have a lot of small scale past projects. You've had two full years to get this done. The law came into effect the 14th of April 2016. It is now May 2018. > Not everyone is a VC…

> 95% Such as? Everything. Even if you process just an IP you need to document your procedures, change privacy policies. If at any point you ask for anything you need to implement opt ins, a way for (unauthenticated) users to request their data (even if it's just 1 IP) etc. My point is that having negligible private data is not less of a compliance burden than having a lot of private data. > You've had two full years…

> Even if you hold just an IP you need to document your procedures, change privacy policies.

So don't hold IPs if you can't be bothered to know where the might end up and if you don't want to update your privacy policy. Why would you?

> My point is that having negligible private data is no less compliance burden than having a lot of private data.

And no data means no compliance burden.

Note that holding data already has costs associated with it no matter what you do: you need to secure that data, you need to back it up, you need to process it and eventually you will need to get rid of it. All of those cost money and effort.

> You mean i ve had 2 years to attempt to interpret a vaguely written law.

As laws come the GDPR is surprisingly clear. I was quite skeptical until I actually got a copy of the draft and I was positively surprised. They actually got it mostly right, there are some minor things that I would have liked to see different but on the whole I am not complaining.

> Actionable information is just now coming out, and even that is contradictory (cue this topic).

The hysteria is ridiculous. Anybody that has spent even so much as a couple of hours on this subject - and from a somewhat serious point of view rather than the ridiculous fear mongering - knows enough to not have written a silly blog post like the one on display here.

> Even the EU parliament's website does not comply yet.

That article was not exactly enlightened to put it mildly.

> First, that is a directive, not a law and compliance can vary widely.

Yes, but if you did take it serious then you are well underway.

> Second, gdpr requires new procedures which means it requires amendments anyway

Yes, there is some overhead. But this is mostly to ensure that the law will not be ignored like what happened with the DPD. As you say 'it was a directive' which many companies interpreted as 'can be ignored'. What they failed to realize is that if you don't self regulate after a directive is issued that there will be a version of the directive with teeth that has the strength of law. Congratulations, we are there.

Re: GDPR: Removing Monal from the EU

#387
post #295

Every time something like this comes up, we see similar objections. They normally take one of three forms: 1) You are overreacting. The EU isn't going to come after some small fry operation, or some non-business entity. This is an easy thing to say when you're not personally exposed to the risk. Would advocates of this position be willing to personally indemnify open source projects / side projects against GDPR enfor…

"Even if I had the desire to read through the law (I don't)" "If such a set of instructions exists, I haven't seen it" https://gdpr-info.eu/ Maybe for me it is easy set of instructions, for some maybe not.

[deleted]

Re: GDPR: Removing Monal from the EU

#388
post #237

Earlier quoted context omitted.

>We sleep-walked into a society where the expectation is that any and all data is scooped up and sent off remotely without adequate controls We used to live in a society where webmasters' rights to the fruits of their labor weren't trampled on by inane regulation (to this degree at least). Now if you run a website in the EU, any user who signs up to it has control over the contents of your servers and you have to ask…

I find your view very interesting. You have a very capitalist and US law based perspective on it. For one, not everything in a society needs to allow to "collect the fruits" of individual work (which is essentially capitalism). Europe has much more socialism mixed into their understanding of their societies than the US. Further, the US law is based on risks of heavy punishments but few regulations, while the law in m…

Please don't just say this is a US perspective. This is a sociopaths perspective that the current US legal system promotes due to the machinations of the same group of sociopaths.

Every business owner here who would complain about how the GPDR is taking their rights to their personally earned data away would be the same people who launch a lawsuit because one of their competitior's products had a typeface that was vaguely similar to theirs

There are regular people here, they just don't go starting businesses that have abusing their customers as a business model because they couldn't sleep at night if they did that

Re: GDPR: Removing Monal from the EU

#389
post #28

Earlier quoted context omitted.

Yeah, they are over-reacting. For example, IP addresses are considered personal information but what that means is you just can't blindly collect them. If the service you use relies on IP addresses as a basic point of operation then its fine. CDNs aren't going out of business for example.

> that means is you just can't blindly collect them Genuinely curious, what about all of the web servers that log every request which usually by default includes the client IP? Not doing anything special with the IP, they are just there in log files and archives.

`tail /var/log/nginx/access.log` Oops.

Also the section of the GDPR that talks about pseudonymization using a token how should my user DB table be GDPR compliant? Contains ID (primary key), username, password hash, email, etc and the ID is also in other DB tables for obvious reasons (such as user posts/actions).

Re: GDPR: Removing Monal from the EU

#390
post #5

There is so much misconception about GDPR. It is cleary directed at large data-tracking corps, not single person IM apps. Even if someone tries to "sue" you (which he can't, only report you to authorities), it first needs to go through many iterations where you can make your case. At the very least read this: https://privacylawblog.fieldfisher.com/2016/what-you-think-y...

> you can make your case What if you don't want to deal with any of that. You can no longer just create some useful, free service and make it public.Heck, I don't even like having to be familiar with software licensing just to add something in Github.

"What if you don't want to deal with any of that."

What if you don't want to deal with the rules of the road?

Post reply on HN