Live data from Hacker News

The GDPR blog post

medium.com

11–20 of 144 posts

Re: The GDPR blog post

#11
post #3

A popup (probably what used to be cookie warning) on Medium says: > Medium uses browser cookies to give you the best possible experience. To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy. I must agree to logging user data and sharing it with processors? EDIT: come to think of it, it might be a new, GDPR-specific, dark pattern. I can use the site w…

Nope, the site works fine if you disable cookies. Once Facebook and Google fail I'm sure they'll be next.

I didn't click "I Agree" anyway. If they processed the data, I guess they're in violation now.

That said, it's not the first time I've seen something like that this week. I wonder if some companies aren't simply testing if they can get away with it.

Re: The GDPR blog post

#12
post #3

A popup (probably what used to be cookie warning) on Medium says: > Medium uses browser cookies to give you the best possible experience. To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy. I must agree to logging user data and sharing it with processors? EDIT: come to think of it, it might be a new, GDPR-specific, dark pattern. I can use the site w…

I don't agree. What's the next step? Will they ban me? Is it my responsibility to reach out to them and tell them I disagree? Or am I just expected to never go to Medium again?

To be GDPR compliant, everything needs to be opt-in (except for the stuff that is critical to functionality). If you refuse to answer their questions, they need to assume that means "no". From this you can see that it's not your responsibility to tell them anything and you can still use their website just fine.

Re: The GDPR blog post

#14
post #6

I got a few dozen gdpr emails today, some from companies I didn't know existed. This law is a fantastic development for end users/consumers.

Yup. Today I opened my fridge wondering if I'll see a note about an updated privacy policy inside.

It's ironic seeing that the law was in power for the last 2 years, but companies woke up only last week. A lot of those mails are only information, with no (clearly marked) link to a consent panel, so I assume that me ignoring them means they won't be allowed to spam me anymore.

Re: The GDPR blog post

#16
post #3

A popup (probably what used to be cookie warning) on Medium says: > Medium uses browser cookies to give you the best possible experience. To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy. I must agree to logging user data and sharing it with processors? EDIT: come to think of it, it might be a new, GDPR-specific, dark pattern. I can use the site w…

Some complaints have been filed against Google and Facebook for this practice today:

http://www.bbc.com/news/technology-44252327

Re: The GDPR blog post

#17
post #2

Is there not any issue with having a hashed version of the email, given the entropy of an email address is quite small?

The practical entropy of email addresses is indeed pretty small, lots of them are going to be first.last@company.example and a bunch more end in gmail.com or another popular provider.

If you can accept some level of false positives you could make the hash too narrow to be able to usefully reverse it. For example if only sixty people will ever subscribe or refuse to subscribe,a 24-bit hash is plenty to reject mistaken attempts to subscriber somebody who doesn't want in, but good luck guessing which GMail user is "2ca24b".

Another problem is, what if the email address changes hands - maybe even the whole email domain changed ownership. You probably need a way for people to change their minds, as that then also covers the case where the person behind the address changed.

Re: The GDPR blog post

#19
post #6

I got a few dozen gdpr emails today, some from companies I didn't know existed. This law is a fantastic development for end users/consumers.

Yup. Today I opened my fridge wondering if I'll see a note about an updated privacy policy inside. It's ironic seeing that the law was in power for the last 2 years, but companies woke up only last week. A lot of those mails are only information, with no (clearly marked) link to a consent panel, so I assume that me ignoring them means they won't be allowed to spam me anymore.

That is implied in some of the e-mails - that is, they're asking you for explicit opt-in permission to keep mailing you. Mind you the old required 'unsubscribe' link was often adequate, but I don't mind this either.

The flood of emails is a nice reminder of how many services you're signed up with, too. Some even with multiple e-mail addresses.

Re: The GDPR blog post

#20

Earlier quoted context omitted.

Yup. Today I opened my fridge wondering if I'll see a note about an updated privacy policy inside. It's ironic seeing that the law was in power for the last 2 years, but companies woke up only last week. A lot of those mails are only information, with no (clearly marked) link to a consent panel, so I assume that me ignoring them means they won't be allowed to spam me anymore.

That is implied in some of the e-mails - that is, they're asking you for explicit opt-in permission to keep mailing you. Mind you the old required 'unsubscribe' link was often adequate, but I don't mind this either. The flood of emails is a nice reminder of how many services you're signed up with, too. Some even with multiple e-mail addresses.

I was particularly surprised seeing names I don't even recognize. Turns out that some of my one-off on-line purchases were handled by companies with names completely different than the names of the shops they put on-line.
Post reply on HN