Live data from Hacker News

The GDPR blog post

medium.com

61–70 of 144 posts

Re: The GDPR blog post

#61

Earlier quoted context omitted.

The problem is identification of physical persons. Your e-mail is public, but it also identifies you as a person. This is important, because it allows for correlating different data sets. Touch Surgery sounds like a honest company, so for them this was just some extra burden. But the same law prevents ShadyAdtechCo from getting datasets from several companies and joining them on e-mail column to build a profile of yo…

Wouldn't then a hash of your email also identify you as a person? The companies can still build a profile of you if they just agree to use the same hashing function :/

IANAL, but specifying how you hash the e-mails (algorithm + salt generation) would be part of your GDPR compliance process.

Re: The GDPR blog post

#62

So far I have received over 300 GDPR emails. When I am supposed to read all this? How do I track it? How can I track what each company stores about me? Do I feel this in any way improved safety of my data? I don't think so.

In theory, if you don't reply, all these companies should stop using your data and quite likely delete it. Sounds like improving safety for me.

Re: The GDPR blog post

#63

Earlier quoted context omitted.

What if someone else registered using his email (some websites for example don't send confirmation email if you change it in your profile or add additional email) or leaked data is fake? How that protects him?

You can't store the e-mail address without consent, and getting consent would probably involve sending a confirmation email.

But providing an email so it can be associated with your profile implies giving consent, as you don't have to do that.

Re: The GDPR blog post

#64

Earlier quoted context omitted.

The problem is identification of physical persons. Your e-mail is public, but it also identifies you as a person. This is important, because it allows for correlating different data sets. Touch Surgery sounds like a honest company, so for them this was just some extra burden. But the same law prevents ShadyAdtechCo from getting datasets from several companies and joining them on e-mail column to build a profile of yo…

Wouldn't then a hash of your email also identify you as a person? The companies can still build a profile of you if they just agree to use the same hashing function :/

We'll have to wait til someone got sued into oblivion before we know that

Re: The GDPR blog post

#65
post #60

Earlier quoted context omitted.

Wouldn't then a hash of your email also identify you as a person? The companies can still build a profile of you if they just agree to use the same hashing function :/

Or even if ShadyAdtechCo just knows what the hashing function is, and has a list of plaintext email addresses to test against – perhaps obtained from one of the datasets they're joining against, or even from crawling the web.

Hashing should be done with salt for precisely that reason.

Re: The GDPR blog post

#66
post #6

I got a few dozen gdpr emails today, some from companies I didn't know existed. This law is a fantastic development for end users/consumers.

To be honest, I thought most companies just took it as an excuse to send me one final piece of spam.

Re: The GDPR blog post

#67

"To make Medium work, we log user data and share it with processors. To use Medium, you must agree to our Privacy Policy, including cookie policy." No Medium, I must NOT agree to your privacy policy and your cookie policy, because to use and share my data you need my FREE consent. AND you can NOT deny me reading an article without giving consent, because then the consent is not FREE, and it is NOT strictly necessary…

Why is it a problem that you have to agree to be monetized to read a stupid blog post? If you don't like those terms, go read something else. If you refuse their terms, it seems obvious to me that they should be able to refuse to serve you. Maybe I'm missing something here, but this sounds like asking for a free lunch.

Re: The GDPR blog post

#68
post #64

Earlier quoted context omitted.

Wouldn't then a hash of your email also identify you as a person? The companies can still build a profile of you if they just agree to use the same hashing function :/

We'll have to wait til someone got sued into oblivion before we know that

Noone will get sued under the GDPR. That's not how it works.

Re: The GDPR blog post

#69
post #6

I got a few dozen gdpr emails today, some from companies I didn't know existed. This law is a fantastic development for end users/consumers.

Yup. Today I opened my fridge wondering if I'll see a note about an updated privacy policy inside. It's ironic seeing that the law was in power for the last 2 years, but companies woke up only last week. A lot of those mails are only information, with no (clearly marked) link to a consent panel, so I assume that me ignoring them means they won't be allowed to spam me anymore.

[deleted]

Re: The GDPR blog post

#70

Earlier quoted context omitted.

Yup. Today I opened my fridge wondering if I'll see a note about an updated privacy policy inside. It's ironic seeing that the law was in power for the last 2 years, but companies woke up only last week. A lot of those mails are only information, with no (clearly marked) link to a consent panel, so I assume that me ignoring them means they won't be allowed to spam me anymore.

If you're in the US, it's often not a bad bet to backburner compliance with ill-conceived, fuzzily-defined law that is going into effect 2+ years in the future. Chance are good that a new crop of House of Representatives members will have been voted in during the intervening time, possibly flopping the majority, and the provisions of the statute in question will either be reversed, endlessly delayed, or mangled out o…

We have a ton more parties and the majority are not religiously/fanatically opposed to each other. Also, they tend to shift over time, nobody battens down the hatches as the Democrats or the Republicans do. They have to be flexible to survive.

In the US one of the sides could start killing people in the street and they'd still end up in Congress...

What this means is that for many topics it's easier to reach consensus and the opposing party, now in power, is much more likely to continue a policy the general population likes.

Post reply on HN