Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

451–460 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#451
post #244
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

I don't get the complaints about how hard GDPR is and having to understand it all. If you're based in the US, have you read the actual DMCA document? CFAA? California S.B. 1386? TWEA? ADA? Or at least any interpretations of them and validated that you comply?

If not, then worrying about GDPR which is mostly not enforceable in the US sounds disingenuous.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#452
post #429
post #244

Earlier quoted context omitted.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

> A College student working on a side project with no revenue are treated the same as some massive multi-national. Am I reading this wrong? If the college student creates just a simple page, he/she is already complaint with GDPR. If the student starts collecting personal information, then they need to know what's allowed or not. There are already things that are not legal to do, GDPR just adds private information int…

Web servers are non-compliant out of the box because they all by default log and store IP addresses of visitors.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#453
post #387

Earlier quoted context omitted.

What does it mean for a website to "cater" to just my home country? The internet doesn't know political boundaries and most sites cater to all visitors on some marginal level.

Most websites are products nowadays. If you have a simple blog without trackers and ads this is really not going to effect you that much. > The internet doesn't know political boundaries Tell that to this US law the whole world has to comply with to called DMCA.

> Tell that to this US law the whole world has to comply to called DMCA.

If a site has no US presence and blocks all users in the US, what negative repercussion can violating the DMCA incur? Maybe their domain can be siezed, but that can be avoided by not having a domain hosted in the US. The US could block all traffic to the site, but that should be moot if the site has no US users.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#454
post #429
post #244

Earlier quoted context omitted.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

> A College student working on a side project with no revenue are treated the same as some massive multi-national. Am I reading this wrong? If the college student creates just a simple page, he/she is already complaint with GDPR. If the student starts collecting personal information, then they need to know what's allowed or not. There are already things that are not legal to do, GDPR just adds private information int…

If a kid makes a meme generator site where you can create a profile and organize your dank memes, then now they have to have a data protection officer, build a system to purge user data, and build a system to get user consent, etc.

I can easily see small websites just ignoring GDPR and hoping they fly under the radar. Or, using something like this Cloudflare configuration to block all EU users until they reach a size where achieving GDPR compliance is feasible and worth the effort.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#455

My biggest _annoyance_ with GDPR and its advocates is the constant touting of "giving users control over their data" when in reality it is hindering voluntary actions that by their nature require some of "my data". If I want to service a small group of people with, say, an XMPP network, and those users are willing and eager to just go with it without any of this bs with terms and three-letter EU dictated roles, then…

I don't think it applies to individuals and noncommercial activity, though I have heard anecdotal reports of european cops hassling people shooting pictures on mobile phones

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#456
post #244
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

> " It's a foreign requirement that feels like a violation of sovereignty."

How about you look at what bs comes out of the US gov't? That is the worst foreign requirement and violation of sovereignty so far, and it keeps on giving.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#457
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

[deleted]

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#458

My biggest _annoyance_ with GDPR and its advocates is the constant touting of "giving users control over their data" when in reality it is hindering voluntary actions that by their nature require some of "my data". If I want to service a small group of people with, say, an XMPP network, and those users are willing and eager to just go with it without any of this bs with terms and three-letter EU dictated roles, then…

It hinders nothing. It ensures that what you're with user data doing is truly voluntary and that your users really are 'willing and eager" about it beyond you pinky-swearing you'll be good with what you're given.

Be annoyed all you want, the only people whining about the GDPR are those showing their true colors when it comes to user privacy and agency. If you're complaining that it hinders you from using user data as you please, that's precisely the point.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#459
Funny that that site announces it's using cookies in a pop-up that blocks much of the text before a click, per another EU reg.

Not that we got the best UX from that one, where I'm constantly reminded cookies are a thing, via a large blocking box requiring user interaction, like a pop-up ad for something I already know and can totally control on my end.

There's a saying about how internet considers censorship damage and routes around it? Maybe better: the internet considers regulations information, and anycasts them, regardless of their quality.

China's a bit of a counterexample. Maybe the firewall is bidirectional, keeps democracy out and censorship in?

Maybe that's the endgame, balkanization. Some people will get to live under paternalistic maximalism, some under authoritarians hunting dissidents, some under anarchocapitalism, all dystopias in their own special way. And some of us will flee to Tor and .onion sites and encrypted signatures where we manage our own privacy and prevent third parties from auditing our communications.

Edit, "brevity."

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#460
post #429

Earlier quoted context omitted.

> A College student working on a side project with no revenue are treated the same as some massive multi-national. Am I reading this wrong? If the college student creates just a simple page, he/she is already complaint with GDPR. If the student starts collecting personal information, then they need to know what's allowed or not. There are already things that are not legal to do, GDPR just adds private information int…

Web servers are non-compliant out of the box because they all by default log and store IP addresses of visitors.

There is nothing non-compliant about that. You seem to misunderstand essential vs. data hoarding for advertisement purposes. If you were to keep that data forever, sell it to third parties or profile users based on that logging data, not tell them about it, then yeah, you'd be violating the GDPR.

For normal operation system logging is pretty much a requirement for essential operation. That includes most properties of a connection like IP, UA, date, time, URI etc.

Post reply on HN