Live data from Hacker News

GDPR for lazy people: Block all European users with Cloudflare Workers

apility.io

471–480 of 1001 posts

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#471
post #244
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

>1) A College student working on a side project with no revenue are treated the same as some massive multi-national.

If the side project uses personal user data, then there is no reason to treat them differently.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#472
post #301

Earlier quoted context omitted.

> A College student working on a side project with no revenue are treated the same as some massive multi-national. And why not? The result/harm is the same. It doesn't matter a bit whether a company's web site is handing its visitors' data over to Facebook or a "private site" does. The side project or the private site always have the option of not participating in the adtech frenzy. But of course they want to partici…

No, it's not the same. The lack of proportionality is precisely why the UK/EU is such a hard place to conduct business. These rules don't stop anything about ads, they just make them less targeted. Not a big deal, but it will increase the costs of serving users and thus decrease the total amount of commercial projects started.

> UK/EU is such a hard place to conduct business

is it though? According to https://en.wikipedia.org/wiki/Ease_of_doing_business_index#R...

USA is 3 positions behind Denmark which is in EU, and just one ahead of UK.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#473

My biggest _annoyance_ with GDPR and its advocates is the constant touting of "giving users control over their data" when in reality it is hindering voluntary actions that by their nature require some of "my data". If I want to service a small group of people with, say, an XMPP network, and those users are willing and eager to just go with it without any of this bs with terms and three-letter EU dictated roles, then…

GDPR is simply a response to abusive behavior. May not be the best response, but it was about time.

Then, it is surprising to me that Americans are against a national id card, but are not OK with a privacy protection law.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#474
post #198
post #53

I keep seeing these posts on how to block European users to avoid the GDPR. As a citizen of Europe, seeing these posts consistently making it to the front page is disappointing. It would seem that Silicon Valley perceives the GDPR as more of a hindrance than an opportunity to offer users better privacy. Nothing has been learned.

> Nothing has been learned. I don't know about you, but I have learned a great deal! I've mostly learned that Eurocrats can't actually write useful regulation. Blah blah blah human rights blah blah reasonable measures. Next chapter. Blah blah envisage blah blah reasonable measures. Blah blah blah inter-government communications protocols blah blah codes of conduct. What's a reasonable measure? How do I know if I'm co…

>How do I know if a vendor is compliant? //

Did they ask for explicit permission to use your data? Do they provide the service if you only provide the data they actually need, rather than asking for a swathe of PII so they can sell it on? Do they provide info on how your data is stored, and who has access to it? Do they provide a way for you to view and/or delete all the PII they have on you?

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#475

My biggest _annoyance_ with GDPR and its advocates is the constant touting of "giving users control over their data" when in reality it is hindering voluntary actions that by their nature require some of "my data". If I want to service a small group of people with, say, an XMPP network, and those users are willing and eager to just go with it without any of this bs with terms and three-letter EU dictated roles, then…

I don't think it applies to individuals and noncommercial activity, though I have heard anecdotal reports of european cops hassling people shooting pictures on mobile phones

> I don't think it applies to individuals and noncommercial activity

Why would these be unaffected? You have to comply with GDPR as soon as you start processing personal data.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#476

Earlier quoted context omitted.

Web servers are non-compliant out of the box because they all by default log and store IP addresses of visitors.

There is nothing non-compliant about that. You seem to misunderstand essential vs. data hoarding for advertisement purposes. If you were to keep that data forever, sell it to third parties or profile users based on that logging data, not tell them about it, then yeah, you'd be violating the GDPR. For normal operation system logging is pretty much a requirement for essential operation. That includes most properties of…

Which is the answer I see all of 50% of the time. Then, I see "Well, actually it is non-compliant because yadda yadda". My company isn't going to hire international compliance experts to review the operations of every public website we run, and we don't have any that need European visitors. So, best to just block them.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#477
post #198

Earlier quoted context omitted.

> Nothing has been learned. I don't know about you, but I have learned a great deal! I've mostly learned that Eurocrats can't actually write useful regulation. Blah blah blah human rights blah blah reasonable measures. Next chapter. Blah blah envisage blah blah reasonable measures. Blah blah blah inter-government communications protocols blah blah codes of conduct. What's a reasonable measure? How do I know if I'm co…

>How do I know if a vendor is compliant? // Did they ask for explicit permission to use your data? Do they provide the service if you only provide the data they actually need, rather than asking for a swathe of PII so they can sell it on? Do they provide info on how your data is stored, and who has access to it? Do they provide a way for you to view and/or delete all the PII they have on you?

You're right! Those are all critically important questions to ask! It's just possible that they might not be completely exhaustive, though.

Do they take reasonable measures to detect and inform me of a breach? Do they take reasonable measures to ensure it's me requesting data being deleted? Can they provide the same data about all Data Processors they make use of?

It's possible that the answers to this might not be easily and readily answered in every single potential case one might encounter when dealing with specialist vendors.

You're completely right to spell out those questions. It's just possible that there may be more to GDPR compliance - and certainty - than that in some cases.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#478
post #461
post #244

Earlier quoted context omitted.

I feel the EU regulators could stand to learn something. If EU citizens are small portion of your users, and your tasked with parsing this document http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX... just blocking them doesn't seem like that bad of an idea, especially with the fines involved. I think the things that bother me is: 1) A College student working on a side project with no revenue are treated t…

1. when you open a restaurant nobody cares you're a collage student. You have to have all the checks and permits to serve people food. It's not because somebody hates small businesses, it's because the right not to be poisoned is more important than the right to do business hassle-free. Why should internet be different? 2. Fuck your souvereignty. Seriously. USA has no problem violating secrecy of correspondency world…

Equivocating mishandling user data on a project that some kid in a dorm made for fun, which collects maybe an email address. With putting someone in the hospital with food poisoning is beyond a dishonest comparison.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#479
I’ve been reading hacker news for about a decade, and it’s getting to the point where I don’t think there are many entrepreneurs and/or technical people on here anymore.

The number of people who are saying it’s no big deal to comply with this huge law, especially for very small startups, is mind boggling.

Let’s just take one feature: the requirement that you can permanently delete all of your information. Most early-stage startups use the (in 2008, when I did mine) best practice of “delete=1”. Changing your whole database over to permanent cascade delete is only easy if you’re a very experienced programmer or who knows what he’s doing. And that sets aside the fact that even if you know what you’re doing technically, there are lots of business logic problems with just deleting things out of the database and anonymizing users is very tricky.

I was not a great programmer when I started my first startup. I was learning as I went along.

We couldn’t afford a lawyer, and the amount of time for me (the only programmer) to go through and read all the regulations and make all the requisite changes in the product I would estimate might take on the order of a month or two, which if timed poorly would’ve killed our company. I say again: at an early stage startup with one programmer, you cannot have that one programmer spending two months on compliance.

It’s just gotten to the point that there’s one comment after another responding to this regulation or that regulation or this situation or whatever with “well, just call HR“, or “I can’t believe you don’t have a company policy for that!”

Or “well just ask your lawyers“. It ain’t that easy. Do you have any idea how much it would cost to have “your lawyers” go through the GDPR, tell you what you need to do, and deal with all of the edge cases and gray areas? $20k or $30k doesn’t seem too high.

My biggest fear is that all of these complex bureaucratic laws are just raising the bar for doing a startup. Maybe the days of two people doing a startup in someone’s garage should be in the past? If so, that makes me kind of sad.

Regardless it’s not obvious that GDPR is the right policy or that it’s well designed or clear.

Re: GDPR for lazy people: Block all European users with Cloudflare Workers

#480

My biggest _annoyance_ with GDPR and its advocates is the constant touting of "giving users control over their data" when in reality it is hindering voluntary actions that by their nature require some of "my data". If I want to service a small group of people with, say, an XMPP network, and those users are willing and eager to just go with it without any of this bs with terms and three-letter EU dictated roles, then…

The processing of personal data should be designed to serve mankind. The right to the protection of personal data is not an absolute right; it must be considered in relation to its function in society and be balanced against other fundamental rights, in accordance with the principle of proportionality. This Regulation respects all fundamental rights and observes the freedoms and principles recognised in the Charter a…

This basically boils down to, "just hope that all current and future EU member nation agree with you on what is and isn't morally right."

Good thing different societies and cultures have never disagreed on what is and isn't morally just, amirite?

Post reply on HN