Live data from Hacker News

USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

theregister.co.uk

141–150 of 231 posts

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#141
post #75

Earlier quoted context omitted.

> Erasing everything I ever wrote down about you is difficult. It is not difficult to avoid storing data you don't need. You don't need a user phone number? Easy, don't ask for it. Of course you argument is that it is difficult to change existing systems to follow this principle. Except that your starting position was that this regulation was about stifling competition, which is thus in direct contradition with this…

>It is not difficult to avoid storing data you don't need. Access logs for one thing are pretty unreasonable to force people to avoid storing. >Existing systems were built on the assumption that "misappropriating" PII was a lucrative thing to do. This led to abuse from the industry. Can you point out a specific example of somebody suffering actual damages from this "abuse?"

> Access logs for one thing are pretty unreasonable to force people to avoid storing.

Store them for a limited time, it's not hard.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#142
post #104
post #96

Earlier quoted context omitted.

Since when has more regulation translated in more entrepreneurship?

Currently, honest companies that respect the user's data cannot compete with companies that try to profit as much as possible from our it. I see this as similar to regulating pollution. Forbidding companies from cutting costs by polluting the air and the rivers allows for innovation and entrepreneurship in cleaner alternatives.

What? Apple's stance on user data privacy is a selling point in the market. They're not really hurting against other companies.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#143
post #96

Earlier quoted context omitted.

The hope is that in a new regulatory landscape we will see the emergence of new companies. Just because the tech unicorns of the last 10-15 years, like uber and facebook, were backed on odious behavior doesn't mean that a more palatable business model won't be discovered.

Since when has more regulation translated in more entrepreneurship?

I was thinking about this the other day. Didn't the HIPAA regulations create a whole new industry around the handling of patient records?

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#144

Earlier quoted context omitted.

Is it really so hard to believe that people are all out of trust and goodwill at this point? It’s like having a classroom full of toddlers who all play with matches, and every few weeks they burn the whole school down. Finally the teachers makes rule: no one gets to play with matches. A couple of kids say they’re very responsible and never set fire to anything. Nobody cares.

I could say the same thing in reverse about regulations. Every few weeks some regulation ruins the internet even more and finally people are sick of the regulations. Name one way your life was ever negatively impacted, in a concrete way and not just in your head, by companies using your data to create value in the form of targeted ads and such to keep websites free. I'm waiting.

Equifax breach and stolen identities? Cambridge Analytica and the 2016 US Presidential election? Ashley Madison and affairs being revealed?

We can go back and forth about the best way to deal with this, but it's crazy to think that this systemic gobbling up of personal data doesn't have real consequences.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#145
post #110
post #69

Earlier quoted context omitted.

What you don't realize is that the lawlessness around user data hurts big corporations too. If you're a big corporation collecting significant data than you've taken on a significant liability but the nature of this liability is amorphous. How much will it cost you if your data gets hacked? What will be the impact if you share the data with a partner and the partner gets hacked? How much can you share in your api? Wh…

> How much will it cost you if your data gets hacked? If I understand it correctly (IANAL), there are no penalties for getting hacked. Rather there are penalties for not having proper procedures for how to respond to a hack.

It depends what data you had; why you had it; whether you knew you had it; and how it was hacked.

https://ico.org.uk/about-the-ico/news-and-events/news-and-bl...

> The data was taken from an underlying customer database that was part of TalkTalk’s acquisition of Tiscali’s UK operations in 2009. The data was accessed through an attack on three vulnerable webpages within the inherited infrastructure. TalkTalk failed to properly scan this infrastructure for possible threats and so was unaware the vulnerable pages existed or that they enabled access to a database that held customer information.

> TalkTalk was not aware that the installed version of the database software was outdated and no longer supported by the provider. The company said it did not know at the time that the software was affected by a bug – for which a fix was available. The bug allowed the attacker to bypass access restrictions. Had it been fixed, this would not have been possible.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#146
post #75

Earlier quoted context omitted.

> Erasing everything I ever wrote down about you is difficult. It is not difficult to avoid storing data you don't need. You don't need a user phone number? Easy, don't ask for it. Of course you argument is that it is difficult to change existing systems to follow this principle. Except that your starting position was that this regulation was about stifling competition, which is thus in direct contradition with this…

>It is not difficult to avoid storing data you don't need. Access logs for one thing are pretty unreasonable to force people to avoid storing. >Existing systems were built on the assumption that "misappropriating" PII was a lucrative thing to do. This led to abuse from the industry. Can you point out a specific example of somebody suffering actual damages from this "abuse?"

Cambridge analytica is a good example. I guess considering this abuse may be different from a US customer point of view, but for my european sensibility, this is definitely abuse. Furthermore, that Facebook could harvest ghost profiles that could be used in this manner is problematic.

I think it is certainly possible to find cases of identity theft resulting from PII that were leaked in security breaches, made easier by overreaching data collection.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#147
I would like to see the US enact a law that says US companies must grant their users in the US all of the benefits that they grant their non-US users under non-US laws. So small US companies would still be able to avoid onerous non-US laws by not doing business in those countries, but the big ones, who can't afford to forgo the market in the rest of the world but who can afford to comply with the laws there, will. And their US users will reap the benefits.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#148

There has already been a lot of discussion about GDPR in the recent weeks, but one thing that shocked me is that the regulation is seriously described like this: From https://ico.org.uk/for-organisations/guide-to-the-general-da... : > The GDPR does not specify how to make a valid request. Therefore, an individual can make a subject access request to you verbally or in writing. It can also be made to any part of your…

Your customer service should know how to deal with product warranty. Or should be able to handle a request to cancel an online purchase for 14 days after the order ([1]). How is making a request to access your personal data different?

[1]: https://europa.eu/youreurope/citizens/consumers/shopping/gua...

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#149
post #96

Earlier quoted context omitted.

The hope is that in a new regulatory landscape we will see the emergence of new companies. Just because the tech unicorns of the last 10-15 years, like uber and facebook, were backed on odious behavior doesn't mean that a more palatable business model won't be discovered.

Since when has more regulation translated in more entrepreneurship?

Off the top of my head, Obamacare led to the founding of Zenefits and other companies in that industry.

The EPA's exhaust regulations in the 1970s arguably birthed the catalytic converter industry.

If the regulation is costly enough or introduces sufficient compliance risk, the rise of an industry to help companies comply with it is almost inevitable.

Re: USA needs law 'a lot like GDPR' says Salesforce CEO Marc Benioff

#150

Can we just take a step back and admit that treating an IP address as personal information is patently ridiculous?

Doubly so when legal precedent exists that IP isn’t sufficient enough to identify a person.

Maybe not to a "reasonable doubt" threshold, but it's a pretty strong identifier.
Post reply on HN