Live data from Hacker News

Flattr now deletes your web browsing history within 3 months

ctrl.blog

81–90 of 98 posts

Re: Flattr now deletes your web browsing history within 3 months

#81

I feel like this whole thing with the GDPR is people fighting each other for the wrong reasons. The people for it argue that gets large companies to behave better. The people against it argue that it's unnecessarily complicated, poorly drafted and burdensome to small businesses. But it's both at the same time . The issue is that it doesn't have to be. It's possible to get the desired effect without using such a compl…

No, the point is that the cost of automating this should be part of the cost of doing the collection, not a separate item. If you can't afford to deal with the so-called "nightmare letter", then you can't afford to snoop.

The problem is there is no exception for companies whose business model isn't snooping.

Normal companies have customer lists, accounts receivable information, customer email addresses for password resets and announcements etc. A business can't stop keeping records of who owes them money. But then they're subject to regulations designed to make things difficult for the likes of Facebook and Microsoft.

Re: Flattr now deletes your web browsing history within 3 months

#82

Earlier quoted context omitted.

No, the point is that the cost of automating this should be part of the cost of doing the collection, not a separate item. If you can't afford to deal with the so-called "nightmare letter", then you can't afford to snoop.

The problem is there is no exception for companies whose business model isn't snooping. Normal companies have customer lists, accounts receivable information, customer email addresses for password resets and announcements etc. A business can't stop keeping records of who owes them money. But then they're subject to regulations designed to make things difficult for the likes of Facebook and Microsoft.

There is exceptions though, since this data is required. They just need to delete it, if they no longer have a reason to keep it.

Re: Flattr now deletes your web browsing history within 3 months

#83
post #13

I love how some of the tech industry is beginning to see data as a liability rather than an asset. It dramatically reduces the ability for government mass surveillance for two reasons: 1. If companies only collect what they need (to reduce their liability), governments can't demand more than that (or even hack in to get the data illegally). 2. If the industry culture is to limit data collection, governments can't jus…

> governments can't just say, "Well every company does it, so why can't we."

Odd. That's precisely what's happening with GDPR. While the EU governments are demanding that private companies limit collection and use of data, the intelligence arms of these same countries (I'm looking at you, GCHQ) and their FVEY partners are doing everything they can to hoover up and store every single bit of data on the world population, including their own citizens.

And somehow, we think this is fine. An entity with the power to disappear you and render you to black sites can have all the data on you they wish. But Facebook determining that there is an 83.7% chance you are stressed serving up an ad for vacation rentals is completely verboten.

It's absolutely mad.

Re: Flattr now deletes your web browsing history within 3 months

#84
post #16
post #12

"Ads on this site don’t track or stalk you. Please disable your blocker." According to my blocker those are Google ads so...

Google AdSense on Ctrl blog is configured to only show non-personalized ads to any users with the Do-Not-Track (DNT) setting enabled or European Economic Area (EEA) citizens. AdSense still uses cookies for rate-limiting and fraud prevention, but not ad personalization or tracking. requestNonPersonalizedAds=1 is part of AdSense’s GDPR APIs. https://www.ctrl.blog/entry/adsense-gdpr-consent You also only see that partic…

Wow, I never knew that was an option. Now I wish my adblocker gave the option of allowing those ads. That sounds like what I'd hoped AdBlocks's Acceptable Ads program would be.

Re: Flattr now deletes your web browsing history within 3 months

#85

Earlier quoted context omitted.

>GDPR doesn't in any way protect people from data leaks. Article 32: Security of processing Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measure…

I can't see how this protects people. You can evaluate risks all the time you want, but unless you have exceptional security team, you won't get your situation improved beyond what's already been established in the industry. Unless you think about companies leaving their databases facing the public without password - but then I still can't see how GDPR would help there. Requirements for post mortem actions are quite…

The criteria for when such a delay is undue in Germany ("ohne schuldhafte Verzoegerung"), is if it would have been within your power and not incurring gross risks/costs (unless it's your fault for creating a situation where there are gross risks/costs) to have done the required action at an earlier time. It is not undue delay if you needed to sleep, or if your ISP just cut you off and you need to go into the city and get some other ISP to get you a connection, but it is your fault if you then sit around for a month, waiting for the ISP to get it ready, without the ISP getting the connection up soon enough. They would require you to go to the city and get a permit to string fiber across from the next hub to your building, if there was no other way to get it done sooner, due to e.g. there not being anyone with free time to dig up the street and fix the cable, or whatever.

Re: Flattr now deletes your web browsing history within 3 months

#86
post #57
post #51

Earlier quoted context omitted.

However governments often have undisclosed access not even known to the holder of the information. I doubt GDPR will significantly affect information to which the government wants access Can I ask the government to delete all information on me?

There will undoubtedly be a lawsuit again soon over whether companies are allowed to transfer data out of the EU to US government warrantless requests.

I hope its Greece so we can all be as transparent as possible about the real issue here...

(Democracy)

Re: Flattr now deletes your web browsing history within 3 months

#87

I feel like this whole thing with the GDPR is people fighting each other for the wrong reasons. The people for it argue that gets large companies to behave better. The people against it argue that it's unnecessarily complicated, poorly drafted and burdensome to small businesses. But it's both at the same time . The issue is that it doesn't have to be. It's possible to get the desired effect without using such a compl…

>For example, one of the major burdens on small businesses is the cost of producing the data the company has on you -- but there is a simple way to fix that. Require the requester to pay the cost of collecting the information, similar to FOIA requests in the US. Then the requirement is no longer an unfunded mandate and can't be used by griefers as a method of harassment. If you can't cheaply and quickly respond to a…

> Being a small business doesn't give you the right to be negligent.

I can't understand this attitude that it's negligence to not want to be bankrupted by poorly crafted regulations.

We're dealing with things like a website to sell wood carvings that someone makes as a hobby. They've got names and addresses because they need to know where to ship them.

This is not a reasonable place to apply a complex regulatory framework. The idea that this involves "serious responsibility" or "grave risks" is akin to applying a regulatory framework designed for an oil refinery to a garage sale because a used lawnmower may contain some "hazardous" motor oil.

It's not that the danger isn't theoretically possible, it's that the regulatory requirements are totally inappropriate to the context.

Re: Flattr now deletes your web browsing history within 3 months

#88
post #73
post #71

Earlier quoted context omitted.

In the talk, there's a parallel drawn between the nuclear industry 60 years ago and big data now, where the nuclear was originally touted as a miracle cure for everything, then disasters happened, then it never really got over the stigma despite its huge potential. Society decided, for now, the upsides aren't worth the downsides. Oil is another parallel where society is currently just at the point where we are starti…

Seems like oil and nuclear energy are different because both can be replaced with alternative sources of energy. What are the alternative sources of user data?

Paper records, human memory....

Comparing growth in data storage versus energy usage per capita is interesting.

Even if you look back to the founding of the U.S., the change in energy use per person is actually only a few fold, definitely less than an order of magnitude.

Harder to compare quantity of data storage but the change would seem much larger. How much data is there, per U.S. person?

Re: Flattr now deletes your web browsing history within 3 months

#89
post #77
post #42

Earlier quoted context omitted.

That doesn't make any sense. The point of privacy badger is to prevent cookies that track you across different domains. Allowing tracking cookies just because a certain parameter is present is asking for abuse. If you are serious about not tracking people, don't use tracking cookies.

Cookies is just a tool it all comes down to how you use it. Not all knifes are stabbing-people-to-death knifes.

Privacy badger is quite specific in what it blocks. It blocks third party tracking cookies that track you across multiple domains.

First party cookies are no problem. Third party cookies that are only used in one domain are no problem. Third party non-tracking cookies are no problem.

So it does block the equivalent of bringing a large knife to a bar.

Re: Flattr now deletes your web browsing history within 3 months

#90

Earlier quoted context omitted.

>For example, one of the major burdens on small businesses is the cost of producing the data the company has on you -- but there is a simple way to fix that. Require the requester to pay the cost of collecting the information, similar to FOIA requests in the US. Then the requirement is no longer an unfunded mandate and can't be used by griefers as a method of harassment. If you can't cheaply and quickly respond to a…

> Being a small business doesn't give you the right to be negligent. I can't understand this attitude that it's negligence to not want to be bankrupted by poorly crafted regulations. We're dealing with things like a website to sell wood carvings that someone makes as a hobby. They've got names and addresses because they need to know where to ship them. This is not a reasonable place to apply a complex regulatory fram…

>This is not a reasonable place to apply a complex regulatory framework. The idea that this involves "serious responsibility" or "grave risks" is akin to applying a regulatory framework designed for an oil refinery to a garage sale because a used lawnmower may contain some "hazardous" motor oil.

You're subject to exactly the same regulations on health and safety and hazardous materials handling. The steps you need to take are smaller and simpler, because the scope of your activities are smaller and less hazardous. You're not allowed to take the guards off your machine tools or pour motor oil down the drain just because you're a small shop. Same with GDPR.

If you're a small company that sells wood carvings, you don't need to do very much to comply. If you're a small company that maintains a blacklist of construction workers, you're in deep trouble.

https://en.wikipedia.org/wiki/Consulting_Association

Post reply on HN