Live data from Hacker News

The European Union versus the Internet

stratechery.com

191–200 of 211 posts

Re: The European Union versus the Internet

#191

Earlier quoted context omitted.

No, since implicit consent is disallowed by the GDPR.

I'm a bit confused why the filter list's page says that then. I'm not sure why they need such a disclaimer, even if what it said was true.

The page is about the pre-GDPR cookie law, not about GDPR. Under the pre-GDPR cookie law, requiring an opt-out rather than an opt-in was allowed. Under GDPR, it is not.

Re: The European Union versus the Internet

#192
post #77

Earlier quoted context omitted.

A very American view! This just sort of proves the point the poster was making. People here don't assume that the worst case is going to happen. Most sorts of these laws so far result in initial action taken to help (or force) the company to comply. Fines are usually only considered for those who repeatedly refuse to come into line. My view of the US is that there are many more aggressive public prosecutors who will…

It isn't about assuming that the worst will always happen, it is just NOT assuming that the worst WON'T happen. How is that a bad thing to do? Pretending that the worst result couldn't happen is just delusional - it is like people who don't wear seat belts or helmets, or don't buy insurance. Just because something is unlikely doesn't mean you should ignore the risk, especially when the consequences of the unlikely ev…

If you are always going to assume that the worst case scenario might happen, you should probably worry about the things that will actually kill you, many of which are far more likely than getting the maximum fine as a small company that is not intentionally violating the law. Something like getting killed in a car crash is much more likely and much higher stakes.

Re: The European Union versus the Internet

#193
post #51
post #38

Earlier quoted context omitted.

I mean, the former attitude is known to be totally ineffective. The latter is possibly effective, at the cost of being (possibly?) extremely damaging.

I don't use any social media, how is that ineffective?

Unless every single person you know also strictly avoids social media, you are still getting tracked by social media companies.

Re: The European Union versus the Internet

#194

Earlier quoted context omitted.

I am not a lawyer, but GDPR explicitly covers the plugin pipelines - they're "processors". The requirements for processors are basically that you can only use processors that are compliant with GDPR themselves. Any well designed regulation disallows skirting liability by subcontracting out functionality. Is that really unreasonable? It describes pretty clearly how to be a compliant processor, and it's basically sayin…

> The requirements for processors are basically that you can only use processors that are compliant with GDPR themselves. How can you be sure that the compliance isn't just marketing? There is no official cert body or institution for GDPR afaik. Isn't it all trust based at this point? Actual certification would require a huge continous investment, where a outside body would constantly monitor and proof your code and…

From the link:

makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.

Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.

You can subcontract, in the same way that a any other business has to subcontract with businesses that obey relevant laws. They didn't ignore history or the present - they added new responsibilities to subcontractors, and described requirements for those contracts.

The subcontracting provisions I think are actually very reasonable and well defined. Things like the Right to be Forgotten have other issues around free speech, but the controller -> processor relationship seems pretty well specified.

Re: The European Union versus the Internet

#195
post #186

Earlier quoted context omitted.

Assuming a well-functioning democracy, they have whatever rights The populace wants them to have, including deciding what types of speech are acceptable.

>Assuming a well-functioning democracy, they have whatever rights The populace wants them to have, including deciding what types of speech are acceptable. So... mob rule. That seems like a very stable and restrained society. I can't think of any obvious problem with that, or any time in, say, German history (to name a particularly egregious example) where mob rule run amok destroyed most of the Continent. Or Russian…

While mob rule can be problem it has long been the 'democratic bogeyman' to justify why oligarchs and dictators must retain power even if what they want isn't remotely close to being unreasonable like not facing famine when it can be prevented. I'm not sure that decentralization works for stopping it - just limiting their demesne to one small town where you could be lynched instead of a whole country.

The system of constitutional rights of some sort has worked pretty well to excellent for limiting that purpose especially when combined with a judiciary willing to look ahead. The issue it helps prevent is the same as the mob rule example although it can also happen with more 'restrained mob rule' situations in a set up for a turnkey dictatorship that allows for absolute power in just a few steps.

The 'democratic institutions' and societal structure seems to be a factor of how resistant from degrading as well, how likely a transition to democracy is to stick and not have travesties in the attempt and how the aftermath of a dictatorship is handled. It would be interesting to see if there can be a good qualitative breakdown here as there are for signs of rising fascism and dictatorships.

Re: The European Union versus the Internet

#196
post #188
post #100

Earlier quoted context omitted.

Yea, I agree. AFAIK GDPR does explicitly legislate against all that - dialogues should be "opt-in" and should include a simple "no" option, and that sites shouldn't "ban" you for not clicking "yes". But unless EU actually starts delivering some hefty fines, the law is just a dead tree.

But if the site relies on cookies and localStorage and cannot work without it, "no" option is equivalent of "ban". And it's their computer that allows the usage of cookies and localstorage. All modern web browsers has an option to disable them. It's technically stupid.

> But if the site relies on cookies and localStorage and cannot work without it, "no" option is equivalent of "ban".

This - unless I misread it - is flat out wrong for most of the cookie warnings I see.

There's no valid reason for a news site to need cookies or similar except for logins.

It can be proved easily by wiping cookies and verifying the site still works.

Re: The European Union versus the Internet

#197
post #100

Earlier quoted context omitted.

Yea, I agree. AFAIK GDPR does explicitly legislate against all that - dialogues should be "opt-in" and should include a simple "no" option, and that sites shouldn't "ban" you for not clicking "yes". But unless EU actually starts delivering some hefty fines, the law is just a dead tree.

I think they're saying that a lot of sites use cookies instead of the web storage api to store the option on the dialog, meaning that even if the dialogue are opt-in, they won't work unless the user enables cookies. Basically a fundamental misunderstanding of the difference between cookies and local storage on the part of the web developers of many sites; i.e. cookies are sent with every request, whereas localstorage…

[deleted]

Re: The European Union versus the Internet

#198

Earlier quoted context omitted.

They don't run ads to generate revenue. Most content sites do.

You can definitely put ads without deep profiling. They can even be relevant. Just advertise for fishing accessories in fishing articles. Or hardware load balancers on Slashdot. Why not? Better than serving me whatever someone in my family has looked before (that is if I didn't have an adblocker for the past 10 tears)

Probably most content people read does not easily translate to a product as in your fishing example. Generally, ads with no targeting are not very profitable.

Re: The European Union versus the Internet

#199
post #174
post #160

Earlier quoted context omitted.

What? You can make money by charging people for it. Don't want to pay for newspapers for example? Without ads you can either pay up directly or not enjoy the publication. I don't understand where this entitlement for free stuff comes from.

I don't know why you think I was advocating for free stuff. I was not. I'm happy to pay for content I want. It's what time companies should be doing instead of not charging, tracking invasively, and selling user data. If you can convince people to pay for your content then the market is telling you you don't have a viable business.

I think the issue with GDPR is that you can't deny service if they don't want to pay and don't want to be tracked. Iow, you can't ask them to pay if they don't want to be tracked. That's where the complaint about demanding a free service comes from.

Re: The European Union versus the Internet

#200
post #198

Earlier quoted context omitted.

You can definitely put ads without deep profiling. They can even be relevant. Just advertise for fishing accessories in fishing articles. Or hardware load balancers on Slashdot. Why not? Better than serving me whatever someone in my family has looked before (that is if I didn't have an adblocker for the past 10 tears)

Probably most content people read does not easily translate to a product as in your fishing example. Generally, ads with no targeting are not very profitable.

My point was there can be targeting on content. Magazines have ads. Are they as profitable as privacy invading content ? Maybe not but they're tolerable.
Post reply on HN