Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

31–40 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#31
It's somewhat amusing watching the overt rhetoric of advocating for data privacy enforced by governments when the majority of even technical people understand covert exploitation that is happening by said governments (and leaked to n number of 3rd parties [non govs, ngos, even the public occasionally via incompetence/leaks/hacks, etc] around the world on an increasing basis), which has the dual benefits of making the uniformed or willful ignorant feel good without actually changing the state of things.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#32

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

> half a dozen consent popups every day

I don't see any such things. What I got is many emails when GDPR started and companies asked me to click a link so that they can keep my data and emails saying that they changed privacy. I didn't click any of those links.

BTW I use ad blocker and that hides many nonsense. Even before GDPR there were too many of these dickbars[1] everywhere and I'm annoyed at those. Every site has those subscribe to email popup and other dickbars floating around.

So GDPR didn't make things worse like you say. Although the internet has become worse with tracking everywhere and stupid designs making us suffer.

[1]https://daringfireball.net/2017/06/medium_dickbars

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#33
post #12

1) I don't agree. I prefer to have GDPR in Europe, no GDPR in the USA, and see which turns out to be better for human rights. I suspect that GDPR will very soon start to be used by corrupt politicians and other criminals who want "to be forgotten" for their misdeeds (ie, censor us when we want to remind the public). 2) I can't help but notice that GDPR is a great idea for Brave / BAT. And look: I'm long on BAT (I'm n…

Ironically, I want an ad-blocker that hides all GDPR consent popovers, cookie warnings, etc. They are constant annoyance, especially on mobile. Also a browser that automatically uses a VPN when an American news site blocks European IPs.

That would be fantastic, at least for sites that comply with the GDPR - they don't get to bug me, and since I also don't explicitly opt-in, they also don't get to track me.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#34
If legislation is really required, and I'm not convinced it is, can we start small? This stuff never gets rolled back and tech companies' use of personal data is the new terrorism.

Again I'll take none, but if this ridiculous fervor that's been built requires something, how about not-tech-specific rules around data sharing transparency? Just require details on what's shared and with whom for those seeking it (ideally companies publish it to prevent requiring individual request/response scaling issues, but their choice). You're gonna find most people don't care anyways, so they shouldn't be burdened with more hardline privacy requirements. Just increase the visibility for now.

And please please learn from EU mistakes and establish enforcement mechanisms. Don't just make exorbitant ceilings and move on. Have a framework to punish violators, and again start with small legislation until it can be shown enforcement occurs and is working.

Having said all that, can we just start with pro-privacy PSAs, education, targeted advertisement awareness, punitive measures for breaches, and relaxation of legislation preventing me from scraping/manipulating/proxying these sites however I want? If we all have to hire lawyers and/or compliance assistance, then the first step is too large. We can make our way towards delete-all-my-data-on-request laws later. Not sure what made this an emergency (actually I do know based on media and political driven fervor, but that will be best studied through the lens of history). But all these tech people, OP and commenters here especially, don't speak for many people who accept the current state or reasonably understand heavy-handed government regulations on the internet bring more bad than good.

And for goodness sake, don't use the domain of your should-be-neutral software to make a political post. You aren't gonna feel any pain now because you are in the same line with other popular pitchfork wielders, but your political leanings have bit you before, why would you associate your company with them?

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#35
post #11

Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enable c…

> Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it.

>With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enable competition.

How is this the 'old internet' and not still the current internet. With exeption maybe to the EU with GDPR now, this is what the internet is: everyone has to take care of their own privacy and anonimity.

Barriers for entry for new website and services are lower than they've ever been. You don't even need your own hardware, just rent it.

>Regulations like GDPR arguably make users complacent and lowers their guard,

So according to this theory, people living outside GDPR territory, like the US, are less complacent regarding their data?

Do you really think the _average_ American is less complacent than the average European? I hardly think so.

>The internet was doing fine for decades with minimal involvement from governments - why change things?

The internet was literally built by government(s).

Why Change things? Because we are now finding out people are building massive databases with personal information, bought from small, medium and bigger websites who happily sold it without telling users they did.

GDPR prevents this.

How can I be 'less complacent' and 'have my guard up' if I don't even know that companies sell my data behind my back?

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#36

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

> These are very real, very concrete negative effects of GDPR

No, these are very real, very concrete negative effects of every company and their grandma spying on your internet usage.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#37
post #30

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

This is how unintended consequences happen. Complaining how rational actors work around roadblocks has no practical effect. Who someone blames has no practical effect. The downside of looking at the intent of the law and assigning blame towards the market is that it encourages doubling down on these negative actions. Why not make popups illegal, they'll say. Why not make it illegal for you to optionally trade your data/tracking for services, they'll say. We need to keep fighting the market's misapplication of our original intent with more codified words, they'll say.

Pragmatic realizations of cause and effect are required instead of blame.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#38
post #24

Earlier quoted context omitted.

> GDPR isn't the right to be forgotten, it's mainly about ownership of customer data, consent & privacy. I'm not sure if you're making a humorous observation about how the "right to be forgotten" is not a legitimate form of privacy. If you are, bravo. If you're not, and you are actually unaware of article 17, please see this link: https://gdpr-info.eu/art-17-gdpr/

I'm aware of this article, it's only for personal data (and especially targeted against data leaks & data gathering in its wording), you can't take off an article of the BBC with that. It's nothing like the French law about the Right to be forgotten.

There are experts on this topic who have this exact view of the "right to be forgotten" elements of this article. I'm literally at CANS in Naples right now and someone spoke on this subject yesterday.

I don't see anything about it that makes it "especially targeted against data leaks". It offers protections for free speech without being specific about what that means or how it is balanced.

Of course it's not the same as the French Law, but it's still a vector for threatening legal action against someone who wants to maintain and publish facts about an individual.

There was substantial hullabaloo about this here yesterday.

I mean, look, I'm a US national, so my knowledge is limited. But I've spent time in Europe and talked to many people (again, including some leading thinkers and European activists) and I'm telling you, without a shred of a doubt, that this concern exists here.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#39

If legislation is really required, and I'm not convinced it is, can we start small? This stuff never gets rolled back and tech companies' use of personal data is the new terrorism. Again I'll take none, but if this ridiculous fervor that's been built requires something, how about not-tech-specific rules around data sharing transparency? Just require details on what's shared and with whom for those seeking it (ideally…

> And please please learn from EU mistakes and establish enforcement mechanisms. Don't just make exorbitant ceilings and move on. Have a framework to punish violators, and again start with small legislation until it can be shown enforcement occurs and is working.

There are enforcement mechanism in the GDPR. IMO they also are quite good. The max fine are huge, but there are mechanism to help misbehaving companies into compliance and also protect companies from random lawsuit by individuals.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#40
post #11

Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enable c…

> Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. >With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enabl…

> How can I be 'less complacent' and 'have my guard up' if I don't even know that companies sell my data behind my back?

By assuming they will, and taking steps to not provide your data to all and sundry. At the end of the day, companies can sell your data because they have it.

Post reply on HN