Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

41–50 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#41

Earlier quoted context omitted.

> Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. >With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enabl…

> How can I be 'less complacent' and 'have my guard up' if I don't even know that companies sell my data behind my back? By assuming they will, and taking steps to not provide your data to all and sundry. At the end of the day, companies can sell your data because they have it.

>By assuming they will, and taking steps to not provide your data to all and sundry. At the end of the day, companies can sell your data because they have it.

Okay I now assume that all companies will harvest as much data as they can. I will now take steps to prevent this.

I am now offline and there is no way to know if they do.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#42

If legislation is really required, and I'm not convinced it is, can we start small? This stuff never gets rolled back and tech companies' use of personal data is the new terrorism. Again I'll take none, but if this ridiculous fervor that's been built requires something, how about not-tech-specific rules around data sharing transparency? Just require details on what's shared and with whom for those seeking it (ideally…

> how about not-tech-specific rules around data sharing transparency

Such as... a General Data Protection Regulation? GDPR is not "tech-specific", it applies to technical solutions, yes, but also to business requirements and administration, and non-technical data collection. One non-tech consequence here is that stores are encouraged not to ask your SSID equivalent, since that exposes deeply personal information to others nearby.

> Just require details on what's shared and with whom for those seeking it

That's a big part of GDPR, actually. You're allowed to collect data, with certain rules about transparency and anonymization, and as long as there are reasonable motivators for collecting it. Within reason and with exceptions, I'm sure, but nonetheless, that's a big part of it.

> You're gonna find most people don't care anyways

I'm willing to bet few people cared about regulations on traffic safety and alcohol as well. That doesn't mean that regulations to hold bad actors responsible aren't necessary, as has been proven countless times through leaks, sometimes very large or sensitive leaks.

> And please please learn from EU mistakes and establish enforcement mechanisms.

What do you mean by this? What "mistake" has the EU made? They have enforcement mechanisms in place to target companies for violations of GDPR. It will take time to work out the details and establish case law, but I don't see anyway around that. Even if you introduce "small" regulations, companies will fight the charges or fines that you bring to establish precedent.

> If we all have to hire lawyers and/or compliance assistance, then the first step is too large.

You all don't. Larger corporations probably do, but that's unavoidable. GDPR was announced something like two years before implementation, and published in a lot of different ways beforehand. There were compliance consultants, yes, but there were also PSAs, education, advertisement, easy-to-read summaries and tons and tons of material to read up on.

> heavy-handed government regulations on the internet bring more bad than good

The view of pre-GDPR internet as something free of regulation, or free from government involvement, or as nothing but a land of milk and honey seems to me like a pretty severe case of rose-tinted glasses, especially if we're talking the last 10-15 years.

There have been a lot of issues with the internet, even without mentioning all the severe privacy breaches, or breaches that are a concern for national security.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#43
post #38

Earlier quoted context omitted.

I'm aware of this article, it's only for personal data (and especially targeted against data leaks & data gathering in its wording), you can't take off an article of the BBC with that. It's nothing like the French law about the Right to be forgotten.

There are experts on this topic who have this exact view of the "right to be forgotten" elements of this article. I'm literally at CANS in Naples right now and someone spoke on this subject yesterday. I don't see anything about it that makes it "especially targeted against data leaks". It offers protections for free speech without being specific about what that means or how it is balanced. Of course it's not the same…

As with every law, we will see how it's actually used in practice but on my case I did not have much doubts about how it's supposed to be applied, I never understood it as an equivalent on the French one. For me, one of the goals here is when you delete your Facebook account, the data is actually deleted unlike what probably happens now.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#44

If legislation is really required, and I'm not convinced it is, can we start small? This stuff never gets rolled back and tech companies' use of personal data is the new terrorism. Again I'll take none, but if this ridiculous fervor that's been built requires something, how about not-tech-specific rules around data sharing transparency? Just require details on what's shared and with whom for those seeking it (ideally…

> And please please learn from EU mistakes and establish enforcement mechanisms. Don't just make exorbitant ceilings and move on. Have a framework to punish violators, and again start with small legislation until it can be shown enforcement occurs and is working. There are enforcement mechanism in the GDPR. IMO they also are quite good. The max fine are huge, but there are mechanism to help misbehaving companies into…

> There are enforcement mechanism in the GDPR. IMO they also are quite good.

Based on my research into the lax enforcement of GDPR predecessors and GDPR leveraging those same enforcement bodies, I disagree. This is why I advocate an incremental approach; so you can prove you are adept at implementing the measures you write down lest it become just words, or worse, an economic warfare tool to subjectively apply on a whim. Sometimes you even have to temper those words knowing your enforcement mechanisms aren't yet prepared. Nobody's asking for going after all offenders, just reasonable attempts at equitable large-scale enforcement.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#45
post #23
post #12

1) I don't agree. I prefer to have GDPR in Europe, no GDPR in the USA, and see which turns out to be better for human rights. I suspect that GDPR will very soon start to be used by corrupt politicians and other criminals who want "to be forgotten" for their misdeeds (ie, censor us when we want to remind the public). 2) I can't help but notice that GDPR is a great idea for Brave / BAT. And look: I'm long on BAT (I'm n…

> It seems to me that people are working to find ways to improve their lives, and that they'll keep doing so to the shegrin of the internet behemoths absent any "regulation" I'd agree with you if ad & tracking blocking was mainstream, or even better, built into major browsers & operating systems and enabled by default. We are not there yet (and might never be since a major OS developer - Google - has a vested interes…

> the cancer that is called advertising

In these conversations "advertising" is a very loaded term, not all advertising is tracking, not all advertising is invasive and not all advertising is served by shady clickbait companies.

With a little stretch even a review of a movie or a game is advertising. The GDPR might push toward a more sustainable advertising model and honestly I cannot see anything negative in that.

(also not all advertising is fake news and product discovery is a hard problem for both sellers and buyers)

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#46

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

> The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that.

At this point I just want those consent forms to be standardized via ARIA tags or whatever so that some extension can click the "yea, sure, whatever" button for me.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#47
post #13
post #11

Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enable c…

> The internet was doing fine for decades with minimal involvement from governments - why change things? Things change on their own. The internet used to be accessed by highly sophisticated and technical users. Now it's mainstream. And all mainstream things follow two basic rules: 1. Everything move at the speed of the slowest person. 2. The weakest members of the community need to be protected.

> The internet used to be accessed by highly sophisticated and technical users.

Quaint but that's simply not true unless you're talking pre 90's. No point in kidding ourselves.

The internet was accessed by people who accessed the internet. They popped a floppy/cd in a drive and followed instructions. They then opened a browser and typed a url.

Nothing sophisticated about it.

Nobody was creating electrical signals by hand and sending them down a home made wire.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#48

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

I have started using https://www.i-dont-care-about-cookies.eu (along with uBlock Origin and Cookie AutoDelete) for this reason. It just gets rid of as many of those dialogues as possible, haven't seen one in a month.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#49

If legislation is really required, and I'm not convinced it is, can we start small? This stuff never gets rolled back and tech companies' use of personal data is the new terrorism. Again I'll take none, but if this ridiculous fervor that's been built requires something, how about not-tech-specific rules around data sharing transparency? Just require details on what's shared and with whom for those seeking it (ideally…

> how about not-tech-specific rules around data sharing transparency Such as... a General Data Protection Regulation? GDPR is not "tech-specific", it applies to technical solutions, yes, but also to business requirements and administration, and non-technical data collection. One non-tech consequence here is that stores are encouraged not to ask your SSID equivalent, since that exposes deeply personal information to o…

> Such as... a General Data Protection Regulation?

Without the rest, sure. Law's also exist for consumer data sharing transparency in the US, they just need to require more detail and have their scope increased (again, if we're resigned to the fact that something must happen).

> That's a big part of GDPR, actually

Right, my whole point is starting small, i.e. without all the other big parts.

> I'm willing to bet few people cared about regulations on traffic safety and alcohol as well

We have to stop debating like this. I could bring up drug laws or prohibition to bolster my point about government regulatory overreach and its consequences. But doing this at a high level negates the nuances in the debate on this issue which has no historical equivalences from which to draw.

> What do you mean by this?

I have not seen large scale equitable enforcement of EU internet laws to justify their size. It's becoming a more rational approach to ignore the laws. Even proponents of the GDPR use subjective enforcement to allay small business fears of compliance. This is why I promote proving you can enforce before expanding scope.

> You all don't

That is a product of levels of risk, legislation scope, and market reaction to the general murkiness of how it will be interpreted and enforced. It's like telling a business they don't need an accountant, the information is all out there.

> The view of pre-GDPR internet as something free of regulation, or free from government involvement, or as nothing but a land of milk and honey seems to me like a pretty severe case of rose-tinted glasses, especially if we're talking the last 10-15 years.

Agree and I definitely don't share that view. I am proud of my peers for fighting it where we have, I just wish we could separate what we want vs how we get it.

Speaking of breaches, I think that's a great initial place to direct legislation and build citizen support against reckless companies without going all in on legislation of data specifically. It also has the benefit of punishing violations instead of prescribing specific maintenance rules.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#50

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

> half a dozen consent popups every day I don't see any such things. What I got is many emails when GDPR started and companies asked me to click a link so that they can keep my data and emails saying that they changed privacy. I didn't click any of those links. BTW I use ad blocker and that hides many nonsense. Even before GDPR there were too many of these dickbars[1] everywhere and I'm annoyed at those. Every site h…

> I don't see any such things.

I usually browse the web from within the EU, and I have really begun to mentally filter out the popups because there's just so darn many, but on a recent trip back to the US, the difference was remarkable. A visit to commonly used sites like SourceForge or Washington Post were suddenly just seamless, and on some other sites I was no longer even searching around for the obnoxious cookie warning so that my screen didn't feel so cluttered.

Post reply on HN