Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

61–70 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#61
The GDPR is mostly good. The right to find out and delete the data is excellent. The bad thing is the constant consent popups which have become synonymous with the GDPR.

Obviously there are also still a lot of sites that try to wiggle around the GDPR by saying "By entering the site you agree to X", a practice that should soon be found to be in violation of the regulation. If that is allowed, the regulation for storage/processing becomes almost pointless.

That data collection should be opt in if it isn't an essential function of the app/site/service.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#62
post #13

Earlier quoted context omitted.

> The internet was doing fine for decades with minimal involvement from governments - why change things? Things change on their own. The internet used to be accessed by highly sophisticated and technical users. Now it's mainstream. And all mainstream things follow two basic rules: 1. Everything move at the speed of the slowest person. 2. The weakest members of the community need to be protected.

> The internet used to be accessed by highly sophisticated and technical users. Quaint but that's simply not true unless you're talking pre 90's. No point in kidding ourselves. The internet was accessed by people who accessed the internet. They popped a floppy/cd in a drive and followed instructions. They then opened a browser and typed a url. Nothing sophisticated about it. Nobody was creating electrical signals by…

> Nobody was creating electrical signals by hand and sending them down a home made wire.

I think we're talking about completely different levels of sophistication.

You're talking about electrical engineers vs regular users, I'm talking about levels of functional literacy... Don't forget that the average Joe/Jane has a level of functional literacy of somewhere around mid to late secondary school.

The earliest internet adopters were universities (so a entirely different level of education) and after that it was middle or upper class people who could afford a PC and an internet connection plus had the interest in doing so, considering that PCs until Windows 95 were either too expensive or not very user friendly.

The current internet, thanks to mobile devices and cheap, ubiquitous internet access, is truly accessible universally.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#63
post #55
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

You talk as if the GDPR was a win for privacy. It wasn't. It was poorly drafted legislation by people who had no idea what they were doing.

Your comment is being downvoted because you're just rambling like an old man grumpy about kids on his lawn. Not a single shred of evidence, or even an attempt at making an actual reasoned point.

Every time there's comments like this I can't help but think I'd be extremely surprised if the people writing them knew any of the names of the people who worked on the law.

I wonder what you even define as "having an idea what you're doing".

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#64

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

I believe this is more due to lack of enforcement of the GDPR. The dark UX patterns you mention are not technically legal. There a numerous stipulations about how the consent must be freely given, simple and concise, opt-in, withdrawable, etc.

I think an equivalent of the GDPR becoming US law would go a long way to improving the problems of enforceability.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#65

Earlier quoted context omitted.

This is how unintended consequences happen. Complaining how rational actors work around roadblocks has no practical effect. Who someone blames has no practical effect. The downside of looking at the intent of the law and assigning blame towards the market is that it encourages doubling down on these negative actions. Why not make popups illegal, they'll say. Why not make it illegal for you to optionally trade your da…

>This is how unintended consequences happen. Complaining how rational actors work around roadblocks has no practical effect. Who someone blames has no practical effect. The downside of looking at the intent of the law and assigning blame towards the market is that it encourages doubling down on these negative actions. Bounce rates must be through the roof, especially for clickbait. I'm certain that the market has not…

This would only work for automatic opt-in. why would companies, that monetize your privacy stop bugging you unless you close that pop-up manually? I imagine there are a lot of people that use their browser with default settings, so there is a chance they don’t actually care about privacy

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#66

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

I can’t agree more. The popups are insanely stupid, frustrating, and a usability and design disaster. I would adamantly oppose any US regulation that could lead to something similar here.

That’s just the tip of the iceberg of the problems with GDPR. Watch as the enforcement side becomes selectively weaponized as a political tool against unpopular sites and the other shoe will have dropped.

GDPR is a regulatory bandaid to a technical problem. That geeks are calling for more regulation to fix their own failings to design privacy resilient network protocols and decentralized software which truly and actually puts users in control of their own data, is shameful.

It’s a common trope that users don’t care enough to seek out and use privacy enhancing and protecting solutions. I think that’s a load of crap. The current solutions are alpha quality and are not ready for general use. But the technology will improve and I am convinced they will destroy the competition when they get there.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#67
post #56
post #11

Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enable c…

that's some ancap crap if I ever heard some Facebook and co hire psychologists to make their data collection as painless and humanly possible, most of the time people only ever fully realise the extent of the data collected once they get pinpoint accurate ads, at which point they even resort to accusing facebook of listening to your conversations. The point is, the average person can't assess what exactly you can acc…

So then, one can advocate against the use of social media in general or Facebook in particular, (ironically) run targeted ads on these platforms to educate the users, etc.

In truth, I think social media as we know it is on the way out anyway. The new generation will rebel against it, and might go back to writing hand-written letters to each other for all I know. I feel like giving these companies all this attention and treating them as "the new utilities" that are forever to stay here and must be regulated also psychologically cements their position as such.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#68
post #11

Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enable c…

> any internet user has to take care of their own privacy and anonymity. Easy to say, hard in practice when there's some really dodgy shit going on and given that most people don't actually (want to) dive into the subject, this isn't something that can apply to the modern age. I mean while I agree, you postulate some libertarian ideal - freedom for all on the internet. And while I agree, there's some scummy companies…

My main concern is that the big government will be used by big corporations with massive compliance and legal departments to shut down any emerging competition that refuses to be bought out.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#69
post #30

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

But is GDPR really making the kind of difference people wanted?

What I see, is that mostly companies continue the same behavior, but now with a disclosure you are prompted to accept.

I predicted everyone would just accept those terms in exchange for free services they already have invested into. Now we just have an extra annoyance. Has anything substantially changed?

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#70

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

It's much to early to understand any of the effects of the GDPR yet. We'll need to see some case history before we can even understand what companies will be penalized for, or how they can come into compliance.

It might not be necessary, or even compliant, to notify and gather consent for cookies via popup. This is just something that many web site operators are assuming will bring them into compliance, but there's no way to know that yet. Just like there's no way to know if you'll still be clicking through cookie prompts 5 years from now once we have a few GDPR test cases.

Let's wait and see how this all plays out.

Post reply on HN