Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

91–100 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#91
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

> Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. Actually, I think we should be annoyed at browser vendors for letting the problems with cookies get to this point. They're obsessed with backwards compatibility, but sometimes you need to break things to fix a problem. This is one of those times. Conside…

Chrome is the biggest browser by market share and is maintained by a company whose entire business model revolves around tracking users to feed them ads. They have zero incentive to remove cookies. Same goes for Safari and Edge, even though they're not as dependent on ad revenue.

This is a textbook example of negative externalities that can't be solved by market forces. That's where regulators should be stepping in.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#92

Earlier quoted context omitted.

> How can I be 'less complacent' and 'have my guard up' if I don't even know that companies sell my data behind my back? By assuming they will, and taking steps to not provide your data to all and sundry. At the end of the day, companies can sell your data because they have it.

>By assuming they will, and taking steps to not provide your data to all and sundry. At the end of the day, companies can sell your data because they have it. Okay I now assume that all companies will harvest as much data as they can. I will now take steps to prevent this. I am now offline and there is no way to know if they do.

> Okay I now assume that all companies will harvest as much data as they can.

You say harvest, as if they are taking something. The reality is, people always gave the data. The companies just kept what it was freely given. It's a bit hypocritical if I get upset that you keep something I gave you. The reality is, the problem wasn't with the users who gave the data, or the companies who kept what was given, but rather the people who made it possible to do it so easily in the first place. Browser makers share the majority of this responsibility. We look to them to create secure browsers that can't be hacked, but completely ignore the fact that they created browsers that are easily tracked. And then we adopt Chrome, a browser made by a company built on tracking.

And I find it funny that Brendan Eich's creation is probably the biggest reason we are in this situation in the first place.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#93

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

It's pretty much having the same impact as California Prop 65, which requires warning signs about "chemicals known to the State of California to cause cancer and birth defects or other reproductive harm" to be displayed where ever you may come into contact with them.

Of course, the state of "what the State of California knows" changes every few days, and there's no penalty for being proactive and posting your signs without actually verifying that one of the ~800 chemicals exists on your property. So every business just places a warning sign anyway, and consumers ignore the signs.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#94
post #64

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

I believe this is more due to lack of enforcement of the GDPR. The dark UX patterns you mention are not technically legal. There a numerous stipulations about how the consent must be freely given, simple and concise, opt-in, withdrawable, etc. I think an equivalent of the GDPR becoming US law would go a long way to improving the problems of enforceability.

A GDPR for the US will be written by the very companies it was intended to protect consumers from.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#95
post #76

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

Yeah I don't want to sit down with the digital form of someone's lawyers each time I visit a site, and if I have to I imagine I and others all just click away to get the dang content already. The way GDPR works out it sort of expects us to care to follow this annoying process, and I don't think people do / want to and thus ultimately won't make good choices. GDPR demands users engage in the process on the web in a ve…

I find it fascinating how people blame the solution while it's the symptom that bothers them and they don't even notice the disease.

GDPR isn't only related to internet services. I received a phone call today from my mobile operator, they got bought by a larger company and it was a sales call. However, they were asking to speak to person in charge in regards to company-wide mobile subscription and services - we use none.

What was disturbing is that I was contacted on my private phone number in regards to a sales call related to the company I work at.

The details I left when buying their mobile service (which was 20 years ago) don't contain where I work at. I didn't work at all at the time, but I kept paying for the service.

I didn't update my account details so I found it a huge surprise when they knew exactly who to call and on what number.

Being a EU citizen, I went GDPR on them. I don't want people to call my personal number and disturb me in my own free time with sales calls in regards to my company. How did they get my details? Who authorized them to contact me? I've many questions and luckily - now I have legal backing when asking them to anonymize my data.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#96
post #89
post #76

Earlier quoted context omitted.

Yeah I don't want to sit down with the digital form of someone's lawyers each time I visit a site, and if I have to I imagine I and others all just click away to get the dang content already. The way GDPR works out it sort of expects us to care to follow this annoying process, and I don't think people do / want to and thus ultimately won't make good choices. GDPR demands users engage in the process on the web in a ve…

> The way GDPR works out it sort of expects us to care to follow this annoying process, and I don't think people do / want to and thus ultimately won't make good choices. This is simply false. GDPR only allows opt-in for these choices, companies are just implementing GDPR incorrectly.

I keep seeing this response but I've seen no articles about the EU laying down the law and punishing these so blatantly obvious infractions. So either companies are not implementing it incorrectly or the GDPR has no teeth. The EU needs to act on these bad actors sooner than later if they want people to actually respect the spirit of the law.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#97
post #30

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

Counterpoint: be annoyed at GDPR.

If a new regulation insisted that on entering a hotel room, a member of the hotel staff had to use a blacklight and you needed to explicitly approve every illuminated mark larger than a quarter, then you would be annoyed at that regulation.

There are supposed to be all sorts of other GDPR protections, about rights to be forgotten, about being able to access and selectively remove personal data from an online profile, that I have no idea how to activate. Instead all I get, as a user, is a bunch of consent forms, like the stupid cookie warnings, that I have no idea how to respond to, and no idea what I'm committing to when I click them.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#98
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

> Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. Actually, I think we should be annoyed at browser vendors for letting the problems with cookies get to this point. They're obsessed with backwards compatibility, but sometimes you need to break things to fix a problem. This is one of those times. Conside…

Isn't this kinda what Brave/Brendan are doing?

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#99

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

Yes. And you're lucky if you see any Refuse button. Most all what I see the choices are to Agree completely to all terms, or "do not use this site".

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#100

Earlier quoted context omitted.

>By assuming they will, and taking steps to not provide your data to all and sundry. At the end of the day, companies can sell your data because they have it. Okay I now assume that all companies will harvest as much data as they can. I will now take steps to prevent this. I am now offline and there is no way to know if they do.

> Okay I now assume that all companies will harvest as much data as they can. You say harvest, as if they are taking something. The reality is, people always gave the data. The companies just kept what it was freely given. It's a bit hypocritical if I get upset that you keep something I gave you. The reality is, the problem wasn't with the users who gave the data, or the companies who kept what was given, but rather…

People - not the ones here on HN - have no clue what they 'give' away. They also have no clue how often small companies, indie game devs etc make a living by selling said information that was 'given' to them.

These data aggregators can build profiles on people by buying data from as many sources as possible.

How is the average user supposed to know this happens on the background when they load www.nytimes.com? How are they supposed to know that those flashy banners contain entire programs designed to track them?

How should the average user now that the ad banners on acb.com are the same as on xyz.com?

How should the average user know that a FB button on every website also tracks you. As does G+ button, as does Twiter etc...

How are regular users supposed to know how much data they produce online.

Honestly it even scares me to see how many JS is loaded on average websites. Just for tracking, just for profile building.

This isn't given. It's taken.

Post reply on HN