Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

101–110 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#101
post #30

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

> Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy.

What about people who had absolutely no issue with the tracking and "privacy" concerns? I don't care if advertisers target me. If I do care, I use incognito sessions. I'm happy with all the free services I get on the internet and I don't mind giving them a bit of information about myself especially since I've literally never clicked on an ad, ever, so their efforts aren't even effective.

I think there's a small minority of people who care about this stuff, they just had loud voices and the ability to push global legislation through to make everyone else's life more difficult.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#102
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

> Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. Actually, I think we should be annoyed at browser vendors for letting the problems with cookies get to this point. They're obsessed with backwards compatibility, but sometimes you need to break things to fix a problem. This is one of those times. Conside…

Can we have this without forcing it? Ideally browsers would be extensible enough for you to build these things. I miss the document days of yore where implementing a browser would be a reasonable endeavor. And that the limited size of the choices is now seen as a benefit to enforce change is scary. Sure, some see it as a good thing, I mean look at all these features and all the places they've steered the web (e.g. HTTPS). I see it as too much bad with the good and I'm becoming wary of the non-neutrality of my browser. I'm at the point where I want them all to stand still or work backwards fixing bugs and improving what exists. When you get what you want by browsers leveraging their user share to make sites change their practices, you just have to know you fostered the environment for them to do that in places you might not want.

> like removing JS access to cookies and/or making cookies opt-in only for sites storing login info

To this point specifically, making a simple AJAX call to have my web server set and/or send me back the cookies from the HTTP headers is trivial. A browser is not going to be able to tell the purpose of the cookie, and opt-in is user hostile to the point that never-ask-me-again will become the norm.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#103
post #69
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

But is GDPR really making the kind of difference people wanted? What I see, is that mostly companies continue the same behavior, but now with a disclosure you are prompted to accept. I predicted everyone would just accept those terms in exchange for free services they already have invested into. Now we just have an extra annoyance. Has anything substantially changed?

The GDPR is about a lot more than that, which can't be simply covered by a one-click TOS.

https://www.itgovernance.co.uk/articles-of-the-gdpr

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#105
post #96
post #89

Earlier quoted context omitted.

> The way GDPR works out it sort of expects us to care to follow this annoying process, and I don't think people do / want to and thus ultimately won't make good choices. This is simply false. GDPR only allows opt-in for these choices, companies are just implementing GDPR incorrectly.

I keep seeing this response but I've seen no articles about the EU laying down the law and punishing these so blatantly obvious infractions. So either companies are not implementing it incorrectly or the GDPR has no teeth. The EU needs to act on these bad actors sooner than later if they want people to actually respect the spirit of the law.

Enforcement is only still starting up. Officially as of May this year, with the possibility of handing out fines for violations up to two years back from that date.

https://iapp.org/news/a/heres-why-the-first-gdpr-fines-could...

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#106
post #55

Earlier quoted context omitted.

You talk as if the GDPR was a win for privacy. It wasn't. It was poorly drafted legislation by people who had no idea what they were doing.

Your comment is being downvoted because you're just rambling like an old man grumpy about kids on his lawn. Not a single shred of evidence, or even an attempt at making an actual reasoned point. Every time there's comments like this I can't help but think I'd be extremely surprised if the people writing them knew any of the names of the people who worked on the law. I wonder what you even define as "having an idea wh…

Is the best way to fight ignorance, virulent personal attacks? Does that constructively influence people?

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#107

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

Yes that's what is most annoying that many companies by default assume opt-in to their spying activity, despite GDPR regulation saying that all consents should be opt-out by default. As a result, after clicking on 21 pop-up and opting out suddenly I notice that I stop caring... so in this area it seems GDPR is effectively dead regulation.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#108
post #78

Earlier quoted context omitted.

And yet the poster is right for the reason mentioned by the first poster. Most people click on the option that gives quick access to the content. If it creates more than 2 seconds of distraction, I might even close the page. There is no reason to trust the EU legislature regarding the internet after something like this: https://juliareda.eu/2018/08/censorship-machines-gonna-censo...

The poster claims two things: 1. It was "poorly drafted legislation" 2. The authors had "no idea what they were doing" Whether it was poorly drafted legislation remains to be seen. The "unintended consequences" people are talking about here are minor, what matters are the intended consequences such as the augmented rights europeans have over their data, their privacy, etc. I personally don't give a shit about the ann…

I agree with you that an important and useful part of the GDPR is deletion of your data. Good examples: No advertising and spam. Prevention of later hacking and theft of your data like e.g. credit card numbers or private messages. You have revealed your true identity on social media and want to remove your posts.

But maybe GDPR gives a false sense of safety and security and control:

- What is technically possible ? When I cite you, must my posts be deleted as well ?

- Who controls what companies do outside of the EU or even within the EU ?

- National police and secret services in the USA and EU might be more interested in the data than some US company. They have no moral problem with installing spyware on your computer.

- Banks and maybe even insurance companies have already the right to know much about you.

- https://ec.europa.eu/info/law/law-topic/data-protection/refo...

- https://ec.europa.eu/info/law/law-topic/data-protection/refo...

IMO, you can only trust that the EU and the rest of the world does not give you control when it really matters.

Another example: https://www.youtube.com/watch?v=gGeevtdp1WQ&t=1

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#109

Earlier quoted context omitted.

I very much wish incentives were aligned this way. However, as the ad tech sector has shown, consumer apathy is pervasive enough that you can push the envelope quite hard against them before the costs near the benefits. Couple that with the uncertainty of an ever-changing tech landscape (especially considering impending government interference), and optimizing for short term profits is "rational". That's "rational" a…

Hence the GDPR, which sort of makes this go full circle. These 'rational actors' are now trying with all their might to do an end-run around the law. It is interesting to see which companies 'get it' and which really don't get it. I suspect - and hope - that five years from now or so the ones that didn't get it will either have changed tack or will no longer be around.

Although they are doing an end-run around the law, I'm not sure they are trying that hard. I suspect the law will become largely ignored (or massively paid lip service just to avoid being the tiniest rare case that is punished), and hope that alternative tech overcomes the entrenched.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#110
post #96
post #89

Earlier quoted context omitted.

> The way GDPR works out it sort of expects us to care to follow this annoying process, and I don't think people do / want to and thus ultimately won't make good choices. This is simply false. GDPR only allows opt-in for these choices, companies are just implementing GDPR incorrectly.

I keep seeing this response but I've seen no articles about the EU laying down the law and punishing these so blatantly obvious infractions. So either companies are not implementing it incorrectly or the GDPR has no teeth. The EU needs to act on these bad actors sooner than later if they want people to actually respect the spirit of the law.

That's not how any of this works. We weren't going to get fines dropping on the first day.
Post reply on HN