Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

111–120 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#111
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

Counterpoint: be annoyed at GDPR. If a new regulation insisted that on entering a hotel room, a member of the hotel staff had to use a blacklight and you needed to explicitly approve every illuminated mark larger than a quarter, then you would be annoyed at that regulation. There are supposed to be all sorts of other GDPR protections, about rights to be forgotten, about being able to access and selectively remove per…

>If a new regulation insisted that on entering a hotel room, a member of the hotel staff had to use a blacklight and you needed to explicitly approve every illuminated mark larger than a quarter, then you would be annoyed at that regulation.

How about this. For the past 25 years every hotel that you checked into has kept a record of:

- How often did you visit?

- How much money did you spend?

- What type of CC do you have?

- Did you watch porn?

- If so, what is your favorite type?

- Did you pass on dietary restrictions to the chef?

- Were you alone?

- Did someone other than the person listed as your wife on FB join you for the night?

- etc... etc... etc...

And then, without your consent, without even notifying you they sold this information to credit score companies, to advertising companies and to whoever the fuck will buy it.

Without. Your. Consent.

THIS is how the internet works today. Everyone grabs as much data as they can and then sells it to whoever wants to buy it. You have no vote in this. It just happens and it says so in weird legal terms on page 373 section 44 subsection 7a of their 700 page Terms of Service.

GDPR gives you this vote.

GDPR says: if you want to resell data you harvest you HAVE to get their consent, in clear and understandable terms. Can't bury it in your TOS.

GDPR says: you cannot make your website / app / service unavailable if people refuse this.

GDPR says: you can ask companies how much and which data they got on you and they have to provide it.

GDPR protects you from an invisible industry many people don't even know exists.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#112
post #90
post #69

Earlier quoted context omitted.

But is GDPR really making the kind of difference people wanted? What I see, is that mostly companies continue the same behavior, but now with a disclosure you are prompted to accept. I predicted everyone would just accept those terms in exchange for free services they already have invested into. Now we just have an extra annoyance. Has anything substantially changed?

Just a few hours ago there was an article on the front page about yet another tech giant getting hacked and losing contact info on hundreds of millions of users [1]. A GDPR in the US should have the power to audit companies and ensure compliance, just like the FDA does with health-tech companies. On the user side you might only see the effects of GDPR in the form of cookies that were added as a quick-and-dirty soluti…

> GDPR in the US should have the power to audit companies and ensure compliance, just like the FDA

This is wanton overregulation. All we need is strict liability for data loss. After a few years of watching cases play out in the courts, we can revisit to see if more onerous regulation is required.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#113
post #89
post #76

Earlier quoted context omitted.

Yeah I don't want to sit down with the digital form of someone's lawyers each time I visit a site, and if I have to I imagine I and others all just click away to get the dang content already. The way GDPR works out it sort of expects us to care to follow this annoying process, and I don't think people do / want to and thus ultimately won't make good choices. GDPR demands users engage in the process on the web in a ve…

> The way GDPR works out it sort of expects us to care to follow this annoying process, and I don't think people do / want to and thus ultimately won't make good choices. This is simply false. GDPR only allows opt-in for these choices, companies are just implementing GDPR incorrectly.

I should have been more specific. I meant good choice as something other than just clicking to get past the notice.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#114
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

Counterpoint: be annoyed at GDPR. If a new regulation insisted that on entering a hotel room, a member of the hotel staff had to use a blacklight and you needed to explicitly approve every illuminated mark larger than a quarter, then you would be annoyed at that regulation. There are supposed to be all sorts of other GDPR protections, about rights to be forgotten, about being able to access and selectively remove per…

> There are supposed to be all sorts of other GDPR protections, about rights to be forgotten, about being able to access and selectively remove personal data from an online profile, that I have no idea how to activate.

You don’t have to do anything to “activate” these rights under GDPR. You can just email the website in question and ask them to send an accessible copy of your data, or remove some or all of it from their servers. GDPR simply requires companies to adhere to certain consumer demands about my own data and respond within reasonable time frames.

Also I disagree with your analogy. Companies are allowed to track users for internal purposes Uber GDPR. But they are not allowed to sell your data to third parties without consent. The reason all these pop ups and consent forms are so complicated have nothing to do with GDPR, and everything to do with the fact that companies are trying to nudge you into making a choice against your own best interests.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#115
post #76

Earlier quoted context omitted.

Yeah I don't want to sit down with the digital form of someone's lawyers each time I visit a site, and if I have to I imagine I and others all just click away to get the dang content already. The way GDPR works out it sort of expects us to care to follow this annoying process, and I don't think people do / want to and thus ultimately won't make good choices. GDPR demands users engage in the process on the web in a ve…

I find it fascinating how people blame the solution while it's the symptom that bothers them and they don't even notice the disease. GDPR isn't only related to internet services. I received a phone call today from my mobile operator, they got bought by a larger company and it was a sales call. However, they were asking to speak to person in charge in regards to company-wide mobile subscription and services - we use n…

I think people get too tied up in the problem (and I agree it is a problem) that they just dismiss the flaws with GDPR.

I really think (like the one I describe) that for many cases GDPR isn't going to have the desired effect, if the result is that we have to sit through notices on every site and click away to get through them.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#116

I don't want it to end up in annoying dialog boxes and degraded UX on every website like it currently is in Europe.

That's great. I don't want my information stored, analyzed, cross-referenced and re-sold around without me knowing what's going on.

Oddly enough, you're frustrated about "degraded UX", but for several years now - UX has been terrible with annoying popups asking you for your email, advertisement-ridden websites that attracts traffic via well-crafted titles while the content is something to be desired...

Don't be a peon. But if you decide you want to be one, think about your other fellow humans - maybe they don't want to be peons.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#117
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

> Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. What about people who had absolutely no issue with the tracking and "privacy" concerns? I don't care if advertisers target me. If I do care, I use incognito sessions. I'm happy with all the free services I get on the internet and I don't mind giving them…

Good, you can opt in to tracking and profiling, if you wish.

The rest of us would rather abolish this flagrant abuse of personal information.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#118
I would prefer starting small and cautiously scaling up. “If you lose my data, you are strictly liable” is a good start because it lets case law work through the holes. (It also causes companies to see personal data as an asset and a liability, not just the former.)

Full-blown GDPR is overkill. It makes more sense to wait a few years and see if the situation in Europe evolves differently from the U.S. I personally believe the law fails to incentivise the sort of behaviour it aspires to, but that’s merely a hunch—better to wait until we have data.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#119
post #96

Earlier quoted context omitted.

I keep seeing this response but I've seen no articles about the EU laying down the law and punishing these so blatantly obvious infractions. So either companies are not implementing it incorrectly or the GDPR has no teeth. The EU needs to act on these bad actors sooner than later if they want people to actually respect the spirit of the law.

That's not how any of this works. We weren't going to get fines dropping on the first day.

I really hope it doesn't take the EU over 4 full months to prove a cookie banner is in violation. That seems like a straight forward infraction if the way people have interpreted the law is accurate.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#120

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

A couple things to be happy about:

1. Private Browsing, separate sessions in web previews, etc. are all somewhat less privacy protecting than you'd hope (IP tracking[A], browser fingerprinting, etc.) the GDPR mandates that companies ask you about tracking before they do it. Those notices are a sign that they're trying to do that.

2. I do work in the tech, marketing and security arenas and the GDPR was like kicking a beehive. Everyone at least looked around and asked themselves: "Do we really need to keep this data?" and in many/most cases the answer was: "No". So they got rid of it.

The GDPR is a lot like a vaccine, the power is in the prevention. Which won't make splashy headlines, nobody is going to write: "A million records weren't leaked today b/c they were deleted off the server 6 months ago as they weren't needed."

A - every time GDPR comes up on HN, someone complains about IPs (either that it doesn't matter and/or that their Apache log file is full of them, so why bother). GDPR regs focus on what data a company is collecting, how are they using that data and did they get consent for that. In the case of IPs, you can consider implicit consent b/c they're browsing your site. But you did _not_ consent to have your IP tracked as part of a 3rd party marketplace for retargeting ads.

Post reply on HN