Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

131–140 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#131
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

Counterpoint: be annoyed at GDPR. If a new regulation insisted that on entering a hotel room, a member of the hotel staff had to use a blacklight and you needed to explicitly approve every illuminated mark larger than a quarter, then you would be annoyed at that regulation. There are supposed to be all sorts of other GDPR protections, about rights to be forgotten, about being able to access and selectively remove per…

There are supposed to be all sorts of other GDPR protections, about rights to be forgotten, about being able to access and selectively remove personal data from an online profile, that I have no idea how to activate. Instead all I get, as a user, is a bunch of consent forms, like the stupid cookie warnings, that I have no idea how to respond to, and no idea what I'm committing to when I click them.

This again, is the fault of most websites. GDPR requires opt-in for tracking, etc. A website could just, by default, not do tracking. Then provide the tracking options in the preferences. However, most sites have gotten so data hungry that they can't accept GDPR's privacy-by-default and have to bother you with pop-ups to try to get your consent to track you. Add some dark patterns, like designing these pop-up forms such that they are effectively opt-out.

I can't wait until some organization sues some big fish to send a signal that blanket data collection or using dark patterns to trick people into data collection is not an acceptable modus operandi.

Also, we as consumers of the web can also help to improve things. Contact companies and ask them to switch to opt-in (as required by the GDPR), encourage them to not collect data by default (avoiding popups), exercise your right to remove data and/or see what data is collected. If enough people request this by e-mail, companies will have to set up automated procedures (provide a webpage to see or remove data).

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#132

It's somewhat amusing watching the overt rhetoric of advocating for data privacy enforced by governments when the majority of even technical people understand covert exploitation that is happening by said governments (and leaked to n number of 3rd parties [non govs, ngos, even the public occasionally via incompetence/leaks/hacks, etc] around the world on an increasing basis), which has the dual benefits of making the…

Yup, and notice not a single person crying about privacy has been materially harmed from companies using their information to target ads or provide better products.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#133
post #69
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

But is GDPR really making the kind of difference people wanted? What I see, is that mostly companies continue the same behavior, but now with a disclosure you are prompted to accept. I predicted everyone would just accept those terms in exchange for free services they already have invested into. Now we just have an extra annoyance. Has anything substantially changed?

accept those terms in exchange for free services

Such exchanges are illegal under the GDPR. Consent must be freely given; if access to a service (that doesn't require that data, or that use of the data) is dependent on it, then it's not valid.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#134

Data protection we do need indeed, but the EU is the last entity I want to be emulating on internet laws, except maybe China.

What specifically do you take exception to with regard to GDPR/EU Internet laws? Having hands-on experience with compliance, I find GDPR to be quite reasonable - if anything, I'd say it's overly lax with regards to deletion of data that's not visible to the user (i.e. logs, 'shadow profiles', etc.).

What material harm or damage to you or your person did you experience prior to GDPR that GDPR has prevented or compensated for?

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#135
post #78

Earlier quoted context omitted.

Your comment is being downvoted because you're just rambling like an old man grumpy about kids on his lawn. Not a single shred of evidence, or even an attempt at making an actual reasoned point. Every time there's comments like this I can't help but think I'd be extremely surprised if the people writing them knew any of the names of the people who worked on the law. I wonder what you even define as "having an idea wh…

And yet the poster is right for the reason mentioned by the first poster. Most people click on the option that gives quick access to the content. If it creates more than 2 seconds of distraction, I might even close the page. There is no reason to trust the EU legislature regarding the internet after something like this: https://juliareda.eu/2018/08/censorship-machines-gonna-censo...

If it creates more than 2 seconds of distraction, I might even close the page.

That's a win for the GDPR, not a loss! Sites that track people less will have less bounces and therefore higher revenue.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#136

Earlier quoted context omitted.

Counterpoint: be annoyed at GDPR. If a new regulation insisted that on entering a hotel room, a member of the hotel staff had to use a blacklight and you needed to explicitly approve every illuminated mark larger than a quarter, then you would be annoyed at that regulation. There are supposed to be all sorts of other GDPR protections, about rights to be forgotten, about being able to access and selectively remove per…

>If a new regulation insisted that on entering a hotel room, a member of the hotel staff had to use a blacklight and you needed to explicitly approve every illuminated mark larger than a quarter, then you would be annoyed at that regulation. How about this. For the past 25 years every hotel that you checked into has kept a record of: - How often did you visit? - How much money did you spend? - What type of CC do you…

> And then, without your consent, without even notifying you they sold this information to credit score companies, to advertising companies and to whoever the fuck will buy it.

> Without. Your. Consent.

I'm really sure that every hotel has its terms of services. So does Facebook and every other site. What you described has always been illegal, and it has also never happened. What was sold was composed of data according to the terms of service that every person included agreed with. If agreement isn't consent, what is?

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#137
post #91

Earlier quoted context omitted.

> Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. Actually, I think we should be annoyed at browser vendors for letting the problems with cookies get to this point. They're obsessed with backwards compatibility, but sometimes you need to break things to fix a problem. This is one of those times. Conside…

Chrome is the biggest browser by market share and is maintained by a company whose entire business model revolves around tracking users to feed them ads. They have zero incentive to remove cookies. Same goes for Safari and Edge, even though they're not as dependent on ad revenue. This is a textbook example of negative externalities that can't be solved by market forces. That's where regulators should be stepping in.

> Chrome is the biggest browser by market share and is maintained by a company whose entire business model revolves around tracking users to feed them ads. They have zero incentive to remove cookies.

Not true. If they don't do something, legislators are going to impose hamfisted regulation like GDPR which does impact their bottom line and hampers their business.

So Google's incentives overlap somewhat with users here. It's possible there's a middle ground in this overlap where the browser includes features specifically for ad-driven content rather than relying on general data load/store mechanisms like cookies which can be easily abused for more nefarious purposes.

Although regulation specifically targeting browser vendors to develop such features would also do the job. It's a mistake to try and push this on websites though.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#138
post #38

Earlier quoted context omitted.

There are experts on this topic who have this exact view of the "right to be forgotten" elements of this article. I'm literally at CANS in Naples right now and someone spoke on this subject yesterday. I don't see anything about it that makes it "especially targeted against data leaks". It offers protections for free speech without being specific about what that means or how it is balanced. Of course it's not the same…

As with every law, we will see how it's actually used in practice but on my case I did not have much doubts about how it's supposed to be applied, I never understood it as an equivalent on the French one. For me, one of the goals here is when you delete your Facebook account, the data is actually deleted unlike what probably happens now.

There's been public analysis of the right to be forgotten. A few good reads: A summary article from NPR [1] and a research paper with a lot more details [2].

[1] https://www.npr.org/sections/thetwo-way/2018/02/28/589411543...)

[2] https://g.co/research/rtbf_report

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#139

The GDPR is mostly good. The right to find out and delete the data is excellent. The bad thing is the constant consent popups which have become synonymous with the GDPR. Obviously there are also still a lot of sites that try to wiggle around the GDPR by saying "By entering the site you agree to X", a practice that should soon be found to be in violation of the regulation. If that is allowed, the regulation for storag…

It's certainly in violation - Recital 43 is quite clear on that.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#140

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

As others have said, you should direct your anger towards every company showing you a GDPR popup. The more complex it is, the more they're trying to fuck with you, and the more they did fuck with you in the past.

I know it's too much to ask, and I'm happy the GDPR went through as it is, but I wish EU could nudge browsers to centralize cookie and GDPR consent forms. Both to fix the UX (a standard browser interface would be much better than most of the popups out there), and to enable me to select "decline everything" once and for all, and never be bugged by it again.

Post reply on HN