Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

141–150 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#141

Earlier quoted context omitted.

>If a new regulation insisted that on entering a hotel room, a member of the hotel staff had to use a blacklight and you needed to explicitly approve every illuminated mark larger than a quarter, then you would be annoyed at that regulation. How about this. For the past 25 years every hotel that you checked into has kept a record of: - How often did you visit? - How much money did you spend? - What type of CC do you…

> And then, without your consent, without even notifying you they sold this information to credit score companies, to advertising companies and to whoever the fuck will buy it. > Without. Your. Consent. I'm really sure that every hotel has its terms of services. So does Facebook and every other site. What you described has always been illegal, and it has also never happened. What was sold was composed of data accordi…

Did you read, or was even aware of, a ToS of a hotel on use of personal data? This is entering the "local planning department in Alpha Centauri" territory.

As a regular person, you should not need to be aware of such things. What GDPR tries to do is to restore some sane defaults into the process, just like customer protection laws do.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#142

Earlier quoted context omitted.

Counterpoint: be annoyed at GDPR. If a new regulation insisted that on entering a hotel room, a member of the hotel staff had to use a blacklight and you needed to explicitly approve every illuminated mark larger than a quarter, then you would be annoyed at that regulation. There are supposed to be all sorts of other GDPR protections, about rights to be forgotten, about being able to access and selectively remove per…

> There are supposed to be all sorts of other GDPR protections, about rights to be forgotten, about being able to access and selectively remove personal data from an online profile, that I have no idea how to activate. You don’t have to do anything to “activate” these rights under GDPR. You can just email the website in question and ask them to send an accessible copy of your data, or remove some or all of it from th…

> You don't have to do anything .... just email the website ...

Okay ... let me try this.

> TO: cnn.com

> SUBJECT: Remove my data

Okay, let's send it!

> gmail: The address "cnn.com" in the "To" field was not recognized. Please make sure that all addresses are properly formed.

Oh. I've been around the block; maybe I can try admin@ or support@ or look at whois data, or browse around their website for a "Contact us" link, and maybe I can figure out how to properly assert that I do in fact own the account in question whose data I wish to remove, assuming I even have an explicit account rather than just a tracking cookie and a "shadow" profile. But isn't the GDPR supposed to be consumer-focused? What earthly consumer is going to go through these steps?

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#143

Earlier quoted context omitted.

> Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. Actually, I think we should be annoyed at browser vendors for letting the problems with cookies get to this point. They're obsessed with backwards compatibility, but sometimes you need to break things to fix a problem. This is one of those times. Conside…

Can we have this without forcing it? Ideally browsers would be extensible enough for you to build these things. I miss the document days of yore where implementing a browser would be a reasonable endeavor. And that the limited size of the choices is now seen as a benefit to enforce change is scary. Sure, some see it as a good thing, I mean look at all these features and all the places they've steered the web (e.g. HT…

> Ideally browsers would be extensible enough for you to build these things.

The generality of the environments available in browsers is exactly the problem: we can't tell what they're doing because opaque programs are manipulating opaque data. Making the problem tractable means restricting the ability to communicate via well-defined channels with well-defined data, possibly with specific purposes.

> opt-in is user hostile to the point that never-ask-me-again will become the norm.

You're assuming a lot. Opt-in is not blanket user hostile, it depends on the frequency and circumstances the user encounters it.

My first thought is that opt-in dialogs would be triggered only for forms with password inputs, just like it works now in browsers where users can save their passwords. The cookie is tied to that form submission only so we know its origin and uses, and all other cookies are forbidden. It doesn't strike me as user-hostile at all to then ask the user if they want to permit the site to store a persistent authentication token.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#145
post #62

Earlier quoted context omitted.

> The internet used to be accessed by highly sophisticated and technical users. Quaint but that's simply not true unless you're talking pre 90's. No point in kidding ourselves. The internet was accessed by people who accessed the internet. They popped a floppy/cd in a drive and followed instructions. They then opened a browser and typed a url. Nothing sophisticated about it. Nobody was creating electrical signals by…

> Nobody was creating electrical signals by hand and sending them down a home made wire. I think we're talking about completely different levels of sophistication. You're talking about electrical engineers vs regular users, I'm talking about levels of functional literacy... Don't forget that the average Joe/Jane has a level of functional literacy of somewhere around mid to late secondary school. The earliest internet…

> highly sophisticated and technical users

I'm pointing out that referring to those users as the above is simply not true.

As you then point out, wealth(direct or by proxy) was the determinant in whether somebody had internet access, not high technical sophistication.

And wealth in and of itself is not a signal of high technical sophistication.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#146

Earlier quoted context omitted.

> There are supposed to be all sorts of other GDPR protections, about rights to be forgotten, about being able to access and selectively remove personal data from an online profile, that I have no idea how to activate. You don’t have to do anything to “activate” these rights under GDPR. You can just email the website in question and ask them to send an accessible copy of your data, or remove some or all of it from th…

> You don't have to do anything .... just email the website ... Okay ... let me try this. > TO: cnn.com > SUBJECT: Remove my data Okay, let's send it! > gmail: The address "cnn.com" in the "To" field was not recognized. Please make sure that all addresses are properly formed. Oh. I've been around the block; maybe I can try admin@ or support@ or look at whois data, or browse around their website for a "Contact us" lin…

What earthly consumer is going to go through these steps?

I have requested the removal of my personal data from multiple business, and I can assure you I'm quite earth-bound. Copy-pasting a template and filling in my name and account ID is not that hard.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#147

Earlier quoted context omitted.

> And then, without your consent, without even notifying you they sold this information to credit score companies, to advertising companies and to whoever the fuck will buy it. > Without. Your. Consent. I'm really sure that every hotel has its terms of services. So does Facebook and every other site. What you described has always been illegal, and it has also never happened. What was sold was composed of data accordi…

Did you read, or was even aware of, a ToS of a hotel on use of personal data? This is entering the "local planning department in Alpha Centauri" territory. As a regular person, you should not need to be aware of such things. What GDPR tries to do is to restore some sane defaults into the process, just like customer protection laws do.

Yes, I generally check ToS of whatever services I use, including hotels. And no, it's no "local planning department of Alpha Centauri" territory, it's available on their webpage and in paper form at the reception, usually framed and hanging on the wall. I check it to see what happens if I overstay, but skim through the whole thing.

As a regular person, if I want to use a service offered by someone, I should at least look into their terms - even with GDPR in place.

I'm not saying I disagree with you - but that's an opinion; on the other hand you said that consent was not given, which is simply not true - consent has a definition and that definition was fulfilled, the law doesn't treat ignorant people differently. If you want to say "I don't think should be enough expression of consent", that's OK, say it - but don't lie.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#148

Earlier quoted context omitted.

> Okay I now assume that all companies will harvest as much data as they can. You say harvest, as if they are taking something. The reality is, people always gave the data. The companies just kept what it was freely given. It's a bit hypocritical if I get upset that you keep something I gave you. The reality is, the problem wasn't with the users who gave the data, or the companies who kept what was given, but rather…

People - not the ones here on HN - have no clue what they 'give' away. They also have no clue how often small companies, indie game devs etc make a living by selling said information that was 'given' to them. These data aggregators can build profiles on people by buying data from as many sources as possible. How is the average user supposed to know this happens on the background when they load www.nytimes.com? How ar…

> People - not the ones here on HN - have no clue what they 'give' away.

Doesn't change the fact that browsers requests assets from servers, not the other way around.

People being ignorant of this fact doesn't change this fact. Rather, again, we should place the blame on the thing giving this data to sites: browsers.

> How is the average user supposed to know this happens on the background when they load www.nytimes.com? ...

They shouldn't have to, and thinking they should know this is silly. Which is why I don't blame the users. I blame the browsers. The browsers are the ones sending user data.

> This isn't given. It's taken.

No, it's actually not. This is delusional thinking at best, and ignores where the problem lies. Browsers are giving the necessary information to allow people to be tracked. Only now do we see companies addressing this (see Safari for example).

Suggesting that given data is instead taken allows the people that actually gave the data to the companies to continue to get away with it, and is more harmful.

Stop lying.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#149
post #106

Earlier quoted context omitted.

Your comment is being downvoted because you're just rambling like an old man grumpy about kids on his lawn. Not a single shred of evidence, or even an attempt at making an actual reasoned point. Every time there's comments like this I can't help but think I'd be extremely surprised if the people writing them knew any of the names of the people who worked on the law. I wonder what you even define as "having an idea wh…

Is the best way to fight ignorance, virulent personal attacks? Does that constructively influence people?

I was attacking the contents of the comment, not the person. As for ignorance, I usually give the benefit of the doubt, but I've seen enough of those types of comments regarding GDPR that I'm cynical. They're almost always from non-EU business owners annoyed at having to suddenly comply to EU laws, or business owners in general annoyed at having to care about privacy (where they didn't before).

Uninformed consumers who think GDPR is a cookie law also exist, but they're not HN's usual audience.

Edit: A quick stroll through scoom's comments reveals an nauseatingly unsurprising picture. I'm so very shocked.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#150

Earlier quoted context omitted.

>If a new regulation insisted that on entering a hotel room, a member of the hotel staff had to use a blacklight and you needed to explicitly approve every illuminated mark larger than a quarter, then you would be annoyed at that regulation. How about this. For the past 25 years every hotel that you checked into has kept a record of: - How often did you visit? - How much money did you spend? - What type of CC do you…

> And then, without your consent, without even notifying you they sold this information to credit score companies, to advertising companies and to whoever the fuck will buy it. > Without. Your. Consent. I'm really sure that every hotel has its terms of services. So does Facebook and every other site. What you described has always been illegal, and it has also never happened. What was sold was composed of data accordi…

Freely given consent, as per the GDPR, must be explicit and optional (even if you have consent to use the data for the service being performed). A line buried in a ToS does not comply.
Post reply on HN