Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

161–170 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#161
post #62

Earlier quoted context omitted.

> Nobody was creating electrical signals by hand and sending them down a home made wire. I think we're talking about completely different levels of sophistication. You're talking about electrical engineers vs regular users, I'm talking about levels of functional literacy... Don't forget that the average Joe/Jane has a level of functional literacy of somewhere around mid to late secondary school. The earliest internet…

> highly sophisticated and technical users I'm pointing out that referring to those users as the above is simply not true. As you then point out, wealth(direct or by proxy) was the determinant in whether somebody had internet access, not high technical sophistication. And wealth in and of itself is not a signal of high technical sophistication.

It wasn't wealth, it was interest. There was a period where the Internet (or PCs in general) were more of a curiosity than anything else, and you had to have some motivation to jump over the complexities of operating a computer and going on-line (not to mention some motivation to buy a PC/get your parents to do it). It served as a natural quality filter for a while.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#162
post #108

Earlier quoted context omitted.

The poster claims two things: 1. It was "poorly drafted legislation" 2. The authors had "no idea what they were doing" Whether it was poorly drafted legislation remains to be seen. The "unintended consequences" people are talking about here are minor, what matters are the intended consequences such as the augmented rights europeans have over their data, their privacy, etc. I personally don't give a shit about the ann…

I agree with you that an important and useful part of the GDPR is deletion of your data. Good examples: No advertising and spam. Prevention of later hacking and theft of your data like e.g. credit card numbers or private messages. You have revealed your true identity on social media and want to remove your posts. But maybe GDPR gives a false sense of safety and security and control: - What is technically possible ? W…

IANAL so I can't address most of your questions, but

> When I cite you, must my posts be deleted as well ?

You mean for comments and such? What I write on a site's comment section falls under copyright law, with the usual attribution reservations etc. So no.

> Banks and maybe even insurance companies have already the right to know much about you.

I shouldn't have used the word "privacy" in my comment. I think calling GDPR a privacy law is a shortcut a lot of people take (myself included), but it really is a data protection law. (It's even in the name!)

GDPR doesn't talk about privacy very much. In fact, I just searched the full english text of the law: There isn't a single instance of the word "privacy".

In other words, it doesn't so much say who can and cannot store and analyze your data. Instead, it lays out your responsibilities if you are storing/analyzing personal data, and your (consumer) rights as someone whose data is stored/analyzed somewhere.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#163

Earlier quoted context omitted.

> You don't have to do anything .... just email the website ... Okay ... let me try this. > TO: cnn.com > SUBJECT: Remove my data Okay, let's send it! > gmail: The address "cnn.com" in the "To" field was not recognized. Please make sure that all addresses are properly formed. Oh. I've been around the block; maybe I can try admin@ or support@ or look at whois data, or browse around their website for a "Contact us" lin…

What earthly consumer is going to go through these steps? I have requested the removal of my personal data from multiple business, and I can assure you I'm quite earth-bound. Copy-pasting a template and filling in my name and account ID is not that hard.

I'm going to go out on a limb and guess that you are a fairly technical user. My snarkiness in the previous reply was excessive, but reflected my frustration with being told that something is simple that is actually a multi-step process with questions that are not easy to find the answer to.

I guess the problem with email for this process is that you have a number of questions, all of which may not have an easy answer.

1. Identify an email address -- is this standardized? Searching "GDPR address for cnn" gives nothing, and similar more general queries yield little information.

2. Identify a template -- is there a standard one? I see a bunch of websites that claim to have them, looks like 'datarequests.org' is a good(?) one? It seems to have only a small set of sites that can be submitted. The template is incredibly verbose and it isn't clear how to request specific information; would that typically happen as part of a dialog?

3. Identify an account number/user name/verification of identity -- is there a standardized process for this? Could someone else send a request to remove my data? What is the process for this and how can I activate it?

4. Email is not a structured medium. I don't want to get into a whole conversation about this; I want to see the data about me and be able to remove bits of it.

Note that as a software developer #4 sounds kind of ridiculous to me, since user data can be represented in a variety of site-specific manners, and the existing pre-GDPR protections put in place for PII make this almost impossible. But to an end user it feels like it should be a natural thing and having to deal with a number of complex bespoke systems sounds like a pretty heavy load.

I can see the GDPR in this sense being useful for celebrities and the wealthy, who can afford managers or consultants to take this action on their behalf, but not for people like my parents, for whom even step 1 is daunting.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#164
post #23

Earlier quoted context omitted.

> It seems to me that people are working to find ways to improve their lives, and that they'll keep doing so to the shegrin of the internet behemoths absent any "regulation" I'd agree with you if ad & tracking blocking was mainstream, or even better, built into major browsers & operating systems and enabled by default. We are not there yet (and might never be since a major OS developer - Google - has a vested interes…

> the cancer that is called advertising In these conversations "advertising" is a very loaded term, not all advertising is tracking, not all advertising is invasive and not all advertising is served by shady clickbait companies. With a little stretch even a review of a movie or a game is advertising. The GDPR might push toward a more sustainable advertising model and honestly I cannot see anything negative in that. (…

Not all advertising is tracking and clickbait, but in general it is still a cancer on the Internet, and on the modern society. The world is oversaturated with advertising, and we're all forced to look at it everywhere, day in, day out. Advertising is eating absurd amount of resources directly and indirectly (through support industries - from graphics design to printing, transportation and distribution), mostly to shift the split of a fixed pie of customers, in what's pretty much a fractal of zero sum games.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#165
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

> Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. What about people who had absolutely no issue with the tracking and "privacy" concerns? I don't care if advertisers target me. If I do care, I use incognito sessions. I'm happy with all the free services I get on the internet and I don't mind giving them…

> I use incognito sessions.

If you think these do anything at all to prevent tracking, you're unfortunately sadly mistaken :(

> a bit of information about myself

"A bit"? That's... well, the only thing I can say is that you indeed seem not to care about this.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#166

Earlier quoted context omitted.

> Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. What about people who had absolutely no issue with the tracking and "privacy" concerns? I don't care if advertisers target me. If I do care, I use incognito sessions. I'm happy with all the free services I get on the internet and I don't mind giving them…

> I use incognito sessions. If you think these do anything at all to prevent tracking, you're unfortunately sadly mistaken :( > a bit of information about myself "A bit"? That's... well, the only thing I can say is that you indeed seem not to care about this.

> If you think these do anything at all to prevent tracking, you're unfortunately sadly mistaken :(

It definitely stops them from identifying me as logged into Facebook, Twitter... via social share buttons.

> "A bit"? That's... well, the only thing I can say is that you indeed seem not to care about this.

Correct, and I wonder what harm people who complain about this have actually ever come to?

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#167
I am sick and tired of auto playing videos, popups etc. It is not GDPRs fault, media companies are milking us. Yesterday I got to an article that was covered with overlays and popups. You couldn't even see the title. I realized, I didn't care that badly to read it anyway and abandoned it.

Strangely, we are still enduring this terrrible UX experience, mostly because we don't have good alternatives or those that exist, are not known. I think we should spend time creating those and discovering and promoting healthier information sources.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#168

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

It's much to early to understand any of the effects of the GDPR yet. We'll need to see some case history before we can even understand what companies will be penalized for, or how they can come into compliance. It might not be necessary, or even compliant, to notify and gather consent for cookies via popup. This is just something that many web site operators are assuming will bring them into compliance, but there's n…

This is my biggest problem with GDPR. Noone knows how to comply with the rules, because the rules won't be understood until someone gets punished for violating them. Good intentions, imho, do not make for good laws.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#169

Earlier quoted context omitted.

Did you read, or was even aware of, a ToS of a hotel on use of personal data? This is entering the "local planning department in Alpha Centauri" territory. As a regular person, you should not need to be aware of such things. What GDPR tries to do is to restore some sane defaults into the process, just like customer protection laws do.

Yes, I generally check ToS of whatever services I use, including hotels. And no, it's no "local planning department of Alpha Centauri" territory, it's available on their webpage and in paper form at the reception, usually framed and hanging on the wall. I check it to see what happens if I overstay, but skim through the whole thing. As a regular person, if I want to use a service offered by someone, I should at least…

It sounds like you agree that forcing people to read and agree to individual portions of the ToS is not a downside of GDPR, since we should all be doing that anyway.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#170

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

I agree that these are real negative effects of GDPR. However, the concrete design of these pop-ups is mostly not GDPR-compliant: for example, users not agreeing to being tracked must not be disadvantaged, and having to click through a cumbersome array of options is certainly a disadvantage. At least for European web sites, the authorities will hopefully take action after a while, and then these bad practices will stop.

In addition, this is a bit like fire safety regulations. Sure, they are very annoying. All of us probably have experienced the empty battery beep of a smoke sensor in the middle of the night, and many have experienced a false alarm. That's the price you pay for lowering a significant risk.

Wait a few years, and you will see significantly lower risks of your data being collected and distributed without your consent.

I'd like to add that the GDPR is truly disruptive, and it will probably take a few 'product iterations' to get it perfectly right. That alone would be a reason to wait a bit and learn from experiences before rolling such regulations out everywhere. (I'm saying this as an EU citizen)

Post reply on HN