Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

191–200 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#191

I would prefer starting small and cautiously scaling up. “If you lose my data, you are strictly liable” is a good start because it lets case law work through the holes. (It also causes companies to see personal data as an asset and a liability, not just the former.) Full-blown GDPR is overkill. It makes more sense to wait a few years and see if the situation in Europe evolves differently from the U.S. I personally be…

"This is not the time to talk about guns"

> This is not the time to talk about guns

That’s disengenuous. I’m saying this is the time to talk about data. But instead of coming out of the gate with a gargantuan salvo or complicated, expensive and unpredictable regulation, let’s start small and work gradually.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#192
post #93

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

It's pretty much having the same impact as California Prop 65, which requires warning signs about "chemicals known to the State of California to cause cancer and birth defects or other reproductive harm" to be displayed where ever you may come into contact with them. Of course, the state of "what the State of California knows" changes every few days, and there's no penalty for being proactive and posting your signs w…

This actually changed recently. Businesses now have to specify exactly which chemical(s) may be encountered.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#193
post #183
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

Most of these sites do have high regard for your privacy. It's not all for ads. Much of it is just for tracking logins and preferences, but warnings for that are required now too.

It's probably not true that warnings are required for tracking logins and preferences:

> The GDPR sets a high standard for consent. But you often won’t need consent. If consent is difficult, look for a different lawful basis.

> https://ico.org.uk/for-organisations/guide-to-the-general-da...

In most circumstances, I would expect things like logins to fall under the 'legitimate interests' basis rather than the 'consent' basis, and interestingly, if login is required to provide service it shouldn't fall under consent anyway.

I think the majority of the consent popups I've seen do not in fact comply with my reading of the GDPR. It's strange, but apparently people don't read the legislation or guidance before making these changes to their sites.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#194
post #6

It's funny, I was listening to the Hanselminutes, and in a recent episode, his guest (a lawyer) was underlining that the US partially created the current situation where current its companies are at loss in front of GDPR: by refusing to take the lead on data privacy issues, the US didn't have a framework for privacy laws, and couldn't negotiate a convergence of laws with the EU (I'm paraphrasing). https://www.hanselm…

While I haven't listened to your linked episode, 'privacy laws' by definition come into direct conflict with the 1st amendment (i.e. free speech) to the U.S Constitution.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#195

Earlier quoted context omitted.

> How can I be 'less complacent' and 'have my guard up' if I don't even know that companies sell my data behind my back? By assuming they will, and taking steps to not provide your data to all and sundry. At the end of the day, companies can sell your data because they have it.

Right, and the logical conclusion of this is to stop interacting with companies. Any companies. All companies. Always. Because they are all doing it to an offensive degree. GM want to know where your car has been, and what radio stations you listen to. Facebook want everything, Google have everything. The pretty light bulb you bought is both a privacy risk and an attack vector. Phone apps want to know your location a…

I was thinking more along the lines of don't post stuff online you don't want anyone to know, but sure you could make a whole big deal arguing against a straw man too if that's your bag. There's also some fundamental industry practices that want changing but if you want to do anything more practical than stomping your feet, avoiding posting personal info is a good start.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#196

I would prefer starting small and cautiously scaling up. “If you lose my data, you are strictly liable” is a good start because it lets case law work through the holes. (It also causes companies to see personal data as an asset and a liability, not just the former.) Full-blown GDPR is overkill. It makes more sense to wait a few years and see if the situation in Europe evolves differently from the U.S. I personally be…

I agree with the sentiment of starting small, but your example of strict liability might be starting too strong. Personally, I would start with a lower mens rea. Maybe I see the situation differently, but I believe most of the subjects covered by GDPR are distinguishable from areas of law such as, e.g., products liability, that utilize strict liability.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#197

Data protection we do need indeed, but the EU is the last entity I want to be emulating on internet laws, except maybe China.

What specifically do you take exception to with regard to GDPR/EU Internet laws? Having hands-on experience with compliance, I find GDPR to be quite reasonable - if anything, I'd say it's overly lax with regards to deletion of data that's not visible to the user (i.e. logs, 'shadow profiles', etc.).

Maybe GDPR is okay, I'm not terribly well informed about it. But every couple weeks the entire internet is up in arms against a new attempt by the EU to censor the entire internet, and I've been dealing for too long with the damn "We use cookies" pop-up they ignorantly required.

So I'm just saying their track record isn't great.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#198
post #11

Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enable c…

> With an unregulated internet, any internet user has to take care of their own privacy and anonymity.

Not really, because much of the information data brokers have about you comes from other people. Oh, your mom gave LinkedIn access to her contact list? Now they’ve got your phone number, mailing address, email address, a contact photo for facial recognition, and lord knows what else.

Oh, your friend and confidant gave an app access to their text messages and email? Great, some data broker now has a copy of every email and text message sent between you. Hope there wasn’t anything private in there.

The argument that you can somehow protect your own privacy on the internet rings hollow when it’s invaded without any action on your part.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#199

Earlier quoted context omitted.

> Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. What about people who had absolutely no issue with the tracking and "privacy" concerns? I don't care if advertisers target me. If I do care, I use incognito sessions. I'm happy with all the free services I get on the internet and I don't mind giving them…

Good, you can opt in to tracking and profiling, if you wish. The rest of us would rather abolish this flagrant abuse of personal information.

> Good, you can opt in to tracking and profiling, if you wish.

What we wish is to be able to opt-in once and for all, to get rid of these incessant interstitial pop-ups sprouting like mushrooms across the Internet.

Perhaps we could introduce a new HTTP header X-GDPR-Consent-Granted, controlled by a checkbox in the browser, to explicitly acknowledge that yes, we know that anyone we interact with online is going to learn various things about us, some of which may be quite personal; that we accept this; and would you please just get out of the way and let us read the article we came here for already?

If the intent was that anyone can decline without any change in service they should have just declared consent irrelevant. No one wants to be accosted 50 times a day for something so trivial, and the answer is obvious—the law prohibits offering any incentive to consent, so the only reason for anyone to grant consent is that they didn't understand the question.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#200
post #6

It's funny, I was listening to the Hanselminutes, and in a recent episode, his guest (a lawyer) was underlining that the US partially created the current situation where current its companies are at loss in front of GDPR: by refusing to take the lead on data privacy issues, the US didn't have a framework for privacy laws, and couldn't negotiate a convergence of laws with the EU (I'm paraphrasing). https://www.hanselm…

While I haven't listened to your linked episode, 'privacy laws' by definition come into direct conflict with the 1st amendment (i.e. free speech) to the U.S Constitution.

I admit I'm not an American citizen, and have never actually stepped foot on American soil, but I do see the "first amendment" and "free speech" arguments being trotted out for almost anything that involves communication between two parties being restricted. This, in my experience has been common in (privately owned) web forums when an American user is banned for misbehaviour, or rules are changed to prohibit certain types of content or speech on those forums.

The text of the amendment, as I'm sure you're aware, reads as follows:

> Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances.

I admit I fail to see how this prohibits introducing a law preventing an organisation from collecting data from individuals without them explicitly opting in to it.

Post reply on HN