Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

201–210 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#201

Earlier quoted context omitted.

People - not the ones here on HN - have no clue what they 'give' away. They also have no clue how often small companies, indie game devs etc make a living by selling said information that was 'given' to them. These data aggregators can build profiles on people by buying data from as many sources as possible. How is the average user supposed to know this happens on the background when they load www.nytimes.com? How ar…

> People - not the ones here on HN - have no clue what they 'give' away. Doesn't change the fact that browsers requests assets from servers, not the other way around. People being ignorant of this fact doesn't change this fact. Rather, again, we should place the blame on the thing giving this data to sites: browsers. > How is the average user supposed to know this happens on the background when they load www.nytimes.…

Incivility like that will get you banned here, regardless of how wrong another comment is or feels. Please review https://news.ycombinator.com/newsguidelines.html and don't do this again.

https://news.ycombinator.com/newsguidelines.html

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#202
post #187

Earlier quoted context omitted.

> Chrome is the biggest browser by market share and is maintained by a company whose entire business model revolves around tracking users to feed them ads. They have zero incentive to remove cookies. Not true. If they don't do something, legislators are going to impose hamfisted regulation like GDPR which does impact their bottom line and hampers their business. So Google's incentives overlap somewhat with users here…

GDPR may affect Google's bottom line in EU markets (we are still awaiting proof as it's too early too tell). But seeing how the FCC dealt with the issue of net neutrality, I have serious doubts that they'd get anywhere near a consumer-first policy regarding Internet privacy.

The previous Democratic administration FCC rule was pro-NN.

The GOP FCC has undone all that. Vote for Democratic congresscriiters this year and begin to undo the damage.

Vote Trump and his FCC out of office in 2020 and a GDPR may be possible.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#203

Earlier quoted context omitted.

While I haven't listened to your linked episode, 'privacy laws' by definition come into direct conflict with the 1st amendment (i.e. free speech) to the U.S Constitution.

I admit I'm not an American citizen, and have never actually stepped foot on American soil, but I do see the "first amendment" and "free speech" arguments being trotted out for almost anything that involves communication between two parties being restricted. This, in my experience has been common in (privately owned) web forums when an American user is banned for misbehaviour, or rules are changed to prohibit certain…

In the same way that recording your interactions with the police is protected.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#204

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

This should be temporarily as it shows (IMO) an extreme misunderstanding of the GDPR:

- by default they are not allowed to collect more data than strictly necessary.

- additional collection must be opt-in, and there can be no punishment for not opting in.

- showing these dialogs that are opt-out seems like a way to beg for a fine: "We hereby declare to all our visitors that by default we collect way more information than we are allowed to."

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#205

Earlier quoted context omitted.

This is how unintended consequences happen. Complaining how rational actors work around roadblocks has no practical effect. Who someone blames has no practical effect. The downside of looking at the intent of the law and assigning blame towards the market is that it encourages doubling down on these negative actions. Why not make popups illegal, they'll say. Why not make it illegal for you to optionally trade your da…

> Complaining how rational actors work around roadblocks has no practical effect. I'm not sure I agree with the 'rational'. If you are so short-sighted as a company that your main course of action boils down to 'piss off the user' while doing everything you can to skirt the law then you deserve to suffer the longer term consequences. Rationality should operate on all time-frames simultaneously.

Everybody has to do it, so not pissing your users is not an advantage. The other options for them are: block EU visitors (that pisses me even more) or go out of business (because they need the tracking to make at least some ad money from the freeloaders who want to read their content but won’t pay a dime).

Saying “just don’t track” is magical thinking. They ARE rational in doing the minimally revenue harming thing to comply in their less lucrative market.

The only ones suffering any consequences are people like us who have to click through so much crap to read something because of the bloody GDPR we didn’t ask for. (Like we didn’t ask for Netflix to have 30% of crappy EU content. That’s EU’s next disaster in making.)

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#206
post #69
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

But is GDPR really making the kind of difference people wanted? What I see, is that mostly companies continue the same behavior, but now with a disclosure you are prompted to accept. I predicted everyone would just accept those terms in exchange for free services they already have invested into. Now we just have an extra annoyance. Has anything substantially changed?

Well, you can’t even access some major news sites from EU...

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#207
post #69

Earlier quoted context omitted.

But is GDPR really making the kind of difference people wanted? What I see, is that mostly companies continue the same behavior, but now with a disclosure you are prompted to accept. I predicted everyone would just accept those terms in exchange for free services they already have invested into. Now we just have an extra annoyance. Has anything substantially changed?

accept those terms in exchange for free services Such exchanges are illegal under the GDPR. Consent must be freely given; if access to a service (that doesn't require that data, or that use of the data) is dependent on it, then it's not valid.

That was OP’s point. Some people, like me, want to freely accept such terms. I don’t give a damn about some cookies tracking. What I do give a damn about is making my own choices.

The entirely predictable consequence of making this trade illegal is that I can’t even access information on sites that have minuscule EU revenue, are too big to be afraid they might become a target, and can’t afford to provide me their services for nothing.

The Great European Firewall is a thing now.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#208

Earlier quoted context omitted.

> Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. What about people who had absolutely no issue with the tracking and "privacy" concerns? I don't care if advertisers target me. If I do care, I use incognito sessions. I'm happy with all the free services I get on the internet and I don't mind giving them…

I see no issue with opt-in as default (which GDPR requires). Then people can make informed decisions and choose to be tracked, while less technical and privacy-mined people don't get tracked.

You’re not in EU, are you?

Everyone defending GDPR around here should be required to take a one week trip to EU and spend some time online while there.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#209
post #64

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

I believe this is more due to lack of enforcement of the GDPR. The dark UX patterns you mention are not technically legal. There a numerous stipulations about how the consent must be freely given, simple and concise, opt-in, withdrawable, etc. I think an equivalent of the GDPR becoming US law would go a long way to improving the problems of enforceability.

You say they are not legal, but then list all the requirements that they do comply with. That’s precisely why they are popups before first interaction, ask you to opt in (or not) and spend half a screen ( but not 50 pages) explaining themselves - concise yet clear and exhaustively explanatory as required.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#210
post #170

The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…

I agree that these are real negative effects of GDPR. However, the concrete design of these pop-ups is mostly not GDPR-compliant: for example, users not agreeing to being tracked must not be disadvantaged, and having to click through a cumbersome array of options is certainly a disadvantage. At least for European web sites, the authorities will hopefully take action after a while, and then these bad practices will st…

I don’t get the disadvantage comment: everyone gets the popup crap, whether you say no or yes. Maybe I visit different sites, maybe I don’t notice because I reflexively click the closest button? In any case, the disadvantaging language is hardly meant that way: it’s about withdrawing actual content or features from you.

We have waited a few years with cookies law and nothing changed. Unless some browser based fix takes place, this degradation of web is staying with us.

Post reply on HN