Live data from Hacker News

Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

brave.com

221–230 of 238 posts

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#221

Earlier quoted context omitted.

>If a new regulation insisted that on entering a hotel room, a member of the hotel staff had to use a blacklight and you needed to explicitly approve every illuminated mark larger than a quarter, then you would be annoyed at that regulation. How about this. For the past 25 years every hotel that you checked into has kept a record of: - How often did you visit? - How much money did you spend? - What type of CC do you…

>GDPR gives you this vote. >GDPR says: if you want to resell data you harvest you HAVE to get their consent, in clear and understandable terms. Can't bury it in your TOS. >GDPR says: you cannot make your website / app / service unavailable if people refuse this. >GDPR says: you can ask companies how much and which data they got on you and they have to provide it. >GDPR protects you from an invisible industry many peo…

How does not selling your personal information to a third party block you from visiting a website?

GDPR is fine with the selling of information, as long as you have given consent in clear language and not buried in TOS.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#222

Earlier quoted context omitted.

Yes, I generally check ToS of whatever services I use, including hotels. And no, it's no "local planning department of Alpha Centauri" territory, it's available on their webpage and in paper form at the reception, usually framed and hanging on the wall. I check it to see what happens if I overstay, but skim through the whole thing. As a regular person, if I want to use a service offered by someone, I should at least…

It sounds like you agree that forcing people to read and agree to individual portions of the ToS is not a downside of GDPR, since we should all be doing that anyway.

I don't agree nor disagree. The comment I replied to was talking about the past, and in the past, the laws were different and consent was given according to them. I deliberately didn't say if I support GDPR or not, it doesn't matter; the comment said "without your consent" which is simply not true.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#223

Earlier quoted context omitted.

Good, you can opt in to tracking and profiling, if you wish. The rest of us would rather abolish this flagrant abuse of personal information.

> Good, you can opt in to tracking and profiling, if you wish. What we wish is to be able to opt-in once and for all, to get rid of these incessant interstitial pop-ups sprouting like mushrooms across the Internet. Perhaps we could introduce a new HTTP header X-GDPR-Consent-Granted, controlled by a checkbox in the browser, to explicitly acknowledge that yes, we know that anyone we interact with online is going to lea…

>"What we wish is to be able to opt-in once and for all, to get rid of these incessant interstitial pop-ups sprouting like mushrooms across the Internet."

If they implemented GDPR correctly and in a sensible manner, you would get one popup per site, once. You would give your consent to data collection and usage, and they would save that preference in a cookie or your profile settings for that site.

Instead, they want to punish and irritate you into simply accepting whatever they say, in order for the popups to go away. It's completely deliberate.

They could also simply support the Do Not Track header, or a "Please Track Me" counterpart. But they won't do that, because that would make it too easy to escape data collection and profiling, and wouldn't let them annoy you into accepting their onerous terms.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#224

Earlier quoted context omitted.

> Good, you can opt in to tracking and profiling, if you wish. What we wish is to be able to opt-in once and for all, to get rid of these incessant interstitial pop-ups sprouting like mushrooms across the Internet. Perhaps we could introduce a new HTTP header X-GDPR-Consent-Granted, controlled by a checkbox in the browser, to explicitly acknowledge that yes, we know that anyone we interact with online is going to lea…

>"What we wish is to be able to opt-in once and for all, to get rid of these incessant interstitial pop-ups sprouting like mushrooms across the Internet." If they implemented GDPR correctly and in a sensible manner, you would get one popup per site, once. You would give your consent to data collection and usage, and they would save that preference in a cookie or your profile settings for that site. Instead, they want…

> If they implemented GDPR correctly and in a sensible manner, you would get one popup per site, once. You would give your consent to data collection and usage, and they would save that preference in a cookie or your profile settings for that site.

And how is that supposed to work, exactly? If you choose "deny" then they can't track you, so they can't set a cookie or save profile data! Of course you'll get the same prompt the next time you show up. At that point you're just another anonymous visitor of whom they have no prior knowledge. You have to consent before they are allowed to remember your preference.

The same issue applies if you grant consent but take your own measures to thwart tracking, such as limiting cookie lifetime. The next time you show up they don't remember you and must ask again, or else give up and assume that no one ever grants consent.

If you are already signed in to an account that is a different matter, of course, but even for the minority of sites where I would have an account signing in would generally be more trouble than dealing with the pop-up, and thus not an improvement.

> ... into accepting their onerous terms.

There is nothing "onerous" about their terms. They have every right to require your consent in exchange for their services, the GDPR's infringement of that right notwithstanding. For that matter, they have every right to collect, store, and make use of whatever data they are able to gather from your interaction with their service without your consent. The law in this case is blatantly one-sided, and consequently unjust—you aren't forced to beg for their consent to remember and/or communicate whatever data you can gather about the them. For that matter, where is the GDPR equivalent for the government? They collect more information, and more personal information, than anyone else. Based on the same principles as the GDPR, you should be able to opt out of all those income and sales tax reporting forms, for a start, or demand that they delete you from all their databases, with no change in services received.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#226

Earlier quoted context omitted.

>GDPR gives you this vote. >GDPR says: if you want to resell data you harvest you HAVE to get their consent, in clear and understandable terms. Can't bury it in your TOS. >GDPR says: you cannot make your website / app / service unavailable if people refuse this. >GDPR says: you can ask companies how much and which data they got on you and they have to provide it. >GDPR protects you from an invisible industry many peo…

How does not selling your personal information to a third party block you from visiting a website? GDPR is fine with the selling of information, as long as you have given consent in clear language and not buried in TOS.

I think he is referring to websites that are now blocking all EU users because of GDPR.

I'm surprised companies aren't just pulling the same move porn/alcohol websites use with age by asking the user if they are an EU citizen/in the EU and if they answer yes, send them to a static "we don't service the EU" page at which point everyone just lies so they can still access the page with the tracking.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#227
post #182
post #30

Earlier quoted context omitted.

> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…

The cost of determining the tracking behavior of every dependency of every part of your web site is prohibitive. Can you be sure that every hosted font and JavaScript framework you use is hosted on a server that isn't, say, logging IP addresses? Why bother? It's much easier to just throw up a warning popup, which users universally dismiss.

I would argue that you should be able to and then follow that up as to why its prohibitive (and what prohibitive means)?

At least on the library side, there tends to be a default-to-trust to the point where large projects put dependencies on libraries that are built by literally one-guy-with-a-github. I posit that developers should be more critical of including dependencies, and factors like "can we guarantee support" and "how do we know it doesn't have malware, both now and in the future, and who can we hold responsible if it does" should be considered for every dependency we add. As it is, I find a lot of developers will uncritically slurp in any dependency or library that saves them a bit of effort.

If the tooling isn't there to help with this problem then it should be built.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#228

This is so misguided. GDPR is a disaster and only entrenches large companies.

No, big companies have the greatest business-plan, tech, and compliance debt and are slowest to change -- the bizplan debt alone can be retired rapidly only at great risk of breaching fiduciary duty to shareholders.

Neither Google nor Facebook is in compliance with GDPR. FB was busted using 2FA phone number for ad targeting. Google has been taking data for various purposes for decades and linking it all together for other purposes. These are bright-line violations of GDPR's purpose-limitation design.

Smaller companies, by contrast, can change more quickly or start with compliance by construction, as Brave has.

It's a silly slogan that GDPR only helps big incumbents. Regulation tends to help incumbents under varying degrees of regulatory capture, as in the US. Europe is different, and India, Brazil, and others jurisdictions are following suit. California's CCPA is weaker (on protected data, opt out rather than opt in, ambiguity about duress = denial of service if off-purpose data not provided, enforcement), but also in line.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#229
post #209
post #64

Earlier quoted context omitted.

I believe this is more due to lack of enforcement of the GDPR. The dark UX patterns you mention are not technically legal. There a numerous stipulations about how the consent must be freely given, simple and concise, opt-in, withdrawable, etc. I think an equivalent of the GDPR becoming US law would go a long way to improving the problems of enforceability.

You say they are not legal, but then list all the requirements that they do comply with. That’s precisely why they are popups before first interaction, ask you to opt in (or not) and spend half a screen ( but not 50 pages) explaining themselves - concise yet clear and exhaustively explanatory as required.

Most services I've seen set tracking to the maximum by default, then present the user with an "OK, accept everything" and a less obvious "more options", where they must disable numerous default-on tracking options. That's opt-out, not opt-in, hardly simple or concise.

There are also plenty which simply say: accept our tracking or you can't use the service. Which is plainly in breach of Ch. 2 Art. 7.4 of the GDPR.

Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States

#230

Earlier quoted context omitted.

What material harm or damage to you or your person did you experience prior to GDPR that GDPR has prevented or compensated for?

What material harm or damage would you suffer if I snooped on all of your Internet browsing activity with the knowledge of who you are in real life and kept that information around forever to use for whatever purposes I so choose?

Straw man. That’s not analogous to what was being discussed. A better analogy is: HN can see my email because I gave it to them to login. I don’t need to request what HN is doing with my email, because I already know I gave it to them. Giving them my email doesn’t harm me. Using it to do something illegal might, but the GDPR wouldn’t be able to stop that.
Post reply on HN